WINTEM.EXE
Résolu
balou30
Messages postés
33
Statut
Membre
-
alexandrezeke -
alexandrezeke -
Bonjour,
Mon ordinateur est infecté par le virus wintens.exe et je n'arrive pas à l'enlever quelqu'un peut m'aider ?
Mon ordinateur est infecté par le virus wintens.exe et je n'arrive pas à l'enlever quelqu'un peut m'aider ?
51 réponses
Bonjour,
Je pense que le problème est résolu. j'ai mis antivir, ccleaner et spybot. Et je crois qu'il l'ont enlever. Vu que tous mes antivirus marche et moins ordinateur est moins lourd. Merci a tous en tous cas.
Je pense que le problème est résolu. j'ai mis antivir, ccleaner et spybot. Et je crois qu'il l'ont enlever. Vu que tous mes antivirus marche et moins ordinateur est moins lourd. Merci a tous en tous cas.
Lut'
Moué , tu peux toujours faire un nettoyage complémentaire pour désinfecter jusqu'au bout =)
*******
TéléchargeCleanup
Lance-le et choisi l'option ' cleanup! '
*******
Et aussi ! prend un pare-feu !!!!
http://www.commentcamarche.net/faq/sujet 2612 firewall installation et configuration du pare feu zonealarm
A+
Moué , tu peux toujours faire un nettoyage complémentaire pour désinfecter jusqu'au bout =)
*******
TéléchargeCleanup
Lance-le et choisi l'option ' cleanup! '
*******
Et aussi ! prend un pare-feu !!!!
http://www.commentcamarche.net/faq/sujet 2612 firewall installation et configuration du pare feu zonealarm
A+
Salut à vous deux
cyrildu17, pour ma recherche, j'aimerais que tu lui fasses utiliser ComboFix, SVP.
Merci
Al.
cyrildu17, pour ma recherche, j'aimerais que tu lui fasses utiliser ComboFix, SVP.
Merci
Al.
Okk Balou30 , une chose encore stp ,
Télécharge ComboFix ici:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Et enregistre le sur le bureau.
Regardes ici, si tu souhaites te familiariser avec son utilisation:
http://mickael.barroux.free.fr/securite/combofix.php
Sur ton bureau double clic sur Combofix.exe.
Appuies sur la touche 1, pour que le programme commence à s'exécuter et suis les instructions à l'écran.
En cours de nettoyage il est possible, que tu reçoives un avertissement te disant que le pc va redémarrer, laisse faire.
Après le redemarrage du pc, un rapport s'ouvrira dans le Bloc notes en fin d'analyse, copie et colle tout son contenu dans ton prochain message.
(Le fichier rapport Combofix.txt , est ensuite automatiquement sauvegardé dans C:\Combofix.txt)
/!\ Pendant toute la durée (ça peut être assez long si le pc est très infecté) du scan de ComboFix, n'ouvres aucun programme et ne surfe pas sur le net.
A+
Télécharge ComboFix ici:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
Et enregistre le sur le bureau.
Regardes ici, si tu souhaites te familiariser avec son utilisation:
http://mickael.barroux.free.fr/securite/combofix.php
Sur ton bureau double clic sur Combofix.exe.
Appuies sur la touche 1, pour que le programme commence à s'exécuter et suis les instructions à l'écran.
En cours de nettoyage il est possible, que tu reçoives un avertissement te disant que le pc va redémarrer, laisse faire.
Après le redemarrage du pc, un rapport s'ouvrira dans le Bloc notes en fin d'analyse, copie et colle tout son contenu dans ton prochain message.
(Le fichier rapport Combofix.txt , est ensuite automatiquement sauvegardé dans C:\Combofix.txt)
/!\ Pendant toute la durée (ça peut être assez long si le pc est très infecté) du scan de ComboFix, n'ouvres aucun programme et ne surfe pas sur le net.
A+
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
le voici oui effectivement javais pas vu qu'il yavait de nouveau msg desole
omboFix 08-02-25.3 - mac30@hotmail.fr 2008-02-26 20:50:07.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.205 [GMT 1:00]
Endroit: C:\Users\mac30@hotmail.fr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2S9CEIUH\ComboFix[1].exe
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Users\MAC30@~1.FR\AppData\Roaming\inst.exe
C:\Users\mac30@hotmail.fr\AppData\Roaming\inst.exe
C:\Windows\system32\drivers\down
C:\Windows\system32\drivers\down\103350.exe
C:\Windows\system32\drivers\down\103584.exe
C:\Windows\system32\drivers\down\107531.exe
C:\Windows\system32\drivers\down\111759.exe
C:\Windows\system32\drivers\down\114457.exe
C:\Windows\system32\drivers\down\115206.exe
C:\Windows\system32\drivers\down\116673.exe
C:\Windows\system32\drivers\down\118014.exe
C:\Windows\system32\drivers\down\118404.exe
C:\Windows\system32\drivers\down\118669.exe
C:\Windows\system32\drivers\down\120417.exe
C:\Windows\system32\drivers\down\125814.exe
C:\Windows\system32\drivers\down\130370.exe
C:\Windows\system32\drivers\down\138482.exe
C:\Windows\system32\drivers\down\139355.exe
C:\Windows\system32\drivers\down\140322.exe
C:\Windows\system32\drivers\down\144581.exe
C:\Windows\system32\drivers\down\145018.exe
C:\Windows\system32\drivers\down\145299.exe
C:\Windows\system32\drivers\down\147514.exe
C:\Windows\system32\drivers\down\149043.exe
C:\Windows\system32\drivers\down\151461.exe
C:\Windows\system32\drivers\down\152256.exe
C:\Windows\system32\drivers\down\157592.exe
C:\Windows\system32\drivers\down\164113.exe
C:\Windows\system32\drivers\down\164362.exe
C:\Windows\system32\drivers\down\168683.exe
C:\Windows\system32\drivers\down\170181.exe
C:\Windows\system32\drivers\down\174923.exe
C:\Windows\system32\drivers\down\177638.exe
C:\Windows\system32\drivers\down\180321.exe
C:\Windows\system32\drivers\down\187528.exe
C:\Windows\system32\drivers\down\189307.exe
C:\Windows\system32\drivers\down\190087.exe
C:\Windows\system32\drivers\down\192583.exe
C:\Windows\system32\drivers\down\193441.exe
C:\Windows\system32\drivers\down\193456.exe
C:\Windows\system32\drivers\down\194174.exe
C:\Windows\system32\drivers\down\198027.exe
C:\Windows\system32\drivers\down\203409.exe
C:\Windows\system32\drivers\down\206654.exe
C:\Windows\system32\drivers\down\211755.exe
C:\Windows\system32\drivers\down\213456.exe
C:\Windows\system32\drivers\down\220429.exe
C:\Windows\system32\drivers\down\220601.exe
C:\Windows\system32\drivers\down\227028.exe
C:\Windows\system32\drivers\down\228728.exe
C:\Windows\system32\drivers\down\247027.exe
C:\Windows\system32\drivers\down\254344.exe
C:\Windows\system32\drivers\down\344949.exe
C:\Windows\system32\drivers\down\347398.exe
C:\Windows\system32\drivers\down\348007.exe
C:\Windows\system32\drivers\down\353217.exe
C:\Windows\system32\drivers\down\355307.exe
C:\Windows\system32\drivers\down\357164.exe
C:\Windows\system32\drivers\down\399986.exe
C:\Windows\system32\drivers\down\402232.exe
C:\Windows\system32\drivers\down\407942.exe
C:\Windows\system32\drivers\down\411031.exe
C:\Windows\system32\drivers\down\412357.exe
C:\Windows\system32\drivers\down\412981.exe
C:\Windows\system32\drivers\down\413589.exe
C:\Windows\system32\drivers\down\416413.exe
C:\Windows\system32\drivers\down\417692.exe
C:\Windows\system32\drivers\down\444634.exe
C:\Windows\system32\drivers\down\447208.exe
C:\Windows\system32\drivers\down\451342.exe
C:\Windows\system32\drivers\down\612444.exe
C:\Windows\system32\drivers\down\622568.exe
C:\Windows\system32\drivers\down\627170.exe
C:\Windows\system32\drivers\down\65348.exe
C:\Windows\system32\drivers\down\79997.exe
C:\Windows\system32\drivers\down\82196.exe
C:\Windows\system32\drivers\down\88702.exe
C:\Windows\system32\drivers\down\92071.exe
C:\Windows\system32\drivers\down\94770.exe
C:\Windows\system32\drivers\down\94786.exe
C:\Windows\system32\drivers\down\96720.exe
C:\Windows\system32\koos.exe
C:\Windows\system32\kprof
C:\Windows\system32\poof
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_IDSVIX86
-------\LEGACY_SROSA
((((((((((((((((((((((((((((( Fichiers créés 2008-01-26 to 2008-02-26 ))))))))))))))))))))))))))))))))))))
.
2008-02-26 20:14 . 2007-09-19 15:26 195,928 --a------ C:\Windows\System32\drivers\pctfw2.sys
2008-02-26 20:14 . 2007-09-19 15:26 114,008 --a------ C:\Windows\System32\drivers\pctfw.sys
2008-02-26 20:13 . 2008-02-26 20:17 <REP> d-------- C:\Program Files\PC Tools Firewall Plus
2008-02-26 20:13 . 2008-02-26 20:13 <REP> d-------- C:\Program Files\Common Files\PC Tools
2008-02-26 20:13 . 2007-09-19 15:26 39,768 --a------ C:\Windows\System32\drivers\pctmp.sys
2008-02-26 20:13 . 2007-09-19 15:26 17,752 --a------ C:\Windows\System32\drivers\pctssipc.sys
2008-02-26 18:29 . 2008-02-26 18:42 <REP> d-------- C:\Program Files\Windows Live
2008-02-25 11:17 . 2008-02-25 17:06 <REP> d-------- C:\metin
2008-02-24 14:55 . 2008-02-24 14:55 <REP> d-------- C:\Program Files\Metin2_France
2008-02-22 16:37 . 2008-02-22 16:37 <REP> d-------- C:\Users\mac30@hotmail.fr\AppData\Roaming\Media Player Classic
2008-02-22 16:37 . 2008-02-22 16:37 <REP> d-------- C:\Users\MAC30@~1.FR\AppData\Roaming\Media Player Classic
2008-02-18 15:14 . 2008-02-18 15:15 <REP> d-------- C:\Program Files\Windows Live Safety Center
2008-02-14 09:56 . 2008-02-14 09:56 194,560 --a------ C:\Windows\System32\WebClnt.dll
2008-02-14 09:56 . 2008-02-14 09:56 110,080 --a------ C:\Windows\System32\drivers\mrxdav.sys
2008-02-14 09:52 . 2008-02-14 09:52 803,328 --a------ C:\Windows\System32\drivers\tcpip.sys
2008-02-14 09:52 . 2008-02-14 09:52 216,632 --a------ C:\Windows\System32\drivers\netio.sys
2008-02-14 09:52 . 2008-02-14 09:52 167,424 --a------ C:\Windows\System32\tcpipcfg.dll
2008-02-14 09:52 . 2008-02-14 09:52 24,064 --a------ C:\Windows\System32\netcfg.exe
2008-02-14 09:52 . 2008-02-14 09:52 22,016 --a------ C:\Windows\System32\netiougc.exe
2008-02-01 21:57 . 2008-02-01 21:57 244 --ah----- C:\sqmnoopt05.sqm
2008-02-01 21:57 . 2008-02-01 21:57 232 --ah----- C:\sqmdata05.sqm
2008-02-01 21:53 . 2008-02-01 21:53 244 --ah----- C:\sqmnoopt04.sqm
2008-02-01 21:53 . 2008-02-01 21:53 232 --ah----- C:\sqmdata04.sqm
2008-02-01 21:30 . 2008-02-01 21:30 244 --ah----- C:\sqmnoopt03.sqm
2008-02-01 21:30 . 2008-02-01 21:30 232 --ah----- C:\sqmdata03.sqm
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-26 19:38 --------- d-----w C:\PROGRA~2\Microsoft Help
2008-02-26 17:36 --------- d-----w C:\PROGRA~2\WLInstaller
2008-02-16 12:57 230,432 ----a-w C:\SPC500NC.DAT
2008-02-14 08:49 824,832 ----a-w C:\Windows\System32\wininet.dll
2008-02-14 08:49 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-14 08:49 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-14 08:49 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-01-23 18:49 --------- d-----w C:\Users\mac30@hotmail.fr\AppData\Roaming\CyberLink
2008-01-23 18:49 --------- d-----w C:\Users\MAC30@~1.FR\AppData\Roaming\CyberLink
2008-01-23 18:49 --------- d-----w C:\PROGRA~2\CyberLink
2008-01-23 08:35 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-22 17:17 --------- d-----w C:\Program Files\Lavasoft
2008-01-22 12:34 --------- d-----w C:\PROGRA~2\Spybot - Search & Destroy
2008-01-22 11:47 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-01-22 11:37 81,984 ----a-w C:\Windows\System32\bdod.bin
2008-01-21 21:41 --------- d-----w C:\Program Files\Avira
2008-01-21 21:41 --------- d-----w C:\PROGRA~2\Avira
2008-01-21 18:40 --------- d-----w C:\PROGRA~2\F-Secure
2008-01-20 16:57 --------- d-----w C:\Users\mac30@hotmail.fr\AppData\Roaming\F-Secure
2008-01-20 16:57 --------- d-----w C:\Users\MAC30@~1.FR\AppData\Roaming\F-Secure
2008-01-20 16:45 --------- d-----w C:\PROGRA~2\fssg
2008-01-20 15:40 --------- d-----w C:\Program Files\CCleaner
2008-01-20 13:44 --------- d-----w C:\Program Files\Trend Micro
2008-01-20 11:27 --------- d-----w C:\Program Files\MSN Messenger
2008-01-20 11:10 --------- d-----w C:\PROGRA~2\WindowsLiveInstaller
2008-01-19 21:38 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-19 09:46 --------- d-----w C:\PROGRA~2\ashampoo
2008-01-19 09:26 47,360 ----a-w C:\Users\mac30@hotmail.fr\AppData\Roaming\pcouffin.sys
2008-01-19 09:26 47,360 ----a-w C:\Users\MAC30@~1.FR\AppData\Roaming\pcouffin.sys
2008-01-19 09:26 --------- d-----w C:\Users\mac30@hotmail.fr\AppData\Roaming\Vso
2008-01-19 09:26 --------- d-----w C:\Users\MAC30@~1.FR\AppData\Roaming\Vso
2008-01-19 09:23 47,360 ----a-w C:\Windows\system32\drivers\pcouffin.sys
2008-01-13 10:53 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-10 18:07 --------- d-----w C:\Users\mac30@hotmail.fr\AppData\Roaming\GrabIt
2008-01-10 18:07 --------- d-----w C:\Users\MAC30@~1.FR\AppData\Roaming\GrabIt
2008-01-09 22:12 11,776 ----a-w C:\Windows\System32\sbunattend.exe
2008-01-09 22:12 --------- d-----w C:\Program Files\Windows Sidebar
2007-12-29 20:42 --------- d-----w C:\Users\mac30@hotmail.fr\AppData\Roaming\vlc
2007-12-29 20:42 --------- d-----w C:\Users\MAC30@~1.FR\AppData\Roaming\vlc
2007-12-29 19:32 --------- d-----w C:\Program Files\Free.fr
2007-12-13 06:31 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2007-12-13 06:30 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2007-12-13 06:30 223,232 ----a-w C:\Windows\System32\WMASF.DLL
2007-12-13 06:27 3,504,824 ----a-w C:\Windows\System32\ntkrnlpa.exe
2007-12-13 06:27 3,470,520 ----a-w C:\Windows\System32\ntoskrnl.exe
2006-11-02 12:50 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-09 23:12 1232896]
"????r"="" []
"?????????"="" []
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35 125440]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [ ]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 15:30 249856]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [ ]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
"ares"="D:\Ares\Ares.exe" [2007-12-31 15:29 962560]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 13:36 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-04-13 10:16 1006264]
"RtHDVCpl"="RtHDVCpl.exe" [2006-11-09 03:57 3784704 C:\Windows\RtHDVCpl.exe]
"Acer Tour"="" []
"Acer Empowering Technology Monitor"="C:\Windows\system32\SysMonitor.exe" [2006-11-23 15:24 319488]
"WarReg_PopUp"="C:\Acer\WR_PopUp\WarReg_PopUp.exe" [ ]
"eRecoveryService"="" []
"BigDog305"="C:\Windows\VM305_STI.exe" [2005-08-05 21:15 61440]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 05:24 286720]
"SPC500NC_Monitor"="C:\Windows\Philips\SPC500NC\Monitor.exe" [2008-01-20 17:09 319488]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-01-21 22:42 249896]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06 40048]
"00PCTFW"="C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" [2007-09-19 15:27 2483504]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Startup\
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2006-12-14 14:18:59 528384]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2007-03-03 15:24:52 450560]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{D2DB2E45-4DF4-47AD-AE2F-2AB9F1292E38}C:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe"= UDP:C:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe:Logitech Desktop Messenger|Desc=Logitech Desktop Messenger
"UDP Query User{D8A09E2A-5420-4DB2-98C4-25862086CBA5}C:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe"= TCP:C:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe:Logitech Desktop Messenger|Desc=Logitech Desktop Messenger
"TCP Query User{E800720B-AC92-421D-8CC0-0C6DED54FA4D}D:\emule\emule.exe"= UDP:D:\emule\emule.exe:eMule|Desc=eMule
"UDP Query User{3A7A2828-8113-40F1-ADA1-C2132F5A6647}D:\emule\emule.exe"= TCP:D:\emule\emule.exe:eMule|Desc=eMule
"{18617E06-76E5-4282-B201-5C1C391342A0}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{E670E9F6-7CCB-49F1-9ABD-A605DD691FC6}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{8B8A54D0-A47D-43E6-9905-480E28A99232}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{4E12AA0C-ACC4-4C18-A516-0DFDEC5BBEE3}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{73090CB7-B532-4212-99D5-8BCD161D317D}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{CEF4DDD1-D5B3-45AF-8684-3B7BF8F9B425}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{29F5D07F-AA72-4967-B21A-7FB4722DED1D}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{74CB2E61-4221-438E-8A33-CD56A88AECBC}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{7CCB08B9-7286-4EB7-9A9E-2DE13C8681CD}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{302F1AF8-7A51-4BCB-96C9-6868BCFDFE83}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{CF237559-E272-4B9B-8105-A976502B4879}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{A3698AB0-CDB4-427A-9FF2-F542527386CD}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{687AE64B-5A4A-401B-BE87-1E5C8BF0EA9E}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{52963A72-6958-4427-932A-1FEBE6253019}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{1F9D876A-FB8B-4AEB-B86F-1D42C42A8A23}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{3FA83965-A2B0-496E-89E8-A0186004D60D}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{93ABBE35-B905-46FF-BB0F-C8DF68201500}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{143632B5-38C9-4CE6-AF52-B769ACBAD7C4}"= UDP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{0BFE481F-258E-4FB9-8FAF-14CC3BAAD900}"= TCP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{C27FB5FA-4A2F-4DDA-AFD7-BF948C8D5390}"= UDP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{A61614BA-8F85-49FE-A59E-09999F181870}"= TCP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{B661D304-D8F1-4218-B750-F0D8FF5D1867}"= UDP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{83237FEF-AA89-48F7-88F7-D77D1F383007}"= TCP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"TCP Query User{2F8439F9-D3FE-4686-87F4-E51B4ED4296A}C:\users\mac30@hotmail.fr\appdata\local\temp\qztemp\emule.exe"= UDP:C:\users\mac30@hotmail.fr\appdata\local\temp\qztemp\emule.exe:emule.exe|Desc=emule.exe
"UDP Query User{CEE0EA9F-F0BB-42B4-B140-180B81EFCAAC}C:\users\mac30@hotmail.fr\appdata\local\temp\qztemp\emule.exe"= TCP:C:\users\mac30@hotmail.fr\appdata\local\temp\qztemp\emule.exe:emule.exe|Desc=emule.exe
"TCP Query User{98811D98-75D5-40BB-9D9A-7C56D328E182}D:\lphant\elephantclient.exe"= UDP:D:\lphant\elephantclient.exe:lphant Client|Desc=lphant Client
"UDP Query User{75A8E5CB-0D87-46D0-A3B1-7D5789D1ECBA}D:\lphant\elephantclient.exe"= TCP:D:\lphant\elephantclient.exe:lphant Client|Desc=lphant Client
"{24FB3F2C-9EFA-4739-AD13-AB2CF3AB978C}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)|Edge=TRUE|
"{B7811C2D-AF33-4F4F-954E-416D3B551C93}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)|Edge=TRUE|
"{999E9AA4-71FA-4AB3-9D21-20B313FA0B36}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)|Edge=TRUE|
"{DD568884-2F44-4533-A4DB-410716E8A10D}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)|Edge=TRUE|
"{CBD0E49E-28D2-4179-9990-CA902AE10270}"= UDP:D:\LimeWire\LimeWire.exe:LimeWire
"{51C61193-F29A-4F67-AADA-6DDEC953E062}"= TCP:D:\LimeWire\LimeWire.exe:LimeWire
"{CE345439-B060-4BE5-B90B-352A25BF2B52}"= UDP:C:\Program Files\BitTorrent_DNA\dna.exe:DNA
"{9FFB11E5-7ABD-4955-AF83-F574A8AC29D1}"= TCP:C:\Program Files\BitTorrent_DNA\dna.exe:DNA
"{6890988F-A17C-4BC0-858A-A63BE3495D4B}"= UDP:D:\BitTorrent\bittorrent.exe:BitTorrent
"{D68886A8-3F1A-47DB-8AC3-ADC8275438A3}"= TCP:D:\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{341DD81C-6868-4B49-A30F-10E68470D321}D:\adsltv.exe"= UDP:D:\adsltv.exe:adsltv|Desc=adsltv
"UDP Query User{0C8E23AC-5337-4F59-8F73-9D59D99E06A1}D:\adsltv.exe"= TCP:D:\adsltv.exe:adsltv|Desc=adsltv
"{8F29CC60-6695-4D46-89EF-94BCC3F66097}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)|Edge=TRUE|
"{F01724EC-D533-4F58-945A-66B12CEFA812}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"TCP Query User{4CBAC4AC-88BF-4C35-9BA7-060AB81AE142}D:\azureus\azureus.exe"= Disabled:UDP:D:\azureus\azureus.exe:Azureus|Desc=Azureus
"UDP Query User{5CAE9B81-D0FD-464C-BB13-1FA6B3241F78}D:\azureus\azureus.exe"= Disabled:TCP:D:\azureus\azureus.exe:Azureus|Desc=Azureus
"{12A45747-2372-4071-AFC2-797A16389BB3}"= Disabled:UDP:C:\Program Files\Acer Zone\Acer Zone Main Page\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
"{857E81E3-6A25-4038-A976-590002A8FF54}"= Disabled:TCP:C:\Program Files\Acer Zone\Acer Zone Main Page\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
"{B2690F95-1BA9-42B6-8151-D37A873D97E9}"= Disabled:UDP:C:\Program Files\Acer Zone\Acer Picture Slide DVD\Component\CLSLDVD.exe:Cyberlink Picture Slide DVD workprocess
"{BE8168BD-1587-48C9-B8A9-8DA29EB488A4}"= Disabled:TCP:C:\Program Files\Acer Zone\Acer Picture Slide DVD\Component\CLSLDVD.exe:Cyberlink Picture Slide DVD workprocess
"{97A20D34-D5EB-42F9-8D75-7772B1CAAAB2}"= Disabled:UDP:C:\Program Files\Acer Zone\Acer Plug and Record\Component\ARAWP.exe:Cyberlink Plug and Record ARA workprocess
"{8FFFA071-A90B-466D-AAC6-D07DB72C5A9C}"= Disabled:TCP:C:\Program Files\Acer Zone\Acer Plug and Record\Component\ARAWP.exe:Cyberlink Plug and Record ARA workprocess
"{FBB2CD35-5498-46F4-8829-2DF3885C1C12}"= Disabled:UDP:C:\Program Files\Acer Zone\Acer Plug and Record\Component\DVAX2Process.exe:Cyberlink Plug and Record AVAX workprocess
"{0035BDE0-2E3C-476E-9D74-C9778E365572}"= Disabled:TCP:C:\Program Files\Acer Zone\Acer Plug and Record\Component\DVAX2Process.exe:Cyberlink Plug and Record AVAX workprocess
"{2C7749D8-584C-471D-AEFF-C677570CEC98}"= Disabled:UDP:C:\Program Files\Acer Zone\Acer Zone SoftDMA\SoftDMA.exe:CyberLink SoftDMA
"{6C2ADED2-5CD6-425A-A80E-00AA1D08D67B}"= Disabled:TCP:C:\Program Files\Acer Zone\Acer Zone SoftDMA\SoftDMA.exe:CyberLink SoftDMA
"{29278D60-0D80-4A89-8D19-3FAAAEB8CAB1}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"D:\BitTorrent\bittorrent.exe"= D:\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R1 pctfw2;pctfw2;C:\Windows\system32\drivers\pctfw2.sys [2007-09-19 15:26]
R1 pctmp;PC Tools Firewall Memory Protection Driver;C:\Windows\system32\drivers\pctmp.sys [2007-09-19 15:26]
R1 pctssipc;PC Tools Security Suite IPC Driver;C:\Windows\system32\drivers\pctssipc.sys [2007-09-19 15:26]
R3 SPC500NC;SPC 500NC Laptop Camera;C:\Windows\system32\DRIVERS\SPC610NC.SYS [2007-01-19 16:14]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-09 02:52]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;C:\Windows\system32\DRIVERS\fbxusb32.sys [2004-10-20 14:23]
S3 WSVD;WSVD;C:\Windows\system32\drivers\WSVD.sys [2006-09-19 16:47]
S3 ZSMC0305;A4 TECH PC Camera V;C:\Windows\system32\Drivers\usbVM305.sys [2006-05-08 16:24]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20714440-70d1-11dc-96e1-0007cb0000ff}]
\shell\Auto\command - cmd /C launch.bat
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL cmd /C launch.bat
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-26 20:58:30
Windows 6.0.6000 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\PC Tools Firewall Plus\FWService.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\ehome\ehmsas.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
.
**************************************************************************
.
Temps d'accomplissement: 2008-02-26 21:01:01 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-26 20:00:56
.
2008-02-26 19:38:26 --- E O F ---
omboFix 08-02-25.3 - mac30@hotmail.fr 2008-02-26 20:50:07.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.205 [GMT 1:00]
Endroit: C:\Users\mac30@hotmail.fr\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2S9CEIUH\ComboFix[1].exe
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Users\MAC30@~1.FR\AppData\Roaming\inst.exe
C:\Users\mac30@hotmail.fr\AppData\Roaming\inst.exe
C:\Windows\system32\drivers\down
C:\Windows\system32\drivers\down\103350.exe
C:\Windows\system32\drivers\down\103584.exe
C:\Windows\system32\drivers\down\107531.exe
C:\Windows\system32\drivers\down\111759.exe
C:\Windows\system32\drivers\down\114457.exe
C:\Windows\system32\drivers\down\115206.exe
C:\Windows\system32\drivers\down\116673.exe
C:\Windows\system32\drivers\down\118014.exe
C:\Windows\system32\drivers\down\118404.exe
C:\Windows\system32\drivers\down\118669.exe
C:\Windows\system32\drivers\down\120417.exe
C:\Windows\system32\drivers\down\125814.exe
C:\Windows\system32\drivers\down\130370.exe
C:\Windows\system32\drivers\down\138482.exe
C:\Windows\system32\drivers\down\139355.exe
C:\Windows\system32\drivers\down\140322.exe
C:\Windows\system32\drivers\down\144581.exe
C:\Windows\system32\drivers\down\145018.exe
C:\Windows\system32\drivers\down\145299.exe
C:\Windows\system32\drivers\down\147514.exe
C:\Windows\system32\drivers\down\149043.exe
C:\Windows\system32\drivers\down\151461.exe
C:\Windows\system32\drivers\down\152256.exe
C:\Windows\system32\drivers\down\157592.exe
C:\Windows\system32\drivers\down\164113.exe
C:\Windows\system32\drivers\down\164362.exe
C:\Windows\system32\drivers\down\168683.exe
C:\Windows\system32\drivers\down\170181.exe
C:\Windows\system32\drivers\down\174923.exe
C:\Windows\system32\drivers\down\177638.exe
C:\Windows\system32\drivers\down\180321.exe
C:\Windows\system32\drivers\down\187528.exe
C:\Windows\system32\drivers\down\189307.exe
C:\Windows\system32\drivers\down\190087.exe
C:\Windows\system32\drivers\down\192583.exe
C:\Windows\system32\drivers\down\193441.exe
C:\Windows\system32\drivers\down\193456.exe
C:\Windows\system32\drivers\down\194174.exe
C:\Windows\system32\drivers\down\198027.exe
C:\Windows\system32\drivers\down\203409.exe
C:\Windows\system32\drivers\down\206654.exe
C:\Windows\system32\drivers\down\211755.exe
C:\Windows\system32\drivers\down\213456.exe
C:\Windows\system32\drivers\down\220429.exe
C:\Windows\system32\drivers\down\220601.exe
C:\Windows\system32\drivers\down\227028.exe
C:\Windows\system32\drivers\down\228728.exe
C:\Windows\system32\drivers\down\247027.exe
C:\Windows\system32\drivers\down\254344.exe
C:\Windows\system32\drivers\down\344949.exe
C:\Windows\system32\drivers\down\347398.exe
C:\Windows\system32\drivers\down\348007.exe
C:\Windows\system32\drivers\down\353217.exe
C:\Windows\system32\drivers\down\355307.exe
C:\Windows\system32\drivers\down\357164.exe
C:\Windows\system32\drivers\down\399986.exe
C:\Windows\system32\drivers\down\402232.exe
C:\Windows\system32\drivers\down\407942.exe
C:\Windows\system32\drivers\down\411031.exe
C:\Windows\system32\drivers\down\412357.exe
C:\Windows\system32\drivers\down\412981.exe
C:\Windows\system32\drivers\down\413589.exe
C:\Windows\system32\drivers\down\416413.exe
C:\Windows\system32\drivers\down\417692.exe
C:\Windows\system32\drivers\down\444634.exe
C:\Windows\system32\drivers\down\447208.exe
C:\Windows\system32\drivers\down\451342.exe
C:\Windows\system32\drivers\down\612444.exe
C:\Windows\system32\drivers\down\622568.exe
C:\Windows\system32\drivers\down\627170.exe
C:\Windows\system32\drivers\down\65348.exe
C:\Windows\system32\drivers\down\79997.exe
C:\Windows\system32\drivers\down\82196.exe
C:\Windows\system32\drivers\down\88702.exe
C:\Windows\system32\drivers\down\92071.exe
C:\Windows\system32\drivers\down\94770.exe
C:\Windows\system32\drivers\down\94786.exe
C:\Windows\system32\drivers\down\96720.exe
C:\Windows\system32\koos.exe
C:\Windows\system32\kprof
C:\Windows\system32\poof
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_IDSVIX86
-------\LEGACY_SROSA
((((((((((((((((((((((((((((( Fichiers créés 2008-01-26 to 2008-02-26 ))))))))))))))))))))))))))))))))))))
.
2008-02-26 20:14 . 2007-09-19 15:26 195,928 --a------ C:\Windows\System32\drivers\pctfw2.sys
2008-02-26 20:14 . 2007-09-19 15:26 114,008 --a------ C:\Windows\System32\drivers\pctfw.sys
2008-02-26 20:13 . 2008-02-26 20:17 <REP> d-------- C:\Program Files\PC Tools Firewall Plus
2008-02-26 20:13 . 2008-02-26 20:13 <REP> d-------- C:\Program Files\Common Files\PC Tools
2008-02-26 20:13 . 2007-09-19 15:26 39,768 --a------ C:\Windows\System32\drivers\pctmp.sys
2008-02-26 20:13 . 2007-09-19 15:26 17,752 --a------ C:\Windows\System32\drivers\pctssipc.sys
2008-02-26 18:29 . 2008-02-26 18:42 <REP> d-------- C:\Program Files\Windows Live
2008-02-25 11:17 . 2008-02-25 17:06 <REP> d-------- C:\metin
2008-02-24 14:55 . 2008-02-24 14:55 <REP> d-------- C:\Program Files\Metin2_France
2008-02-22 16:37 . 2008-02-22 16:37 <REP> d-------- C:\Users\mac30@hotmail.fr\AppData\Roaming\Media Player Classic
2008-02-22 16:37 . 2008-02-22 16:37 <REP> d-------- C:\Users\MAC30@~1.FR\AppData\Roaming\Media Player Classic
2008-02-18 15:14 . 2008-02-18 15:15 <REP> d-------- C:\Program Files\Windows Live Safety Center
2008-02-14 09:56 . 2008-02-14 09:56 194,560 --a------ C:\Windows\System32\WebClnt.dll
2008-02-14 09:56 . 2008-02-14 09:56 110,080 --a------ C:\Windows\System32\drivers\mrxdav.sys
2008-02-14 09:52 . 2008-02-14 09:52 803,328 --a------ C:\Windows\System32\drivers\tcpip.sys
2008-02-14 09:52 . 2008-02-14 09:52 216,632 --a------ C:\Windows\System32\drivers\netio.sys
2008-02-14 09:52 . 2008-02-14 09:52 167,424 --a------ C:\Windows\System32\tcpipcfg.dll
2008-02-14 09:52 . 2008-02-14 09:52 24,064 --a------ C:\Windows\System32\netcfg.exe
2008-02-14 09:52 . 2008-02-14 09:52 22,016 --a------ C:\Windows\System32\netiougc.exe
2008-02-01 21:57 . 2008-02-01 21:57 244 --ah----- C:\sqmnoopt05.sqm
2008-02-01 21:57 . 2008-02-01 21:57 232 --ah----- C:\sqmdata05.sqm
2008-02-01 21:53 . 2008-02-01 21:53 244 --ah----- C:\sqmnoopt04.sqm
2008-02-01 21:53 . 2008-02-01 21:53 232 --ah----- C:\sqmdata04.sqm
2008-02-01 21:30 . 2008-02-01 21:30 244 --ah----- C:\sqmnoopt03.sqm
2008-02-01 21:30 . 2008-02-01 21:30 232 --ah----- C:\sqmdata03.sqm
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-26 19:38 --------- d-----w C:\PROGRA~2\Microsoft Help
2008-02-26 17:36 --------- d-----w C:\PROGRA~2\WLInstaller
2008-02-16 12:57 230,432 ----a-w C:\SPC500NC.DAT
2008-02-14 08:49 824,832 ----a-w C:\Windows\System32\wininet.dll
2008-02-14 08:49 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-14 08:49 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-14 08:49 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-01-23 18:49 --------- d-----w C:\Users\mac30@hotmail.fr\AppData\Roaming\CyberLink
2008-01-23 18:49 --------- d-----w C:\Users\MAC30@~1.FR\AppData\Roaming\CyberLink
2008-01-23 18:49 --------- d-----w C:\PROGRA~2\CyberLink
2008-01-23 08:35 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-22 17:17 --------- d-----w C:\Program Files\Lavasoft
2008-01-22 12:34 --------- d-----w C:\PROGRA~2\Spybot - Search & Destroy
2008-01-22 11:47 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-01-22 11:37 81,984 ----a-w C:\Windows\System32\bdod.bin
2008-01-21 21:41 --------- d-----w C:\Program Files\Avira
2008-01-21 21:41 --------- d-----w C:\PROGRA~2\Avira
2008-01-21 18:40 --------- d-----w C:\PROGRA~2\F-Secure
2008-01-20 16:57 --------- d-----w C:\Users\mac30@hotmail.fr\AppData\Roaming\F-Secure
2008-01-20 16:57 --------- d-----w C:\Users\MAC30@~1.FR\AppData\Roaming\F-Secure
2008-01-20 16:45 --------- d-----w C:\PROGRA~2\fssg
2008-01-20 15:40 --------- d-----w C:\Program Files\CCleaner
2008-01-20 13:44 --------- d-----w C:\Program Files\Trend Micro
2008-01-20 11:27 --------- d-----w C:\Program Files\MSN Messenger
2008-01-20 11:10 --------- d-----w C:\PROGRA~2\WindowsLiveInstaller
2008-01-19 21:38 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-19 09:46 --------- d-----w C:\PROGRA~2\ashampoo
2008-01-19 09:26 47,360 ----a-w C:\Users\mac30@hotmail.fr\AppData\Roaming\pcouffin.sys
2008-01-19 09:26 47,360 ----a-w C:\Users\MAC30@~1.FR\AppData\Roaming\pcouffin.sys
2008-01-19 09:26 --------- d-----w C:\Users\mac30@hotmail.fr\AppData\Roaming\Vso
2008-01-19 09:26 --------- d-----w C:\Users\MAC30@~1.FR\AppData\Roaming\Vso
2008-01-19 09:23 47,360 ----a-w C:\Windows\system32\drivers\pcouffin.sys
2008-01-13 10:53 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-10 18:07 --------- d-----w C:\Users\mac30@hotmail.fr\AppData\Roaming\GrabIt
2008-01-10 18:07 --------- d-----w C:\Users\MAC30@~1.FR\AppData\Roaming\GrabIt
2008-01-09 22:12 11,776 ----a-w C:\Windows\System32\sbunattend.exe
2008-01-09 22:12 --------- d-----w C:\Program Files\Windows Sidebar
2007-12-29 20:42 --------- d-----w C:\Users\mac30@hotmail.fr\AppData\Roaming\vlc
2007-12-29 20:42 --------- d-----w C:\Users\MAC30@~1.FR\AppData\Roaming\vlc
2007-12-29 19:32 --------- d-----w C:\Program Files\Free.fr
2007-12-13 06:31 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2007-12-13 06:30 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2007-12-13 06:30 223,232 ----a-w C:\Windows\System32\WMASF.DLL
2007-12-13 06:27 3,504,824 ----a-w C:\Windows\System32\ntkrnlpa.exe
2007-12-13 06:27 3,470,520 ----a-w C:\Windows\System32\ntoskrnl.exe
2006-11-02 12:50 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-09 23:12 1232896]
"????r"="" []
"?????????"="" []
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35 125440]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [ ]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 15:30 249856]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [ ]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
"ares"="D:\Ares\Ares.exe" [2007-12-31 15:29 962560]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 13:36 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-04-13 10:16 1006264]
"RtHDVCpl"="RtHDVCpl.exe" [2006-11-09 03:57 3784704 C:\Windows\RtHDVCpl.exe]
"Acer Tour"="" []
"Acer Empowering Technology Monitor"="C:\Windows\system32\SysMonitor.exe" [2006-11-23 15:24 319488]
"WarReg_PopUp"="C:\Acer\WR_PopUp\WarReg_PopUp.exe" [ ]
"eRecoveryService"="" []
"BigDog305"="C:\Windows\VM305_STI.exe" [2005-08-05 21:15 61440]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 05:24 286720]
"SPC500NC_Monitor"="C:\Windows\Philips\SPC500NC\Monitor.exe" [2008-01-20 17:09 319488]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-01-21 22:42 249896]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06 40048]
"00PCTFW"="C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" [2007-09-19 15:27 2483504]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Startup\
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2006-12-14 14:18:59 528384]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2007-03-03 15:24:52 450560]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{D2DB2E45-4DF4-47AD-AE2F-2AB9F1292E38}C:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe"= UDP:C:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe:Logitech Desktop Messenger|Desc=Logitech Desktop Messenger
"UDP Query User{D8A09E2A-5420-4DB2-98C4-25862086CBA5}C:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe"= TCP:C:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe:Logitech Desktop Messenger|Desc=Logitech Desktop Messenger
"TCP Query User{E800720B-AC92-421D-8CC0-0C6DED54FA4D}D:\emule\emule.exe"= UDP:D:\emule\emule.exe:eMule|Desc=eMule
"UDP Query User{3A7A2828-8113-40F1-ADA1-C2132F5A6647}D:\emule\emule.exe"= TCP:D:\emule\emule.exe:eMule|Desc=eMule
"{18617E06-76E5-4282-B201-5C1C391342A0}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{E670E9F6-7CCB-49F1-9ABD-A605DD691FC6}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{8B8A54D0-A47D-43E6-9905-480E28A99232}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{4E12AA0C-ACC4-4C18-A516-0DFDEC5BBEE3}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{73090CB7-B532-4212-99D5-8BCD161D317D}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{CEF4DDD1-D5B3-45AF-8684-3B7BF8F9B425}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{29F5D07F-AA72-4967-B21A-7FB4722DED1D}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{74CB2E61-4221-438E-8A33-CD56A88AECBC}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{7CCB08B9-7286-4EB7-9A9E-2DE13C8681CD}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{302F1AF8-7A51-4BCB-96C9-6868BCFDFE83}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{CF237559-E272-4B9B-8105-A976502B4879}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{A3698AB0-CDB4-427A-9FF2-F542527386CD}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{687AE64B-5A4A-401B-BE87-1E5C8BF0EA9E}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{52963A72-6958-4427-932A-1FEBE6253019}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{1F9D876A-FB8B-4AEB-B86F-1D42C42A8A23}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{3FA83965-A2B0-496E-89E8-A0186004D60D}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{93ABBE35-B905-46FF-BB0F-C8DF68201500}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{143632B5-38C9-4CE6-AF52-B769ACBAD7C4}"= UDP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{0BFE481F-258E-4FB9-8FAF-14CC3BAAD900}"= TCP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{C27FB5FA-4A2F-4DDA-AFD7-BF948C8D5390}"= UDP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{A61614BA-8F85-49FE-A59E-09999F181870}"= TCP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{B661D304-D8F1-4218-B750-F0D8FF5D1867}"= UDP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{83237FEF-AA89-48F7-88F7-D77D1F383007}"= TCP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"TCP Query User{2F8439F9-D3FE-4686-87F4-E51B4ED4296A}C:\users\mac30@hotmail.fr\appdata\local\temp\qztemp\emule.exe"= UDP:C:\users\mac30@hotmail.fr\appdata\local\temp\qztemp\emule.exe:emule.exe|Desc=emule.exe
"UDP Query User{CEE0EA9F-F0BB-42B4-B140-180B81EFCAAC}C:\users\mac30@hotmail.fr\appdata\local\temp\qztemp\emule.exe"= TCP:C:\users\mac30@hotmail.fr\appdata\local\temp\qztemp\emule.exe:emule.exe|Desc=emule.exe
"TCP Query User{98811D98-75D5-40BB-9D9A-7C56D328E182}D:\lphant\elephantclient.exe"= UDP:D:\lphant\elephantclient.exe:lphant Client|Desc=lphant Client
"UDP Query User{75A8E5CB-0D87-46D0-A3B1-7D5789D1ECBA}D:\lphant\elephantclient.exe"= TCP:D:\lphant\elephantclient.exe:lphant Client|Desc=lphant Client
"{24FB3F2C-9EFA-4739-AD13-AB2CF3AB978C}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)|Edge=TRUE|
"{B7811C2D-AF33-4F4F-954E-416D3B551C93}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)|Edge=TRUE|
"{999E9AA4-71FA-4AB3-9D21-20B313FA0B36}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)|Edge=TRUE|
"{DD568884-2F44-4533-A4DB-410716E8A10D}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)|Edge=TRUE|
"{CBD0E49E-28D2-4179-9990-CA902AE10270}"= UDP:D:\LimeWire\LimeWire.exe:LimeWire
"{51C61193-F29A-4F67-AADA-6DDEC953E062}"= TCP:D:\LimeWire\LimeWire.exe:LimeWire
"{CE345439-B060-4BE5-B90B-352A25BF2B52}"= UDP:C:\Program Files\BitTorrent_DNA\dna.exe:DNA
"{9FFB11E5-7ABD-4955-AF83-F574A8AC29D1}"= TCP:C:\Program Files\BitTorrent_DNA\dna.exe:DNA
"{6890988F-A17C-4BC0-858A-A63BE3495D4B}"= UDP:D:\BitTorrent\bittorrent.exe:BitTorrent
"{D68886A8-3F1A-47DB-8AC3-ADC8275438A3}"= TCP:D:\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{341DD81C-6868-4B49-A30F-10E68470D321}D:\adsltv.exe"= UDP:D:\adsltv.exe:adsltv|Desc=adsltv
"UDP Query User{0C8E23AC-5337-4F59-8F73-9D59D99E06A1}D:\adsltv.exe"= TCP:D:\adsltv.exe:adsltv|Desc=adsltv
"{8F29CC60-6695-4D46-89EF-94BCC3F66097}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)|Edge=TRUE|
"{F01724EC-D533-4F58-945A-66B12CEFA812}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"TCP Query User{4CBAC4AC-88BF-4C35-9BA7-060AB81AE142}D:\azureus\azureus.exe"= Disabled:UDP:D:\azureus\azureus.exe:Azureus|Desc=Azureus
"UDP Query User{5CAE9B81-D0FD-464C-BB13-1FA6B3241F78}D:\azureus\azureus.exe"= Disabled:TCP:D:\azureus\azureus.exe:Azureus|Desc=Azureus
"{12A45747-2372-4071-AFC2-797A16389BB3}"= Disabled:UDP:C:\Program Files\Acer Zone\Acer Zone Main Page\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
"{857E81E3-6A25-4038-A976-590002A8FF54}"= Disabled:TCP:C:\Program Files\Acer Zone\Acer Zone Main Page\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
"{B2690F95-1BA9-42B6-8151-D37A873D97E9}"= Disabled:UDP:C:\Program Files\Acer Zone\Acer Picture Slide DVD\Component\CLSLDVD.exe:Cyberlink Picture Slide DVD workprocess
"{BE8168BD-1587-48C9-B8A9-8DA29EB488A4}"= Disabled:TCP:C:\Program Files\Acer Zone\Acer Picture Slide DVD\Component\CLSLDVD.exe:Cyberlink Picture Slide DVD workprocess
"{97A20D34-D5EB-42F9-8D75-7772B1CAAAB2}"= Disabled:UDP:C:\Program Files\Acer Zone\Acer Plug and Record\Component\ARAWP.exe:Cyberlink Plug and Record ARA workprocess
"{8FFFA071-A90B-466D-AAC6-D07DB72C5A9C}"= Disabled:TCP:C:\Program Files\Acer Zone\Acer Plug and Record\Component\ARAWP.exe:Cyberlink Plug and Record ARA workprocess
"{FBB2CD35-5498-46F4-8829-2DF3885C1C12}"= Disabled:UDP:C:\Program Files\Acer Zone\Acer Plug and Record\Component\DVAX2Process.exe:Cyberlink Plug and Record AVAX workprocess
"{0035BDE0-2E3C-476E-9D74-C9778E365572}"= Disabled:TCP:C:\Program Files\Acer Zone\Acer Plug and Record\Component\DVAX2Process.exe:Cyberlink Plug and Record AVAX workprocess
"{2C7749D8-584C-471D-AEFF-C677570CEC98}"= Disabled:UDP:C:\Program Files\Acer Zone\Acer Zone SoftDMA\SoftDMA.exe:CyberLink SoftDMA
"{6C2ADED2-5CD6-425A-A80E-00AA1D08D67B}"= Disabled:TCP:C:\Program Files\Acer Zone\Acer Zone SoftDMA\SoftDMA.exe:CyberLink SoftDMA
"{29278D60-0D80-4A89-8D19-3FAAAEB8CAB1}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"D:\BitTorrent\bittorrent.exe"= D:\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R1 pctfw2;pctfw2;C:\Windows\system32\drivers\pctfw2.sys [2007-09-19 15:26]
R1 pctmp;PC Tools Firewall Memory Protection Driver;C:\Windows\system32\drivers\pctmp.sys [2007-09-19 15:26]
R1 pctssipc;PC Tools Security Suite IPC Driver;C:\Windows\system32\drivers\pctssipc.sys [2007-09-19 15:26]
R3 SPC500NC;SPC 500NC Laptop Camera;C:\Windows\system32\DRIVERS\SPC610NC.SYS [2007-01-19 16:14]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-09 02:52]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;C:\Windows\system32\DRIVERS\fbxusb32.sys [2004-10-20 14:23]
S3 WSVD;WSVD;C:\Windows\system32\drivers\WSVD.sys [2006-09-19 16:47]
S3 ZSMC0305;A4 TECH PC Camera V;C:\Windows\system32\Drivers\usbVM305.sys [2006-05-08 16:24]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20714440-70d1-11dc-96e1-0007cb0000ff}]
\shell\Auto\command - cmd /C launch.bat
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL cmd /C launch.bat
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-26 20:58:30
Windows 6.0.6000 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\PC Tools Firewall Plus\FWService.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\ehome\ehmsas.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
.
**************************************************************************
.
Temps d'accomplissement: 2008-02-26 21:01:01 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-26 20:00:56
.
2008-02-26 19:38:26 --- E O F ---
Re ,
Ouvre le Bloc-Notes (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
Copie ce texte ( en gras )d'une traite ( CTRL+C pour copier ) puis colle-le ( CTRL+V dans le bloc-note )
Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"????r"=-
"?????????"=-
Sauvegarde ce fichier sur ton bureau sous le nom de CFScript.txt.
Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :
http://serveur1.archive-host.com/membres/up/1366464061/CFScript.gif
Cela va relancer Combofix,
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.
S'il n'y a pas de rédémarrage, poste quand même les rapports.
*****************************************************
1)Va dans ' poste de travail ' > ' Outil ' > ' Options des dossiers ' > Onglet ' Affichage '
2)Active le bouton ' Afficher les fichiers et dossiers cachés '
3)Décoche ' Masquer les fichiers protégés du systeme d'exploitation ( recommandé ) '
4)Décoche ' Masquer les extensions dont le type est connu '
5)Va sur ce site --> https://www.virustotal.com/gui/
Clique sur ' parcourir '
Cherche ce fichier : ( mis en gras )
C:\Windows\system32\SysMonitor.exe
Clique sur ' send '
Un rapport va s'élaborer ligne à ligne.
Attends la fin. Il doit comprendre la taille du fichier envoyé.
Sauvegarde le rapport avec le bloc-note.
-> Poste le moi stp.
*************
Puis va sur ce site : http://virusscan.jotti.org/de/
Et fait analyser le même fichier -> poste le rapport.
*****
A+
( 3 rapports )
Ouvre le Bloc-Notes (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
Copie ce texte ( en gras )d'une traite ( CTRL+C pour copier ) puis colle-le ( CTRL+V dans le bloc-note )
Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"????r"=-
"?????????"=-
Sauvegarde ce fichier sur ton bureau sous le nom de CFScript.txt.
Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :
http://serveur1.archive-host.com/membres/up/1366464061/CFScript.gif
Cela va relancer Combofix,
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.
S'il n'y a pas de rédémarrage, poste quand même les rapports.
*****************************************************
1)Va dans ' poste de travail ' > ' Outil ' > ' Options des dossiers ' > Onglet ' Affichage '
2)Active le bouton ' Afficher les fichiers et dossiers cachés '
3)Décoche ' Masquer les fichiers protégés du systeme d'exploitation ( recommandé ) '
4)Décoche ' Masquer les extensions dont le type est connu '
5)Va sur ce site --> https://www.virustotal.com/gui/
Clique sur ' parcourir '
Cherche ce fichier : ( mis en gras )
C:\Windows\system32\SysMonitor.exe
Clique sur ' send '
Un rapport va s'élaborer ligne à ligne.
Attends la fin. Il doit comprendre la taille du fichier envoyé.
Sauvegarde le rapport avec le bloc-note.
-> Poste le moi stp.
*************
Puis va sur ce site : http://virusscan.jotti.org/de/
Et fait analyser le même fichier -> poste le rapport.
*****
A+
( 3 rapports )
Re,
C'est tout de même de l'inconscience exagérée.
Hello cyrildu17,
Eh bien! Il y a encore du boulot.
Je repasserai d'ici 1 mois ....
Bonne continuation
Al.
C'est tout de même de l'inconscience exagérée.
Hello cyrildu17,
Eh bien! Il y a encore du boulot.
Je repasserai d'ici 1 mois ....
Bonne continuation
Al.
j'ai suivi t instruction mais dans la fenêtre bleu je nai pas sa : "Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide. "
il me sort une fenêtre limite de garantie.
PS: vous me faite flipper tous les 2 je croyais que mon probleme etait résolu moi !!
il me sort une fenêtre limite de garantie.
PS: vous me faite flipper tous les 2 je croyais que mon probleme etait résolu moi !!
voici le message :
un guide d'utilisation de combofix adéquate se trouve ici :
https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
__________________________________________________
Cet outi a été crée pour un usage privé. il ne doit jamais être utilisé sans supervision. Si des imperfections sont identifiés, l'outil redemerrera automatiquement windows pour compléter le processus de suppression. Merci de vous assurer que toutes les fenêtres soit bien fermé avant de procéder.
_____________________________________________________
Le programme vous est proposé "telquel", sans aucune garantie.
Toutes garantie implicites sont exclue.
Si vous n'accepter les termes ci-dessus, merci de cliquer sur no pour quitter.
oui non
un guide d'utilisation de combofix adéquate se trouve ici :
https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
__________________________________________________
Cet outi a été crée pour un usage privé. il ne doit jamais être utilisé sans supervision. Si des imperfections sont identifiés, l'outil redemerrera automatiquement windows pour compléter le processus de suppression. Merci de vous assurer que toutes les fenêtres soit bien fermé avant de procéder.
_____________________________________________________
Le programme vous est proposé "telquel", sans aucune garantie.
Toutes garantie implicites sont exclue.
Si vous n'accepter les termes ci-dessus, merci de cliquer sur no pour quitter.
oui non
voici le premier rapportvoici le premier rapport
ComboFix 08-02-25.3 - mac30@hotmail.fr 2008-02-26 22:11:29.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.208 [GMT 1:00]
Endroit: C:\Users\mac30@hotmail.fr\Desktop\ComboFix.exe
Command switches used :: C:\Users\mac30@hotmail.fr\Desktop\CFScript.txt..txt
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\system32\koos.exe
C:\Windows\system32\kprof
C:\Windows\system32\poof
.
---- Previous Run -------
.
C:\Windows\system32\koos.exe
C:\Windows\system32\kprof
C:\Windows\system32\poof
.
((((((((((((((((((((((((((((( Fichiers créés 2008-01-26 to 2008-02-26 ))))))))))))))))))))))))))))))))))))
.
2008-02-26 21:37 . 2008-02-26 21:40 <REP> d-------- C:\ComboFix[1]
2008-02-26 20:14 . 2007-09-19 15:26 195,928 --a------ C:\Windows\System32\drivers\pctfw2.sys
2008-02-26 20:14 . 2007-09-19 15:26 114,008 --a------ C:\Windows\System32\drivers\pctfw.sys
2008-02-26 20:13 . 2008-02-26 20:17 <REP> d-------- C:\Program Files\PC Tools Firewall Plus
2008-02-26 20:13 . 2008-02-26 20:13 <REP> d-------- C:\Program Files\Common Files\PC Tools
2008-02-26 20:13 . 2007-09-19 15:26 39,768 --a------ C:\Windows\System32\drivers\pctmp.sys
2008-02-26 20:13 . 2007-09-19 15:26 17,752 --a------ C:\Windows\System32\drivers\pctssipc.sys
2008-02-26 18:29 . 2008-02-26 18:42 <REP> d-------- C:\Program Files\Windows Live
2008-02-22 16:37 . 2008-02-22 16:37 <REP> d-------- C:\Users\mac30@hotmail.fr\AppData\Roaming\Media Player Classic
2008-02-18 15:14 . 2008-02-18 15:15 <REP> d-------- C:\Program Files\Windows Live Safety Center
2008-02-14 09:56 . 2008-02-14 09:56 194,560 --a------ C:\Windows\System32\WebClnt.dll
2008-02-14 09:56 . 2008-02-14 09:56 110,080 --a------ C:\Windows\System32\drivers\mrxdav.sys
2008-02-14 09:52 . 2008-02-14 09:52 803,328 --a------ C:\Windows\System32\drivers\tcpip.sys
2008-02-14 09:52 . 2008-02-14 09:52 216,632 --a------ C:\Windows\System32\drivers\netio.sys
2008-02-14 09:52 . 2008-02-14 09:52 167,424 --a------ C:\Windows\System32\tcpipcfg.dll
2008-02-14 09:52 . 2008-02-14 09:52 24,064 --a------ C:\Windows\System32\netcfg.exe
2008-02-14 09:52 . 2008-02-14 09:52 22,016 --a------ C:\Windows\System32\netiougc.exe
2008-02-01 21:57 . 2008-02-01 21:57 244 --ah----- C:\sqmnoopt05.sqm
2008-02-01 21:57 . 2008-02-01 21:57 232 --ah----- C:\sqmdata05.sqm
2008-02-01 21:53 . 2008-02-01 21:53 244 --ah----- C:\sqmnoopt04.sqm
2008-02-01 21:53 . 2008-02-01 21:53 232 --ah----- C:\sqmdata04.sqm
2008-02-01 21:30 . 2008-02-01 21:30 244 --ah----- C:\sqmnoopt03.sqm
2008-02-01 21:30 . 2008-02-01 21:30 232 --ah----- C:\sqmdata03.sqm
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-26 19:38 --------- d-----w C:\PROGRA~2\Microsoft Help
2008-02-26 17:36 --------- d-----w C:\PROGRA~2\WLInstaller
2008-02-14 08:55 54,784 ----a-w C:\Windows\system32\drivers\i8042prt.sys
2008-02-14 08:55 495,160 ----a-w C:\Windows\system32\drivers\Wdf01000.sys
2008-02-14 08:55 35,384 ----a-w C:\Windows\system32\drivers\WdfLdr.sys
2008-02-14 08:55 35,384 ----a-w C:\Windows\system32\drivers\kbdclass.sys
2008-02-14 08:55 34,360 ----a-w C:\Windows\system32\drivers\mouclass.sys
2008-02-14 08:55 19,968 ----a-w C:\Windows\system32\drivers\sermouse.sys
2008-02-14 08:55 15,872 ----a-w C:\Windows\system32\drivers\mouhid.sys
2008-02-14 08:55 15,872 ----a-w C:\Windows\system32\drivers\kbdhid.sys
2008-02-14 08:49 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-01-23 18:49 --------- d-----w C:\Users\mac30@hotmail.fr\AppData\Roaming\CyberLink
2008-01-23 18:49 --------- d-----w C:\PROGRA~2\CyberLink
2008-01-23 08:35 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-22 17:17 --------- d-----w C:\Program Files\Lavasoft
2008-01-22 12:34 --------- d-----w C:\PROGRA~2\Spybot - Search & Destroy
2008-01-22 11:47 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-01-21 21:41 --------- d-----w C:\Program Files\Avira
2008-01-21 21:41 --------- d-----w C:\PROGRA~2\Avira
2008-01-21 18:40 --------- d-----w C:\PROGRA~2\F-Secure
2008-01-20 16:57 --------- d-----w C:\Users\mac30@hotmail.fr\AppData\Roaming\F-Secure
2008-01-20 16:45 --------- d-----w C:\PROGRA~2\fssg
2008-01-20 15:40 --------- d-----w C:\Program Files\CCleaner
2008-01-20 11:27 --------- d-----w C:\Program Files\MSN Messenger
2008-01-20 11:10 --------- d-----w C:\PROGRA~2\WindowsLiveInstaller
2008-01-19 21:38 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-19 09:46 --------- d-----w C:\PROGRA~2\ashampoo
2008-01-19 09:26 47,360 ----a-w C:\Users\mac30@hotmail.fr\AppData\Roaming\pcouffin.sys
2008-01-19 09:26 --------- d-----w C:\Users\mac30@hotmail.fr\AppData\Roaming\Vso
2008-01-19 09:23 47,360 ----a-w C:\Windows\system32\drivers\pcouffin.sys
2008-01-13 10:53 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-10 18:07 --------- d-----w C:\Users\mac30@hotmail.fr\AppData\Roaming\GrabIt
2008-01-09 22:12 --------- d-----w C:\Program Files\Windows Sidebar
2007-12-29 20:42 --------- d-----w C:\Users\mac30@hotmail.fr\AppData\Roaming\vlc
2007-12-29 19:32 --------- d-----w C:\Program Files\Free.fr
2006-11-02 12:50 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-09 23:12 1232896]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35 125440]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [ ]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 15:30 249856]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [ ]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
"ares"="D:\Ares\Ares.exe" [2007-12-31 15:29 962560]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 13:36 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-04-13 10:16 1006264]
"RtHDVCpl"="RtHDVCpl.exe" [2006-11-09 03:57 3784704 C:\Windows\RtHDVCpl.exe]
"Acer Tour"="" []
"Acer Empowering Technology Monitor"="C:\Windows\system32\SysMonitor.exe" [2006-11-23 15:24 319488]
"WarReg_PopUp"="C:\Acer\WR_PopUp\WarReg_PopUp.exe" [ ]
"eRecoveryService"="" []
"BigDog305"="C:\Windows\VM305_STI.exe" [2005-08-05 21:15 61440]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 05:24 286720]
"SPC500NC_Monitor"="C:\Windows\Philips\SPC500NC\Monitor.exe" [2008-01-20 17:09 319488]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-01-21 22:42 249896]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06 40048]
"00PCTFW"="C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" [2007-09-19 15:27 2483504]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Startup\
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2006-12-14 14:18:59 528384]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2007-03-03 15:24:52 450560]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{D2DB2E45-4DF4-47AD-AE2F-2AB9F1292E38}C:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe"= UDP:C:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe:Logitech Desktop Messenger|Desc=Logitech Desktop Messenger
"UDP Query User{D8A09E2A-5420-4DB2-98C4-25862086CBA5}C:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe"= TCP:C:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe:Logitech Desktop Messenger|Desc=Logitech Desktop Messenger
"TCP Query User{E800720B-AC92-421D-8CC0-0C6DED54FA4D}D:\emule\emule.exe"= UDP:D:\emule\emule.exe:eMule|Desc=eMule
"UDP Query User{3A7A2828-8113-40F1-ADA1-C2132F5A6647}D:\emule\emule.exe"= TCP:D:\emule\emule.exe:eMule|Desc=eMule
"{18617E06-76E5-4282-B201-5C1C391342A0}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{E670E9F6-7CCB-49F1-9ABD-A605DD691FC6}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{8B8A54D0-A47D-43E6-9905-480E28A99232}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{4E12AA0C-ACC4-4C18-A516-0DFDEC5BBEE3}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{73090CB7-B532-4212-99D5-8BCD161D317D}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{CEF4DDD1-D5B3-45AF-8684-3B7BF8F9B425}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{29F5D07F-AA72-4967-B21A-7FB4722DED1D}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{74CB2E61-4221-438E-8A33-CD56A88AECBC}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{7CCB08B9-7286-4EB7-9A9E-2DE13C8681CD}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{302F1AF8-7A51-4BCB-96C9-6868BCFDFE83}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{CF237559-E272-4B9B-8105-A976502B4879}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{A3698AB0-CDB4-427A-9FF2-F542527386CD}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{687AE64B-5A4A-401B-BE87-1E5C8BF0EA9E}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{52963A72-6958-4427-932A-1FEBE6253019}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{1F9D876A-FB8B-4AEB-B86F-1D42C42A8A23}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{3FA83965-A2B0-496E-89E8-A0186004D60D}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{93ABBE35-B905-46FF-BB0F-C8DF68201500}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{143632B5-38C9-4CE6-AF52-B769ACBAD7C4}"= UDP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{0BFE481F-258E-4FB9-8FAF-14CC3BAAD900}"= TCP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{C27FB5FA-4A2F-4DDA-AFD7-BF948C8D5390}"= UDP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{A61614BA-8F85-49FE-A59E-09999F181870}"= TCP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{B661D304-D8F1-4218-B750-F0D8FF5D1867}"= UDP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{83237FEF-AA89-48F7-88F7-D77D1F383007}"= TCP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"TCP Query User{2F8439F9-D3FE-4686-87F4-E51B4ED4296A}C:\users\mac30@hotmail.fr\appdata\local\temp\qztemp\emule.exe"= UDP:C:\users\mac30@hotmail.fr\appdata\local\temp\qztemp\emule.exe:emule.exe|Desc=emule.exe
"UDP Query User{CEE0EA9F-F0BB-42B4-B140-180B81EFCAAC}C:\users\mac30@hotmail.fr\appdata\local\temp\qztemp\emule.exe"= TCP:C:\users\mac30@hotmail.fr\appdata\local\temp\qztemp\emule.exe:emule.exe|Desc=emule.exe
"TCP Query User{98811D98-75D5-40BB-9D9A-7C56D328E182}D:\lphant\elephantclient.exe"= UDP:D:\lphant\elephantclient.exe:lphant Client|Desc=lphant Client
"UDP Query User{75A8E5CB-0D87-46D0-A3B1-7D5789D1ECBA}D:\lphant\elephantclient.exe"= TCP:D:\lphant\elephantclient.exe:lphant Client|Desc=lphant Client
"{24FB3F2C-9EFA-4739-AD13-AB2CF3AB978C}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)|Edge=TRUE|
"{B7811C2D-AF33-4F4F-954E-416D3B551C93}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)|Edge=TRUE|
"{999E9AA4-71FA-4AB3-9D21-20B313FA0B36}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)|Edge=TRUE|
"{DD568884-2F44-4533-A4DB-410716E8A10D}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)|Edge=TRUE|
"{CBD0E49E-28D2-4179-9990-CA902AE10270}"= UDP:D:\LimeWire\LimeWire.exe:LimeWire
"{51C61193-F29A-4F67-AADA-6DDEC953E062}"= TCP:D:\LimeWire\LimeWire.exe:LimeWire
"{CE345439-B060-4BE5-B90B-352A25BF2B52}"= UDP:C:\Program Files\BitTorrent_DNA\dna.exe:DNA
"{9FFB11E5-7ABD-4955-AF83-F574A8AC29D1}"= TCP:C:\Program Files\BitTorrent_DNA\dna.exe:DNA
"{6890988F-A17C-4BC0-858A-A63BE3495D4B}"= UDP:D:\BitTorrent\bittorrent.exe:BitTorrent
"{D68886A8-3F1A-47DB-8AC3-ADC8275438A3}"= TCP:D:\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{341DD81C-6868-4B49-A30F-10E68470D321}D:\adsltv.exe"= UDP:D:\adsltv.exe:adsltv|Desc=adsltv
"UDP Query User{0C8E23AC-5337-4F59-8F73-9D59D99E06A1}D:\adsltv.exe"= TCP:D:\adsltv.exe:adsltv|Desc=adsltv
"{8F29CC60-6695-4D46-89EF-94BCC3F66097}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)|Edge=TRUE|
"{F01724EC-D533-4F58-945A-66B12CEFA812}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"TCP Query User{4CBAC4AC-88BF-4C35-9BA7-060AB81AE142}D:\azureus\azureus.exe"= Disabled:UDP:D:\azureus\azureus.exe:Azureus|Desc=Azureus
"UDP Query User{5CAE9B81-D0FD-464C-BB13-1FA6B3241F78}D:\azureus\azureus.exe"= Disabled:TCP:D:\azureus\azureus.exe:Azureus|Desc=Azureus
"{12A45747-2372-4071-AFC2-797A16389BB3}"= Disabled:UDP:C:\Program Files\Acer Zone\Acer Zone Main Page\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
"{857E81E3-6A25-4038-A976-590002A8FF54}"= Disabled:TCP:C:\Program Files\Acer Zone\Acer Zone Main Page\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
"{B2690F95-1BA9-42B6-8151-D37A873D97E9}"= Disabled:UDP:C:\Program Files\Acer Zone\Acer Picture Slide DVD\Component\CLSLDVD.exe:Cyberlink Picture Slide DVD workprocess
"{BE8168BD-1587-48C9-B8A9-8DA29EB488A4}"= Disabled:TCP:C:\Program Files\Acer Zone\Acer Picture Slide DVD\Component\CLSLDVD.exe:Cyberlink Picture Slide DVD workprocess
"{97A20D34-D5EB-42F9-8D75-7772B1CAAAB2}"= Disabled:UDP:C:\Program Files\Acer Zone\Acer Plug and Record\Component\ARAWP.exe:Cyberlink Plug and Record ARA workprocess
"{8FFFA071-A90B-466D-AAC6-D07DB72C5A9C}"= Disabled:TCP:C:\Program Files\Acer Zone\Acer Plug and Record\Component\ARAWP.exe:Cyberlink Plug and Record ARA workprocess
"{FBB2CD35-5498-46F4-8829-2DF3885C1C12}"= Disabled:UDP:C:\Program Files\Acer Zone\Acer Plug and Record\Component\DVAX2Process.exe:Cyberlink Plug and Record AVAX workprocess
"{0035BDE0-2E3C-476E-9D74-C9778E365572}"= Disabled:TCP:C:\Program Files\Acer Zone\Acer Plug and Record\Component\DVAX2Process.exe:Cyberlink Plug and Record AVAX workprocess
"{2C7749D8-584C-471D-AEFF-C677570CEC98}"= Disabled:UDP:C:\Program Files\Acer Zone\Acer Zone SoftDMA\SoftDMA.exe:CyberLink SoftDMA
"{6C2ADED2-5CD6-425A-A80E-00AA1D08D67B}"= Disabled:TCP:C:\Program Files\Acer Zone\Acer Zone SoftDMA\SoftDMA.exe:CyberLink SoftDMA
"{29278D60-0D80-4A89-8D19-3FAAAEB8CAB1}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"D:\BitTorrent\bittorrent.exe"= D:\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R1 pctfw2;pctfw2;C:\Windows\system32\drivers\pctfw2.sys [2007-09-19 15:26]
R1 pctmp;PC Tools Firewall Memory Protection Driver;C:\Windows\system32\drivers\pctmp.sys [2007-09-19 15:26]
R1 pctssipc;PC Tools Security Suite IPC Driver;C:\Windows\system32\drivers\pctssipc.sys [2007-09-19 15:26]
R3 SPC500NC;SPC 500NC Laptop Camera;C:\Windows\system32\DRIVERS\SPC610NC.SYS [2007-01-19 16:14]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-09 02:52]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;C:\Windows\system32\DRIVERS\fbxusb32.sys [2004-10-20 14:23]
S3 WSVD;WSVD;C:\Windows\system32\drivers\WSVD.sys [2006-09-19 16:47]
S3 ZSMC0305;A4 TECH PC Camera V;C:\Windows\system32\Drivers\usbVM305.sys [2006-05-08 16:24]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20714440-70d1-11dc-96e1-0007cb0000ff}]
\shell\Auto\command - cmd /C launch.bat
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL cmd /C launch.bat
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-26 22:18:41
Windows 6.0.6000 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\PC Tools Firewall Plus\FWService.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\conime.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Windows\ehome\ehmsas.exe
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
.
**************************************************************************
.
Temps d'accomplissement: 2008-02-26 22:20:59 - machine was rebooted [mac30@hotmail.fr]
ComboFix-quarantined-files.txt 2008-02-26 21:20:54
ComboFix2.txt 2008-02-26 20:01:01
.
2008-02-26 19:38:26 --- E O F ---
ComboFix 08-02-25.3 - mac30@hotmail.fr 2008-02-26 22:11:29.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.208 [GMT 1:00]
Endroit: C:\Users\mac30@hotmail.fr\Desktop\ComboFix.exe
Command switches used :: C:\Users\mac30@hotmail.fr\Desktop\CFScript.txt..txt
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\system32\koos.exe
C:\Windows\system32\kprof
C:\Windows\system32\poof
.
---- Previous Run -------
.
C:\Windows\system32\koos.exe
C:\Windows\system32\kprof
C:\Windows\system32\poof
.
((((((((((((((((((((((((((((( Fichiers créés 2008-01-26 to 2008-02-26 ))))))))))))))))))))))))))))))))))))
.
2008-02-26 21:37 . 2008-02-26 21:40 <REP> d-------- C:\ComboFix[1]
2008-02-26 20:14 . 2007-09-19 15:26 195,928 --a------ C:\Windows\System32\drivers\pctfw2.sys
2008-02-26 20:14 . 2007-09-19 15:26 114,008 --a------ C:\Windows\System32\drivers\pctfw.sys
2008-02-26 20:13 . 2008-02-26 20:17 <REP> d-------- C:\Program Files\PC Tools Firewall Plus
2008-02-26 20:13 . 2008-02-26 20:13 <REP> d-------- C:\Program Files\Common Files\PC Tools
2008-02-26 20:13 . 2007-09-19 15:26 39,768 --a------ C:\Windows\System32\drivers\pctmp.sys
2008-02-26 20:13 . 2007-09-19 15:26 17,752 --a------ C:\Windows\System32\drivers\pctssipc.sys
2008-02-26 18:29 . 2008-02-26 18:42 <REP> d-------- C:\Program Files\Windows Live
2008-02-22 16:37 . 2008-02-22 16:37 <REP> d-------- C:\Users\mac30@hotmail.fr\AppData\Roaming\Media Player Classic
2008-02-18 15:14 . 2008-02-18 15:15 <REP> d-------- C:\Program Files\Windows Live Safety Center
2008-02-14 09:56 . 2008-02-14 09:56 194,560 --a------ C:\Windows\System32\WebClnt.dll
2008-02-14 09:56 . 2008-02-14 09:56 110,080 --a------ C:\Windows\System32\drivers\mrxdav.sys
2008-02-14 09:52 . 2008-02-14 09:52 803,328 --a------ C:\Windows\System32\drivers\tcpip.sys
2008-02-14 09:52 . 2008-02-14 09:52 216,632 --a------ C:\Windows\System32\drivers\netio.sys
2008-02-14 09:52 . 2008-02-14 09:52 167,424 --a------ C:\Windows\System32\tcpipcfg.dll
2008-02-14 09:52 . 2008-02-14 09:52 24,064 --a------ C:\Windows\System32\netcfg.exe
2008-02-14 09:52 . 2008-02-14 09:52 22,016 --a------ C:\Windows\System32\netiougc.exe
2008-02-01 21:57 . 2008-02-01 21:57 244 --ah----- C:\sqmnoopt05.sqm
2008-02-01 21:57 . 2008-02-01 21:57 232 --ah----- C:\sqmdata05.sqm
2008-02-01 21:53 . 2008-02-01 21:53 244 --ah----- C:\sqmnoopt04.sqm
2008-02-01 21:53 . 2008-02-01 21:53 232 --ah----- C:\sqmdata04.sqm
2008-02-01 21:30 . 2008-02-01 21:30 244 --ah----- C:\sqmnoopt03.sqm
2008-02-01 21:30 . 2008-02-01 21:30 232 --ah----- C:\sqmdata03.sqm
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-26 19:38 --------- d-----w C:\PROGRA~2\Microsoft Help
2008-02-26 17:36 --------- d-----w C:\PROGRA~2\WLInstaller
2008-02-14 08:55 54,784 ----a-w C:\Windows\system32\drivers\i8042prt.sys
2008-02-14 08:55 495,160 ----a-w C:\Windows\system32\drivers\Wdf01000.sys
2008-02-14 08:55 35,384 ----a-w C:\Windows\system32\drivers\WdfLdr.sys
2008-02-14 08:55 35,384 ----a-w C:\Windows\system32\drivers\kbdclass.sys
2008-02-14 08:55 34,360 ----a-w C:\Windows\system32\drivers\mouclass.sys
2008-02-14 08:55 19,968 ----a-w C:\Windows\system32\drivers\sermouse.sys
2008-02-14 08:55 15,872 ----a-w C:\Windows\system32\drivers\mouhid.sys
2008-02-14 08:55 15,872 ----a-w C:\Windows\system32\drivers\kbdhid.sys
2008-02-14 08:49 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-01-23 18:49 --------- d-----w C:\Users\mac30@hotmail.fr\AppData\Roaming\CyberLink
2008-01-23 18:49 --------- d-----w C:\PROGRA~2\CyberLink
2008-01-23 08:35 --------- d-----w C:\Program Files\Common Files\Adobe
2008-01-22 17:17 --------- d-----w C:\Program Files\Lavasoft
2008-01-22 12:34 --------- d-----w C:\PROGRA~2\Spybot - Search & Destroy
2008-01-22 11:47 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-01-21 21:41 --------- d-----w C:\Program Files\Avira
2008-01-21 21:41 --------- d-----w C:\PROGRA~2\Avira
2008-01-21 18:40 --------- d-----w C:\PROGRA~2\F-Secure
2008-01-20 16:57 --------- d-----w C:\Users\mac30@hotmail.fr\AppData\Roaming\F-Secure
2008-01-20 16:45 --------- d-----w C:\PROGRA~2\fssg
2008-01-20 15:40 --------- d-----w C:\Program Files\CCleaner
2008-01-20 11:27 --------- d-----w C:\Program Files\MSN Messenger
2008-01-20 11:10 --------- d-----w C:\PROGRA~2\WindowsLiveInstaller
2008-01-19 21:38 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-01-19 09:46 --------- d-----w C:\PROGRA~2\ashampoo
2008-01-19 09:26 47,360 ----a-w C:\Users\mac30@hotmail.fr\AppData\Roaming\pcouffin.sys
2008-01-19 09:26 --------- d-----w C:\Users\mac30@hotmail.fr\AppData\Roaming\Vso
2008-01-19 09:23 47,360 ----a-w C:\Windows\system32\drivers\pcouffin.sys
2008-01-13 10:53 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-10 18:07 --------- d-----w C:\Users\mac30@hotmail.fr\AppData\Roaming\GrabIt
2008-01-09 22:12 --------- d-----w C:\Program Files\Windows Sidebar
2007-12-29 20:42 --------- d-----w C:\Users\mac30@hotmail.fr\AppData\Roaming\vlc
2007-12-29 19:32 --------- d-----w C:\Program Files\Free.fr
2006-11-02 12:50 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-09 23:12 1232896]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35 125440]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [ ]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 15:30 249856]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [ ]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
"ares"="D:\Ares\Ares.exe" [2007-12-31 15:29 962560]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 13:36 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-04-13 10:16 1006264]
"RtHDVCpl"="RtHDVCpl.exe" [2006-11-09 03:57 3784704 C:\Windows\RtHDVCpl.exe]
"Acer Tour"="" []
"Acer Empowering Technology Monitor"="C:\Windows\system32\SysMonitor.exe" [2006-11-23 15:24 319488]
"WarReg_PopUp"="C:\Acer\WR_PopUp\WarReg_PopUp.exe" [ ]
"eRecoveryService"="" []
"BigDog305"="C:\Windows\VM305_STI.exe" [2005-08-05 21:15 61440]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 05:24 286720]
"SPC500NC_Monitor"="C:\Windows\Philips\SPC500NC\Monitor.exe" [2008-01-20 17:09 319488]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-01-21 22:42 249896]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06 40048]
"00PCTFW"="C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" [2007-09-19 15:27 2483504]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Startup\
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2006-12-14 14:18:59 528384]
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2007-03-03 15:24:52 450560]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{D2DB2E45-4DF4-47AD-AE2F-2AB9F1292E38}C:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe"= UDP:C:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe:Logitech Desktop Messenger|Desc=Logitech Desktop Messenger
"UDP Query User{D8A09E2A-5420-4DB2-98C4-25862086CBA5}C:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe"= TCP:C:\program files\logitech\desktop messenger\8876480\program\backweb-8876480.exe:Logitech Desktop Messenger|Desc=Logitech Desktop Messenger
"TCP Query User{E800720B-AC92-421D-8CC0-0C6DED54FA4D}D:\emule\emule.exe"= UDP:D:\emule\emule.exe:eMule|Desc=eMule
"UDP Query User{3A7A2828-8113-40F1-ADA1-C2132F5A6647}D:\emule\emule.exe"= TCP:D:\emule\emule.exe:eMule|Desc=eMule
"{18617E06-76E5-4282-B201-5C1C391342A0}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{E670E9F6-7CCB-49F1-9ABD-A605DD691FC6}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{8B8A54D0-A47D-43E6-9905-480E28A99232}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{4E12AA0C-ACC4-4C18-A516-0DFDEC5BBEE3}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{73090CB7-B532-4212-99D5-8BCD161D317D}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{CEF4DDD1-D5B3-45AF-8684-3B7BF8F9B425}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{29F5D07F-AA72-4967-B21A-7FB4722DED1D}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{74CB2E61-4221-438E-8A33-CD56A88AECBC}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{7CCB08B9-7286-4EB7-9A9E-2DE13C8681CD}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{302F1AF8-7A51-4BCB-96C9-6868BCFDFE83}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{CF237559-E272-4B9B-8105-A976502B4879}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{A3698AB0-CDB4-427A-9FF2-F542527386CD}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{687AE64B-5A4A-401B-BE87-1E5C8BF0EA9E}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{52963A72-6958-4427-932A-1FEBE6253019}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{1F9D876A-FB8B-4AEB-B86F-1D42C42A8A23}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{3FA83965-A2B0-496E-89E8-A0186004D60D}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{93ABBE35-B905-46FF-BB0F-C8DF68201500}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"{143632B5-38C9-4CE6-AF52-B769ACBAD7C4}"= UDP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{0BFE481F-258E-4FB9-8FAF-14CC3BAAD900}"= TCP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{C27FB5FA-4A2F-4DDA-AFD7-BF948C8D5390}"= UDP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{A61614BA-8F85-49FE-A59E-09999F181870}"= TCP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{B661D304-D8F1-4218-B750-F0D8FF5D1867}"= UDP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{83237FEF-AA89-48F7-88F7-D77D1F383007}"= TCP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"TCP Query User{2F8439F9-D3FE-4686-87F4-E51B4ED4296A}C:\users\mac30@hotmail.fr\appdata\local\temp\qztemp\emule.exe"= UDP:C:\users\mac30@hotmail.fr\appdata\local\temp\qztemp\emule.exe:emule.exe|Desc=emule.exe
"UDP Query User{CEE0EA9F-F0BB-42B4-B140-180B81EFCAAC}C:\users\mac30@hotmail.fr\appdata\local\temp\qztemp\emule.exe"= TCP:C:\users\mac30@hotmail.fr\appdata\local\temp\qztemp\emule.exe:emule.exe|Desc=emule.exe
"TCP Query User{98811D98-75D5-40BB-9D9A-7C56D328E182}D:\lphant\elephantclient.exe"= UDP:D:\lphant\elephantclient.exe:lphant Client|Desc=lphant Client
"UDP Query User{75A8E5CB-0D87-46D0-A3B1-7D5789D1ECBA}D:\lphant\elephantclient.exe"= TCP:D:\lphant\elephantclient.exe:lphant Client|Desc=lphant Client
"{24FB3F2C-9EFA-4739-AD13-AB2CF3AB978C}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)|Edge=TRUE|
"{B7811C2D-AF33-4F4F-954E-416D3B551C93}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)|Edge=TRUE|
"{999E9AA4-71FA-4AB3-9D21-20B313FA0B36}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)|Edge=TRUE|
"{DD568884-2F44-4533-A4DB-410716E8A10D}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)|Edge=TRUE|
"{CBD0E49E-28D2-4179-9990-CA902AE10270}"= UDP:D:\LimeWire\LimeWire.exe:LimeWire
"{51C61193-F29A-4F67-AADA-6DDEC953E062}"= TCP:D:\LimeWire\LimeWire.exe:LimeWire
"{CE345439-B060-4BE5-B90B-352A25BF2B52}"= UDP:C:\Program Files\BitTorrent_DNA\dna.exe:DNA
"{9FFB11E5-7ABD-4955-AF83-F574A8AC29D1}"= TCP:C:\Program Files\BitTorrent_DNA\dna.exe:DNA
"{6890988F-A17C-4BC0-858A-A63BE3495D4B}"= UDP:D:\BitTorrent\bittorrent.exe:BitTorrent
"{D68886A8-3F1A-47DB-8AC3-ADC8275438A3}"= TCP:D:\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{341DD81C-6868-4B49-A30F-10E68470D321}D:\adsltv.exe"= UDP:D:\adsltv.exe:adsltv|Desc=adsltv
"UDP Query User{0C8E23AC-5337-4F59-8F73-9D59D99E06A1}D:\adsltv.exe"= TCP:D:\adsltv.exe:adsltv|Desc=adsltv
"{8F29CC60-6695-4D46-89EF-94BCC3F66097}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)|Edge=TRUE|
"{F01724EC-D533-4F58-945A-66B12CEFA812}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
"TCP Query User{4CBAC4AC-88BF-4C35-9BA7-060AB81AE142}D:\azureus\azureus.exe"= Disabled:UDP:D:\azureus\azureus.exe:Azureus|Desc=Azureus
"UDP Query User{5CAE9B81-D0FD-464C-BB13-1FA6B3241F78}D:\azureus\azureus.exe"= Disabled:TCP:D:\azureus\azureus.exe:Azureus|Desc=Azureus
"{12A45747-2372-4071-AFC2-797A16389BB3}"= Disabled:UDP:C:\Program Files\Acer Zone\Acer Zone Main Page\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
"{857E81E3-6A25-4038-A976-590002A8FF54}"= Disabled:TCP:C:\Program Files\Acer Zone\Acer Zone Main Page\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
"{B2690F95-1BA9-42B6-8151-D37A873D97E9}"= Disabled:UDP:C:\Program Files\Acer Zone\Acer Picture Slide DVD\Component\CLSLDVD.exe:Cyberlink Picture Slide DVD workprocess
"{BE8168BD-1587-48C9-B8A9-8DA29EB488A4}"= Disabled:TCP:C:\Program Files\Acer Zone\Acer Picture Slide DVD\Component\CLSLDVD.exe:Cyberlink Picture Slide DVD workprocess
"{97A20D34-D5EB-42F9-8D75-7772B1CAAAB2}"= Disabled:UDP:C:\Program Files\Acer Zone\Acer Plug and Record\Component\ARAWP.exe:Cyberlink Plug and Record ARA workprocess
"{8FFFA071-A90B-466D-AAC6-D07DB72C5A9C}"= Disabled:TCP:C:\Program Files\Acer Zone\Acer Plug and Record\Component\ARAWP.exe:Cyberlink Plug and Record ARA workprocess
"{FBB2CD35-5498-46F4-8829-2DF3885C1C12}"= Disabled:UDP:C:\Program Files\Acer Zone\Acer Plug and Record\Component\DVAX2Process.exe:Cyberlink Plug and Record AVAX workprocess
"{0035BDE0-2E3C-476E-9D74-C9778E365572}"= Disabled:TCP:C:\Program Files\Acer Zone\Acer Plug and Record\Component\DVAX2Process.exe:Cyberlink Plug and Record AVAX workprocess
"{2C7749D8-584C-471D-AEFF-C677570CEC98}"= Disabled:UDP:C:\Program Files\Acer Zone\Acer Zone SoftDMA\SoftDMA.exe:CyberLink SoftDMA
"{6C2ADED2-5CD6-425A-A80E-00AA1D08D67B}"= Disabled:TCP:C:\Program Files\Acer Zone\Acer Zone SoftDMA\SoftDMA.exe:CyberLink SoftDMA
"{29278D60-0D80-4A89-8D19-3FAAAEB8CAB1}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)|Edge=TRUE|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"D:\BitTorrent\bittorrent.exe"= D:\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R1 pctfw2;pctfw2;C:\Windows\system32\drivers\pctfw2.sys [2007-09-19 15:26]
R1 pctmp;PC Tools Firewall Memory Protection Driver;C:\Windows\system32\drivers\pctmp.sys [2007-09-19 15:26]
R1 pctssipc;PC Tools Security Suite IPC Driver;C:\Windows\system32\drivers\pctssipc.sys [2007-09-19 15:26]
R3 SPC500NC;SPC 500NC Laptop Camera;C:\Windows\system32\DRIVERS\SPC610NC.SYS [2007-01-19 16:14]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-09 02:52]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;C:\Windows\system32\DRIVERS\fbxusb32.sys [2004-10-20 14:23]
S3 WSVD;WSVD;C:\Windows\system32\drivers\WSVD.sys [2006-09-19 16:47]
S3 ZSMC0305;A4 TECH PC Camera V;C:\Windows\system32\Drivers\usbVM305.sys [2006-05-08 16:24]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20714440-70d1-11dc-96e1-0007cb0000ff}]
\shell\Auto\command - cmd /C launch.bat
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL cmd /C launch.bat
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-26 22:18:41
Windows 6.0.6000 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\PC Tools Firewall Plus\FWService.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\conime.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Windows\ehome\ehmsas.exe
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
.
**************************************************************************
.
Temps d'accomplissement: 2008-02-26 22:20:59 - machine was rebooted [mac30@hotmail.fr]
ComboFix-quarantined-files.txt 2008-02-26 21:20:54
ComboFix2.txt 2008-02-26 20:01:01
.
2008-02-26 19:38:26 --- E O F ---
VOICI LE DEUXIEME RAPPORT
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.2.22.0 2008.02.22 -
AntiVir 7.6.0.67 2008.02.22 -
Authentium 4.93.8 2008.02.22 -
Avast 4.7.1098.0 2008.02.22 -
AVG 7.5.0.516 2008.02.22 -
BitDefender 7.2 2008.02.22 -
CAT-QuickHeal 9.50 2008.02.22 -
ClamAV 0.92.1 2008.02.22 -
DrWeb 4.44.0.09170 2008.02.22 -
eSafe 7.0.15.0 2008.02.21 -
eTrust-Vet 31.3.5555 2008.02.22 -
Ewido 4.0 2008.02.22 -
FileAdvisor 1 2008.02.22 -
Fortinet 3.14.0.0 2008.02.22 -
F-Prot 4.4.2.54 2008.02.22 -
F-Secure 6.70.13260.0 2008.02.22 -
Ikarus T3.1.1.20 2008.02.22 -
Kaspersky 7.0.0.125 2008.02.22 -
McAfee 5236 2008.02.22 -
Microsoft 1.3204 2008.02.22 -
NOD32v2 2896 2008.02.22 -
Norman 5.80.02 2008.02.22 -
Panda 9.0.0.4 2008.02.22 -
Prevx1 V2 2008.02.22 -
Rising 20.32.42.00 2008.02.22 -
Sophos 4.26.0 2008.02.22 -
Sunbelt 3.0.890.0 2008.02.22 -
Symantec 10 2008.02.22 -
TheHacker 6.2.9.226 2008.02.22 -
VBA32 3.12.6.1 2008.02.21 -
VirusBuster 4.3.26:9 2008.02.22 -
Webwasher-Gateway 6.6.2 2008.02.22 -
Information additionnelle
File size: 319488 bytes
MD5: 201f07f6e5e08b41b5bcc2ab3d339ecc
SHA1: e5139b16a8fffcce46cb1bb21dc7d01f59b5b3ff
PEiD: -
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.2.22.0 2008.02.22 -
AntiVir 7.6.0.67 2008.02.22 -
Authentium 4.93.8 2008.02.22 -
Avast 4.7.1098.0 2008.02.22 -
AVG 7.5.0.516 2008.02.22 -
BitDefender 7.2 2008.02.22 -
CAT-QuickHeal 9.50 2008.02.22 -
ClamAV 0.92.1 2008.02.22 -
DrWeb 4.44.0.09170 2008.02.22 -
eSafe 7.0.15.0 2008.02.21 -
eTrust-Vet 31.3.5555 2008.02.22 -
Ewido 4.0 2008.02.22 -
FileAdvisor 1 2008.02.22 -
Fortinet 3.14.0.0 2008.02.22 -
F-Prot 4.4.2.54 2008.02.22 -
F-Secure 6.70.13260.0 2008.02.22 -
Ikarus T3.1.1.20 2008.02.22 -
Kaspersky 7.0.0.125 2008.02.22 -
McAfee 5236 2008.02.22 -
Microsoft 1.3204 2008.02.22 -
NOD32v2 2896 2008.02.22 -
Norman 5.80.02 2008.02.22 -
Panda 9.0.0.4 2008.02.22 -
Prevx1 V2 2008.02.22 -
Rising 20.32.42.00 2008.02.22 -
Sophos 4.26.0 2008.02.22 -
Sunbelt 3.0.890.0 2008.02.22 -
Symantec 10 2008.02.22 -
TheHacker 6.2.9.226 2008.02.22 -
VBA32 3.12.6.1 2008.02.21 -
VirusBuster 4.3.26:9 2008.02.22 -
Webwasher-Gateway 6.6.2 2008.02.22 -
Information additionnelle
File size: 319488 bytes
MD5: 201f07f6e5e08b41b5bcc2ab3d339ecc
SHA1: e5139b16a8fffcce46cb1bb21dc7d01f59b5b3ff
PEiD: -
PAR CONTRE POUR LE 3EME RAPPORT JE NE SAIS PAS SI C SA QUE TU VEUX
Service load: 0% 100%
File: SysMonitor.exe
Status: OK
MD5: 201f07f6e5e08b41b5bcc2ab3d339ecc
Packers detected: -
Bit9 reports: Not analyzed yet (more info)
Scanner results
Scan taken on 26 Feb 2008 21:33:21 (GMT)
A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Ikarus Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Rising Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing
Service load: 0% 100%
File: SysMonitor.exe
Status: OK
MD5: 201f07f6e5e08b41b5bcc2ab3d339ecc
Packers detected: -
Bit9 reports: Not analyzed yet (more info)
Scanner results
Scan taken on 26 Feb 2008 21:33:21 (GMT)
A-Squared Found nothing
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
CPsecure Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
F-Secure Anti-Virus Found nothing
Fortinet Found nothing
Ikarus Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
Panda Antivirus Found nothing
Rising Antivirus Found nothing
Sophos Antivirus Found nothing
VirusBuster Found nothing
VBA32 Found nothing