A voir également:
- Pub
- Youtube sans pub - Accueil - Streaming
- Netflix avec pub avis - Accueil - Streaming
- Stop pub gratuit - Télécharger - Divers Utilitaires
- Supprimer pub - Guide
- Acteur pub skoda - Forum Cinéma / Télé
22 réponses
Utilisateur anonyme
9 juin 2008 à 15:31
9 juin 2008 à 15:31
Salut Marie de passage ,
ici -> http://www.commentcamarche.net/forum/affich 6693104 pub#3
Aucun des 2 n'a été supprimé ;)
a+++
ici -> http://www.commentcamarche.net/forum/affich 6693104 pub#3
C:\WINDOWS\system32\jmllm.ini2 trouvé ! infection Vundo possible non traitée par cet outil ! C:\WINDOWS\system32\prutv.ini2 trouvé ! infection Vundo possible non traitée par cet outil !
Aucun des 2 n'a été supprimé ;)
a+++
voila le rapport:
ComboFix 08-06-09.7 - Administrateur 2008-06-09 18:29:40.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.232 [GMT -4:00]
Endroit: C:\Documents and Settings\Administrateur\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrateur\Application Data\FunWebProducts
C:\Documents and Settings\Administrateur\Application Data\FunWebProducts\Data\Administrateur\avatar.dat
C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\AntiSpywareShield
C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\AntiSpywareShield\AntiSpywareShield.lnk
C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\AntiSpywareShield\Uninstall.lnk
C:\Program Files\AntiSpywareShield
C:\Program Files\AntiSpywareShield\AntiSpywareShield.exe
C:\Program Files\AntiSpywareShield\AntiSpywareShield.lic
C:\Program Files\AntiSpywareShield\AntiSpywareShield1.ad
C:\Program Files\AntiSpywareShield\Uninstall.exe
C:\WINDOWS\BMf3f1cb63.xml
C:\WINDOWS\system32\jmllm.ini2
C:\WINDOWS\system32\prutv.ini2
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-05-09 to 2008-06-09 ))))))))))))))))))))))))))))))))))))
.
2008-06-09 03:01 . 2008-06-09 03:01 <REP> d-------- C:\WINDOWS\LastGood.Tmp
2008-06-08 23:17 . 2008-06-08 23:17 <REP> d-------- C:\Program Files\Sun
2008-06-08 23:16 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-06-08 23:15 . 2008-06-08 23:15 <REP> d-------- C:\Program Files\Fichiers communs\Java
2008-06-08 20:58 . 2008-06-08 20:58 <REP> d-------- C:\Documents and Settings\Administrateur\.thumbnails
2008-06-04 18:20 . 2008-06-04 19:33 <REP> d-------- C:\Backups
2008-06-04 00:52 . 2008-06-04 00:52 <REP> d-------- C:\Program Files\RealDataSupport
2008-05-31 00:30 . 2008-05-31 00:30 0 --a------ C:\WINDOWS\system32\mapisvc.inf
2008-05-31 00:28 . 2008-06-04 18:05 <REP> d-------- C:\Program Files\ESET
2008-05-17 13:16 . 2008-05-20 13:11 <REP> d-------- C:\Program Files\Microsoft Silverlight
2008-05-17 13:15 . 2008-05-17 13:15 <REP> d-------- C:\Program Files\Microsoft Synchronization Services
2008-05-17 13:15 . 2008-05-17 13:15 <REP> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2008-05-17 13:09 . 2008-06-01 17:47 <REP> d-------- C:\Program Files\Microsoft Visual Studio 9.0
2008-05-17 13:08 . 2008-05-17 13:08 <REP> d-------- C:\Program Files\Microsoft SDKs
2008-05-17 13:03 . 2008-05-17 13:06 <REP> d-------- C:\WINDOWS\system32\XPSViewer
2008-05-17 13:03 . 2008-05-17 13:03 <REP> d-------- C:\Program Files\Reference Assemblies
2008-05-17 13:03 . 2008-05-17 13:03 <REP> d-------- C:\Program Files\MSBuild
2008-05-17 13:02 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-05-17 13:01 . 2008-05-17 13:01 <REP> d-------- C:\Program Files\MSXML 6.0
2008-05-12 17:59 . 2008-06-09 09:10 <REP> d-------- C:\WINDOWS\ERUNT
2008-05-09 15:33 . 2008-05-09 16:18 <REP> d-------- C:\Program Files\Lopxp
2008-05-09 15:32 . 2008-05-09 15:54 2,746 --a------ C:\WINDOWS\system32\tmp.reg
2008-05-09 15:31 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-05-09 15:31 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-05-09 15:31 . 2008-04-24 08:10 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-05-09 15:31 . 2008-04-28 08:03 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-05-09 15:31 . 2008-04-28 08:03 82,944 --a------ C:\WINDOWS\system32\404Fix.exe
2008-05-09 15:31 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-05-09 15:31 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-09 13:10 --------- d-----w C:\Program Files\Trend Micro
2008-06-09 07:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-06-09 03:16 --------- d-----w C:\Program Files\Java
2008-06-09 03:03 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\gtk-2.0
2008-06-05 09:59 --------- d-----w C:\Program Files\Hijackthis Version Française
2008-06-04 04:53 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\RealDataSupport
2008-06-04 04:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\LICENSE FORD HOPE DRAW
2008-06-01 21:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-25 00:34 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\LimeWire
2008-05-08 23:36 --------- d-----w C:\Program Files\Yahoo!
2008-05-08 23:36 --------- d-----w C:\Program Files\CCleaner
2008-05-08 21:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-05-08 21:56 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Grisoft
2008-05-08 02:59 652 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err
2008-05-08 00:34 --------- d-----w C:\Program Files\Google
2008-05-07 23:58 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Malwarebytes
2008-05-07 23:57 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-05-07 23:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-07 20:42 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-06 00:46 27,048 ----a-w C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-06 00:46 15,864 ----a-w C:\WINDOWS\system32\drivers\mbam.sys
2008-04-28 01:49 --------- d-----w C:\Program Files\Notepad++
2008-04-28 01:49 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Notepad++
2008-04-11 15:33 --------- d-----w C:\Program Files\Picasa2
2008-04-09 02:43 --------- d-----w C:\Program Files\eMule
2008-02-15 19:34 774,144 ----a-w C:\Program Files\RngInterstitial.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccleaner"="C:\Program Files\CCleaner\CCleaner.exe" [2008-04-23 12:19 1189104]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:54 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-22 13:56 68856]
"cdrom vga"="C:\DOCUME~1\ADMINI~1\APPLIC~1\REALDA~1\Film each.exe" [2008-06-04 00:51 454656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-11-02 08:59 126976]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-16 09:16 262401]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25 6731312]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
"ControlCenter2.0"=C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
"IndexSearch"=C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
"PaperPort PTD"=C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"SetDefPrt"=C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
"Smapp"=C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
"SSBkgdUpdate"="C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Documents and Settings\\Administrateur\\Mes documents\\eMule\\emule.exe"=
"C:\\Documents and Settings\\Administrateur\\Mes documents\\marie\\VLC\\vlc.exe"=
"C:\\Program Files\\Heroes2\\HEROES2W.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2869:TCP"= 2869:TCP:@xpsp2res.dll,-22008
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundRouterRequest"= 1 (0x1)
R3 BrScnUsb;Brother USB Still Image driver;C:\WINDOWS\system32\Drivers\BrScnUsb.sys [2003-12-19 21:15]
R3 BrSerIf;Brother MFC Serial Port Interface WDM Driver;C:\WINDOWS\system32\Drivers\BrSerIf.sys [2004-06-12 05:27]
R3 BrUsbSer;Brother MFC USB Serial WDM Driver;C:\WINDOWS\system32\Drivers\BrUsbSer.sys [2004-01-10 04:28]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cd02bb5d-5eb3-11dc-8e0b-806d6172696f}]
\Shell\AutoRun\command - D:\setup.exe
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-06-06 15:52:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-09 22:00:01 C:\WINDOWS\Tasks\BB502C539ACFA827.job"
- c:\docume~1\admini~1\applic~1\realda~1\time link style.exe
"2008-06-06 19:00:00 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-09 18:35:07
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\brss01a.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Internet Explorer\iexplore.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-06-09 18:37:35 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-09 22:37:31
Pre-Run: 16,359,301,120 octets libres
Post-Run: 16,557,666,304 octets libres
171 --- E O F --- 2008-06-09 07:02:05
ComboFix 08-06-09.7 - Administrateur 2008-06-09 18:29:40.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.232 [GMT -4:00]
Endroit: C:\Documents and Settings\Administrateur\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrateur\Application Data\FunWebProducts
C:\Documents and Settings\Administrateur\Application Data\FunWebProducts\Data\Administrateur\avatar.dat
C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\AntiSpywareShield
C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\AntiSpywareShield\AntiSpywareShield.lnk
C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\AntiSpywareShield\Uninstall.lnk
C:\Program Files\AntiSpywareShield
C:\Program Files\AntiSpywareShield\AntiSpywareShield.exe
C:\Program Files\AntiSpywareShield\AntiSpywareShield.lic
C:\Program Files\AntiSpywareShield\AntiSpywareShield1.ad
C:\Program Files\AntiSpywareShield\Uninstall.exe
C:\WINDOWS\BMf3f1cb63.xml
C:\WINDOWS\system32\jmllm.ini2
C:\WINDOWS\system32\prutv.ini2
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-05-09 to 2008-06-09 ))))))))))))))))))))))))))))))))))))
.
2008-06-09 03:01 . 2008-06-09 03:01 <REP> d-------- C:\WINDOWS\LastGood.Tmp
2008-06-08 23:17 . 2008-06-08 23:17 <REP> d-------- C:\Program Files\Sun
2008-06-08 23:16 . 2008-03-25 02:37 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-06-08 23:15 . 2008-06-08 23:15 <REP> d-------- C:\Program Files\Fichiers communs\Java
2008-06-08 20:58 . 2008-06-08 20:58 <REP> d-------- C:\Documents and Settings\Administrateur\.thumbnails
2008-06-04 18:20 . 2008-06-04 19:33 <REP> d-------- C:\Backups
2008-06-04 00:52 . 2008-06-04 00:52 <REP> d-------- C:\Program Files\RealDataSupport
2008-05-31 00:30 . 2008-05-31 00:30 0 --a------ C:\WINDOWS\system32\mapisvc.inf
2008-05-31 00:28 . 2008-06-04 18:05 <REP> d-------- C:\Program Files\ESET
2008-05-17 13:16 . 2008-05-20 13:11 <REP> d-------- C:\Program Files\Microsoft Silverlight
2008-05-17 13:15 . 2008-05-17 13:15 <REP> d-------- C:\Program Files\Microsoft Synchronization Services
2008-05-17 13:15 . 2008-05-17 13:15 <REP> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2008-05-17 13:09 . 2008-06-01 17:47 <REP> d-------- C:\Program Files\Microsoft Visual Studio 9.0
2008-05-17 13:08 . 2008-05-17 13:08 <REP> d-------- C:\Program Files\Microsoft SDKs
2008-05-17 13:03 . 2008-05-17 13:06 <REP> d-------- C:\WINDOWS\system32\XPSViewer
2008-05-17 13:03 . 2008-05-17 13:03 <REP> d-------- C:\Program Files\Reference Assemblies
2008-05-17 13:03 . 2008-05-17 13:03 <REP> d-------- C:\Program Files\MSBuild
2008-05-17 13:02 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-05-17 13:01 . 2008-05-17 13:01 <REP> d-------- C:\Program Files\MSXML 6.0
2008-05-12 17:59 . 2008-06-09 09:10 <REP> d-------- C:\WINDOWS\ERUNT
2008-05-09 15:33 . 2008-05-09 16:18 <REP> d-------- C:\Program Files\Lopxp
2008-05-09 15:32 . 2008-05-09 15:54 2,746 --a------ C:\WINDOWS\system32\tmp.reg
2008-05-09 15:31 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-05-09 15:31 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-05-09 15:31 . 2008-04-24 08:10 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-05-09 15:31 . 2008-04-28 08:03 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-05-09 15:31 . 2008-04-28 08:03 82,944 --a------ C:\WINDOWS\system32\404Fix.exe
2008-05-09 15:31 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-05-09 15:31 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-09 13:10 --------- d-----w C:\Program Files\Trend Micro
2008-06-09 07:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-06-09 03:16 --------- d-----w C:\Program Files\Java
2008-06-09 03:03 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\gtk-2.0
2008-06-05 09:59 --------- d-----w C:\Program Files\Hijackthis Version Française
2008-06-04 04:53 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\RealDataSupport
2008-06-04 04:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\LICENSE FORD HOPE DRAW
2008-06-01 21:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-25 00:34 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\LimeWire
2008-05-08 23:36 --------- d-----w C:\Program Files\Yahoo!
2008-05-08 23:36 --------- d-----w C:\Program Files\CCleaner
2008-05-08 21:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-05-08 21:56 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Grisoft
2008-05-08 02:59 652 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err
2008-05-08 00:34 --------- d-----w C:\Program Files\Google
2008-05-07 23:58 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Malwarebytes
2008-05-07 23:57 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-05-07 23:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-07 20:42 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-06 00:46 27,048 ----a-w C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-06 00:46 15,864 ----a-w C:\WINDOWS\system32\drivers\mbam.sys
2008-04-28 01:49 --------- d-----w C:\Program Files\Notepad++
2008-04-28 01:49 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Notepad++
2008-04-11 15:33 --------- d-----w C:\Program Files\Picasa2
2008-04-09 02:43 --------- d-----w C:\Program Files\eMule
2008-02-15 19:34 774,144 ----a-w C:\Program Files\RngInterstitial.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ccleaner"="C:\Program Files\CCleaner\CCleaner.exe" [2008-04-23 12:19 1189104]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:54 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-22 13:56 68856]
"cdrom vga"="C:\DOCUME~1\ADMINI~1\APPLIC~1\REALDA~1\Film each.exe" [2008-06-04 00:51 454656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2004-11-02 08:59 126976]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-16 09:16 262401]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25 6731312]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
"ControlCenter2.0"=C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
"IndexSearch"=C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
"PaperPort PTD"=C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"SetDefPrt"=C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
"Smapp"=C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
"SSBkgdUpdate"="C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Documents and Settings\\Administrateur\\Mes documents\\eMule\\emule.exe"=
"C:\\Documents and Settings\\Administrateur\\Mes documents\\marie\\VLC\\vlc.exe"=
"C:\\Program Files\\Heroes2\\HEROES2W.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2869:TCP"= 2869:TCP:@xpsp2res.dll,-22008
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundRouterRequest"= 1 (0x1)
R3 BrScnUsb;Brother USB Still Image driver;C:\WINDOWS\system32\Drivers\BrScnUsb.sys [2003-12-19 21:15]
R3 BrSerIf;Brother MFC Serial Port Interface WDM Driver;C:\WINDOWS\system32\Drivers\BrSerIf.sys [2004-06-12 05:27]
R3 BrUsbSer;Brother MFC USB Serial WDM Driver;C:\WINDOWS\system32\Drivers\BrUsbSer.sys [2004-01-10 04:28]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cd02bb5d-5eb3-11dc-8e0b-806d6172696f}]
\Shell\AutoRun\command - D:\setup.exe
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-06-06 15:52:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-09 22:00:01 C:\WINDOWS\Tasks\BB502C539ACFA827.job"
- c:\docume~1\admini~1\applic~1\realda~1\time link style.exe
"2008-06-06 19:00:00 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-09 18:35:07
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\brss01a.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe
C:\Program Files\Internet Explorer\iexplore.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-06-09 18:37:35 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-09 22:37:31
Pre-Run: 16,359,301,120 octets libres
Post-Run: 16,557,666,304 octets libres
171 --- E O F --- 2008-06-09 07:02:05
9 juin 2008 à 15:37
Je me marre avec ta signature à rallonge ;;))
9 juin 2008 à 15:43
Je voulais faire encore + long mais après ça le fait plus x)
bon aller j'arrête de raconter ma vie :)
+++