Virus "about.Brontok.A"
galomert
Messages postés
15
Statut
Membre
-
sKe69 Messages postés 21955 Statut Contributeur sécurité -
sKe69 Messages postés 21955 Statut Contributeur sécurité -
Bonjour,
j'ai le virus about.Brontok.A qui me soule !!!
voici les symptomes :
- lancement de vista a l'aide du "gestionnaire de tache", faut que je tape explorer.exe
- telechargement impossible, l'ordi redemarre seul
- dans le dossier msconfig, il y a : "Bron-Spizaetus", "Tok-cirhatus-2058", "empty" qui sont cocher pour le démarrage et qui revient a chaque fois meme en les décochant.
- dans mon dossier Image il y a le fameux "about.Brontok.A"
j'ai eu ce probleme a partir du moment ou j'ai mis une clef USB dans mon ordi. 1 jour apres ca a commencer les problemes.
C'est grave docteur ?
je suis entrain de faire un rapport BITdefender en ligne. est ce deja une bonne initiative ?
j'ai le virus about.Brontok.A qui me soule !!!
voici les symptomes :
- lancement de vista a l'aide du "gestionnaire de tache", faut que je tape explorer.exe
- telechargement impossible, l'ordi redemarre seul
- dans le dossier msconfig, il y a : "Bron-Spizaetus", "Tok-cirhatus-2058", "empty" qui sont cocher pour le démarrage et qui revient a chaque fois meme en les décochant.
- dans mon dossier Image il y a le fameux "about.Brontok.A"
j'ai eu ce probleme a partir du moment ou j'ai mis une clef USB dans mon ordi. 1 jour apres ca a commencer les problemes.
C'est grave docteur ?
je suis entrain de faire un rapport BITdefender en ligne. est ce deja une bonne initiative ?
A voir également:
- Virus "about.Brontok.A"
- Virus mcafee - Accueil - Piratage
- Virus facebook demande d'amis - Accueil - Facebook
- Virus informatique - Guide
- Panda anti virus gratuit - Télécharger - Antivirus & Antimalwares
- Undisclosed-recipients virus - Guide
72 réponses
Re,
il est sur ton Bureau.
fais ceci :
Acte 2 :
Copie ou imprime les instructions avant
Déconnecte toi d'internet et ferme toutes tes applications.
Désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)
Crée un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :
File::
C:\Windows\ShellNew\RakyatKelaparan.exe
C:\Users\Corrado\AppData\Local\br5139on.exe
C:\Windows\MS32DLL.dll.vbs
C:\Windows\system32\kjshsvsr.exe
Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bron-Spizaetus]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tok-Cirrhatus-2058]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MS32DLL]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mijwyefd]
RenV::
C:\SWSetup\SP34746\WCAMC\FW_210_Silence Install .exe
Enregistre ce fichier sous le nom CFscript
Fait un glisser/déposer de ce fichier CFscript sur le fichier ComboFix.exe :
Clique sur le fichier CFscript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFscrïpt vienne recouvrir l'icône de Combofix. Relache la souris. Combofix va démarrer.
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Réactive ton parefeu, ton antivirus, la garde de ton antispyware
Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
Attention : cette manip a été fait pour cet ordi. Tout réutilisation peut endommager sévèrement le système d'exploitation.
il est sur ton Bureau.
fais ceci :
Acte 2 :
Copie ou imprime les instructions avant
Déconnecte toi d'internet et ferme toutes tes applications.
Désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)
Crée un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :
File::
C:\Windows\ShellNew\RakyatKelaparan.exe
C:\Users\Corrado\AppData\Local\br5139on.exe
C:\Windows\MS32DLL.dll.vbs
C:\Windows\system32\kjshsvsr.exe
Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bron-Spizaetus]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tok-Cirrhatus-2058]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MS32DLL]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mijwyefd]
RenV::
C:\SWSetup\SP34746\WCAMC\FW_210_Silence Install .exe
Enregistre ce fichier sous le nom CFscript
Fait un glisser/déposer de ce fichier CFscript sur le fichier ComboFix.exe :
Clique sur le fichier CFscript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFscrïpt vienne recouvrir l'icône de Combofix. Relache la souris. Combofix va démarrer.
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Réactive ton parefeu, ton antivirus, la garde de ton antispyware
Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
Attention : cette manip a été fait pour cet ordi. Tout réutilisation peut endommager sévèrement le système d'exploitation.
lorsque je clik sur combofix ca me dit :
"une reference a ete renvoyer par le serveur" et ca ne souvre pas.
"une reference a ete renvoyer par le serveur" et ca ne souvre pas.
Salut,
Fait un glisser/déposer de ce fichier CFscript sur le fichier ComboFix.exe :
Clique sur le fichier CFscript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFscrïpt vienne recouvrir l'icône de Combofix. Relache la souris. Combofix va démarrer.
Il ne faut donc pas cliquer sur Combofix !
A+
Fait un glisser/déposer de ce fichier CFscript sur le fichier ComboFix.exe :
Clique sur le fichier CFscript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFscrïpt vienne recouvrir l'icône de Combofix. Relache la souris. Combofix va démarrer.
Il ne faut donc pas cliquer sur Combofix !
A+
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
je fais exactement ca mais ca me dit :
"combofix fonctionne que sur xp ou 2000"
et le logiciel sarette ! je dois faire quoi
"combofix fonctionne que sur xp ou 2000"
et le logiciel sarette ! je dois faire quoi
Bien ... pour avancer ^^ :
on va supprimé le combofix que tu as et le retéléchargé :
1- Pour supprimer :
-->Cliques sur " Démarrer ( ou combine la touche Windows + R ) -> " Executer " -> copie/colle cette ligne :
ComboFix /u
( laisse l'espace entre Combofix et /u )
-->Valide.
2- re-télécharges le ainsi :
Télécharges ComboFix (par sUBs) sur ton Bureau (et pas ailleur !):
http://download.bleepingcomputer.com/sUBs/ComboFix.exe <--- clik droit sur ce lien et choisis "enregistrer la cible sous ... " : dans la fenêtre qui s'ouvre tape C-Fix et valide .
puis reprend la manipe de Lyonnais92 du poste 63 ...
postes le rapport obtenu et attends la suite avec DIID ...
on va supprimé le combofix que tu as et le retéléchargé :
1- Pour supprimer :
-->Cliques sur " Démarrer ( ou combine la touche Windows + R ) -> " Executer " -> copie/colle cette ligne :
ComboFix /u
( laisse l'espace entre Combofix et /u )
-->Valide.
2- re-télécharges le ainsi :
Télécharges ComboFix (par sUBs) sur ton Bureau (et pas ailleur !):
http://download.bleepingcomputer.com/sUBs/ComboFix.exe <--- clik droit sur ce lien et choisis "enregistrer la cible sous ... " : dans la fenêtre qui s'ouvre tape C-Fix et valide .
puis reprend la manipe de Lyonnais92 du poste 63 ...
postes le rapport obtenu et attends la suite avec DIID ...
voici le rapport
ComboFix 08-07-31.01 - Corrado 2008-07-31 20:16:50.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.1359 [GMT 2:00]
Endroit: C:\Users\Corrado\Desktop\C-Fix.exe
Command switches used :: C:\Users\Corrado\Desktop\CFscript.txt
* Création d'un nouveau point de restauration
FILE ::
C:\Users\Corrado\AppData\Local\br5139on.exe
C:\Windows\MS32DLL.dll.vbs
C:\Windows\ShellNew\RakyatKelaparan.exe
C:\Windows\system32\kjshsvsr.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2008-06-28 to 2008-07-31 ))))))))))))))))))))))))))))))))))))
.
2008-07-31 20:14 . 2008-07-31 20:14 <REP> d-------- C:\ComboFix
2008-07-31 16:39 . 2008-07-31 16:39 <REP> d-------- C:\Program Files\iTunes
2008-07-31 16:39 . 2008-07-31 16:39 <REP> d-------- C:\Program Files\iPod
2008-07-31 16:39 . 2008-07-31 16:39 <REP> d-------- C:\Program Files\Bonjour
2008-07-31 16:38 . 2008-07-31 16:38 <REP> d-------- C:\Program Files\QuickTime
2008-07-31 16:37 . 2008-07-31 16:37 <REP> d-------- C:\Windows\LastGood
2008-07-31 16:37 . 2008-07-31 16:39 <REP> d-------- C:\Users\All Users\Apple Computer
2008-07-31 16:37 . 2008-07-31 16:39 <REP> d-------- C:\PROGRA~2\Apple Computer
2008-07-31 16:36 . 2008-07-31 16:36 <REP> d-------- C:\Program Files\Common Files\Apple
2008-07-31 16:31 . 2008-07-31 20:15 <REP> d-------- C:\327882R2FWJFW
2008-07-30 14:17 . 2008-07-30 14:17 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-30 14:17 . 2008-07-23 20:09 38,472 --a------ C:\Windows\System32\drivers\mbamswissarmy.sys
2008-07-30 14:17 . 2008-07-23 20:09 17,144 --a------ C:\Windows\System32\drivers\mbam.sys
2008-07-29 14:49 . 2008-07-30 16:09 <REP> d-------- C:\Toolbar SD
2008-07-29 04:27 . 2008-07-29 04:28 225,594,157 --a------ C:\Windows\MEMORY.DMP
2008-07-29 04:15 . 2008-07-29 04:25 96,559 --a------ C:\Windows\System32\drivers\klin.dat
2008-07-29 04:15 . 2008-07-29 04:25 87,855 --a------ C:\Windows\System32\drivers\klick.dat
2008-07-29 04:14 . 2008-07-31 18:43 <REP> d-------- C:\Users\All Users\Kaspersky Lab
2008-07-29 04:14 . 2008-07-29 04:14 <REP> d-------- C:\Program Files\Kaspersky Lab
2008-07-29 04:14 . 2008-07-31 18:43 <REP> d-------- C:\PROGRA~2\Kaspersky Lab
2008-07-29 04:14 . 2008-07-31 16:27 3,519,520 --ahs---- C:\Windows\System32\drivers\fidbox.dat
2008-07-29 04:14 . 2008-07-31 20:14 319,520 --ahs---- C:\Windows\System32\drivers\fidbox2.dat
2008-07-29 04:14 . 2008-07-31 16:27 29,624 --ahs---- C:\Windows\System32\drivers\fidbox.idx
2008-07-29 04:14 . 2008-07-31 20:14 2,116 --ahs---- C:\Windows\System32\drivers\fidbox2.idx
2008-07-29 03:56 . 2008-07-29 03:56 <REP> d-------- C:\Deckard
2008-07-29 02:30 . 2008-05-27 06:59 106,605 --a------ C:\Windows\System32\StructuredQuerySchema.bin
2008-07-29 02:30 . 2008-05-27 07:17 34,816 --a------ C:\Windows\System32\msscb.dll
2008-07-29 02:30 . 2008-05-27 06:59 18,904 --a------ C:\Windows\System32\StructuredQuerySchemaTrivial.bin
2008-07-29 02:30 . 2008-05-27 07:17 11,776 --a------ C:\Windows\System32\msshooks.dll
2008-07-23 17:24 . 2008-07-23 17:24 <REP> d-------- C:\Users\All Users\Malwarebytes
2008-07-23 17:24 . 2008-07-23 17:24 <REP> d-------- C:\PROGRA~2\Malwarebytes
2008-07-22 11:52 . 2008-07-22 11:52 <REP> d-------- C:\autorun.MSNFix
2008-07-22 11:46 . 2008-07-22 11:46 173 --a------ C:\curr_ver.tmp
2008-07-21 20:46 . 2008-07-22 03:35 <REP> d-------- C:\Windows\BDOSCAN8
2008-07-21 20:00 . 2008-07-29 02:37 <REP> d-------- C:\Windows\ShellNew
2008-07-11 11:46 . 2008-06-26 03:45 12,240,896 --a------ C:\Windows\System32\NlsLexicons0007.dll
2008-07-11 11:46 . 2008-06-26 03:45 2,644,480 --a------ C:\Windows\System32\NlsLexicons0009.dll
2008-07-11 11:46 . 2008-06-26 05:29 801,280 --a------ C:\Windows\System32\NaturalLanguage6.dll
2008-07-03 01:08 . 2008-07-03 01:08 <REP> d-------- C:\Program Files\Red Kawa
2008-07-02 18:09 . 2008-07-02 18:09 510 --a------ C:\Windows\WORDPAD.INI
2008-06-25 18:49 . 2008-07-18 16:34 <REP> d-------- C:\Program Files\CSO-DAX Compressor
2008-06-25 18:00 . 2008-06-25 18:00 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-06-24 22:20 . 2008-06-24 22:20 <REP> d-------- C:\Downloads
2008-06-24 22:19 . 2008-06-30 00:46 <REP> d-------- C:\Program Files\BitComet
2008-06-24 21:16 . 2008-06-24 21:16 <REP> dr------- C:\Users\Public\Videos
2008-06-24 21:16 . 2008-06-24 21:16 <REP> dr------- C:\Users\Public\Downloads
2008-06-24 21:05 . 2008-06-24 21:05 <REP> d-------- C:\Program Files\Microsoft Games
2008-06-24 21:05 . 2008-06-24 21:05 <REP> d-------- C:\PerfLogs
2008-06-24 08:53 . 2008-01-19 05:12 3,662,296 --a------ C:\Windows\System32\locale.nls
2008-06-24 08:52 . 2008-01-19 09:35 9,847,296 --a------ C:\Windows\System32\NlsData000a.dll
2008-06-24 08:51 . 2008-01-19 09:35 3,072,000 --a------ C:\Windows\System32\networkmap.dll
2008-06-24 08:50 . 2008-01-19 09:32 5,714,432 --a------ C:\Windows\System32\logon.scr
2008-06-24 08:49 . 2008-01-19 08:06 8,147,456 --a------ C:\Windows\System32\wmploc.DLL
2008-06-24 08:48 . 2008-01-19 09:36 704,512 --a------ C:\Windows\System32\SmiEngine.dll
2008-06-24 08:48 . 2008-01-19 09:36 357,888 --a------ C:\Windows\System32\wbemcomn.dll
2008-06-24 08:48 . 2008-01-19 09:36 218,624 --a------ C:\Windows\System32\wdscore.dll
2008-06-24 08:48 . 2008-01-19 09:36 139,264 --a------ C:\Windows\System32\SmiInstaller.dll
2008-06-24 08:48 . 2008-01-19 09:33 130,560 --a------ C:\Windows\System32\PkgMgr.exe
2008-06-24 08:47 . 2008-01-19 09:34 305,152 --a------ C:\Windows\System32\msdelta.dll
2008-06-24 08:47 . 2008-01-19 09:34 258,560 --a------ C:\Windows\System32\dpx.dll
2008-06-24 08:47 . 2008-01-19 09:34 246,784 --a------ C:\Windows\System32\drvstore.dll
2008-06-24 08:47 . 2008-01-19 09:35 35,328 --a------ C:\Windows\System32\mspatcha.dll
2008-06-23 13:42 . 1999-11-30 23:40 401,462 --a------ C:\Windows\System32\temp.002
2008-06-23 13:42 . 2001-04-09 03:03 17,784 --a------ C:\Windows\System32\drivers\NSynas32.sys
2008-06-23 01:05 . 2008-06-23 01:05 1,720,086 --a------ C:\Windows\System32\TmpA141356125
2008-06-23 01:03 . 2008-06-23 01:03 <REP> d-------- C:\Users\All Users\Pinnacle
2008-06-23 01:03 . 2008-06-23 01:03 <REP> d-------- C:\PROGRA~2\Pinnacle
2008-06-23 01:03 . 2003-07-31 19:28 147,425 --a------ C:\Windows\System32\SYNSOACC-Aide.chm
2008-06-23 01:03 . 2003-05-26 14:29 120,468 --a------ C:\Windows\System32\SYNSOACC-Hilfe.chm
2008-06-23 01:03 . 2003-05-26 14:29 114,279 --a------ C:\Windows\System32\SYNSOACC-Help.chm
2008-06-14 18:16 . 2008-06-23 13:43 <REP> d-------- C:\Program Files\Syncrosoft
2008-06-14 18:16 . 2004-10-09 14:45 757,760 --a------ C:\Windows\System32\SYNSOACC.dll
2008-06-14 18:16 . 1999-12-01 00:40 401,462 --a------ C:\Windows\System32\temp.001
2008-06-14 18:16 . 2004-05-10 13:58 147,456 --a------ C:\Windows\System32\SynsoLChk.dll
2008-06-14 17:23 . 2008-04-23 06:42 428,544 --a------ C:\Windows\System32\EncDec.dll
2008-06-14 17:23 . 2008-04-23 06:42 293,376 --a------ C:\Windows\System32\psisdecd.dll
2008-06-14 17:23 . 2008-04-23 06:41 218,624 --a------ C:\Windows\System32\psisrndr.ax
2008-06-14 17:23 . 2008-01-19 09:33 80,896 --a------ C:\Windows\System32\MSNP.ax
2008-06-14 17:23 . 2008-01-19 09:33 69,632 --a------ C:\Windows\System32\Mpeg2Data.ax
2008-06-14 17:23 . 2008-04-23 06:41 57,856 --a------ C:\Windows\System32\MSDvbNP.ax
2008-06-10 20:19 . 2008-06-23 01:05 <REP> d-------- C:\Program Files\DivX
2008-06-06 17:28 . 2008-06-06 17:28 <REP> d-------- C:\Program Files\Propellerhead
2008-06-06 13:45 . 2008-06-06 13:46 <REP> d-------- C:\Program Files\Image-Line
2008-06-06 00:04 . 2008-06-06 00:04 1,720,086 --a------ C:\Windows\System32\TmpA2998011
2008-06-04 15:22 . 2008-06-04 15:22 1,720,086 --a------ C:\Windows\System32\TmpA155714347
2008-06-02 17:57 . 2008-06-02 17:57 <REP> d-------- C:\Program Files\Free Audio Pack converter
2008-06-02 17:57 . 2005-02-24 12:10 2,084,864 --a------ C:\Windows\System32\AudDesign.dll
2008-06-02 17:57 . 2005-03-11 17:37 1,986,560 --a------ C:\Windows\System32\AudFile.dll
2008-06-02 17:57 . 2005-02-24 12:11 1,212,416 --a------ C:\Windows\System32\AudioInfos.dll
2008-06-02 17:57 . 2005-02-24 12:11 479,232 --a------ C:\Windows\System32\AudioVisu.dll
2008-06-02 17:57 . 2005-02-24 15:21 458,752 --a------ C:\Windows\System32\AudPlayer.dll
2008-06-02 17:57 . 2005-03-10 16:00 454,656 --a------ C:\Windows\System32\AudioRecord.dll
2008-06-02 17:57 . 2005-02-24 12:10 417,792 --a------ C:\Windows\System32\AudDisplay.dll
2008-06-02 17:57 . 2005-02-24 11:51 348,160 --a------ C:\Windows\System32\WMAFile.dll
2008-06-02 17:57 . 2003-08-07 15:01 237,568 --a------ C:\Windows\System32\lame_enc.dll
2008-06-02 17:57 . 2005-01-10 12:54 116,296 --a------ C:\Windows\System32\NCTWMAProfiles.prx
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-29 12:33 214,893,813 ----a-w C:\Program Files\dvd1983-scn_2.wmv
2008-07-21 19:11 --------- d-----w C:\Program Files\Sony
2008-07-10 05:07 --------- d-----w C:\Program Files\Windows Mail
2008-07-07 20:04 --------- d-----w C:\Program Files\eMule
2008-06-24 19:16 174 --sha-w C:\Program Files\desktop.ini
2008-06-24 19:06 --------- d-----w C:\Program Files\Windows Sidebar
2008-06-24 19:06 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-06-24 19:06 --------- d-----w C:\Program Files\Windows Journal
2008-06-24 19:06 --------- d-----w C:\Program Files\Windows Defender
2008-06-24 19:06 --------- d-----w C:\Program Files\Windows Collaboration
2008-06-24 19:06 --------- d-----w C:\Program Files\Windows Calendar
2008-06-24 13:40 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-06-24 13:40 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-06-19 17:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-05 15:44 --------- d-----w C:\PROGRA~2\Propellerhead Software
2008-05-27 05:21 1,582,592 ----a-w C:\Windows\System32\tquery.dll
2008-05-27 05:21 1,418,240 ----a-w C:\Windows\System32\mssrch.dll
2008-05-27 05:17 87,552 ----a-w C:\Windows\System32\SearchFilterHost.exe
2008-05-27 05:17 87,552 ----a-w C:\Windows\System32\mssitlb.dll
2008-05-27 05:17 754,176 ----a-w C:\Windows\System32\propsys.dll
2008-05-27 05:17 60,416 ----a-w C:\Windows\System32\msscntrs.dll
2008-05-27 05:17 6,103,040 ----a-w C:\Windows\System32\chtbrkr.dll
2008-05-27 05:17 32,768 ----a-w C:\Windows\System32\mssprxy.dll
2008-05-27 05:17 313,344 ----a-w C:\Windows\System32\thawbrkr.dll
2008-05-27 05:17 301,568 ----a-w C:\Windows\System32\srchadmin.dll
2008-05-27 05:17 194,560 ----a-w C:\Windows\System32\offfilt.dll
2008-05-27 05:17 143,872 ----a-w C:\Windows\System32\korwbrkr.dll
2008-05-27 05:17 1,671,680 ----a-w C:\Windows\System32\chsbrkr.dll
2008-05-22 22:20 200,704 ----a-w C:\Windows\System32\ssldivx.dll
2008-05-22 22:20 1,044,480 ----a-w C:\Windows\System32\libdivx.dll
2008-05-10 03:35 564,736 ----a-w C:\Windows\System32\emdmgmt.dll
2008-05-08 21:59 90,112 ----a-w C:\Windows\System32\wshext.dll
2008-05-08 21:59 430,080 ----a-w C:\Windows\System32\vbscript.dll
2008-05-08 21:59 180,224 ----a-w C:\Windows\System32\scrobj.dll
2008-05-08 21:59 172,032 ----a-w C:\Windows\System32\scrrun.dll
2008-05-08 21:59 155,648 ----a-w C:\Windows\System32\wscript.exe
2008-05-08 21:58 135,168 ----a-w C:\Windows\System32\cscript.exe
2008-04-29 03:54 181,760 ----a-w C:\Windows\System32\fsquirt.exe
2008-04-26 08:25 3,600,952 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-04-26 08:25 3,549,240 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-04-26 08:08 1,314,816 ----a-w C:\Windows\System32\quartz.dll
2008-04-25 16:22 206,088 ----a-w C:\Windows\System32\klogon.dll
2008-04-25 04:35 826,880 ----a-w C:\Windows\System32\wininet.dll
2008-04-12 03:32 784,896 ----a-w C:\Windows\System32\rpcrt4.dll
2008-04-05 03:34 15,360 ----a-w C:\Windows\System32\pacerprf.dll
2007-08-29 13:06 278,528 ----a-w C:\Program Files\Common Files\FDEUnInstaller.exe
2005-05-11 12:23 1 --sha-w C:\Windows\fidbox.dat
2007-09-03 18:26 22 --sha-w C:\Windows\SMINST\HPCD.sys
.
[code]<pre>
----a-w 325,204 2006-12-21 19:56:28 C:\SwSetup\SP34746\WCAMC\FW_210_Silence Install .exe
</pre>/code
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2008-04-25 18:21 201992]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 20:42 116040]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-30 10:47 289064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"ValidateAdminCodeSignatures"= 1 (0x1)
"FilterAdministratorToken"= 1 (0x1)
"EnableUIADesktopToggle"= 0 (0x0)
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\Windows\pss\Adobe Reader Synchronizer.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^AOL 9.0 Icône AOL.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AOL 9.0 Icône AOL.lnk
backup=C:\Windows\pss\AOL 9.0 Icône AOL.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Lancement rapide d'Adobe Reader.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Lancement rapide d'Adobe Reader.lnk
backup=C:\Windows\pss\Lancement rapide d'Adobe Reader.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Corrado^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Empty.pif]
path=C:\Users\Corrado\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Empty.pif
backup=C:\Windows\pss\Empty.pif.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
--a------ 2007-09-01 01:40 2321600 C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-06-27 19:03 152872 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
c:\Program Files\Common Files\Symantec Shared\ccApp.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
--a------ 2007-03-12 11:54 50696 C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-02-16 23:11 49152 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
--a------ 2007-03-01 13:18 472776 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
--a------ 2007-02-12 16:37 174872 C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IS CfgWiz]
c:\Program Files\Common Files\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\cltUIStb.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kaspersky Anti-Virus 2006]
C:\Program Files\Kaspersky Lab\AVP6\avp.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2007-10-18 12:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
C:\Program Files\MySpace\IM\MySpaceIM.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 15:57 153136 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-05-01 12:27 8429568 C:\Windows\System32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-05-01 12:27 81920 C:\Windows\System32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
--a------ 2007-05-01 12:27 86016 C:\Windows\System32\nvsvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl]
--a------ 2007-02-13 11:38 159744 C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
--a------ 2007-04-23 18:11 176128 C:\Program Files\HP\QuickPlay\QPService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings]
C:\Program Files\Search Settings\SearchSettings.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
--a------ 2006-10-09 22:43 729088 C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Speech Recognition]
--a------ 2008-01-19 09:33 49664 C:\Windows\Speech\Common\sapisvr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
--a------ 2007-08-31 16:46 1460560 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 02:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 2007-09-15 03:50 1021224 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPStart]
--a------ 2007-09-15 03:29 102400 C:\Program Files\Synaptics\SynTP\SynTPStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WAWifiMessage]
--a------ 2007-01-10 16:12 317128 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2008-01-19 09:38 1008184 C:\Program Files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
--a------ 2007-03-09 19:50 4390912 C:\Windows\RtHDVCpl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{394C533B-4CC1-4246-B362-3E4670DD45AE}"= C:\Program Files\HP\QuickPlay\QP.exe:Quick Play
"{A0D656E2-4E3F-4346-9AF0-1784F49B370E}"= C:\Program Files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{E9700DD2-050E-4830-8C93-832E14A18463}"= Disabled:UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{D344DB5F-C5F3-44E3-A3CC-55968796A2F2}"= Disabled:TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{6B3457A2-6EBB-402E-8C10-3A8FEDAFDA91}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{AAF1863A-C0EF-4B4D-B716-45FD18BED69D}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{A874C707-D8F1-4601-A008-E0C00DB77D0D}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{6AC94B1A-D3B4-4E13-B887-F4C3CDB35C46}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
"{C2E70F68-7DEF-460C-8322-DDF5D6B072B6}"= UDP:C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:AOL
"{4489134E-3826-435F-AC6D-85B159A39019}"= TCP:C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:AOL
"{B6B748F4-C964-4B81-A91E-93A5E67E6F16}"= UDP:C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:AOL
"{C114D0B1-1A79-45FC-B171-A8556EA69D0E}"= TCP:C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:AOL
"{9001CAE8-9CDC-46AC-9351-E6957EC93A7D}"= UDP:C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:AOL
"{56A83B31-B762-488A-B173-776A2894E1C5}"= TCP:C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:AOL
"{4EACD929-ECAD-43F2-A08D-827F2CE211D7}"= UDP:C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:AOL
"{FE4303F6-DA63-4D4F-BB5F-3414DA2240B8}"= TCP:C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:AOL
"TCP Query User{0BC85039-FC9D-45C2-8672-4E0C950D016B}C:\\users\\corrado\\desktop\\emule.exe"= UDP:C:\users\corrado\desktop\emule.exe:emule.exe
"UDP Query User{898B0540-2106-4CC4-8286-DB417B613548}C:\\users\\corrado\\desktop\\emule.exe"= TCP:C:\users\corrado\desktop\emule.exe:emule.exe
"{3F02AE31-21F3-42B4-985B-06E1F4CAD841}"= UDP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{2D76E154-FE39-4913-AE8A-FDE1080153FF}"= TCP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{FC4B22E4-670E-45A7-B876-57768C358036}"= UDP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{A13EE0FC-1F55-44F6-A339-302E65B7628D}"= TCP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{B5C1A022-BB1E-4F52-8166-DF8FEF1C5731}"= UDP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{0FD80F68-B039-4AA8-8CFE-B0B9094D373C}"= TCP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{0A3CAF7F-1B70-48F4-80A7-F03B102F069D}"= UDP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{678A1B50-FCBB-456F-838F-73E99E4904C9}"= TCP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"TCP Query User{37DE6567-6E6C-4834-9385-089823895476}C:\\users\\corrado\\desktop\\viviplay.exe"= UDP:C:\users\corrado\desktop\viviplay.exe:viviplay.exe
"UDP Query User{503B1753-A77F-46F2-AF89-8DCFF03C8E21}C:\\users\\corrado\\desktop\\viviplay.exe"= TCP:C:\users\corrado\desktop\viviplay.exe:viviplay.exe
"TCP Query User{AA44DFEA-6C40-4013-B3C0-D489BF795B9D}C:\\program files\\viviplay.exe"= UDP:C:\program files\viviplay.exe:ViViMediaPlay
"UDP Query User{561D3765-BF30-4AE7-9DEC-37366FC2B289}C:\\program files\\viviplay.exe"= TCP:C:\program files\viviplay.exe:ViViMediaPlay
"{FBE87BE3-68C1-4C6F-9422-FE07C4F9471A}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{E0F53F23-86F4-44AD-A727-669A619684B1}"= UDP:21023:BitComet 21023 TCP
"{067CA1AD-2084-453F-BD43-5A365D255602}"= TCP:21023:BitComet 21023 UDP
"TCP Query User{ED9CB2FE-15BD-47D3-8E26-05AFD236E2EB}C:\\program files\\bitcomet\\bitcomet.exe"= UDP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{FF41D150-7FFF-4A01-AF60-07329200804C}C:\\program files\\bitcomet\\bitcomet.exe"= TCP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"{94360218-BD7F-4761-95AC-9AFAAF2F0760}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{132B2614-2836-4AFD-A13A-D33D0EAE35FC}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{444EEED4-5FA7-4FC6-A9C6-513EE9DBABBD}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{9DF0DD96-BAC7-453D-AEDD-3F85DD0CFE9F}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{F52026A4-C52F-4121-B6D5-201030667FEE}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\Windows\system32\drivers\klbg.sys [2008-01-29 18:29]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys [2008-03-26 13:10]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-31 20:20:06
Windows 6.0.6001 Service Pack 1 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-07-31 20:21:54
ComboFix-quarantined-files.txt 2008-07-31 18:21:49
ComboFix2.txt 2008-07-29 18:32:52
Pre-Run: 5,233,184,768 octets libres
Post-Run: 5,175,967,744 octets libres
329 --- E O F --- 2008-07-30 00:24:50
ComboFix 08-07-31.01 - Corrado 2008-07-31 20:16:50.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.1359 [GMT 2:00]
Endroit: C:\Users\Corrado\Desktop\C-Fix.exe
Command switches used :: C:\Users\Corrado\Desktop\CFscript.txt
* Création d'un nouveau point de restauration
FILE ::
C:\Users\Corrado\AppData\Local\br5139on.exe
C:\Windows\MS32DLL.dll.vbs
C:\Windows\ShellNew\RakyatKelaparan.exe
C:\Windows\system32\kjshsvsr.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2008-06-28 to 2008-07-31 ))))))))))))))))))))))))))))))))))))
.
2008-07-31 20:14 . 2008-07-31 20:14 <REP> d-------- C:\ComboFix
2008-07-31 16:39 . 2008-07-31 16:39 <REP> d-------- C:\Program Files\iTunes
2008-07-31 16:39 . 2008-07-31 16:39 <REP> d-------- C:\Program Files\iPod
2008-07-31 16:39 . 2008-07-31 16:39 <REP> d-------- C:\Program Files\Bonjour
2008-07-31 16:38 . 2008-07-31 16:38 <REP> d-------- C:\Program Files\QuickTime
2008-07-31 16:37 . 2008-07-31 16:37 <REP> d-------- C:\Windows\LastGood
2008-07-31 16:37 . 2008-07-31 16:39 <REP> d-------- C:\Users\All Users\Apple Computer
2008-07-31 16:37 . 2008-07-31 16:39 <REP> d-------- C:\PROGRA~2\Apple Computer
2008-07-31 16:36 . 2008-07-31 16:36 <REP> d-------- C:\Program Files\Common Files\Apple
2008-07-31 16:31 . 2008-07-31 20:15 <REP> d-------- C:\327882R2FWJFW
2008-07-30 14:17 . 2008-07-30 14:17 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-30 14:17 . 2008-07-23 20:09 38,472 --a------ C:\Windows\System32\drivers\mbamswissarmy.sys
2008-07-30 14:17 . 2008-07-23 20:09 17,144 --a------ C:\Windows\System32\drivers\mbam.sys
2008-07-29 14:49 . 2008-07-30 16:09 <REP> d-------- C:\Toolbar SD
2008-07-29 04:27 . 2008-07-29 04:28 225,594,157 --a------ C:\Windows\MEMORY.DMP
2008-07-29 04:15 . 2008-07-29 04:25 96,559 --a------ C:\Windows\System32\drivers\klin.dat
2008-07-29 04:15 . 2008-07-29 04:25 87,855 --a------ C:\Windows\System32\drivers\klick.dat
2008-07-29 04:14 . 2008-07-31 18:43 <REP> d-------- C:\Users\All Users\Kaspersky Lab
2008-07-29 04:14 . 2008-07-29 04:14 <REP> d-------- C:\Program Files\Kaspersky Lab
2008-07-29 04:14 . 2008-07-31 18:43 <REP> d-------- C:\PROGRA~2\Kaspersky Lab
2008-07-29 04:14 . 2008-07-31 16:27 3,519,520 --ahs---- C:\Windows\System32\drivers\fidbox.dat
2008-07-29 04:14 . 2008-07-31 20:14 319,520 --ahs---- C:\Windows\System32\drivers\fidbox2.dat
2008-07-29 04:14 . 2008-07-31 16:27 29,624 --ahs---- C:\Windows\System32\drivers\fidbox.idx
2008-07-29 04:14 . 2008-07-31 20:14 2,116 --ahs---- C:\Windows\System32\drivers\fidbox2.idx
2008-07-29 03:56 . 2008-07-29 03:56 <REP> d-------- C:\Deckard
2008-07-29 02:30 . 2008-05-27 06:59 106,605 --a------ C:\Windows\System32\StructuredQuerySchema.bin
2008-07-29 02:30 . 2008-05-27 07:17 34,816 --a------ C:\Windows\System32\msscb.dll
2008-07-29 02:30 . 2008-05-27 06:59 18,904 --a------ C:\Windows\System32\StructuredQuerySchemaTrivial.bin
2008-07-29 02:30 . 2008-05-27 07:17 11,776 --a------ C:\Windows\System32\msshooks.dll
2008-07-23 17:24 . 2008-07-23 17:24 <REP> d-------- C:\Users\All Users\Malwarebytes
2008-07-23 17:24 . 2008-07-23 17:24 <REP> d-------- C:\PROGRA~2\Malwarebytes
2008-07-22 11:52 . 2008-07-22 11:52 <REP> d-------- C:\autorun.MSNFix
2008-07-22 11:46 . 2008-07-22 11:46 173 --a------ C:\curr_ver.tmp
2008-07-21 20:46 . 2008-07-22 03:35 <REP> d-------- C:\Windows\BDOSCAN8
2008-07-21 20:00 . 2008-07-29 02:37 <REP> d-------- C:\Windows\ShellNew
2008-07-11 11:46 . 2008-06-26 03:45 12,240,896 --a------ C:\Windows\System32\NlsLexicons0007.dll
2008-07-11 11:46 . 2008-06-26 03:45 2,644,480 --a------ C:\Windows\System32\NlsLexicons0009.dll
2008-07-11 11:46 . 2008-06-26 05:29 801,280 --a------ C:\Windows\System32\NaturalLanguage6.dll
2008-07-03 01:08 . 2008-07-03 01:08 <REP> d-------- C:\Program Files\Red Kawa
2008-07-02 18:09 . 2008-07-02 18:09 510 --a------ C:\Windows\WORDPAD.INI
2008-06-25 18:49 . 2008-07-18 16:34 <REP> d-------- C:\Program Files\CSO-DAX Compressor
2008-06-25 18:00 . 2008-06-25 18:00 0 --ah----- C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-06-24 22:20 . 2008-06-24 22:20 <REP> d-------- C:\Downloads
2008-06-24 22:19 . 2008-06-30 00:46 <REP> d-------- C:\Program Files\BitComet
2008-06-24 21:16 . 2008-06-24 21:16 <REP> dr------- C:\Users\Public\Videos
2008-06-24 21:16 . 2008-06-24 21:16 <REP> dr------- C:\Users\Public\Downloads
2008-06-24 21:05 . 2008-06-24 21:05 <REP> d-------- C:\Program Files\Microsoft Games
2008-06-24 21:05 . 2008-06-24 21:05 <REP> d-------- C:\PerfLogs
2008-06-24 08:53 . 2008-01-19 05:12 3,662,296 --a------ C:\Windows\System32\locale.nls
2008-06-24 08:52 . 2008-01-19 09:35 9,847,296 --a------ C:\Windows\System32\NlsData000a.dll
2008-06-24 08:51 . 2008-01-19 09:35 3,072,000 --a------ C:\Windows\System32\networkmap.dll
2008-06-24 08:50 . 2008-01-19 09:32 5,714,432 --a------ C:\Windows\System32\logon.scr
2008-06-24 08:49 . 2008-01-19 08:06 8,147,456 --a------ C:\Windows\System32\wmploc.DLL
2008-06-24 08:48 . 2008-01-19 09:36 704,512 --a------ C:\Windows\System32\SmiEngine.dll
2008-06-24 08:48 . 2008-01-19 09:36 357,888 --a------ C:\Windows\System32\wbemcomn.dll
2008-06-24 08:48 . 2008-01-19 09:36 218,624 --a------ C:\Windows\System32\wdscore.dll
2008-06-24 08:48 . 2008-01-19 09:36 139,264 --a------ C:\Windows\System32\SmiInstaller.dll
2008-06-24 08:48 . 2008-01-19 09:33 130,560 --a------ C:\Windows\System32\PkgMgr.exe
2008-06-24 08:47 . 2008-01-19 09:34 305,152 --a------ C:\Windows\System32\msdelta.dll
2008-06-24 08:47 . 2008-01-19 09:34 258,560 --a------ C:\Windows\System32\dpx.dll
2008-06-24 08:47 . 2008-01-19 09:34 246,784 --a------ C:\Windows\System32\drvstore.dll
2008-06-24 08:47 . 2008-01-19 09:35 35,328 --a------ C:\Windows\System32\mspatcha.dll
2008-06-23 13:42 . 1999-11-30 23:40 401,462 --a------ C:\Windows\System32\temp.002
2008-06-23 13:42 . 2001-04-09 03:03 17,784 --a------ C:\Windows\System32\drivers\NSynas32.sys
2008-06-23 01:05 . 2008-06-23 01:05 1,720,086 --a------ C:\Windows\System32\TmpA141356125
2008-06-23 01:03 . 2008-06-23 01:03 <REP> d-------- C:\Users\All Users\Pinnacle
2008-06-23 01:03 . 2008-06-23 01:03 <REP> d-------- C:\PROGRA~2\Pinnacle
2008-06-23 01:03 . 2003-07-31 19:28 147,425 --a------ C:\Windows\System32\SYNSOACC-Aide.chm
2008-06-23 01:03 . 2003-05-26 14:29 120,468 --a------ C:\Windows\System32\SYNSOACC-Hilfe.chm
2008-06-23 01:03 . 2003-05-26 14:29 114,279 --a------ C:\Windows\System32\SYNSOACC-Help.chm
2008-06-14 18:16 . 2008-06-23 13:43 <REP> d-------- C:\Program Files\Syncrosoft
2008-06-14 18:16 . 2004-10-09 14:45 757,760 --a------ C:\Windows\System32\SYNSOACC.dll
2008-06-14 18:16 . 1999-12-01 00:40 401,462 --a------ C:\Windows\System32\temp.001
2008-06-14 18:16 . 2004-05-10 13:58 147,456 --a------ C:\Windows\System32\SynsoLChk.dll
2008-06-14 17:23 . 2008-04-23 06:42 428,544 --a------ C:\Windows\System32\EncDec.dll
2008-06-14 17:23 . 2008-04-23 06:42 293,376 --a------ C:\Windows\System32\psisdecd.dll
2008-06-14 17:23 . 2008-04-23 06:41 218,624 --a------ C:\Windows\System32\psisrndr.ax
2008-06-14 17:23 . 2008-01-19 09:33 80,896 --a------ C:\Windows\System32\MSNP.ax
2008-06-14 17:23 . 2008-01-19 09:33 69,632 --a------ C:\Windows\System32\Mpeg2Data.ax
2008-06-14 17:23 . 2008-04-23 06:41 57,856 --a------ C:\Windows\System32\MSDvbNP.ax
2008-06-10 20:19 . 2008-06-23 01:05 <REP> d-------- C:\Program Files\DivX
2008-06-06 17:28 . 2008-06-06 17:28 <REP> d-------- C:\Program Files\Propellerhead
2008-06-06 13:45 . 2008-06-06 13:46 <REP> d-------- C:\Program Files\Image-Line
2008-06-06 00:04 . 2008-06-06 00:04 1,720,086 --a------ C:\Windows\System32\TmpA2998011
2008-06-04 15:22 . 2008-06-04 15:22 1,720,086 --a------ C:\Windows\System32\TmpA155714347
2008-06-02 17:57 . 2008-06-02 17:57 <REP> d-------- C:\Program Files\Free Audio Pack converter
2008-06-02 17:57 . 2005-02-24 12:10 2,084,864 --a------ C:\Windows\System32\AudDesign.dll
2008-06-02 17:57 . 2005-03-11 17:37 1,986,560 --a------ C:\Windows\System32\AudFile.dll
2008-06-02 17:57 . 2005-02-24 12:11 1,212,416 --a------ C:\Windows\System32\AudioInfos.dll
2008-06-02 17:57 . 2005-02-24 12:11 479,232 --a------ C:\Windows\System32\AudioVisu.dll
2008-06-02 17:57 . 2005-02-24 15:21 458,752 --a------ C:\Windows\System32\AudPlayer.dll
2008-06-02 17:57 . 2005-03-10 16:00 454,656 --a------ C:\Windows\System32\AudioRecord.dll
2008-06-02 17:57 . 2005-02-24 12:10 417,792 --a------ C:\Windows\System32\AudDisplay.dll
2008-06-02 17:57 . 2005-02-24 11:51 348,160 --a------ C:\Windows\System32\WMAFile.dll
2008-06-02 17:57 . 2003-08-07 15:01 237,568 --a------ C:\Windows\System32\lame_enc.dll
2008-06-02 17:57 . 2005-01-10 12:54 116,296 --a------ C:\Windows\System32\NCTWMAProfiles.prx
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-29 12:33 214,893,813 ----a-w C:\Program Files\dvd1983-scn_2.wmv
2008-07-21 19:11 --------- d-----w C:\Program Files\Sony
2008-07-10 05:07 --------- d-----w C:\Program Files\Windows Mail
2008-07-07 20:04 --------- d-----w C:\Program Files\eMule
2008-06-24 19:16 174 --sha-w C:\Program Files\desktop.ini
2008-06-24 19:06 --------- d-----w C:\Program Files\Windows Sidebar
2008-06-24 19:06 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-06-24 19:06 --------- d-----w C:\Program Files\Windows Journal
2008-06-24 19:06 --------- d-----w C:\Program Files\Windows Defender
2008-06-24 19:06 --------- d-----w C:\Program Files\Windows Collaboration
2008-06-24 19:06 --------- d-----w C:\Program Files\Windows Calendar
2008-06-24 13:40 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-06-24 13:40 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-06-19 17:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-05 15:44 --------- d-----w C:\PROGRA~2\Propellerhead Software
2008-05-27 05:21 1,582,592 ----a-w C:\Windows\System32\tquery.dll
2008-05-27 05:21 1,418,240 ----a-w C:\Windows\System32\mssrch.dll
2008-05-27 05:17 87,552 ----a-w C:\Windows\System32\SearchFilterHost.exe
2008-05-27 05:17 87,552 ----a-w C:\Windows\System32\mssitlb.dll
2008-05-27 05:17 754,176 ----a-w C:\Windows\System32\propsys.dll
2008-05-27 05:17 60,416 ----a-w C:\Windows\System32\msscntrs.dll
2008-05-27 05:17 6,103,040 ----a-w C:\Windows\System32\chtbrkr.dll
2008-05-27 05:17 32,768 ----a-w C:\Windows\System32\mssprxy.dll
2008-05-27 05:17 313,344 ----a-w C:\Windows\System32\thawbrkr.dll
2008-05-27 05:17 301,568 ----a-w C:\Windows\System32\srchadmin.dll
2008-05-27 05:17 194,560 ----a-w C:\Windows\System32\offfilt.dll
2008-05-27 05:17 143,872 ----a-w C:\Windows\System32\korwbrkr.dll
2008-05-27 05:17 1,671,680 ----a-w C:\Windows\System32\chsbrkr.dll
2008-05-22 22:20 200,704 ----a-w C:\Windows\System32\ssldivx.dll
2008-05-22 22:20 1,044,480 ----a-w C:\Windows\System32\libdivx.dll
2008-05-10 03:35 564,736 ----a-w C:\Windows\System32\emdmgmt.dll
2008-05-08 21:59 90,112 ----a-w C:\Windows\System32\wshext.dll
2008-05-08 21:59 430,080 ----a-w C:\Windows\System32\vbscript.dll
2008-05-08 21:59 180,224 ----a-w C:\Windows\System32\scrobj.dll
2008-05-08 21:59 172,032 ----a-w C:\Windows\System32\scrrun.dll
2008-05-08 21:59 155,648 ----a-w C:\Windows\System32\wscript.exe
2008-05-08 21:58 135,168 ----a-w C:\Windows\System32\cscript.exe
2008-04-29 03:54 181,760 ----a-w C:\Windows\System32\fsquirt.exe
2008-04-26 08:25 3,600,952 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-04-26 08:25 3,549,240 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-04-26 08:08 1,314,816 ----a-w C:\Windows\System32\quartz.dll
2008-04-25 16:22 206,088 ----a-w C:\Windows\System32\klogon.dll
2008-04-25 04:35 826,880 ----a-w C:\Windows\System32\wininet.dll
2008-04-12 03:32 784,896 ----a-w C:\Windows\System32\rpcrt4.dll
2008-04-05 03:34 15,360 ----a-w C:\Windows\System32\pacerprf.dll
2007-08-29 13:06 278,528 ----a-w C:\Program Files\Common Files\FDEUnInstaller.exe
2005-05-11 12:23 1 --sha-w C:\Windows\fidbox.dat
2007-09-03 18:26 22 --sha-w C:\Windows\SMINST\HPCD.sys
.
[code]<pre>
----a-w 325,204 2006-12-21 19:56:28 C:\SwSetup\SP34746\WCAMC\FW_210_Silence Install .exe
</pre>/code
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2008-04-25 18:21 201992]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 20:42 116040]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-30 10:47 289064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"ValidateAdminCodeSignatures"= 1 (0x1)
"FilterAdministratorToken"= 1 (0x1)
"EnableUIADesktopToggle"= 0 (0x0)
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\Windows\pss\Adobe Reader Synchronizer.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^AOL 9.0 Icône AOL.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AOL 9.0 Icône AOL.lnk
backup=C:\Windows\pss\AOL 9.0 Icône AOL.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Lancement rapide d'Adobe Reader.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Lancement rapide d'Adobe Reader.lnk
backup=C:\Windows\pss\Lancement rapide d'Adobe Reader.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Corrado^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Empty.pif]
path=C:\Users\Corrado\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Empty.pif
backup=C:\Windows\pss\Empty.pif.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
--a------ 2007-09-01 01:40 2321600 C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-06-27 19:03 152872 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
c:\Program Files\Common Files\Symantec Shared\ccApp.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
--a------ 2007-03-12 11:54 50696 C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-02-16 23:11 49152 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
--a------ 2007-03-01 13:18 472776 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
--a------ 2007-02-12 16:37 174872 C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IS CfgWiz]
c:\Program Files\Common Files\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\cltUIStb.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kaspersky Anti-Virus 2006]
C:\Program Files\Kaspersky Lab\AVP6\avp.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2007-10-18 12:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
C:\Program Files\MySpace\IM\MySpaceIM.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 15:57 153136 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-05-01 12:27 8429568 C:\Windows\System32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-05-01 12:27 81920 C:\Windows\System32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
--a------ 2007-05-01 12:27 86016 C:\Windows\System32\nvsvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl]
--a------ 2007-02-13 11:38 159744 C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
--a------ 2007-04-23 18:11 176128 C:\Program Files\HP\QuickPlay\QPService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings]
C:\Program Files\Search Settings\SearchSettings.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
--a------ 2006-10-09 22:43 729088 C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Speech Recognition]
--a------ 2008-01-19 09:33 49664 C:\Windows\Speech\Common\sapisvr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
--a------ 2007-08-31 16:46 1460560 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 02:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 2007-09-15 03:50 1021224 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPStart]
--a------ 2007-09-15 03:29 102400 C:\Program Files\Synaptics\SynTP\SynTPStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WAWifiMessage]
--a------ 2007-01-10 16:12 317128 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2008-01-19 09:38 1008184 C:\Program Files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
--a------ 2007-03-09 19:50 4390912 C:\Windows\RtHDVCpl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{394C533B-4CC1-4246-B362-3E4670DD45AE}"= C:\Program Files\HP\QuickPlay\QP.exe:Quick Play
"{A0D656E2-4E3F-4346-9AF0-1784F49B370E}"= C:\Program Files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{E9700DD2-050E-4830-8C93-832E14A18463}"= Disabled:UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{D344DB5F-C5F3-44E3-A3CC-55968796A2F2}"= Disabled:TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{6B3457A2-6EBB-402E-8C10-3A8FEDAFDA91}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{AAF1863A-C0EF-4B4D-B716-45FD18BED69D}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{A874C707-D8F1-4601-A008-E0C00DB77D0D}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{6AC94B1A-D3B4-4E13-B887-F4C3CDB35C46}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
"{C2E70F68-7DEF-460C-8322-DDF5D6B072B6}"= UDP:C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:AOL
"{4489134E-3826-435F-AC6D-85B159A39019}"= TCP:C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:AOL
"{B6B748F4-C964-4B81-A91E-93A5E67E6F16}"= UDP:C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:AOL
"{C114D0B1-1A79-45FC-B171-A8556EA69D0E}"= TCP:C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:AOL
"{9001CAE8-9CDC-46AC-9351-E6957EC93A7D}"= UDP:C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:AOL
"{56A83B31-B762-488A-B173-776A2894E1C5}"= TCP:C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:AOL
"{4EACD929-ECAD-43F2-A08D-827F2CE211D7}"= UDP:C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:AOL
"{FE4303F6-DA63-4D4F-BB5F-3414DA2240B8}"= TCP:C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:AOL
"TCP Query User{0BC85039-FC9D-45C2-8672-4E0C950D016B}C:\\users\\corrado\\desktop\\emule.exe"= UDP:C:\users\corrado\desktop\emule.exe:emule.exe
"UDP Query User{898B0540-2106-4CC4-8286-DB417B613548}C:\\users\\corrado\\desktop\\emule.exe"= TCP:C:\users\corrado\desktop\emule.exe:emule.exe
"{3F02AE31-21F3-42B4-985B-06E1F4CAD841}"= UDP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{2D76E154-FE39-4913-AE8A-FDE1080153FF}"= TCP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{FC4B22E4-670E-45A7-B876-57768C358036}"= UDP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{A13EE0FC-1F55-44F6-A339-302E65B7628D}"= TCP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{B5C1A022-BB1E-4F52-8166-DF8FEF1C5731}"= UDP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{0FD80F68-B039-4AA8-8CFE-B0B9094D373C}"= TCP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{0A3CAF7F-1B70-48F4-80A7-F03B102F069D}"= UDP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{678A1B50-FCBB-456F-838F-73E99E4904C9}"= TCP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"TCP Query User{37DE6567-6E6C-4834-9385-089823895476}C:\\users\\corrado\\desktop\\viviplay.exe"= UDP:C:\users\corrado\desktop\viviplay.exe:viviplay.exe
"UDP Query User{503B1753-A77F-46F2-AF89-8DCFF03C8E21}C:\\users\\corrado\\desktop\\viviplay.exe"= TCP:C:\users\corrado\desktop\viviplay.exe:viviplay.exe
"TCP Query User{AA44DFEA-6C40-4013-B3C0-D489BF795B9D}C:\\program files\\viviplay.exe"= UDP:C:\program files\viviplay.exe:ViViMediaPlay
"UDP Query User{561D3765-BF30-4AE7-9DEC-37366FC2B289}C:\\program files\\viviplay.exe"= TCP:C:\program files\viviplay.exe:ViViMediaPlay
"{FBE87BE3-68C1-4C6F-9422-FE07C4F9471A}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{E0F53F23-86F4-44AD-A727-669A619684B1}"= UDP:21023:BitComet 21023 TCP
"{067CA1AD-2084-453F-BD43-5A365D255602}"= TCP:21023:BitComet 21023 UDP
"TCP Query User{ED9CB2FE-15BD-47D3-8E26-05AFD236E2EB}C:\\program files\\bitcomet\\bitcomet.exe"= UDP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{FF41D150-7FFF-4A01-AF60-07329200804C}C:\\program files\\bitcomet\\bitcomet.exe"= TCP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"{94360218-BD7F-4761-95AC-9AFAAF2F0760}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{132B2614-2836-4AFD-A13A-D33D0EAE35FC}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{444EEED4-5FA7-4FC6-A9C6-513EE9DBABBD}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{9DF0DD96-BAC7-453D-AEDD-3F85DD0CFE9F}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{F52026A4-C52F-4121-B6D5-201030667FEE}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\Windows\system32\drivers\klbg.sys [2008-01-29 18:29]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys [2008-03-26 13:10]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-31 20:20:06
Windows 6.0.6001 Service Pack 1 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-07-31 20:21:54
ComboFix-quarantined-files.txt 2008-07-31 18:21:49
ComboFix2.txt 2008-07-29 18:32:52
Pre-Run: 5,233,184,768 octets libres
Post-Run: 5,175,967,744 octets libres
329 --- E O F --- 2008-07-30 00:24:50
VOICI DEUX RAPPORT. UN DE COMBOFIX ET LAUTRE DE VIRUS TOTAL
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.7.29.1 2008.08.01 -
AntiVir 7.8.1.15 2008.08.01 -
Authentium 5.1.0.4 2008.07.31 -
Avast 4.8.1195.0 2008.08.01 -
AVG 8.0.0.156 2008.08.01 -
BitDefender 7.2 2008.08.01 -
CAT-QuickHeal 9.50 2008.08.01 -
ClamAV 0.93.1 2008.08.01 -
DrWeb 4.44.0.09170 2008.08.01 -
eSafe 7.0.17.0 2008.07.29 Suspicious File
eTrust-Vet 31.6.6001 2008.08.01 -
Ewido 4.0 2008.08.01 -
F-Prot 4.4.4.56 2008.08.01 -
F-Secure 7.60.13501.0 2008.08.01 -
Fortinet 3.14.0.0 2008.08.01 -
GData 2.0.7306.1023 2008.08.01 -
Ikarus T3.1.1.34.0 2008.08.01 -
K7AntiVirus 7.10.402 2008.08.01 -
Kaspersky 7.0.0.125 2008.08.01 -
McAfee 5352 2008.08.01 -
Microsoft 1.3704 2008.07.28 -
NOD32v2 3317 2008.08.01 -
Norman 5.80.02 2008.08.01 -
Panda 9.0.0.4 2008.08.01 -
PCTools 4.4.2.0 2008.08.01 -
Prevx1 V2 2008.08.01 Suspicious
Rising 20.55.42.00 2008.08.01 -
Sophos 4.31.0 2008.08.01 -
Sunbelt 3.1.1537.1 2008.08.01 -
Symantec 10 2008.08.01 -
TheHacker 6.2.96.391 2008.07.31 Trojan/Downloader.IstBar.gen
TrendMicro 8.700.0.1004 2008.08.01 -
VBA32 3.12.8.2 2008.08.01 -
ViRobot 2008.8.1.1321 2008.08.01 -
VirusBuster 4.5.11.0 2008.08.01 -
Webwasher-Gateway 6.6.2 2008.08.01 -
Information additionnelle
File size: 325204 bytes
MD5...: d957b2c08edcf5cf79ce0a3d1360be14
SHA1..: 16c04bb034fc70b281aaef2fdcd0ff282ddffa5b
SHA256: 04477b3bfdf36f72da90e6f2fa43cec2260852ebd34dc366e3754263239eb8a0
SHA512: 4d4b0af56a16e0ec24151f56120f4858fc522f9e846385cc9eb96737f673bc15
b8c9f45b1469cad34934f91e4d302fd21f250ee557b2c01e8073f755ef83dec0
PEiD..: UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x421be0
timedatestamp.....: 0x41ceda00 (Sun Dec 26 15:34:24 2004)
machinetype.......: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x16000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x17000 0xb000 0xae00 7.90 35849369911491f8267e2981b59805f6
.rsrc 0x22000 0x2000 0x1c00 4.77 9a761c627f38d5bd79eba036284f4afe
( 8 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, ExitProcess
> ADVAPI32.DLL: RegCloseKey
> COMCTL32.DLL: -
> COMDLG32.DLL: GetOpenFileNameA
> GDI32.DLL: DeleteObject
> OLE32.DLL: OleInitialize
> SHELL32.DLL: SHGetMalloc
> USER32.DLL: SetMenu
( 0 exports )
ThreatExpert info: https://www.symantec.com?md5=d957b2c08edcf5cf79ce0a3d1360be14
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=DA7D742754E875C7F6B7041BFAB03900E16C4957
packers (Kaspersky): UPX
packers (F-Prot): UPX, RAR
RAPPORT COMBOFIX
ComboFix 08-07-31.01 - Corrado 2008-08-01 20:52:15.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.1300 [GMT 2:00]
Endroit: C:\Users\Corrado\Desktop\C-Fix.exe
Command switches used :: C:\Users\Corrado\Desktop\CFScript.txt
* Création d'un nouveau point de restauration
FILE ::
C:\Program Files\Search Settings\SearchSettings.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2008-07-01 to 2008-08-01 ))))))))))))))))))))))))))))))))))))
.
2008-07-31 20:14 . 2008-07-31 20:14 <REP> d-------- C:\ComboFix
2008-07-31 16:39 . 2008-07-31 16:39 <REP> d-------- C:\Program Files\iTunes
2008-07-31 16:39 . 2008-07-31 16:39 <REP> d-------- C:\Program Files\iPod
2008-07-31 16:39 . 2008-07-31 16:39 <REP> d-------- C:\Program Files\Bonjour
2008-07-31 16:38 . 2008-07-31 16:38 <REP> d-------- C:\Program Files\QuickTime
2008-07-31 16:37 . 2008-07-31 16:37 <REP> d-------- C:\Windows\LastGood
2008-07-31 16:37 . 2008-07-31 16:39 <REP> d-------- C:\Users\All Users\Apple Computer
2008-07-31 16:37 . 2008-07-31 16:39 <REP> d-------- C:\PROGRA~2\Apple Computer
2008-07-31 16:36 . 2008-07-31 16:36 <REP> d-------- C:\Program Files\Common Files\Apple
2008-07-30 14:17 . 2008-07-30 14:17 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-30 14:17 . 2008-07-23 20:09 38,472 --a------ C:\Windows\System32\drivers\mbamswissarmy.sys
2008-07-30 14:17 . 2008-07-23 20:09 17,144 --a------ C:\Windows\System32\drivers\mbam.sys
2008-07-29 14:49 . 2008-07-30 16:09 <REP> d-------- C:\Toolbar SD
2008-07-29 04:27 . 2008-07-29 04:28 225,594,157 --a------ C:\Windows\MEMORY.DMP
2008-07-29 04:15 . 2008-07-29 04:25 96,559 --a------ C:\Windows\System32\drivers\klin.dat
2008-07-29 04:15 . 2008-07-29 04:25 87,855 --a------ C:\Windows\System32\drivers\klick.dat
2008-07-29 04:14 . 2008-07-31 20:31 <REP> d-------- C:\Users\All Users\Kaspersky Lab
2008-07-29 04:14 . 2008-07-29 04:14 <REP> d-------- C:\Program Files\Kaspersky Lab
2008-07-29 04:14 . 2008-07-31 20:31 <REP> d-------- C:\PROGRA~2\Kaspersky Lab
2008-07-29 04:14 . 2008-07-31 16:27 3,519,520 --ahs---- C:\Windows\System32\drivers\fidbox.dat
2008-07-29 04:14 . 2008-08-01 01:59 344,096 --ahs---- C:\Windows\System32\drivers\fidbox2.dat
2008-07-29 04:14 . 2008-07-31 16:27 29,624 --ahs---- C:\Windows\System32\drivers\fidbox.idx
2008-07-29 04:14 . 2008-08-01 01:59 2,256 --ahs---- C:\Windows\System32\drivers\fidbox2.idx
2008-07-29 03:56 . 2008-07-29 03:56 <REP> d-------- C:\Deckard
2008-07-29 02:30 . 2008-05-27 06:59 106,605 --a------ C:\Windows\System32\StructuredQuerySchema.bin
2008-07-29 02:30 . 2008-05-27 07:17 34,816 --a------ C:\Windows\System32\msscb.dll
2008-07-29 02:30 . 2008-05-27 06:59 18,904 --a------ C:\Windows\System32\StructuredQuerySchemaTrivial.bin
2008-07-29 02:30 . 2008-05-27 07:17 11,776 --a------ C:\Windows\System32\msshooks.dll
2008-07-23 17:24 . 2008-07-23 17:24 <REP> d-------- C:\Users\All Users\Malwarebytes
2008-07-23 17:24 . 2008-07-23 17:24 <REP> d-------- C:\PROGRA~2\Malwarebytes
2008-07-22 11:52 . 2008-07-22 11:52 <REP> d-------- C:\autorun.MSNFix
2008-07-22 11:46 . 2008-07-22 11:46 173 --a------ C:\curr_ver.tmp
2008-07-21 20:46 . 2008-07-22 03:35 <REP> d-------- C:\Windows\BDOSCAN8
2008-07-21 20:00 . 2008-07-29 02:37 <REP> d-------- C:\Windows\ShellNew
2008-07-11 11:46 . 2008-06-26 03:45 12,240,896 --a------ C:\Windows\System32\NlsLexicons0007.dll
2008-07-11 11:46 . 2008-06-26 03:45 2,644,480 --a------ C:\Windows\System32\NlsLexicons0009.dll
2008-07-11 11:46 . 2008-06-26 05:29 801,280 --a------ C:\Windows\System32\NaturalLanguage6.dll
2008-07-03 01:08 . 2008-07-03 01:08 <REP> d-------- C:\Program Files\Red Kawa
2008-07-02 18:09 . 2008-07-02 18:09 510 --a------ C:\Windows\WORDPAD.INI
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-21 19:11 --------- d-----w C:\Program Files\Sony
2008-07-18 14:34 --------- d-----w C:\Program Files\CSO-DAX Compressor
2008-07-10 05:07 --------- d-----w C:\Program Files\Windows Mail
2008-07-07 20:04 --------- d-----w C:\Program Files\eMule
2008-06-29 22:46 --------- d-----w C:\Program Files\BitComet
2008-06-25 16:00 0 ---ha-w C:\Windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-06-24 19:16 174 --sha-w C:\Program Files\desktop.ini
2008-06-24 19:06 --------- d-----w C:\Program Files\Windows Sidebar
2008-06-24 19:06 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-06-24 19:06 --------- d-----w C:\Program Files\Windows Journal
2008-06-24 19:06 --------- d-----w C:\Program Files\Windows Defender
2008-06-24 19:06 --------- d-----w C:\Program Files\Windows Collaboration
2008-06-24 19:06 --------- d-----w C:\Program Files\Windows Calendar
2008-06-24 19:05 --------- d-----w C:\Program Files\Microsoft Games
2008-06-24 13:40 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-06-24 13:40 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-06-23 11:43 --------- d-----w C:\Program Files\Syncrosoft
2008-06-22 23:05 --------- d-----w C:\Program Files\DivX
2008-06-22 23:03 --------- d-----w C:\PROGRA~2\Pinnacle
2008-06-19 17:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-06 15:28 --------- d-----w C:\Program Files\Propellerhead
2008-06-06 11:46 --------- d-----w C:\Program Files\Image-Line
2008-06-05 15:44 --------- d-----w C:\PROGRA~2\Propellerhead Software
2008-06-02 15:57 --------- d-----w C:\Program Files\Free Audio Pack converter
2008-05-27 05:21 1,582,592 ----a-w C:\Windows\System32\tquery.dll
2008-05-27 05:21 1,418,240 ----a-w C:\Windows\System32\mssrch.dll
2008-05-27 05:17 87,552 ----a-w C:\Windows\System32\SearchFilterHost.exe
2008-05-27 05:17 87,552 ----a-w C:\Windows\System32\mssitlb.dll
2008-05-27 05:17 754,176 ----a-w C:\Windows\System32\propsys.dll
2008-05-27 05:17 60,416 ----a-w C:\Windows\System32\msscntrs.dll
2008-05-27 05:17 6,103,040 ----a-w C:\Windows\System32\chtbrkr.dll
2008-05-27 05:17 32,768 ----a-w C:\Windows\System32\mssprxy.dll
2008-05-27 05:17 313,344 ----a-w C:\Windows\System32\thawbrkr.dll
2008-05-27 05:17 301,568 ----a-w C:\Windows\System32\srchadmin.dll
2008-05-27 05:17 194,560 ----a-w C:\Windows\System32\offfilt.dll
2008-05-27 05:17 143,872 ----a-w C:\Windows\System32\korwbrkr.dll
2008-05-27 05:17 1,671,680 ----a-w C:\Windows\System32\chsbrkr.dll
2008-05-22 22:20 200,704 ----a-w C:\Windows\System32\ssldivx.dll
2008-05-22 22:20 1,044,480 ----a-w C:\Windows\System32\libdivx.dll
2008-05-10 03:35 564,736 ----a-w C:\Windows\System32\emdmgmt.dll
2008-05-08 21:59 90,112 ----a-w C:\Windows\System32\wshext.dll
2008-05-08 21:59 430,080 ----a-w C:\Windows\System32\vbscript.dll
2008-05-08 21:59 180,224 ----a-w C:\Windows\System32\scrobj.dll
2008-05-08 21:59 172,032 ----a-w C:\Windows\System32\scrrun.dll
2008-05-08 21:59 155,648 ----a-w C:\Windows\System32\wscript.exe
2008-05-08 21:58 135,168 ----a-w C:\Windows\System32\cscript.exe
2007-08-29 13:06 278,528 ----a-w C:\Program Files\Common Files\FDEUnInstaller.exe
2005-05-11 12:23 1 --sha-w C:\Windows\fidbox.dat
2007-09-03 18:26 22 --sha-w C:\Windows\SMINST\HPCD.sys
.
[code]<pre>
----a-w 325,204 2006-12-21 19:56:28 C:\SwSetup\SP34746\WCAMC\FW_210_Silence Install .exe
</pre>/code
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\327882R2FWJFW ----
C:\327882R2FWJFW\
((((((((((((((((((((((((((((( snapshot@2008-07-31_20.21.13.46 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2008-04-25 18:21 201992]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"ValidateAdminCodeSignatures"= 1 (0x1)
"FilterAdministratorToken"= 1 (0x1)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\Windows\pss\Adobe Reader Synchronizer.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^AOL 9.0 Icône AOL.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AOL 9.0 Icône AOL.lnk
backup=C:\Windows\pss\AOL 9.0 Icône AOL.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Lancement rapide d'Adobe Reader.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Lancement rapide d'Adobe Reader.lnk
backup=C:\Windows\pss\Lancement rapide d'Adobe Reader.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Corrado^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Empty.pif]
path=C:\Users\Corrado\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Empty.pif
backup=C:\Windows\pss\Empty.pif.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
--a------ 2007-09-01 01:40 2321600 C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-06-27 19:03 152872 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
c:\Program Files\Common Files\Symantec Shared\ccApp.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
--a------ 2007-03-12 11:54 50696 C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-02-16 23:11 49152 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
--a------ 2007-03-01 13:18 472776 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
--a------ 2007-02-12 16:37 174872 C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IS CfgWiz]
c:\Program Files\Common Files\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\cltUIStb.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kaspersky Anti-Virus 2006]
C:\Program Files\Kaspersky Lab\AVP6\avp.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2007-10-18 12:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
C:\Program Files\MySpace\IM\MySpaceIM.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 15:57 153136 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-05-01 12:27 8429568 C:\Windows\System32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-05-01 12:27 81920 C:\Windows\System32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
--a------ 2007-05-01 12:27 86016 C:\Windows\System32\nvsvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl]
--a------ 2007-02-13 11:38 159744 C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
--a------ 2007-04-23 18:11 176128 C:\Program Files\HP\QuickPlay\QPService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
--a------ 2006-10-09 22:43 729088 C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Speech Recognition]
--a------ 2008-01-19 09:33 49664 C:\Windows\Speech\Common\sapisvr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
--a------ 2007-08-31 16:46 1460560 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 02:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 2007-09-15 03:50 1021224 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPStart]
--a------ 2007-09-15 03:29 102400 C:\Program Files\Synaptics\SynTP\SynTPStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WAWifiMessage]
--a------ 2007-01-10 16:12 317128 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2008-01-19 09:38 1008184 C:\Program Files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
--a------ 2007-03-09 19:50 4390912 C:\Windows\RtHDVCpl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{394C533B-4CC1-4246-B362-3E4670DD45AE}"= C:\Program Files\HP\QuickPlay\QP.exe:Quick Play
"{A0D656E2-4E3F-4346-9AF0-1784F49B370E}"= C:\Program Files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{E9700DD2-050E-4830-8C93-832E14A18463}"= Disabled:UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{D344DB5F-C5F3-44E3-A3CC-55968796A2F2}"= Disabled:TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{6B3457A2-6EBB-402E-8C10-3A8FEDAFDA91}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{AAF1863A-C0EF-4B4D-B716-45FD18BED69D}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{A874C707-D8F1-4601-A008-E0C00DB77D0D}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{6AC94B1A-D3B4-4E13-B887-F4C3CDB35C46}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
"{C2E70F68-7DEF-460C-8322-DDF5D6B072B6}"= UDP:C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:AOL
"{4489134E-3826-435F-AC6D-85B159A39019}"= TCP:C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:AOL
"{B6B748F4-C964-4B81-A91E-93A5E67E6F16}"= UDP:C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:AOL
"{C114D0B1-1A79-45FC-B171-A8556EA69D0E}"= TCP:C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:AOL
"{9001CAE8-9CDC-46AC-9351-E6957EC93A7D}"= UDP:C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:AOL
"{56A83B31-B762-488A-B173-776A2894E1C5}"= TCP:C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:AOL
"{4EACD929-ECAD-43F2-A08D-827F2CE211D7}"= UDP:C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:AOL
"{FE4303F6-DA63-4D4F-BB5F-3414DA2240B8}"= TCP:C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:AOL
"TCP Query User{0BC85039-FC9D-45C2-8672-4E0C950D016B}C:\\users\\corrado\\desktop\\emule.exe"= UDP:C:\users\corrado\desktop\emule.exe:emule.exe
"UDP Query User{898B0540-2106-4CC4-8286-DB417B613548}C:\\users\\corrado\\desktop\\emule.exe"= TCP:C:\users\corrado\desktop\emule.exe:emule.exe
"{3F02AE31-21F3-42B4-985B-06E1F4CAD841}"= UDP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{2D76E154-FE39-4913-AE8A-FDE1080153FF}"= TCP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{FC4B22E4-670E-45A7-B876-57768C358036}"= UDP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{A13EE0FC-1F55-44F6-A339-302E65B7628D}"= TCP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{B5C1A022-BB1E-4F52-8166-DF8FEF1C5731}"= UDP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{0FD80F68-B039-4AA8-8CFE-B0B9094D373C}"= TCP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{0A3CAF7F-1B70-48F4-80A7-F03B102F069D}"= UDP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{678A1B50-FCBB-456F-838F-73E99E4904C9}"= TCP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"TCP Query User{37DE6567-6E6C-4834-9385-089823895476}C:\\users\\corrado\\desktop\\viviplay.exe"= UDP:C:\users\corrado\desktop\viviplay.exe:viviplay.exe
"UDP Query User{503B1753-A77F-46F2-AF89-8DCFF03C8E21}C:\\users\\corrado\\desktop\\viviplay.exe"= TCP:C:\users\corrado\desktop\viviplay.exe:viviplay.exe
"TCP Query User{AA44DFEA-6C40-4013-B3C0-D489BF795B9D}C:\\program files\\viviplay.exe"= UDP:C:\program files\viviplay.exe:ViViMediaPlay
"UDP Query User{561D3765-BF30-4AE7-9DEC-37366FC2B289}C:\\program files\\viviplay.exe"= TCP:C:\program files\viviplay.exe:ViViMediaPlay
"{FBE87BE3-68C1-4C6F-9422-FE07C4F9471A}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{E0F53F23-86F4-44AD-A727-669A619684B1}"= UDP:21023:BitComet 21023 TCP
"{067CA1AD-2084-453F-BD43-5A365D255602}"= TCP:21023:BitComet 21023 UDP
"TCP Query User{ED9CB2FE-15BD-47D3-8E26-05AFD236E2EB}C:\\program files\\bitcomet\\bitcomet.exe"= UDP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{FF41D150-7FFF-4A01-AF60-07329200804C}C:\\program files\\bitcomet\\bitcomet.exe"= TCP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"{94360218-BD7F-4761-95AC-9AFAAF2F0760}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{132B2614-2836-4AFD-A13A-D33D0EAE35FC}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{444EEED4-5FA7-4FC6-A9C6-513EE9DBABBD}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{9DF0DD96-BAC7-453D-AEDD-3F85DD0CFE9F}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{F52026A4-C52F-4121-B6D5-201030667FEE}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\Windows\system32\drivers\klbg.sys [2008-01-29 18:29]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys [2008-03-26 13:10]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-01 20:55:12
Windows 6.0.6001 Service Pack 1 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-08-01 20:56:59
ComboFix-quarantined-files.txt 2008-08-01 18:56:27
ComboFix2.txt 2008-07-31 18:21:55
ComboFix3.txt 2008-07-29 18:32:52
Pre-Run: 3,055,190,016 octets libres
Post-Run: 3,891,441,664 octets libres
275 --- E O F --- 2008-07-30 00:24:50
Antivirus Version Dernière mise à jour Résultat
AhnLab-V3 2008.7.29.1 2008.08.01 -
AntiVir 7.8.1.15 2008.08.01 -
Authentium 5.1.0.4 2008.07.31 -
Avast 4.8.1195.0 2008.08.01 -
AVG 8.0.0.156 2008.08.01 -
BitDefender 7.2 2008.08.01 -
CAT-QuickHeal 9.50 2008.08.01 -
ClamAV 0.93.1 2008.08.01 -
DrWeb 4.44.0.09170 2008.08.01 -
eSafe 7.0.17.0 2008.07.29 Suspicious File
eTrust-Vet 31.6.6001 2008.08.01 -
Ewido 4.0 2008.08.01 -
F-Prot 4.4.4.56 2008.08.01 -
F-Secure 7.60.13501.0 2008.08.01 -
Fortinet 3.14.0.0 2008.08.01 -
GData 2.0.7306.1023 2008.08.01 -
Ikarus T3.1.1.34.0 2008.08.01 -
K7AntiVirus 7.10.402 2008.08.01 -
Kaspersky 7.0.0.125 2008.08.01 -
McAfee 5352 2008.08.01 -
Microsoft 1.3704 2008.07.28 -
NOD32v2 3317 2008.08.01 -
Norman 5.80.02 2008.08.01 -
Panda 9.0.0.4 2008.08.01 -
PCTools 4.4.2.0 2008.08.01 -
Prevx1 V2 2008.08.01 Suspicious
Rising 20.55.42.00 2008.08.01 -
Sophos 4.31.0 2008.08.01 -
Sunbelt 3.1.1537.1 2008.08.01 -
Symantec 10 2008.08.01 -
TheHacker 6.2.96.391 2008.07.31 Trojan/Downloader.IstBar.gen
TrendMicro 8.700.0.1004 2008.08.01 -
VBA32 3.12.8.2 2008.08.01 -
ViRobot 2008.8.1.1321 2008.08.01 -
VirusBuster 4.5.11.0 2008.08.01 -
Webwasher-Gateway 6.6.2 2008.08.01 -
Information additionnelle
File size: 325204 bytes
MD5...: d957b2c08edcf5cf79ce0a3d1360be14
SHA1..: 16c04bb034fc70b281aaef2fdcd0ff282ddffa5b
SHA256: 04477b3bfdf36f72da90e6f2fa43cec2260852ebd34dc366e3754263239eb8a0
SHA512: 4d4b0af56a16e0ec24151f56120f4858fc522f9e846385cc9eb96737f673bc15
b8c9f45b1469cad34934f91e4d302fd21f250ee557b2c01e8073f755ef83dec0
PEiD..: UPX 2.90 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x421be0
timedatestamp.....: 0x41ceda00 (Sun Dec 26 15:34:24 2004)
machinetype.......: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x16000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0x17000 0xb000 0xae00 7.90 35849369911491f8267e2981b59805f6
.rsrc 0x22000 0x2000 0x1c00 4.77 9a761c627f38d5bd79eba036284f4afe
( 8 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, ExitProcess
> ADVAPI32.DLL: RegCloseKey
> COMCTL32.DLL: -
> COMDLG32.DLL: GetOpenFileNameA
> GDI32.DLL: DeleteObject
> OLE32.DLL: OleInitialize
> SHELL32.DLL: SHGetMalloc
> USER32.DLL: SetMenu
( 0 exports )
ThreatExpert info: https://www.symantec.com?md5=d957b2c08edcf5cf79ce0a3d1360be14
Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=DA7D742754E875C7F6B7041BFAB03900E16C4957
packers (Kaspersky): UPX
packers (F-Prot): UPX, RAR
RAPPORT COMBOFIX
ComboFix 08-07-31.01 - Corrado 2008-08-01 20:52:15.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.1300 [GMT 2:00]
Endroit: C:\Users\Corrado\Desktop\C-Fix.exe
Command switches used :: C:\Users\Corrado\Desktop\CFScript.txt
* Création d'un nouveau point de restauration
FILE ::
C:\Program Files\Search Settings\SearchSettings.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2008-07-01 to 2008-08-01 ))))))))))))))))))))))))))))))))))))
.
2008-07-31 20:14 . 2008-07-31 20:14 <REP> d-------- C:\ComboFix
2008-07-31 16:39 . 2008-07-31 16:39 <REP> d-------- C:\Program Files\iTunes
2008-07-31 16:39 . 2008-07-31 16:39 <REP> d-------- C:\Program Files\iPod
2008-07-31 16:39 . 2008-07-31 16:39 <REP> d-------- C:\Program Files\Bonjour
2008-07-31 16:38 . 2008-07-31 16:38 <REP> d-------- C:\Program Files\QuickTime
2008-07-31 16:37 . 2008-07-31 16:37 <REP> d-------- C:\Windows\LastGood
2008-07-31 16:37 . 2008-07-31 16:39 <REP> d-------- C:\Users\All Users\Apple Computer
2008-07-31 16:37 . 2008-07-31 16:39 <REP> d-------- C:\PROGRA~2\Apple Computer
2008-07-31 16:36 . 2008-07-31 16:36 <REP> d-------- C:\Program Files\Common Files\Apple
2008-07-30 14:17 . 2008-07-30 14:17 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-30 14:17 . 2008-07-23 20:09 38,472 --a------ C:\Windows\System32\drivers\mbamswissarmy.sys
2008-07-30 14:17 . 2008-07-23 20:09 17,144 --a------ C:\Windows\System32\drivers\mbam.sys
2008-07-29 14:49 . 2008-07-30 16:09 <REP> d-------- C:\Toolbar SD
2008-07-29 04:27 . 2008-07-29 04:28 225,594,157 --a------ C:\Windows\MEMORY.DMP
2008-07-29 04:15 . 2008-07-29 04:25 96,559 --a------ C:\Windows\System32\drivers\klin.dat
2008-07-29 04:15 . 2008-07-29 04:25 87,855 --a------ C:\Windows\System32\drivers\klick.dat
2008-07-29 04:14 . 2008-07-31 20:31 <REP> d-------- C:\Users\All Users\Kaspersky Lab
2008-07-29 04:14 . 2008-07-29 04:14 <REP> d-------- C:\Program Files\Kaspersky Lab
2008-07-29 04:14 . 2008-07-31 20:31 <REP> d-------- C:\PROGRA~2\Kaspersky Lab
2008-07-29 04:14 . 2008-07-31 16:27 3,519,520 --ahs---- C:\Windows\System32\drivers\fidbox.dat
2008-07-29 04:14 . 2008-08-01 01:59 344,096 --ahs---- C:\Windows\System32\drivers\fidbox2.dat
2008-07-29 04:14 . 2008-07-31 16:27 29,624 --ahs---- C:\Windows\System32\drivers\fidbox.idx
2008-07-29 04:14 . 2008-08-01 01:59 2,256 --ahs---- C:\Windows\System32\drivers\fidbox2.idx
2008-07-29 03:56 . 2008-07-29 03:56 <REP> d-------- C:\Deckard
2008-07-29 02:30 . 2008-05-27 06:59 106,605 --a------ C:\Windows\System32\StructuredQuerySchema.bin
2008-07-29 02:30 . 2008-05-27 07:17 34,816 --a------ C:\Windows\System32\msscb.dll
2008-07-29 02:30 . 2008-05-27 06:59 18,904 --a------ C:\Windows\System32\StructuredQuerySchemaTrivial.bin
2008-07-29 02:30 . 2008-05-27 07:17 11,776 --a------ C:\Windows\System32\msshooks.dll
2008-07-23 17:24 . 2008-07-23 17:24 <REP> d-------- C:\Users\All Users\Malwarebytes
2008-07-23 17:24 . 2008-07-23 17:24 <REP> d-------- C:\PROGRA~2\Malwarebytes
2008-07-22 11:52 . 2008-07-22 11:52 <REP> d-------- C:\autorun.MSNFix
2008-07-22 11:46 . 2008-07-22 11:46 173 --a------ C:\curr_ver.tmp
2008-07-21 20:46 . 2008-07-22 03:35 <REP> d-------- C:\Windows\BDOSCAN8
2008-07-21 20:00 . 2008-07-29 02:37 <REP> d-------- C:\Windows\ShellNew
2008-07-11 11:46 . 2008-06-26 03:45 12,240,896 --a------ C:\Windows\System32\NlsLexicons0007.dll
2008-07-11 11:46 . 2008-06-26 03:45 2,644,480 --a------ C:\Windows\System32\NlsLexicons0009.dll
2008-07-11 11:46 . 2008-06-26 05:29 801,280 --a------ C:\Windows\System32\NaturalLanguage6.dll
2008-07-03 01:08 . 2008-07-03 01:08 <REP> d-------- C:\Program Files\Red Kawa
2008-07-02 18:09 . 2008-07-02 18:09 510 --a------ C:\Windows\WORDPAD.INI
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-21 19:11 --------- d-----w C:\Program Files\Sony
2008-07-18 14:34 --------- d-----w C:\Program Files\CSO-DAX Compressor
2008-07-10 05:07 --------- d-----w C:\Program Files\Windows Mail
2008-07-07 20:04 --------- d-----w C:\Program Files\eMule
2008-06-29 22:46 --------- d-----w C:\Program Files\BitComet
2008-06-25 16:00 0 ---ha-w C:\Windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-06-24 19:16 174 --sha-w C:\Program Files\desktop.ini
2008-06-24 19:06 --------- d-----w C:\Program Files\Windows Sidebar
2008-06-24 19:06 --------- d-----w C:\Program Files\Windows Photo Gallery
2008-06-24 19:06 --------- d-----w C:\Program Files\Windows Journal
2008-06-24 19:06 --------- d-----w C:\Program Files\Windows Defender
2008-06-24 19:06 --------- d-----w C:\Program Files\Windows Collaboration
2008-06-24 19:06 --------- d-----w C:\Program Files\Windows Calendar
2008-06-24 19:05 --------- d-----w C:\Program Files\Microsoft Games
2008-06-24 13:40 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-06-24 13:40 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-06-23 11:43 --------- d-----w C:\Program Files\Syncrosoft
2008-06-22 23:05 --------- d-----w C:\Program Files\DivX
2008-06-22 23:03 --------- d-----w C:\PROGRA~2\Pinnacle
2008-06-19 17:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-06 15:28 --------- d-----w C:\Program Files\Propellerhead
2008-06-06 11:46 --------- d-----w C:\Program Files\Image-Line
2008-06-05 15:44 --------- d-----w C:\PROGRA~2\Propellerhead Software
2008-06-02 15:57 --------- d-----w C:\Program Files\Free Audio Pack converter
2008-05-27 05:21 1,582,592 ----a-w C:\Windows\System32\tquery.dll
2008-05-27 05:21 1,418,240 ----a-w C:\Windows\System32\mssrch.dll
2008-05-27 05:17 87,552 ----a-w C:\Windows\System32\SearchFilterHost.exe
2008-05-27 05:17 87,552 ----a-w C:\Windows\System32\mssitlb.dll
2008-05-27 05:17 754,176 ----a-w C:\Windows\System32\propsys.dll
2008-05-27 05:17 60,416 ----a-w C:\Windows\System32\msscntrs.dll
2008-05-27 05:17 6,103,040 ----a-w C:\Windows\System32\chtbrkr.dll
2008-05-27 05:17 32,768 ----a-w C:\Windows\System32\mssprxy.dll
2008-05-27 05:17 313,344 ----a-w C:\Windows\System32\thawbrkr.dll
2008-05-27 05:17 301,568 ----a-w C:\Windows\System32\srchadmin.dll
2008-05-27 05:17 194,560 ----a-w C:\Windows\System32\offfilt.dll
2008-05-27 05:17 143,872 ----a-w C:\Windows\System32\korwbrkr.dll
2008-05-27 05:17 1,671,680 ----a-w C:\Windows\System32\chsbrkr.dll
2008-05-22 22:20 200,704 ----a-w C:\Windows\System32\ssldivx.dll
2008-05-22 22:20 1,044,480 ----a-w C:\Windows\System32\libdivx.dll
2008-05-10 03:35 564,736 ----a-w C:\Windows\System32\emdmgmt.dll
2008-05-08 21:59 90,112 ----a-w C:\Windows\System32\wshext.dll
2008-05-08 21:59 430,080 ----a-w C:\Windows\System32\vbscript.dll
2008-05-08 21:59 180,224 ----a-w C:\Windows\System32\scrobj.dll
2008-05-08 21:59 172,032 ----a-w C:\Windows\System32\scrrun.dll
2008-05-08 21:59 155,648 ----a-w C:\Windows\System32\wscript.exe
2008-05-08 21:58 135,168 ----a-w C:\Windows\System32\cscript.exe
2007-08-29 13:06 278,528 ----a-w C:\Program Files\Common Files\FDEUnInstaller.exe
2005-05-11 12:23 1 --sha-w C:\Windows\fidbox.dat
2007-09-03 18:26 22 --sha-w C:\Windows\SMINST\HPCD.sys
.
[code]<pre>
----a-w 325,204 2006-12-21 19:56:28 C:\SwSetup\SP34746\WCAMC\FW_210_Silence Install .exe
</pre>/code
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\327882R2FWJFW ----
C:\327882R2FWJFW\
((((((((((((((((((((((((((((( snapshot@2008-07-31_20.21.13.46 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2008-04-25 18:21 201992]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"ValidateAdminCodeSignatures"= 1 (0x1)
"FilterAdministratorToken"= 1 (0x1)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\Windows\pss\Adobe Reader Synchronizer.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^AOL 9.0 Icône AOL.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AOL 9.0 Icône AOL.lnk
backup=C:\Windows\pss\AOL 9.0 Icône AOL.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Lancement rapide d'Adobe Reader.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Lancement rapide d'Adobe Reader.lnk
backup=C:\Windows\pss\Lancement rapide d'Adobe Reader.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Corrado^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Empty.pif]
path=C:\Users\Corrado\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Empty.pif
backup=C:\Windows\pss\Empty.pif.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
--a------ 2007-09-01 01:40 2321600 C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AOLDialer]
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast!]
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-06-27 19:03 152872 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
c:\Program Files\Common Files\Symantec Shared\ccApp.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
--a------ 2007-03-12 11:54 50696 C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-02-16 23:11 49152 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
--a------ 2007-03-01 13:18 472776 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
--a------ 2007-02-12 16:37 174872 C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IS CfgWiz]
c:\Program Files\Common Files\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\cltUIStb.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kaspersky Anti-Virus 2006]
C:\Program Files\Kaspersky Lab\AVP6\avp.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2007-10-18 12:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MySpaceIM]
C:\Program Files\MySpace\IM\MySpaceIM.exe [N/A]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 15:57 153136 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2007-05-01 12:27 8429568 C:\Windows\System32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-05-01 12:27 81920 C:\Windows\System32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
--a------ 2007-05-01 12:27 86016 C:\Windows\System32\nvsvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl]
--a------ 2007-02-13 11:38 159744 C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
--a------ 2007-04-23 18:11 176128 C:\Program Files\HP\QuickPlay\QPService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-05-27 10:50 413696 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSERIAL]
--a------ 2006-10-09 22:43 729088 C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Speech Recognition]
--a------ 2008-01-19 09:33 49664 C:\Windows\Speech\Common\sapisvr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
--a------ 2007-08-31 16:46 1460560 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 02:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 2007-09-15 03:50 1021224 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPStart]
--a------ 2007-09-15 03:29 102400 C:\Program Files\Synaptics\SynTP\SynTPStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WAWifiMessage]
--a------ 2007-01-10 16:12 317128 C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2008-01-19 09:38 1008184 C:\Program Files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
--a------ 2007-03-09 19:50 4390912 C:\Windows\RtHDVCpl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{394C533B-4CC1-4246-B362-3E4670DD45AE}"= C:\Program Files\HP\QuickPlay\QP.exe:Quick Play
"{A0D656E2-4E3F-4346-9AF0-1784F49B370E}"= C:\Program Files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{E9700DD2-050E-4830-8C93-832E14A18463}"= Disabled:UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{D344DB5F-C5F3-44E3-A3CC-55968796A2F2}"= Disabled:TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{6B3457A2-6EBB-402E-8C10-3A8FEDAFDA91}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{AAF1863A-C0EF-4B4D-B716-45FD18BED69D}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{A874C707-D8F1-4601-A008-E0C00DB77D0D}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{6AC94B1A-D3B4-4E13-B887-F4C3CDB35C46}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
"{C2E70F68-7DEF-460C-8322-DDF5D6B072B6}"= UDP:C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:AOL
"{4489134E-3826-435F-AC6D-85B159A39019}"= TCP:C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:AOL
"{B6B748F4-C964-4B81-A91E-93A5E67E6F16}"= UDP:C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:AOL
"{C114D0B1-1A79-45FC-B171-A8556EA69D0E}"= TCP:C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:AOL
"{9001CAE8-9CDC-46AC-9351-E6957EC93A7D}"= UDP:C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:AOL
"{56A83B31-B762-488A-B173-776A2894E1C5}"= TCP:C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:AOL
"{4EACD929-ECAD-43F2-A08D-827F2CE211D7}"= UDP:C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:AOL
"{FE4303F6-DA63-4D4F-BB5F-3414DA2240B8}"= TCP:C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:AOL
"TCP Query User{0BC85039-FC9D-45C2-8672-4E0C950D016B}C:\\users\\corrado\\desktop\\emule.exe"= UDP:C:\users\corrado\desktop\emule.exe:emule.exe
"UDP Query User{898B0540-2106-4CC4-8286-DB417B613548}C:\\users\\corrado\\desktop\\emule.exe"= TCP:C:\users\corrado\desktop\emule.exe:emule.exe
"{3F02AE31-21F3-42B4-985B-06E1F4CAD841}"= UDP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{2D76E154-FE39-4913-AE8A-FDE1080153FF}"= TCP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{FC4B22E4-670E-45A7-B876-57768C358036}"= UDP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{A13EE0FC-1F55-44F6-A339-302E65B7628D}"= TCP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{B5C1A022-BB1E-4F52-8166-DF8FEF1C5731}"= UDP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{0FD80F68-B039-4AA8-8CFE-B0B9094D373C}"= TCP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{0A3CAF7F-1B70-48F4-80A7-F03B102F069D}"= UDP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{678A1B50-FCBB-456F-838F-73E99E4904C9}"= TCP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"TCP Query User{37DE6567-6E6C-4834-9385-089823895476}C:\\users\\corrado\\desktop\\viviplay.exe"= UDP:C:\users\corrado\desktop\viviplay.exe:viviplay.exe
"UDP Query User{503B1753-A77F-46F2-AF89-8DCFF03C8E21}C:\\users\\corrado\\desktop\\viviplay.exe"= TCP:C:\users\corrado\desktop\viviplay.exe:viviplay.exe
"TCP Query User{AA44DFEA-6C40-4013-B3C0-D489BF795B9D}C:\\program files\\viviplay.exe"= UDP:C:\program files\viviplay.exe:ViViMediaPlay
"UDP Query User{561D3765-BF30-4AE7-9DEC-37366FC2B289}C:\\program files\\viviplay.exe"= TCP:C:\program files\viviplay.exe:ViViMediaPlay
"{FBE87BE3-68C1-4C6F-9422-FE07C4F9471A}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{E0F53F23-86F4-44AD-A727-669A619684B1}"= UDP:21023:BitComet 21023 TCP
"{067CA1AD-2084-453F-BD43-5A365D255602}"= TCP:21023:BitComet 21023 UDP
"TCP Query User{ED9CB2FE-15BD-47D3-8E26-05AFD236E2EB}C:\\program files\\bitcomet\\bitcomet.exe"= UDP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"UDP Query User{FF41D150-7FFF-4A01-AF60-07329200804C}C:\\program files\\bitcomet\\bitcomet.exe"= TCP:C:\program files\bitcomet\bitcomet.exe:BitComet - a BitTorrent Client
"{94360218-BD7F-4761-95AC-9AFAAF2F0760}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{132B2614-2836-4AFD-A13A-D33D0EAE35FC}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{444EEED4-5FA7-4FC6-A9C6-513EE9DBABBD}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{9DF0DD96-BAC7-453D-AEDD-3F85DD0CFE9F}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{F52026A4-C52F-4121-B6D5-201030667FEE}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\Windows\system32\drivers\klbg.sys [2008-01-29 18:29]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys [2008-03-26 13:10]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-01 20:55:12
Windows 6.0.6001 Service Pack 1 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-08-01 20:56:59
ComboFix-quarantined-files.txt 2008-08-01 18:56:27
ComboFix2.txt 2008-07-31 18:21:55
ComboFix3.txt 2008-07-29 18:32:52
Pre-Run: 3,055,190,016 octets libres
Post-Run: 3,891,441,664 octets libres
275 --- E O F --- 2008-07-30 00:24:50
ET VOIC LE RAPPORT HIJACTIS /
O2 - BHO: (no name) - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - (no file)
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Statistiques de la protection du trafic Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\Windows\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
O13 - Gopher Prefix:
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-24-0.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.6.0_03) -
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} (Java Plug-in 1.6.0_02) -
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
O2 - BHO: (no name) - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - (no file)
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: &Recherche AOL Toolbar - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Statistiques de la protection du trafic Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\Windows\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
O13 - Gopher Prefix:
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-24-0.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.6.0_03) -
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} (Java Plug-in 1.6.0_02) -
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
Bien ...
le fichier analyser sur VirusTotal s'avère malicieux pour certains AV ... on va s'en occupper .
on continue :
1-Télécharges OTMoveIt (de Old_Timer) sur ton Bureau.
http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
ou http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
Déconnectes toi et fermes toute tes applications en cours .
Cliques droit/"exécuter entant qu'admin..." sur OTMoveIt.exe pour le lancer.
copie la liste qui se trouve en citation ci-dessous,
C:\327882R2FWJFW
C:\SwSetup\SP34746\WCAMC\FW_210_Silence Install .exe
et colles-la dans le cadre de gauche de OTMoveIt2 :
Paste standard List of Files/Folders to be moved.
cliques sur MoveIt! pour lancer la suppression.
le résultat apparaîtra dans le cadre Results.
cliques sur Exit pour fermer.
--->postes le rapport situé dans " C:\OTMoveIt\MovedFiles."
il te sera peut-être demandé de redémarrer le pc pour achever la suppression.
si c'est le cas acceptes par "Yes".
Une fois ce-ci fais et le rapport posté , enchaines :
2- Télécharges : - CCleaner
https://www.pcastuces.com/logitheque/ccleaner.htm
Ce logiciel va permettre de supprimer tous les fichiers temporaires et de corrigé ton registre .Lors de l'installation, avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires" sauf les 2 première.
Une fois le prg instalé et lancé, Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures"( Par la suite, laisse-le avec ses réglages par défaut. C'est tout ).
Un tuto ( aide ):
http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm
---> Utilisation:
vas dans "nettoyeur" : fait analyse puis nettoyage
et vas dans "registre" : fait chercher les erreurs et réparer ( plusieurs fois jusqu'à ce qu'il n'y est plus d'erreur ) .
( CCleaner : soft à garder sur son PC , super utile pour de bons nettoyages ... )
3- redémarre ton PC , refais un scan hijackthis et postes le nouveau rapport obtenu pour analyse...
Dis nous aussi comment va le PC , y a t'il du mieux ?
le fichier analyser sur VirusTotal s'avère malicieux pour certains AV ... on va s'en occupper .
on continue :
1-Télécharges OTMoveIt (de Old_Timer) sur ton Bureau.
http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
ou http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
Déconnectes toi et fermes toute tes applications en cours .
Cliques droit/"exécuter entant qu'admin..." sur OTMoveIt.exe pour le lancer.
copie la liste qui se trouve en citation ci-dessous,
C:\327882R2FWJFW
C:\SwSetup\SP34746\WCAMC\FW_210_Silence Install .exe
et colles-la dans le cadre de gauche de OTMoveIt2 :
Paste standard List of Files/Folders to be moved.
cliques sur MoveIt! pour lancer la suppression.
le résultat apparaîtra dans le cadre Results.
cliques sur Exit pour fermer.
--->postes le rapport situé dans " C:\OTMoveIt\MovedFiles."
il te sera peut-être demandé de redémarrer le pc pour achever la suppression.
si c'est le cas acceptes par "Yes".
Une fois ce-ci fais et le rapport posté , enchaines :
2- Télécharges : - CCleaner
https://www.pcastuces.com/logitheque/ccleaner.htm
Ce logiciel va permettre de supprimer tous les fichiers temporaires et de corrigé ton registre .Lors de l'installation, avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires" sauf les 2 première.
Une fois le prg instalé et lancé, Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures"( Par la suite, laisse-le avec ses réglages par défaut. C'est tout ).
Un tuto ( aide ):
http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm
---> Utilisation:
vas dans "nettoyeur" : fait analyse puis nettoyage
et vas dans "registre" : fait chercher les erreurs et réparer ( plusieurs fois jusqu'à ce qu'il n'y est plus d'erreur ) .
( CCleaner : soft à garder sur son PC , super utile pour de bons nettoyages ... )
3- redémarre ton PC , refais un scan hijackthis et postes le nouveau rapport obtenu pour analyse...
Dis nous aussi comment va le PC , y a t'il du mieux ?