Rapport de HijackThis

Résolu
john doe11 Messages postés 17 Statut Membre -  
 Utilisateur anonyme -
Bonjour,
j'ai attrapé un virus il y a quelque jours quand je veux ouvrir un dossier tout s'efface et je me
retrouve devant mon fond d'écran vide après une analyse anti-virus avec Avast il ne détecte rien
j'ai utilisé HijackThis mais je ne sais pas interpréter le rapport pouvez-vous m'aider s'il vous plait?

voici mon rapport :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:07:49, on 19/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Search Settings\SearchSettings.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Lavasoft\Ad-Aware\Ad-Aware.exe
C:\Documents and Settings\Dimitri\Bureau\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr/toolbar/ie8/sidebar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.fr/?gws_rd=ssl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.fr/toolbar/ie8/sidebar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.fr/keyword/%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
R3 - URLSearchHook: P2P Energy Toolbar - {2bae58c2-79f9-45d1-a286-81f911301c3a} - C:\Program Files\P2P_Energy\tbP2P1.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: P2P Energy Toolbar - {2bae58c2-79f9-45d1-a286-81f911301c3a} - C:\Program Files\P2P_Energy\tbP2P1.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {48727E2A-A70E-4654-A3A4-CB98FA2555E0} - C:\WINDOWS\system32\khfecBqQ.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {6A87B991-A31F-4130-AE72-6D0C294BF082} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {CDA46C9C-A772-4F9C-B9F3-7C7A86EE0013} - C:\WINDOWS\system32\fccATlIb.dll
O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: P2P Energy Toolbar - {2bae58c2-79f9-45d1-a286-81f911301c3a} - C:\Program Files\P2P_Energy\tbP2P1.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Open Remote] C:\DOCUME~1\Dimitri\APPLIC~1\ERRORO~1\Bend Kind Inter.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
O4 - S-1-5-18 Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: Y'z Toolbar.lnk = ? (User 'SYSTEM')
O4 - .DEFAULT Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Default user')
O4 - .DEFAULT Startup: Y'z Toolbar.lnk = ? (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Y'z Toolbar.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O20 - Winlogon Notify: fccATlIb - C:\WINDOWS\SYSTEM32\fccATlIb.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
A voir également:

31 réponses

Utilisateur anonyme
 
Y A pas que xp qui est cracké .............

=> C:\Documents and Settings\Dimitri\Bureau\Adobe Photoshop CS2 v9.0.1 FR\Crack et Keygen
=> C:\Documents and Settings\Dimitri\Bureau\Adobe Photoshop CS2 v9.0.1 FR\Crack et Keygen\Crack Activation Photoshop CS2 Fr.exe
=> C:\Documents and Settings\Dimitri\Bureau\Adobe Photoshop CS2 v9.0.1 FR\Crack et Keygen\KeyGen Adobe.PhotoShop.CS2.exe
=> C:\Documents and Settings\Dimitri\Bureau\Adobe_Photoshop_CS3_Extended_Final\C­rack.txt
=> C:\Documents and Settings\Dimitri\Bureau\Adobe Photoshop CS2 v9.0.1 FR\Crack et Keygen
=> C:\Documents and Settings\Dimitri\Bureau\Adobe Photoshop CS2 v9.0.1 FR\Crack et Keygen\Crack Activation Photoshop CS2 Fr.exe
=> C:\Documents and Settings\Dimitri\Bureau\Adobe Photoshop CS2 v9.0.1 FR\Crack et Keygen\KeyGen Adobe.PhotoShop.CS2.exe

Je te conseil de supprimer tout ça

Relance Lop S&D

* Choisis cette fois ci l'Option 2 (Suppression)
* Ne ferme pas la fenêtre lors de la suppression !
* Poste le rapport généré (C:\lopR.txt)

( Si le Bureau ne réapparaît , lance le gestionnaire des tâches en cliquant sur Ctrl + Alt + Suppr , puis Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide )

1
sKe69 Messages postés 21955 Statut Contributeur sécurité 463
 
Salut,

Télécharges ToolBar S&D ( de Eric_71 ) :
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

( Tuto : https://sites.google.com/site/toolbarsd/aideenimages )

!! Déconnectes toi et fermes toute tes applications en cours le temps de la manipe !!

* double-cliques sur l'.exe pour lancer l'installe et laisses toi guider ...
* Une fois fait, cliques sur le raccourci créé sur ton bureau pour lancer l'outil .
* Choisis l'option 1 ( "recherche") et tapes "entrée" .
* Une fois le scan finit , un rapport va apparaître, copie/colles l'intégralité
de son contenu dans ta prochaine réponse ...
( le rapport est en outre sauvegardé ici -> C:\TB.txt )

0
Utilisateur anonyme
 
Salut,

Ton XP est cracké, non ?
Car sinon c'est pas les mêmes manip.

A+
0
Utilisateur anonyme
 
Salut

XP CRACKE ...........

LOP S&D d'Eric71

Télécharge LOP S&D d'Eric71 ici https://sites.google.com/site/eric71mespages/lop.sd.exe

Double-clique dessus pour lancer l'installation.
Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau.
Séléctionne la langue souhaitée , puis choisis l'Option 1 ( Recherche )
Patiente jusqu'à la fin du scan.

Poste le rapport généré (situé aussi ici C:\lopR.txt )

( Si le Bureau ne réapparaît , lance le gestionnaire des tâches en cliquant sur Ctrl + Alt + Suppr , puis Onglet Fichier , Nouvelle tâche , tape explorer.exe et valide )

Tutorial ( aide ) : http://bibou0007.com/outils-specifiques-f78/tuto-lop-sd-t956.htm
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
sKe69 Messages postés 21955 Statut Contributeur sécurité 463
 
Salut les gas ;)
Je vous laisse faire , ça fait trop de monde sur le coup ....

PS : quesqu'il vous fait croire que son XP est cracké ... -_-
0
john doe11 Messages postés 17 Statut Membre
 
effectivement mon PC est cracké j'ai eu un souci et j'ai du le formater mais mon PC est un Acer est il n'y avait pas de CD et quand je voulais formater sa refusé donc j'ai du me résoudre a une version cracké même si je n'aime pas trop

voila le rapport :

-----------------------[ Lop S&D 4.2.2-1 XP/Vista ]---------------------

[ Windows XP (NT 5.1) Build 2600, Service Pack 2 ]
[ USER : Dimitri ] [ "C:\Lop SD" ] [ Selection : 1 ]
[ 19/07/2008 | 17:37:33,37 ] [ PC : XPSP2-58840E2A2 ]
[ MAJ : 09-07-2008 | 21:02 ]

-------------[ Listing des dossiers dans Application Data ]------------

[20/04/2008|17:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[18/02/2008|20:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe Systems
[22/06/2008|19:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
[18/02/2008|14:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[18/02/2008|14:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[19/02/2008|13:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AVS4YOU
[17/02/2008|20:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[19/07/2008|17:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[20/03/2008|21:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logishrd
[20/03/2008|20:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logitech
[02/06/2008|12:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ma-config.com
[11/04/2008|19:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[10/07/2008|20:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[03/05/2008|10:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero
[29/02/2008|21:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Outspark
[18/07/2008|13:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Readme Live Axis Tons
[19/07/2008|17:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[19/07/2008|16:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Uniblue
[17/02/2008|21:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[10/07/2008|21:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[18/02/2008|20:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!
[08/04/2008|12:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion

[17/02/2008|20:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[17/02/2008|19:45] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[24/05/2008|08:47] C:\DOCUME~1\Dimitri\APPLIC~1\Adobe
[10/03/2008|23:11] C:\DOCUME~1\Dimitri\APPLIC~1\Apple Computer
[20/05/2008|10:48] C:\DOCUME~1\Dimitri\APPLIC~1\Cabos
[20/05/2008|10:48] C:\DOCUME~1\Dimitri\APPLIC~1\Cabos.plist
[04/06/2008|20:59] C:\DOCUME~1\Dimitri\APPLIC~1\DAEMON Tools
[17/02/2008|20:37] C:\DOCUME~1\Dimitri\APPLIC~1\desktop.ini
[07/03/2008|11:45] C:\DOCUME~1\Dimitri\APPLIC~1\dvdcss
[18/07/2008|13:45] C:\DOCUME~1\Dimitri\APPLIC~1\ErrorOwnsNew
[04/07/2008|22:10] C:\DOCUME~1\Dimitri\APPLIC~1\fltk.org
[17/02/2008|20:18] C:\DOCUME~1\Dimitri\APPLIC~1\Identities
[17/02/2008|20:25] C:\DOCUME~1\Dimitri\APPLIC~1\InstallShield
[16/07/2008|22:59] C:\DOCUME~1\Dimitri\APPLIC~1\LimeWire
[24/05/2008|08:47] C:\DOCUME~1\Dimitri\APPLIC~1\Macromedia
[10/03/2008|07:42] C:\DOCUME~1\Dimitri\APPLIC~1\Media Player Classic
[24/06/2008|16:37] C:\DOCUME~1\Dimitri\APPLIC~1\Microsoft
[19/06/2008|06:30] C:\DOCUME~1\Dimitri\APPLIC~1\Mozilla
[02/05/2008|18:14] C:\DOCUME~1\Dimitri\APPLIC~1\Nero
[03/07/2008|15:37] C:\DOCUME~1\Dimitri\APPLIC~1\OpenOffice.org2
[18/02/2008|22:05] C:\DOCUME~1\Dimitri\APPLIC~1\Opera
[30/03/2008|15:04] C:\DOCUME~1\Dimitri\APPLIC~1\Real
[22/04/2008|20:29] C:\DOCUME~1\Dimitri\APPLIC~1\Search Settings
[26/06/2008|20:20] C:\DOCUME~1\Dimitri\APPLIC~1\SecuROM
[21/05/2008|11:52] C:\DOCUME~1\Dimitri\APPLIC~1\Shareaza
[21/02/2008|17:29] C:\DOCUME~1\Dimitri\APPLIC~1\Sports Interactive
[21/02/2008|14:13] C:\DOCUME~1\Dimitri\APPLIC~1\Sun
[04/05/2008|22:30] C:\DOCUME~1\Dimitri\APPLIC~1\U3
[19/07/2008|16:44] C:\DOCUME~1\Dimitri\APPLIC~1\Uniblue
[18/02/2008|23:00] C:\DOCUME~1\Dimitri\APPLIC~1\vlc
[17/02/2008|23:22] C:\DOCUME~1\Dimitri\APPLIC~1\WinRAR

[24/06/2008|18:55] C:\DOCUME~1\Fabien\APPLIC~1\Adobe
[10/03/2008|18:43] C:\DOCUME~1\Fabien\APPLIC~1\Apple Computer
[19/02/2008|13:01] C:\DOCUME~1\Fabien\APPLIC~1\AVS4YOU
[23/04/2008|11:00] C:\DOCUME~1\Fabien\APPLIC~1\Dealio
[17/02/2008|20:37] C:\DOCUME~1\Fabien\APPLIC~1\desktop.ini
[18/02/2008|13:25] C:\DOCUME~1\Fabien\APPLIC~1\DivX
[18/07/2008|13:52] C:\DOCUME~1\Fabien\APPLIC~1\ErrorOwnsNew
[18/02/2008|13:21] C:\DOCUME~1\Fabien\APPLIC~1\Identities
[24/06/2008|18:55] C:\DOCUME~1\Fabien\APPLIC~1\Macromedia
[18/02/2008|13:25] C:\DOCUME~1\Fabien\APPLIC~1\Media Player Classic
[14/03/2008|18:35] C:\DOCUME~1\Fabien\APPLIC~1\Microsoft
[20/06/2008|11:12] C:\DOCUME~1\Fabien\APPLIC~1\Mozilla
[26/05/2008|16:16] C:\DOCUME~1\Fabien\APPLIC~1\OpenOffice.org2
[18/04/2008|19:12] C:\DOCUME~1\Fabien\APPLIC~1\Real
[23/04/2008|10:56] C:\DOCUME~1\Fabien\APPLIC~1\Search Settings
[23/05/2008|10:24] C:\DOCUME~1\Fabien\APPLIC~1\Shareaza
[26/03/2008|11:19] C:\DOCUME~1\Fabien\APPLIC~1\Sun
[17/03/2008|23:45] C:\DOCUME~1\Fabien\APPLIC~1\U3
[20/02/2008|13:57] C:\DOCUME~1\Fabien\APPLIC~1\vlc
[18/02/2008|14:19] C:\DOCUME~1\Fabien\APPLIC~1\WinRAR

[18/02/2008|16:51] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[17/02/2008|19:49] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

[30/04/2008|12:49] C:\DOCUME~1\pascal\APPLIC~1\Adobe
[30/04/2008|12:49] C:\DOCUME~1\pascal\APPLIC~1\Dealio
[17/02/2008|20:37] C:\DOCUME~1\pascal\APPLIC~1\desktop.ini
[30/04/2008|12:54] C:\DOCUME~1\pascal\APPLIC~1\ErrorOwnsNew
[29/04/2008|12:39] C:\DOCUME~1\pascal\APPLIC~1\Identities
[30/04/2008|12:50] C:\DOCUME~1\pascal\APPLIC~1\Macromedia
[30/04/2008|12:49] C:\DOCUME~1\pascal\APPLIC~1\Microsoft
[30/04/2008|12:48] C:\DOCUME~1\pascal\APPLIC~1\Mozilla
[29/04/2008|12:40] C:\DOCUME~1\pascal\APPLIC~1\Real
[30/04/2008|12:49] C:\DOCUME~1\pascal\APPLIC~1\Search Settings
[27/05/2008|18:53] C:\DOCUME~1\pascal\APPLIC~1\vlc

----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------

[19/07/2008 17:04][--a------] C:\WINDOWS\tasks\Uniblue SpyEraser Nag.job
[19/07/2008 17:04][--a------] C:\WINDOWS\tasks\Uniblue SpyEraser.job
[17/07/2008 19:15][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[19/07/2008 08:24][--ah-----] C:\WINDOWS\tasks\SA.DAT
[24/08/2001 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

---------------[ Listing des dossiers dans C:\Program Files ]--------------

[30/06/2008|11:14] C:\Program Files\Adobe
[22/06/2008|19:38] C:\Program Files\Ahead
[31/03/2008|13:14] C:\Program Files\Alwil Software
[27/03/2008|13:46] C:\Program Files\Apple Software Update
[19/02/2008|13:17] C:\Program Files\AVS4YOU
[17/05/2008|12:28] C:\Program Files\BitLord
[18/02/2008|22:01] C:\Program Files\BlackSunSoft.net
[29/04/2008|13:55] C:\Program Files\CA Yahoo! Anti-Spy
[07/04/2008|23:34] C:\Program Files\CCleaner
[26/05/2008|19:10] C:\Program Files\Circle Developement
[07/04/2008|23:29] C:\Program Files\Common Files
[17/02/2008|19:42] C:\Program Files\ComPlus Applications
[23/05/2008|18:55] C:\Program Files\Conduit
[04/06/2008|21:32] C:\Program Files\DAEMON Tools Lite
[26/06/2008|15:59] C:\Program Files\ErrorOwnsNew
[19/07/2008|16:47] C:\Program Files\Fichiers communs
[21/02/2008|13:49] C:\Program Files\Free
[23/04/2008|10:54] C:\Program Files\Free Audio Pack
[16/06/2008|17:52] C:\Program Files\Free Easy Burner
[01/03/2008|22:43] C:\Program Files\Games-Masters.com
[26/06/2008|18:08] C:\Program Files\InstallShield Installation Information
[17/02/2008|20:28] C:\Program Files\Intel
[09/07/2008|09:30] C:\Program Files\Internet Explorer
[18/02/2008|14:01] C:\Program Files\iPod
[18/02/2008|14:01] C:\Program Files\iTunes
[14/07/2008|12:01] C:\Program Files\Java
[17/02/2008|22:16] C:\Program Files\K-Lite Codec Pack
[20/03/2008|20:57] C:\Program Files\Labtec
[17/02/2008|22:20] C:\Program Files\Lavalys
[19/07/2008|17:02] C:\Program Files\Lavasoft
[12/07/2008|10:04] C:\Program Files\LimeWire
[28/05/2008|17:16] C:\Program Files\Logitech
[04/06/2008|21:41] C:\Program Files\LucasArts
[02/06/2008|11:18] C:\Program Files\ma-config.com
[01/04/2008|16:49] C:\Program Files\Messenger Plus! Live
[17/02/2008|23:41] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[17/02/2008|19:46] C:\Program Files\microsoft frontpage
[30/03/2008|00:21] C:\Program Files\Movie Maker
[19/07/2008|15:25] C:\Program Files\Mozilla Firefox
[17/02/2008|19:46] C:\Program Files\msn gaming zone
[10/07/2008|21:45] C:\Program Files\MSN Messenger
[17/02/2008|21:34] C:\Program Files\MSXML 4.0
[02/05/2008|18:17] C:\Program Files\NeroInstall.bak
[17/02/2008|19:46] C:\Program Files\netmeeting
[27/06/2008|11:23] C:\Program Files\OpenOffice.org 2.3
[27/06/2008|11:24] C:\Program Files\OpenOffice.org 2.4
[17/02/2008|23:25] C:\Program Files\Outlook Express
[24/05/2008|06:48] C:\Program Files\P2P_Energy
[18/02/2008|14:01] C:\Program Files\QuickTime
[30/03/2008|14:55] C:\Program Files\Real
[17/02/2008|21:10] C:\Program Files\Realtek
[15/07/2008|15:09] C:\Program Files\RomStation
[22/04/2008|18:52] C:\Program Files\Search Settings
[17/02/2008|19:44] C:\Program Files\Services en ligne
[21/05/2008|11:52] C:\Program Files\Shareaza
[01/05/2008|12:35] C:\Program Files\Smart Data Recovery
[26/06/2008|19:47] C:\Program Files\Sports Interactive
[19/07/2008|16:45] C:\Program Files\Spybot - Search & Destroy
[20/02/2008|12:36] C:\Program Files\Ultra AVI Converter
[19/07/2008|16:44] C:\Program Files\Uniblue
[17/02/2008|20:18] C:\Program Files\Uninstall Information
[17/02/2008|20:54] C:\Program Files\VIA
[17/02/2008|22:15] C:\Program Files\VideoLAN
[14/03/2008|17:11] C:\Program Files\WinAVI Video Converter
[10/07/2008|20:41] C:\Program Files\Windows Live
[13/05/2008|19:14] C:\Program Files\Windows Media Connect 2
[21/06/2008|17:13] C:\Program Files\Windows Media Player
[17/02/2008|19:46] C:\Program Files\Windows NT
[17/02/2008|19:44] C:\Program Files\WindowsUpdate
[17/02/2008|23:10] C:\Program Files\WinRAR
[17/02/2008|19:46] C:\Program Files\xerox
[29/04/2008|12:34] C:\Program Files\Yahoo!
[26/06/2008|19:48] C:\Program Files\Zero G Registry

------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------

[20/04/2008|17:56] C:\Program Files\Fichiers communs\Adobe
[18/02/2008|20:33] C:\Program Files\Fichiers communs\Adobe Systems Shared
[22/06/2008|19:34] C:\Program Files\Fichiers communs\Ahead
[18/02/2008|14:01] C:\Program Files\Fichiers communs\Apple
[19/02/2008|13:03] C:\Program Files\Fichiers communs\AVSMedia
[27/02/2008|22:24] C:\Program Files\Fichiers communs\DirectX
[17/02/2008|20:54] C:\Program Files\Fichiers communs\InstallShield
[21/02/2008|14:13] C:\Program Files\Fichiers communs\Java
[17/02/2008|20:37] C:\Program Files\Fichiers communs\Labtec
[22/06/2008|19:37] C:\Program Files\Fichiers communs\LightScribe
[20/03/2008|20:58] C:\Program Files\Fichiers communs\LogiShrd
[28/05/2008|17:16] C:\Program Files\Fichiers communs\Logitech
[10/07/2008|20:42] C:\Program Files\Fichiers communs\Microsoft Shared
[17/02/2008|19:43] C:\Program Files\Fichiers communs\MSSoap
[22/06/2008|19:36] C:\Program Files\Fichiers communs\Nero
[17/02/2008|20:38] C:\Program Files\Fichiers communs\ODBC
[30/03/2008|14:56] C:\Program Files\Fichiers communs\Real
[29/04/2008|12:36] C:\Program Files\Fichiers communs\Scanner
[17/02/2008|19:43] C:\Program Files\Fichiers communs\Services
[17/02/2008|20:38] C:\Program Files\Fichiers communs\SpeechEngines
[17/02/2008|21:33] C:\Program Files\Fichiers communs\System
[17/02/2008|22:05] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[19/07/2008|16:47] C:\Program Files\Fichiers communs\Wise Installation Wizard
[30/03/2008|14:56] C:\Program Files\Fichiers communs\xing shared

---------------------------[ Process ]--------------------------

... 49

... OK !

----------------------[ Recherche avec S_Lop ]---------------------

Aucun fichier / dossier Lop trouvé !

-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------

C:\DOCUME~1\ALLUSE~1\APPLIC~1\Readme Live Axis Tons
C:\Program Files\Circle Developement
C:\DOCUME~1\Dimitri\Cookies\dimitri@www.adserver5[2].txt
C:\DOCUME~1\Dimitri\Cookies\dimitri@adin.bigpoint[1].txt
C:\DOCUME~1\Dimitri\Cookies\dimitri@fr1.seafight.bigpoint[2].txt
C:\DOCUME~1\Dimitri\Cookies\dimitri@cotedazurpalace[1].txt
C:\DOCUME~1\Dimitri\Cookies\dimitri@fr1.seafight.bigpoint[2].txt
C:\DOCUME~1\Dimitri\Cookies\dimitri@32vegas[2].txt
C:\DOCUME~1\Dimitri\Cookies\dimitri@banner.32vegas[2].txt
C:\DOCUME~1\Dimitri\Cookies\dimitri@2xmoinscher[1].txt
C:\DOCUME~1\Dimitri\Cookies\dimitri@www.2xmoinscher[1].txt

----------------------[ Verification du Registre ]----------------------

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

..... OK !

--------------------[ Verification du fichier Hosts ]---------------------

Fichier Hosts MODIFIE

127.0.0.1 bin.errorprotector.com ## added by CiD
127.0.0.1 br.errorsafe.com ## added by CiD
127.0.0.1 br.winantivirus.com ## added by CiD
127.0.0.1 br.winfixer.com ## added by CiD
127.0.0.1 cdn.drivecleaner.com ## added by CiD
127.0.0.1 cdn.errorsafe.com ## added by CiD
127.0.0.1 cdn.winsoftware.com ## added by CiD
127.0.0.1 de.errorsafe.com ## added by CiD
127.0.0.1 de.winantivirus.com ## added by CiD
127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
127.0.0.1 download.cdn.errorsafe.com ## added by CiD
127.0.0.1 download.cdn.winsoftware.com ## added by CiD
127.0.0.1 download.errorsafe.com ## added by CiD
127.0.0.1 download.systemdoctor.com ## added by CiD
127.0.0.1 download.winantispyware.com ## added by CiD
127.0.0.1 download.windrivecleaner.com ## added by CiD
127.0.0.1 download.winfixer.com ## added by CiD
127.0.0.1 drivecleaner.com ## added by CiD
127.0.0.1 dynamique.drivecleaner.com ## added by CiD
127.0.0.1 errorprotector.com ## added by CiD
127.0.0.1 errorsafe.com ## added by CiD
127.0.0.1 es.winantivirus.com ## added by CiD
127.0.0.1 fr.winantivirus.com ## added by CiD
127.0.0.1 fr.winfixer.com ## added by CiD
127.0.0.1 go.drivecleaner.com ## added by CiD
127.0.0.1 go.errorsafe.com ## added by CiD
127.0.0.1 go.winantispyware.com ## added by CiD
127.0.0.1 go.winantivirus.com ## added by CiD
127.0.0.1 hk.winantivirus.com ## added by CiD
127.0.0.1 instlog.errorsafe.com ## added by CiD
127.0.0.1 instlog.winantivirus.com ## added by CiD
127.0.0.1 instlog.winfixer.com ## added by CiD
127.0.0.1 jsp.drivecleaner.com ## added by CiD
127.0.0.1 kb.errorsafe.com ## added by CiD
127.0.0.1 kb.winantivirus.com ## added by CiD
127.0.0.1 nl.errorsafe.com ## added by CiD
127.0.0.1 se.errorsafe.com ## added by CiD
127.0.0.1 secure.drivecleaner.com ## added by CiD
127.0.0.1 secure.errorsafe.com ## added by CiD
127.0.0.1 secure.winantispam.com ## added by CiD
127.0.0.1 secure.winantispy.com ## added by CiD
127.0.0.1 secure.winantivirus.com ## added by CiD
127.0.0.1 support.winantivirus.com ## added by CiD
127.0.0.1 trial.updates.winsoftware.com ## added by CiD
127.0.0.1 ulog.winantivirus.com ## added by CiD
127.0.0.1 utils.errorsafe.com ## added by CiD
127.0.0.1 utils.winantivirus.com ## added by CiD
127.0.0.1 utils.winfixer.com ## added by CiD
127.0.0.1 winantispyware.com ## added by CiD
127.0.0.1 winantivirus.com ## added by CiD
127.0.0.1 winfixer.com ## added by CiD
127.0.0.1 winfixer2006.com ## added by CiD
127.0.0.1 winsoftware.com ## added by CiD
127.0.0.1 [i]ww/iw.drivecleaner.com ## added by CiD
127.0.0.1 [i]ww/iw.errorprotector.com ## added by CiD
127.0.0.1 [i]ww/iw.errorsafe.com ## added by CiD
127.0.0.1 [i]ww/iw.systemdoctor.com ## added by CiD
127.0.0.1 [i]ww/iw.utils.winfixer.com ## added by CiD
127.0.0.1 [i]ww/iw.win-anti-virus-pro.com ## added by CiD
127.0.0.1 [i]ww/iw.win-virus-pro.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispam.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispy.com ## added by CiD
127.0.0.1 [i]ww/iw.winantispyware.com ## added by CiD
127.0.0.1 [i]ww/iw.winantivirus.com ## added by CiD
127.0.0.1 [i]ww/iw.winantiviruspro.com ## added by CiD
127.0.0.1 [i]ww/iw.windrivecleaner.com ## added by CiD
127.0.0.1 [i]ww/iw.windrivesafe.com ## added by CiD
127.0.0.1 [i]ww/iw.winfixer.com ## added by CiD
127.0.0.1 [i]ww/iw.winfixer2006.com ## added by CiD
127.0.0.1 [i]ww/iw.winsoftware.com ## added by CiD

-> 8504 ( 70 ## added by CiD )

/!\ 1 Not 127.0.0.1 !!

----------------[ Recherche de fichiers avec Catchme ]-----------------

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-19 17:40:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------[ Recherche d'autres infections ]---------------------

C:\WINDOWS\system32\QqBcefhk.ini2
C:\WINDOWS\system32\QqBcefhk.ini
C:\WINDOWS\system32\RBIPAcfe.ini2
C:\WINDOWS\system32\RBIPAcfe.ini
[b]! VUNDO Possible !/b

=> C:\Documents and Settings\Dimitri\Bureau\Adobe Photoshop CS2 v9.0.1 FR\Crack et Keygen
=> C:\Documents and Settings\Dimitri\Bureau\Adobe Photoshop CS2 v9.0.1 FR\Crack et Keygen\Crack Activation Photoshop CS2 Fr.exe
=> C:\Documents and Settings\Dimitri\Bureau\Adobe Photoshop CS2 v9.0.1 FR\Crack et Keygen\KeyGen Adobe.PhotoShop.CS2.exe
=> C:\Documents and Settings\Dimitri\Bureau\Adobe_Photoshop_CS3_Extended_Final\Crack.txt
=> C:\Documents and Settings\Dimitri\Bureau\Adobe Photoshop CS2 v9.0.1 FR\Crack et Keygen
=> C:\Documents and Settings\Dimitri\Bureau\Adobe Photoshop CS2 v9.0.1 FR\Crack et Keygen\Crack Activation Photoshop CS2 Fr.exe
=> C:\Documents and Settings\Dimitri\Bureau\Adobe Photoshop CS2 v9.0.1 FR\Crack et Keygen\KeyGen Adobe.PhotoShop.CS2.exe

[F:1529][D:41]-> C:\DOCUME~1\Dimitri\LOCALS~1\Temp
[F:199][D:0]-> C:\DOCUME~1\Dimitri\Cookies
[F:1803][D:6]-> C:\DOCUME~1\Dimitri\LOCALS~1\TEMPOR~1\content.IE5

--------------------[ Fin du rapport a 17:41:35,09 ]----------------------

merci
0
Utilisateur anonyme
 
Re,

effectivement mon PC est cracké j'ai eu un souci et j'ai du le formater mais mon PC est un Acer est il n'y avait pas de CD et quand je voulais formater sa refusé donc j'ai du me résoudre a une version cracké même si je n'aime pas trop


=> emprunte le Windows XP même édition d'un ami et rentre ta clé.
Et hop ! Le tour est joué !

A+
0
john doe11 Messages postés 17 Statut Membre
 
je viens de faire ce que tu m'as dit voila le rapport:

-----------------------[ Lop S&D 4.2.2-1 XP/Vista ]---------------------

[ Windows Registry Editor Version 5.00 ]
[ [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] ]
[ "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe" ]
[ "Open Remote"="C:\\DOCUME~1\\Dimitri\\APPLIC~1\\ERRORO~1\\Bend Kind Inter.exe" ]
[ "LDM"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\BackWeb-8876480.exe" ]
[ "DAEMON Tools Lite"="\"C:\\Program Files\\DAEMON Tools Lite\\daemon.exe\" -autorun" ]
[ "SpybotSD TeaTimer"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe" ]
[ ???????????????????????? ]
[ USER : Dimitri ] [ "C:\Lop SD" ] [ Selection : 2 ]
[ 19/07/2008 | 18:12:52,56 ] [ PC : XPSP2-58840E2A2 ]
[ MAJ : 09-07-2008 | 21:02 ]

//////////////////////////////////////-\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\

-------------[ Listing des dossiers dans Application Data ]------------

[20/04/2008|17:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[18/02/2008|20:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe Systems
[22/06/2008|19:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
[18/02/2008|14:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[18/02/2008|14:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[19/02/2008|13:01] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AVS4YOU
[17/02/2008|20:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
[19/07/2008|17:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
[20/03/2008|21:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logishrd
[20/03/2008|20:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Logitech
[02/06/2008|12:21] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ma-config.com
[11/04/2008|19:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Messenger Plus!
[10/07/2008|20:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[03/05/2008|10:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Nero
[29/02/2008|21:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Outspark
[19/07/2008|17:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
[19/07/2008|16:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Uniblue
[17/02/2008|21:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[10/07/2008|21:35] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[18/02/2008|20:38] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!
[08/04/2008|12:51] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion

[17/02/2008|20:37] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
[17/02/2008|19:45] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[24/05/2008|08:47] C:\DOCUME~1\Dimitri\APPLIC~1\Adobe
[10/03/2008|23:11] C:\DOCUME~1\Dimitri\APPLIC~1\Apple Computer
[20/05/2008|10:48] C:\DOCUME~1\Dimitri\APPLIC~1\Cabos
[20/05/2008|10:48] C:\DOCUME~1\Dimitri\APPLIC~1\Cabos.plist
[04/06/2008|20:59] C:\DOCUME~1\Dimitri\APPLIC~1\DAEMON Tools
[17/02/2008|20:37] C:\DOCUME~1\Dimitri\APPLIC~1\desktop.ini
[07/03/2008|11:45] C:\DOCUME~1\Dimitri\APPLIC~1\dvdcss
[18/07/2008|13:45] C:\DOCUME~1\Dimitri\APPLIC~1\ErrorOwnsNew
[04/07/2008|22:10] C:\DOCUME~1\Dimitri\APPLIC~1\fltk.org
[17/02/2008|20:18] C:\DOCUME~1\Dimitri\APPLIC~1\Identities
[17/02/2008|20:25] C:\DOCUME~1\Dimitri\APPLIC~1\InstallShield
[16/07/2008|22:59] C:\DOCUME~1\Dimitri\APPLIC~1\LimeWire
[24/05/2008|08:47] C:\DOCUME~1\Dimitri\APPLIC~1\Macromedia
[10/03/2008|07:42] C:\DOCUME~1\Dimitri\APPLIC~1\Media Player Classic
[24/06/2008|16:37] C:\DOCUME~1\Dimitri\APPLIC~1\Microsoft
[19/06/2008|06:30] C:\DOCUME~1\Dimitri\APPLIC~1\Mozilla
[02/05/2008|18:14] C:\DOCUME~1\Dimitri\APPLIC~1\Nero
[03/07/2008|15:37] C:\DOCUME~1\Dimitri\APPLIC~1\OpenOffice.org2
[18/02/2008|22:05] C:\DOCUME~1\Dimitri\APPLIC~1\Opera
[30/03/2008|15:04] C:\DOCUME~1\Dimitri\APPLIC~1\Real
[22/04/2008|20:29] C:\DOCUME~1\Dimitri\APPLIC~1\Search Settings
[26/06/2008|20:20] C:\DOCUME~1\Dimitri\APPLIC~1\SecuROM
[21/05/2008|11:52] C:\DOCUME~1\Dimitri\APPLIC~1\Shareaza
[21/02/2008|17:29] C:\DOCUME~1\Dimitri\APPLIC~1\Sports Interactive
[21/02/2008|14:13] C:\DOCUME~1\Dimitri\APPLIC~1\Sun
[04/05/2008|22:30] C:\DOCUME~1\Dimitri\APPLIC~1\U3
[19/07/2008|16:44] C:\DOCUME~1\Dimitri\APPLIC~1\Uniblue
[18/02/2008|23:00] C:\DOCUME~1\Dimitri\APPLIC~1\vlc
[17/02/2008|23:22] C:\DOCUME~1\Dimitri\APPLIC~1\WinRAR

[24/06/2008|18:55] C:\DOCUME~1\Fabien\APPLIC~1\Adobe
[10/03/2008|18:43] C:\DOCUME~1\Fabien\APPLIC~1\Apple Computer
[19/02/2008|13:01] C:\DOCUME~1\Fabien\APPLIC~1\AVS4YOU
[23/04/2008|11:00] C:\DOCUME~1\Fabien\APPLIC~1\Dealio
[17/02/2008|20:37] C:\DOCUME~1\Fabien\APPLIC~1\desktop.ini
[18/02/2008|13:25] C:\DOCUME~1\Fabien\APPLIC~1\DivX
[18/07/2008|13:52] C:\DOCUME~1\Fabien\APPLIC~1\ErrorOwnsNew
[18/02/2008|13:21] C:\DOCUME~1\Fabien\APPLIC~1\Identities
[24/06/2008|18:55] C:\DOCUME~1\Fabien\APPLIC~1\Macromedia
[18/02/2008|13:25] C:\DOCUME~1\Fabien\APPLIC~1\Media Player Classic
[14/03/2008|18:35] C:\DOCUME~1\Fabien\APPLIC~1\Microsoft
[20/06/2008|11:12] C:\DOCUME~1\Fabien\APPLIC~1\Mozilla
[26/05/2008|16:16] C:\DOCUME~1\Fabien\APPLIC~1\OpenOffice.org2
[18/04/2008|19:12] C:\DOCUME~1\Fabien\APPLIC~1\Real
[23/04/2008|10:56] C:\DOCUME~1\Fabien\APPLIC~1\Search Settings
[23/05/2008|10:24] C:\DOCUME~1\Fabien\APPLIC~1\Shareaza
[26/03/2008|11:19] C:\DOCUME~1\Fabien\APPLIC~1\Sun
[17/03/2008|23:45] C:\DOCUME~1\Fabien\APPLIC~1\U3
[20/02/2008|13:57] C:\DOCUME~1\Fabien\APPLIC~1\vlc
[18/02/2008|14:19] C:\DOCUME~1\Fabien\APPLIC~1\WinRAR

[18/02/2008|16:51] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

[17/02/2008|19:49] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

[30/04/2008|12:49] C:\DOCUME~1\pascal\APPLIC~1\Adobe
[30/04/2008|12:49] C:\DOCUME~1\pascal\APPLIC~1\Dealio
[17/02/2008|20:37] C:\DOCUME~1\pascal\APPLIC~1\desktop.ini
[30/04/2008|12:54] C:\DOCUME~1\pascal\APPLIC~1\ErrorOwnsNew
[29/04/2008|12:39] C:\DOCUME~1\pascal\APPLIC~1\Identities
[30/04/2008|12:50] C:\DOCUME~1\pascal\APPLIC~1\Macromedia
[30/04/2008|12:49] C:\DOCUME~1\pascal\APPLIC~1\Microsoft
[30/04/2008|12:48] C:\DOCUME~1\pascal\APPLIC~1\Mozilla
[29/04/2008|12:40] C:\DOCUME~1\pascal\APPLIC~1\Real
[30/04/2008|12:49] C:\DOCUME~1\pascal\APPLIC~1\Search Settings
[27/05/2008|18:53] C:\DOCUME~1\pascal\APPLIC~1\vlc

----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------

[19/07/2008 17:04][--a------] C:\WINDOWS\tasks\Uniblue SpyEraser Nag.job
[19/07/2008 17:04][--a------] C:\WINDOWS\tasks\Uniblue SpyEraser.job
[17/07/2008 19:15][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[19/07/2008 18:10][--ah-----] C:\WINDOWS\tasks\SA.DAT
[24/08/2001 14:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

---------------[ Listing des dossiers dans C:\Program Files ]--------------

[30/06/2008|11:14] C:\Program Files\Adobe
[22/06/2008|19:38] C:\Program Files\Ahead
[31/03/2008|13:14] C:\Program Files\Alwil Software
[27/03/2008|13:46] C:\Program Files\Apple Software Update
[19/02/2008|13:17] C:\Program Files\AVS4YOU
[17/05/2008|12:28] C:\Program Files\BitLord
[18/02/2008|22:01] C:\Program Files\BlackSunSoft.net
[29/04/2008|13:55] C:\Program Files\CA Yahoo! Anti-Spy
[07/04/2008|23:34] C:\Program Files\CCleaner
[07/04/2008|23:29] C:\Program Files\Common Files
[17/02/2008|19:42] C:\Program Files\ComPlus Applications
[23/05/2008|18:55] C:\Program Files\Conduit
[04/06/2008|21:32] C:\Program Files\DAEMON Tools Lite
[26/06/2008|15:59] C:\Program Files\ErrorOwnsNew
[19/07/2008|16:47] C:\Program Files\Fichiers communs
[21/02/2008|13:49] C:\Program Files\Free
[23/04/2008|10:54] C:\Program Files\Free Audio Pack
[16/06/2008|17:52] C:\Program Files\Free Easy Burner
[01/03/2008|22:43] C:\Program Files\Games-Masters.com
[26/06/2008|18:08] C:\Program Files\InstallShield Installation Information
[17/02/2008|20:28] C:\Program Files\Intel
[09/07/2008|09:30] C:\Program Files\Internet Explorer
[18/02/2008|14:01] C:\Program Files\iPod
[18/02/2008|14:01] C:\Program Files\iTunes
[14/07/2008|12:01] C:\Program Files\Java
[17/02/2008|22:16] C:\Program Files\K-Lite Codec Pack
[20/03/2008|20:57] C:\Program Files\Labtec
[17/02/2008|22:20] C:\Program Files\Lavalys
[19/07/2008|17:02] C:\Program Files\Lavasoft
[12/07/2008|10:04] C:\Program Files\LimeWire
[28/05/2008|17:16] C:\Program Files\Logitech
[04/06/2008|21:41] C:\Program Files\LucasArts
[02/06/2008|11:18] C:\Program Files\ma-config.com
[01/04/2008|16:49] C:\Program Files\Messenger Plus! Live
[17/02/2008|23:41] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[17/02/2008|19:46] C:\Program Files\microsoft frontpage
[30/03/2008|00:21] C:\Program Files\Movie Maker
[19/07/2008|18:11] C:\Program Files\Mozilla Firefox
[17/02/2008|19:46] C:\Program Files\msn gaming zone
[10/07/2008|21:45] C:\Program Files\MSN Messenger
[17/02/2008|21:34] C:\Program Files\MSXML 4.0
[02/05/2008|18:17] C:\Program Files\NeroInstall.bak
[17/02/2008|19:46] C:\Program Files\netmeeting
[27/06/2008|11:23] C:\Program Files\OpenOffice.org 2.3
[27/06/2008|11:24] C:\Program Files\OpenOffice.org 2.4
[17/02/2008|23:25] C:\Program Files\Outlook Express
[24/05/2008|06:48] C:\Program Files\P2P_Energy
[18/02/2008|14:01] C:\Program Files\QuickTime
[30/03/2008|14:55] C:\Program Files\Real
[17/02/2008|21:10] C:\Program Files\Realtek
[15/07/2008|15:09] C:\Program Files\RomStation
[22/04/2008|18:52] C:\Program Files\Search Settings
[17/02/2008|19:44] C:\Program Files\Services en ligne
[21/05/2008|11:52] C:\Program Files\Shareaza
[01/05/2008|12:35] C:\Program Files\Smart Data Recovery
[26/06/2008|19:47] C:\Program Files\Sports Interactive
[19/07/2008|16:45] C:\Program Files\Spybot - Search & Destroy
[20/02/2008|12:36] C:\Program Files\Ultra AVI Converter
[19/07/2008|16:44] C:\Program Files\Uniblue
[17/02/2008|20:18] C:\Program Files\Uninstall Information
[17/02/2008|20:54] C:\Program Files\VIA
[17/02/2008|22:15] C:\Program Files\VideoLAN
[14/03/2008|17:11] C:\Program Files\WinAVI Video Converter
[10/07/2008|20:41] C:\Program Files\Windows Live
[13/05/2008|19:14] C:\Program Files\Windows Media Connect 2
[21/06/2008|17:13] C:\Program Files\Windows Media Player
[17/02/2008|19:46] C:\Program Files\Windows NT
[17/02/2008|19:44] C:\Program Files\WindowsUpdate
[17/02/2008|23:10] C:\Program Files\WinRAR
[17/02/2008|19:46] C:\Program Files\xerox
[29/04/2008|12:34] C:\Program Files\Yahoo!
[26/06/2008|19:48] C:\Program Files\Zero G Registry

------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]------

[20/04/2008|17:56] C:\Program Files\Fichiers communs\Adobe
[18/02/2008|20:33] C:\Program Files\Fichiers communs\Adobe Systems Shared
[22/06/2008|19:34] C:\Program Files\Fichiers communs\Ahead
[18/02/2008|14:01] C:\Program Files\Fichiers communs\Apple
[19/02/2008|13:03] C:\Program Files\Fichiers communs\AVSMedia
[27/02/2008|22:24] C:\Program Files\Fichiers communs\DirectX
[17/02/2008|20:54] C:\Program Files\Fichiers communs\InstallShield
[21/02/2008|14:13] C:\Program Files\Fichiers communs\Java
[17/02/2008|20:37] C:\Program Files\Fichiers communs\Labtec
[22/06/2008|19:37] C:\Program Files\Fichiers communs\LightScribe
[20/03/2008|20:58] C:\Program Files\Fichiers communs\LogiShrd
[28/05/2008|17:16] C:\Program Files\Fichiers communs\Logitech
[10/07/2008|20:42] C:\Program Files\Fichiers communs\Microsoft Shared
[17/02/2008|19:43] C:\Program Files\Fichiers communs\MSSoap
[22/06/2008|19:36] C:\Program Files\Fichiers communs\Nero
[17/02/2008|20:38] C:\Program Files\Fichiers communs\ODBC
[30/03/2008|14:56] C:\Program Files\Fichiers communs\Real
[29/04/2008|12:36] C:\Program Files\Fichiers communs\Scanner
[17/02/2008|19:43] C:\Program Files\Fichiers communs\Services
[17/02/2008|20:38] C:\Program Files\Fichiers communs\SpeechEngines
[17/02/2008|21:33] C:\Program Files\Fichiers communs\System
[17/02/2008|22:05] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[19/07/2008|16:47] C:\Program Files\Fichiers communs\Wise Installation Wizard
[30/03/2008|14:56] C:\Program Files\Fichiers communs\xing shared

---------------------------[ Process ]--------------------------

... 49

... OK !

----------------------[ Recherche avec S_Lop ]---------------------

Aucun fichier / dossier Lop trouvé !

-----------------[ Recherche de Fichiers / Dossiers Lop ]-----------------

Aucun fichier / dossier Lop trouvé !

----------------------[ Verification du Registre ]----------------------

..... OK !

--------------------[ Verification du fichier Hosts ]---------------------

Fichier Hosts PROPRE

----------------[ Recherche de fichiers avec Catchme ]-----------------

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-19 18:17:32
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------[ Recherche d'autres infections ]---------------------

C:\WINDOWS\system32\QqBcefhk.ini2
C:\WINDOWS\system32\QqBcefhk.ini
C:\WINDOWS\system32\RBIPAcfe.ini2
C:\WINDOWS\system32\RBIPAcfe.ini
[b]! VUNDO Possible !/b

=> C:\Documents and Settings\Dimitri\Bureau\Adobe Photoshop CS2 v9.0.1 FR\Crack et Keygen
=> C:\Documents and Settings\Dimitri\Bureau\Adobe Photoshop CS2 v9.0.1 FR\Crack et Keygen\Crack Activation Photoshop CS2 Fr.exe
=> C:\Documents and Settings\Dimitri\Bureau\Adobe Photoshop CS2 v9.0.1 FR\Crack et Keygen\KeyGen Adobe.PhotoShop.CS2.exe
=> C:\Documents and Settings\Dimitri\Bureau\Adobe_Photoshop_CS3_Extended_Final\Crack.txt
=> C:\Documents and Settings\Dimitri\Bureau\Adobe Photoshop CS2 v9.0.1 FR\Crack et Keygen
=> C:\Documents and Settings\Dimitri\Bureau\Adobe Photoshop CS2 v9.0.1 FR\Crack et Keygen\Crack Activation Photoshop CS2 Fr.exe
=> C:\Documents and Settings\Dimitri\Bureau\Adobe Photoshop CS2 v9.0.1 FR\Crack et Keygen\KeyGen Adobe.PhotoShop.CS2.exe

[F:1529][D:42]-> C:\DOCUME~1\Dimitri\LOCALS~1\Temp
[F:191][D:0]-> C:\DOCUME~1\Dimitri\Cookies
[F:1803][D:6]-> C:\DOCUME~1\Dimitri\LOCALS~1\TEMPOR~1\content.IE5

--------------------[ Fin du rapport a 18:18:46,68 ]----------------------
merci
0
Utilisateur anonyme
 
Telecharge malwarebytes

-> http://www.malwarebytes.org/mbam/program/mbam-setup.exe

Tu l´instale; le programme va se mettre automatiquement a jour.

Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

Click maintenant sur l´onglet recherche et coche la case : "executer un examen complet".

Puis click sur "rechercher".

Laisse le scanner le pc...

Si des elements on ete trouvés > click sur supprimer la selection.

si il t´es demandé de redemarrer > click sur "yes".

A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.

Copie et colle le rapport stp.

ps : les rapport sont aussi rangé dans l onglet rapport/log
0
john doe11 Messages postés 17 Statut Membre
 
Malwarebytes' Anti-Malware 1.21
Version de la base de données: 967
Windows 5.1.2600 Service Pack 2

21:31:34 19/07/2008
mbam-log-7-19-2008 (21-31-34).txt

Type de recherche: Examen complet (C:\|)
Eléments examinés: 158844
Temps écoulé: 2 hour(s), 42 minute(s), 37 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 2
Clé(s) du Registre infectée(s): 8
Valeur(s) du Registre infectée(s): 1
Elément(s) de données du Registre infecté(s): 3
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 9

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
C:\WINDOWS\system32\khfecBqQ.dll (Trojan.Vundo) -> Unloaded module successfully.
C:\WINDOWS\system32\fccATlIb.dll (Trojan.Vundo) -> Unloaded module successfully.

Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4e57f6e8-bed2-4093-818b-b349ef9964bf} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{4e57f6e8-bed2-4093-818b-b349ef9964bf} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{cda46c9c-a772-4f9c-b9f3-7c7a86ee0013} (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cda46c9c-a772-4f9c-b9f3-7c7a86ee0013} (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\fccatlib (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{cda46c9c-a772-4f9c-b9f3-7c7a86ee0013} (Trojan.Vundo) -> Delete on reboot.

Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo) -> Data: c:\windows\system32\khfecbqq -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\khfecbqq -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowHelp (Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
C:\WINDOWS\system32\khfecBqQ.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\QqBcefhk.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\QqBcefhk.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\efcAPIBR.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\RBIPAcfe.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\RBIPAcfe.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fccATlIb.dll (Trojan.Vundo) -> Delete on reboot.
C:\Documents and Settings\Fabien\Local Settings\Temporary Internet Files\Content.IE5\UF1GRHC3\css4[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ssqQiICR.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

voila le rapport
0
Utilisateur anonyme
 
ok

réouvre malewarebyte
va sur quarantaine
supprime tout

ensuite refais un scan hijackthis et post le rapport stp
0
john doe11 Messages postés 17 Statut Membre
 
c'est fait :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:50:26, on 19/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Search Settings\SearchSettings.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\Packs\Crystal XP\YzToolbar\YzToolbar.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Sports Interactive\Football Manager 2008\fm.exe
C:\Documents and Settings\Dimitri\Bureau\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr/toolbar/ie8/sidebar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.fr/?gws_rd=ssl
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.fr/toolbar/ie8/sidebar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.fr/keyword/%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll (file missing)
R3 - URLSearchHook: P2P Energy Toolbar - {2bae58c2-79f9-45d1-a286-81f911301c3a} - C:\Program Files\P2P_Energy\tbP2P1.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: P2P Energy Toolbar - {2bae58c2-79f9-45d1-a286-81f911301c3a} - C:\Program Files\P2P_Energy\tbP2P1.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {4E57F6E8-BED2-4093-818B-B349EF9964BF} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {6A87B991-A31F-4130-AE72-6D0C294BF082} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {CDA46C9C-A772-4F9C-B9F3-7C7A86EE0013} - (no file)
O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: P2P Energy Toolbar - {2bae58c2-79f9-45d1-a286-81f911301c3a} - C:\Program Files\P2P_Energy\tbP2P1.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Open Remote] C:\DOCUME~1\Dimitri\APPLIC~1\ERRORO~1\Bend Kind Inter.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
O4 - S-1-5-18 Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: Y'z Toolbar.lnk = ? (User 'SYSTEM')
O4 - .DEFAULT Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Default user')
O4 - .DEFAULT Startup: Y'z Toolbar.lnk = ? (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Y'z Toolbar.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
0
Utilisateur anonyme
 
Télécharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe

-> Double clique sur combofix.exe.
-> Tape sur la touche 1 (Yes) pour démarrer le scan.
-> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

NOTE : Le rapport se trouve également ici : C:\Combofix.txt

Avant d'utiliser ComboFix :

-> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

-> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.

Une fois fait, sur ton bureau double-clic sur Combofix.exe.

- Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

/!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

- En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

- Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

-> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

-> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

-> Tutoriel https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

0
john doe11 Messages postés 17 Statut Membre
 
re voila j'ai fait comme tu m'as dit voila le rapport :

ComboFix 08-07-18.5 - Dimitri 2008-07-19 22:35:33.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.591 [GMT 2:00]
Endroit: C:\Documents and Settings\Dimitri\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Dimitri\Bureau\WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
* Création d'un nouveau point de restauration
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\pascal\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\WINDOWS\system32\fccATlIb.dll
C:\WINDOWS\system32\khfecBqQ.dll

.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-19 to 2008-07-19 ))))))))))))))))))))))))))))))))))))
.

2008-07-19 18:45 . 2008-07-19 18:45 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-19 18:45 . 2008-07-19 18:45 <REP> d-------- C:\Documents and Settings\Dimitri\Application Data\Malwarebytes
2008-07-19 18:45 . 2008-07-19 18:45 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-19 18:45 . 2008-07-18 19:15 36,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-19 18:45 . 2008-07-18 19:15 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-19 17:36 . 2008-07-19 18:18 <REP> d-------- C:\Lop SD
2008-07-19 17:02 . 2008-07-19 17:02 <REP> d-------- C:\Program Files\Lavasoft
2008-07-19 17:02 . 2008-07-19 17:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-19 16:44 . 2008-07-19 16:44 <REP> d-------- C:\Program Files\Uniblue
2008-07-19 16:44 . 2008-07-19 16:44 <REP> d-------- C:\Documents and Settings\Dimitri\Application Data\Uniblue
2008-07-19 16:44 . 2008-07-19 16:44 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Uniblue
2008-07-19 16:40 . 2001-08-17 20:28 794,654 --a--c--- C:\WINDOWS\system32\dllcache\usr1801.sys
2008-07-19 16:39 . 2001-08-23 16:47 525,568 --a--c--- C:\WINDOWS\system32\dllcache\tridxp.dll
2008-07-19 16:38 . 2004-08-03 18:41 404,990 --a--c--- C:\WINDOWS\system32\dllcache\slntamr.sys
2008-07-19 16:37 . 2001-08-23 16:47 495,616 --a--c--- C:\WINDOWS\system32\dllcache\sblfx.dll
2008-07-19 16:36 . 2001-08-23 16:18 899,914 --a--c--- C:\WINDOWS\system32\dllcache\r2mdkxga.sys
2008-07-19 16:35 . 2004-08-19 12:09 4,274,816 --a--c--- C:\WINDOWS\system32\dllcache\nv4_disp.dll
2008-07-19 16:34 . 2001-08-17 20:28 802,683 --a--c--- C:\WINDOWS\system32\dllcache\ltsm.sys
2008-07-19 16:33 . 2004-08-19 12:09 702,845 --a--c--- C:\WINDOWS\system32\dllcache\i81xdnt5.dll
2008-07-19 16:32 . 2001-08-23 16:46 1,733,120 --a--c--- C:\WINDOWS\system32\dllcache\g400d.dll
2008-07-19 16:31 . 2001-08-17 19:14 952,007 --a--c--- C:\WINDOWS\system32\dllcache\diwan.sys
2008-07-19 16:30 . 2001-08-23 16:04 980,034 --a--c--- C:\WINDOWS\system32\dllcache\cicap.sys
2008-07-19 16:29 . 2001-08-23 16:03 715,466 --a--c--- C:\WINDOWS\system32\dllcache\cbmdmkxx.sys
2008-07-19 16:28 . 2001-08-17 20:28 871,388 --a--c--- C:\WINDOWS\system32\dllcache\bcmdm.sys
2008-07-19 16:27 . 2004-08-19 12:09 870,784 --a--c--- C:\WINDOWS\system32\dllcache\ati3d1ag.dll
2008-07-19 16:26 . 2001-08-17 20:28 762,780 --a--c--- C:\WINDOWS\system32\dllcache\3cwmcru.sys
2008-07-19 16:17 . 2008-07-19 16:17 <REP> d-------- C:\VundoFix Backups
2008-07-19 08:47 . 2008-07-19 08:47 <REP> d-------- C:\Documents and Settings\Dimitri\dwhelper
2008-07-12 10:03 . 2008-07-12 10:04 <REP> d-------- C:\Program Files\LimeWire
2008-07-04 22:10 . 2008-07-04 22:10 <REP> d-------- C:\Documents and Settings\Dimitri\Application Data\fltk.org
2008-07-02 19:25 . 2008-07-02 19:25 <REP> d--h----- C:\WINDOWS\PIF
2008-06-27 11:24 . 2008-06-27 11:24 <REP> d-------- C:\Program Files\OpenOffice.org 2.4
2008-06-26 20:20 . 2008-06-26 20:20 <REP> dr-h----- C:\Documents and Settings\Dimitri\Application Data\SecuROM
2008-06-26 20:20 . 2008-06-26 20:20 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-06-26 19:47 . 2008-06-26 19:48 <REP> d--h----- C:\Program Files\Zero G Registry
2008-06-26 19:47 . 2008-06-26 19:47 <REP> d-------- C:\Program Files\Sports Interactive
2008-06-26 19:46 . 2008-06-26 19:46 <REP> d--h----- C:\Documents and Settings\Dimitri\InstallAnywhere
2008-06-26 15:59 . 2008-06-26 15:59 <REP> d-------- C:\Program Files\ErrorOwnsNew
2008-06-25 09:25 . 2008-07-17 11:28 116 --a------ C:\WINDOWS\NeroDigital.ini
2008-06-22 19:38 . 2005-04-20 13:32 2,916,352 --------- C:\WINDOWS\UNNMP.exe
2008-06-22 19:38 . 2005-10-07 16:22 49,883 --------- C:\WINDOWS\UNNMP.cfg
2008-06-22 19:37 . 2008-06-22 19:37 <REP> d-------- C:\Program Files\Fichiers communs\LightScribe
2008-06-22 19:36 . 2001-07-09 11:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2008-06-22 19:35 . 2005-07-01 15:56 2,969,600 --------- C:\WINDOWS\UNNeroVision.exe
2008-06-22 19:35 . 2005-10-07 16:22 123,452 --------- C:\WINDOWS\UNNeroVision.cfg
2008-06-22 19:34 . 2008-06-22 19:34 <REP> d-------- C:\Program Files\Fichiers communs\Ahead
2008-06-22 19:34 . 2008-06-22 19:38 <REP> d-------- C:\Program Files\Ahead
2008-06-22 19:34 . 2008-06-22 19:34 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Ahead
2008-06-22 19:34 . 2004-07-26 17:16 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll
2008-06-22 19:34 . 2004-07-26 17:16 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll
2008-06-22 19:34 . 2004-07-26 17:16 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll
2008-06-22 19:34 . 2004-07-09 09:43 364,544 --------- C:\WINDOWS\system32\TwnLib4.dll
2008-06-22 19:34 . 2004-07-26 17:16 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll
2008-06-22 19:34 . 2000-06-26 11:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2008-06-22 19:34 . 2001-06-26 08:15 38,912 --------- C:\WINDOWS\system32\picn20.dll

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-19 15:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-19 14:45 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-07-18 11:52 --------- d-----w C:\Documents and Settings\Fabien\Application Data\ErrorOwnsNew
2008-07-18 11:45 --------- d-----w C:\Documents and Settings\Dimitri\Application Data\ErrorOwnsNew
2008-07-16 20:59 --------- d-----w C:\Documents and Settings\Dimitri\Application Data\LimeWire
2008-07-15 13:09 --------- d-----w C:\Program Files\RomStation
2008-07-14 10:01 --------- d-----w C:\Program Files\Java
2008-07-10 19:45 --------- d-----w C:\Program Files\MSN Messenger
2008-07-10 19:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-07-10 18:41 --------- d-----w C:\Program Files\Windows Live
2008-07-03 13:37 --------- d-----w C:\Documents and Settings\Dimitri\Application Data\OpenOffice.org2
2008-06-27 09:23 --------- d-----w C:\Program Files\OpenOffice.org 2.3
2008-06-26 16:08 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-22 17:36 --------- d-----w C:\Program Files\Fichiers communs\Nero
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-16 15:52 --------- d-----w C:\Program Files\Free Easy Burner
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-04 19:41 --------- d-----w C:\Program Files\LucasArts
2008-06-04 19:32 --------- d-----w C:\Program Files\DAEMON Tools Lite
2008-06-04 18:59 717,296 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-06-04 18:59 --------- d-----w C:\Documents and Settings\Dimitri\Application Data\DAEMON Tools
2008-06-02 10:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\ma-config.com
2008-06-02 09:18 --------- d-----w C:\Program Files\ma-config.com
2008-05-28 15:17 81,920 ------r C:\WINDOWS\bwUnin-6.1.4.36-8876480L.exe
2008-05-28 15:16 --------- d-----w C:\Program Files\Logitech
2008-05-28 15:16 --------- d-----w C:\Program Files\Fichiers communs\Logitech
2008-05-27 16:53 --------- d-----w C:\Documents and Settings\pascal\Application Data\vlc
2008-05-26 14:16 --------- d-----w C:\Documents and Settings\Fabien\Application Data\OpenOffice.org2
2008-05-24 04:48 --------- d-----w C:\Program Files\P2P_Energy
2008-05-23 16:55 --------- d-----w C:\Program Files\Conduit
2008-05-23 08:24 --------- d-----w C:\Documents and Settings\Fabien\Application Data\Shareaza
2008-05-21 09:52 --------- d-----w C:\Program Files\Shareaza
2008-05-21 09:52 --------- d-----w C:\Documents and Settings\Dimitri\Application Data\Shareaza
2008-05-20 08:48 --------- d-----w C:\Documents and Settings\Dimitri\Application Data\Cabos
2008-05-12 15:56 397,312 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2008-05-12 15:54 305,152 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2008-05-12 15:53 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2008-05-12 15:45 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2008-05-12 15:45 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2008-05-12 15:45 180,224 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2008-05-12 15:45 139,264 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2008-05-12 15:44 139,264 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2008-05-12 15:43 540,672 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2008-05-12 15:43 10,153,984 ----a-w C:\WINDOWS\system32\atioglx2.dll
2008-05-12 15:41 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2008-05-12 15:32 3,203,168 ----a-w C:\WINDOWS\system32\ati3duag.dll
2008-05-12 15:22 1,999,616 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2008-05-12 15:09 47,104 ----a-w C:\WINDOWS\system32\amdpcom32.dll
2008-05-12 15:05 5,439,488 ----a-w C:\WINDOWS\system32\atioglxx.dll
2008-05-12 15:05 327,680 ----a-w C:\WINDOWS\system32\atikvmag.dll
2008-05-12 15:03 19,968 ----a-w C:\WINDOWS\system32\atiadlxx.dll
2008-05-12 15:03 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2008-05-12 15:02 241,664 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2008-05-12 14:57 548,864 ----a-w C:\WINDOWS\system32\ati2cqag.dll
2008-05-12 08:49 593,920 ------w C:\WINDOWS\system32\ati2sgag.exe
2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-23 04:16 1,260,544 ----a-w C:\WINDOWS\system32\WININET.DLL
.

------- Sigcheck -------

2006-03-09 10:25 578048 0df75fb73f705b011630159a43d7c354 C:\WINDOWS\system32\user32.dll

2007-10-11 01:22 825344 871ae10d6ae8877e9636ae5017953d52 C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\wininet.dll
2007-12-07 03:42 825344 f4fd487241d3ac291046a22cebd2cf71 C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll
2008-03-01 14:34 827392 5a0093f59b505c008ed0cee615563c72 C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\wininet.dll
2008-04-23 09:19 827392 78d3d2b0be6ad3e6d82ccb115cf74310 C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\wininet.dll
2006-04-12 20:13 667648 241dbc4c2714b2f39afded49459ed420 C:\WINDOWS\ie7\wininet.dll
2007-08-13 19:54 818688 a4a0fc92358f39538a6494c42ef99fe9 C:\WINDOWS\ie7updates\KB942615-IE7\wininet.dll
2007-10-11 01:49 824832 bc5119c53bdd48dabc628d448a3bdccb C:\WINDOWS\ie7updates\KB944533-IE7\wininet.dll
2007-12-07 04:08 1259008 02fe4156ffba75a9ec0187469aee2f3c C:\WINDOWS\ie7updates\KB947864-IE7\wininet.dll
2008-03-01 14:58 826368 8e027981ddffa690d456fe18b37415a0 C:\WINDOWS\ie7updates\KB950759-IE7\wininet.dll
2007-10-11 01:49 824832 bc5119c53bdd48dabc628d448a3bdccb C:\WINDOWS\SoftwareDistribution\Download\3da5fb25f9bca1c53dde30405d5bbc6e\SP2GDR\wininet.dll
2007-10-11 01:22 825344 871ae10d6ae8877e9636ae5017953d52 C:\WINDOWS\SoftwareDistribution\Download\3da5fb25f9bca1c53dde30405d5bbc6e\SP2QFE\wininet.dll
2007-12-07 03:07 663552 c5a40de381481d288addee45fc67f652 C:\WINDOWS\SoftwareDistribution\Download\b2fae1d88b9f406a2afb1c850ba6f5a0\SP2GDR\wininet.dll
2007-12-07 02:47 670208 c057d734b1951393fd07e2607513d4d9 C:\WINDOWS\SoftwareDistribution\Download\b2fae1d88b9f406a2afb1c850ba6f5a0\SP2QFE\wininet.dll
2007-12-07 04:08 824832 4fc90bece54fac81b0090b94e27bfb6b C:\WINDOWS\SoftwareDistribution\Download\d2a86e41f655ff4548759e4137a0944d\SP2GDR\wininet.dll
2007-12-07 03:42 825344 f4fd487241d3ac291046a22cebd2cf71 C:\WINDOWS\SoftwareDistribution\Download\d2a86e41f655ff4548759e4137a0944d\SP2QFE\wininet.dll
2008-04-23 06:16 1260544 2288a0fb94319ccbeae49d64f7db00d1 C:\WINDOWS\system32\WININET.DLL

2007-06-13 15:22 2716160 6f341b3ca16af1e82d1fd2a54177e997 C:\WINDOWS\explorer.exe
2007-06-13 15:10 1037312 b795475444d6d57a572c14b9e1a29839 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2004-08-19 17:09 1036288 2a7bd330924252a2fd80344fc949bb72 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe

2006-03-09 10:25 57856 da81ec57acd4cdc3d4c51cf3d409af9f C:\WINDOWS\system32\spoolsv.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2bae58c2-79f9-45d1-a286-81f911301c3a}]
2008-05-24 06:48 1470488 --a------ C:\Program Files\P2P_Energy\tbP2P1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{2bae58c2-79f9-45d1-a286-81f911301c3a}"= "C:\Program Files\P2P_Energy\tbP2P1.dll" [2008-05-24 06:48 1470488]

[HKEY_CLASSES_ROOT\clsid\{2bae58c2-79f9-45d1-a286-81f911301c3a}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{2BAE58C2-79F9-45D1-A286-81F911301C3A}"= "C:\Program Files\P2P_Energy\tbP2P1.dll" [2008-05-24 06:48 1470488]

[HKEY_CLASSES_ROOT\clsid\{2bae58c2-79f9-45d1-a286-81f911301c3a}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 17:09 15360]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-04-01 11:39 486856]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 09:42 2156368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 00:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-04 15:18 267048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"LogitechCommunicationsManager"="C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 17:33 563984]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 17:37 2178832]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-03-30 14:55 185896]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"SearchSettings"="C:\Program Files\Search Settings\SearchSettings.exe" [2008-04-16 17:56 985440]
"EM_EXEC"="C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE" [2002-07-01 09:50 28672]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 18:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 10:06 88363 C:\WINDOWS\AGRSMMSG.exe]
"SoundMan"="SOUNDMAN.EXE" [2006-07-21 17:14 86016 C:\WINDOWS\SoundMan.exe]
"AlcWzrd"="ALCWZRD.EXE" [2006-05-04 17:26 2808832 C:\WINDOWS\alcwzrd.exe]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoDesktopCleanupWizard"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoStrCmpLogical"= 0 (0x0)
"NoInstrumentation"= 0 (0x0)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoDesktopCleanupWizard"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"DisablePagingExecutive"=dword:00000001
"SecondLevelDataCache"=dword:00000200

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Shareaza\\Shareaza.exe"=
"C:\\Program Files\\BitLord\\BitLord.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6346:TCP"= 6346:TCP:Shareaza
"6346:UDP"= 6346:UDP:Shareaza

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
S3 maconfservice;Ma-Config Service;C:\Program Files\ma-config.com\maconfservice.exe [2008-05-30 16:49]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2de2add1-ded7-11dc-9439-000feace6d0d}]
\Shell\AutoRun\command - J:\start.exe
\Shell\iledefrance\command - J:\start.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3294d9a7-f402-11dc-9465-000feace6d0d}]
\Shell\AutoRun\command - J:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{526eff32-e45b-11dc-9449-000feace6d0d}]
\Shell\AutoRun\command - J:\start.exe
\Shell\iledefrance\command - J:\start.exe
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-07-17 17:15:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-07-19 15:04:09 C:\WINDOWS\Tasks\Uniblue SpyEraser Nag.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
"2008-07-19 15:04:07 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
- - - - ORPHANS REMOVED - - - -

BHO-{4E57F6E8-BED2-4093-818B-B349EF9964BF} - (no file)
BHO-{CDA46C9C-A772-4F9C-B9F3-7C7A86EE0013} - (no file)
BHO-{E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
HKCU-Run-Open Remote - C:\DOCUME~1\Dimitri\APPLIC~1\ERRORO~1\Bend Kind Inter.exe
HKCU-Run-LDM - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-19 22:41:03
Windows 5.1.2600 Service Pack 2 NTFS

Balayage processus cach‚s ...

Balayage cach‚ autostart entries ...

Balayage des fichiers cach‚s ...

Scan termin‚ avec succŠs
Les fichiers cach‚s: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\Packs\Crystal XP\YzToolbar\YzToolBar.exe
C:\Program Files\Fichiers communs\LogiShrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-07-19 22:44:50 - machine was rebooted [Dimitri]
ComboFix-quarantined-files.txt 2008-07-19 20:44:45

Pre-Run: 38,755,688,448 octets libres
Post-Run: 39,316,865,024 octets libres

WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons

294 --- E O F --- 2008-07-10 18:33:08

comment tu fais pour savoir tout ça ??
0
Utilisateur anonyme
 
comment tu fais pour savoir tout ça ??

C est du travail/patience etc

auriez vous l amabilitée de me faire parvenir un nouveau rapport hijackthis des que possible

-:)
0
john doe11 Messages postés 17 Statut Membre
 
tout de suite monsieur

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:13:01, on 19/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Search Settings\SearchSettings.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Documents and Settings\Dimitri\Bureau\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.fr/keyword/%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
R3 - URLSearchHook: P2P Energy Toolbar - {2bae58c2-79f9-45d1-a286-81f911301c3a} - C:\Program Files\P2P_Energy\tbP2P1.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: P2P Energy Toolbar - {2bae58c2-79f9-45d1-a286-81f911301c3a} - C:\Program Files\P2P_Energy\tbP2P1.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: P2P Energy Toolbar - {2bae58c2-79f9-45d1-a286-81f911301c3a} - C:\Program Files\P2P_Energy\tbP2P1.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
O4 - S-1-5-18 Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: Y'z Toolbar.lnk = ? (User 'SYSTEM')
O4 - .DEFAULT Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Default user')
O4 - .DEFAULT Startup: Y'z Toolbar.lnk = ? (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Y'z Toolbar.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
0
Utilisateur anonyme
 
Copie le texte ci-dessous :

File::
C:\Program Files\Search Settings\SearchSettings.exe

Folder::
C:\Program Files\Search Settings
C:\Program Files\P2P_Energy
C:\Program Files\Conduit
C:\Documents and Settings\Dimitri\Application Data\ErrorOwnsNew
C:\Program Files\ErrorOwnsNew
C:\VundoFix Backups
C:\Lop SD

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2bae58c2-79f9-45d1-a286-81f911301c3a}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{2bae58c2-79f9-45d1-a286-81f911301c3a}"=-
[-HKEY_CLASSES_ROOT\clsid\{2bae58c2-79f9-45d1-a286-81f911301c­3a}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{2BAE58C2-79F9-45D1-A286-81F911301C3A}"=-
[-HKEY_CLASSES_ROOT\clsid\{2bae58c2-79f9-45d1-a286-81f911301c­3a}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersio­n\Run]
"SearchSettings"=-

Ouvre le Bloc-Notes puis colle le texte copié.
(Démarrer\Tous les programmes\Accessoires\Bloc notes.)
Sauvegarde ce fichier sous le nom de CFScript.txt.

Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :

http://sd-1.archive-host.com/membres/up/1366464061/CFScript.gif

Cela va relancer Combofix,

Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

Ne touche à rien tant que le scan n'est pas terminé.

Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.

S'il n'y a pas de rédémarrage, poste quand même les rapports.

0
john doe11 Messages postés 17 Statut Membre
 
voila le rapport ComboFix :

ComboFix 08-07-18.5 - Dimitri 2008-07-19 23:38:07.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.611 [GMT 2:00]
Endroit: C:\Documents and Settings\Dimitri\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Dimitri\Bureau\CFScript.txt
* Création d'un nouveau point de restauration

FILE ::
C:\Program Files\Search Settings\SearchSettings.exe
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Dimitri\Application Data\ErrorOwnsNew
C:\Lop SD
C:\Lop SD\App-Prog.lsd
C:\Lop SD\AuDoss.lsd
C:\Lop SD\autrinf.cmd
C:\Lop SD\AWF.cmd
C:\Lop SD\Back.cmd
C:\Lop SD\Backup-Lop\DOCUME~1\Dimitri\Cookies\dimitri@2xmoinscher[1].txt
C:\Lop SD\Backup-Lop\DOCUME~1\Dimitri\Cookies\dimitri@32vegas[2].txt
C:\Lop SD\Backup-Lop\DOCUME~1\Dimitri\Cookies\dimitri@adin.bigpoint[1].txt
C:\Lop SD\Backup-Lop\DOCUME~1\Dimitri\Cookies\dimitri@banner.32vegas[2].txt
C:\Lop SD\Backup-Lop\DOCUME~1\Dimitri\Cookies\dimitri@cotedazurpalace[1].txt
C:\Lop SD\Backup-Lop\DOCUME~1\Dimitri\Cookies\dimitri@fr1.seafight.bigpoint[2].txt
C:\Lop SD\Backup-Lop\DOCUME~1\Dimitri\Cookies\dimitri@www.2xmoinscher[1].txt
C:\Lop SD\Backup-Lop\DOCUME~1\Dimitri\Cookies\dimitri@www.adserver5[2].txt
C:\Lop SD\Backup-Lop\Hosts\hosts
C:\Lop SD\Backup-Lop\Reg\HKCU_Run.reg
C:\Lop SD\Backup-Lop\Reg\HKLM_Run.reg
C:\Lop SD\Backup-Lop\Reg\HKLM_Uninstall.reg
C:\Lop SD\Backup-Lop\Search Settings\SearchSettings.exe
C:\Lop SD\Boo.reg
C:\Lop SD\BooFix.cmd
C:\Lop SD\catchme.exe
C:\Lop SD\DirectFix.cmd
C:\Lop SD\Doss.lsd
C:\Lop SD\Icon_Lop.ico
C:\Lop SD\KILL.cmd
C:\Lop SD\Langues.cmd
C:\Lop SD\Lop S&D.lnk
C:\Lop SD\LopScript.cmd
C:\Lop SD\LopSD.cmd
C:\Lop SD\lsTasks.exe
C:\Lop SD\Orph.egd
C:\Lop SD\osVer.exe
C:\Lop SD\paths.bat
C:\Lop SD\Process.exe
C:\Lop SD\Rapport-Lop.txt
C:\Lop SD\RegLop.reg
C:\Lop SD\S_LopV.cmd
C:\Lop SD\S_LopX.cmd
C:\Lop SD\sed.exe
C:\Lop SD\setpath.exe
C:\Lop SD\task.txt
C:\Lop SD\Uninstal.exe
C:\Program Files\Conduit
C:\Program Files\Conduit\Community Alerts\Alert.dll
C:\Program Files\ErrorOwnsNew
C:\Program Files\P2P_Energy
C:\Program Files\P2P_Energy\INSTALL.LOG
C:\Program Files\P2P_Energy\tbP2P_.dll
C:\Program Files\P2P_Energy\tbP2P1.dll
C:\Program Files\P2P_Energy\toolbar.cfg
C:\Program Files\P2P_Energy\UNWISE.EXE
C:\Program Files\Search Settings
C:\Program Files\Search Settings\kb127\SearchSettingsRes409.dll
C:\Program Files\Search Settings\SearchSettings.exe
C:\VundoFix Backups

.
((((((((((((((((((((((((((((( Fichiers créés 2008-06-19 to 2008-07-19 ))))))))))))))))))))))))))))))))))))
.

2008-07-19 18:45 . 2008-07-19 18:45 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-19 18:45 . 2008-07-19 18:45 <REP> d-------- C:\Documents and Settings\Dimitri\Application Data\Malwarebytes
2008-07-19 18:45 . 2008-07-19 18:45 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-19 18:45 . 2008-07-18 19:15 36,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-19 18:45 . 2008-07-18 19:15 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-19 17:02 . 2008-07-19 17:02 <REP> d-------- C:\Program Files\Lavasoft
2008-07-19 17:02 . 2008-07-19 17:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-19 16:44 . 2008-07-19 16:44 <REP> d-------- C:\Program Files\Uniblue
2008-07-19 16:44 . 2008-07-19 16:44 <REP> d-------- C:\Documents and Settings\Dimitri\Application Data\Uniblue
2008-07-19 16:44 . 2008-07-19 16:44 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Uniblue
2008-07-19 16:40 . 2001-08-17 20:28 794,654 --a--c--- C:\WINDOWS\system32\dllcache\usr1801.sys
2008-07-19 16:39 . 2001-08-23 16:47 525,568 --a--c--- C:\WINDOWS\system32\dllcache\tridxp.dll
2008-07-19 16:38 . 2004-08-03 18:41 404,990 --a--c--- C:\WINDOWS\system32\dllcache\slntamr.sys
2008-07-19 16:37 . 2001-08-23 16:47 495,616 --a--c--- C:\WINDOWS\system32\dllcache\sblfx.dll
2008-07-19 16:36 . 2001-08-23 16:18 899,914 --a--c--- C:\WINDOWS\system32\dllcache\r2mdkxga.sys
2008-07-19 16:35 . 2004-08-19 12:09 4,274,816 --a--c--- C:\WINDOWS\system32\dllcache\nv4_disp.dll
2008-07-19 16:34 . 2001-08-17 20:28 802,683 --a--c--- C:\WINDOWS\system32\dllcache\ltsm.sys
2008-07-19 16:33 . 2004-08-19 12:09 702,845 --a--c--- C:\WINDOWS\system32\dllcache\i81xdnt5.dll
2008-07-19 16:32 . 2001-08-23 16:46 1,733,120 --a--c--- C:\WINDOWS\system32\dllcache\g400d.dll
2008-07-19 16:31 . 2001-08-17 19:14 952,007 --a--c--- C:\WINDOWS\system32\dllcache\diwan.sys
2008-07-19 16:30 . 2001-08-23 16:04 980,034 --a--c--- C:\WINDOWS\system32\dllcache\cicap.sys
2008-07-19 16:29 . 2001-08-23 16:03 715,466 --a--c--- C:\WINDOWS\system32\dllcache\cbmdmkxx.sys
2008-07-19 16:28 . 2001-08-17 20:28 871,388 --a--c--- C:\WINDOWS\system32\dllcache\bcmdm.sys
2008-07-19 16:27 . 2004-08-19 12:09 870,784 --a--c--- C:\WINDOWS\system32\dllcache\ati3d1ag.dll
2008-07-19 16:26 . 2001-08-17 20:28 762,780 --a--c--- C:\WINDOWS\system32\dllcache\3cwmcru.sys
2008-07-19 08:47 . 2008-07-19 08:47 <REP> d-------- C:\Documents and Settings\Dimitri\dwhelper
2008-07-12 10:03 . 2008-07-12 10:04 <REP> d-------- C:\Program Files\LimeWire
2008-07-04 22:10 . 2008-07-04 22:10 <REP> d-------- C:\Documents and Settings\Dimitri\Application Data\fltk.org
2008-07-02 19:25 . 2008-07-02 19:25 <REP> d--h----- C:\WINDOWS\PIF
2008-06-27 11:24 . 2008-06-27 11:24 <REP> d-------- C:\Program Files\OpenOffice.org 2.4
2008-06-26 20:20 . 2008-06-26 20:20 <REP> dr-h----- C:\Documents and Settings\Dimitri\Application Data\SecuROM
2008-06-26 20:20 . 2008-06-26 20:20 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-06-26 19:47 . 2008-06-26 19:48 <REP> d--h----- C:\Program Files\Zero G Registry
2008-06-26 19:47 . 2008-06-26 19:47 <REP> d-------- C:\Program Files\Sports Interactive
2008-06-26 19:46 . 2008-06-26 19:46 <REP> d--h----- C:\Documents and Settings\Dimitri\InstallAnywhere
2008-06-25 09:25 . 2008-07-17 11:28 116 --a------ C:\WINDOWS\NeroDigital.ini
2008-06-22 19:38 . 2005-04-20 13:32 2,916,352 --------- C:\WINDOWS\UNNMP.exe
2008-06-22 19:38 . 2005-10-07 16:22 49,883 --------- C:\WINDOWS\UNNMP.cfg
2008-06-22 19:37 . 2008-06-22 19:37 <REP> d-------- C:\Program Files\Fichiers communs\LightScribe
2008-06-22 19:36 . 2001-07-09 11:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2008-06-22 19:35 . 2005-07-01 15:56 2,969,600 --------- C:\WINDOWS\UNNeroVision.exe
2008-06-22 19:35 . 2005-10-07 16:22 123,452 --------- C:\WINDOWS\UNNeroVision.cfg
2008-06-22 19:34 . 2008-06-22 19:34 <REP> d-------- C:\Program Files\Fichiers communs\Ahead
2008-06-22 19:34 . 2008-06-22 19:38 <REP> d-------- C:\Program Files\Ahead
2008-06-22 19:34 . 2008-06-22 19:34 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Ahead
2008-06-22 19:34 . 2004-07-26 17:16 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll
2008-06-22 19:34 . 2004-07-26 17:16 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll
2008-06-22 19:34 . 2004-07-26 17:16 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll
2008-06-22 19:34 . 2004-07-09 09:43 364,544 --------- C:\WINDOWS\system32\TwnLib4.dll
2008-06-22 19:34 . 2004-07-26 17:16 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll
2008-06-22 19:34 . 2000-06-26 11:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2008-06-22 19:34 . 2001-06-26 08:15 38,912 --------- C:\WINDOWS\system32\picn20.dll

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-19 15:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-19 14:45 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-07-18 11:52 --------- d-----w C:\Documents and Settings\Fabien\Application Data\ErrorOwnsNew
2008-07-16 20:59 --------- d-----w C:\Documents and Settings\Dimitri\Application Data\LimeWire
2008-07-15 13:09 --------- d-----w C:\Program Files\RomStation
2008-07-14 10:01 --------- d-----w C:\Program Files\Java
2008-07-10 19:45 --------- d-----w C:\Program Files\MSN Messenger
2008-07-10 19:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-07-10 18:41 --------- d-----w C:\Program Files\Windows Live
2008-07-03 13:37 --------- d-----w C:\Documents and Settings\Dimitri\Application Data\OpenOffice.org2
2008-06-27 09:23 --------- d-----w C:\Program Files\OpenOffice.org 2.3
2008-06-26 16:08 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-22 17:36 --------- d-----w C:\Program Files\Fichiers communs\Nero
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-16 15:52 --------- d-----w C:\Program Files\Free Easy Burner
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-04 19:41 --------- d-----w C:\Program Files\LucasArts
2008-06-04 19:32 --------- d-----w C:\Program Files\DAEMON Tools Lite
2008-06-04 18:59 717,296 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-06-04 18:59 --------- d-----w C:\Documents and Settings\Dimitri\Application Data\DAEMON Tools
2008-06-02 10:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\ma-config.com
2008-06-02 09:18 --------- d-----w C:\Program Files\ma-config.com
2008-05-28 15:17 81,920 ------r C:\WINDOWS\bwUnin-6.1.4.36-8876480L.exe
2008-05-28 15:16 --------- d-----w C:\Program Files\Logitech
2008-05-28 15:16 --------- d-----w C:\Program Files\Fichiers communs\Logitech
2008-05-27 16:53 --------- d-----w C:\Documents and Settings\pascal\Application Data\vlc
2008-05-26 14:16 --------- d-----w C:\Documents and Settings\Fabien\Application Data\OpenOffice.org2
2008-05-23 08:24 --------- d-----w C:\Documents and Settings\Fabien\Application Data\Shareaza
2008-05-21 09:52 --------- d-----w C:\Program Files\Shareaza
2008-05-21 09:52 --------- d-----w C:\Documents and Settings\Dimitri\Application Data\Shareaza
2008-05-20 08:48 --------- d-----w C:\Documents and Settings\Dimitri\Application Data\Cabos
2008-05-12 15:56 397,312 ----a-w C:\WINDOWS\system32\ATIDEMGX.dll
2008-05-12 15:54 305,152 ----a-w C:\WINDOWS\system32\ati2dvag.dll
2008-05-12 15:53 307,200 ----a-w C:\WINDOWS\system32\atiiiexx.dll
2008-05-12 15:45 43,520 ----a-w C:\WINDOWS\system32\ati2edxx.dll
2008-05-12 15:45 26,112 ----a-w C:\WINDOWS\system32\Ati2mdxx.exe
2008-05-12 15:45 180,224 ----a-w C:\WINDOWS\system32\atipdlxx.dll
2008-05-12 15:45 139,264 ----a-w C:\WINDOWS\system32\Oemdspif.dll
2008-05-12 15:44 139,264 ----a-w C:\WINDOWS\system32\ati2evxx.dll
2008-05-12 15:43 540,672 ----a-w C:\WINDOWS\system32\ati2evxx.exe
2008-05-12 15:43 10,153,984 ----a-w C:\WINDOWS\system32\atioglx2.dll
2008-05-12 15:41 53,248 ----a-w C:\WINDOWS\system32\ATIDDC.DLL
2008-05-12 15:32 3,203,168 ----a-w C:\WINDOWS\system32\ati3duag.dll
2008-05-12 15:22 1,999,616 ----a-w C:\WINDOWS\system32\ativvaxx.dll
2008-05-12 15:09 47,104 ----a-w C:\WINDOWS\system32\amdpcom32.dll
2008-05-12 15:05 5,439,488 ----a-w C:\WINDOWS\system32\atioglxx.dll
2008-05-12 15:05 327,680 ----a-w C:\WINDOWS\system32\atikvmag.dll
2008-05-12 15:03 19,968 ----a-w C:\WINDOWS\system32\atiadlxx.dll
2008-05-12 15:03 17,408 ----a-w C:\WINDOWS\system32\atitvo32.dll
2008-05-12 15:02 241,664 ----a-w C:\WINDOWS\system32\atiok3x2.dll
2008-05-12 14:57 548,864 ----a-w C:\WINDOWS\system32\ati2cqag.dll
2008-05-12 08:49 593,920 ------w C:\WINDOWS\system32\ati2sgag.exe
2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-23 04:16 1,260,544 ----a-w C:\WINDOWS\system32\WININET.DLL
.

------- Sigcheck -------

2006-03-09 10:25 578048 0df75fb73f705b011630159a43d7c354 C:\WINDOWS\system32\user32.dll

2007-10-11 01:22 825344 871ae10d6ae8877e9636ae5017953d52 C:\WINDOWS\$hf_mig$\KB942615-IE7\SP2QFE\wininet.dll
2007-12-07 03:42 825344 f4fd487241d3ac291046a22cebd2cf71 C:\WINDOWS\$hf_mig$\KB944533-IE7\SP2QFE\wininet.dll
2008-03-01 14:34 827392 5a0093f59b505c008ed0cee615563c72 C:\WINDOWS\$hf_mig$\KB947864-IE7\SP2QFE\wininet.dll
2008-04-23 09:19 827392 78d3d2b0be6ad3e6d82ccb115cf74310 C:\WINDOWS\$hf_mig$\KB950759-IE7\SP2QFE\wininet.dll
2006-04-12 20:13 667648 241dbc4c2714b2f39afded49459ed420 C:\WINDOWS\ie7\wininet.dll
2007-08-13 19:54 818688 a4a0fc92358f39538a6494c42ef99fe9 C:\WINDOWS\ie7updates\KB942615-IE7\wininet.dll
2007-10-11 01:49 824832 bc5119c53bdd48dabc628d448a3bdccb C:\WINDOWS\ie7updates\KB944533-IE7\wininet.dll
2007-12-07 04:08 1259008 02fe4156ffba75a9ec0187469aee2f3c C:\WINDOWS\ie7updates\KB947864-IE7\wininet.dll
2008-03-01 14:58 826368 8e027981ddffa690d456fe18b37415a0 C:\WINDOWS\ie7updates\KB950759-IE7\wininet.dll
2007-10-11 01:49 824832 bc5119c53bdd48dabc628d448a3bdccb C:\WINDOWS\SoftwareDistribution\Download\3da5fb25f9bca1c53dde30405d5bbc6e\SP2GDR\wininet.dll
2007-10-11 01:22 825344 871ae10d6ae8877e9636ae5017953d52 C:\WINDOWS\SoftwareDistribution\Download\3da5fb25f9bca1c53dde30405d5bbc6e\SP2QFE\wininet.dll
2007-12-07 03:07 663552 c5a40de381481d288addee45fc67f652 C:\WINDOWS\SoftwareDistribution\Download\b2fae1d88b9f406a2afb1c850ba6f5a0\SP2GDR\wininet.dll
2007-12-07 02:47 670208 c057d734b1951393fd07e2607513d4d9 C:\WINDOWS\SoftwareDistribution\Download\b2fae1d88b9f406a2afb1c850ba6f5a0\SP2QFE\wininet.dll
2007-12-07 04:08 824832 4fc90bece54fac81b0090b94e27bfb6b C:\WINDOWS\SoftwareDistribution\Download\d2a86e41f655ff4548759e4137a0944d\SP2GDR\wininet.dll
2007-12-07 03:42 825344 f4fd487241d3ac291046a22cebd2cf71 C:\WINDOWS\SoftwareDistribution\Download\d2a86e41f655ff4548759e4137a0944d\SP2QFE\wininet.dll
2008-04-23 06:16 1260544 2288a0fb94319ccbeae49d64f7db00d1 C:\WINDOWS\system32\WININET.DLL

2007-06-13 15:22 2716160 6f341b3ca16af1e82d1fd2a54177e997 C:\WINDOWS\explorer.exe
2007-06-13 15:10 1037312 b795475444d6d57a572c14b9e1a29839 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2004-08-19 17:09 1036288 2a7bd330924252a2fd80344fc949bb72 C:\WINDOWS\$NtUninstallKB938828$\explorer.exe

2006-03-09 10:25 57856 da81ec57acd4cdc3d4c51cf3d409af9f C:\WINDOWS\system32\spoolsv.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 17:09 15360]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-04-01 11:39 486856]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 09:42 2156368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 00:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-04 15:18 267048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"LogitechCommunicationsManager"="C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 17:33 563984]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 17:37 2178832]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-03-30 14:55 185896]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"EM_EXEC"="C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE" [2002-07-01 09:50 28672]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 18:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 10:06 88363 C:\WINDOWS\AGRSMMSG.exe]
"SoundMan"="SOUNDMAN.EXE" [2006-07-21 17:14 86016 C:\WINDOWS\SoundMan.exe]
"AlcWzrd"="ALCWZRD.EXE" [2006-05-04 17:26 2808832 C:\WINDOWS\alcwzrd.exe]

C:\Documents and Settings\Dimitri\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 20:16:50 113664]
Y'z Toolbar.lnk - C:\WINDOWS\Packs\Crystal XP\YzToolbar\YzToolbar.exe [2008-02-17 23:23:53 90112]

C:\Documents and Settings\Dimitri\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 20:16:50 113664]
Y'z Toolbar.lnk - C:\WINDOWS\Packs\Crystal XP\YzToolbar\YzToolbar.exe [2008-02-17 23:23:53 90112]

C:\Documents and Settings\Dimitri\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 20:16:50 113664]
Y'z Toolbar.lnk - C:\WINDOWS\Packs\Crystal XP\YzToolbar\YzToolbar.exe [2008-02-17 23:23:53 90112]

C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2008-05-28 17:17:13 169472]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoDesktopCleanupWizard"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoStrCmpLogical"= 0 (0x0)
"NoInstrumentation"= 0 (0x0)

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoDesktopCleanupWizard"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"DisablePagingExecutive"=dword:00000001
"SecondLevelDataCache"=dword:00000200

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Shareaza\\Shareaza.exe"=
"C:\\Program Files\\BitLord\\BitLord.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6346:TCP"= 6346:TCP:Shareaza
"6346:UDP"= 6346:UDP:Shareaza

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
S3 maconfservice;Ma-Config Service;C:\Program Files\ma-config.com\maconfservice.exe [2008-05-30 16:49]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2de2add1-ded7-11dc-9439-000feace6d0d}]
\Shell\AutoRun\command - J:\start.exe
\Shell\iledefrance\command - J:\start.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3294d9a7-f402-11dc-9465-000feace6d0d}]
\Shell\AutoRun\command - J:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{526eff32-e45b-11dc-9449-000feace6d0d}]
\Shell\AutoRun\command - J:\start.exe
\Shell\iledefrance\command - J:\start.exe
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-07-17 17:15:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-07-19 15:04:09 C:\WINDOWS\Tasks\Uniblue SpyEraser Nag.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
"2008-07-19 15:04:07 C:\WINDOWS\Tasks\Uniblue SpyEraser.job"
- C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe
.
- - - - ORPHANS REMOVED - - - -

HKLM-Run-SearchSettings - C:\Program Files\Search Settings\SearchSettings.exe

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-19 23:40:35
Windows 5.1.2600 Service Pack 2 NTFS

Balayage processus cachés ...

Balayage caché autostart entries ...

Balayage des fichiers cachés ...

Scan terminé avec succès
Les fichiers cachés: 0

**************************************************************************
.
Temps d'accomplissement: 2008-07-19 23:42:11
ComboFix-quarantined-files.txt 2008-07-19 21:42:05
ComboFix2.txt 2008-07-19 20:44:51

Pre-Run: 41,340,190,720 octets libres
Post-Run: 41,323,884,544 octets libres

314 --- E O F --- 2008-07-10 18:33:08
0
john doe11 Messages postés 17 Statut Membre
 
voila le rapport HijackThis :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:45:03, on 19/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Dimitri\Bureau\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.fr/keyword/%s
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
R3 - URLSearchHook: (no name) - {2bae58c2-79f9-45d1-a286-81f911301c3a} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2bae58c2-79f9-45d1-a286-81f911301c3a} - (no file)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
O4 - S-1-5-18 Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: Y'z Toolbar.lnk = ? (User 'SYSTEM')
O4 - .DEFAULT Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe (User 'Default user')
O4 - .DEFAULT Startup: Y'z Toolbar.lnk = ? (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Y'z Toolbar.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
0
Utilisateur anonyme
 
si c est la version gratuite désinstal adobe reader acrobat car pas a jours et telecharge et instal cette version :

https://get2.adobe.com/reader/otherversions/

ensuite réouvre hijackthis
fais scan only
coche ces lignes :

R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
R3 - URLSearchHook: (no name) - {2bae58c2-79f9-45d1-a286-81f911301c3a} - (no file)

O2 - BHO: (no name) - {2bae58c2-79f9-45d1-a286-81f911301c3a} - (no file)

O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')

O4 - S-1-5-18 Startup: Y'z Toolbar.lnk = ? (User 'SYSTEM')

O4 - .DEFAULT Startup: Y'z Toolbar.lnk = ? (User 'Default user')

O4 - Startup: Y'z Toolbar.lnk = ?

O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)

tu les coches et tu clic sur fix checked

ensuite :

télécharge OTMoveIt http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe (de Old_Timer) sur ton Bureau.
double-clique sur OTMoveIt.exe pour le lancer.
Assure toi que la case Unregister Dll's and Ocx's soit bien cochée
copie la liste qui se trouve en gras ci-dessous,
et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

C:\WINDOWS\Packs\Crystal XP\YzToolbar\

clique sur MoveIt! pour lancer la suppression.
le résultat apparaitra dans le cadre "Results".
clique sur Exit pour fermer.
poste le rapport situé dans C:\_OTMoveIt\MovedFiles + un nouveau rapport hijackthis

il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

et dis nous tes soucis actuels

0