Virus Virtumonde
Fermé
mahnie
Messages postés
8
Date d'inscription
dimanche 11 mai 2008
Statut
Membre
Dernière intervention
13 mai 2008
-
11 mai 2008 à 12:06
Utilisateur anonyme - 13 mai 2008 à 21:55
Utilisateur anonyme - 13 mai 2008 à 21:55
A voir également:
- Virus Virtumonde
- Youtu.be virus - Accueil - Guide virus
- Svchost.exe virus - Guide
- Faux message virus ordinateur - Accueil - Arnaque
- Softonic virus ✓ - Forum Virus
- Virus mcafee - Accueil - Piratage
24 réponses
Utilisateur anonyme
12 mai 2008 à 01:05
12 mai 2008 à 01:05
pourquoi il m'a dit que la force soit avec toi le monsieur la-haut là.......????????????
mahnie
Messages postés
8
Date d'inscription
dimanche 11 mai 2008
Statut
Membre
Dernière intervention
13 mai 2008
12 mai 2008 à 01:45
12 mai 2008 à 01:45
salut,
J'ai fait:
-VundoFix, et il ne m'a rien trouvé, donc j'ai pas de rapport.
-VirtumondoBeGone, voici le log:
[05/12/2008, 1:02:29] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Mahnie\Bureau\VirtumundoBeGone.exe" )
[05/12/2008, 1:02:48] - Detected System Information:
[05/12/2008, 1:02:48] - Windows Version: 5.1.2600, Service Pack 2
[05/12/2008, 1:02:48] - Current Username: Mahnie (Admin)
[05/12/2008, 1:02:48] - Windows is in NORMAL mode.
[05/12/2008, 1:02:48] - Searching for Browser Helper Objects:
[05/12/2008, 1:02:48] - BHO 1: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[05/12/2008, 1:02:48] - BHO 2: {96367F29-207F-40DC-9C39-6D8E836B1AB3} ()
[05/12/2008, 1:02:48] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/12/2008, 1:02:48] - Checking for HKLM\...\Winlogon\Notify\pmnnKCrO
[05/12/2008, 1:02:48] - Key not found: HKLM\...\Winlogon\Notify\pmnnKCrO, continuing.
[05/12/2008, 1:02:48] - Finished Searching Browser Helper Objects
[05/12/2008, 1:02:48] - Finishing up...
[05/12/2008, 1:02:48] - Nothing found! Exiting...
-Combofix, voici le log:
ComboFix 08-05-11.1 - Mahnie 2008-05-12 1:36:08.1 - NTFSx86
Microsoft Windows XP …dition familiale 5.1.2600.2.1252.1.1036.18.457 [GMT 2:00]
Endroit: C:\Documents and Settings\Mahnie\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mahnie\Bureau\WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
* CrÈation d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\fcadvice
C:\Program Files\fcadvice\patterns.dat
C:\Program Files\fcadvice\Uninstall.exe
C:\WINDOWS\pack.epk
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\gswgqvrn.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mnmlyigt.ini
C:\WINDOWS\system32\OrCKnnmp.ini
C:\WINDOWS\system32\OrCKnnmp.ini2
C:\WINDOWS\system32\pmnnKCrO.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\pWDLkUvw.ini
C:\WINDOWS\system32\pWDLkUvw.ini2
c:\WINDOWS\system32\zpjthwuyu.dat
c:\windows\system32\zpjthwuyu.exe
c:\WINDOWS\system32\zpjthwuyu_navps.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Service_NPF
((((((((((((((((((((((((((((( Fichiers crÇÇs 2008-04-11 to 2008-05-11 ))))))))))))))))))))))))))))))))))))
.
C:\ComboFix\CreateC00.bat .
2008-05-12 00:49 . 2008-05-12 00:49 <REP> d-------- C:\VundoFix Backups
2008-05-11 12:45 . 2008-05-11 12:45 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-11 12:45 . 2008-05-11 12:45 <REP> d-------- C:\Documents and Settings\Mahnie\Application Data\Malwarebytes
2008-05-11 12:45 . 2008-05-11 12:45 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-11 12:45 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-11 12:45 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-11 12:05 . 2008-05-11 12:05 <REP> d-------- C:\Program Files\Trend Micro
2008-05-09 15:34 . 2008-05-09 15:34 <REP> d-------- C:\Program Files\Alwil Software
2008-05-09 14:51 . 2008-05-09 14:51 2,048 --a------ C:\WINDOWS\system32\xucbhdhl.exe
2008-05-09 12:11 . 2008-05-09 12:11 2,048 --a------ C:\WINDOWS\system32\cyivgnhm.exe
2008-04-25 22:53 . 2008-05-04 13:04 443 --a------ C:\WINDOWS\wininit.ini
2008-04-21 00:55 . 2008-04-21 00:55 <REP> d-------- C:\Documents and Settings\Mahnie\Application Data\Canon
2008-04-21 00:50 . 2008-04-21 00:50 <REP> d-------- C:\Documents and Settings\Mahnie\Application Data\ZoomBrowser EX
2008-04-20 23:39 . 2008-04-20 23:39 <REP> d-------- C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-04-20 23:37 . 2008-04-20 23:37 <REP> d-------- C:\Program Files\Fichiers communs\Canon
2008-04-20 23:37 . 2008-04-20 23:40 <REP> d-------- C:\Program Files\Canon
2008-04-20 15:35 . 2008-04-25 21:52 594 ---hs---- C:\WINDOWS\system32\oymmrnsb.ini
2008-04-20 15:30 . 2008-05-11 11:02 109,738 --a------ C:\WINDOWS\BMbb971fa2.xml
2008-04-19 23:38 . 2008-04-19 23:38 <REP> d-------- C:\Program Files\LaCieTools
2008-04-19 23:38 . 2005-10-19 08:34 15,872 --a------ C:\WINDOWS\system32\drivers\LaCieUSBFilter.sys
2008-04-19 23:38 . 2005-10-18 07:28 14,848 --a------ C:\WINDOWS\system32\drivers\LaCieFWFilter.sys
2008-04-19 23:38 . 2002-07-26 16:02 6,752 --a------ C:\UNWISE.INI
2008-04-19 23:38 . 2008-04-19 23:38 640 --a------ C:\WINDOWS\UndeviceUpd
2008-04-19 18:39 . 2008-04-19 18:39 <REP> d-------- C:\Program Files\Bonjour
2008-04-19 18:25 . 2008-04-19 18:25 <REP> d-------- C:\Program Files\Fichiers communs\Macrovision Shared
2008-04-19 15:50 . 2008-04-19 15:50 <REP> d-------- C:\Documents and Settings\Mahnie\.DownloadManager
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-11 23:42 13,440 ----a-w C:\WINDOWS\system32\drivers\USBCRFT.SYS
2008-05-11 10:35 --------- d-----w C:\Program Files\freeCommander2006
2008-05-11 08:52 --------- d-----w C:\Program Files\ewido anti-malware
2008-05-11 08:43 --------- d-----w C:\Program Files\Boonty
2008-05-11 08:43 --------- d-----w C:\Program Files\BitTorrent
2008-05-09 16:15 --------- d-----w C:\Program Files\Lecteur CANALPLAY
2008-05-09 16:14 --------- d-----w C:\Program Files\PokerStars
2008-05-09 16:13 --------- d-----w C:\Program Files\RenMultiFiles Pro
2008-05-09 15:59 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-25 19:55 --------- d-----w C:\Program Files\3ds max
2008-04-20 21:11 --------- d-----w C:\Documents and Settings\Mahnie\Application Data\combustion4
2008-04-19 21:13 17,408 ----a-w C:\psapi.dll
2008-04-19 16:39 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-04-19 13:36 --------- d-----w C:\Documents and Settings\Mahnie\Application Data\Azureus
2008-04-06 11:26 --------- d-----w C:\Program Files\Fichiers communs\Sony MXF Filters
2008-04-06 11:25 --------- d-----w C:\Program Files\Quantel
2008-04-06 11:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Quantel
2008-03-14 11:07 --------- d-----w C:\Program Files\TomTom HOME 2
2008-03-14 11:07 --------- d-----w C:\Documents and Settings\Mahnie\Application Data\TomTom
2008-03-14 11:06 --------- d-----w C:\Program Files\TomTom HOME
2008-02-28 21:36 36,216 ----a-w C:\Documents and Settings\Mahnie\Application Data\wklnhst.dat
2006-05-22 21:30 67,008 ----a-w C:\Documents and Settings\Mahnie\Application Data\GDIPFONTCACHEV1.DAT
2005-07-01 21:58 4,096 ----a-w C:\Documents and Settings\Mahnie\log.dat
2005-01-18 02:21 1,416 ----a-w C:\Program Files\GenesisConfig.dat
2002-02-13 15:04 110,592 ----a-w C:\Program Files\internet explorer\plugins\CAPWebActiveX.dll
2006-10-11 10:35 56 --sh--r C:\WINDOWS\system32\95B28A1EE6.sys
2006-10-11 10:35 11,894 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ÇlÇments vides & les ÇlÇments initiaux lÇgitimes ne sont pas listÇs
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TomTomHOME.exe"="C:\Program Files\TomTom HOME 2\HOMERunner.exe" [2008-02-18 12:58 206184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 12:01 88209 C:\WINDOWS\AGRSMMSG.exe]
"Dit"="Dit.exe" [2004-04-02 13:31 86016 C:\WINDOWS\Dit.exe]
"ledpointer"="CNYHKey.exe" [2004-02-03 18:15 5794816 C:\WINDOWS\CNYHKey.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-12 22:10 339968]
"Norman ZANDA"="C:\Norman\Npm\bin\ZLH.exe" [2007-08-09 14:40 183352]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58 282624]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.yv12"= yv12vfw.dll
"vidc.X264"= x264vfw.dll
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
"updateMgr"=C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Picasa Media Detector"=C:\Program Files\Picasa2\PicasaMediaDetector.exe
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe
"CHotkey"=mHotkey.exe
"PCMService"="C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
"SPAMfighter Agent"="C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
"TomTomHOME.exe"="C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
"BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
"CanalPlayerHelper"=C:\Program Files\Lecteur CANALPLAY\CanalPlayerHelper.exe
"FileZilla Server Interface"="C:\Program Files\FileZilla Server\FileZilla Server Interface.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"C:\\Program Files\\Outlook Express\\msimn.exe"=
"C:\\Program Files\\discreet\\combustion 3\\combustion.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\3ds max\\3dsmax.exe"=
"C:\\Program Files\\backburner 2\\manager.exe"=
"C:\\Program Files\\backburner 2\\monitor.exe"=
"C:\\Program Files\\backburner 2\\server.exe"=
"C:\\Program Files\\discreet\\combustion 4\\combustion.exe"=
"C:\\Program Files\\FileZilla\\FileZilla.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\neuf telecom\\MP9 Premium\\MP9Premium.exe"=
"C:\\Program Files\\Media Player Classic\\mplayerc.exe"=
"C:\\Program Files\\Fusion\\eyeonScript.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\TYPSoft FTP Server\\ftpserv.exe"=
"C:\Program Files\Neuf\Media Center\httpd\httpd.exe"= C:\Program Files\Neuf\Media Center\httpd\httpd.exe:172.16.255.0/255.255.255.0,192.168.1.2/255.255.255.255:Enabled:Serveur de partage Media Center (Player Neuf Cegetel)
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"139:TCP"= 139:TCP:LocalSubNet,172.16.255.0/255.255.255.0:Enabled:@xpsp2res.dll,-22004
"445:TCP"= 445:TCP:LocalSubNet,172.16.255.0/255.255.255.0:Enabled:@xpsp2res.dll,-22005
"137:UDP"= 137:UDP:LocalSubNet,172.16.255.0/255.255.255.0:Enabled:@xpsp2res.dll,-22001
"138:UDP"= 138:UDP:LocalSubNet,172.16.255.0/255.255.255.0:Enabled:@xpsp2res.dll,-22002
"26180:TCP"= 26180:TCP:neuf telecom
"26181:TCP"= 26181:TCP:neuf telecom
"9876:TCP"= 9876:TCP:neuf telecom
"26190:UDP"= 26190:UDP:SesamTV PVR
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
R2 Ndiskio;Ndiskio;C:\Norman\Nse\bin\NDISKIO.SYS [2007-01-02 10:55]
R3 Cap7134;MEDION (7134) WDM Video Capture;C:\WINDOWS\system32\DRIVERS\Cap7134.sys [2003-06-05 09:04]
R3 CardReaderFilter;Card Reader Filter;C:\WINDOWS\system32\Drivers\USBCRFT.SYS [2008-05-12 01:42]
R3 cmudax;C-Media High Definition Audio Interface;C:\WINDOWS\system32\drivers\cmudax.sys [2004-10-01 14:58]
R3 LaCieFWFilter;Silver 1394 Filter (1394 BUS Filter Driver);C:\WINDOWS\system32\DRIVERS\LaCieFWFilter.sys [2005-10-18 07:28]
R3 LaCieUSBFilter;Silver USB Filter (USB BUS Filter Driver);C:\WINDOWS\system32\DRIVERS\LaCieUSBFilter.sys [2005-10-19 08:34]
R3 NvcMFlt;NvcMFlt;C:\WINDOWS\system32\DRIVERS\nvcw32mf.sys [2007-07-09 10:50]
R3 nvcoas;Norman Virus Control on-access component;C:\Norman\Nvc\bin\nvcoas.exe [2007-07-12 11:38]
R3 NVCScheduler;Norman Virus Control Scheduler;C:\Norman\Nvc\BIN\NVCSCHED.EXE [2007-05-23 13:23]
R3 PhTVTune;MEDION TV-TUNER 7134 MK2/3;C:\WINDOWS\system32\DRIVERS\PhTVTune.sys [2003-06-12 09:47]
R3 PRISM_A00;CREATIX 802.11g Driver;C:\WINDOWS\system32\DRIVERS\PRISMA00.sys [2004-01-16 10:31]
R3 UKBFLT;UKBFLT;C:\WINDOWS\system32\DRIVERS\UKBFLT.sys [2003-12-19 18:13]
S3 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" [2007-03-24 21:59]
S3 MBAMCatchMe;MBAMCatchMe;C:\WINDOWS\system32\drivers\mbamcatchme.sys [2008-05-05 20:46]
S3 nvcfsr;nvcfsr;C:\Norman\Nvc\bin\nvcfsr.sys [2007-01-09 15:25]
S3 nvcoafl51;nvcoafl51;C:\Norman\Nvc\bin\nvcoafl51.sys [2007-01-09 15:25]
S3 nvcoaft51;nvcoaft51;C:\Norman\Nvc\bin\nvcoaft51.sys [2007-01-09 15:25]
S3 nvcoarc51;nvcoarc51;C:\Norman\Nvc\bin\nvcoarc51.sys [2007-01-09 15:25]
S3 phil2vid;Appareil photo VGA USB Philips PCVC690;C:\WINDOWS\system32\DRIVERS\philcam2.sys [2001-08-17 23:04]
S3 w300bus;Sony Ericsson W300 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\w300bus.sys [2006-03-13 16:49]
S3 w300mdfl;Sony Ericsson W300 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w300mdfl.sys [2006-03-13 16:50]
S3 w300mdm;Sony Ericsson W300 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w300mdm.sys [2006-03-13 16:50]
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w300mgmt.sys [2006-03-13 16:50]
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w300obex.sys [2006-03-13 16:50]
S3 xbreader;ActionReplay XBox Driver (xbreader.sys);C:\WINDOWS\system32\Drivers\xbreader.sys [2001-01-02 23:53]
S4 BackRenderServicev18;ColorFront Background Render v1.8;C:\Program Files\discreet\lustre\Service.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2348B595-E675-43E5-0601-010400040806}]
C:\WINDOWS\system32\yahoo.exe
.
Contenu du dossier 'Scheduled Tasks/TÉches planifiÇes'
"2008-03-12 10:58:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-07-30 16:34:32 C:\WINDOWS\Tasks\SesamTVMC.job"
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-12 01:42:47
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachÇs ...
Balayage cachÇ autostart entries ...
Balayage des fichiers cachÇs ...
Scan terminÇ avec succäs
Les fichiers cachÇs: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Norman\npm\bin\elogsvc.exe
C:\Norman\npm\bin\Zanda.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\FileZilla Server\FileZilla server.exe
C:\WINDOWS\system32\snmp.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Norman\npm\bin\Njeeves.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Norman\NVC\bin\Nip.exe
C:\Norman\NVC\bin\CClaw.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-05-12 1:46:24 - machine was rebooted [Mahnie]
ComboFix-quarantined-files.txt 2008-05-11 23:46:18
Pre-Run: 19,258,015,744 octets libres
Post-Run: 19,327,913,984 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP êdition familiale" /fastdetect /NoExecute=OptOut
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
249 --- E O F --- 2008-02-27 16:46:43
Voila, j'espere qu'il est gueri!!!
Merci de votre aide
mahnie
J'ai fait:
-VundoFix, et il ne m'a rien trouvé, donc j'ai pas de rapport.
-VirtumondoBeGone, voici le log:
[05/12/2008, 1:02:29] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Mahnie\Bureau\VirtumundoBeGone.exe" )
[05/12/2008, 1:02:48] - Detected System Information:
[05/12/2008, 1:02:48] - Windows Version: 5.1.2600, Service Pack 2
[05/12/2008, 1:02:48] - Current Username: Mahnie (Admin)
[05/12/2008, 1:02:48] - Windows is in NORMAL mode.
[05/12/2008, 1:02:48] - Searching for Browser Helper Objects:
[05/12/2008, 1:02:48] - BHO 1: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[05/12/2008, 1:02:48] - BHO 2: {96367F29-207F-40DC-9C39-6D8E836B1AB3} ()
[05/12/2008, 1:02:48] - WARNING: BHO has no default name. Checking for Winlogon reference.
[05/12/2008, 1:02:48] - Checking for HKLM\...\Winlogon\Notify\pmnnKCrO
[05/12/2008, 1:02:48] - Key not found: HKLM\...\Winlogon\Notify\pmnnKCrO, continuing.
[05/12/2008, 1:02:48] - Finished Searching Browser Helper Objects
[05/12/2008, 1:02:48] - Finishing up...
[05/12/2008, 1:02:48] - Nothing found! Exiting...
-Combofix, voici le log:
ComboFix 08-05-11.1 - Mahnie 2008-05-12 1:36:08.1 - NTFSx86
Microsoft Windows XP …dition familiale 5.1.2600.2.1252.1.1036.18.457 [GMT 2:00]
Endroit: C:\Documents and Settings\Mahnie\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mahnie\Bureau\WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
* CrÈation d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\fcadvice
C:\Program Files\fcadvice\patterns.dat
C:\Program Files\fcadvice\Uninstall.exe
C:\WINDOWS\pack.epk
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\gswgqvrn.ini
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mnmlyigt.ini
C:\WINDOWS\system32\OrCKnnmp.ini
C:\WINDOWS\system32\OrCKnnmp.ini2
C:\WINDOWS\system32\pmnnKCrO.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\pWDLkUvw.ini
C:\WINDOWS\system32\pWDLkUvw.ini2
c:\WINDOWS\system32\zpjthwuyu.dat
c:\windows\system32\zpjthwuyu.exe
c:\WINDOWS\system32\zpjthwuyu_navps.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Service_NPF
((((((((((((((((((((((((((((( Fichiers crÇÇs 2008-04-11 to 2008-05-11 ))))))))))))))))))))))))))))))))))))
.
C:\ComboFix\CreateC00.bat .
2008-05-12 00:49 . 2008-05-12 00:49 <REP> d-------- C:\VundoFix Backups
2008-05-11 12:45 . 2008-05-11 12:45 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-11 12:45 . 2008-05-11 12:45 <REP> d-------- C:\Documents and Settings\Mahnie\Application Data\Malwarebytes
2008-05-11 12:45 . 2008-05-11 12:45 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-11 12:45 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-11 12:45 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-11 12:05 . 2008-05-11 12:05 <REP> d-------- C:\Program Files\Trend Micro
2008-05-09 15:34 . 2008-05-09 15:34 <REP> d-------- C:\Program Files\Alwil Software
2008-05-09 14:51 . 2008-05-09 14:51 2,048 --a------ C:\WINDOWS\system32\xucbhdhl.exe
2008-05-09 12:11 . 2008-05-09 12:11 2,048 --a------ C:\WINDOWS\system32\cyivgnhm.exe
2008-04-25 22:53 . 2008-05-04 13:04 443 --a------ C:\WINDOWS\wininit.ini
2008-04-21 00:55 . 2008-04-21 00:55 <REP> d-------- C:\Documents and Settings\Mahnie\Application Data\Canon
2008-04-21 00:50 . 2008-04-21 00:50 <REP> d-------- C:\Documents and Settings\Mahnie\Application Data\ZoomBrowser EX
2008-04-20 23:39 . 2008-04-20 23:39 <REP> d-------- C:\Documents and Settings\All Users\Application Data\ZoomBrowser
2008-04-20 23:37 . 2008-04-20 23:37 <REP> d-------- C:\Program Files\Fichiers communs\Canon
2008-04-20 23:37 . 2008-04-20 23:40 <REP> d-------- C:\Program Files\Canon
2008-04-20 15:35 . 2008-04-25 21:52 594 ---hs---- C:\WINDOWS\system32\oymmrnsb.ini
2008-04-20 15:30 . 2008-05-11 11:02 109,738 --a------ C:\WINDOWS\BMbb971fa2.xml
2008-04-19 23:38 . 2008-04-19 23:38 <REP> d-------- C:\Program Files\LaCieTools
2008-04-19 23:38 . 2005-10-19 08:34 15,872 --a------ C:\WINDOWS\system32\drivers\LaCieUSBFilter.sys
2008-04-19 23:38 . 2005-10-18 07:28 14,848 --a------ C:\WINDOWS\system32\drivers\LaCieFWFilter.sys
2008-04-19 23:38 . 2002-07-26 16:02 6,752 --a------ C:\UNWISE.INI
2008-04-19 23:38 . 2008-04-19 23:38 640 --a------ C:\WINDOWS\UndeviceUpd
2008-04-19 18:39 . 2008-04-19 18:39 <REP> d-------- C:\Program Files\Bonjour
2008-04-19 18:25 . 2008-04-19 18:25 <REP> d-------- C:\Program Files\Fichiers communs\Macrovision Shared
2008-04-19 15:50 . 2008-04-19 15:50 <REP> d-------- C:\Documents and Settings\Mahnie\.DownloadManager
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-11 23:42 13,440 ----a-w C:\WINDOWS\system32\drivers\USBCRFT.SYS
2008-05-11 10:35 --------- d-----w C:\Program Files\freeCommander2006
2008-05-11 08:52 --------- d-----w C:\Program Files\ewido anti-malware
2008-05-11 08:43 --------- d-----w C:\Program Files\Boonty
2008-05-11 08:43 --------- d-----w C:\Program Files\BitTorrent
2008-05-09 16:15 --------- d-----w C:\Program Files\Lecteur CANALPLAY
2008-05-09 16:14 --------- d-----w C:\Program Files\PokerStars
2008-05-09 16:13 --------- d-----w C:\Program Files\RenMultiFiles Pro
2008-05-09 15:59 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-25 19:55 --------- d-----w C:\Program Files\3ds max
2008-04-20 21:11 --------- d-----w C:\Documents and Settings\Mahnie\Application Data\combustion4
2008-04-19 21:13 17,408 ----a-w C:\psapi.dll
2008-04-19 16:39 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-04-19 13:36 --------- d-----w C:\Documents and Settings\Mahnie\Application Data\Azureus
2008-04-06 11:26 --------- d-----w C:\Program Files\Fichiers communs\Sony MXF Filters
2008-04-06 11:25 --------- d-----w C:\Program Files\Quantel
2008-04-06 11:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Quantel
2008-03-14 11:07 --------- d-----w C:\Program Files\TomTom HOME 2
2008-03-14 11:07 --------- d-----w C:\Documents and Settings\Mahnie\Application Data\TomTom
2008-03-14 11:06 --------- d-----w C:\Program Files\TomTom HOME
2008-02-28 21:36 36,216 ----a-w C:\Documents and Settings\Mahnie\Application Data\wklnhst.dat
2006-05-22 21:30 67,008 ----a-w C:\Documents and Settings\Mahnie\Application Data\GDIPFONTCACHEV1.DAT
2005-07-01 21:58 4,096 ----a-w C:\Documents and Settings\Mahnie\log.dat
2005-01-18 02:21 1,416 ----a-w C:\Program Files\GenesisConfig.dat
2002-02-13 15:04 110,592 ----a-w C:\Program Files\internet explorer\plugins\CAPWebActiveX.dll
2006-10-11 10:35 56 --sh--r C:\WINDOWS\system32\95B28A1EE6.sys
2006-10-11 10:35 11,894 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ÇlÇments vides & les ÇlÇments initiaux lÇgitimes ne sont pas listÇs
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TomTomHOME.exe"="C:\Program Files\TomTom HOME 2\HOMERunner.exe" [2008-02-18 12:58 206184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AGRSMMSG"="AGRSMMSG.exe" [2005-03-04 12:01 88209 C:\WINDOWS\AGRSMMSG.exe]
"Dit"="Dit.exe" [2004-04-02 13:31 86016 C:\WINDOWS\Dit.exe]
"ledpointer"="CNYHKey.exe" [2004-02-03 18:15 5794816 C:\WINDOWS\CNYHKey.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-12 22:10 339968]
"Norman ZANDA"="C:\Norman\Npm\bin\ZLH.exe" [2007-08-09 14:40 183352]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58 282624]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.yv12"= yv12vfw.dll
"vidc.X264"= x264vfw.dll
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
"updateMgr"=C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe
"SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Picasa Media Detector"=C:\Program Files\Picasa2\PicasaMediaDetector.exe
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe"
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe
"CHotkey"=mHotkey.exe
"PCMService"="C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
"SPAMfighter Agent"="C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
"TomTomHOME.exe"="C:\Program Files\TomTom HOME\TomTomHOME.exe" -s
"BluetoothAuthenticationAgent"=rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
"CanalPlayerHelper"=C:\Program Files\Lecteur CANALPLAY\CanalPlayerHelper.exe
"FileZilla Server Interface"="C:\Program Files\FileZilla Server\FileZilla Server Interface.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"C:\\Program Files\\Outlook Express\\msimn.exe"=
"C:\\Program Files\\discreet\\combustion 3\\combustion.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\3ds max\\3dsmax.exe"=
"C:\\Program Files\\backburner 2\\manager.exe"=
"C:\\Program Files\\backburner 2\\monitor.exe"=
"C:\\Program Files\\backburner 2\\server.exe"=
"C:\\Program Files\\discreet\\combustion 4\\combustion.exe"=
"C:\\Program Files\\FileZilla\\FileZilla.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\neuf telecom\\MP9 Premium\\MP9Premium.exe"=
"C:\\Program Files\\Media Player Classic\\mplayerc.exe"=
"C:\\Program Files\\Fusion\\eyeonScript.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\TYPSoft FTP Server\\ftpserv.exe"=
"C:\Program Files\Neuf\Media Center\httpd\httpd.exe"= C:\Program Files\Neuf\Media Center\httpd\httpd.exe:172.16.255.0/255.255.255.0,192.168.1.2/255.255.255.255:Enabled:Serveur de partage Media Center (Player Neuf Cegetel)
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"139:TCP"= 139:TCP:LocalSubNet,172.16.255.0/255.255.255.0:Enabled:@xpsp2res.dll,-22004
"445:TCP"= 445:TCP:LocalSubNet,172.16.255.0/255.255.255.0:Enabled:@xpsp2res.dll,-22005
"137:UDP"= 137:UDP:LocalSubNet,172.16.255.0/255.255.255.0:Enabled:@xpsp2res.dll,-22001
"138:UDP"= 138:UDP:LocalSubNet,172.16.255.0/255.255.255.0:Enabled:@xpsp2res.dll,-22002
"26180:TCP"= 26180:TCP:neuf telecom
"26181:TCP"= 26181:TCP:neuf telecom
"9876:TCP"= 9876:TCP:neuf telecom
"26190:UDP"= 26190:UDP:SesamTV PVR
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
R2 Ndiskio;Ndiskio;C:\Norman\Nse\bin\NDISKIO.SYS [2007-01-02 10:55]
R3 Cap7134;MEDION (7134) WDM Video Capture;C:\WINDOWS\system32\DRIVERS\Cap7134.sys [2003-06-05 09:04]
R3 CardReaderFilter;Card Reader Filter;C:\WINDOWS\system32\Drivers\USBCRFT.SYS [2008-05-12 01:42]
R3 cmudax;C-Media High Definition Audio Interface;C:\WINDOWS\system32\drivers\cmudax.sys [2004-10-01 14:58]
R3 LaCieFWFilter;Silver 1394 Filter (1394 BUS Filter Driver);C:\WINDOWS\system32\DRIVERS\LaCieFWFilter.sys [2005-10-18 07:28]
R3 LaCieUSBFilter;Silver USB Filter (USB BUS Filter Driver);C:\WINDOWS\system32\DRIVERS\LaCieUSBFilter.sys [2005-10-19 08:34]
R3 NvcMFlt;NvcMFlt;C:\WINDOWS\system32\DRIVERS\nvcw32mf.sys [2007-07-09 10:50]
R3 nvcoas;Norman Virus Control on-access component;C:\Norman\Nvc\bin\nvcoas.exe [2007-07-12 11:38]
R3 NVCScheduler;Norman Virus Control Scheduler;C:\Norman\Nvc\BIN\NVCSCHED.EXE [2007-05-23 13:23]
R3 PhTVTune;MEDION TV-TUNER 7134 MK2/3;C:\WINDOWS\system32\DRIVERS\PhTVTune.sys [2003-06-12 09:47]
R3 PRISM_A00;CREATIX 802.11g Driver;C:\WINDOWS\system32\DRIVERS\PRISMA00.sys [2004-01-16 10:31]
R3 UKBFLT;UKBFLT;C:\WINDOWS\system32\DRIVERS\UKBFLT.sys [2003-12-19 18:13]
S3 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" [2007-03-24 21:59]
S3 MBAMCatchMe;MBAMCatchMe;C:\WINDOWS\system32\drivers\mbamcatchme.sys [2008-05-05 20:46]
S3 nvcfsr;nvcfsr;C:\Norman\Nvc\bin\nvcfsr.sys [2007-01-09 15:25]
S3 nvcoafl51;nvcoafl51;C:\Norman\Nvc\bin\nvcoafl51.sys [2007-01-09 15:25]
S3 nvcoaft51;nvcoaft51;C:\Norman\Nvc\bin\nvcoaft51.sys [2007-01-09 15:25]
S3 nvcoarc51;nvcoarc51;C:\Norman\Nvc\bin\nvcoarc51.sys [2007-01-09 15:25]
S3 phil2vid;Appareil photo VGA USB Philips PCVC690;C:\WINDOWS\system32\DRIVERS\philcam2.sys [2001-08-17 23:04]
S3 w300bus;Sony Ericsson W300 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\w300bus.sys [2006-03-13 16:49]
S3 w300mdfl;Sony Ericsson W300 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w300mdfl.sys [2006-03-13 16:50]
S3 w300mdm;Sony Ericsson W300 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w300mdm.sys [2006-03-13 16:50]
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w300mgmt.sys [2006-03-13 16:50]
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w300obex.sys [2006-03-13 16:50]
S3 xbreader;ActionReplay XBox Driver (xbreader.sys);C:\WINDOWS\system32\Drivers\xbreader.sys [2001-01-02 23:53]
S4 BackRenderServicev18;ColorFront Background Render v1.8;C:\Program Files\discreet\lustre\Service.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2348B595-E675-43E5-0601-010400040806}]
C:\WINDOWS\system32\yahoo.exe
.
Contenu du dossier 'Scheduled Tasks/TÉches planifiÇes'
"2008-03-12 10:58:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-07-30 16:34:32 C:\WINDOWS\Tasks\SesamTVMC.job"
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-12 01:42:47
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachÇs ...
Balayage cachÇ autostart entries ...
Balayage des fichiers cachÇs ...
Scan terminÇ avec succäs
Les fichiers cachÇs: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Norman\npm\bin\elogsvc.exe
C:\Norman\npm\bin\Zanda.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\FileZilla Server\FileZilla server.exe
C:\WINDOWS\system32\snmp.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Norman\npm\bin\Njeeves.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Norman\NVC\bin\Nip.exe
C:\Norman\NVC\bin\CClaw.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-05-12 1:46:24 - machine was rebooted [Mahnie]
ComboFix-quarantined-files.txt 2008-05-11 23:46:18
Pre-Run: 19,258,015,744 octets libres
Post-Run: 19,327,913,984 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP êdition familiale" /fastdetect /NoExecute=OptOut
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
249 --- E O F --- 2008-02-27 16:46:43
Voila, j'espere qu'il est gueri!!!
Merci de votre aide
mahnie
mahnie
Messages postés
8
Date d'inscription
dimanche 11 mai 2008
Statut
Membre
Dernière intervention
13 mai 2008
12 mai 2008 à 20:18
12 mai 2008 à 20:18
Salut,
Comme je n'ai pas eue de reponses, je suppose qu'il n'y a plus de problemes. Pouvez vous juste me laisser un message pour que je sache si c'est ok?
Merci d'avance.
Encore merci.
mahnie
Comme je n'ai pas eue de reponses, je suppose qu'il n'y a plus de problemes. Pouvez vous juste me laisser un message pour que je sache si c'est ok?
Merci d'avance.
Encore merci.
mahnie
Utilisateur anonyme
12 mai 2008 à 22:13
12 mai 2008 à 22:13
salut
analyse ces fichiers sur virustotal 1 par 1 et colle le rapport de ces3 fichiers , voir ici :
https://www.virustotal.com/gui/
clicsur parcourir,1 fenetre va s'ouvrir et cherche ceci , le 1er ...clic sur envoyer le fichier ...patiente ...1 fois l'analyse faite colle le rapport etfais de même pour les 2 autres fichiers
fichiers :
C:\WINDOWS\system32\xucbhdhl.exe
C:\WINDOWS\system32\cyivgnhm.exe
C:\WINDOWS\system32\oymmrnsb.ini
bizz
analyse ces fichiers sur virustotal 1 par 1 et colle le rapport de ces3 fichiers , voir ici :
https://www.virustotal.com/gui/
clicsur parcourir,1 fenetre va s'ouvrir et cherche ceci , le 1er ...clic sur envoyer le fichier ...patiente ...1 fois l'analyse faite colle le rapport etfais de même pour les 2 autres fichiers
fichiers :
C:\WINDOWS\system32\xucbhdhl.exe
C:\WINDOWS\system32\cyivgnhm.exe
C:\WINDOWS\system32\oymmrnsb.ini
bizz
mahnie
Messages postés
8
Date d'inscription
dimanche 11 mai 2008
Statut
Membre
Dernière intervention
13 mai 2008
13 mai 2008 à 21:30
13 mai 2008 à 21:30
Salut,
voici les 3 log dans le meme ordre que dans ton message :
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.5.10.0 2008.05.13 -
AntiVir 7.8.0.17 2008.05.13 -
Authentium 5.1.0.4 2008.05.13 -
Avast 4.8.1169.0 2008.05.12 -
AVG 7.5.0.516 2008.05.12 Generic10.UDV
BitDefender 7.2 2008.05.08 -
CAT-QuickHeal 9.50 2008.05.12 -
ClamAV 0.92.1 2008.05.12 -
DrWeb 4.44.0.09170 2008.05.13 -
eSafe 7.0.15.0 2008.05.12 -
eTrust-Vet 31.4.5783 2008.05.12 -
Ewido 4.0 2008.05.12 -
F-Prot 4.4.2.54 2008.05.13 -
F-Secure 6.70.13260.0 2008.05.13 -
Fortinet 3.14.0.0 2008.05.13 W32/Vundou.ZAE!tr
GData 2.0.7306.1023 2008.05.13 -
Ikarus T3.1.1.26.0 2008.05.13 Trojan.Crypt.XPACK
Kaspersky 7.0.0.125 2008.05.13 -
McAfee 5293 2008.05.12 -
Microsoft 1.3408 2008.05.13 -
NOD32v2 3094 2008.05.12 Win32/PrivacySet.A
Norman 5.80.02 2008.05.09 W32/Smalltroj.EGXV
Panda 9.0.0.4 2008.05.12 Trj/Agent.ITR
Prevx1 V2 2008.05.13 Malicious Software
Rising 20.44.10.00 2008.05.13 -
Sophos 4.29.0 2008.05.13 Troj/PrivZone-A
Sunbelt 3.0.1114.0 2008.05.12 -
Symantec 10 2008.05.13 -
TheHacker 6.2.92.309 2008.05.13 -
VBA32 3.12.6.5 2008.05.12 -
VirusBuster 4.3.26:9 2008.05.12 -
Webwasher-Gateway 6.6.2 2008.05.13 Win32.Malware.gen!80 (suspicious)
Information additionnelle
File size: 2048 bytes
MD5...: 5a3b18025b98839909f0b549778d3cbf
SHA1..: 2aa51c6d57b2bb0d4b8b7f509a7e54961fc961e4
SHA256: a554b5b6fbf42e9a6614269c821aa33dbad9a956bdcf0246d6c433915e05df86
SHA512: d14abf3cb4d51216b31ae149badced932bcd4e516aff891783ccb6e564dee0d3
f782d11fd7cda6894b0eec0b23969421727698d02d712f42135abde4d0edac19
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x4003bc
timedatestamp.....: 0x481efb0f (Mon May 05 12:18:23 2008)
machinetype.......: 0x14c (I386)
( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x300 0x100 0x100 5.61 a41be52b475dfb013265b8b57025f995
.rdata 0x400 0x56 0x100 1.94 68d8c02b103700290ea8f3edd062f675
INIT 0x500 0x8e 0x100 2.56 0ea0b8b784d0ab9865f99165ef5808a7
.rsrc 0x600 0xb0 0x100 4.51 f69dace89ec47d43460b9c59b53ac76f
.reloc 0x700 0x20 0x100 0.47 919c4ebdb9f32d2f76bfdc55608301be
( 1 imports )
> KERNEL32.dll: LoadLibraryA, GetProcAddress, ExitProcess, GetModuleHandleA
( 0 exports )
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=55E8360A0031C9FB08AB0039378BBA00B79BCD14
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.5.10.0 2008.05.13 -
AntiVir 7.8.0.17 2008.05.13 -
Authentium 5.1.0.4 2008.05.13 -
Avast 4.8.1169.0 2008.05.12 -
AVG 7.5.0.516 2008.05.12 Generic10.UDV
BitDefender 7.2 2008.05.08 -
CAT-QuickHeal 9.50 2008.05.12 -
ClamAV 0.92.1 2008.05.12 -
DrWeb 4.44.0.09170 2008.05.13 -
eSafe 7.0.15.0 2008.05.12 -
eTrust-Vet 31.4.5783 2008.05.12 -
Ewido 4.0 2008.05.12 -
F-Prot 4.4.2.54 2008.05.13 -
F-Secure 6.70.13260.0 2008.05.13 -
Fortinet 3.14.0.0 2008.05.13 W32/Vundou.ZAE!tr
GData 2.0.7306.1023 2008.05.13 -
Ikarus T3.1.1.26.0 2008.05.13 Trojan.Crypt.XPACK
Kaspersky 7.0.0.125 2008.05.13 -
McAfee 5293 2008.05.12 -
Microsoft 1.3408 2008.05.13 -
NOD32v2 3094 2008.05.12 Win32/PrivacySet.A
Norman 5.80.02 2008.05.09 W32/Smalltroj.EGXV
Panda 9.0.0.4 2008.05.12 Trj/Agent.ITR
Prevx1 V2 2008.05.13 Malicious Software
Rising 20.44.10.00 2008.05.13 -
Sophos 4.29.0 2008.05.13 Troj/PrivZone-A
Sunbelt 3.0.1114.0 2008.05.12 -
Symantec 10 2008.05.13 -
TheHacker 6.2.92.309 2008.05.13 -
VBA32 3.12.6.5 2008.05.12 -
VirusBuster 4.3.26:9 2008.05.12 -
Webwasher-Gateway 6.6.2 2008.05.13 Win32.Malware.gen!80 (suspicious)
Information additionnelle
File size: 2048 bytes
MD5...: 5a3b18025b98839909f0b549778d3cbf
SHA1..: 2aa51c6d57b2bb0d4b8b7f509a7e54961fc961e4
SHA256: a554b5b6fbf42e9a6614269c821aa33dbad9a956bdcf0246d6c433915e05df86
SHA512: d14abf3cb4d51216b31ae149badced932bcd4e516aff891783ccb6e564dee0d3
f782d11fd7cda6894b0eec0b23969421727698d02d712f42135abde4d0edac19
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x4003bc
timedatestamp.....: 0x481efb0f (Mon May 05 12:18:23 2008)
machinetype.......: 0x14c (I386)
( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x300 0x100 0x100 5.61 a41be52b475dfb013265b8b57025f995
.rdata 0x400 0x56 0x100 1.94 68d8c02b103700290ea8f3edd062f675
INIT 0x500 0x8e 0x100 2.56 0ea0b8b784d0ab9865f99165ef5808a7
.rsrc 0x600 0xb0 0x100 4.51 f69dace89ec47d43460b9c59b53ac76f
.reloc 0x700 0x20 0x100 0.47 919c4ebdb9f32d2f76bfdc55608301be
( 1 imports )
> KERNEL32.dll: LoadLibraryA, GetProcAddress, ExitProcess, GetModuleHandleA
( 0 exports )
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=55E8360A0031C9FB08AB0039378BBA00B79BCD14
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.5.10.0 2008.05.13 -
AntiVir 7.8.0.17 2008.05.13 -
Authentium 5.1.0.4 2008.05.13 -
Avast 4.8.1195.0 2008.05.13 -
AVG 7.5.0.516 2008.05.13 -
BitDefender 7.2 2008.05.08 -
CAT-QuickHeal 9.50 2008.05.13 -
ClamAV 0.92.1 2008.05.13 -
DrWeb 4.44.0.09170 2008.05.13 -
eSafe 7.0.15.0 2008.05.13 -
eTrust-Vet 31.4.5784 2008.05.13 -
Ewido 4.0 2008.05.13 -
F-Prot 4.4.2.54 2008.05.13 -
F-Secure 6.70.13260.0 2008.05.13 -
Fortinet 3.14.0.0 2008.05.13 -
GData 2.0.7306.1023 2008.05.13 -
Ikarus T3.1.1.26.0 2008.05.13 -
Kaspersky 7.0.0.125 2008.05.13 -
McAfee 5294 2008.05.13 -
Microsoft 1.3520 2008.05.13 -
NOD32v2 3096 2008.05.13 -
Norman 5.80.02 2008.05.13 -
Panda 9.0.0.4 2008.05.12 -
Prevx1 V2 2008.05.13 -
Rising 20.44.12.00 2008.05.13 -
Sophos 4.29.0 2008.05.13 -
Sunbelt 3.0.1114.0 2008.05.12 -
Symantec 10 2008.05.13 -
TheHacker 6.2.92.309 2008.05.13 -
VBA32 3.12.6.6 2008.05.13 -
VirusBuster 4.3.26:9 2008.05.13 -
Webwasher-Gateway 6.6.2 2008.05.13 -
Information additionnelle
File size: 594 bytes
MD5...: ff152eb35374d4ea8ae9a33f1b93d163
SHA1..: 7183a8718a3f14602fd501573c8d7caae5496c49
SHA256: a4ab86f36865e7eba2dc5331001b068f138c5a3b7493ebd00a89519b1898986f
SHA512: f72035fd067bc8723b30819dfb573b9233e44024a58c71284f85133a00cab551
b234275c2266b3a4f19f713e8989c95adda8d35a0ffb3fb6b9efab800fa03a45
PEiD..: -
PEInfo: -
Merci de ton aide.
Mahnie
voici les 3 log dans le meme ordre que dans ton message :
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.5.10.0 2008.05.13 -
AntiVir 7.8.0.17 2008.05.13 -
Authentium 5.1.0.4 2008.05.13 -
Avast 4.8.1169.0 2008.05.12 -
AVG 7.5.0.516 2008.05.12 Generic10.UDV
BitDefender 7.2 2008.05.08 -
CAT-QuickHeal 9.50 2008.05.12 -
ClamAV 0.92.1 2008.05.12 -
DrWeb 4.44.0.09170 2008.05.13 -
eSafe 7.0.15.0 2008.05.12 -
eTrust-Vet 31.4.5783 2008.05.12 -
Ewido 4.0 2008.05.12 -
F-Prot 4.4.2.54 2008.05.13 -
F-Secure 6.70.13260.0 2008.05.13 -
Fortinet 3.14.0.0 2008.05.13 W32/Vundou.ZAE!tr
GData 2.0.7306.1023 2008.05.13 -
Ikarus T3.1.1.26.0 2008.05.13 Trojan.Crypt.XPACK
Kaspersky 7.0.0.125 2008.05.13 -
McAfee 5293 2008.05.12 -
Microsoft 1.3408 2008.05.13 -
NOD32v2 3094 2008.05.12 Win32/PrivacySet.A
Norman 5.80.02 2008.05.09 W32/Smalltroj.EGXV
Panda 9.0.0.4 2008.05.12 Trj/Agent.ITR
Prevx1 V2 2008.05.13 Malicious Software
Rising 20.44.10.00 2008.05.13 -
Sophos 4.29.0 2008.05.13 Troj/PrivZone-A
Sunbelt 3.0.1114.0 2008.05.12 -
Symantec 10 2008.05.13 -
TheHacker 6.2.92.309 2008.05.13 -
VBA32 3.12.6.5 2008.05.12 -
VirusBuster 4.3.26:9 2008.05.12 -
Webwasher-Gateway 6.6.2 2008.05.13 Win32.Malware.gen!80 (suspicious)
Information additionnelle
File size: 2048 bytes
MD5...: 5a3b18025b98839909f0b549778d3cbf
SHA1..: 2aa51c6d57b2bb0d4b8b7f509a7e54961fc961e4
SHA256: a554b5b6fbf42e9a6614269c821aa33dbad9a956bdcf0246d6c433915e05df86
SHA512: d14abf3cb4d51216b31ae149badced932bcd4e516aff891783ccb6e564dee0d3
f782d11fd7cda6894b0eec0b23969421727698d02d712f42135abde4d0edac19
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x4003bc
timedatestamp.....: 0x481efb0f (Mon May 05 12:18:23 2008)
machinetype.......: 0x14c (I386)
( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x300 0x100 0x100 5.61 a41be52b475dfb013265b8b57025f995
.rdata 0x400 0x56 0x100 1.94 68d8c02b103700290ea8f3edd062f675
INIT 0x500 0x8e 0x100 2.56 0ea0b8b784d0ab9865f99165ef5808a7
.rsrc 0x600 0xb0 0x100 4.51 f69dace89ec47d43460b9c59b53ac76f
.reloc 0x700 0x20 0x100 0.47 919c4ebdb9f32d2f76bfdc55608301be
( 1 imports )
> KERNEL32.dll: LoadLibraryA, GetProcAddress, ExitProcess, GetModuleHandleA
( 0 exports )
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=55E8360A0031C9FB08AB0039378BBA00B79BCD14
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.5.10.0 2008.05.13 -
AntiVir 7.8.0.17 2008.05.13 -
Authentium 5.1.0.4 2008.05.13 -
Avast 4.8.1169.0 2008.05.12 -
AVG 7.5.0.516 2008.05.12 Generic10.UDV
BitDefender 7.2 2008.05.08 -
CAT-QuickHeal 9.50 2008.05.12 -
ClamAV 0.92.1 2008.05.12 -
DrWeb 4.44.0.09170 2008.05.13 -
eSafe 7.0.15.0 2008.05.12 -
eTrust-Vet 31.4.5783 2008.05.12 -
Ewido 4.0 2008.05.12 -
F-Prot 4.4.2.54 2008.05.13 -
F-Secure 6.70.13260.0 2008.05.13 -
Fortinet 3.14.0.0 2008.05.13 W32/Vundou.ZAE!tr
GData 2.0.7306.1023 2008.05.13 -
Ikarus T3.1.1.26.0 2008.05.13 Trojan.Crypt.XPACK
Kaspersky 7.0.0.125 2008.05.13 -
McAfee 5293 2008.05.12 -
Microsoft 1.3408 2008.05.13 -
NOD32v2 3094 2008.05.12 Win32/PrivacySet.A
Norman 5.80.02 2008.05.09 W32/Smalltroj.EGXV
Panda 9.0.0.4 2008.05.12 Trj/Agent.ITR
Prevx1 V2 2008.05.13 Malicious Software
Rising 20.44.10.00 2008.05.13 -
Sophos 4.29.0 2008.05.13 Troj/PrivZone-A
Sunbelt 3.0.1114.0 2008.05.12 -
Symantec 10 2008.05.13 -
TheHacker 6.2.92.309 2008.05.13 -
VBA32 3.12.6.5 2008.05.12 -
VirusBuster 4.3.26:9 2008.05.12 -
Webwasher-Gateway 6.6.2 2008.05.13 Win32.Malware.gen!80 (suspicious)
Information additionnelle
File size: 2048 bytes
MD5...: 5a3b18025b98839909f0b549778d3cbf
SHA1..: 2aa51c6d57b2bb0d4b8b7f509a7e54961fc961e4
SHA256: a554b5b6fbf42e9a6614269c821aa33dbad9a956bdcf0246d6c433915e05df86
SHA512: d14abf3cb4d51216b31ae149badced932bcd4e516aff891783ccb6e564dee0d3
f782d11fd7cda6894b0eec0b23969421727698d02d712f42135abde4d0edac19
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x4003bc
timedatestamp.....: 0x481efb0f (Mon May 05 12:18:23 2008)
machinetype.......: 0x14c (I386)
( 5 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x300 0x100 0x100 5.61 a41be52b475dfb013265b8b57025f995
.rdata 0x400 0x56 0x100 1.94 68d8c02b103700290ea8f3edd062f675
INIT 0x500 0x8e 0x100 2.56 0ea0b8b784d0ab9865f99165ef5808a7
.rsrc 0x600 0xb0 0x100 4.51 f69dace89ec47d43460b9c59b53ac76f
.reloc 0x700 0x20 0x100 0.47 919c4ebdb9f32d2f76bfdc55608301be
( 1 imports )
> KERNEL32.dll: LoadLibraryA, GetProcAddress, ExitProcess, GetModuleHandleA
( 0 exports )
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=55E8360A0031C9FB08AB0039378BBA00B79BCD14
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.5.10.0 2008.05.13 -
AntiVir 7.8.0.17 2008.05.13 -
Authentium 5.1.0.4 2008.05.13 -
Avast 4.8.1195.0 2008.05.13 -
AVG 7.5.0.516 2008.05.13 -
BitDefender 7.2 2008.05.08 -
CAT-QuickHeal 9.50 2008.05.13 -
ClamAV 0.92.1 2008.05.13 -
DrWeb 4.44.0.09170 2008.05.13 -
eSafe 7.0.15.0 2008.05.13 -
eTrust-Vet 31.4.5784 2008.05.13 -
Ewido 4.0 2008.05.13 -
F-Prot 4.4.2.54 2008.05.13 -
F-Secure 6.70.13260.0 2008.05.13 -
Fortinet 3.14.0.0 2008.05.13 -
GData 2.0.7306.1023 2008.05.13 -
Ikarus T3.1.1.26.0 2008.05.13 -
Kaspersky 7.0.0.125 2008.05.13 -
McAfee 5294 2008.05.13 -
Microsoft 1.3520 2008.05.13 -
NOD32v2 3096 2008.05.13 -
Norman 5.80.02 2008.05.13 -
Panda 9.0.0.4 2008.05.12 -
Prevx1 V2 2008.05.13 -
Rising 20.44.12.00 2008.05.13 -
Sophos 4.29.0 2008.05.13 -
Sunbelt 3.0.1114.0 2008.05.12 -
Symantec 10 2008.05.13 -
TheHacker 6.2.92.309 2008.05.13 -
VBA32 3.12.6.6 2008.05.13 -
VirusBuster 4.3.26:9 2008.05.13 -
Webwasher-Gateway 6.6.2 2008.05.13 -
Information additionnelle
File size: 594 bytes
MD5...: ff152eb35374d4ea8ae9a33f1b93d163
SHA1..: 7183a8718a3f14602fd501573c8d7caae5496c49
SHA256: a4ab86f36865e7eba2dc5331001b068f138c5a3b7493ebd00a89519b1898986f
SHA512: f72035fd067bc8723b30819dfb573b9233e44024a58c71284f85133a00cab551
b234275c2266b3a4f19f713e8989c95adda8d35a0ffb3fb6b9efab800fa03a45
PEiD..: -
PEInfo: -
Merci de ton aide.
Mahnie
Utilisateur anonyme
>
mahnie
Messages postés
8
Date d'inscription
dimanche 11 mai 2008
Statut
Membre
Dernière intervention
13 mai 2008
13 mai 2008 à 21:55
13 mai 2008 à 21:55
salut
lance ceci stp:
Télécharge OTMoveIt http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe (de Old_Timer) sur ton Bureau.
Double-clique sur OTMoveIt.exe pour le lancer.
Copie la liste qui se trouve en citation ci-dessous et colle-la dans le cadre de gauche de OTMoveIt sous Paste List of Files/Folders to move.
Citation :
C:\WINDOWS\system32\xucbhdhl.exe
C:\WINDOWS\system32\cyivgnhm.exe
C:\WINDOWS\system32\oymmrnsb.ini
clique sur MoveIt! pour lancer la suppression.
Le résultat apparaitra dans le cadre "Results".
Clique sur Exit pour fermer.
Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
Il te sera peut-être demandé de redémarrer le pc pour achever la suppression. Si c'est le cas accepte par Yes.
bises
lance ceci stp:
Télécharge OTMoveIt http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe (de Old_Timer) sur ton Bureau.
Double-clique sur OTMoveIt.exe pour le lancer.
Copie la liste qui se trouve en citation ci-dessous et colle-la dans le cadre de gauche de OTMoveIt sous Paste List of Files/Folders to move.
Citation :
C:\WINDOWS\system32\xucbhdhl.exe
C:\WINDOWS\system32\cyivgnhm.exe
C:\WINDOWS\system32\oymmrnsb.ini
clique sur MoveIt! pour lancer la suppression.
Le résultat apparaitra dans le cadre "Results".
Clique sur Exit pour fermer.
Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
Il te sera peut-être demandé de redémarrer le pc pour achever la suppression. Si c'est le cas accepte par Yes.
bises
12 mai 2008 à 01:12
En plus c'est mal on est entrin de polluer le post lol (enfin vous xD)