"TR/Dldr.Zlob.moa" et "Contains sus - Page 2
Résolu
Précédent
- 1
- 2
-
-
Salut
ok, poste un nouveau combo stp
++ -
salut excuse moi de se gros retard je n'etait pas chez moi
je fait le combo je revien -
ComboFix 08-05-01.3 - bigwolf 2008-05-09 0:49:18.3 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.969 [GMT 2:00]
Endroit: C:\Users\bigwolf\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2008-04-08 to 2008-05-08 ))))))))))))))))))))))))))))))))))))
.
2008-05-07 04:54 . 2008-03-03 15:05 54,672 --a------ C:\Windows\System32\vsutil_loc040c.dll
2008-05-07 04:53 . 2008-03-03 15:06 279,440 --a------ C:\Windows\System32\drivers\~GLH0013.TMP
2008-05-06 23:22 . 2008-05-07 13:58 <REP> d-------- C:\Windows\System32\ZoneLabs
2008-05-06 23:22 . 2008-05-06 23:22 <REP> d----c--- C:\Program Files\Zone Labs
2008-05-06 22:30 . 2008-05-06 22:30 2,560 --a------ C:\Windows\_MSRSTRT.EXE
2008-05-06 18:50 . 2008-05-06 22:31 <REP> d----c--- C:\Program Files\Invisible Secrets 4
2008-05-06 17:04 . 2008-05-06 17:04 <REP> d-------- C:\Users\bigwolf\AppData\Roaming\Malwarebytes
2008-05-06 17:03 . 2008-05-06 17:03 <REP> d-------- C:\Users\All Users\Malwarebytes
2008-05-06 17:03 . 2008-05-06 17:03 <REP> d----c--- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-06 17:03 . 2008-05-05 20:46 27,048 --a------ C:\Windows\System32\drivers\mbamcatchme.sys
2008-05-06 17:03 . 2008-05-05 20:46 15,864 --a------ C:\Windows\System32\drivers\mbam.sys
2008-05-06 16:03 . 2008-05-05 21:43 <REP> d----c--- C:\Program Files\SDFix
2008-05-06 12:16 . 2008-05-06 12:16 156 --a------ C:\Windows\wininit.ini
2008-05-06 10:12 . 2008-05-06 13:20 81,984 --a------ C:\Windows\System32\bdod.bin
2008-05-06 10:09 . 2008-05-06 13:22 <REP> d-------- C:\Users\All Users\BitDefender
2008-05-06 10:08 . 2008-05-06 13:22 <REP> d----c--- C:\Program Files\Common Files\Softwin
2008-05-06 10:01 . 2008-05-06 10:01 <REP> d-------- C:\Users\bigwolf\.housecall6.6
2008-05-06 07:59 . 2008-05-06 07:59 <REP> d-------- C:\Users\bigwolf\AppData\Roaming\ItsLabel
2008-05-05 16:47 . 2008-05-05 17:12 <REP> d----c--- C:\Program Files\e-anim
2008-05-04 23:01 . 2008-05-04 23:01 <REP> d-------- C:\Users\bigwolf\AppData\Roaming\gtk-2.0
2008-05-04 23:00 . 2008-05-04 23:00 <REP> d-------- C:\Users\bigwolf\.thumbnails
2008-05-04 22:49 . 2008-05-04 23:08 <REP> d-------- C:\Users\bigwolf\.gimp-2.4
2008-05-01 09:44 . 2008-05-01 09:44 <REP> d-------- C:\Users\bigwolf\AppData\Roaming\EmailNotifier
2008-05-01 09:18 . 2008-05-01 09:18 507,904 --a------ C:\Windows\TMUPDATE.DLL
2008-05-01 09:18 . 2008-05-01 09:18 286,720 --a------ C:\Windows\PATCH.EXE
2008-05-01 09:18 . 2008-05-01 09:18 69,689 --a------ C:\Windows\UNZIP.DLL
2008-05-01 08:58 . 2008-05-01 08:58 <REP> d-------- C:\Users\All Users\EmailNotifier
2008-05-01 08:58 . 2008-05-01 08:58 <REP> d----c--- C:\Program Files\CA VMN Anti-Spyware
2008-04-27 20:37 . 2008-04-27 20:37 <REP> d-------- C:\Users\bigwolf\Nouveau dossier
2008-04-25 18:59 . 2008-05-06 08:08 <REP> d----c--- C:\Program Files\Norton Security Scan
2008-04-25 18:58 . 2008-04-25 18:59 <REP> d-------- C:\Windows\System32\Adobe
2008-04-25 13:56 . 2005-09-01 11:03 127,488 --------- C:\Windows\System32\drivers\imagesrv.sys
2008-04-25 13:56 . 2005-09-01 11:03 5,888 --------- C:\Windows\System32\drivers\imagedrv.sys
2008-04-25 13:54 . 2004-07-26 16:16 1,568,768 --------- C:\Windows\System32\ImagX7.dll
2008-04-25 13:54 . 2004-07-26 16:16 476,320 --------- C:\Windows\System32\ImagXpr7.dll
2008-04-25 13:54 . 2004-07-26 16:16 471,040 --------- C:\Windows\System32\ImagXRA7.dll
2008-04-25 13:54 . 2004-07-09 08:43 364,544 --------- C:\Windows\System32\TwnLib4.dll
2008-04-25 13:54 . 2004-07-26 16:16 262,144 --------- C:\Windows\System32\ImagXR7.dll
2008-04-25 13:54 . 2001-07-09 10:50 155,648 --a------ C:\Windows\System32\NeroCheck.exe
2008-04-25 13:54 . 2000-06-26 10:45 106,496 --a------ C:\Windows\System32\TwnLib20.dll
2008-04-25 13:53 . 2008-04-25 13:54 <REP> d----c--- C:\Program Files\Ahead
2008-04-23 11:08 . 2008-05-08 22:43 <REP> d----c--- C:\eMule
2008-04-23 10:42 . 2008-04-23 10:42 <REP> d-------- C:\Users\bigwolf\AppData\Roaming\Notepad++
2008-04-23 10:42 . 2008-04-23 10:42 <REP> d----c--- C:\Program Files\Notepad++
2008-04-20 16:52 . 2008-05-01 09:42 524,288 --ahs---- C:\Users\bigwolf\ntuser.dat{33271a4f-0ee9-11dd-8877-0015af3e5d27}.TMContainer00000000000000000002.regtrans-ms
2008-04-20 16:52 . 2008-05-01 09:42 524,288 --ahs---- C:\Users\bigwolf\ntuser.dat{33271a4f-0ee9-11dd-8877-0015af3e5d27}.TMContainer00000000000000000001.regtrans-ms
2008-04-20 16:52 . 2008-05-01 09:42 65,536 --ahs---- C:\Users\bigwolf\ntuser.dat{33271a4f-0ee9-11dd-8877-0015af3e5d27}.TM.blf
2008-04-12 10:26 . 2008-04-12 10:26 <REP> d-------- C:\Users\bigwolf\Program Files
2008-04-09 10:40 . 2008-02-15 01:19 944,184 --a------ C:\Windows\System32\winload.exe
2008-04-09 10:40 . 2008-02-19 07:10 620,088 --a------ C:\Windows\System32\ci.dll
2008-04-09 10:40 . 2008-02-29 08:39 371,712 --a------ C:\Windows\System32\srcore.dll
2008-04-09 10:40 . 2008-02-29 08:38 313,856 --a------ C:\Windows\System32\rstrui.exe
2008-04-09 10:40 . 2008-02-29 08:39 40,960 --a------ C:\Windows\System32\srclient.dll
2008-04-09 10:40 . 2008-02-29 08:51 19,000 --a------ C:\Windows\System32\kd1394.dll
2008-04-09 10:40 . 2008-02-29 08:38 16,384 --a------ C:\Windows\System32\srdelayed.exe
2008-04-09 10:40 . 2008-02-29 08:34 7,168 --a------ C:\Windows\System32\f3ahvoas.dll
2008-04-09 10:40 . 2008-02-29 08:35 6,656 --a------ C:\Windows\System32\kbd106n.dll
2008-04-09 10:29 . 2008-02-29 06:16 2,027,008 --a------ C:\Windows\System32\win32k.sys
2008-04-09 10:29 . 2008-02-21 06:43 296,448 --a------ C:\Windows\System32\gdi32.dll
2008-04-09 10:24 . 2007-12-16 13:42 83,968 --a------ C:\Windows\System32\dnsrslvr.dll
2008-04-09 10:24 . 2007-12-16 13:41 24,576 --a------ C:\Windows\System32\dnscacheugc.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-06 15:09 3,936 ----a-w C:\Users\bigwolf\AppData\Roaming\wklnhst.dat
2008-05-06 06:03 --------- d-----w C:\Users\bigwolf\AppData\Roaming\EoRezo
2008-05-06 06:02 --------- dc----w C:\Program Files\Beneton Movie GIF
2008-05-05 14:43 --------- d-----w C:\Program Files\Visicom Media
2008-05-03 10:26 --------- d-----w C:\Program Files\vmntoolbar
2008-05-01 07:07 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-04-25 11:53 --------- dc----w C:\Program Files\Common Files\Ahead
2008-04-23 07:25 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-04-13 15:02 --------- d-----w C:\Program Files\Panda Security
2008-04-10 10:29 --------- d-----w C:\Program Files\Windows Mail
2008-03-30 22:21 --------- d-----w C:\Users\bigwolf\AppData\Roaming\Yahoo! Companion
2008-03-30 22:21 --------- d-----w C:\Program Files\Google
2008-03-30 02:04 --------- d-----w C:\Users\bigwolf\AppData\Roaming\XnView
2008-03-30 01:40 --------- d-----w C:\Program Files\XnView
2008-03-29 11:30 --------- d-----w C:\Program Files\Common Files\xing shared
2008-03-29 11:29 --------- dc----w C:\Program Files\Common Files\Real
2008-03-28 17:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-28 17:32 --------- dc----w C:\Program Files\Common Files\PX Storage Engine
2008-03-28 17:32 --------- d-----w C:\Program Files\DivX
2008-03-09 11:53 --------- d-----w C:\Users\trou de balle\AppData\Roaming\Talkback
2008-03-08 17:27 --------- d--h--r C:\Users\trou de balle\AppData\Roaming\SecuROM
2008-03-07 18:30 234,166 ----a-w C:\Windows\EasyGifAnimator_Toolbar_Uninstaller_442.exe
2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-02-21 02:05 129,784 ------w C:\Windows\System32\PxAFS.DLL
2008-02-21 02:03 156,992 ----a-w C:\Windows\System32\DivXCodecVersionChecker.exe
2008-02-14 02:00 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-02-14 01:56 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-02-14 01:56 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-02-14 01:56 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-02-14 01:56 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-02-14 01:56 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-02-14 01:55 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-14 01:55 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-14 01:55 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-02-14 01:55 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-02-14 01:55 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-14 01:55 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-14 01:55 1,686,528 ----a-w C:\Windows\System32\gameux.dll
2008-02-09 04:18 691,545 ----a-w C:\Windows\unins000.exe
2008-01-27 06:54 27,525 ----a-w C:\Users\bigwolf\AppData\Roaming\nvModes.dat
2007-01-01 00:43 174 --sha-w C:\Program Files\desktop.ini
2007-12-19 08:36 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-12-19 08:36 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-12-19 08:36 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2007-11-16 20:30 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012007111620071117\index.dat
.
((((((((((((((((((((((((((((( snapshot@2008-05-06_14.53.27.56 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-05-06 20:30:42 2,560 ----a-w C:\Windows\_MSRSTRT.EXE
- 2008-05-06 12:48:48 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2008-05-07 11:58:11 67,584 --s-a-w C:\Windows\bootstat.dat
- 2008-05-01 06:23:14 51,200 ----a-w C:\Windows\inf\infpub.dat
+ 2008-05-07 02:52:56 51,200 ----a-w C:\Windows\inf\infpub.dat
- 2008-05-01 06:23:10 86,016 ----a-w C:\Windows\inf\infstor.dat
+ 2008-05-07 02:52:55 86,016 ----a-w C:\Windows\inf\infstor.dat
- 2008-05-01 06:23:14 86,016 ----a-w C:\Windows\inf\infstrng.dat
+ 2008-05-07 02:52:56 86,016 ----a-w C:\Windows\inf\infstrng.dat
+ 2008-05-07 11:58:13 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-05-07 11:58:13 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-05-06 12:39:31 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\UsrClass.dat
+ 2008-05-08 22:13:26 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\UsrClass.dat
- 2008-05-06 12:49:49 1,572,864 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
+ 2008-05-07 11:59:57 1,572,864 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
- 2008-05-06 12:50:25 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\UsrClass.dat
+ 2008-05-08 22:49:21 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\UsrClass.dat
- 2008-05-06 12:49:49 1,572,864 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2008-05-07 11:59:46 1,572,864 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
- 2008-05-06 11:40:03 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-05-08 22:52:21 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-05-06 11:40:03 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-05-08 22:52:21 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-05-06 11:40:03 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-05-08 22:52:21 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-03-03 13:06:04 279,440 ----a-w C:\Windows\System32\DriverStore\FileRepository\vsdatant.inf_52bc6cc9\vsdatant.sys
- 2008-05-06 11:28:40 103,228 ----a-w C:\Windows\System32\perfc009.dat
+ 2008-05-08 12:24:42 103,228 ----a-w C:\Windows\System32\perfc009.dat
- 2008-05-06 11:28:40 117,086 ----a-w C:\Windows\System32\perfc00C.dat
+ 2008-05-08 12:24:43 117,086 ----a-w C:\Windows\System32\perfc00C.dat
- 2008-05-06 11:28:40 614,084 ----a-w C:\Windows\System32\perfh009.dat
+ 2008-05-08 12:24:43 614,084 ----a-w C:\Windows\System32\perfh009.dat
- 2008-05-06 11:28:40 685,520 ----a-w C:\Windows\System32\perfh00C.dat
+ 2008-05-08 12:24:43 685,520 ----a-w C:\Windows\System32\perfh00C.dat
- 2008-05-06 11:26:16 10,090 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-608901210-432299812-286693133-1002_UserData.bin
+ 2008-05-07 12:00:06 10,428 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-608901210-432299812-286693133-1002_UserData.bin
- 2008-05-06 11:26:16 57,468 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-05-07 12:00:06 57,924 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-05-06 11:23:04 2,694 ----a-w C:\Windows\System32\WDI\ERCQueuedResolutions.dat
+ 2008-05-06 20:25:07 2,694 ----a-w C:\Windows\System32\WDI\ERCQueuedResolutions.dat
- 2008-05-06 11:26:11 54,506 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-05-07 03:02:00 55,064 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2008-05-03 10:25:16 218,760 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2008-05-07 09:02:55 219,446 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2008-03-03 13:05:30 17,808 ----a-w C:\Windows\System32\ZoneLabs\scheduler_loc040c.dll
+ 2008-03-03 13:05:30 17,808 ----a-w C:\Windows\System32\ZoneLabs\vsdb_loc040c.dll
+ 2008-03-03 13:05:30 50,576 ----a-w C:\Windows\System32\ZoneLabs\vsmon_loc040c.dll
+ 2008-03-03 13:05:30 198,032 ----a-w C:\Windows\System32\ZoneLabs\vsruledb_loc040c.dll
+ 2008-03-03 13:05:30 17,808 ----a-w C:\Windows\System32\ZoneLabs\vsvault_loc040c.dll
+ 2008-03-03 13:05:30 17,808 ----a-w C:\Windows\System32\ZoneLabs\zlquarantine_loc040c.dll
+ 2008-03-03 13:05:30 21,904 ----a-w C:\Windows\System32\ZoneLabs\zlsre_loc040c.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-8287-79A187E26987}]
2007-09-24 16:26 2022912 --a------ C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-8287-79A187E26987}"= "C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL" [2007-09-24 16:26 2022912]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-8287-79a187e26987}]
[HKEY_CLASSES_ROOT\vmntoolbar.VMNTOOLBAR]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{A057A204-BACC-4D26-8287-79A187E26987}"= C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL [2007-09-24 16:26 2022912]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-8287-79a187e26987}]
[HKEY_CLASSES_ROOT\vmntoolbar.VMNTOOLBAR]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-09 19:07 1232896]
"WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 14:34 2159104 C:\Windows\System32\oobefldr.dll]
"SmpcSys"="C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe" [2007-07-19 15:32 1120568]
"ccleaner"="C:\Program Files\CCleaner\CCleaner.exe" [2008-02-20 16:15 816368]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 14:35 125440]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 12:43 2097488]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 11:37 2321600]
"eMuleAutoStart"="C:\eMule\emule.exe" [2007-05-13 16:57 5308416]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-03-31 00:19:01 124400]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"= 2 (0x2)
"DontDisplayLogonHoursWarnings"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{C0D6CFCF-F032-4C36-A8D8-8284A6D23A31}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{0D803923-CBC2-4F62-B50F-AF82B2C60771}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{3C367DB0-477B-4B63-BD84-7368123BB5A6}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{D7205450-19C7-451E-BC69-F8C6162D6EBF}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{CD201523-1A2C-4184-99D0-C62E771D8783}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{29797336-22FB-4DC6-BCA4-540A875BDC70}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{21BB3ABE-6C1D-49F4-A234-DEAABF01B3F8}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{D49603BF-E4E0-4BB4-9372-78A67B4E5E1C}"= UDP:C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe:Sony Ericsson Media Manager 1.0
"{A8311C70-551E-495C-AA58-63E73703AA13}"= TCP:C:\Program Files\Sony Ericsson\Sony Ericsson Media Manager 1.0\MediaManager.exe:Sony Ericsson Media Manager 1.0
"{3945DC6C-BE9A-4A04-A8FA-CD50AAD51DD3}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{00B0D406-F9F2-4EB6-9048-6CB20C6D50D4}"= UDP:C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"{0D4B8946-B4A6-417D-9BA1-539B74201CA6}"= TCP:C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe:Football Manager 2008
"TCP Query User{7ABA62C5-0416-47AA-B312-8A4754E96CF7}C:\\program files\\bittorrent\\bittorrent.exe"= UDP:C:\program files\bittorrent\bittorrent.exe:bittorrent
"UDP Query User{697A47BB-3779-4D6A-AAC9-C634BBBBD842}C:\\program files\\bittorrent\\bittorrent.exe"= TCP:C:\program files\bittorrent\bittorrent.exe:bittorrent
"TCP Query User{69A4376C-8D2E-45AF-BAFA-620E7E055E37}C:\\program files\\real\\realplayer\\realplay.exe"= UDP:C:\program files\real\realplayer\realplay.exe:RealPlayer
"UDP Query User{F91187D1-0E5D-4F72-9449-F09EE2177D08}C:\\program files\\real\\realplayer\\realplay.exe"= TCP:C:\program files\real\realplayer\realplay.exe:RealPlayer
"TCP Query User{11B938A2-8513-4880-AEC9-871725D8621D}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{D68AD715-846B-477D-B177-0F0A5B3944CA}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
"TCP Query User{C1B46920-5C39-4427-AA25-DD107DE2CADC}C:\\users\\bigwolf\\program files\\utorrent\\utorrent.exe"= UDP:C:\users\bigwolf\program files\utorrent\utorrent.exe:utorrent.exe
"UDP Query User{DD1C91B6-ECB7-4E8D-8C7A-CEAB97547004}C:\\users\\bigwolf\\program files\\utorrent\\utorrent.exe"= TCP:C:\users\bigwolf\program files\utorrent\utorrent.exe:utorrent.exe
"TCP Query User{3EFB369A-6BF1-41A4-980B-0E6F5745F36A}C:\\emule\\emule.exe"= UDP:C:\emule\emule.exe:eMule
"UDP Query User{3BA30AD8-FB7D-4FE1-9A06-CE166B8AAC67}C:\\emule\\emule.exe"= TCP:C:\emule\emule.exe:eMule
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R2 RapiMgr;Connectivité de l'appareil Windows Mobile;C:\Windows\system32\svchost.exe [2006-11-02 11:45]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 12:43]
R2 WcesComm;Connectivité de l'appareil Windows Mobile 2003;C:\Windows\system32\svchost.exe [2006-11-02 11:45]
R3 Cam5607;Bison WebCam;C:\Windows\system32\Drivers\BisonC07.sys [2007-07-23 20:35]
R3 nvsmu;nvsmu;C:\Windows\system32\DRIVERS\nvsmu.sys [2007-02-16 02:50]
R3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;C:\Windows\system32\DRIVERS\RTL8187B.sys [2007-09-27 14:46]
R3 RTSTOR;USB Mass Storage Device;C:\Windows\system32\drivers\RTSTOR.SYS [2007-06-15 22:47]
S3 MBAMCatchMe;MBAMCatchMe;C:\Windows\system32\drivers\mbamcatchme.sys [2008-05-05 20:46]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
*Newly Created Service* - CATCHME
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-05-08 22:30:00 C:\Windows\Tasks\Extension de garantie.job"
- C:\Program Files\Packard Bell\SetupmyPC\PBCarNot.exe
"2008-05-08 22:30:00 C:\Windows\Tasks\Recovery DVD Creator.job"
- C:\Program Files\Packard Bell\SetupMyPc\MCDCheck.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-09 00:54:22
Windows 6.0.6000 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 57
**************************************************************************
.
Temps d'accomplissement: 2008-05-09 0:58:55
ComboFix-quarantined-files.txt 2008-05-08 22:58:45
ComboFix2.txt 2008-05-06 12:54:05
Pre-Run: 97,952,411,648 octets libres
Post-Run: 97,214,226,432 octets libres
273 --- E O F --- 2008-05-08 22:46:09
voila lol merci en tous cas de m'aider parsque je suppose qu'a ton age ta po toujour le temp d'etre la lol -
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question -
Salut ! ;-)
où en sont tes soucis à présent ?
@+ -
re excuse je suis rarement l, bah j'ai plus de souci merci gentil genie
vive les fille experte
merci -
Salut
pas de quoi ! :-)
à lire à l'occasion :
http://www.commentcamarche.net/faq/sujet 2432 securite proteger un ordinateur contre les malwares d internet
@+
Précédent
- 1
- 2