Win32:Trojan-gen. {Other} suite... - Page 2

Résolu
Précédent
  • 1
  • 2
  • 3
  1. elioth
     
    et ba teste:

    http://telechargement.zebulon.fr/zeb-restore.html
    0
  2. elioth
     
    oici les éléments qui peuvent être restaurés :
    - RegEdit : réactive l'accès à RegEdit
    - Clés RUN : réactive le lancement de programmes par clés RunXXX
    - Bouton Arrêter : rétablit le bouton Arrêter
    - Windows Update : rétablit la fonction Windows Update
    - Gestionnaire des tâches : réactive le gestionnaire des tâches
    - Panneau de configuration : réactive le Panneau de configuration
    - Ajout/Suppression de programmes : restaure la fonction Ajout-Suppression de programmes
    - Policies : remet en place des éléments désactivés par "Policies"
    - Bureau : réactive le bureau
    - Réparation IE : répare Internet Exploreur (pages de recherche)
    - Extension des fichiers : répare les extensions des fichiers .exe .bat .reg .pif .cmd .scr .com
    - Sites de confiance et sensibles : efface le contenu de ces zones (à utiliser si vous êtes infecté par des malwares)
    - Préfixes et Protocoles Internet : restore les clés des protocoles Internet (ZoneMap etc.)
    - Réinitialiser Fichier Hosts : réinitialise le fichier Hosts
    0
  3. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  4. elioth
     
    kerberos si tu fait ca tout est reglé mais si tu prefere resté dans le caca libre a toi.

    bye bye
    0
  5. K3RB3ROS Messages postés 66 Statut Membre
     
    salut,

    non je ne veux pas rester dans le caca, mais je prefere terminer completement une "solution" , genre avec Destrio5
    et ensuite si ca ne marche pas j'essayrai avec toi :)
    0
  6. g!rly Messages postés 18462 Statut Contributeur 407
     
    doublon...
    0
  7. K3RB3ROS Messages postés 66 Statut Membre
     
    sympa l'edit...

    tiens voila ton rapport ComboFix :)

    ComboFix 08-08-02.01 - ARBARNI 2008-08-03 15:16:55.3 - NTFSx86
    Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.609 [GMT 2:00]
    Endroit: C:\Documents and Settings\ARBARNI\Bureau\ComboFix.exe
    * Création d'un nouveau point de restauration
    .

    ((((((((((((((((((((((((((((( Fichiers créés 2008-07-03 to 2008-08-03 ))))))))))))))))))))))))))))))))))))
    .

    2008-08-03 14:45 . 2008-08-03 14:45 <REP> d-------- C:\Program Files\CCleaner
    2008-08-02 21:11 . 2008-08-02 21:11 <REP> d-------- C:\Program Files\VirginMega
    2008-08-02 21:09 . 2008-08-02 21:09 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
    2008-08-02 21:01 . 2008-08-02 21:01 <REP> d-------- C:\Program Files\Windows Media Connect 2
    2008-08-02 20:59 . 2008-08-02 21:00 <REP> d-------- C:\WINDOWS\system32\drivers\UMDF
    2008-08-02 19:15 . 2008-08-02 19:15 <REP> d-------- C:\Program Files\Avira
    2008-08-02 19:15 . 2008-08-02 19:15 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
    2008-08-02 18:39 . 2008-08-02 18:39 <REP> d-------- C:\Program Files\Unlocker
    2008-08-02 18:39 . 2008-08-02 18:39 <REP> d-------- C:\Documents and Settings\ARBARNI\Application Data\Desktopicon
    2008-08-01 02:45 . 2008-08-01 02:45 579,584 --a------ C:\WINDOWS\system32\dllcache\user32.dll
    2008-08-01 02:42 . 2008-08-01 02:42 <REP> d-------- C:\WINDOWS\ERUNT
    2008-08-01 02:19 . 2008-08-01 02:19 1,882 --a------ C:\WINDOWS\system32\tmp.reg
    2008-07-30 22:06 . 2008-07-30 22:44 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
    2008-07-30 20:20 . 2008-07-30 20:32 <REP> d-------- C:\Program Files\Microsoft Bootvis
    2008-07-30 19:57 . 2008-06-20 13:51 361,600 --------- C:\WINDOWS\system32\dllcache\tcpip.sys
    2008-07-30 19:57 . 2008-06-20 19:47 247,808 --------- C:\WINDOWS\system32\dllcache\mswsock.dll
    2008-07-30 19:57 . 2008-06-20 13:08 225,856 --------- C:\WINDOWS\system32\dllcache\tcpip6.sys
    2008-07-30 19:57 . 2008-06-20 19:47 147,968 --------- C:\WINDOWS\system32\dllcache\dnsapi.dll
    2008-07-30 19:57 . 2008-06-20 13:40 138,496 --------- C:\WINDOWS\system32\dllcache\afd.sys
    2008-07-22 11:05 . 2008-07-22 11:05 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Malwarebytes
    2008-07-22 11:03 . 2008-05-30 01:05 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
    2008-07-22 11:03 . 2008-05-30 01:05 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
    2008-07-22 11:03 . 2008-05-30 01:08 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
    2008-07-22 11:03 . 2008-05-30 01:08 <REP> dr------- C:\Documents and Settings\Administrateur\Mes documents
    2008-07-22 11:03 . 2008-05-30 01:08 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
    2008-07-22 11:03 . 2008-05-30 01:08 <REP> dr------- C:\Documents and Settings\Administrateur\Favoris
    2008-07-22 11:03 . 2008-07-22 12:53 <REP> dr------- C:\Documents and Settings\Administrateur\Bureau
    2008-07-22 11:03 . 2008-05-30 01:05 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\You've Got Pictures Screensaver
    2008-07-22 11:03 . 2008-05-30 01:05 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Symantec
    2008-07-22 11:03 . 2008-07-22 11:03 <REP> d-------- C:\Documents and Settings\Administrateur
    2008-07-22 08:18 . 2008-07-31 23:17 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-07-22 08:18 . 2008-07-22 08:18 <REP> d-------- C:\Documents and Settings\ARBARNI\Application Data\Malwarebytes
    2008-07-22 08:18 . 2008-07-22 08:18 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-07-22 08:18 . 2008-07-30 20:07 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
    2008-07-22 08:18 . 2008-07-30 20:07 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
    2008-07-21 22:45 . 2008-08-03 14:41 <REP> d-------- C:\Program Files\Trend Micro
    2008-07-21 20:57 . 2008-06-19 17:24 28,544 --a------ C:\WINDOWS\system32\drivers\pavboot.sys
    2008-07-21 20:56 . 2008-07-21 20:56 <REP> d-------- C:\Program Files\Panda Security
    2008-07-21 20:38 . 2008-06-14 19:33 272,768 --------- C:\WINDOWS\system32\dllcache\bthport.sys
    2008-07-21 20:36 . 2008-04-23 06:16 6,066,176 --------- C:\WINDOWS\system32\dllcache\ieframe.dll
    2008-07-21 20:36 . 2007-04-17 11:32 2,455,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dat
    2008-07-21 20:36 . 2007-03-08 07:10 1,048,576 --------- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
    2008-07-21 20:36 . 2008-04-23 06:16 459,264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll
    2008-07-21 20:36 . 2008-04-23 06:16 383,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll
    2008-07-21 20:36 . 2008-04-23 06:16 267,776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll
    2008-07-21 20:36 . 2008-04-23 06:16 63,488 --------- C:\WINDOWS\system32\dllcache\icardie.dll
    2008-07-21 20:36 . 2008-04-23 06:16 52,224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
    2008-07-21 20:36 . 2008-04-22 09:39 13,824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe
    2008-07-21 20:35 . 2008-05-09 12:55 180,224 --------- C:\WINDOWS\system32\dllcache\scrobj.dll
    2008-07-21 20:35 . 2008-05-09 12:55 172,032 --------- C:\WINDOWS\system32\dllcache\scrrun.dll
    2008-07-21 20:35 . 2008-05-08 13:24 155,648 --------- C:\WINDOWS\system32\dllcache\wscript.exe
    2008-07-21 20:35 . 2008-05-09 10:45 135,168 --------- C:\WINDOWS\system32\dllcache\cscript.exe
    2008-07-21 20:35 . 2008-05-09 12:55 90,112 --------- C:\WINDOWS\system32\dllcache\wshext.dll
    2008-07-21 20:33 . 2008-05-07 07:11 1,294,336 --------- C:\WINDOWS\system32\dllcache\quartz.dll
    2008-07-21 20:32 . 2008-07-21 20:32 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
    2008-07-21 20:13 . 2008-05-08 16:02 203,136 --------- C:\WINDOWS\system32\dllcache\rmcast.sys
    2008-07-21 20:10 . 2008-07-21 20:10 <REP> d-------- C:\Program Files\MSXML 4.0
    2008-07-21 17:42 . 2008-07-21 17:42 <REP> d-------- C:\Program Files\ma-config.com
    2008-07-21 17:42 . 2008-07-21 17:42 <REP> d-------- C:\Documents and Settings\All Users\Application Data\ma-config.com
    2008-07-09 20:42 . 2001-09-30 19:10 246,784 --a------ C:\WINDOWS\system32\ActiveSkin.ocx
    2008-07-09 20:42 . 2001-05-24 12:59 162,304 --a------ C:\UNWISE.EXE
    2008-07-09 20:42 . 2002-01-18 18:12 112 --a------ C:\WINDOWS\ActiveSkin.INI

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-08-03 13:07 --------- d-----w C:\Documents and Settings\ARBARNI\Application Data\OpenOffice.org2
    2008-07-30 18:12 --------- d-----w C:\Program Files\Java
    2008-07-19 12:29 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
    2008-06-27 21:19 135,168 ----a-w C:\WINDOWS\system32\drivers\Bjg46.sys
    2008-06-20 17:47 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
    2008-06-20 16:56 --------- d-----w C:\Documents and Settings\ARBARNI\Application Data\AdobeUM
    2008-06-20 11:51 361,600 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
    2008-06-20 11:40 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
    2008-06-20 11:08 225,856 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
    2008-06-14 17:33 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
    2008-06-05 07:20 --------- d--h--w C:\Documents and Settings\All Users\Application Data\CanonBJ
    2008-06-05 07:17 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-06-05 07:17 --------- d-----w C:\Program Files\ArcSoft
    2008-06-05 07:15 --------- d-----w C:\Program Files\Canon
    2008-06-04 12:47 --------- d-----w C:\Program Files\Google
    2008-05-09 10:55 90,112 ----a-w C:\WINDOWS\system32\wshext.dll
    2008-05-09 10:55 512,000 ------w C:\WINDOWS\system32\dllcache\jscript.dll
    2008-05-09 10:55 430,080 ----a-w C:\WINDOWS\system32\vbscript.dll
    2008-05-09 10:55 430,080 ------w C:\WINDOWS\system32\dllcache\vbscript.dll
    2008-05-09 10:55 180,224 ----a-w C:\WINDOWS\system32\scrobj.dll
    2008-05-09 10:55 172,032 ----a-w C:\WINDOWS\system32\scrrun.dll
    2008-05-09 08:45 135,168 ----a-w C:\WINDOWS\system32\cscript.exe
    2008-05-08 11:24 155,648 ----a-w C:\WINDOWS\system32\wscript.exe
    2008-05-07 05:11 1,294,336 ----a-w C:\WINDOWS\system32\quartz.dll
    .

    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-14 04:34 1695232]
    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-06-04 14:47 171448]
    "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2004-11-22 08:18 307200]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 04:33 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2005-07-28 21:29 102400]
    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-05-11 21:03 708697]
    "SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 09:11 1388544]
    "PCMService"="c:\Apps\Powercinema\PCMService.exe" [2005-05-11 13:48 127118]
    "UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2008-05-02 06:15 15872]
    "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
    "SiSPower"="SiSPower.dll" [2005-07-13 02:55 49152 C:\WINDOWS\system32\SiSPower.dll]

    C:\Documents and Settings\ARBARNI\Menu D‚marrer\Programmes\D‚marrage\
    OpenOffice.org 2.4.lnk - C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 15:41:28 393216]

    C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
    Utility Tray.lnk - C:\WINDOWS\system32\sistray.exe [2005-10-24 14:56:08 262144]

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001
    "AntiVirusOverride"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%ProgramFiles%\\AOL 9.0\\aol.exe"=
    "%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
    "%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\APPS\\Inventime\\my.exe"=
    "C:\\APPS\\skype\\phone\\Skype.exe"=
    "C:\\APPS\\Powercinema\\PowerCinema.exe"=
    "C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDial.exe"=
    "C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLacsd.exe"=
    "C:\\Program Files\\AOL 9.0\\waol.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=

    R0 Bjg46;Bjg46;C:\WINDOWS\system32\drivers\Bjg46.sys [2008-06-27 23:19]
    R0 pavboot;pavboot;C:\WINDOWS\system32\drivers\pavboot.sys [2008-06-19 17:24]
    R0 qhvloatj;qhvloatj;C:\WINDOWS\system32\drivers\qhvloatj.sys [2004-08-05 14:00]
    R3 ASNDIS5;ASNDIS5 Protocol Driver;C:\WINDOWS\ATK0100\ASNDIS5.SYS [2004-05-28 10:13]
    R3 HSFHWSIS;HSFHWSIS;C:\WINDOWS\system32\DRIVERS\HSFHWSIS.sys [2005-06-22 14:50]
    R3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys [2004-11-05 16:43]
    S0 Winva71;Winva71;C:\WINDOWS\system32\Drivers\Winva71.sys []
    S3 maconfservice;Ma-Config Service;C:\Program Files\ma-config.com\maconfservice.exe [2008-06-26 09:13]
    S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 20:45]
    S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 20:45]
    S3 ZD1211U(ASUS);ASUS ZD1211 IEEE 802.11b+g Wireless LAN Driver (USB)(ASUS);C:\WINDOWS\system32\DRIVERS\zd1211u.sys [2005-09-08 09:41]

    *Newly Created Service* - CATCHME
    .
    - - - - ORPHANS REMOVED - - - -

    BHO-{92E5DF6B-D89A-4103-AC7B-F3F10ADB2A47} - C:\DOCUME~1\ARBARNI\LOCALS~1\Temp\dmE.dll
    BHO-{957C849E-DA93-42F4-948B-E7E20208E0D6} - c:\windows\system32\ylroxhk.dll

    .
    ------- Supplementary Scan -------
    .
    FireFox -: Profile - C:\Documents and Settings\ARBARNI\Application Data\Mozilla\Firefox\Profiles\ujb2i2k8.default\
    FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.fr/
    FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
    FF -: plugin - C:\Program Files\ma-config.com\nphardwaredetection.dll
    FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll

    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-08-03 15:19:25
    Windows 5.1.2600 Service Pack 3 NTFS

    Balayage processus cachés ...

    Balayage caché autostart entries ...

    Balayage des fichiers cachés ...

    Scan terminé avec succès
    Les fichiers cachés: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MySqlInventime]
    "ImagePath"="c:\mysql\bin\mysqld-max-nt MySqlInventime"
    .
    Temps d'accomplissement: 2008-08-03 15:20:20
    ComboFix-quarantined-files.txt 2008-08-03 13:20:13
    ComboFix2.txt 2008-08-03 11:34:34

    Pre-Run: 41,296,117,760 octets libres
    Post-Run: 41,286,688,768 octets libres

    180 --- E O F --- 2008-08-03 12:55:22
    0
  8. g!rly Messages postés 18462 Statut Contributeur 407
     
    oué desolé, mais en meme temps tu as plusieurs topiks...
    0
  9. K3RB3ROS Messages postés 66 Statut Membre
     
    oui je sais bien mais au bout d'un moment Destrio5 n'avait plus de solutions et ma conseillé de faire un nouveau topic

    sauf qu'après il a eu de nouveau des idées ^^ et vu que vous aviez posté sur ce topic aussi je l'ai laissé :/

    sinon tu as une idée ?
    0
  10. g!rly Messages postés 18462 Statut Contributeur 407
     
    Vu comme ca...

    Télécharge Lop S&D (de Angeldark et Eric71) sur le Bureau :
    https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2

    [*]Double-clique sur Lop S&D.exe pour lancer l'installation,
    [*]Puis double-clique sur le raccourci Lop S&D présent sur le Bureau.
    [*]Séléctionne la langue souhaitée , puis choisis l'Option 1 (Recherche)
    Le scan prend moins d'une minute.
    [*]A l'issue du scan, le bloc-notes va s'ouvrir avec le résultat de la recherche.
    [*]Enregistre le rapport LopR.txt sur le Bureau pour le retrouver facilement, sinon il sauvegardé à la racine de la partition système : C:\LopR.txt

    puis

    Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
    http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
    Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
    • Redémarre ton ordinateur
    • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
    • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
    • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
    • Choisis ton compte.
    Déroule la liste des instructions ci-dessous :
    • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
    • Appuie sur Y pour commencer le processus de nettoyage.
    • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
    • Appuie sur une touche pour redémarrer le PC.
    • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
    • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
    • Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
    • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
    • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau log Hijackthis !

    @+
    0
  11. K3RB3ROS Messages postés 66 Statut Membre
     
    alors, voila les rapports :

    Lop S&D

    --------------------\\ Lop S&D 4.2.2-5 XP/Vista

    [ Windows XP (NT 5.1) Build 2600, Service Pack 3 ]
    [ USER : ARBARNI ] [ "C:\Lop SD" ] [ Selection : 1 ]
    [ 03/08/2008 | 15:39:37,84 ] [ PC : SNNECCI ]
    [ MAJ : 01-08-2008 | 01:40 ]

    --------------------\\ Listing des dossiers dans APPLIC~1

    [16/08/2004|17:55] C:\DOCUME~1\ADMINI~1\APPLIC~1\desktop.ini
    [30/05/2008|01:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\Identities
    [30/05/2008|01:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\Macromedia
    [22/07/2008|11:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\Malwarebytes
    [30/05/2008|01:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\Microsoft
    [30/05/2008|01:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\Real
    [30/05/2008|01:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\Sun
    [30/05/2008|01:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\Symantec
    [30/05/2008|01:05] C:\DOCUME~1\ADMINI~1\APPLIC~1\You've Got Pictures Screensaver

    [30/05/2008|01:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
    [30/05/2008|01:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\AOL
    [02/08/2008|19:15] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Avira
    [05/06/2008|09:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CanonBJ
    [30/05/2008|01:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\CyberLink
    [16/08/2004|17:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\desktop.ini
    [02/08/2008|21:09] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Downloaded Installations
    [04/06/2008|14:47] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
    [21/07/2008|17:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ma-config.com
    [22/07/2008|08:18] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
    [27/06/2008|21:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
    [30/05/2008|01:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\OD2
    [30/05/2008|01:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
    [30/05/2008|01:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\SBSI
    [30/07/2008|22:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
    [30/05/2008|01:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
    [29/05/2008|16:36] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
    [30/05/2008|10:33] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller

    [07/06/2008|18:47] C:\DOCUME~1\ARBARNI\APPLIC~1\Adobe
    [20/06/2008|18:56] C:\DOCUME~1\ARBARNI\APPLIC~1\AdobeUM
    [16/08/2004|17:55] C:\DOCUME~1\ARBARNI\APPLIC~1\desktop.ini
    [02/08/2008|18:39] C:\DOCUME~1\ARBARNI\APPLIC~1\Desktopicon
    [04/06/2008|14:48] C:\DOCUME~1\ARBARNI\APPLIC~1\Google
    [30/05/2008|01:05] C:\DOCUME~1\ARBARNI\APPLIC~1\Identities
    [30/05/2008|10:03] C:\DOCUME~1\ARBARNI\APPLIC~1\Macromedia
    [22/07/2008|08:18] C:\DOCUME~1\ARBARNI\APPLIC~1\Malwarebytes
    [30/07/2008|20:20] C:\DOCUME~1\ARBARNI\APPLIC~1\Microsoft
    [19/07/2008|15:10] C:\DOCUME~1\ARBARNI\APPLIC~1\Mozilla
    [30/05/2008|10:49] C:\DOCUME~1\ARBARNI\APPLIC~1\OD2
    [03/08/2008|15:07] C:\DOCUME~1\ARBARNI\APPLIC~1\OpenOffice.org2
    [03/06/2008|16:58] C:\DOCUME~1\ARBARNI\APPLIC~1\Real
    [30/05/2008|01:05] C:\DOCUME~1\ARBARNI\APPLIC~1\Sun
    [30/07/2008|20:39] C:\DOCUME~1\ARBARNI\APPLIC~1\WinRAR
    [30/05/2008|01:05] C:\DOCUME~1\ARBARNI\APPLIC~1\You've Got Pictures Screensaver

    [16/08/2004|17:55] C:\DOCUME~1\DEFAUL~1\APPLIC~1\desktop.ini
    [30/05/2008|01:05] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Identities
    [30/05/2008|01:05] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Macromedia
    [30/05/2008|01:05] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft
    [30/05/2008|01:05] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Real
    [30/05/2008|01:05] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Sun
    [30/05/2008|01:05] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Symantec
    [30/05/2008|01:05] C:\DOCUME~1\DEFAUL~1\APPLIC~1\You've Got Pictures Screensaver

    [30/05/2008|01:05] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft

    [22/07/2008|13:00] C:\DOCUME~1\NETWOR~1\APPLIC~1\Adobe
    [22/07/2008|13:00] C:\DOCUME~1\NETWOR~1\APPLIC~1\Macromedia
    [29/05/2008|18:31] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft
    [19/07/2008|16:24] C:\DOCUME~1\NETWOR~1\APPLIC~1\Mozilla

    --------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

    [03/08/2008 15:06][--ah-----] C:\WINDOWS\tasks\SA.DAT
    [05/08/2004 14:00][-rah-----] C:\WINDOWS\tasks\desktop.ini

    --------------------\\ Listing des dossiers dans C:\Program Files

    [30/05/2008|01:05] C:\Program Files\Adobe
    [30/05/2008|11:03] C:\Program Files\Alwil Software
    [30/05/2008|01:05] C:\Program Files\Analog Devices
    [30/05/2008|01:05] C:\Program Files\AOL 9.0
    [30/05/2008|01:05] C:\Program Files\AOL Compagnon
    [05/06/2008|09:17] C:\Program Files\ArcSoft
    [02/08/2008|19:15] C:\Program Files\Avira
    [05/06/2008|09:15] C:\Program Files\Canon
    [03/08/2008|14:45] C:\Program Files\CCleaner
    [30/05/2008|01:05] C:\Program Files\ComPlus Applications
    [30/05/2008|01:05] C:\Program Files\CONEXANT
    [30/05/2008|01:05] C:\Program Files\CyberLink
    [03/08/2008|15:18] C:\Program Files\Fichiers communs
    [04/06/2008|14:47] C:\Program Files\Google
    [05/06/2008|09:17] C:\Program Files\InstallShield Installation Information
    [21/07/2008|20:39] C:\Program Files\Internet Explorer
    [30/07/2008|20:12] C:\Program Files\Java
    [30/05/2008|01:05] C:\Program Files\Learn2.com
    [21/07/2008|17:42] C:\Program Files\ma-config.com
    [31/07/2008|23:17] C:\Program Files\Malwarebytes' Anti-Malware
    [29/05/2008|17:58] C:\Program Files\Messenger
    [30/07/2008|20:32] C:\Program Files\Microsoft Bootvis
    [21/07/2008|20:32] C:\Program Files\Microsoft CAPICOM 2.1.0.2
    [30/05/2008|01:05] C:\Program Files\microsoft frontpage
    [29/05/2008|17:01] C:\Program Files\Movie Maker
    [30/07/2008|22:43] C:\Program Files\Mozilla Firefox
    [30/05/2008|01:05] C:\Program Files\MSN
    [30/05/2008|01:05] C:\Program Files\MSN Gaming Zone
    [21/07/2008|20:10] C:\Program Files\MSXML 4.0
    [29/05/2008|16:58] C:\Program Files\NetMeeting
    [30/05/2008|01:09] C:\Program Files\Online Services
    [30/05/2008|10:58] C:\Program Files\OpenOffice.org 2.4
    [29/05/2008|16:58] C:\Program Files\Outlook Express
    [21/07/2008|20:56] C:\Program Files\Panda Security
    [30/05/2008|01:09] C:\Program Files\QuickTime
    [30/05/2008|01:05] C:\Program Files\Real
    [30/05/2008|01:10] C:\Program Files\Services en ligne
    [30/05/2008|01:10] C:\Program Files\SiS VGA Utilities V3.68
    [30/05/2008|01:10] C:\Program Files\sisagp
    [30/05/2008|01:05] C:\Program Files\Sonic
    [30/05/2008|01:05] C:\Program Files\Synaptics
    [03/08/2008|14:41] C:\Program Files\Trend Micro
    [30/05/2008|01:05] C:\Program Files\Uninstall Information
    [02/08/2008|18:39] C:\Program Files\Unlocker
    [30/05/2008|01:05] C:\Program Files\Viewpoint
    [02/08/2008|21:11] C:\Program Files\VirginMega
    [30/05/2008|10:04] C:\Program Files\Windows Live
    [02/08/2008|21:01] C:\Program Files\Windows Media Connect 2
    [02/08/2008|21:01] C:\Program Files\Windows Media Player
    [29/05/2008|16:58] C:\Program Files\Windows NT
    [30/05/2008|01:05] C:\Program Files\WindowsUpdate
    [30/05/2008|10:52] C:\Program Files\WinRAR
    [30/05/2008|01:05] C:\Program Files\xerox

    --------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

    [30/05/2008|01:05] C:\Program Files\Fichiers communs\Adobe
    [30/05/2008|01:07] C:\Program Files\Fichiers communs\AOL
    [30/05/2008|01:07] C:\Program Files\Fichiers communs\aolshare
    [30/05/2008|01:05] C:\Program Files\Fichiers communs\InstallShield
    [30/05/2008|01:05] C:\Program Files\Fichiers communs\Java
    [30/05/2008|10:04] C:\Program Files\Fichiers communs\Microsoft Shared
    [05/08/2004|14:00] C:\Program Files\Fichiers communs\Mozilla Shared
    [30/05/2008|01:05] C:\Program Files\Fichiers communs\MSSoap
    [30/05/2008|01:05] C:\Program Files\Fichiers communs\Nullsoft
    [30/05/2008|01:05] C:\Program Files\Fichiers communs\ODBC
    [30/05/2008|01:05] C:\Program Files\Fichiers communs\Real
    [30/05/2008|01:07] C:\Program Files\Fichiers communs\Services
    [30/05/2008|01:07] C:\Program Files\Fichiers communs\Sonic Shared
    [30/05/2008|01:05] C:\Program Files\Fichiers communs\SpeechEngines
    [30/05/2008|01:07] C:\Program Files\Fichiers communs\SureThing Shared
    [19/07/2008|14:29] C:\Program Files\Fichiers communs\Symantec Shared
    [29/05/2008|16:58] C:\Program Files\Fichiers communs\System
    [30/05/2008|10:07] C:\Program Files\Fichiers communs\WindowsLiveInstaller
    [30/05/2008|01:05] C:\Program Files\Fichiers communs\xing shared

    --------------------\\ Process

    ( 37 Processus )

    iexplore.exe ~ [2124]

    --------------------\\ Recherche avec S_Lop

    Aucun fichier / dossier Lop trouvé !

    --------------------\\ Recherche de Fichiers / Dossiers Lop

    Aucun fichier / dossier Lop trouvé !

    --------------------\\ Verification du Registre

    ..... OK !

    --------------------\\ Verification du fichier Hosts

    Fichier Hosts PROPRE

    --------------------\\ Recherche de fichiers avec Catchme

    catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-08-03 15:41:32
    Windows 5.1.2600 Service Pack 3 NTFS
    scanning hidden processes ...
    scanning hidden files ...
    scan completed successfully
    hidden processes: 0
    hidden files: 0

    --------------------\\ Recherche d'autres infections

    Aucune autre infection trouvée !

    [F:13][D:0]-> C:\DOCUME~1\ARBARNI\Cookies
    [F:92][D:4]-> C:\DOCUME~1\ARBARNI\LOCALS~1\TEMPOR~1\content.IE5

    --------------------\\ Fin du rapport a 15:42:05,04


    SDFix


    [b]SDFix: Version 1.209 /b
    Run by ARBARNI on 03/08/2008 at 15:50

    Microsoft Windows XP [version 5.1.2600]
    Running From: C:\DOCUME~1\ARBARNI\Bureau\CHASSE~1\SDFix

    [b]Checking Services /b:

    Restoring Default Security Values
    Restoring Default Hosts File

    Rebooting

    [b]Checking Files /b:

    No Trojan Files Found

    Removing Temp Files

    [b]ADS Check /b:

    [b]Final Check /b:

    catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-08-03 16:09:24
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden services & system hive ...

    scanning hidden registry entries ...

    scanning hidden files ...

    scan completed successfully
    hidden processes: 0
    hidden services: 0
    hidden files: 0

    [b]Remaining Services /b:

    Authorized Application Key Export:

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%ProgramFiles%\\AOL 9.0\\aol.exe"="%ProgramFiles%\\AOL 9.0\\aol.exe:*:Enabled:AOL"
    "%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"="%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe:*:Enabled:SPLINTER CELL PANDORA"
    "%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"="%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe:*:Enabled:PANDORA"
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\\APPS\\Inventime\\my.exe"="C:\\APPS\\Inventime\\my.exe:*:Enabled:INVENTIME"
    "C:\\APPS\\skype\\phone\\Skype.exe"="C:\\APPS\\skype\\phone\\Skype.exe:*:Enabled:Skype"
    "C:\\APPS\\Powercinema\\PowerCinema.exe"="C:\\APPS\\Powercinema\\PowerCinema.exe:*:Enabled:PowerCinema"
    "C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
    "C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
    "C:\\Program Files\\AOL 9.0\\waol.exe"="C:\\Program Files\\AOL 9.0\\waol.exe:*:Enabled:AOL"
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "C:\\Program Files\\ma-config.com\\maconfservice.exe"="C:\\Program Files\\ma-config.com\\maconfservice.exe:LocalSubNet:Enabled:maconfservice"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL"
    "C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL"
    "C:\\Program Files\\AOL 9.0\\waol.exe"="C:\\Program Files\\AOL 9.0\\waol.exe:*:Enabled:AOL"
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

    [b]Remaining Files /b:

    [b]Files with Hidden Attributes /b:

    Mon 24 Oct 2005 215 A.SHR --- "C:\BOOT.BAK"
    Tue 31 May 2005 54,384 A..H. --- "C:\Program Files\AOL 9.0\aolphx.exe"
    Tue 31 May 2005 156,784 A..H. --- "C:\Program Files\AOL 9.0\aoltray.exe"
    Tue 31 May 2005 31,344 A..H. --- "C:\Program Files\AOL 9.0\RBM.exe"
    Mon 14 Mar 2005 299,008 A..H. --- "C:\Program Files\Canon\MP Navigator 2.0\Maint.exe"
    Mon 25 Apr 2005 61,440 A..H. --- "C:\Program Files\Canon\MP Navigator 2.0\uinstrsc.dll"
    Sat 2 Aug 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
    Fri 30 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\8171d23d6d072d8b50d065ca55a754fb\BIT1.tmp"
    Tue 31 May 2005 106,496 A..H. --- "C:\Program Files\Fichiers communs\aolshare\shell\fr\shellext.dll"

    [b]Finished!/b



    et HijackThis

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 16:17:06, on 03/08/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16674)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
    c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
    C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
    c:\APPS\HIDSERVICE\HIDSERVICE.exe
    C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\system32\svchost.exe
    c:\APPS\Powercinema\Kernel\TV\CLSched.exe
    C:\WINDOWS\system32\notepad.exe
    C:\WINDOWS\ATK0100\HControl.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    C:\Apps\Powercinema\PCMService.exe
    C:\Program Files\Unlocker\UnlockerAssistant.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\sistray.exe
    C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
    C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
    C:\WINDOWS\ATK0100\ATKOSD.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Documents and Settings\ARBARNI\Bureau\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.google.fr/?gws_rd=ssl
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: (no name) - {92E5DF6B-D89A-4103-AC7B-F3F10ADB2A47} - C:\DOCUME~1\ARBARNI\LOCALS~1\Temp\dmE.dll (file missing)
    O2 - BHO: (no name) - {957C849E-DA93-42F4-948B-E7E20208E0D6} - c:\windows\system32\ylroxhk.dll (file missing)
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
    O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
    O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
    O17 - HKLM\System\CCS\Services\Tcpip\..\{A8AAE048-74CC-46B3-A3D2-041C5967FC68}: NameServer = 192.168.1.1
    O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
    O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
    O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
    O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
    O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
    O23 - Service: MySqlInventime - Unknown owner - c:\mysql\bin\mysqld-max-nt.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    0
  12. g!rly Messages postés 18462 Statut Contributeur 407
     
    ok

    Copie le texte ci-dessous :

    File::
    C:\WINDOWS\system32\Drivers\Winva71.sys
    C:\WINDOWS\system32\drivers\Bjg46.sys
    C:\WINDOWS\system32\drivers\pavboot.sys

    Folder::
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
    C:\Program Files\Viewpoint

    Driver::
    Winva71
    Bjg46
    pavboot

    Ouvre le Bloc-Notes puis colle le texte copié.
    (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
    Sauvegarde ce fichier sous le nom de CFScript.txt.

    Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :

    http://sd-1.archive-host.com/membres/up/1366464061/CFScript.gif

    Cela va relancer Combofix,

    Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

    Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

    Ne touche à rien tant que le scan n'est pas terminé.

    Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.

    S'il n'y a pas de rédémarrage, poste quand même les rapports.

    @+
    0
  13. K3RB3ROS Messages postés 66 Statut Membre
     
    et hop !

    ComboFix

    ComboFix 08-08-02.01 - ARBARNI 2008-08-03 16:44:51.4 - NTFSx86
    Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.626 [GMT 2:00]
    Endroit: C:\Documents and Settings\ARBARNI\Bureau\Chasse aux virus\ComboFix.exe
    Command switches used :: C:\Documents and Settings\ARBARNI\Bureau\CFScript.txt
    * Création d'un nouveau point de restauration

    FILE ::
    C:\WINDOWS\system32\drivers\Bjg46.sys
    C:\WINDOWS\system32\drivers\pavboot.sys
    C:\WINDOWS\system32\Drivers\Winva71.sys
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint\Viewpoint Experience Technology\MetaStreamConfig.ini
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint\Viewpoint Experience Technology\MetaStreamID.ini
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_00\-672059697.swf
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_00\-681648789.swf
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_00\-716026614.swf
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_00\URLCache.ini
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_01\-1588488936.swf
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_01\-1697589072.swf
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_01\1024896942.swf
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_01\1136233701.swf
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_01\290547230.swf
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_01\URLCache.ini
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_02\-207333975.mtx
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_02\346840136.mtx
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_02\648662744.swf
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_02\URLCache.ini
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_03\-299234580.swf
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_03\-347626359.swf
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_03\2091149108.swf
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint\Viewpoint Experience Technology\Resources\ResourceFolder_03\URLCache.ini
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint\Viewpoint Experience Technology\UserShell\AOL9\FLFBootStrap.mtx
    C:\DOCUME~1\ALLUSE~1\APPLIC~1\Viewpoint\Viewpoint Experience Technology\UserShell\AOL9Plus\FLFBootStrap.mtx
    C:\Program Files\Viewpoint
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\AxMetaStream.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\ClassIDs.ini
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\ComponentMgr.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\MetaStreamID.ini
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\MtsAxInstaller.exe
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\AOLArt.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\AOLShell.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\AOLUserShell.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\Cursors.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\DataTracking.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\GifReader.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\JpegReader.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\LensFlares.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\Mts3Reader.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\ObjectMovie.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\SceneComponent.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\ServiceComponent.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\SreeDMMX.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\SWFView.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\VectorView.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\VMPAudio.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\VMPExtras.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\VMPSpeech.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\VMPVideo.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\WaveletReader.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\NewComponents\ZoomView.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
    C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.xpt
    C:\WINDOWS\system32\drivers\Bjg46.sys
    C:\WINDOWS\system32\drivers\pavboot.sys

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_BJG46
    -------\Legacy_PAVBOOT
    -------\Legacy_WINVA71
    -------\Service_Bjg46
    -------\Service_pavboot
    -------\Service_Winva71

    ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-07-03 to 2008-08-03 ))))))))))))))))))))))))))))))))))))
    .

    2008-08-03 15:39 . 2008-08-03 15:42 <REP> d-------- C:\Lop SD
    2008-08-03 14:45 . 2008-08-03 14:45 <REP> d-------- C:\Program Files\CCleaner
    2008-08-02 21:11 . 2008-08-02 21:11 <REP> d-------- C:\Program Files\VirginMega
    2008-08-02 21:09 . 2008-08-02 21:09 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
    2008-08-02 21:01 . 2008-08-02 21:01 <REP> d-------- C:\Program Files\Windows Media Connect 2
    2008-08-02 20:59 . 2008-08-02 21:00 <REP> d-------- C:\WINDOWS\system32\drivers\UMDF
    2008-08-02 19:15 . 2008-08-02 19:15 <REP> d-------- C:\Program Files\Avira
    2008-08-02 19:15 . 2008-08-02 19:15 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
    2008-08-02 18:39 . 2008-08-02 18:39 <REP> d-------- C:\Program Files\Unlocker
    2008-08-02 18:39 . 2008-08-02 18:39 <REP> d-------- C:\Documents and Settings\ARBARNI\Application Data\Desktopicon
    2008-08-01 02:45 . 2008-08-01 02:45 579,584 --a------ C:\WINDOWS\system32\dllcache\user32.dll
    2008-08-01 02:42 . 2008-08-01 02:42 <REP> d-------- C:\WINDOWS\ERUNT
    2008-08-01 02:19 . 2008-08-01 02:19 1,882 --a------ C:\WINDOWS\system32\tmp.reg
    2008-07-30 22:06 . 2008-07-30 22:44 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
    2008-07-30 20:20 . 2008-07-30 20:32 <REP> d-------- C:\Program Files\Microsoft Bootvis
    2008-07-30 19:57 . 2008-06-20 13:51 361,600 --------- C:\WINDOWS\system32\dllcache\tcpip.sys
    2008-07-30 19:57 . 2008-06-20 19:47 247,808 --------- C:\WINDOWS\system32\dllcache\mswsock.dll
    2008-07-30 19:57 . 2008-06-20 13:08 225,856 --------- C:\WINDOWS\system32\dllcache\tcpip6.sys
    2008-07-30 19:57 . 2008-06-20 19:47 147,968 --------- C:\WINDOWS\system32\dllcache\dnsapi.dll
    2008-07-30 19:57 . 2008-06-20 13:40 138,496 --------- C:\WINDOWS\system32\dllcache\afd.sys
    2008-07-22 11:05 . 2008-07-22 11:05 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Malwarebytes
    2008-07-22 11:03 . 2008-05-30 01:05 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage r‚seau
    2008-07-22 11:03 . 2008-05-30 01:05 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
    2008-07-22 11:03 . 2008-05-30 01:08 <REP> d--h----- C:\Documents and Settings\Administrateur\ModŠles
    2008-07-22 11:03 . 2008-05-30 01:08 <REP> dr------- C:\Documents and Settings\Administrateur\Mes documents
    2008-07-22 11:03 . 2008-05-30 01:08 <REP> dr------- C:\Documents and Settings\Administrateur\Menu D‚marrer
    2008-07-22 11:03 . 2008-05-30 01:08 <REP> dr------- C:\Documents and Settings\Administrateur\Favoris
    2008-07-22 11:03 . 2008-07-22 12:53 <REP> dr------- C:\Documents and Settings\Administrateur\Bureau
    2008-07-22 11:03 . 2008-05-30 01:05 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\You've Got Pictures Screensaver
    2008-07-22 11:03 . 2008-05-30 01:05 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Symantec
    2008-07-22 11:03 . 2008-07-22 11:03 <REP> d-------- C:\Documents and Settings\Administrateur
    2008-07-22 08:18 . 2008-07-31 23:17 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-07-22 08:18 . 2008-07-22 08:18 <REP> d-------- C:\Documents and Settings\ARBARNI\Application Data\Malwarebytes
    2008-07-22 08:18 . 2008-07-22 08:18 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-07-22 08:18 . 2008-07-30 20:07 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
    2008-07-22 08:18 . 2008-07-30 20:07 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
    2008-07-21 22:45 . 2008-08-03 14:41 <REP> d-------- C:\Program Files\Trend Micro
    2008-07-21 20:56 . 2008-07-21 20:56 <REP> d-------- C:\Program Files\Panda Security
    2008-07-21 20:38 . 2008-06-14 19:33 272,768 --------- C:\WINDOWS\system32\dllcache\bthport.sys
    2008-07-21 20:36 . 2008-04-23 06:16 6,066,176 --------- C:\WINDOWS\system32\dllcache\ieframe.dll
    2008-07-21 20:36 . 2007-04-17 11:32 2,455,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dat
    2008-07-21 20:36 . 2007-03-08 07:10 1,048,576 --------- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
    2008-07-21 20:36 . 2008-04-23 06:16 459,264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll
    2008-07-21 20:36 . 2008-04-23 06:16 383,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll
    2008-07-21 20:36 . 2008-04-23 06:16 267,776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll
    2008-07-21 20:36 . 2008-04-23 06:16 63,488 --------- C:\WINDOWS\system32\dllcache\icardie.dll
    2008-07-21 20:36 . 2008-04-23 06:16 52,224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
    2008-07-21 20:36 . 2008-04-22 09:39 13,824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe
    2008-07-21 20:35 . 2008-05-09 12:55 180,224 --------- C:\WINDOWS\system32\dllcache\scrobj.dll
    2008-07-21 20:35 . 2008-05-09 12:55 172,032 --------- C:\WINDOWS\system32\dllcache\scrrun.dll
    2008-07-21 20:35 . 2008-05-08 13:24 155,648 --------- C:\WINDOWS\system32\dllcache\wscript.exe
    2008-07-21 20:35 . 2008-05-09 10:45 135,168 --------- C:\WINDOWS\system32\dllcache\cscript.exe
    2008-07-21 20:35 . 2008-05-09 12:55 90,112 --------- C:\WINDOWS\system32\dllcache\wshext.dll
    2008-07-21 20:33 . 2008-05-07 07:11 1,294,336 --------- C:\WINDOWS\system32\dllcache\quartz.dll
    2008-07-21 20:32 . 2008-07-21 20:32 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
    2008-07-21 20:13 . 2008-05-08 16:02 203,136 --------- C:\WINDOWS\system32\dllcache\rmcast.sys
    2008-07-21 20:10 . 2008-07-21 20:10 <REP> d-------- C:\Program Files\MSXML 4.0
    2008-07-21 17:42 . 2008-07-21 17:42 <REP> d-------- C:\Program Files\ma-config.com
    2008-07-21 17:42 . 2008-07-21 17:42 <REP> d-------- C:\Documents and Settings\All Users\Application Data\ma-config.com
    2008-07-09 20:42 . 2001-09-30 19:10 246,784 --a------ C:\WINDOWS\system32\ActiveSkin.ocx
    2008-07-09 20:42 . 2001-05-24 12:59 162,304 --a------ C:\UNWISE.EXE
    2008-07-09 20:42 . 2002-01-18 18:12 112 --a------ C:\WINDOWS\ActiveSkin.INI

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-08-03 14:12 --------- d-----w C:\Documents and Settings\ARBARNI\Application Data\OpenOffice.org2
    2008-07-30 18:12 --------- d-----w C:\Program Files\Java
    2008-07-19 12:29 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
    2008-06-20 17:47 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
    2008-06-20 16:56 --------- d-----w C:\Documents and Settings\ARBARNI\Application Data\AdobeUM
    2008-06-20 11:51 361,600 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
    2008-06-20 11:40 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
    2008-06-20 11:08 225,856 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
    2008-06-14 17:33 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
    2008-06-05 07:20 --------- d--h--w C:\Documents and Settings\All Users\Application Data\CanonBJ
    2008-06-05 07:17 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-06-05 07:17 --------- d-----w C:\Program Files\ArcSoft
    2008-06-05 07:15 --------- d-----w C:\Program Files\Canon
    2008-06-04 12:47 --------- d-----w C:\Program Files\Google
    2008-05-09 10:55 90,112 ----a-w C:\WINDOWS\system32\wshext.dll
    2008-05-09 10:55 512,000 ------w C:\WINDOWS\system32\dllcache\jscript.dll
    2008-05-09 10:55 430,080 ----a-w C:\WINDOWS\system32\vbscript.dll
    2008-05-09 10:55 430,080 ------w C:\WINDOWS\system32\dllcache\vbscript.dll
    2008-05-09 10:55 180,224 ----a-w C:\WINDOWS\system32\scrobj.dll
    2008-05-09 10:55 172,032 ----a-w C:\WINDOWS\system32\scrrun.dll
    2008-05-09 08:45 135,168 ----a-w C:\WINDOWS\system32\cscript.exe
    2008-05-08 11:24 155,648 ----a-w C:\WINDOWS\system32\wscript.exe
    2008-05-07 05:11 1,294,336 ----a-w C:\WINDOWS\system32\quartz.dll
    .

    ((((((((((((((((((((((((((((( snapshot@2008-08-03_15.19.53.78 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2008-08-01 00:42:37 3,084,288 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0/u0000001\NTUSER.DAT
    + 2008-08-03 13:47:42 3,084,288 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0/u0000001\NTUSER.DAT
    - 2008-08-01 00:42:38 163,840 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0/u0000002\UsrClass.dat
    + 2008-08-03 13:47:42 163,840 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0/u0000002\UsrClass.dat
    .
    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{92E5DF6B-D89A-4103-AC7B-F3F10ADB2A47}]
    C:\DOCUME~1\ARBARNI\LOCALS~1\Temp\dmE.dll [BU]

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{957C849E-DA93-42F4-948B-E7E20208E0D6}]
    c:\windows\system32\ylroxhk.dll [BU]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-14 04:34 1695232]
    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-06-04 14:47 171448]
    "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2004-11-22 08:18 307200]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 04:33 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2005-07-28 21:29 102400]
    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-05-11 21:03 708697]
    "SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 09:11 1388544]
    "PCMService"="c:\Apps\Powercinema\PCMService.exe" [2005-05-11 13:48 127118]
    "UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2008-05-02 06:15 15872]
    "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
    "SiSPower"="SiSPower.dll" [2005-07-13 02:55 49152 C:\WINDOWS\system32\SiSPower.dll]

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001
    "AntiVirusOverride"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%ProgramFiles%\\AOL 9.0\\aol.exe"=
    "%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
    "%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\APPS\\Inventime\\my.exe"=
    "C:\\APPS\\skype\\phone\\Skype.exe"=
    "C:\\APPS\\Powercinema\\PowerCinema.exe"=
    "C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDial.exe"=
    "C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLacsd.exe"=
    "C:\\Program Files\\AOL 9.0\\waol.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=

    R0 qhvloatj;qhvloatj;C:\WINDOWS\system32\drivers\qhvloatj.sys [2004-08-05 14:00]
    R3 ASNDIS5;ASNDIS5 Protocol Driver;C:\WINDOWS\ATK0100\ASNDIS5.SYS [2004-05-28 10:13]
    R3 HSFHWSIS;HSFHWSIS;C:\WINDOWS\system32\DRIVERS\HSFHWSIS.sys [2005-06-22 14:50]
    R3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys [2004-11-05 16:43]
    R3 ZD1211U(ASUS);ASUS ZD1211 IEEE 802.11b+g Wireless LAN Driver (USB)(ASUS);C:\WINDOWS\system32\DRIVERS\zd1211u.sys [2005-09-08 09:41]
    S3 maconfservice;Ma-Config Service;C:\Program Files\ma-config.com\maconfservice.exe [2008-06-26 09:13]
    S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 20:45]
    S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 20:45]
    .
    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-08-03 16:49:21
    Windows 5.1.2600 Service Pack 3 NTFS

    Balayage processus cach‚s ...

    Balayage cach‚ autostart entries ...

    Balayage des fichiers cach‚s ...

    Scan termin‚ avec succŠs
    Les fichiers cach‚s: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySqlInventime]
    "ImagePath"="c:\mysql\bin\mysqld-max-nt MySqlInventime"
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
    C:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
    C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
    C:\APPS\HIDSERVICE\HidService.exe
    C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\APPS\Powercinema\Kernel\TV\CLSched.exe
    C:\WINDOWS\system32\sistray.exe
    C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
    C:\Program Files\OpenOffice.org 2.4\program\soffice.bin
    C:\WINDOWS\ATK0100\ATKOSD.exe
    .
    **************************************************************************
    .
    Temps d'accomplissement: 2008-08-03 16:52:22 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-08-03 14:52:13
    ComboFix2.txt 2008-08-03 13:20:21
    ComboFix3.txt 2008-08-03 11:34:34

    Pre-Run: 41,265,467,392 octets libres
    Post-Run: 41,253,199,872 octets libres

    260 --- E O F --- 2008-08-03 12:55:22

    et Hijack

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 16:53:56, on 03/08/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16674)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
    c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
    C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
    c:\APPS\HIDSERVICE\HIDSERVICE.exe
    C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\system32\svchost.exe
    c:\APPS\Powercinema\Kernel\TV\CLSched.exe
    C:\WINDOWS\ATK0100\HControl.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    C:\Apps\Powercinema\PCMService.exe
    C:\Program Files\Unlocker\UnlockerAssistant.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\sistray.exe
    C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
    C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\ATK0100\ATKOSD.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Documents and Settings\ARBARNI\Bureau\Chasse aux virus\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.google.fr/?gws_rd=ssl
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: (no name) - {92E5DF6B-D89A-4103-AC7B-F3F10ADB2A47} - C:\DOCUME~1\ARBARNI\LOCALS~1\Temp\dmE.dll (file missing)
    O2 - BHO: (no name) - {957C849E-DA93-42F4-948B-E7E20208E0D6} - c:\windows\system32\ylroxhk.dll (file missing)
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
    O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
    O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
    O17 - HKLM\System\CCS\Services\Tcpip\..\{A8AAE048-74CC-46B3-A3D2-041C5967FC68}: NameServer = 192.168.1.1
    O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
    O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
    O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
    O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
    O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
    O23 - Service: MySqlInventime - Unknown owner - c:\mysql\bin\mysqld-max-nt.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    0
  14. g!rly Messages postés 18462 Statut Contributeur 407
     
    re

    Vas sur le site https://virusscan.jotti.org/
    - Clic en haut à droite sur "Parcourir", navigue dans les dossiers et sélectionne ce fichier :
    C:\WINDOWS\system32\drivers\qhvloatj.sys
    - Clic sur submit toujours en haut à droite
    - Le scan va se lancer, ça va prendre un petit instant
    - En bas, tu as le résultat du scan, copie/colle le résultat complet du scan ici.
    Aide : https://www.malekal.com/scan-antivirus-ligne-nod32/#mozTocId662799
    0
  15. K3RB3ROS Messages postés 66 Statut Membre
     
    Scan taken on 03 Aug 2008 15:02:15 (GMT)
    A-Squared Found nothing
    AntiVir Found nothing
    ArcaVir Found nothing
    Avast Found nothing
    AVG Antivirus Found nothing
    BitDefender Found nothing
    ClamAV Found nothing
    CPsecure Found nothing
    Dr.Web Found nothing
    F-Prot Antivirus Found nothing
    F-Secure Anti-Virus Found nothing
    Fortinet Found nothing
    Ikarus Found nothing
    Kaspersky Anti-Virus Found nothing
    NOD32 Found nothing
    Norman Virus Control Found nothing
    Panda Antivirus Found nothing
    Sophos Antivirus Found nothing
    VirusBuster Found nothing
    VBA32 Found nothing
    0
  16. g!rly Messages postés 18462 Statut Contributeur 407
     
    ok

    Edit :

    T´as edité le message ?


    celui la tu l´as depuis un moment...

    Copie le texte ci-dessous :

    File::
    C:\WINDOWS\system32\drivers\qhvloatj.sys

    Driver::
    qhvloatj

    Ouvre le Bloc-Notes puis colle le texte copié.
    (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
    Sauvegarde ce fichier sous le nom de CFScript.txt.

    Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :

    http://sd-1.archive-host.com/membres/up/1366464061/CFScript.gif

    Cela va relancer Combofix,

    Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

    Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

    Ne touche à rien tant que le scan n'est pas terminé.

    Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.

    S'il n'y a pas de rédémarrage, poste quand même les rapports.

    @+
    0
  17. K3RB3ROS Messages postés 66 Statut Membre
     
    oui oui jai edit javai mi des trucs en trop....

    ComboFix 08-08-02.01 - ARBARNI 2008-08-03 17:16:11.5 - NTFSx86
    Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.628 [GMT 2:00]
    Endroit: C:\Documents and Settings\ARBARNI\Bureau\Chasse aux virus\ComboFix.exe
    Command switches used :: C:\Documents and Settings\ARBARNI\Bureau\CFScript.txt
    * Création d'un nouveau point de restauration

    FILE ::
    C:\WINDOWS\system32\drivers\qhvloatj.sys
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\WINDOWS\system32\drivers\qhvloatj.sys

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_QHVLOATJ
    -------\Service_qhvloatj

    ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-07-03 to 2008-08-03 ))))))))))))))))))))))))))))))))))))
    .

    2008-08-03 15:39 . 2008-08-03 15:42 <REP> d-------- C:\Lop SD
    2008-08-03 14:45 . 2008-08-03 14:45 <REP> d-------- C:\Program Files\CCleaner
    2008-08-02 21:11 . 2008-08-02 21:11 <REP> d-------- C:\Program Files\VirginMega
    2008-08-02 21:09 . 2008-08-02 21:09 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Downloaded Installations
    2008-08-02 21:01 . 2008-08-02 21:01 <REP> d-------- C:\Program Files\Windows Media Connect 2
    2008-08-02 20:59 . 2008-08-02 21:00 <REP> d-------- C:\WINDOWS\system32\drivers\UMDF
    2008-08-02 19:15 . 2008-08-02 19:15 <REP> d-------- C:\Program Files\Avira
    2008-08-02 19:15 . 2008-08-02 19:15 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
    2008-08-02 18:39 . 2008-08-02 18:39 <REP> d-------- C:\Program Files\Unlocker
    2008-08-02 18:39 . 2008-08-02 18:39 <REP> d-------- C:\Documents and Settings\ARBARNI\Application Data\Desktopicon
    2008-08-01 02:45 . 2008-08-01 02:45 579,584 --a------ C:\WINDOWS\system32\dllcache\user32.dll
    2008-08-01 02:42 . 2008-08-01 02:42 <REP> d-------- C:\WINDOWS\ERUNT
    2008-08-01 02:19 . 2008-08-01 02:19 1,882 --a------ C:\WINDOWS\system32\tmp.reg
    2008-07-30 22:06 . 2008-07-30 22:44 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
    2008-07-30 20:20 . 2008-07-30 20:32 <REP> d-------- C:\Program Files\Microsoft Bootvis
    2008-07-30 19:57 . 2008-06-20 13:51 361,600 --------- C:\WINDOWS\system32\dllcache\tcpip.sys
    2008-07-30 19:57 . 2008-06-20 19:47 247,808 --------- C:\WINDOWS\system32\dllcache\mswsock.dll
    2008-07-30 19:57 . 2008-06-20 13:08 225,856 --------- C:\WINDOWS\system32\dllcache\tcpip6.sys
    2008-07-30 19:57 . 2008-06-20 19:47 147,968 --------- C:\WINDOWS\system32\dllcache\dnsapi.dll
    2008-07-30 19:57 . 2008-06-20 13:40 138,496 --------- C:\WINDOWS\system32\dllcache\afd.sys
    2008-07-22 11:05 . 2008-07-22 11:05 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Malwarebytes
    2008-07-22 11:03 . 2008-05-30 01:05 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage r‚seau
    2008-07-22 11:03 . 2008-05-30 01:05 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
    2008-07-22 11:03 . 2008-05-30 01:08 <REP> d--h----- C:\Documents and Settings\Administrateur\ModŠles
    2008-07-22 11:03 . 2008-05-30 01:08 <REP> dr------- C:\Documents and Settings\Administrateur\Mes documents
    2008-07-22 11:03 . 2008-05-30 01:08 <REP> dr------- C:\Documents and Settings\Administrateur\Menu D‚marrer
    2008-07-22 11:03 . 2008-05-30 01:08 <REP> dr------- C:\Documents and Settings\Administrateur\Favoris
    2008-07-22 11:03 . 2008-07-22 12:53 <REP> dr------- C:\Documents and Settings\Administrateur\Bureau
    2008-07-22 11:03 . 2008-05-30 01:05 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\You've Got Pictures Screensaver
    2008-07-22 11:03 . 2008-05-30 01:05 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Symantec
    2008-07-22 11:03 . 2008-07-22 11:03 <REP> d-------- C:\Documents and Settings\Administrateur
    2008-07-22 08:18 . 2008-07-31 23:17 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-07-22 08:18 . 2008-07-22 08:18 <REP> d-------- C:\Documents and Settings\ARBARNI\Application Data\Malwarebytes
    2008-07-22 08:18 . 2008-07-22 08:18 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-07-22 08:18 . 2008-07-30 20:07 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
    2008-07-22 08:18 . 2008-07-30 20:07 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
    2008-07-21 22:45 . 2008-08-03 14:41 <REP> d-------- C:\Program Files\Trend Micro
    2008-07-21 20:56 . 2008-07-21 20:56 <REP> d-------- C:\Program Files\Panda Security
    2008-07-21 20:38 . 2008-06-14 19:33 272,768 --------- C:\WINDOWS\system32\dllcache\bthport.sys
    2008-07-21 20:36 . 2008-04-23 06:16 6,066,176 --------- C:\WINDOWS\system32\dllcache\ieframe.dll
    2008-07-21 20:36 . 2007-04-17 11:32 2,455,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dat
    2008-07-21 20:36 . 2007-03-08 07:10 1,048,576 --------- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
    2008-07-21 20:36 . 2008-04-23 06:16 459,264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll
    2008-07-21 20:36 . 2008-04-23 06:16 383,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll
    2008-07-21 20:36 . 2008-04-23 06:16 267,776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll
    2008-07-21 20:36 . 2008-04-23 06:16 63,488 --------- C:\WINDOWS\system32\dllcache\icardie.dll
    2008-07-21 20:36 . 2008-04-23 06:16 52,224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
    2008-07-21 20:36 . 2008-04-22 09:39 13,824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe
    2008-07-21 20:35 . 2008-05-09 12:55 180,224 --------- C:\WINDOWS\system32\dllcache\scrobj.dll
    2008-07-21 20:35 . 2008-05-09 12:55 172,032 --------- C:\WINDOWS\system32\dllcache\scrrun.dll
    2008-07-21 20:35 . 2008-05-08 13:24 155,648 --------- C:\WINDOWS\system32\dllcache\wscript.exe
    2008-07-21 20:35 . 2008-05-09 10:45 135,168 --------- C:\WINDOWS\system32\dllcache\cscript.exe
    2008-07-21 20:35 . 2008-05-09 12:55 90,112 --------- C:\WINDOWS\system32\dllcache\wshext.dll
    2008-07-21 20:33 . 2008-05-07 07:11 1,294,336 --------- C:\WINDOWS\system32\dllcache\quartz.dll
    2008-07-21 20:32 . 2008-07-21 20:32 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
    2008-07-21 20:13 . 2008-05-08 16:02 203,136 --------- C:\WINDOWS\system32\dllcache\rmcast.sys
    2008-07-21 20:10 . 2008-07-21 20:10 <REP> d-------- C:\Program Files\MSXML 4.0
    2008-07-21 17:42 . 2008-07-21 17:42 <REP> d-------- C:\Program Files\ma-config.com
    2008-07-21 17:42 . 2008-07-21 17:42 <REP> d-------- C:\Documents and Settings\All Users\Application Data\ma-config.com
    2008-07-09 20:42 . 2001-09-30 19:10 246,784 --a------ C:\WINDOWS\system32\ActiveSkin.ocx
    2008-07-09 20:42 . 2001-05-24 12:59 162,304 --a------ C:\UNWISE.EXE
    2008-07-09 20:42 . 2002-01-18 18:12 112 --a------ C:\WINDOWS\ActiveSkin.INI

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-08-03 15:21 --------- d-----w C:\Documents and Settings\ARBARNI\Application Data\OpenOffice.org2
    2008-07-30 18:12 --------- d-----w C:\Program Files\Java
    2008-07-19 12:29 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
    2008-06-20 17:47 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
    2008-06-20 16:56 --------- d-----w C:\Documents and Settings\ARBARNI\Application Data\AdobeUM
    2008-06-20 11:51 361,600 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
    2008-06-20 11:40 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
    2008-06-20 11:08 225,856 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
    2008-06-14 17:33 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
    2008-06-05 07:20 --------- d--h--w C:\Documents and Settings\All Users\Application Data\CanonBJ
    2008-06-05 07:17 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-06-05 07:17 --------- d-----w C:\Program Files\ArcSoft
    2008-06-05 07:15 --------- d-----w C:\Program Files\Canon
    2008-06-04 12:47 --------- d-----w C:\Program Files\Google
    2008-05-09 10:55 90,112 ----a-w C:\WINDOWS\system32\wshext.dll
    2008-05-09 10:55 512,000 ------w C:\WINDOWS\system32\dllcache\jscript.dll
    2008-05-09 10:55 430,080 ----a-w C:\WINDOWS\system32\vbscript.dll
    2008-05-09 10:55 430,080 ------w C:\WINDOWS\system32\dllcache\vbscript.dll
    2008-05-09 10:55 180,224 ----a-w C:\WINDOWS\system32\scrobj.dll
    2008-05-09 10:55 172,032 ----a-w C:\WINDOWS\system32\scrrun.dll
    2008-05-09 08:45 135,168 ----a-w C:\WINDOWS\system32\cscript.exe
    2008-05-08 11:24 155,648 ----a-w C:\WINDOWS\system32\wscript.exe
    2008-05-07 05:11 1,294,336 ----a-w C:\WINDOWS\system32\quartz.dll
    .

    ((((((((((((((((((((((((((((( snapshot@2008-08-03_15.19.53.78 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2008-08-01 00:42:37 3,084,288 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0/u0000001\NTUSER.DAT
    + 2008-08-03 13:47:42 3,084,288 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0/u0000001\NTUSER.DAT
    - 2008-08-01 00:42:38 163,840 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0/u0000002\UsrClass.dat
    + 2008-08-03 13:47:42 163,840 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\[u]0/u0000002\UsrClass.dat
    .
    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{92E5DF6B-D89A-4103-AC7B-F3F10ADB2A47}]
    C:\DOCUME~1\ARBARNI\LOCALS~1\Temp\dmE.dll [BU]

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{957C849E-DA93-42F4-948B-E7E20208E0D6}]
    c:\windows\system32\ylroxhk.dll [BU]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-14 04:34 1695232]
    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-06-04 14:47 171448]
    "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2004-11-22 08:18 307200]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 04:33 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2005-07-28 21:29 102400]
    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-05-11 21:03 708697]
    "SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 09:11 1388544]
    "PCMService"="c:\Apps\Powercinema\PCMService.exe" [2005-05-11 13:48 127118]
    "UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2008-05-02 06:15 15872]
    "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-10-24 15:20 98304]
    "SiSPower"="SiSPower.dll" [2005-07-13 02:55 49152 C:\WINDOWS\system32\SiSPower.dll]

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001
    "AntiVirusOverride"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%ProgramFiles%\\AOL 9.0\\aol.exe"=
    "%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
    "%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\APPS\\Inventime\\my.exe"=
    "C:\\APPS\\skype\\phone\\Skype.exe"=
    "C:\\APPS\\Powercinema\\PowerCinema.exe"=
    "C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLDial.exe"=
    "C:\\Program Files\\Fichiers communs\\AOL\\ACS\\AOLacsd.exe"=
    "C:\\Program Files\\AOL 9.0\\waol.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=

    R3 ASNDIS5;ASNDIS5 Protocol Driver;C:\WINDOWS\ATK0100\ASNDIS5.SYS [2004-05-28 10:13]
    R3 HSFHWSIS;HSFHWSIS;C:\WINDOWS\system32\DRIVERS\HSFHWSIS.sys [2005-06-22 14:50]
    R3 SISNICXP;SiS PCI Fast Ethernet Adapter Driver for NDIS51;C:\WINDOWS\system32\DRIVERS\sisnicxp.sys [2004-11-05 16:43]
    R3 ZD1211U(ASUS);ASUS ZD1211 IEEE 802.11b+g Wireless LAN Driver (USB)(ASUS);C:\WINDOWS\system32\DRIVERS\zd1211u.sys [2005-09-08 09:41]
    S3 maconfservice;Ma-Config Service;C:\Program Files\ma-config.com\maconfservice.exe [2008-06-26 09:13]
    S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 20:45]
    S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 20:45]

    *Newly Created Service* - QHVLOATJ
    .
    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-08-03 17:20:09
    Windows 5.1.2600 Service Pack 3 NTFS

    Balayage processus cach‚s ...

    Balayage cach‚ autostart entries ...

    Balayage des fichiers cach‚s ...

    Scan termin‚ avec succŠs
    Les fichiers cach‚s: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySqlInventime]
    "ImagePath"="c:\mysql\bin\mysqld-max-nt MySqlInventime"
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
    C:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
    C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
    C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
    C:\APPS\HIDSERVICE\HidService.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\APPS\Powercinema\Kernel\TV\CLSched.exe
    C:\WINDOWS\system32\sistray.exe
    C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
    C:\Program Files\OpenOffice.org 2.4\program\soffice.bin
    C:\WINDOWS\ATK0100\ATKOSD.exe
    .
    **************************************************************************
    .
    Temps d'accomplissement: 2008-08-03 17:22:52 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-08-03 15:22:47
    ComboFix2.txt 2008-08-03 14:52:24
    ComboFix3.txt 2008-08-03 13:20:21
    ComboFix4.txt 2008-08-03 11:34:34

    Pre-Run: 41,237,176,320 octets libres
    Post-Run: 41,233,936,384 octets libres

    203 --- E O F --- 2008-08-03 12:55:22

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 17:23:31, on 03/08/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16674)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
    c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
    C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
    C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
    c:\APPS\HIDSERVICE\HIDSERVICE.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    C:\WINDOWS\system32\svchost.exe
    c:\APPS\Powercinema\Kernel\TV\CLSched.exe
    C:\WINDOWS\ATK0100\HControl.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    C:\Apps\Powercinema\PCMService.exe
    C:\Program Files\Unlocker\UnlockerAssistant.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\sistray.exe
    C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
    C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
    C:\WINDOWS\ATK0100\ATKOSD.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Documents and Settings\ARBARNI\Bureau\Chasse aux virus\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.google.fr/?gws_rd=ssl
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: (no name) - {92E5DF6B-D89A-4103-AC7B-F3F10ADB2A47} - C:\DOCUME~1\ARBARNI\LOCALS~1\Temp\dmE.dll (file missing)
    O2 - BHO: (no name) - {957C849E-DA93-42F4-948B-E7E20208E0D6} - c:\windows\system32\ylroxhk.dll (file missing)
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
    O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
    O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
    O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
    O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
    O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
    O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
    O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
    O17 - HKLM\System\CCS\Services\Tcpip\..\{A8AAE048-74CC-46B3-A3D2-041C5967FC68}: NameServer = 192.168.1.1
    O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
    O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
    O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
    O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
    O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
    O23 - Service: MySqlInventime - Unknown owner - c:\mysql\bin\mysqld-max-nt.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    0
  18. g!rly Messages postés 18462 Statut Contributeur 407
     
    ok

    bon

    essaie de fixer ces lignes maintenant :

    O2 - BHO: (no name) - {92E5DF6B-D89A-4103-AC7B-F3F10ADB2A47} - C:\DOCUME~1\ARBARNI\LOCALS~1\Temp\dmE.dll (file missing)
    O2 - BHO: (no name) - {957C849E-DA93-42F4-948B-E7E20208E0D6} - c:\windows\system32\ylroxhk.dll (file missing)
    0
  19. K3RB3ROS Messages postés 66 Statut Membre
     
    oulalala...
    il serait peut être temps que je réponde moi...

    c'est bon, tout marche parfaitement :)
    encore merci a toi Gurly !
    0
Précédent
  • 1
  • 2
  • 3