Tray_cd.exe - Page 3

Précédent
  • 1
  • 2
  • 3
  1. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 325
     
    Faut faire la procédure avec CFScript même si la désinstallation des traces de Norton a supprimé tes problèmes.
    0
  2. mircka
     
    euh mais j'ai pas utilisé le script, merci beaucoup quand meme mais je pense que c est pas la peine que je l utilise vu que tout marche comme avant... hourra je vous aime
    0
  3. mircka
     
    ah il faut que je fasse ce que tu ma demandé a ton avis destrio5 ?
    0
  4. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 325
     
    Oui bien sûr.
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. mircka
     
    ComboFix 08-08-21.02 - Cédric 2008-08-23 19:09:23.2 - NTFSx86
    Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.698 [GMT 2:00]
    Endroit: D:\Documents and Settings\Cédric.SN049180320674\Bureau\ComboFix.exe
    Command switches used :: D:\Documents and Settings\Cédric.SN049180320674\Bureau\CFScript.txt
    * Création d'un nouveau point de restauration

    FILE ::
    C:\WINDOWS\system32\temp\scarface.exe
    .

    ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-07-23 to 2008-08-23 ))))))))))))))))))))))))))))))))))))
    .

    2066-11-19 02:25 . 2008-08-17 16:01 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
    2066-11-19 02:25 . 2008-08-17 16:01 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
    2066-11-19 02:00 . 2066-11-19 03:21 <REP> d--h----- C:\WINDOWS\system32\temp
    2008-08-13 22:24 . 2008-05-01 16:31 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll
    2008-08-07 12:09 . 2008-08-07 12:09 54,156 --ah----- C:\WINDOWS\QTFont.qfn
    2008-08-07 12:09 . 2008-08-07 12:09 1,409 --a------ C:\WINDOWS\QTFont.for
    2008-08-03 16:46 . 2006-11-10 19:23 61,600 -ra------ C:\WINDOWS\system32\drivers\SE2Ebus.sys
    2008-08-03 16:46 . 2006-11-10 19:24 5,872 -ra------ C:\WINDOWS\system32\drivers\SE2Ewhnt.sys
    2008-08-03 16:46 . 2006-11-10 19:24 5,872 -ra------ C:\WINDOWS\system32\drivers\SE2Ewh.sys

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2066-11-19 00:25 --------- d-----w D:\Documents and Settings\All Users\Application Data\Malwarebytes
    2066-11-19 00:25 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
    2066-11-19 00:01 --------- d-----w C:\Program Files\CleanUp!
    2066-11-19 00:00 --------- d-----w C:\Program Files\Ahead
    2008-08-23 10:44 --------- d-----w C:\Program Files\eMule
    2008-08-02 14:38 --------- d-----w C:\Program Files\Java
    2008-07-22 19:48 --------- d-----w C:\Program Files\ETAJV PC
    .

    ((((((((((((((((((((((((((((( snapshot@2008-08-23_18.40.13.51 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2066-11-19 00:00:10 52,900 ----a-w C:\WINDOWS\system32\perfc009.dat
    + 2008-08-23 16:55:09 52,900 ----a-w C:\WINDOWS\system32\perfc009.dat
    - 2066-11-19 00:00:10 63,854 ----a-w C:\WINDOWS\system32\perfc00C.dat
    + 2008-08-23 16:55:09 63,854 ----a-w C:\WINDOWS\system32\perfc00C.dat
    - 2066-11-19 00:00:10 380,486 ----a-w C:\WINDOWS\system32\perfh009.dat
    + 2008-08-23 16:55:09 380,486 ----a-w C:\WINDOWS\system32\perfh009.dat
    - 2066-11-19 00:00:10 445,434 ----a-w C:\WINDOWS\system32\perfh00C.dat
    + 2008-08-23 16:55:09 445,434 ----a-w C:\WINDOWS\system32\perfh00C.dat
    + 2008-08-23 17:12:06 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_5a4.dat
    .
    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ACTIVBOARD"="c:\apps\ABoard\ABoard.exe" [2003-05-02 11:31 24576]
    "PCMService"="c:\Apps\Powercinema\PCMService.exe" [2005-05-11 14:48 127118]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 15:00 15360]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "msacm.dvacm"= C:\PROGRA~1\FICHIE~1\ULEADS~1\Vio\Dvacm.acm
    "msacm.ulmp3acm"= C:\PROGRA~1\FICHIE~1\ULEADS~1\MPEG\ulmp3acm.acm
    "msacm.mpegacm "= C:\PROGRA~1\FICHIE~1\ULEADS~1\MPEG\mpegacm.acm
    "VIDC.MJPG"= pvmjpg21.dll

    [HKLM\~\startupfolder\D:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
    path=D:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
    backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
    --a------ 2005-03-22 22:05 339968 C:\ATI Technologies\ATI Control Panel\atiptaxx.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Easy-PrintToolBox]
    --a------ 2004-01-14 03:10 409600 C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
    --a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OM_Monitor]
    --a------ 2005-06-02 16:14 40960 C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
    -ra------ 2006-11-24 02:06 487424 C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%ProgramFiles%\\AOL 9.0\\aol.exe"=
    "%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
    "%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\APPS\\Inventime\\my.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
    "C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
    "C:\\Program Files\\AOL 9.0\\waol.exe"=
    "C:\\Program Files\\TribalWeb\\tribalweb.exe"=
    "C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
    "C:\\Program Files\\Fritivi\\fritivi.exe"=
    "C:\\Program Files\\Fritivi\\Fritivi_Pip.exe"=
    "C:\\Program Files\\eMule\\emule.exe"=
    "C:\\Program Files\\DMV\\MaxTV\\MaxTV.exe"=
    "D:\\jeux\\LucasArts\\Jedi Knight\\JK.EXE"=

    R0 SI3112r;ATI-437A Serial ATA Controller;C:\WINDOWS\system32\DRIVERS\SI3112r.sys [2004-08-27 17:18]
    R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 16:35]
    R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 16:37]
    R3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2005-05-27 13:51]
    R3 snpstd2;GE 98067 MiniCam Pro;C:\WINDOWS\system32\DRIVERS\snpstd2.sys [2004-12-16 19:14]
    R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 00:08]
    S3 SE2Ebus;Sony Ericsson Device 046 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\SE2Ebus.sys [2006-11-10 19:23]
    .

    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-08-23 19:12:23
    Windows 5.1.2600 Service Pack 2 NTFS

    Balayage processus cach‚s ...

    Balayage cach‚ autostart entries ...

    Balayage des fichiers cach‚s ...

    Scan termin‚ avec succŠs
    Les fichiers cach‚s: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MysqlInventime]
    "ImagePath"="C:\Apps\INVENT~1\mysql\bin\mysqld-nt --defaults-file=C:\Apps\Inventime\mysql\my.ini MysqlInventime"
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\WINDOWS\system32\ati2evxx.exe
    C:\WINDOWS\system32\ati2evxx.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\APPS\ABOARD\AOSD.EXE
    C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
    C:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
    C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
    C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
    C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
    C:\WINDOWS\system32\wdfmgr.exe
    C:\APPS\Powercinema\Kernel\TV\CLSched.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    .
    **************************************************************************
    .
    Temps d'accomplissement: 2008-08-23 19:15:30 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-08-23 17:15:28
    ComboFix2.txt 2008-08-23 16:40:28

    Pre-Run: 26,118,295,552 octets libres
    Post-Run: 26,104,942,592 octets libres

    136 --- E O F --- 2008-08-13 21:10:06
    0
  7. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 325
     
    Plus de problème ?
    0
  8. Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 325
     
    ---> Tu peux supprimer HijackThis, ComboFix, CFScript et le dossier Qoobox situé dans C:\

    ---> Je te conseille de faire un scan rapide avec MBAM :
    http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.htm
    0
Précédent
  • 1
  • 2
  • 3