"TR/Dldr.Zlob.moa" et "Contains sus - Page 2

Résolu
Précédent
  • 1
  • 2
  1. arnaudwolf Messages postés 43 Statut Membre 1
     
    voila scan fini
    0
  2. green day Messages postés 26374 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   2 166
     
    Salut

    ok, poste un nouveau combo stp

    ++
    0
  3. arnaudwolf Messages postés 43 Statut Membre 1
     
    salut excuse moi de se gros retard je n'etait pas chez moi

    je fait le combo je revien
    0
  4. arnaudwolf Messages postés 43 Statut Membre 1
     
    ComboFix 08-05-01.3 - bigwolf 2008-05-09 0:49:18.3 - NTFSx86
    Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.969 [GMT 2:00]
    Endroit: C:\Users\bigwolf\Desktop\ComboFix.exe
    .

    ((((((((((((((((((((((((((((( Fichiers créés 2008-04-08 to 2008-05-08 ))))))))))))))))))))))))))))))))))))
    .

    2008-05-07 04:54 . 2008-03-03 15:05 54,672 --a------ C:\Windows\System32\vsutil_loc040c.dll
    2008-05-07 04:53 . 2008-03-03 15:06 279,440 --a------ C:\Windows\System32\drivers\~GLH0013.TMP
    2008-05-06 23:22 . 2008-05-07 13:58 <REP> d-------- C:\Windows\System32\ZoneLabs
    2008-05-06 23:22 . 2008-05-06 23:22 <REP> d----c--- C:\Program Files\Zone Labs
    2008-05-06 22:30 . 2008-05-06 22:30 2,560 --a------ C:\Windows\_MSRSTRT.EXE
    2008-05-06 18:50 . 2008-05-06 22:31 <REP> d----c--- C:\Program Files\Invisible Secrets 4
    2008-05-06 17:04 . 2008-05-06 17:04 <REP> d-------- C:\Users\bigwolf\AppData\Roaming\Malwarebytes
    2008-05-06 17:03 . 2008-05-06 17:03 <REP> d-------- C:\Users\All Users\Malwarebytes
    2008-05-06 17:03 . 2008-05-06 17:03 <REP> d----c--- C:\Program Files\Malwarebytes' Anti-Malware
    2008-05-06 17:03 . 2008-05-05 20:46 27,048 --a------ C:\Windows\System32\drivers\mbamcatchme.sys
    2008-05-06 17:03 . 2008-05-05 20:46 15,864 --a------ C:\Windows\System32\drivers\mbam.sys
    2008-05-06 16:03 . 2008-05-05 21:43 <REP> d----c--- C:\Program Files\SDFix
    2008-05-06 12:16 . 2008-05-06 12:16 156 --a------ C:\Windows\wininit.ini
    2008-05-06 10:12 . 2008-05-06 13:20 81,984 --a------ C:\Windows\System32\bdod.bin
    2008-05-06 10:09 . 2008-05-06 13:22 <REP> d-------- C:\Users\All Users\BitDefender
    2008-05-06 10:08 . 2008-05-06 13:22 <REP> d----c--- C:\Program Files\Common Files\Softwin
    2008-05-06 10:01 . 2008-05-06 10:01 <REP> d-------- C:\Users\bigwolf\.housecall6.6
    2008-05-06 07:59 . 2008-05-06 07:59 <REP> d-------- C:\Users\bigwolf\AppData\Roaming\ItsLabel
    2008-05-05 16:47 . 2008-05-05 17:12 <REP> d----c--- C:\Program Files\e-anim
    2008-05-04 23:01 . 2008-05-04 23:01 <REP> d-------- C:\Users\bigwolf\AppData\Roaming\gtk-2.0
    2008-05-04 23:00 . 2008-05-04 23:00 <REP> d-------- C:\Users\bigwolf\.thumbnails
    2008-05-04 22:49 . 2008-05-04 23:08 <REP> d-------- C:\Users\bigwolf\.gimp-2.4
    2008-05-01 09:44 . 2008-05-01 09:44 <REP> d-------- C:\Users\bigwolf\AppData\Roaming\EmailNotifier
    2008-05-01 09:18 . 2008-05-01 09:18 507,904 --a------ C:\Windows\TMUPDATE.DLL
    2008-05-01 09:18 . 2008-05-01 09:18 286,720 --a------ C:\Windows\PATCH.EXE
    2008-05-01 09:18 . 2008-05-01 09:18 69,689 --a------ C:\Windows\UNZIP.DLL
    2008-05-01 08:58 . 2008-05-01 08:58 <REP> d-------- C:\Users\All Users\EmailNotifier
    2008-05-01 08:58 . 2008-05-01 08:58 <REP> d----c--- C:\Program Files\CA VMN Anti-Spyware
    2008-04-27 20:37 . 2008-04-27 20:37 <REP> d-------- C:\Users\bigwolf\Nouveau dossier
    2008-04-25 18:59 . 2008-05-06 08:08 <REP> d----c--- C:\Program Files\Norton Security Scan
    2008-04-25 18:58 . 2008-04-25 18:59 <REP> d-------- C:\Windows\System32\Adobe
    2008-04-25 13:56 . 2005-09-01 11:03 127,488 --------- C:\Windows\System32\drivers\imagesrv.sys
    2008-04-25 13:56 . 2005-09-01 11:03 5,888 --------- C:\Windows\System32\drivers\imagedrv.sys
    2008-04-25 13:54 . 2004-07-26 16:16 1,568,768 --------- C:\Windows\System32\ImagX7.dll
    2008-04-25 13:54 . 2004-07-26 16:16 476,320 --------- C:\Windows\System32\ImagXpr7.dll
    2008-04-25 13:54 . 2004-07-26 16:16 471,040 --------- C:\Windows\System32\ImagXRA7.dll
    2008-04-25 13:54 . 2004-07-09 08:43 364,544 --------- C:\Windows\System32\TwnLib4.dll
    2008-04-25 13:54 . 2004-07-26 16:16 262,144 --------- C:\Windows\System32\ImagXR7.dll
    2008-04-25 13:54 . 2001-07-09 10:50 155,648 --a------ C:\Windows\System32\NeroCheck.exe
    2008-04-25 13:54 . 2000-06-26 10:45 106,496 --a------ C:\Windows\System32\TwnLib20.dll
    2008-04-25 13:53 . 2008-04-25 13:54 <REP> d----c--- C:\Program Files\Ahead
    2008-04-23 11:08 . 2008-05-08 22:43 <REP> d----c--- C:\eMule
    2008-04-23 10:42 . 2008-04-23 10:42 <REP> d-------- C:\Users\bigwolf\AppData\Roaming\Notepad++
    2008-04-23 10:42 . 2008-04-23 10:42 <REP> d----c--- C:\Program Files\Notepad++
    2008-04-20 16:52 . 2008-05-01 09:42 524,288 --ahs---- C:\Users\bigwolf\ntuser.dat{33271a4f-0ee9-11dd-8877-0015af3e5d27}.TMContainer00000000000000000002.regtrans-ms
    2008-04-20 16:52 . 2008-05-01 09:42 524,288 --ahs---- C:\Users\bigwolf\ntuser.dat{33271a4f-0ee9-11dd-8877-0015af3e5d27}.TMContainer00000000000000000001.regtrans-ms
    2008-04-20 16:52 . 2008-05-01 09:42 65,536 --ahs---- C:\Users\bigwolf\ntuser.dat{33271a4f-0ee9-11dd-8877-0015af3e5d27}.TM.blf
    2008-04-12 10:26 . 2008-04-12 10:26 <REP> d-------- C:\Users\bigwolf\Program Files
    2008-04-09 10:40 . 2008-02-15 01:19 944,184 --a------ C:\Windows\System32\winload.exe
    2008-04-09 10:40 . 2008-02-19 07:10 620,088 --a------ C:\Windows\System32\ci.dll
    2008-04-09 10:40 . 2008-02-29 08:39 371,712 --a------ C:\Windows\System32\srcore.dll
    2008-04-09 10:40 . 2008-02-29 08:38 313,856 --a------ C:\Windows\System32\rstrui.exe
    2008-04-09 10:40 . 2008-02-29 08:39 40,960 --a------ C:\Windows\System32\srclient.dll
    2008-04-09 10:40 . 2008-02-29 08:51 19,000 --a------ C:\Windows\System32\kd1394.dll
    2008-04-09 10:40 . 2008-02-29 08:38 16,384 --a------ C:\Windows\System32\srdelayed.exe
    2008-04-09 10:40 . 2008-02-29 08:34 7,168 --a------ C:\Windows\System32\f3ahvoas.dll
    2008-04-09 10:40 . 2008-02-29 08:35 6,656 --a------ C:\Windows\System32\kbd106n.dll
    2008-04-09 10:29 . 2008-02-29 06:16 2,027,008 --a------ C:\Windows\System32\win32k.sys
    2008-04-09 10:29 . 2008-02-21 06:43 296,448 --a------ C:\Windows\System32\gdi32.dll
    2008-04-09 10:24 . 2007-12-16 13:42 83,968 --a------ C:\Windows\System32\dnsrslvr.dll
    2008-04-09 10:24 . 2007-12-16 13:41 24,576 --a------ C:\Windows\System32\dnscacheugc.exe

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-05-06 15:09 3,936 ----a-w C:\Users\bigwolf\AppData\Roaming\wklnhst.dat
    2008-05-06 06:03 --------- d-----w C:\Users\bigwolf\AppData\Roaming\EoRezo
    2008-05-06 06:02 --------- dc----w C:\Program Files\Beneton Movie GIF
    2008-05-05 14:43 --------- d-----w C:\Program Files\Visicom Media
    2008-05-03 10:26 --------- d-----w C:\Program Files\vmntoolbar
    2008-05-01 07:07 --------- d-----w C:\Program Files\Windows Live Safety Center
    2008-04-25 11:53 --------- dc----w C:\Program Files\Common Files\Ahead
    2008-04-23 07:25 --------- d-----w C:\Program Files\Messenger Plus! Live
    2008-04-13 15:02 --------- d-----w C:\Program Files\Panda Security
    2008-04-10 10:29 --------- d-----w C:\Program Files\Windows Mail
    2008-03-30 22:21 --------- d-----w C:\Users\bigwolf\AppData\Roaming\Yahoo! Companion
    2008-03-30 22:21 --------- d-----w C:\Program Files\Google
    2008-03-30 02:04 --------- d-----w C:\Users\bigwolf\AppData\Roaming\XnView
    2008-03-30 01:40 --------- d-----w C:\Program Files\XnView
    2008-03-29 11:30 --------- d-----w C:\Program Files\Common Files\xing shared
    2008-03-29 11:29 --------- dc----w C:\Program Files\Common Files\Real
    2008-03-28 17:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-03-28 17:32 --------- dc----w C:\Program Files\Common Files\PX Storage Engine
    2008-03-28 17:32 --------- d-----w C:\Program Files\DivX
    2008-03-09 11:53 --------- d-----w C:\Users\trou de balle\AppData\Roaming\Talkback
    2008-03-08 17:27 --------- d--h--r C:\Users\trou de balle\AppData\Roaming\SecuROM
    2008-03-07 18:30 234,166 ----a-w C:\Windows\EasyGifAnimator_Toolbar_Uninstaller_442.exe
    2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll
    2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll
    2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
    2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
    2008-02-21 02:05 129,784 ------w C:\Windows\System32\PxAFS.DLL
    2008-02-21 02:03 156,992 ----a-w C:\Windows\System32\DivXCodecVersionChecker.exe
    2008-02-14 02:00 194,560 ----a-w C:\Windows\System32\WebClnt.dll
    2008-02-14 01:56 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
    2008-02-14 01:56 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
    2008-02-14 01:56 24,064 ----a-w C:\Windows\System32\netcfg.exe
    2008-02-14 01:56 22,016 ----a-w C:\Windows\System32\netiougc.exe
    2008-02-14 01:56 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
    2008-02-14 01:55 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
    2008-02-14 01:55 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
    2008-02-14 01:55 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
    2008-02-14 01:55 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
    2008-02-14 01:55 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
    2008-02-14 01:55 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
    2008-02-14 01:55 1,686,528 ----a-w C:\Windows\System32\gameux.dll
    2008-02-09 04:18 691,545 ----a-w C:\Windows\unins000.exe
    2008-01-27 06:54 27,525 ----a-w C:\Users\bigwolf\AppData\Roaming\nvModes.dat
    2007-01-01 00:43 174 --sha-w C:\Program Files\desktop.ini
    2007-12-19 08:36 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    2007-12-19 08:36 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    2007-12-19 08:36 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    2007-11-16 20:30 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012007111620071117\index.dat
    .

    ((((((((((((((((((((((((((((( snapshot@2008-05-06_14.53.27.56 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2008-05-06 20:30:42 2,560 ----a-w C:\Windows\_MSRSTRT.EXE
    - 2008-05-06 12:48:48 67,584 --s-a-w C:\Windows\bootstat.dat
    + 2008-05-07 11:58:11 67,584 --s-a-w C:\Windows\bootstat.dat
    - 2008-05-01 06:23:14 51,200 ----a-w C:\Windows\inf\infpub.dat
    + 2008-05-07 02:52:56 51,200 ----a-w C:\Windows\inf\infpub.dat
    - 2008-05-01 06:23:10 86,016 ----a-w C:\Windows\inf\infstor.dat
    + 2008-05-07 02:52:55 86,016 ----a-w C:\Windows\inf\infstor.dat
    - 2008-05-01 06:23:14 86,016 ----a-w C:\Windows\inf\infstrng.dat
    + 2008-05-07 02:52:56 86,016 ----a-w C:\Windows\inf\infstrng.dat
    + 2008-05-07 11:58:13 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    + 2008-05-07 11:58:13 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    - 2008-05-06 12:39:31 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\UsrClass.dat
    + 2008-05-08 22:13:26 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\UsrClass.dat
    - 2008-05-06 12:49:49 1,572,864 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
    + 2008-05-07 11:59:57 1,572,864 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
    - 2008-05-06 12:50:25 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\UsrClass.dat
    + 2008-05-08 22:49:21 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\UsrClass.dat
    - 2008-05-06 12:49:49 1,572,864 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
    + 2008-05-07 11:59:46 1,572,864 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
    - 2008-05-06 11:40:03 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2008-05-08 22:52:21 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2008-05-06 11:40:03 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2008-05-08 22:52:21 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2008-05-06 11:40:03 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2008-05-08 22:52:21 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2008-03-03 13:06:04 279,440 ----a-w C:\Windows\System32\DriverStore\FileRepository\vsdatant.inf_52bc6cc9\vsdatant.sys
    - 2008-05-06 11:28:40 103,228 ----a-w C:\Windows\System32\perfc009.dat
    + 2008-05-08 12:24:42 103,228 ----a-w C:\Windows\System32\perfc009.dat
    - 2008-05-06 11:28:40 117,086 ----a-w C:\Windows\System32\perfc00C.dat
    + 2008-05-08 12:24:43 117,086 ----a-w C:\Windows\System32\perfc00C.dat
    - 2008-05-06 11:28:40 614,084 ----a-w C:\Windows\System32\perfh009.dat
    + 2008-05-08 12:24:43 614,084 ----a-w C:\Windows\System32\perfh009.dat
    - 2008-05-06 11:28:40 685,520 ----a-w C:\Windows\System32\perfh00C.dat
    + 2008-05-08 12:24:43 685,520 ----a-w C:\Windows\System32\perfh00C.dat
    - 2008-05-06 11:26:16 10,090 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-608901210-432299812-286693133-1002_UserData.bin
    + 2008-05-07 12:00:06 10,428 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-608901210-432299812-286693133-1002_UserData.bin
    - 2008-05-06 11:26:16 57,468 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
    + 2008-05-07 12:00:06 57,924 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
    - 2008-05-06 11:23:04 2,694 ----a-w C:\Windows\System32\WDI\ERCQueuedResolutions.dat
    + 2008-05-06 20:25:07 2,694 ----a-w C:\Windows\System32\WDI\ERCQueuedResolutions.dat
    - 2008-05-06 11:26:11 54,506 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2008-05-07 03:02:00 55,064 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
    - 2008-05-03 10:25:16 218,760 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
    + 2008-05-07 09:02:55 219,446 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
    + 2008-03-03 13:05:30 17,808 ----a-w C:\Windows\System32\ZoneLabs\scheduler_loc040c.dll
    + 2008-03-03 13:05:30 17,808 ----a-w C:\Windows\System32\ZoneLabs\vsdb_loc040c.dll
    + 2008-03-03 13:05:30 50,576 ----a-w C:\Windows\System32\ZoneLabs\vsmon_loc040c.dll
    + 2008-03-03 13:05:30 198,032 ----a-w C:\Windows\System32\ZoneLabs\vsruledb_loc040c.dll
    + 2008-03-03 13:05:30 17,808 ----a-w C:\Windows\System32\ZoneLabs\vsvault_loc040c.dll
    + 2008-03-03 13:05:30 17,808 ----a-w C:\Windows\System32\ZoneLabs\zlquarantine_loc040c.dll
    + 2008-03-03 13:05:30 21,904 ----a-w C:\Windows\System32\ZoneLabs\zlsre_loc040c.dll
    .
    -- Snapshot reset to current date --
    .
    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-8287-79A187E26987}]
    2007-09-24 16:26 2022912 --a------ C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{A057A204-BACC-4D26-8287-79A187E26987}"= "C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL" [2007-09-24 16:26 2022912]

    [HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-8287-79a187e26987}]
    [HKEY_CLASSES_ROOT\vmntoolbar.VMNTOOLBAR]

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
    "{A057A204-BACC-4D26-8287-79A187E26987}"= C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL [2007-09-24 16:26 2022912]

    [HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-8287-79a187e26987}]
    [HKEY_CLASSES_ROOT\vmntoolbar.VMNTOOLBAR]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-09 19:07 1232896]
    "WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 14:34 2159104 C:\Windows\System32\oobefldr.dll]
    "SmpcSys"="C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe" [2007-07-19 15:32 1120568]
    "ccleaner"="C:\Program Files\CCleaner\CCleaner.exe" [2008-02-20 16:15 816368]
    "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 14:35 125440]
    "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 12:43 2097488]
    "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
    "AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 11:37 2321600]
    "eMuleAutoStart"="C:\eMule\emule.exe" [2007-05-13 16:57 5308416]

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
    Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-03-31 00:19:01 124400]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
    "LogonHoursAction"= 2 (0x2)
    "DontDisplayLogonHoursWarnings"= 1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
    "{C0D6CFCF-F032-4C36-A8D8-8284A6D23A31}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{0D803923-CBC2-4F62-B50F-AF82B2C60771}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{3C367DB0-477B-4B63-BD84-7368123BB5A6}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
    "{D7205450-19C7-451E-BC69-F8C6162D6EBF}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
    "{CD201523-1A2C-4184-99D0-C62E771D8783}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
    "{29797336-22FB-4DC6-BCA4-540A875BDC70}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
    "{21BB3ABE-6C1D-49F4-A234-DEAABF01B3F8}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
    "{D49603BF-E4E0-4BB4-9372-78A67B4E5E1C}"= UDP:C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe:Sony Ericsson Media Manager 1.0
    "{A8311C70-551E-495C-AA58-63E73703AA13}"= TCP:C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe:Sony Ericsson Media Manager 1.0
    "{3945DC6C-BE9A-4A04-A8FA-CD50AAD51DD3}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
    "{00B0D406-F9F2-4EB6-9048-6CB20C6D50D4}"= UDP:C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
    "{0D4B8946-B4A6-417D-9BA1-539B74201CA6}"= TCP:C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
    "TCP Query User{7ABA62C5-0416-47AA-B312-8A4754E96CF7}C:\\program files\\bittorrent\\bittorrent.exe"= UDP:C:\program files\bittorrent\bittorrent.exe:bittorrent
    "UDP Query User{697A47BB-3779-4D6A-AAC9-C634BBBBD842}C:\\program files\\bittorrent\\bittorrent.exe"= TCP:C:\program files\bittorrent\bittorrent.exe:bittorrent
    "TCP Query User{69A4376C-8D2E-45AF-BAFA-620E7E055E37}C:\\program files\\real\\realplayer\\realplay.exe"= UDP:C:\program files\real\realplayer\realplay.exe:RealPlayer
    "UDP Query User{F91187D1-0E5D-4F72-9449-F09EE2177D08}C:\\program files\\real\\realplayer\\realplay.exe"= TCP:C:\program files\real\realplayer\realplay.exe:RealPlayer
    "TCP Query User{11B938A2-8513-4880-AEC9-871725D8621D}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
    "UDP Query User{D68AD715-846B-477D-B177-0F0A5B3944CA}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
    "TCP Query User{C1B46920-5C39-4427-AA25-DD107DE2CADC}C:\\users\\bigwolf\\program files\\utorrent\\utorrent.exe"= UDP:C:\users\bigwolf\program files\utorrent\utorrent.exe:utorrent.exe
    "UDP Query User{DD1C91B6-ECB7-4E8D-8C7A-CEAB97547004}C:\\users\\bigwolf\\program files\\utorrent\\utorrent.exe"= TCP:C:\users\bigwolf\program files\utorrent\utorrent.exe:utorrent.exe
    "TCP Query User{3EFB369A-6BF1-41A4-980B-0E6F5745F36A}C:\\emule\\emule.exe"= UDP:C:\emule\emule.exe:eMule
    "UDP Query User{3BA30AD8-FB7D-4FE1-9A06-CE166B8AAC67}C:\\emule\\emule.exe"= TCP:C:\emule\emule.exe:eMule

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
    "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
    "C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent

    R2 RapiMgr;Connectivité de l'appareil Windows Mobile;C:\Windows\system32\svchost.exe [2006-11-02 11:45]
    R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 12:43]
    R2 WcesComm;Connectivité de l'appareil Windows Mobile 2003;C:\Windows\system32\svchost.exe [2006-11-02 11:45]
    R3 Cam5607;Bison WebCam;C:\Windows\system32\Drivers\BisonC07.sys [2007-07-23 20:35]
    R3 nvsmu;nvsmu;C:\Windows\system32\DRIVERS\nvsmu.sys [2007-02-16 02:50]
    R3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;C:\Windows\system32\DRIVERS\RTL8187B.sys [2007-09-27 14:46]
    R3 RTSTOR;USB Mass Storage Device;C:\Windows\system32\drivers\RTSTOR.SYS [2007-06-15 22:47]
    S3 MBAMCatchMe;MBAMCatchMe;C:\Windows\system32\drivers\mbamcatchme.sys [2008-05-05 20:46]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    WindowsMobile REG_MULTI_SZ wcescomm rapimgr
    LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr

    *Newly Created Service* - CATCHME
    .
    Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
    "2008-05-08 22:30:00 C:\Windows\Tasks\Extension de garantie.job"
    - C:\Program Files\Packard Bell\SetupmyPC\PBCarNot.exe
    "2008-05-08 22:30:00 C:\Windows\Tasks\Recovery DVD Creator.job"
    - C:\Program Files\Packard Bell\SetupMyPc\MCDCheck.exe
    .
    **************************************************************************

    catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-05-09 00:54:22
    Windows 6.0.6000 NTFS

    Balayage processus cachés ...

    Balayage caché autostart entries ...

    Balayage des fichiers cachés ...

    Scan terminé avec succès
    Les fichiers cachés: 57

    **************************************************************************
    .
    Temps d'accomplissement: 2008-05-09 0:58:55
    ComboFix-quarantined-files.txt 2008-05-08 22:58:45
    ComboFix2.txt 2008-05-06 12:54:05

    Pre-Run: 97,952,411,648 octets libres
    Post-Run: 97,214,226,432 octets libres

    273 --- E O F --- 2008-05-08 22:46:09

    voila lol merci en tous cas de m'aider parsque je suppose qu'a ton age ta po toujour le temp d'etre la lol
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. green day Messages postés 26374 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   2 166
     
    Salut ! ;-)

    où en sont tes soucis à présent ?

    @+
    0
  7. arnaudwolf Messages postés 43 Statut Membre 1
     
    re excuse je suis rarement l, bah j'ai plus de souci merci gentil genie
    vive les fille experte
    merci
    0
  8. green day Messages postés 26374 Date d'inscription   Statut Modérateur, Contributeur sécurité Dernière intervention   2 166
     
    Salut

    pas de quoi ! :-)

    à lire à l'occasion :

    http://www.commentcamarche.net/faq/sujet 2432 securite proteger un ordinateur contre les malwares d internet

    @+
    0
Précédent
  • 1
  • 2