A l'aide ( Virus Hostsnake )
Djet
-
green day Messages postés 26722 Statut Modérateur, Contributeur sécurité -
green day Messages postés 26722 Statut Modérateur, Contributeur sécurité -
Bonjour,
Voici mon problème : J'ai une fenêtre Hostsnake qui s'ouvre et se ferme aussitôt, je n'arrive pas à tuer ce virus. Il fait ramer mon pc. Est ce que quelqu'un pourrait me conseiller ?
Merci beaucoup par avance
Voici mon problème : J'ai une fenêtre Hostsnake qui s'ouvre et se ferme aussitôt, je n'arrive pas à tuer ce virus. Il fait ramer mon pc. Est ce que quelqu'un pourrait me conseiller ?
Merci beaucoup par avance
A voir également:
- A l'aide ( Virus Hostsnake )
- Virus mcafee - Accueil - Piratage
- Virus informatique - Guide
- Panda anti virus gratuit - Télécharger - Antivirus & Antimalwares
- Undisclosed-recipients virus - Guide
- Ordinateur bloqué virus - Accueil - Arnaque
30 réponses
Salut
Télécharge ceci :
Lien : http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis
Démo : http://pageperso.aol.fr/balltrap34/demohijack.htm
Choisir l'option "do a scan and a logfile", et faire un copier/coller du rapport ainsi générer sur le forum.
++
Télécharge ceci :
Lien : http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis
Démo : http://pageperso.aol.fr/balltrap34/demohijack.htm
Choisir l'option "do a scan and a logfile", et faire un copier/coller du rapport ainsi générer sur le forum.
++
Merci à toi donc voici le rapport :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:52:28, on 06/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\TEMP\BN4.tmp
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\WINDOWS\VM_STI.EXE
C:\Program Files\Microsoft Works\WksSb.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\spolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {0B52C7EC-D1A3-4054-923C-DD12567F28B1} - C:\WINDOWS\system32\mljhggf.dll (file missing)
O2 - BHO: (no name) - {68CB3332-B0F5-4DD4-B213-7E423BE033F0} - C:\WINDOWS\system32\awvtu.dll (file missing)
O2 - BHO: (no name) - {7BB21C6E-3DEB-7C31-F9CC-CD09BBB3AC6A} - C:\DOCUME~1\admin\APPLIC~1\AMENJU~1\onenew.exe (file missing)
O2 - BHO: (no name) - {9E7A65D5-AD83-42E9-A906-6ACE19B3816F} - C:\WINDOWS\system32\pmnli.dll (file missing)
O2 - BHO: (no name) - {C8CDF0B6-A3C3-4ABC-BBCA-EA772B562921} - C:\WINDOWS\system32\urqnnnk.dll (file missing)
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [BM6327bf40] Rundll32.exe "C:\WINDOWS\system32\tmqsiwun.dll",s
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RayV] C:\Program Files\RayV\RayV\RayV.exe /background
O4 - HKCU\..\Policies\Explorer\Run: [prov] prov.exe
O4 - HKCU\..\Policies\Explorer\Run: [NT Security Service] NTSecurity.exe
O4 - HKCU\..\Policies\Explorer\Run: [Printing Utilities] spolsv.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Rappels du Calendrier Microsoft Works.lnk = ?
O8 - Extra context menu item: &Search - http://ko.bar.need2find.com/KO/menusearch.html?p=KO
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4414DE02-9B79-4140-B8C0-E66E0779E883}: NameServer = 212.27.54.252,212.27.53.252
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/html - (no CLSID) - (no file)
O20 - Winlogon Notify: mljhggf - mljhggf.dll (file missing)
O20 - Winlogon Notify: urqnnnk - urqnnnk.dll (file missing)
O20 - Winlogon Notify: WLCtrl32 - C:\WINDOWS\SYSTEM32\WLCtrl32.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:52:28, on 06/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\TEMP\BN4.tmp
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
C:\WINDOWS\VM_STI.EXE
C:\Program Files\Microsoft Works\WksSb.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\spolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {0B52C7EC-D1A3-4054-923C-DD12567F28B1} - C:\WINDOWS\system32\mljhggf.dll (file missing)
O2 - BHO: (no name) - {68CB3332-B0F5-4DD4-B213-7E423BE033F0} - C:\WINDOWS\system32\awvtu.dll (file missing)
O2 - BHO: (no name) - {7BB21C6E-3DEB-7C31-F9CC-CD09BBB3AC6A} - C:\DOCUME~1\admin\APPLIC~1\AMENJU~1\onenew.exe (file missing)
O2 - BHO: (no name) - {9E7A65D5-AD83-42E9-A906-6ACE19B3816F} - C:\WINDOWS\system32\pmnli.dll (file missing)
O2 - BHO: (no name) - {C8CDF0B6-A3C3-4ABC-BBCA-EA772B562921} - C:\WINDOWS\system32\urqnnnk.dll (file missing)
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [BM6327bf40] Rundll32.exe "C:\WINDOWS\system32\tmqsiwun.dll",s
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RayV] C:\Program Files\RayV\RayV\RayV.exe /background
O4 - HKCU\..\Policies\Explorer\Run: [prov] prov.exe
O4 - HKCU\..\Policies\Explorer\Run: [NT Security Service] NTSecurity.exe
O4 - HKCU\..\Policies\Explorer\Run: [Printing Utilities] spolsv.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Rappels du Calendrier Microsoft Works.lnk = ?
O8 - Extra context menu item: &Search - http://ko.bar.need2find.com/KO/menusearch.html?p=KO
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4414DE02-9B79-4140-B8C0-E66E0779E883}: NameServer = 212.27.54.252,212.27.53.252
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/html - (no CLSID) - (no file)
O20 - Winlogon Notify: mljhggf - mljhggf.dll (file missing)
O20 - Winlogon Notify: urqnnnk - urqnnnk.dll (file missing)
O20 - Winlogon Notify: WLCtrl32 - C:\WINDOWS\SYSTEM32\WLCtrl32.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
ok,
Télécharger ComboFix (par sUBs) sur le Bureau : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
* Démarrer en mode sans echec
* Double cliquer combofix.exe.
* Appuyer sur la touche Y (Yes) pour démarrer le scan
* Le rapport sera crée dans: C:\Combofix.txt, poste le stp
++
Télécharger ComboFix (par sUBs) sur le Bureau : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
* Démarrer en mode sans echec
* Double cliquer combofix.exe.
* Appuyer sur la touche Y (Yes) pour démarrer le scan
* Le rapport sera crée dans: C:\Combofix.txt, poste le stp
++
Voilà le rapport :
ComboFix 08-04-04.1 - admin 2008-04-06 18:26:09.3 - NTFSx86 MINIMAL
Endroit: C:\Documents and Settings\admin\Bureau\ComboFix.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\kiasys.dll
.
((((((((((((((((((((((((((((( Fichiers créés 2008-03-06 to 2008-04-06 ))))))))))))))))))))))))))))))))))))
.
2008-04-06 17:51 . 2008-04-06 17:51 <REP> d-------- C:\Program Files\Trend Micro
2008-04-06 13:54 . 2008-04-06 13:54 <REP> d-------- C:\Documents and Settings\admin\Application Data\Grisoft
2008-04-06 13:54 . 2007-05-30 14:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-04-06 01:25 . 2008-04-06 12:33 1,744 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-06 00:47 . 2008-04-06 00:47 230 --a------ C:\WINDOWS\system32\spupdsvc.inf
2008-04-06 00:41 . 2008-04-06 00:50 <REP> d-------- C:\WINDOWS\SxsCaPendDel
2008-04-06 00:32 . 2008-04-06 00:32 121 --a------ C:\WINDOWS\bdagent.INI
2008-04-06 00:11 . 2008-04-06 13:28 <REP> d-------- C:\Program Files\Navilog1
2008-04-05 20:41 . 2008-04-05 20:41 <REP> d-------- C:\Program Files\BitDefender
2008-04-05 20:39 . 2008-04-05 20:42 <REP> d-------- C:\Program Files\Fichiers communs\BitDefender
2008-04-05 18:24 . 2008-04-05 18:25 <REP> d-------- C:\Documents and Settings\admin\Application Data\AVG7
2008-04-05 18:23 . 2008-04-05 18:23 <REP> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-04-05 18:22 . 2008-04-05 19:55 <REP> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-04-05 17:10 . 2008-04-05 17:10 3,120 --a------ C:\WINDOWS\system32\118290.54
2008-04-05 17:10 . 2008-04-05 17:10 3,120 --a------ C:\WINDOWS\118294.78
2008-04-05 17:09 . 1996-08-20 20:37 15,840 --a------ C:\WINDOWS\system32\Machnm1.exe
2008-04-05 17:09 . 2005-09-25 16:37 5,632 --a------ C:\WINDOWS\system32\Machnm64.sys
2008-04-05 17:09 . 2003-08-13 00:27 2,304 --a------ C:\WINDOWS\system32\Machnm32.sys
2008-04-05 16:38 . 2008-04-05 16:38 <REP> d-------- C:\WINDOWS\system32\save$$updater
2008-04-05 15:40 . 2008-04-05 20:47 <REP> d-------- C:\Program Files\Fichiers communs\Symantec Shared
2008-04-05 15:28 . 2006-10-05 04:42 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-04-05 15:28 . 2006-10-05 04:42 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-04-05 15:27 . 2008-04-05 15:28 <REP> d-------- C:\Program Files\Picasa2
2008-04-05 13:52 . 2008-04-05 20:03 <REP> d-------- C:\Program Files\MSNFix
2008-04-05 02:32 . 2008-04-05 02:38 <REP> d-------- C:\Program Files\Spyware Doctor
2008-04-05 02:32 . 2008-04-05 02:32 <REP> d-------- C:\Documents and Settings\admin\Application Data\PC Tools
2008-04-05 02:32 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-04-05 02:32 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-04-05 02:32 . 2008-02-01 12:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-04-05 02:32 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-04-04 18:07 . 2005-09-23 07:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2008-04-04 16:47 . 2008-04-04 16:47 <REP> dr------- C:\Documents and Settings\LocalService\Favoris
2008-04-03 20:19 . 2008-04-05 04:15 <REP> d-------- C:\Program Files\a-squared Free
2008-04-02 14:50 . 2008-04-05 19:54 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-02 13:28 . 2008-03-29 19:45 1,146,232 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-04-02 13:28 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-04-02 13:28 . 2008-03-29 19:23 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-04-02 13:28 . 2008-03-29 19:35 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-04-02 13:28 . 2008-01-17 17:34 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-04-02 13:28 . 2008-03-29 19:31 75,856 --a------ C:\WINDOWS\system32\drivers\aswSP.sys
2008-04-02 13:28 . 2008-03-29 19:27 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-04-02 13:28 . 2008-03-29 19:26 26,944 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-04-02 13:28 . 2008-03-29 19:29 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-04-02 13:28 . 2008-03-29 19:35 20,560 --a------ C:\WINDOWS\system32\drivers\aswFsBlk.sys
2008-04-02 01:32 . 2008-04-02 01:31 361,984 --a------ C:\WINDOWS\system32\spolsv.exe
2008-03-23 15:19 . 2008-03-27 15:20 5,034 ---hs---- C:\WINDOWS\system32\eguncsfg.ini
2008-03-23 09:47 . 2008-03-23 15:11 4,734 ---hs---- C:\WINDOWS\system32\svsiriug.ini
2008-03-22 10:20 . 2008-03-23 09:39 4,614 ---hs---- C:\WINDOWS\system32\xtnlgoci.ini
2008-03-22 10:14 . 2008-03-22 10:14 26,132 --a------ C:\WINDOWS\system32\byyevxc.exe
2008-03-21 14:02 . 2008-03-22 10:12 4,494 ---hs---- C:\WINDOWS\system32\uuiotppl.ini
2008-03-19 20:49 . 2008-03-21 13:54 4,374 ---hs---- C:\WINDOWS\system32\ebgcyuqc.ini
2008-03-18 20:43 . 2008-03-19 20:44 4,254 ---hs---- C:\WINDOWS\system32\lmomujxt.ini
2008-03-17 19:00 . 2008-03-18 20:41 4,194 ---hs---- C:\WINDOWS\system32\koxjcext.ini
2008-03-16 19:01 . 2008-03-16 19:01 4,134 ---hs---- C:\WINDOWS\system32\kcqfuhub.ini
2008-03-16 18:50 . 2008-03-16 18:50 26,611 --a------ C:\WINDOWS\system32\caczjfcl.exe
2008-03-12 16:58 . 2008-03-12 16:58 26,611 --a------ C:\WINDOWS\system32\kiydthcyt.exe
2008-03-12 16:53 . 2008-03-12 16:53 217 --a------ C:\WINDOWS\system32\MRT.INI
2008-03-12 13:32 . 2008-03-23 13:55 26,132 --a------ C:\WINDOWS\system32\mjcscij.exe
2008-03-12 01:21 . 2008-03-12 13:28 3,654 ---hs---- C:\WINDOWS\system32\pherjlnh.ini
2008-03-11 01:19 . 2008-03-12 01:19 3,534 ---hs---- C:\WINDOWS\system32\mwegjbkk.ini
2008-03-10 01:20 . 2008-03-10 21:09 3,474 ---hs---- C:\WINDOWS\system32\ccnntsoe.ini
2008-03-10 00:20 . 2008-03-10 00:20 3,354 ---hs---- C:\WINDOWS\system32\txkxtcir.ini
2008-03-09 00:17 . 2008-03-10 00:17 3,294 ---hs---- C:\WINDOWS\system32\mfoyvvwy.ini
2008-03-08 00:12 . 2008-03-09 00:13 3,234 ---hs---- C:\WINDOWS\system32\qjhycpnn.ini
2008-03-07 21:42 . 2008-03-07 21:42 3,174 ---hs---- C:\WINDOWS\system32\buhdvlqr.ini
2008-03-07 00:45 . 2008-03-27 14:01 26,132 --a------ C:\WINDOWS\system32\pggldh.exe
2008-03-06 21:45 . 2008-03-06 21:45 3,114 ---hs---- C:\WINDOWS\system32\canoecgc.ini
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-05 17:57 --------- d-----w C:\Program Files\Google
2008-04-05 16:08 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-04-05 16:07 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-05 15:58 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-04-05 14:42 --------- d-----w C:\Program Files\IBM
2008-04-05 00:48 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-02 11:27 --------- d-----w C:\Program Files\Alwil Software
2008-03-24 11:22 --------- d-----w C:\Documents and Settings\admin\Application Data\OpenOffice.org2
2008-03-22 07:45 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Readme test meow
2008-02-27 08:28 --------- d-----w C:\Program Files\Windows Live
2008-02-23 02:38 43,872 ------w C:\WINDOWS\system32\drivers\pxhelp20.sys
2008-02-19 20:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-02-10 20:07 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-02-10 20:07 --------- d-----w C:\Program Files\eMule
2008-02-10 19:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-10 19:44 --------- d-----w C:\Program Files\FranceTelecomUninstall
2008-02-10 19:40 --------- d-----w C:\Program Files\PeerGuardian2
2008-02-10 17:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-10 17:38 --------- d-----w C:\Program Files\Lavasoft
2008-02-10 17:37 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-02-10 17:28 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-10 17:08 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-02-10 15:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\LICENSE FORD HOPE DRAW
2008-02-10 15:06 --------- d-----w C:\Program Files\Logitech
2008-02-10 13:03 37,888 ----a-w C:\WINDOWS\system32\rar.exe
2008-02-01 10:17 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{68CB3332-B0F5-4DD4-B213-7E423BE033F0}]
C:\WINDOWS\system32\awvtu.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7BB21C6E-3DEB-7C31-F9CC-CD09BBB3AC6A}]
C:\DOCUME~1\admin\APPLIC~1\AMENJU~1\onenew.exe
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9E7A65D5-AD83-42E9-A906-6ACE19B3816F}]
C:\WINDOWS\system32\pmnli.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 01:09 15360]
"RayV"="C:\Program Files\RayV\RayV\RayV.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="irprops.cpl" [2004-08-20 01:10 380928 C:\WINDOWS\system32\irprops.cpl]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-07-10 14:25 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-07-10 14:13 114688]
"PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 18:24 86016]
"BigDogPath"="C:\WINDOWS\VM_STI.exe" [2004-06-09 09:37 40960]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 15:49 1121280]
"WorksFUD"="C:\Program Files\Microsoft Works\wkfud.exe" [2000-07-12 12:59 24576]
"Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [2000-07-12 14:14 311350]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-08-04 03:01 28739]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 19:37 79224]
"BM6327bf40"="C:\WINDOWS\system32\tmqsiwun.dll" [ ]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-20 01:09 15360]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Rappels du Calendrier Microsoft Works.lnk - C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\wkcalrem.exe [2000-07-12 14:14:38 24633]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
"prov"= prov.exe
"NT Security Service"= NTSecurity.exe
"Printing Utilities"= spolsv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljhggf]
mljhggf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqnnnk]
urqnnnk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSVideo8"= VfWWDM32.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lqu40.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Sxd15.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
S0 Lqu40;Lqu40;C:\WINDOWS\system32\Drivers\Lqu40.sys []
S1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
S2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
S3 k600bus;Sony Ericsson 600i driver (WDM);C:\WINDOWS\system32\DRIVERS\k600bus.sys [2005-03-04 19:08]
S3 k600mdfl;Sony Ericsson 600i USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k600mdfl.sys [2005-03-04 19:11]
S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\k600mdm.sys [2005-03-04 19:11]
S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\k600mgmt.sys [2005-03-04 19:13]
S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\k600obex.sys [2005-03-04 19:15]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9f092bd8-cdcf-11dc-8939-000d6027301a}]
\Shell\AutoRun\command - E:\InstallTomTomHOME.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-06 18:29:01
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-04-06 18:31:19
ComboFix-quarantined-files.txt 2008-04-06 16:30:51
ComboFix2.txt 2008-04-06 16:18:52
Pre-Run: 18,721,263,616 octets libres
Post-Run: 18,708,774,912 octets libres
.
2008-04-06 10:24:28 --- E O F ---
ComboFix 08-04-04.1 - admin 2008-04-06 18:26:09.3 - NTFSx86 MINIMAL
Endroit: C:\Documents and Settings\admin\Bureau\ComboFix.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\kiasys.dll
.
((((((((((((((((((((((((((((( Fichiers créés 2008-03-06 to 2008-04-06 ))))))))))))))))))))))))))))))))))))
.
2008-04-06 17:51 . 2008-04-06 17:51 <REP> d-------- C:\Program Files\Trend Micro
2008-04-06 13:54 . 2008-04-06 13:54 <REP> d-------- C:\Documents and Settings\admin\Application Data\Grisoft
2008-04-06 13:54 . 2007-05-30 14:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-04-06 01:25 . 2008-04-06 12:33 1,744 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-06 00:47 . 2008-04-06 00:47 230 --a------ C:\WINDOWS\system32\spupdsvc.inf
2008-04-06 00:41 . 2008-04-06 00:50 <REP> d-------- C:\WINDOWS\SxsCaPendDel
2008-04-06 00:32 . 2008-04-06 00:32 121 --a------ C:\WINDOWS\bdagent.INI
2008-04-06 00:11 . 2008-04-06 13:28 <REP> d-------- C:\Program Files\Navilog1
2008-04-05 20:41 . 2008-04-05 20:41 <REP> d-------- C:\Program Files\BitDefender
2008-04-05 20:39 . 2008-04-05 20:42 <REP> d-------- C:\Program Files\Fichiers communs\BitDefender
2008-04-05 18:24 . 2008-04-05 18:25 <REP> d-------- C:\Documents and Settings\admin\Application Data\AVG7
2008-04-05 18:23 . 2008-04-05 18:23 <REP> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-04-05 18:22 . 2008-04-05 19:55 <REP> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-04-05 17:10 . 2008-04-05 17:10 3,120 --a------ C:\WINDOWS\system32\118290.54
2008-04-05 17:10 . 2008-04-05 17:10 3,120 --a------ C:\WINDOWS\118294.78
2008-04-05 17:09 . 1996-08-20 20:37 15,840 --a------ C:\WINDOWS\system32\Machnm1.exe
2008-04-05 17:09 . 2005-09-25 16:37 5,632 --a------ C:\WINDOWS\system32\Machnm64.sys
2008-04-05 17:09 . 2003-08-13 00:27 2,304 --a------ C:\WINDOWS\system32\Machnm32.sys
2008-04-05 16:38 . 2008-04-05 16:38 <REP> d-------- C:\WINDOWS\system32\save$$updater
2008-04-05 15:40 . 2008-04-05 20:47 <REP> d-------- C:\Program Files\Fichiers communs\Symantec Shared
2008-04-05 15:28 . 2006-10-05 04:42 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-04-05 15:28 . 2006-10-05 04:42 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-04-05 15:27 . 2008-04-05 15:28 <REP> d-------- C:\Program Files\Picasa2
2008-04-05 13:52 . 2008-04-05 20:03 <REP> d-------- C:\Program Files\MSNFix
2008-04-05 02:32 . 2008-04-05 02:38 <REP> d-------- C:\Program Files\Spyware Doctor
2008-04-05 02:32 . 2008-04-05 02:32 <REP> d-------- C:\Documents and Settings\admin\Application Data\PC Tools
2008-04-05 02:32 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-04-05 02:32 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-04-05 02:32 . 2008-02-01 12:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-04-05 02:32 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-04-04 18:07 . 2005-09-23 07:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2008-04-04 16:47 . 2008-04-04 16:47 <REP> dr------- C:\Documents and Settings\LocalService\Favoris
2008-04-03 20:19 . 2008-04-05 04:15 <REP> d-------- C:\Program Files\a-squared Free
2008-04-02 14:50 . 2008-04-05 19:54 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-02 13:28 . 2008-03-29 19:45 1,146,232 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-04-02 13:28 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-04-02 13:28 . 2008-03-29 19:23 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-04-02 13:28 . 2008-03-29 19:35 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-04-02 13:28 . 2008-01-17 17:34 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-04-02 13:28 . 2008-03-29 19:31 75,856 --a------ C:\WINDOWS\system32\drivers\aswSP.sys
2008-04-02 13:28 . 2008-03-29 19:27 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-04-02 13:28 . 2008-03-29 19:26 26,944 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-04-02 13:28 . 2008-03-29 19:29 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-04-02 13:28 . 2008-03-29 19:35 20,560 --a------ C:\WINDOWS\system32\drivers\aswFsBlk.sys
2008-04-02 01:32 . 2008-04-02 01:31 361,984 --a------ C:\WINDOWS\system32\spolsv.exe
2008-03-23 15:19 . 2008-03-27 15:20 5,034 ---hs---- C:\WINDOWS\system32\eguncsfg.ini
2008-03-23 09:47 . 2008-03-23 15:11 4,734 ---hs---- C:\WINDOWS\system32\svsiriug.ini
2008-03-22 10:20 . 2008-03-23 09:39 4,614 ---hs---- C:\WINDOWS\system32\xtnlgoci.ini
2008-03-22 10:14 . 2008-03-22 10:14 26,132 --a------ C:\WINDOWS\system32\byyevxc.exe
2008-03-21 14:02 . 2008-03-22 10:12 4,494 ---hs---- C:\WINDOWS\system32\uuiotppl.ini
2008-03-19 20:49 . 2008-03-21 13:54 4,374 ---hs---- C:\WINDOWS\system32\ebgcyuqc.ini
2008-03-18 20:43 . 2008-03-19 20:44 4,254 ---hs---- C:\WINDOWS\system32\lmomujxt.ini
2008-03-17 19:00 . 2008-03-18 20:41 4,194 ---hs---- C:\WINDOWS\system32\koxjcext.ini
2008-03-16 19:01 . 2008-03-16 19:01 4,134 ---hs---- C:\WINDOWS\system32\kcqfuhub.ini
2008-03-16 18:50 . 2008-03-16 18:50 26,611 --a------ C:\WINDOWS\system32\caczjfcl.exe
2008-03-12 16:58 . 2008-03-12 16:58 26,611 --a------ C:\WINDOWS\system32\kiydthcyt.exe
2008-03-12 16:53 . 2008-03-12 16:53 217 --a------ C:\WINDOWS\system32\MRT.INI
2008-03-12 13:32 . 2008-03-23 13:55 26,132 --a------ C:\WINDOWS\system32\mjcscij.exe
2008-03-12 01:21 . 2008-03-12 13:28 3,654 ---hs---- C:\WINDOWS\system32\pherjlnh.ini
2008-03-11 01:19 . 2008-03-12 01:19 3,534 ---hs---- C:\WINDOWS\system32\mwegjbkk.ini
2008-03-10 01:20 . 2008-03-10 21:09 3,474 ---hs---- C:\WINDOWS\system32\ccnntsoe.ini
2008-03-10 00:20 . 2008-03-10 00:20 3,354 ---hs---- C:\WINDOWS\system32\txkxtcir.ini
2008-03-09 00:17 . 2008-03-10 00:17 3,294 ---hs---- C:\WINDOWS\system32\mfoyvvwy.ini
2008-03-08 00:12 . 2008-03-09 00:13 3,234 ---hs---- C:\WINDOWS\system32\qjhycpnn.ini
2008-03-07 21:42 . 2008-03-07 21:42 3,174 ---hs---- C:\WINDOWS\system32\buhdvlqr.ini
2008-03-07 00:45 . 2008-03-27 14:01 26,132 --a------ C:\WINDOWS\system32\pggldh.exe
2008-03-06 21:45 . 2008-03-06 21:45 3,114 ---hs---- C:\WINDOWS\system32\canoecgc.ini
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-05 17:57 --------- d-----w C:\Program Files\Google
2008-04-05 16:08 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-04-05 16:07 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-05 15:58 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-04-05 14:42 --------- d-----w C:\Program Files\IBM
2008-04-05 00:48 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-02 11:27 --------- d-----w C:\Program Files\Alwil Software
2008-03-24 11:22 --------- d-----w C:\Documents and Settings\admin\Application Data\OpenOffice.org2
2008-03-22 07:45 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Readme test meow
2008-02-27 08:28 --------- d-----w C:\Program Files\Windows Live
2008-02-23 02:38 43,872 ------w C:\WINDOWS\system32\drivers\pxhelp20.sys
2008-02-19 20:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-02-10 20:07 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-02-10 20:07 --------- d-----w C:\Program Files\eMule
2008-02-10 19:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-10 19:44 --------- d-----w C:\Program Files\FranceTelecomUninstall
2008-02-10 19:40 --------- d-----w C:\Program Files\PeerGuardian2
2008-02-10 17:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-10 17:38 --------- d-----w C:\Program Files\Lavasoft
2008-02-10 17:37 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-02-10 17:28 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-10 17:08 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-02-10 15:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\LICENSE FORD HOPE DRAW
2008-02-10 15:06 --------- d-----w C:\Program Files\Logitech
2008-02-10 13:03 37,888 ----a-w C:\WINDOWS\system32\rar.exe
2008-02-01 10:17 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{68CB3332-B0F5-4DD4-B213-7E423BE033F0}]
C:\WINDOWS\system32\awvtu.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7BB21C6E-3DEB-7C31-F9CC-CD09BBB3AC6A}]
C:\DOCUME~1\admin\APPLIC~1\AMENJU~1\onenew.exe
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9E7A65D5-AD83-42E9-A906-6ACE19B3816F}]
C:\WINDOWS\system32\pmnli.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 01:09 15360]
"RayV"="C:\Program Files\RayV\RayV\RayV.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="irprops.cpl" [2004-08-20 01:10 380928 C:\WINDOWS\system32\irprops.cpl]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-07-10 14:25 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-07-10 14:13 114688]
"PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 18:24 86016]
"BigDogPath"="C:\WINDOWS\VM_STI.exe" [2004-06-09 09:37 40960]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 15:49 1121280]
"WorksFUD"="C:\Program Files\Microsoft Works\wkfud.exe" [2000-07-12 12:59 24576]
"Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [2000-07-12 14:14 311350]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-08-04 03:01 28739]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 19:37 79224]
"BM6327bf40"="C:\WINDOWS\system32\tmqsiwun.dll" [ ]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-20 01:09 15360]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Rappels du Calendrier Microsoft Works.lnk - C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\wkcalrem.exe [2000-07-12 14:14:38 24633]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
"prov"= prov.exe
"NT Security Service"= NTSecurity.exe
"Printing Utilities"= spolsv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljhggf]
mljhggf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqnnnk]
urqnnnk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSVideo8"= VfWWDM32.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lqu40.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Sxd15.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
S0 Lqu40;Lqu40;C:\WINDOWS\system32\Drivers\Lqu40.sys []
S1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
S2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
S3 k600bus;Sony Ericsson 600i driver (WDM);C:\WINDOWS\system32\DRIVERS\k600bus.sys [2005-03-04 19:08]
S3 k600mdfl;Sony Ericsson 600i USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k600mdfl.sys [2005-03-04 19:11]
S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\k600mdm.sys [2005-03-04 19:11]
S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\k600mgmt.sys [2005-03-04 19:13]
S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\k600obex.sys [2005-03-04 19:15]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9f092bd8-cdcf-11dc-8939-000d6027301a}]
\Shell\AutoRun\command - E:\InstallTomTomHOME.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-06 18:29:01
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-04-06 18:31:19
ComboFix-quarantined-files.txt 2008-04-06 16:30:51
ComboFix2.txt 2008-04-06 16:18:52
Pre-Run: 18,721,263,616 octets libres
Post-Run: 18,708,774,912 octets libres
.
2008-04-06 10:24:28 --- E O F ---
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
ok,
# Télécharger Vundofix.exe (par Atribune) sur votre Bureau : http://www.atribune.org/ccount/click.php?id=4
* Double-cliquer sur VundoFix.exe afin de le lancer.
* Cliquer sur le bouton Scan for Vundo.
* Lorsque le scan est complété, cliquer sur le bouton Fix Vundo.
* Une invite de commande demandera si l’on souhaite supprimer les fichiers, cliquer sur YES
* Après avoir cliqué "YES", le Bureau disparaîtra un moment lors de la suppression des fichiers. * Une nouvelle invite de commande annoncera que le PC devra s'éteindre ("shutdown"). Cliquer sur OK , puis laisser le redémarrer.
* Le contenu du rapport est situé dans C:\vundofix.txt, poste le stp
++
# Télécharger Vundofix.exe (par Atribune) sur votre Bureau : http://www.atribune.org/ccount/click.php?id=4
* Double-cliquer sur VundoFix.exe afin de le lancer.
* Cliquer sur le bouton Scan for Vundo.
* Lorsque le scan est complété, cliquer sur le bouton Fix Vundo.
* Une invite de commande demandera si l’on souhaite supprimer les fichiers, cliquer sur YES
* Après avoir cliqué "YES", le Bureau disparaîtra un moment lors de la suppression des fichiers. * Une nouvelle invite de commande annoncera que le PC devra s'éteindre ("shutdown"). Cliquer sur OK , puis laisser le redémarrer.
* Le contenu du rapport est situé dans C:\vundofix.txt, poste le stp
++
Il me dit qu'il y a Zéro infections et quand je clique sur "fix Vundo" ça dit "No files were found, VundoFix V7.0.3 will now close"
Il me sort aucun rapport c'est normal où pas ?
Merci encore à toi de m'aider
Il me sort aucun rapport c'est normal où pas ?
Merci encore à toi de m'aider
ok, c'est normal !
Télécharge SDFix sur ton bureau
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau.
Redémarre ton ordinateur en mode sans échec
Ouvre le dossier SDFix qui vient d'être créé sur le Bureau et double clique sur RunThis.cmd pour lancer le script.
Appuie sur Y pour commencer le processus de nettoyage.
Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
Appuie sur une touche pour redémarrer le PC.
Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau log Hijackthis !
++
Télécharge SDFix sur ton bureau
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau.
Redémarre ton ordinateur en mode sans échec
Ouvre le dossier SDFix qui vient d'être créé sur le Bureau et double clique sur RunThis.cmd pour lancer le script.
Appuie sur Y pour commencer le processus de nettoyage.
Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
Appuie sur une touche pour redémarrer le PC.
Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau log Hijackthis !
++
Donc voici le résultat :
[b]SDFix: Version 1.167 [/b]
Run by admin on 06/04/2008 at 19:43
Microsoft Windows XP [version 5.1.2600]
Running From: C:\DOCUME~1\admin\Bureau\SDFix
[b]Checking Services [/b]:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting
[b]Checking Files [/b]:
No Trojan Files Found
Removing Temp Files
[b]ADS Check [/b]:
[b]Final Check [/b]:
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-06 19:55:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 318
[b]Remaining Services [/b]:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Disabled:Firefox"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[b]Remaining Files [/b]:
File Backups: - C:\DOCUME~1\admin\Bureau\SDFix\backups\backups.zip
[b]Files with Hidden Attributes [/b]:
Sat 5 Apr 2008 6,104,632 A..H. --- "C:\Program Files\Picasa2\setup.exe"
Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Tue 14 Mar 2006 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Tue 14 Mar 2006 401 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv16.bak"
Sun 20 Jan 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Tue 14 Mar 2006 4,348 ...H. --- "C:\Documents and Settings\Administrateur\Mes documents\Ma musique\Sauvegarde de la licence\drmv1key.bak"
Fri 4 Aug 2006 401 A..H. --- "C:\Documents and Settings\Administrateur\Mes documents\Ma musique\Sauvegarde de la licence\drmv1lic.bak"
Sat 4 Mar 2006 312 ...H. --- "C:\Documents and Settings\Administrateur\Mes documents\Ma musique\Sauvegarde de la licence\drmv2key.bak"
Fri 4 Aug 2006 1,536 A..H. --- "C:\Documents and Settings\Administrateur\Mes documents\Ma musique\Sauvegarde de la licence\drmv2lic.bak"
[b]Finished![/b]
[b]SDFix: Version 1.167 [/b]
Run by admin on 06/04/2008 at 19:43
Microsoft Windows XP [version 5.1.2600]
Running From: C:\DOCUME~1\admin\Bureau\SDFix
[b]Checking Services [/b]:
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting
[b]Checking Files [/b]:
No Trojan Files Found
Removing Temp Files
[b]ADS Check [/b]:
[b]Final Check [/b]:
catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-06 19:55:50
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 318
[b]Remaining Services [/b]:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Disabled:Firefox"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[b]Remaining Files [/b]:
File Backups: - C:\DOCUME~1\admin\Bureau\SDFix\backups\backups.zip
[b]Files with Hidden Attributes [/b]:
Sat 5 Apr 2008 6,104,632 A..H. --- "C:\Program Files\Picasa2\setup.exe"
Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Tue 14 Mar 2006 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Tue 14 Mar 2006 401 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv16.bak"
Sun 20 Jan 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Tue 14 Mar 2006 4,348 ...H. --- "C:\Documents and Settings\Administrateur\Mes documents\Ma musique\Sauvegarde de la licence\drmv1key.bak"
Fri 4 Aug 2006 401 A..H. --- "C:\Documents and Settings\Administrateur\Mes documents\Ma musique\Sauvegarde de la licence\drmv1lic.bak"
Sat 4 Mar 2006 312 ...H. --- "C:\Documents and Settings\Administrateur\Mes documents\Ma musique\Sauvegarde de la licence\drmv2key.bak"
Fri 4 Aug 2006 1,536 A..H. --- "C:\Documents and Settings\Administrateur\Mes documents\Ma musique\Sauvegarde de la licence\drmv2lic.bak"
[b]Finished![/b]
ok,
Crée un nouveau document texte et nomme le CFScript.txt ( attention très important ! ) : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes en gras :
File::
C:\WINDOWS\system32\spolsv.exe
C:\WINDOWS\system32\eguncsfg.ini
C:\WINDOWS\system32\svsiriug.ini
C:\WINDOWS\system32\xtnlgoci.ini
C:\WINDOWS\system32\byyevxc.exe
C:\WINDOWS\system32\uuiotppl.ini
C:\WINDOWS\system32\ebgcyuqc.ini
C:\WINDOWS\system32\lmomujxt.ini
C:\WINDOWS\system32\koxjcext.ini
C:\WINDOWS\system32\kcqfuhub.ini
C:\WINDOWS\system32\caczjfcl.exe
C:\WINDOWS\system32\kiydthcyt.exe
C:\WINDOWS\system32\MRT.INI
C:\WINDOWS\system32\mjcscij.exe
C:\WINDOWS\system32\pherjlnh.ini
C:\WINDOWS\system32\mwegjbkk.ini
C:\WINDOWS\system32\ccnntsoe.ini
C:\WINDOWS\system32\txkxtcir.ini
C:\WINDOWS\system32\mfoyvvwy.ini
C:\WINDOWS\system32\qjhycpnn.ini
C:\WINDOWS\system32\buhdvlqr.ini
C:\WINDOWS\system32\pggldh.exe
C:\WINDOWS\system32\canoecgc.in
C:\WINDOWS\system32\tmqsiwun.dll"
C:\WINDOWS\system32\awvtu.dll
C:\DOCUME~1\admin\APPLIC~1\AMENJU~1\onenew.exe
C:\WINDOWS\system32\pmnli.dll
C:\WINDOWS\system32\mljhggf.dll
C:\WINDOWS\system32\urqnnnk.dll
registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{68CB3332-B0F5-4DD4-B213-7E423BE033F0}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7BB21C6E-3DEB-7C31-F9CC-CD09BBB3AC6A}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9E7A65D5-AD83-42E9-A906-6ACE19B3816F}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
"prov"=-
"NT Security Service"=-
"Printing Utilities"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljhggf]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqnnnk]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BM6327bf40"=-
ensuite fais glisser le fichier texte sur combo.exe comme sur l'animation :
http://img.bleepingcomputer.com/combofix/usage/rc.gif
Dans la fenêtre qui suit, choisie l'option 1 puis valide
Patiente un peu, si le bureau disparait parfois durant le scan : c'est normal !
A la fin du scan, un rapport va s'afficher : poste le stp ( sinon il se situe dans ici : C:\ComboFix.txt )
@+
Crée un nouveau document texte et nomme le CFScript.txt ( attention très important ! ) : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes en gras :
File::
C:\WINDOWS\system32\spolsv.exe
C:\WINDOWS\system32\eguncsfg.ini
C:\WINDOWS\system32\svsiriug.ini
C:\WINDOWS\system32\xtnlgoci.ini
C:\WINDOWS\system32\byyevxc.exe
C:\WINDOWS\system32\uuiotppl.ini
C:\WINDOWS\system32\ebgcyuqc.ini
C:\WINDOWS\system32\lmomujxt.ini
C:\WINDOWS\system32\koxjcext.ini
C:\WINDOWS\system32\kcqfuhub.ini
C:\WINDOWS\system32\caczjfcl.exe
C:\WINDOWS\system32\kiydthcyt.exe
C:\WINDOWS\system32\MRT.INI
C:\WINDOWS\system32\mjcscij.exe
C:\WINDOWS\system32\pherjlnh.ini
C:\WINDOWS\system32\mwegjbkk.ini
C:\WINDOWS\system32\ccnntsoe.ini
C:\WINDOWS\system32\txkxtcir.ini
C:\WINDOWS\system32\mfoyvvwy.ini
C:\WINDOWS\system32\qjhycpnn.ini
C:\WINDOWS\system32\buhdvlqr.ini
C:\WINDOWS\system32\pggldh.exe
C:\WINDOWS\system32\canoecgc.in
C:\WINDOWS\system32\tmqsiwun.dll"
C:\WINDOWS\system32\awvtu.dll
C:\DOCUME~1\admin\APPLIC~1\AMENJU~1\onenew.exe
C:\WINDOWS\system32\pmnli.dll
C:\WINDOWS\system32\mljhggf.dll
C:\WINDOWS\system32\urqnnnk.dll
registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{68CB3332-B0F5-4DD4-B213-7E423BE033F0}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7BB21C6E-3DEB-7C31-F9CC-CD09BBB3AC6A}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9E7A65D5-AD83-42E9-A906-6ACE19B3816F}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
"prov"=-
"NT Security Service"=-
"Printing Utilities"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljhggf]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqnnnk]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BM6327bf40"=-
ensuite fais glisser le fichier texte sur combo.exe comme sur l'animation :
http://img.bleepingcomputer.com/combofix/usage/rc.gif
Dans la fenêtre qui suit, choisie l'option 1 puis valide
Patiente un peu, si le bureau disparait parfois durant le scan : c'est normal !
A la fin du scan, un rapport va s'afficher : poste le stp ( sinon il se situe dans ici : C:\ComboFix.txt )
@+
Voilà ce que ça a donné :
ComboFix 08-04-04.1 - admin 2008-04-06 22:05:21.4 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.46 [GMT 2:00]
Endroit: C:\Documents and Settings\admin\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\admin\Bureau\CFScript.txt
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.
((((((((((((((((((((((((((((( Fichiers créés 2008-03-06 to 2008-04-06 ))))))))))))))))))))))))))))))))))))
.
2008-04-06 19:40 . 2008-04-06 19:40 <REP> d-------- C:\WINDOWS\ERUNT
2008-04-06 19:34 . 2008-04-06 10:24 <REP> d-------- C:\SDFix
2008-04-06 18:55 . 2008-04-06 18:55 <REP> d-------- C:\VundoFix Backups
2008-04-06 17:51 . 2008-04-06 17:51 <REP> d-------- C:\Program Files\Trend Micro
2008-04-06 13:54 . 2008-04-06 13:54 <REP> d-------- C:\Documents and Settings\admin\Application Data\Grisoft
2008-04-06 13:54 . 2007-05-30 14:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-04-06 01:25 . 2008-04-06 12:33 1,744 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-06 00:47 . 2008-04-06 00:47 230 --a------ C:\WINDOWS\system32\spupdsvc.inf
2008-04-06 00:41 . 2008-04-06 00:50 <REP> d-------- C:\WINDOWS\SxsCaPendDel
2008-04-06 00:32 . 2008-04-06 00:32 121 --a------ C:\WINDOWS\bdagent.INI
2008-04-06 00:11 . 2008-04-06 13:28 <REP> d-------- C:\Program Files\Navilog1
2008-04-05 20:41 . 2008-04-05 20:41 <REP> d-------- C:\Program Files\BitDefender
2008-04-05 20:39 . 2008-04-05 20:42 <REP> d-------- C:\Program Files\Fichiers communs\BitDefender
2008-04-05 18:24 . 2008-04-05 18:25 <REP> d-------- C:\Documents and Settings\admin\Application Data\AVG7
2008-04-05 18:23 . 2008-04-05 18:23 <REP> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-04-05 18:22 . 2008-04-05 19:55 <REP> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-04-05 17:10 . 2008-04-05 17:10 3,120 --a------ C:\WINDOWS\system32\118290.54
2008-04-05 17:10 . 2008-04-05 17:10 3,120 --a------ C:\WINDOWS\118294.78
2008-04-05 17:09 . 1996-08-20 20:37 15,840 --a------ C:\WINDOWS\system32\Machnm1.exe
2008-04-05 17:09 . 2005-09-25 16:37 5,632 --a------ C:\WINDOWS\system32\Machnm64.sys
2008-04-05 17:09 . 2003-08-13 00:27 2,304 --a------ C:\WINDOWS\system32\Machnm32.sys
2008-04-05 16:38 . 2008-04-05 16:38 <REP> d-------- C:\WINDOWS\system32\save$$updater
2008-04-05 15:40 . 2008-04-05 20:47 <REP> d-------- C:\Program Files\Fichiers communs\Symantec Shared
2008-04-05 15:28 . 2006-10-05 04:42 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-04-05 15:28 . 2006-10-05 04:42 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-04-05 15:27 . 2008-04-05 15:28 <REP> d-------- C:\Program Files\Picasa2
2008-04-05 13:52 . 2008-04-05 20:03 <REP> d-------- C:\Program Files\MSNFix
2008-04-05 02:32 . 2008-04-05 02:38 <REP> d-------- C:\Program Files\Spyware Doctor
2008-04-05 02:32 . 2008-04-05 02:32 <REP> d-------- C:\Documents and Settings\admin\Application Data\PC Tools
2008-04-05 02:32 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-04-05 02:32 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-04-05 02:32 . 2008-02-01 12:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-04-05 02:32 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-04-04 18:07 . 2005-09-23 07:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2008-04-04 16:47 . 2008-04-04 16:47 <REP> dr------- C:\Documents and Settings\LocalService\Favoris
2008-04-03 20:19 . 2008-04-05 04:15 <REP> d-------- C:\Program Files\a-squared Free
2008-04-02 14:50 . 2008-04-05 19:54 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-02 13:28 . 2008-03-29 19:45 1,146,232 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-04-02 13:28 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-04-02 13:28 . 2008-03-29 19:23 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-04-02 13:28 . 2008-03-29 19:35 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-04-02 13:28 . 2008-01-17 17:34 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-04-02 13:28 . 2008-03-29 19:31 75,856 --a------ C:\WINDOWS\system32\drivers\aswSP.sys
2008-04-02 13:28 . 2008-03-29 19:27 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-04-02 13:28 . 2008-03-29 19:26 26,944 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-04-02 13:28 . 2008-03-29 19:29 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-04-02 13:28 . 2008-03-29 19:35 20,560 --a------ C:\WINDOWS\system32\drivers\aswFsBlk.sys
2008-04-02 01:32 . 2008-04-02 01:31 361,984 --a------ C:\WINDOWS\system32\spolsv.exe
2008-03-23 15:19 . 2008-03-27 15:20 5,034 ---hs---- C:\WINDOWS\system32\eguncsfg.ini
2008-03-23 09:47 . 2008-03-23 15:11 4,734 ---hs---- C:\WINDOWS\system32\svsiriug.ini
2008-03-22 10:20 . 2008-03-23 09:39 4,614 ---hs---- C:\WINDOWS\system32\xtnlgoci.ini
2008-03-22 10:14 . 2008-03-22 10:14 26,132 --a------ C:\WINDOWS\system32\byyevxc.exe
2008-03-21 14:02 . 2008-03-22 10:12 4,494 ---hs---- C:\WINDOWS\system32\uuiotppl.ini
2008-03-19 20:49 . 2008-03-21 13:54 4,374 ---hs---- C:\WINDOWS\system32\ebgcyuqc.ini
2008-03-18 20:43 . 2008-03-19 20:44 4,254 ---hs---- C:\WINDOWS\system32\lmomujxt.ini
2008-03-17 19:00 . 2008-03-18 20:41 4,194 ---hs---- C:\WINDOWS\system32\koxjcext.ini
2008-03-16 19:01 . 2008-03-16 19:01 4,134 ---hs---- C:\WINDOWS\system32\kcqfuhub.ini
2008-03-16 18:50 . 2008-03-16 18:50 26,611 --a------ C:\WINDOWS\system32\caczjfcl.exe
2008-03-12 16:58 . 2008-03-12 16:58 26,611 --a------ C:\WINDOWS\system32\kiydthcyt.exe
2008-03-12 16:53 . 2008-03-12 16:53 217 --a------ C:\WINDOWS\system32\MRT.INI
2008-03-12 13:32 . 2008-03-23 13:55 26,132 --a------ C:\WINDOWS\system32\mjcscij.exe
2008-03-12 01:21 . 2008-03-12 13:28 3,654 ---hs---- C:\WINDOWS\system32\pherjlnh.ini
2008-03-11 01:19 . 2008-03-12 01:19 3,534 ---hs---- C:\WINDOWS\system32\mwegjbkk.ini
2008-03-10 01:20 . 2008-03-10 21:09 3,474 ---hs---- C:\WINDOWS\system32\ccnntsoe.ini
2008-03-10 00:20 . 2008-03-10 00:20 3,354 ---hs---- C:\WINDOWS\system32\txkxtcir.ini
2008-03-09 00:17 . 2008-03-10 00:17 3,294 ---hs---- C:\WINDOWS\system32\mfoyvvwy.ini
2008-03-08 00:12 . 2008-03-09 00:13 3,234 ---hs---- C:\WINDOWS\system32\qjhycpnn.ini
2008-03-07 21:42 . 2008-03-07 21:42 3,174 ---hs---- C:\WINDOWS\system32\buhdvlqr.ini
2008-03-07 00:45 . 2008-03-27 14:01 26,132 --a------ C:\WINDOWS\system32\pggldh.exe
2008-03-06 21:45 . 2008-03-06 21:45 3,114 ---hs---- C:\WINDOWS\system32\canoecgc.ini
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-06 20:02 --------- d-----w C:\Documents and Settings\admin\Application Data\OpenOffice.org2
2008-04-05 17:57 --------- d-----w C:\Program Files\Google
2008-04-05 16:08 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-04-05 16:07 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-05 15:58 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-04-05 14:42 --------- d-----w C:\Program Files\IBM
2008-04-05 00:48 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-02 11:27 --------- d-----w C:\Program Files\Alwil Software
2008-03-22 07:45 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Readme test meow
2008-02-27 08:28 --------- d-----w C:\Program Files\Windows Live
2008-02-23 02:38 43,872 ------w C:\WINDOWS\system32\drivers\pxhelp20.sys
2008-02-19 20:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-02-10 20:07 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-02-10 20:07 --------- d-----w C:\Program Files\eMule
2008-02-10 19:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-10 19:44 --------- d-----w C:\Program Files\FranceTelecomUninstall
2008-02-10 19:40 --------- d-----w C:\Program Files\PeerGuardian2
2008-02-10 17:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-10 17:38 --------- d-----w C:\Program Files\Lavasoft
2008-02-10 17:37 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-02-10 17:28 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-10 17:08 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-02-10 15:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\LICENSE FORD HOPE DRAW
2008-02-10 15:06 --------- d-----w C:\Program Files\Logitech
2008-02-01 10:17 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
.
((((((((((((((((((((((((((((( snapshot@2008-04-06_18.30.36.68 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-04-06 08:18:57 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-04-06 17:41:03 7,995,392 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0[/u]0000001\ntuser.dat
+ 2008-04-06 17:41:03 262,144 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0[/u]0000002\UsrClass.dat
+ 2008-04-06 08:18:57 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-04-06 17:40:51 7,995,392 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\[u]0[/u]0000001\ntuser.dat
+ 2008-04-06 17:40:51 262,144 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\[u]0[/u]0000002\UsrClass.dat
+ 2008-04-06 18:34:29 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_684.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{68CB3332-B0F5-4DD4-B213-7E423BE033F0}]
C:\WINDOWS\system32\awvtu.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7BB21C6E-3DEB-7C31-F9CC-CD09BBB3AC6A}]
C:\DOCUME~1\admin\APPLIC~1\AMENJU~1\onenew.exe
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9E7A65D5-AD83-42E9-A906-6ACE19B3816F}]
C:\WINDOWS\system32\pmnli.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 01:09 15360]
"RayV"="C:\Program Files\RayV\RayV\RayV.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="irprops.cpl" [2004-08-20 01:10 380928 C:\WINDOWS\system32\irprops.cpl]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-07-10 14:25 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-07-10 14:13 114688]
"PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 18:24 86016]
"BigDogPath"="C:\WINDOWS\VM_STI.exe" [2004-06-09 09:37 40960]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 15:49 1121280]
"WorksFUD"="C:\Program Files\Microsoft Works\wkfud.exe" [2000-07-12 12:59 24576]
"Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [2000-07-12 14:14 311350]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-08-04 03:01 28739]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 19:37 79224]
"BM6327bf40"="C:\WINDOWS\system32\tmqsiwun.dll" [ ]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-20 01:09 15360]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Rappels du Calendrier Microsoft Works.lnk - C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\wkcalrem.exe [2000-07-12 14:14:38 24633]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljhggf]
mljhggf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqnnnk]
urqnnnk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSVideo8"= VfWWDM32.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lqu40.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Sxd15.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
S0 Lqu40;Lqu40;C:\WINDOWS\system32\Drivers\Lqu40.sys []
S0 Sxd15;Sxd15;C:\WINDOWS\system32\Drivers\Sxd15.sys []
S3 k600bus;Sony Ericsson 600i driver (WDM);C:\WINDOWS\system32\DRIVERS\k600bus.sys [2005-03-04 19:08]
S3 k600mdfl;Sony Ericsson 600i USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k600mdfl.sys [2005-03-04 19:11]
S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\k600mdm.sys [2005-03-04 19:11]
S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\k600mgmt.sys [2005-03-04 19:13]
S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\k600obex.sys [2005-03-04 19:15]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-04 06:58]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 08:08]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9f092bd8-cdcf-11dc-8939-000d6027301a}]
\Shell\AutoRun\command - E:\InstallTomTomHOME.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-06 22:09:03
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-04-06 22:12:43
ComboFix-quarantined-files.txt 2008-04-06 20:12:35
ComboFix2.txt 2008-04-06 16:31:19
ComboFix3.txt 2008-04-06 16:18:52
Pre-Run: 18,352,168,960 octets libres
Post-Run: 18,348,208,128 octets libres
.
2008-04-06 10:24:28 --- E O F ---
Merci beaucoup de m'aider ;-)
ComboFix 08-04-04.1 - admin 2008-04-06 22:05:21.4 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.46 [GMT 2:00]
Endroit: C:\Documents and Settings\admin\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\admin\Bureau\CFScript.txt
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.
((((((((((((((((((((((((((((( Fichiers créés 2008-03-06 to 2008-04-06 ))))))))))))))))))))))))))))))))))))
.
2008-04-06 19:40 . 2008-04-06 19:40 <REP> d-------- C:\WINDOWS\ERUNT
2008-04-06 19:34 . 2008-04-06 10:24 <REP> d-------- C:\SDFix
2008-04-06 18:55 . 2008-04-06 18:55 <REP> d-------- C:\VundoFix Backups
2008-04-06 17:51 . 2008-04-06 17:51 <REP> d-------- C:\Program Files\Trend Micro
2008-04-06 13:54 . 2008-04-06 13:54 <REP> d-------- C:\Documents and Settings\admin\Application Data\Grisoft
2008-04-06 13:54 . 2007-05-30 14:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-04-06 01:25 . 2008-04-06 12:33 1,744 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-06 00:47 . 2008-04-06 00:47 230 --a------ C:\WINDOWS\system32\spupdsvc.inf
2008-04-06 00:41 . 2008-04-06 00:50 <REP> d-------- C:\WINDOWS\SxsCaPendDel
2008-04-06 00:32 . 2008-04-06 00:32 121 --a------ C:\WINDOWS\bdagent.INI
2008-04-06 00:11 . 2008-04-06 13:28 <REP> d-------- C:\Program Files\Navilog1
2008-04-05 20:41 . 2008-04-05 20:41 <REP> d-------- C:\Program Files\BitDefender
2008-04-05 20:39 . 2008-04-05 20:42 <REP> d-------- C:\Program Files\Fichiers communs\BitDefender
2008-04-05 18:24 . 2008-04-05 18:25 <REP> d-------- C:\Documents and Settings\admin\Application Data\AVG7
2008-04-05 18:23 . 2008-04-05 18:23 <REP> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-04-05 18:22 . 2008-04-05 19:55 <REP> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-04-05 17:10 . 2008-04-05 17:10 3,120 --a------ C:\WINDOWS\system32\118290.54
2008-04-05 17:10 . 2008-04-05 17:10 3,120 --a------ C:\WINDOWS\118294.78
2008-04-05 17:09 . 1996-08-20 20:37 15,840 --a------ C:\WINDOWS\system32\Machnm1.exe
2008-04-05 17:09 . 2005-09-25 16:37 5,632 --a------ C:\WINDOWS\system32\Machnm64.sys
2008-04-05 17:09 . 2003-08-13 00:27 2,304 --a------ C:\WINDOWS\system32\Machnm32.sys
2008-04-05 16:38 . 2008-04-05 16:38 <REP> d-------- C:\WINDOWS\system32\save$$updater
2008-04-05 15:40 . 2008-04-05 20:47 <REP> d-------- C:\Program Files\Fichiers communs\Symantec Shared
2008-04-05 15:28 . 2006-10-05 04:42 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-04-05 15:28 . 2006-10-05 04:42 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-04-05 15:27 . 2008-04-05 15:28 <REP> d-------- C:\Program Files\Picasa2
2008-04-05 13:52 . 2008-04-05 20:03 <REP> d-------- C:\Program Files\MSNFix
2008-04-05 02:32 . 2008-04-05 02:38 <REP> d-------- C:\Program Files\Spyware Doctor
2008-04-05 02:32 . 2008-04-05 02:32 <REP> d-------- C:\Documents and Settings\admin\Application Data\PC Tools
2008-04-05 02:32 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-04-05 02:32 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-04-05 02:32 . 2008-02-01 12:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-04-05 02:32 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-04-04 18:07 . 2005-09-23 07:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2008-04-04 16:47 . 2008-04-04 16:47 <REP> dr------- C:\Documents and Settings\LocalService\Favoris
2008-04-03 20:19 . 2008-04-05 04:15 <REP> d-------- C:\Program Files\a-squared Free
2008-04-02 14:50 . 2008-04-05 19:54 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-02 13:28 . 2008-03-29 19:45 1,146,232 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-04-02 13:28 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-04-02 13:28 . 2008-03-29 19:23 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-04-02 13:28 . 2008-03-29 19:35 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-04-02 13:28 . 2008-01-17 17:34 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-04-02 13:28 . 2008-03-29 19:31 75,856 --a------ C:\WINDOWS\system32\drivers\aswSP.sys
2008-04-02 13:28 . 2008-03-29 19:27 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-04-02 13:28 . 2008-03-29 19:26 26,944 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-04-02 13:28 . 2008-03-29 19:29 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-04-02 13:28 . 2008-03-29 19:35 20,560 --a------ C:\WINDOWS\system32\drivers\aswFsBlk.sys
2008-04-02 01:32 . 2008-04-02 01:31 361,984 --a------ C:\WINDOWS\system32\spolsv.exe
2008-03-23 15:19 . 2008-03-27 15:20 5,034 ---hs---- C:\WINDOWS\system32\eguncsfg.ini
2008-03-23 09:47 . 2008-03-23 15:11 4,734 ---hs---- C:\WINDOWS\system32\svsiriug.ini
2008-03-22 10:20 . 2008-03-23 09:39 4,614 ---hs---- C:\WINDOWS\system32\xtnlgoci.ini
2008-03-22 10:14 . 2008-03-22 10:14 26,132 --a------ C:\WINDOWS\system32\byyevxc.exe
2008-03-21 14:02 . 2008-03-22 10:12 4,494 ---hs---- C:\WINDOWS\system32\uuiotppl.ini
2008-03-19 20:49 . 2008-03-21 13:54 4,374 ---hs---- C:\WINDOWS\system32\ebgcyuqc.ini
2008-03-18 20:43 . 2008-03-19 20:44 4,254 ---hs---- C:\WINDOWS\system32\lmomujxt.ini
2008-03-17 19:00 . 2008-03-18 20:41 4,194 ---hs---- C:\WINDOWS\system32\koxjcext.ini
2008-03-16 19:01 . 2008-03-16 19:01 4,134 ---hs---- C:\WINDOWS\system32\kcqfuhub.ini
2008-03-16 18:50 . 2008-03-16 18:50 26,611 --a------ C:\WINDOWS\system32\caczjfcl.exe
2008-03-12 16:58 . 2008-03-12 16:58 26,611 --a------ C:\WINDOWS\system32\kiydthcyt.exe
2008-03-12 16:53 . 2008-03-12 16:53 217 --a------ C:\WINDOWS\system32\MRT.INI
2008-03-12 13:32 . 2008-03-23 13:55 26,132 --a------ C:\WINDOWS\system32\mjcscij.exe
2008-03-12 01:21 . 2008-03-12 13:28 3,654 ---hs---- C:\WINDOWS\system32\pherjlnh.ini
2008-03-11 01:19 . 2008-03-12 01:19 3,534 ---hs---- C:\WINDOWS\system32\mwegjbkk.ini
2008-03-10 01:20 . 2008-03-10 21:09 3,474 ---hs---- C:\WINDOWS\system32\ccnntsoe.ini
2008-03-10 00:20 . 2008-03-10 00:20 3,354 ---hs---- C:\WINDOWS\system32\txkxtcir.ini
2008-03-09 00:17 . 2008-03-10 00:17 3,294 ---hs---- C:\WINDOWS\system32\mfoyvvwy.ini
2008-03-08 00:12 . 2008-03-09 00:13 3,234 ---hs---- C:\WINDOWS\system32\qjhycpnn.ini
2008-03-07 21:42 . 2008-03-07 21:42 3,174 ---hs---- C:\WINDOWS\system32\buhdvlqr.ini
2008-03-07 00:45 . 2008-03-27 14:01 26,132 --a------ C:\WINDOWS\system32\pggldh.exe
2008-03-06 21:45 . 2008-03-06 21:45 3,114 ---hs---- C:\WINDOWS\system32\canoecgc.ini
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-06 20:02 --------- d-----w C:\Documents and Settings\admin\Application Data\OpenOffice.org2
2008-04-05 17:57 --------- d-----w C:\Program Files\Google
2008-04-05 16:08 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-04-05 16:07 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-05 15:58 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-04-05 14:42 --------- d-----w C:\Program Files\IBM
2008-04-05 00:48 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-02 11:27 --------- d-----w C:\Program Files\Alwil Software
2008-03-22 07:45 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Readme test meow
2008-02-27 08:28 --------- d-----w C:\Program Files\Windows Live
2008-02-23 02:38 43,872 ------w C:\WINDOWS\system32\drivers\pxhelp20.sys
2008-02-19 20:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-02-10 20:07 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-02-10 20:07 --------- d-----w C:\Program Files\eMule
2008-02-10 19:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-10 19:44 --------- d-----w C:\Program Files\FranceTelecomUninstall
2008-02-10 19:40 --------- d-----w C:\Program Files\PeerGuardian2
2008-02-10 17:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-10 17:38 --------- d-----w C:\Program Files\Lavasoft
2008-02-10 17:37 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-02-10 17:28 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-10 17:08 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-02-10 15:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\LICENSE FORD HOPE DRAW
2008-02-10 15:06 --------- d-----w C:\Program Files\Logitech
2008-02-01 10:17 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
.
((((((((((((((((((((((((((((( snapshot@2008-04-06_18.30.36.68 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-04-06 08:18:57 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-04-06 17:41:03 7,995,392 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0[/u]0000001\ntuser.dat
+ 2008-04-06 17:41:03 262,144 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0[/u]0000002\UsrClass.dat
+ 2008-04-06 08:18:57 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-04-06 17:40:51 7,995,392 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\[u]0[/u]0000001\ntuser.dat
+ 2008-04-06 17:40:51 262,144 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\[u]0[/u]0000002\UsrClass.dat
+ 2008-04-06 18:34:29 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_684.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{68CB3332-B0F5-4DD4-B213-7E423BE033F0}]
C:\WINDOWS\system32\awvtu.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7BB21C6E-3DEB-7C31-F9CC-CD09BBB3AC6A}]
C:\DOCUME~1\admin\APPLIC~1\AMENJU~1\onenew.exe
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9E7A65D5-AD83-42E9-A906-6ACE19B3816F}]
C:\WINDOWS\system32\pmnli.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 01:09 15360]
"RayV"="C:\Program Files\RayV\RayV\RayV.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="irprops.cpl" [2004-08-20 01:10 380928 C:\WINDOWS\system32\irprops.cpl]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-07-10 14:25 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-07-10 14:13 114688]
"PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 18:24 86016]
"BigDogPath"="C:\WINDOWS\VM_STI.exe" [2004-06-09 09:37 40960]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 15:49 1121280]
"WorksFUD"="C:\Program Files\Microsoft Works\wkfud.exe" [2000-07-12 12:59 24576]
"Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [2000-07-12 14:14 311350]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-08-04 03:01 28739]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 19:37 79224]
"BM6327bf40"="C:\WINDOWS\system32\tmqsiwun.dll" [ ]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-20 01:09 15360]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Rappels du Calendrier Microsoft Works.lnk - C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\wkcalrem.exe [2000-07-12 14:14:38 24633]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljhggf]
mljhggf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqnnnk]
urqnnnk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSVideo8"= VfWWDM32.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lqu40.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Sxd15.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
S0 Lqu40;Lqu40;C:\WINDOWS\system32\Drivers\Lqu40.sys []
S0 Sxd15;Sxd15;C:\WINDOWS\system32\Drivers\Sxd15.sys []
S3 k600bus;Sony Ericsson 600i driver (WDM);C:\WINDOWS\system32\DRIVERS\k600bus.sys [2005-03-04 19:08]
S3 k600mdfl;Sony Ericsson 600i USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k600mdfl.sys [2005-03-04 19:11]
S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\k600mdm.sys [2005-03-04 19:11]
S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\k600mgmt.sys [2005-03-04 19:13]
S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\k600obex.sys [2005-03-04 19:15]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-04 06:58]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 08:08]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9f092bd8-cdcf-11dc-8939-000d6027301a}]
\Shell\AutoRun\command - E:\InstallTomTomHOME.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-06 22:09:03
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-04-06 22:12:43
ComboFix-quarantined-files.txt 2008-04-06 20:12:35
ComboFix2.txt 2008-04-06 16:31:19
ComboFix3.txt 2008-04-06 16:18:52
Pre-Run: 18,352,168,960 octets libres
Post-Run: 18,348,208,128 octets libres
.
2008-04-06 10:24:28 --- E O F ---
Merci beaucoup de m'aider ;-)
tu as raison, mais le fix n'a pas fonctionnait apparemment ...
tant pie, on va faire autrement :
télécharge OTMoveIt (de Old_Timer) sur ton Bureau :
http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
double-clique sur OTMoveIt.exe pour le lancer.
copie la liste qui se trouve en gras ci-dessous,
et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.
C:\WINDOWS\system32\spolsv.exe
C:\WINDOWS\system32\eguncsfg.ini
C:\WINDOWS\system32\svsiriug.ini
C:\WINDOWS\system32\xtnlgoci.ini
C:\WINDOWS\system32\byyevxc.exe
C:\WINDOWS\system32\uuiotppl.ini
C:\WINDOWS\system32\ebgcyuqc.ini
C:\WINDOWS\system32\lmomujxt.ini
C:\WINDOWS\system32\koxjcext.ini
C:\WINDOWS\system32\kcqfuhub.ini
C:\WINDOWS\system32\caczjfcl.exe
C:\WINDOWS\system32\kiydthcyt.exe
C:\WINDOWS\system32\MRT.INI
C:\WINDOWS\system32\mjcscij.exe
C:\WINDOWS\system32\pherjlnh.ini
C:\WINDOWS\system32\mwegjbkk.ini
C:\WINDOWS\system32\ccnntsoe.ini
C:\WINDOWS\system32\txkxtcir.ini
C:\WINDOWS\system32\mfoyvvwy.ini
C:\WINDOWS\system32\qjhycpnn.ini
C:\WINDOWS\system32\buhdvlqr.ini
C:\WINDOWS\system32\pggldh.exe
C:\WINDOWS\system32\canoecgc.in
C:\WINDOWS\system32\tmqsiwun.dll"
C:\WINDOWS\system32\awvtu.dll
C:\DOCUME~1\admin\APPLIC~1\AMENJU~1\onenew.exe
C:\WINDOWS\system32\pmnli.dll
C:\WINDOWS\system32\mljhggf.dll
C:\WINDOWS\system32\urqnnnk.dll
clique sur MoveIt! pour lancer la suppression.
le résultat apparaitra dans le cadre Results.
clique sur Exit pour fermer.
poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
il te sera peut-être demander de redémarrer le pc pour achever la suppression.
si c'est le cas accepte par Yes.
++
tant pie, on va faire autrement :
télécharge OTMoveIt (de Old_Timer) sur ton Bureau :
http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
double-clique sur OTMoveIt.exe pour le lancer.
copie la liste qui se trouve en gras ci-dessous,
et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.
C:\WINDOWS\system32\spolsv.exe
C:\WINDOWS\system32\eguncsfg.ini
C:\WINDOWS\system32\svsiriug.ini
C:\WINDOWS\system32\xtnlgoci.ini
C:\WINDOWS\system32\byyevxc.exe
C:\WINDOWS\system32\uuiotppl.ini
C:\WINDOWS\system32\ebgcyuqc.ini
C:\WINDOWS\system32\lmomujxt.ini
C:\WINDOWS\system32\koxjcext.ini
C:\WINDOWS\system32\kcqfuhub.ini
C:\WINDOWS\system32\caczjfcl.exe
C:\WINDOWS\system32\kiydthcyt.exe
C:\WINDOWS\system32\MRT.INI
C:\WINDOWS\system32\mjcscij.exe
C:\WINDOWS\system32\pherjlnh.ini
C:\WINDOWS\system32\mwegjbkk.ini
C:\WINDOWS\system32\ccnntsoe.ini
C:\WINDOWS\system32\txkxtcir.ini
C:\WINDOWS\system32\mfoyvvwy.ini
C:\WINDOWS\system32\qjhycpnn.ini
C:\WINDOWS\system32\buhdvlqr.ini
C:\WINDOWS\system32\pggldh.exe
C:\WINDOWS\system32\canoecgc.in
C:\WINDOWS\system32\tmqsiwun.dll"
C:\WINDOWS\system32\awvtu.dll
C:\DOCUME~1\admin\APPLIC~1\AMENJU~1\onenew.exe
C:\WINDOWS\system32\pmnli.dll
C:\WINDOWS\system32\mljhggf.dll
C:\WINDOWS\system32\urqnnnk.dll
clique sur MoveIt! pour lancer la suppression.
le résultat apparaitra dans le cadre Results.
clique sur Exit pour fermer.
poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
il te sera peut-être demander de redémarrer le pc pour achever la suppression.
si c'est le cas accepte par Yes.
++
Ca ne me fait rien du tout, je comprends pas trop ! J'ai même pas la demande pour redémarrer le pc et puis dans les résultats ça marque Succelly et no found sur certains fichiers, je suis pas trop doué en anglais désolé :-)
redemarre le pc : ensuite va dans demarrer < poste de travail < disque locale C:\ < dans le dossier OTMoveIt poste le fichier nommé MovedFiles.
@+
@+
C:\WINDOWS\system32\spolsv.exe moved successfully.
C:\WINDOWS\system32\eguncsfg.ini moved successfully.
C:\WINDOWS\system32\svsiriug.ini moved successfully.
C:\WINDOWS\system32\xtnlgoci.ini moved successfully.
C:\WINDOWS\system32\byyevxc.exe moved successfully.
C:\WINDOWS\system32\uuiotppl.ini moved successfully.
C:\WINDOWS\system32\ebgcyuqc.ini moved successfully.
C:\WINDOWS\system32\lmomujxt.ini moved successfully.
C:\WINDOWS\system32\koxjcext.ini moved successfully.
C:\WINDOWS\system32\kcqfuhub.ini moved successfully.
C:\WINDOWS\system32\caczjfcl.exe moved successfully.
C:\WINDOWS\system32\kiydthcyt.exe moved successfully.
C:\WINDOWS\system32\MRT.INI moved successfully.
C:\WINDOWS\system32\mjcscij.exe moved successfully.
C:\WINDOWS\system32\pherjlnh.ini moved successfully.
C:\WINDOWS\system32\mwegjbkk.ini moved successfully.
C:\WINDOWS\system32\ccnntsoe.ini moved successfully.
C:\WINDOWS\system32\txkxtcir.ini moved successfully.
C:\WINDOWS\system32\mfoyvvwy.ini moved successfully.
C:\WINDOWS\system32\qjhycpnn.ini moved successfully.
C:\WINDOWS\system32\buhdvlqr.ini moved successfully.
C:\WINDOWS\system32\pggldh.exe moved successfully.
File/Folder C:\WINDOWS\system32\canoecgc.in not found.
File/Folder C:\WINDOWS\system32\tmqsiwun.dll" not found.
File/Folder C:\WINDOWS\system32\awvtu.dll not found.
File/Folder C:\DOCUME~1\admin\APPLIC~1\AMENJU~1\onenew.exe not found.
File/Folder C:\WINDOWS\system32\pmnli.dll not found.
File/Folder C:\WINDOWS\system32\mljhggf.dll not found.
File/Folder C:\WINDOWS\system32\urqnnnk.dll not found.
OTMoveIt2 by OldTimer - Version 1.0.4.0 log created on 04062008_225210
Voilà j'ai trouvé lol ;-)
C:\WINDOWS\system32\eguncsfg.ini moved successfully.
C:\WINDOWS\system32\svsiriug.ini moved successfully.
C:\WINDOWS\system32\xtnlgoci.ini moved successfully.
C:\WINDOWS\system32\byyevxc.exe moved successfully.
C:\WINDOWS\system32\uuiotppl.ini moved successfully.
C:\WINDOWS\system32\ebgcyuqc.ini moved successfully.
C:\WINDOWS\system32\lmomujxt.ini moved successfully.
C:\WINDOWS\system32\koxjcext.ini moved successfully.
C:\WINDOWS\system32\kcqfuhub.ini moved successfully.
C:\WINDOWS\system32\caczjfcl.exe moved successfully.
C:\WINDOWS\system32\kiydthcyt.exe moved successfully.
C:\WINDOWS\system32\MRT.INI moved successfully.
C:\WINDOWS\system32\mjcscij.exe moved successfully.
C:\WINDOWS\system32\pherjlnh.ini moved successfully.
C:\WINDOWS\system32\mwegjbkk.ini moved successfully.
C:\WINDOWS\system32\ccnntsoe.ini moved successfully.
C:\WINDOWS\system32\txkxtcir.ini moved successfully.
C:\WINDOWS\system32\mfoyvvwy.ini moved successfully.
C:\WINDOWS\system32\qjhycpnn.ini moved successfully.
C:\WINDOWS\system32\buhdvlqr.ini moved successfully.
C:\WINDOWS\system32\pggldh.exe moved successfully.
File/Folder C:\WINDOWS\system32\canoecgc.in not found.
File/Folder C:\WINDOWS\system32\tmqsiwun.dll" not found.
File/Folder C:\WINDOWS\system32\awvtu.dll not found.
File/Folder C:\DOCUME~1\admin\APPLIC~1\AMENJU~1\onenew.exe not found.
File/Folder C:\WINDOWS\system32\pmnli.dll not found.
File/Folder C:\WINDOWS\system32\mljhggf.dll not found.
File/Folder C:\WINDOWS\system32\urqnnnk.dll not found.
OTMoveIt2 by OldTimer - Version 1.0.4.0 log created on 04062008_225210
Voilà j'ai trouvé lol ;-)
Excuse moi mais je ne connais pas trop les termes informatiques mdrrr désolé je suis nul je sais lol mais c'est quoi un combo ? Excuse moi et merci à toi de ta patience ! Merci vraiment :-)
ComboFix 08-04-04.1 - admin 2008-04-06 23:51:20.5 - NTFSx86
Endroit: C:\Documents and Settings\admin\Bureau\ComboFix.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.
((((((((((((((((((((((((((((( Fichiers créés 2008-03-06 to 2008-04-06 ))))))))))))))))))))))))))))))))))))
.
2008-04-06 22:52 . 2008-04-06 22:52 <REP> d-------- C:\_OTMoveIt
2008-04-06 19:40 . 2008-04-06 19:40 <REP> d-------- C:\WINDOWS\ERUNT
2008-04-06 19:34 . 2008-04-06 10:24 <REP> d-------- C:\SDFix
2008-04-06 18:55 . 2008-04-06 18:55 <REP> d-------- C:\VundoFix Backups
2008-04-06 17:51 . 2008-04-06 17:51 <REP> d-------- C:\Program Files\Trend Micro
2008-04-06 13:54 . 2008-04-06 13:54 <REP> d-------- C:\Documents and Settings\admin\Application Data\Grisoft
2008-04-06 13:54 . 2007-05-30 14:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-04-06 01:25 . 2008-04-06 12:33 1,744 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-06 00:47 . 2008-04-06 00:47 230 --a------ C:\WINDOWS\system32\spupdsvc.inf
2008-04-06 00:41 . 2008-04-06 00:50 <REP> d-------- C:\WINDOWS\SxsCaPendDel
2008-04-06 00:32 . 2008-04-06 00:32 121 --a------ C:\WINDOWS\bdagent.INI
2008-04-06 00:11 . 2008-04-06 13:28 <REP> d-------- C:\Program Files\Navilog1
2008-04-05 20:41 . 2008-04-05 20:41 <REP> d-------- C:\Program Files\BitDefender
2008-04-05 20:39 . 2008-04-05 20:42 <REP> d-------- C:\Program Files\Fichiers communs\BitDefender
2008-04-05 18:24 . 2008-04-05 18:25 <REP> d-------- C:\Documents and Settings\admin\Application Data\AVG7
2008-04-05 18:23 . 2008-04-05 18:23 <REP> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-04-05 18:22 . 2008-04-05 19:55 <REP> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-04-05 17:10 . 2008-04-05 17:10 3,120 --a------ C:\WINDOWS\system32\118290.54
2008-04-05 17:10 . 2008-04-05 17:10 3,120 --a------ C:\WINDOWS\118294.78
2008-04-05 17:09 . 1996-08-20 20:37 15,840 --a------ C:\WINDOWS\system32\Machnm1.exe
2008-04-05 17:09 . 2005-09-25 16:37 5,632 --a------ C:\WINDOWS\system32\Machnm64.sys
2008-04-05 17:09 . 2003-08-13 00:27 2,304 --a------ C:\WINDOWS\system32\Machnm32.sys
2008-04-05 16:38 . 2008-04-05 16:38 <REP> d-------- C:\WINDOWS\system32\save$$updater
2008-04-05 15:40 . 2008-04-05 20:47 <REP> d-------- C:\Program Files\Fichiers communs\Symantec Shared
2008-04-05 15:28 . 2006-10-05 04:42 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-04-05 15:28 . 2006-10-05 04:42 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-04-05 15:27 . 2008-04-05 15:28 <REP> d-------- C:\Program Files\Picasa2
2008-04-05 13:52 . 2008-04-05 20:03 <REP> d-------- C:\Program Files\MSNFix
2008-04-05 02:32 . 2008-04-05 02:38 <REP> d-------- C:\Program Files\Spyware Doctor
2008-04-05 02:32 . 2008-04-05 02:32 <REP> d-------- C:\Documents and Settings\admin\Application Data\PC Tools
2008-04-05 02:32 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-04-05 02:32 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-04-05 02:32 . 2008-02-01 12:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-04-05 02:32 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-04-04 18:07 . 2005-09-23 07:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2008-04-04 16:47 . 2008-04-04 16:47 <REP> dr------- C:\Documents and Settings\LocalService\Favoris
2008-04-03 20:19 . 2008-04-05 04:15 <REP> d-------- C:\Program Files\a-squared Free
2008-04-02 14:50 . 2008-04-05 19:54 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-02 13:28 . 2008-03-29 19:45 1,146,232 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-04-02 13:28 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-04-02 13:28 . 2008-03-29 19:23 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-04-02 13:28 . 2008-03-29 19:35 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-04-02 13:28 . 2008-01-17 17:34 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-04-02 13:28 . 2008-03-29 19:31 75,856 --a------ C:\WINDOWS\system32\drivers\aswSP.sys
2008-04-02 13:28 . 2008-03-29 19:27 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-04-02 13:28 . 2008-03-29 19:26 26,944 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-04-02 13:28 . 2008-03-29 19:29 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-04-02 13:28 . 2008-03-29 19:35 20,560 --a------ C:\WINDOWS\system32\drivers\aswFsBlk.sys
2008-03-06 21:45 . 2008-03-06 21:45 3,114 ---hs---- C:\WINDOWS\system32\canoecgc.ini
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-06 20:02 --------- d-----w C:\Documents and Settings\admin\Application Data\OpenOffice.org2
2008-04-05 17:57 --------- d-----w C:\Program Files\Google
2008-04-05 16:08 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-04-05 16:07 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-05 15:58 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-04-05 14:42 --------- d-----w C:\Program Files\IBM
2008-04-05 00:48 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-02 11:27 --------- d-----w C:\Program Files\Alwil Software
2008-03-22 07:45 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Readme test meow
2008-02-27 08:28 --------- d-----w C:\Program Files\Windows Live
2008-02-23 02:38 43,872 ------w C:\WINDOWS\system32\drivers\pxhelp20.sys
2008-02-19 20:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-02-10 20:07 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-02-10 20:07 --------- d-----w C:\Program Files\eMule
2008-02-10 19:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-10 19:44 --------- d-----w C:\Program Files\FranceTelecomUninstall
2008-02-10 19:40 --------- d-----w C:\Program Files\PeerGuardian2
2008-02-10 17:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-10 17:38 --------- d-----w C:\Program Files\Lavasoft
2008-02-10 17:37 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-02-10 17:28 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-10 17:08 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-02-10 15:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\LICENSE FORD HOPE DRAW
2008-02-10 15:06 --------- d-----w C:\Program Files\Logitech
2008-02-01 10:17 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
.
((((((((((((((((((((((((((((( snapshot@2008-04-06_18.30.36.68 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-04-06 08:18:57 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-04-06 17:41:03 7,995,392 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0[/u]0000001\ntuser.dat
+ 2008-04-06 17:41:03 262,144 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0[/u]0000002\UsrClass.dat
+ 2008-04-06 08:18:57 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-04-06 17:40:51 7,995,392 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\[u]0[/u]0000001\ntuser.dat
+ 2008-04-06 17:40:51 262,144 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\[u]0[/u]0000002\UsrClass.dat
+ 2008-04-06 21:18:00 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_640.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{68CB3332-B0F5-4DD4-B213-7E423BE033F0}]
C:\WINDOWS\system32\awvtu.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7BB21C6E-3DEB-7C31-F9CC-CD09BBB3AC6A}]
C:\DOCUME~1\admin\APPLIC~1\AMENJU~1\onenew.exe
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9E7A65D5-AD83-42E9-A906-6ACE19B3816F}]
C:\WINDOWS\system32\pmnli.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 01:09 15360]
"RayV"="C:\Program Files\RayV\RayV\RayV.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="irprops.cpl" [2004-08-20 01:10 380928 C:\WINDOWS\system32\irprops.cpl]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-07-10 14:25 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-07-10 14:13 114688]
"PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 18:24 86016]
"BigDogPath"="C:\WINDOWS\VM_STI.exe" [2004-06-09 09:37 40960]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 15:49 1121280]
"WorksFUD"="C:\Program Files\Microsoft Works\wkfud.exe" [2000-07-12 12:59 24576]
"Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [2000-07-12 14:14 311350]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-08-04 03:01 28739]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 19:37 79224]
"BM6327bf40"="C:\WINDOWS\system32\tmqsiwun.dll" [ ]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-20 01:09 15360]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Rappels du Calendrier Microsoft Works.lnk - C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\wkcalrem.exe [2000-07-12 14:14:38 24633]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljhggf]
mljhggf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqnnnk]
urqnnnk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSVideo8"= VfWWDM32.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lqu40.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Sxd15.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
S0 Lqu40;Lqu40;C:\WINDOWS\system32\Drivers\Lqu40.sys []
S0 Sxd15;Sxd15;C:\WINDOWS\system32\Drivers\Sxd15.sys []
S3 k600bus;Sony Ericsson 600i driver (WDM);C:\WINDOWS\system32\DRIVERS\k600bus.sys [2005-03-04 19:08]
S3 k600mdfl;Sony Ericsson 600i USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k600mdfl.sys [2005-03-04 19:11]
S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\k600mdm.sys [2005-03-04 19:11]
S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\k600mgmt.sys [2005-03-04 19:13]
S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\k600obex.sys [2005-03-04 19:15]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-04 06:58]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 08:08]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9f092bd8-cdcf-11dc-8939-000d6027301a}]
\Shell\AutoRun\command - E:\InstallTomTomHOME.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-06 23:55:44
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-04-06 23:59:22
ComboFix-quarantined-files.txt 2008-04-06 21:59:14
ComboFix2.txt 2008-04-06 20:12:45
ComboFix3.txt 2008-04-06 16:31:19
ComboFix4.txt 2008-04-06 16:18:52
Pre-Run: 18,368,385,024 octets libres
Post-Run: 18,355,290,112 octets libres
.
2008-04-06 10:24:28 --- E O F ---
Donc voilà :-)
Endroit: C:\Documents and Settings\admin\Bureau\ComboFix.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.
((((((((((((((((((((((((((((( Fichiers créés 2008-03-06 to 2008-04-06 ))))))))))))))))))))))))))))))))))))
.
2008-04-06 22:52 . 2008-04-06 22:52 <REP> d-------- C:\_OTMoveIt
2008-04-06 19:40 . 2008-04-06 19:40 <REP> d-------- C:\WINDOWS\ERUNT
2008-04-06 19:34 . 2008-04-06 10:24 <REP> d-------- C:\SDFix
2008-04-06 18:55 . 2008-04-06 18:55 <REP> d-------- C:\VundoFix Backups
2008-04-06 17:51 . 2008-04-06 17:51 <REP> d-------- C:\Program Files\Trend Micro
2008-04-06 13:54 . 2008-04-06 13:54 <REP> d-------- C:\Documents and Settings\admin\Application Data\Grisoft
2008-04-06 13:54 . 2007-05-30 14:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-04-06 01:25 . 2008-04-06 12:33 1,744 --a------ C:\WINDOWS\system32\tmp.reg
2008-04-06 00:47 . 2008-04-06 00:47 230 --a------ C:\WINDOWS\system32\spupdsvc.inf
2008-04-06 00:41 . 2008-04-06 00:50 <REP> d-------- C:\WINDOWS\SxsCaPendDel
2008-04-06 00:32 . 2008-04-06 00:32 121 --a------ C:\WINDOWS\bdagent.INI
2008-04-06 00:11 . 2008-04-06 13:28 <REP> d-------- C:\Program Files\Navilog1
2008-04-05 20:41 . 2008-04-05 20:41 <REP> d-------- C:\Program Files\BitDefender
2008-04-05 20:39 . 2008-04-05 20:42 <REP> d-------- C:\Program Files\Fichiers communs\BitDefender
2008-04-05 18:24 . 2008-04-05 18:25 <REP> d-------- C:\Documents and Settings\admin\Application Data\AVG7
2008-04-05 18:23 . 2008-04-05 18:23 <REP> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-04-05 18:22 . 2008-04-05 19:55 <REP> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-04-05 17:10 . 2008-04-05 17:10 3,120 --a------ C:\WINDOWS\system32\118290.54
2008-04-05 17:10 . 2008-04-05 17:10 3,120 --a------ C:\WINDOWS\118294.78
2008-04-05 17:09 . 1996-08-20 20:37 15,840 --a------ C:\WINDOWS\system32\Machnm1.exe
2008-04-05 17:09 . 2005-09-25 16:37 5,632 --a------ C:\WINDOWS\system32\Machnm64.sys
2008-04-05 17:09 . 2003-08-13 00:27 2,304 --a------ C:\WINDOWS\system32\Machnm32.sys
2008-04-05 16:38 . 2008-04-05 16:38 <REP> d-------- C:\WINDOWS\system32\save$$updater
2008-04-05 15:40 . 2008-04-05 20:47 <REP> d-------- C:\Program Files\Fichiers communs\Symantec Shared
2008-04-05 15:28 . 2006-10-05 04:42 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-04-05 15:28 . 2006-10-05 04:42 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-04-05 15:27 . 2008-04-05 15:28 <REP> d-------- C:\Program Files\Picasa2
2008-04-05 13:52 . 2008-04-05 20:03 <REP> d-------- C:\Program Files\MSNFix
2008-04-05 02:32 . 2008-04-05 02:38 <REP> d-------- C:\Program Files\Spyware Doctor
2008-04-05 02:32 . 2008-04-05 02:32 <REP> d-------- C:\Documents and Settings\admin\Application Data\PC Tools
2008-04-05 02:32 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-04-05 02:32 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-04-05 02:32 . 2008-02-01 12:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-04-05 02:32 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-04-04 18:07 . 2005-09-23 07:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2008-04-04 16:47 . 2008-04-04 16:47 <REP> dr------- C:\Documents and Settings\LocalService\Favoris
2008-04-03 20:19 . 2008-04-05 04:15 <REP> d-------- C:\Program Files\a-squared Free
2008-04-02 14:50 . 2008-04-05 19:54 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-02 13:28 . 2008-03-29 19:45 1,146,232 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-04-02 13:28 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-04-02 13:28 . 2008-03-29 19:23 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-04-02 13:28 . 2008-03-29 19:35 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-04-02 13:28 . 2008-01-17 17:34 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-04-02 13:28 . 2008-03-29 19:31 75,856 --a------ C:\WINDOWS\system32\drivers\aswSP.sys
2008-04-02 13:28 . 2008-03-29 19:27 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-04-02 13:28 . 2008-03-29 19:26 26,944 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-04-02 13:28 . 2008-03-29 19:29 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-04-02 13:28 . 2008-03-29 19:35 20,560 --a------ C:\WINDOWS\system32\drivers\aswFsBlk.sys
2008-03-06 21:45 . 2008-03-06 21:45 3,114 ---hs---- C:\WINDOWS\system32\canoecgc.ini
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-06 20:02 --------- d-----w C:\Documents and Settings\admin\Application Data\OpenOffice.org2
2008-04-05 17:57 --------- d-----w C:\Program Files\Google
2008-04-05 16:08 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-04-05 16:07 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-05 15:58 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-04-05 14:42 --------- d-----w C:\Program Files\IBM
2008-04-05 00:48 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-02 11:27 --------- d-----w C:\Program Files\Alwil Software
2008-03-22 07:45 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Readme test meow
2008-02-27 08:28 --------- d-----w C:\Program Files\Windows Live
2008-02-23 02:38 43,872 ------w C:\WINDOWS\system32\drivers\pxhelp20.sys
2008-02-19 20:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-02-10 20:07 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-02-10 20:07 --------- d-----w C:\Program Files\eMule
2008-02-10 19:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-10 19:44 --------- d-----w C:\Program Files\FranceTelecomUninstall
2008-02-10 19:40 --------- d-----w C:\Program Files\PeerGuardian2
2008-02-10 17:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-10 17:38 --------- d-----w C:\Program Files\Lavasoft
2008-02-10 17:37 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-02-10 17:28 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-10 17:08 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-02-10 15:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\LICENSE FORD HOPE DRAW
2008-02-10 15:06 --------- d-----w C:\Program Files\Logitech
2008-02-01 10:17 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
.
((((((((((((((((((((((((((((( snapshot@2008-04-06_18.30.36.68 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-04-06 08:18:57 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-04-06 17:41:03 7,995,392 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0[/u]0000001\ntuser.dat
+ 2008-04-06 17:41:03 262,144 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0[/u]0000002\UsrClass.dat
+ 2008-04-06 08:18:57 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-04-06 17:40:51 7,995,392 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\[u]0[/u]0000001\ntuser.dat
+ 2008-04-06 17:40:51 262,144 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\[u]0[/u]0000002\UsrClass.dat
+ 2008-04-06 21:18:00 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_640.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{68CB3332-B0F5-4DD4-B213-7E423BE033F0}]
C:\WINDOWS\system32\awvtu.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{7BB21C6E-3DEB-7C31-F9CC-CD09BBB3AC6A}]
C:\DOCUME~1\admin\APPLIC~1\AMENJU~1\onenew.exe
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9E7A65D5-AD83-42E9-A906-6ACE19B3816F}]
C:\WINDOWS\system32\pmnli.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 01:09 15360]
"RayV"="C:\Program Files\RayV\RayV\RayV.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BluetoothAuthenticationAgent"="irprops.cpl" [2004-08-20 01:10 380928 C:\WINDOWS\system32\irprops.cpl]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-07-10 14:25 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-07-10 14:13 114688]
"PRONoMgr.exe"="C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe" [2003-03-11 18:24 86016]
"BigDogPath"="C:\WINDOWS\VM_STI.exe" [2004-06-09 09:37 40960]
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 15:49 1121280]
"WorksFUD"="C:\Program Files\Microsoft Works\wkfud.exe" [2000-07-12 12:59 24576]
"Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [2000-07-12 14:14 311350]
"Microsoft Works Update Detection"="C:\Program Files\Microsoft Works\WkDetect.exe" [2000-08-04 03:01 28739]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-03-29 19:37 79224]
"BM6327bf40"="C:\WINDOWS\system32\tmqsiwun.dll" [ ]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-20 01:09 15360]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Rappels du Calendrier Microsoft Works.lnk - C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\wkcalrem.exe [2000-07-12 14:14:38 24633]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljhggf]
mljhggf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqnnnk]
urqnnnk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSVideo8"= VfWWDM32.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lqu40.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Sxd15.sys]
@="Driver"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
S0 Lqu40;Lqu40;C:\WINDOWS\system32\Drivers\Lqu40.sys []
S0 Sxd15;Sxd15;C:\WINDOWS\system32\Drivers\Sxd15.sys []
S3 k600bus;Sony Ericsson 600i driver (WDM);C:\WINDOWS\system32\DRIVERS\k600bus.sys [2005-03-04 19:08]
S3 k600mdfl;Sony Ericsson 600i USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k600mdfl.sys [2005-03-04 19:11]
S3 k600mdm;Sony Ericsson 600i USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\k600mdm.sys [2005-03-04 19:11]
S3 k600mgmt;Sony Ericsson 600i USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\k600mgmt.sys [2005-03-04 19:13]
S3 k600obex;Sony Ericsson 600i USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\k600obex.sys [2005-03-04 19:15]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-04 06:58]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 08:08]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9f092bd8-cdcf-11dc-8939-000d6027301a}]
\Shell\AutoRun\command - E:\InstallTomTomHOME.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-06 23:55:44
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-04-06 23:59:22
ComboFix-quarantined-files.txt 2008-04-06 21:59:14
ComboFix2.txt 2008-04-06 20:12:45
ComboFix3.txt 2008-04-06 16:31:19
ComboFix4.txt 2008-04-06 16:18:52
Pre-Run: 18,368,385,024 octets libres
Post-Run: 18,355,290,112 octets libres
.
2008-04-06 10:24:28 --- E O F ---
Donc voilà :-)