J'ai 45logiciel espions!!!! - Page 2

Précédent
  • 1
  • 2
  1. Utilisateur anonyme
     
    Bon Okay sa fait plaisir de pas se fair insulter... La c'est la galere t'a msn ?
    0
  2. h3r3sia
     
    ComboFix 08-04-24.1 - mamoure 2008-04-25 22:14:43.1 - NTFSx86
    Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.838 [GMT 2:00]
    Endroit: C:\Users\mamoure\Desktop\ComboFix.exe
    * Création d'un nouveau point de restauration
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Program Files\messengerskinner
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MessengerSkinner
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MessengerSkinner\Conditions générales.url
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MessengerSkinner\Confidentialité.url
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MessengerSkinner\Désinstaller.lnk
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MessengerSkinner\MessengerSkinner.lnk
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MessengerSkinner\Website.url
    c:\Users\mamoure\AppData\Local\ghaaca.dat
    c:\users\mamoure\appdata\local\ghaaca.exe
    c:\Users\mamoure\AppData\Local\ghaaca_nav.dat
    C:\Users\mamoure\AppData\Local\ghaaca_navps.dat

    .
    ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-03-25 to 2008-04-25 ))))))))))))))))))))))))))))))))))))
    .

    2008-04-25 22:19 . 2008-04-25 22:19 0 --ahs---- C:\Users\mamoure\NTUSER.DAT{3a539870-6a70-11db-887c-d362bd253390}.TxR.blf
    2008-04-25 22:19 . 2008-04-25 22:19 0 --ahs---- C:\Users\mamoure\NTUSER.DAT{3a539870-6a70-11db-887c-d362bd253390}.TxR.2.regtrans-ms
    2008-04-25 22:19 . 2008-04-25 22:19 0 --ahs---- C:\Users\mamoure\NTUSER.DAT{3a539870-6a70-11db-887c-d362bd253390}.TxR.1.regtrans-ms
    2008-04-25 22:19 . 2008-04-25 22:19 0 --ahs---- C:\Users\mamoure\NTUSER.DAT{3a539870-6a70-11db-887c-d362bd253390}.TxR.0.regtrans-ms
    2008-04-25 21:56 . 2008-04-25 21:56 <REP> d-------- C:\Program Files\Navilog1
    2008-04-25 15:47 . 2008-04-25 15:47 1,296 --a------ C:\Windows\wininit.ini
    2008-04-25 15:21 . 2008-04-25 22:21 <REP> d-------- C:\Users\All Users\Spybot - Search & Destroy
    2008-04-25 15:21 . 2008-04-25 22:21 <REP> d-------- C:\ProgramData\Spybot - Search & Destroy
    2008-04-25 15:21 . 2008-04-25 15:21 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
    2008-04-09 16:14 . 2008-04-09 16:14 944,184 --a------ C:\Windows\System32\winload.exe
    2008-04-09 16:14 . 2008-04-09 16:14 620,088 --a------ C:\Windows\System32\ci.dll
    2008-04-09 16:14 . 2008-04-09 16:14 371,712 --a------ C:\Windows\System32\srcore.dll
    2008-04-09 16:14 . 2008-04-09 16:14 313,856 --a------ C:\Windows\System32\rstrui.exe
    2008-04-09 16:14 . 2008-04-09 16:14 40,960 --a------ C:\Windows\System32\srclient.dll
    2008-04-09 16:14 . 2008-04-09 16:14 19,000 --a------ C:\Windows\System32\kd1394.dll
    2008-04-09 16:14 . 2008-04-09 16:14 16,384 --a------ C:\Windows\System32\srdelayed.exe
    2008-04-09 16:14 . 2008-04-09 16:14 7,168 --a------ C:\Windows\System32\f3ahvoas.dll
    2008-04-09 16:14 . 2008-04-09 16:14 6,656 --a------ C:\Windows\System32\kbd106n.dll
    2008-04-09 16:13 . 2008-04-09 16:13 2,027,008 --a------ C:\Windows\System32\win32k.sys
    2008-04-09 16:13 . 2008-04-09 16:13 296,448 --a------ C:\Windows\System32\gdi32.dll
    2008-04-09 16:11 . 2008-04-09 16:11 83,968 --a------ C:\Windows\System32\dnsrslvr.dll
    2008-04-09 16:11 . 2008-04-09 16:11 24,576 --a------ C:\Windows\System32\dnscacheugc.exe
    2008-04-07 17:59 . 2008-04-07 17:59 <REP> d-------- C:\Users\All Users\Google
    2008-04-07 17:58 . 2008-04-07 17:58 0 --a------ C:\Windows\nsreg.dat
    2008-04-05 13:46 . 2008-04-05 13:47 <REP> d-------- C:\Program Files\PacificPoker4
    2008-04-04 21:46 . 2008-04-04 21:46 <REP> d-------- C:\Users\All Users\Okay meta anti lite
    2008-04-04 21:46 . 2008-04-04 21:46 <REP> d-------- C:\ProgramData\Okay meta anti lite
    2008-04-04 21:45 . 2008-04-04 21:46 <REP> d-------- C:\Users\All Users\The Send
    2008-04-04 21:45 . 2008-04-04 21:46 <REP> d-------- C:\ProgramData\The Send
    2008-04-04 21:45 . 2008-04-04 21:45 <REP> d-------- C:\Program Files\Circle Developement
    2008-04-04 19:47 . 2008-04-04 19:47 <REP> d-------- C:\Program Files\Atari
    2008-04-03 16:09 . 2008-04-03 16:09 <REP> d-------- C:\Users\mamoure\AppData\Roaming\Template
    2008-04-03 16:09 . 2008-04-14 13:57 182 --a------ C:\Users\mamoure\AppData\Roaming\wklnhst.dat
    2008-03-27 23:28 . 2008-03-28 18:47 <REP> d-a------ C:\Users\All Users\TEMP
    2008-03-27 23:28 . 2008-03-27 23:28 <REP> d-------- C:\Users\All Users\Oberon
    2008-03-27 23:28 . 2008-03-28 18:47 <REP> d-a------ C:\ProgramData\TEMP
    2008-03-27 23:28 . 2008-03-27 23:28 <REP> d-------- C:\ProgramData\Oberon
    2008-03-27 23:28 . 2008-03-27 23:36 <REP> d-------- C:\Program Files\MSN Games

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-04-09 14:29 --------- d-----w C:\Program Files\Windows Mail
    2008-04-09 14:16 --------- d-----w C:\ProgramData\Microsoft Help
    2008-04-09 14:04 826,368 ----a-w C:\Windows\System32\wininet.dll
    2008-04-09 14:04 56,320 ----a-w C:\Windows\System32\iesetup.dll
    2008-04-09 14:04 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
    2008-04-09 14:04 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
    2008-04-04 19:45 --------- d-----w C:\Program Files\Messenger Plus! Live
    2008-04-04 17:47 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-04-04 17:45 --------- d-----w C:\Program Files\DAEMON Tools Lite
    2008-03-29 17:32 50,768 ----a-w C:\Windows\system32\drivers\aswMonFlt.sys
    2008-03-13 02:07 41,984 ----a-w C:\Windows\system32\drivers\monitor.sys
    2008-03-13 02:07 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys
    2008-03-11 16:02 --------- d-----w C:\Users\mamoure\AppData\Roaming\Ahead
    2008-03-11 15:58 --------- d-----w C:\Program Files\VistaCodecPack
    2008-03-11 14:45 --------- d-----w C:\Program Files\Common Files\Ahead
    2008-03-11 14:41 --------- d-----w C:\Program Files\Nero
    2008-03-11 14:30 --------- d-----w C:\Program Files\Microsoft Works
    2008-03-11 14:29 --------- d-----w C:\Program Files\MSBuild
    2008-03-11 14:28 --------- d-----w C:\Program Files\Microsoft.NET
    2008-03-11 14:24 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
    2008-03-11 14:15 716,272 ----a-w C:\Windows\system32\drivers\sptd.sys
    2008-03-11 14:15 --------- d-----w C:\Users\mamoure\AppData\Roaming\DAEMON Tools
    2008-03-08 23:15 --------- d-----w C:\ProgramData\Messenger Plus!
    2008-03-08 10:55 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
    2008-03-07 21:43 --------- d-----w C:\ProgramData\eMule
    2008-03-07 21:42 --------- d-----w C:\Program Files\eMule
    2008-03-07 19:02 --------- d-----w C:\Program Files\Alwil Software
    2008-03-07 18:55 --------- d-----w C:\Program Files\Common Files\Symantec Shared
    2008-03-07 18:53 --------- d-----w C:\ProgramData\Symantec
    2008-03-07 10:44 --------- d-----w C:\ProgramData\Yahoo! Companion
    2008-03-07 10:03 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
    2008-03-07 10:03 --------- d-----w C:\Program Files\Windows Live
    2008-03-07 09:56 --------- d-----w C:\ProgramData\WLInstaller
    2008-03-07 07:24 --------- d-----w C:\Program Files\Windows Sidebar
    2008-03-07 07:16 905,400 ----a-w C:\Windows\System32\winresume.exe
    2008-03-07 07:13 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
    2008-03-07 07:13 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
    2008-03-07 07:13 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
    2008-03-07 07:13 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys
    2008-03-07 07:13 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
    2008-03-07 07:13 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
    2008-03-07 07:13 15,928 ----a-w C:\Windows\system32\drivers\pciide.sys
    2008-03-07 07:13 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys
    2008-03-07 07:12 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
    2008-03-07 07:12 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
    2008-03-07 07:12 24,064 ----a-w C:\Windows\System32\netcfg.exe
    2008-03-07 07:12 223,232 ----a-w C:\Windows\System32\WMASF.DLL
    2008-03-07 07:12 22,016 ----a-w C:\Windows\System32\netiougc.exe
    2008-03-07 07:12 216,632 ----a-w C:\Windows\system32\drivers\netio.sys
    2008-03-07 07:12 2,048 ----a-w C:\Windows\System32\asferror.dll
    2008-03-07 07:12 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
    2008-03-07 07:12 1,327,104 ----a-w C:\Windows\System32\quartz.dll
    2008-03-07 07:11 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
    2008-03-07 07:11 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
    2008-03-07 07:11 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
    2008-03-07 07:11 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
    2008-03-07 07:11 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
    2008-03-07 07:11 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
    2008-03-07 07:11 11,776 ----a-w C:\Windows\System32\sbunattend.exe
    2008-03-07 07:11 1,686,528 ----a-w C:\Windows\System32\gameux.dll
    2008-03-07 07:10 84,992 ----a-w C:\Windows\system32\drivers\srvnet.sys
    2008-03-07 07:10 58,368 ----a-w C:\Windows\system32\drivers\mrxsmb20.sys
    2008-03-07 07:10 2,048 ----a-w C:\Windows\System32\tzres.dll
    2008-03-07 07:10 130,048 ----a-w C:\Windows\system32\drivers\srv2.sys
    2008-03-07 07:10 101,888 ----a-w C:\Windows\system32\drivers\mrxsmb.sys
    2008-03-07 07:08 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
    2008-03-06 22:29 966,656 ----a-w C:\Windows\System32\VSFilter.dll
    2008-03-06 22:27 80,896 ----a-w C:\Windows\System32\wudriver.dll
    2008-03-06 22:27 549,720 ----a-w C:\Windows\System32\wuapi.dll
    2008-03-06 22:27 53,080 ----a-w C:\Windows\System32\wuauclt.exe
    2008-03-06 22:27 43,352 ----a-w C:\Windows\System32\wups2.dll
    2008-03-06 22:27 33,624 ----a-w C:\Windows\System32\wups.dll
    2008-03-06 22:27 31,232 ----a-w C:\Windows\System32\wuapp.exe
    2008-03-06 22:27 163,000 ----a-w C:\Windows\System32\wuwebv.dll
    2008-03-06 22:27 1,712,984 ----a-w C:\Windows\System32\wuaueng.dll
    2008-03-06 22:27 1,524,224 ----a-w C:\Windows\System32\wucltux.dll
    2008-03-06 15:57 --------- d-----w C:\Program Files\Orange HSS
    2008-03-06 15:55 --------- d-----w C:\Program Files\Common Files\France Telecom
    2008-03-06 15:51 --------- d-----w C:\Program Files\Securitoo
    2008-03-06 15:51 --------- d-----w C:\Program Files\SAGEM
    2008-03-04 19:33 7,680 ----a-w C:\Windows\System32\ff_vfw.dll
    2007-12-03 08:28 174 --sha-w C:\Program Files\desktop.ini
    .

    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-03-07 09:11 1232896]
    "Acer Tour Reminder"="C:\Acer\AcerTour\Reminder.exe" [2007-08-01 18:30 151552]
    "EPSON Stylus DX4400 Series"="C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.exe" [2007-03-01 08:01 180736]
    "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 14:35 125440]
    "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
    "DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-02-14 01:09 486856]
    "atom poll"="C:\ProgramData\Nouncloseclose.edqur3t" [2008-04-04 21:45 159760]
    "ANTI LITE TITLE DEBUG"="C:\ProgramData\axis glue mp3.67a24" [2008-04-04 21:46 8208]
    "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-12-03 09:53 1006264]
    "ALaunch"="C:\Acer\ALaunch\AlaunchClient.exe" [2007-01-26 15:24 540672]
    "NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-10-25 17:02 86016]
    "NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-10-25 17:02 8497696]
    "NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-10-25 17:02 81920]
    "RtHDVCpl"="RtHDVCpl.exe" [2007-10-11 20:53 4702208 C:\Windows\RtHDVCpl.exe]
    "Acer Empowering Technology Monitor"="C:\Acer\Empowering Technology\SysMonitor.exe" [2007-09-07 18:23 326176]
    "eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-04-25 17:33 457216]
    "PCMMediaSharing"="C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe" [2007-06-21 19:33 204908]
    "Acer Tour"="" []
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 04:06 40048]
    "Apanel"="C:\ACERSW\config\NewSetApanel.cmd" [ ]
    "WarReg_PopUp"="C:\Acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 21:48 57344]
    "StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
    "eRecoveryService"="" []
    "NVRaidService"="C:\Windows\system32\nvraidservice.exe" [2007-09-11 15:19 187936]
    "Acer Tour Reminder"="C:\Acer\AcerTour\Reminder.exe" [2007-08-01 18:30 151552]
    "PlayMovie"="C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe" [2007-07-13 23:24 178280]
    "SystrayORAHSS"="C:\Program Files\Orange HSS\Systray\SystrayApp.exe" [2007-07-24 20:55 94208]
    "ORAHSSSessionManager"="C:\Program Files\Orange HSS\SessionManager\SessionManager.exe" [2007-07-24 20:03 102400]
    "NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 17:40 155648]

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
    Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2007-12-03 10:55:10 535336]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "msacm.mkdmp3enc"= C:\PROGRA~1\ACERAR~1\ACERDV~2\Kernel\Burner\MKDMP3Enc.ACM
    "msacm.divxa32"= divxa32.acm

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
    "{0B8DFDD6-798C-4080-A2DB-B52100AD543A}"= C:\Program Files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live
    "{DB9E81CD-E999-4D30-9431-905A8CDF3057}"= C:\Program Files\Acer Arcade Live\Acer DVDivine\Acer DVDivine.exe:Acer DVDivine
    "{FDE3C5A9-20A2-4666-80CD-094CBF37C993}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia\Acer HomeMedia.exe:Acer HomeMedia
    "{2ED47240-F206-4606-8CDA-2F141807082E}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Acer HomeMedia Connect.exe:Acer HomeMedia Connect
    "{2C6EED45-7B25-44B1-8A9A-972EFE108A9F}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.EXE:Acer HomeMedia Connect Service
    "{BA7F183C-0260-4659-8C57-3CF842FF30AA}"= C:\Program Files\Acer Arcade Live\Acer SlideShow DVD\Acer SlideShow DVD.exe:Acer SlideShow DVD
    "{C2191F0A-02E1-4345-985F-D7EB0C11AAF1}"= C:\Program Files\Acer Arcade Live\Acer VideoMagician\Acer VideoMagician.exe:Acer VideoMagician
    "{F61E8216-CE21-44D7-A083-8FD9EF88C629}"= C:\Program Files\Acer Arcade Live\Acer DV Magician\Acer DV Magician.exe:Acer DV Magician
    "{A9D2B98F-E560-4D36-B125-9AA98B475209}"= C:\Program Files\Acer Arcade Live\Acer PlayMovie\PlayMovie.exe:Acer PlayMovie
    "{5F933DEA-85DB-4599-B692-26AC6788A430}"= C:\Program Files\Acer Arcade Live\Acer PlayMovie\PMVService.exe:Acer PlayMovie Resident Program
    "{19DE8FAA-7AC2-496E-920B-9B9E3FA931D0}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
    "{C9400BED-5221-40E6-B10C-D4BEA95F02C6}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
    "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
    "C:\\Program Files\\Orange HSS\\Connectivity\\ConnectivityManager.exe"= C:\Program Files\Orange HSS\Connectivity\ConnectivityManager.exe:*:enabled:CSS

    R0 nvrd32;NVIDIA nForce RAID Driver;C:\Windows\system32\drivers\nvrd32.sys [2007-09-12 01:19]
    R0 PSDFilter;PSDFilter;C:\Windows\system32\DRIVERS\psdfilter.sys [2007-04-25 17:34]
    R0 PSDNServ;PSDNSERVER;C:\Windows\system32\drivers\PSDNServ.sys [2007-04-25 17:34]
    R0 psdvdisk;psdvdisk;C:\Windows\system32\drivers\psdvdisk.sys [2007-04-25 17:34]
    R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-03-29 19:31]
    R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};C:\Program Files\Acer Arcade Live\Acer PlayMovie\[u]0/u00.fcl [2007-08-31 16:24]
    R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;"C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe" [2007-06-21 19:33]
    R2 ALaunchService;ALaunch Service;C:\Acer\ALaunch\ALaunchSvc.exe [2007-01-26 15:24]
    R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
    R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-03-29 19:32]
    R2 eDataSecurity Service;eDSService.exe;"C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe" [2007-04-25 17:34]
    R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-07-28 09:36]
    R3 nvsmu;nvsmu;C:\Windows\system32\DRIVERS\nvsmu.sys [2007-07-07 15:13]
    R3 PCASp50;PCASp50 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCASp50.sys [2006-11-28 22:46]
    S3 PCAMp50;PCAMp50 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCAMp50.sys [2006-11-28 22:46]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ab667b43-f773-11dc-9e09-001d9246164a}]
    \shell\AutoRun\command - E:\autorun.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bf40f75c-ef75-11dc-a20e-001d9246164a}]
    \shell\AutoRun\command - E:\SETUP.EXE
    \shell\configure\command - E:\SETUP.EXE
    \shell\install\command - E:\SETUP.EXE

    .
    **************************************************************************

    catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-04-25 22:20:10
    Windows 6.0.6000 NTFS

    Balayage processus cach‚s ...

    Balayage cach‚ autostart entries ...

    Balayage des fichiers cach‚s ...

    Scan termin‚ avec succŠs
    Les fichiers cach‚s: 6

    **************************************************************************
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\Windows\System32\Ati2evxx.exe
    C:\Windows\System32\audiodg.exe
    C:\Windows\System32\Ati2evxx.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
    C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\[u]0/u\FTRTSVC.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
    C:\Windows\System32\WUDFHost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Windows\System32\conime.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    C:\Program Files\Orange HSS\Launcher\Launcher.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Windows\ehome\ehmsas.exe
    C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\[u]0/u\AlertModule.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe
    C:\Windows\System32\wbem\unsecapp.exe
    C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Program Files\Orange HSS\Connectivity\ConnectivityManager.exe
    C:\Program Files\Orange HSS\Connectivity\corecom\CoreCom.exe
    C:\Program Files\Orange HSS\Connectivity\corecom\OraConfigRecover.exe
    C:\Program Files\Common Files\France Telecom\Shared Modules\FTCOMModule\[u]0/u\FTCOMModule.exe
    C:\Windows\System32\wbem\WMIADAP.exe
    .
    **************************************************************************
    .
    Temps d'accomplissement: 2008-04-25 22:23:46 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-04-25 20:23:34

    Pre-Run: 149,401,505,792 octets libres
    Post-Run: 150,204,227,584 octets libres

    283 --- E O F --- 2008-04-25 08:23:26
    0
  3. logiciel espion helpppppp Messages postés 17 Statut Membre
     
    oui j'ai msn
    0
    1. Utilisateur anonyme
       
      Ecoute ajoute moi sa sera plus simple on va faire toutes les étapes ensemble: clem@live.fr
      0
  4. bauvaisis Messages postés 343 Statut Membre 103
     
    salut, tu peut aussi utiliser adaware , c'est gratuit et ca marche bien , il détecte souvent des logiciels espions sur mon ordi malgré l'antivirus.
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. besttrooper
     
    Bonsoir,

    Comme je vous l'ai rappeler dans le post precedent (n°5)

    Je suis tres conscient de l'empleur des degat car je suis dans le metier depuis 1981 donc j'ai vu certains cas dans l'informatique vous pouvez imaginer

    Donc voudriez vous s'il vous plait suivre les instruction du post 5 ensuite les lien respectif pour telecharger sont

    - spybot ici: https://www.safer-networking.org/

    - ad aware ici: https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/11643.html

    en fin pour le post hijack this c'est ici: http://www.infos-du-net.com/telecharger/HijackThis,0301-454.html

    Tenez nous au courant

    Cordialement
    0
  7. Utilisateur anonyme
     
    C'es important de fair booter en sans echecs pour executer spybot?
    0
  8. korben21 Messages postés 922 Statut Membre 25
     
    Résolue ? si oui merci de la cocher
    0
  9. help logiciel espion
     
    re, j'ai pas resolue mon bleme le gars j'ai trouver un texte que mon avast n'a pas pu trouver les logiciels mais y'a un document bizarre un texte que je ne peut pas lire il est deja utiliser sur un autre processus c'est un bloc-note je le voit changer de KO toutes les 5sec aumoin ! svp aidez moi en me repondant comment detruire le bloc note du sale noob qui ma envoyer sa ! merci :)
    0
Précédent
  • 1
  • 2