Bagle, sans doute ;)
Résolu
tylooo1
Messages postés
27
Statut
Membre
-
PIF -
PIF -
Bonjour,
voila j'ai un problème lié à la sécurité de mon pc,il m'est impossible d'activermon windefender ainsi que mon pare feu et tous ce qui est du domaine de protection.Lorsque j'essaie d'activer windefender j ai un bref message d erreur qui disparait quasi instantanement, impossible d'activer spyboot, ccleaner,avastet d'installer un logiciel de verification (accé refusé) ect...
J ai donc besoin de votre aide merci
voila j'ai un problème lié à la sécurité de mon pc,il m'est impossible d'activermon windefender ainsi que mon pare feu et tous ce qui est du domaine de protection.Lorsque j'essaie d'activer windefender j ai un bref message d erreur qui disparait quasi instantanement, impossible d'activer spyboot, ccleaner,avastet d'installer un logiciel de verification (accé refusé) ect...
J ai donc besoin de votre aide merci
A voir également:
- Bagle, sans doute ;)
- Mail chronopost, doute si fraude ou non - Forum Consommation & Internet
- (Faux) virus .bat et GROS DOUTE !!!!! HELP ME PLZ !!!! :( ✓ - Forum Virus
- Doute sur une transaction en mandat cash ✓ - Forum Vos droits sur internet
- Un doute sur la capacité de mémoire pc ✓ - Forum Matériel & Système
- Doute présence virus : rapport ZHPDIAG à comprendre - Forum Antivirus
24 réponses
ComboFix 08-08-27.05 - Cyrille 2008-08-28 15:11:19.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2200 [GMT 2:00]
Endroit: C:\Users\Cyrille\Downloads\ComboFix.exe
Command switches used :: C:\Users\Cyrille\Desktop\CFScript.txt
* Création d'un nouveau point de restauration
FILE ::
C:\Windows\_MSRSTRT.EXE
C:\ntdetect.com :#:
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Conduit
C:\Program Files\Conduit\Community Alerts\Alert.dll
C:\Program Files\Secured eMule
C:\Program Files\Secured eMule\secp.exe
C:\Program Files\securedie
C:\Program Files\securedie\INSTALL.LOG
C:\Program Files\securedie\tbsecu.dll
C:\Program Files\securedie\toolbar.cfg
C:\Program Files\securedie\UNWISE.EXE
C:\Windows\_MSRSTRT.EXE
.
---- Previous Run -------
.
C:\Program Files\PCHealthCenter
C:\Program Files\PCHealthCenter\[u]0/u.exe
C:\Program Files\PCHealthCenter\[u]0/u.gif
C:\Program Files\PCHealthCenter\1.gif
C:\Program Files\PCHealthCenter\2.gif
C:\Program Files\PCHealthCenter\3.gif
C:\Program Files\PCHealthCenter\sc.html
C:\Program Files\PCHealthCenter\sex1.ico
C:\Program Files\PCHealthCenter\sex2.ico
C:\Users\Cyrille\AppData\Local\mceguuo.dat
C:\Users\Cyrille\AppData\Local\mceguuo.exe
C:\Users\Cyrille\AppData\Local\mceguuo_nav.dat
C:\Users\Cyrille\AppData\Local\mceguuo_navps.dat
C:\Windows\eqbx.exe
C:\Windows\system32\aeeadae7_z.dll
C:\Windows\system32\bfbnsdpi.ini
C:\Windows\system32\fwcomgif.ini
C:\Windows\system32\gddgsxkd.ini
C:\Windows\system32\lirkwkmf.ini
C:\Windows\system32\olvhpmng.ini
C:\Windows\system32\rtl60.bpl
C:\Windows\system32\vnplpiey.ini
C:\Windows\system32\xxxnphmn.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SROSA
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-07-28 to 2008-08-28 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier cr‚‚ dans cet espace de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-28 14:04 --------- d-----w C:\Users\Cyrille\AppData\Roaming\DNA
2008-08-28 12:51 --------- d-----w C:\Program Files\CCleaner
2008-08-28 11:33 --------- d-----w C:\ProgramData\Avira
2008-08-28 11:33 --------- d-----w C:\Program Files\Avira
2008-08-28 11:28 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-28 11:27 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-08-28 11:22 --------- d-----w C:\Program Files\Trend Micro
2008-08-28 05:32 --------- d-----w C:\ProgramData\Google Updater
2008-08-28 00:52 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-28 00:47 --------- d-----w C:\Program Files\Norton Security Scan
2008-08-28 00:44 --------- d-----w C:\Program Files\Rockstar Games
2008-08-27 23:23 --------- d-----w C:\ProgramData\Lavasoft
2008-08-26 19:30 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Azureus
2008-08-25 22:03 --------- d-----w C:\Program Files\Microsoft Virtual PC
2008-08-25 22:01 --------- d-----w C:\ProgramData\avg8
2008-08-25 21:57 --------- d-----w C:\Program Files\eChanblard
2008-08-24 14:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-24 14:38 --------- d-----w C:\Users\Cyrille\AppData\Roaming\InstallShield
2008-08-23 10:07 --------- d-----w C:\Users\Cyrille\AppData\Roaming\BitTorrent
2008-08-22 21:02 --------- d---a-w C:\ProgramData\TEMP
2008-08-20 22:27 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-14 15:23 --------- d-----w C:\Program Files\BitTorrent
2008-08-14 15:22 --------- d-----w C:\Program Files\DNA
2008-08-13 10:01 --------- d-----w C:\Program Files\Windows Mail
2008-08-13 08:47 --------- d-----w C:\ProgramData\Microsoft Help
2008-08-11 20:48 --------- d-----w C:\Users\Cyrille\AppData\Roaming\PeerNetworking
2008-08-09 22:11 --------- d-----w C:\ProgramData\Downloaded Installations
2008-08-09 09:07 --------- d-----w C:\ProgramData\WindowsSearch
2008-08-09 00:02 --------- d-----w C:\Program Files\DAEMON Tools Lite
2008-08-07 22:55 --------- d-----w C:\Program Files\Runtime Software
2008-08-07 19:26 --------- d-----w C:\Program Files\Google
2008-08-06 11:56 --------- d-----w C:\ProgramData\Media Center Programs
2008-08-05 10:30 --------- d-----w C:\Program Files\CyberLink
2008-08-03 10:34 --------- d-----w C:\Program Files\Ubisoft
2008-08-01 15:10 0 ---ha-w C:\Windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-07-29 15:57 --------- d-----w C:\Program Files\FTPExpert
2008-07-28 00:32 --------- d-----w C:\Program Files\Common Files\AVSMedia
2008-07-28 00:13 --------- d-----w C:\Users\Cyrille\AppData\Roaming\STOIK
2008-07-25 22:21 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Acronis
2008-07-25 13:31 --------- d-----w C:\ProgramData\Acronis
2008-07-25 13:30 441,760 ----a-w C:\Windows\system32\drivers\timntr.sys
2008-07-25 13:30 44,384 ----a-w C:\Windows\system32\drivers\tifsfilt.sys
2008-07-25 13:30 368,480 ----a-w C:\Windows\system32\drivers\tdrpman.sys
2008-07-25 13:30 132,224 ----a-w C:\Windows\system32\drivers\snapman.sys
2008-07-25 13:30 --------- d-----w C:\Program Files\Common Files\Acronis
2008-07-25 13:30 --------- d-----w C:\Program Files\Acronis
2008-07-25 13:25 --------- d-----w C:\Program Files\AviSynth 2.5
2008-07-23 13:27 --------- d-----w C:\Program Files\SoftwarePassport
2008-07-23 13:26 --------- d-----w C:\Program Files\Mindscape
2008-07-22 21:41 131,072 ----a-r C:\Windows\System32\VMSB1.BIN
2008-07-22 21:41 131,072 ----a-r C:\Windows\System32\VMS.BIN
2008-07-22 11:34 --------- d-----w C:\Program Files\IZArc
2008-07-22 11:09 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-07-21 18:08 --------- d-----w C:\ProgramData\InstallShield
2008-07-21 18:07 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-07-19 23:50 --------- d-----w C:\Program Files\OpenOffice.org 2.4
2008-07-19 23:49 --------- d-----w C:\Program Files\Java
2008-07-19 23:48 --------- d-----w C:\Users\Cyrille\AppData\Roaming\LimeWire
2008-07-18 23:47 --------- d-----w C:\Program Files\Common Files\Java
2008-07-18 18:39 587,264 ---ha-w C:\Windows\WLXPGSS.SCR
2008-07-16 01:32 2,048 ----a-w C:\Windows\System32\tzres.dll
2008-07-15 10:43 --------- d-----w C:\Program Files\SlySoft
2008-07-14 14:48 --------- d-----w C:\Users\Cyrille\AppData\Roaming\GRETECH
2008-07-14 14:48 --------- d-----w C:\ProgramData\GRETECH
2008-07-14 14:47 --------- d-----w C:\Program Files\GRETECH
2008-07-12 20:38 --------- d-----w C:\Program Files\Creative
2008-07-12 20:37 --------- d-----w C:\Program Files\Mafia
2008-07-11 22:13 --------- d-----w C:\Program Files\Piratrax
2008-07-11 18:02 --------- dc----w C:\Program Files\Common Files\WindowsLiveInstaller
2008-07-11 18:02 --------- d-----w C:\Program Files\Pcsx2_0.9.4
2008-07-11 17:41 --------- d-----w C:\Users\Cyrille\AppData\Roaming\BSplayer
2008-07-11 17:31 --------- d-----w C:\Program Files\Registry Easy
2008-07-11 15:31 --------- d-----w C:\Program Files\Common Files\Adobe AIR
2008-07-11 14:39 --------- d-----w C:\Users\Cyrille\AppData\Roaming\BSplayer Pro
2008-07-10 23:37 --------- d-----w C:\Users\Cyrille\AppData\Roaming\fltk.org
2008-07-10 22:35 --------- d-----w C:\Program Files\RomStation
2008-07-10 09:16 --------- d-----w C:\Users\Cyrille\AppData\Roaming\InterTrust
2008-07-10 09:16 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-09 18:08 --------- d-----w C:\ProgramData\Ubisoft
2008-07-09 11:27 --------- d-----w C:\Program Files\MSBuild
2008-07-09 11:27 --------- d-----w C:\Program Files\Microsoft Works
2008-07-09 11:26 --------- d-----w C:\Program Files\Microsoft.NET
2008-07-09 00:17 --------- d-----w C:\ProgramData\Symantec
2008-07-08 16:30 --------- d-----w C:\Program Files\FolderSize
2008-07-08 12:32 --------- d-----w C:\Program Files\Defraggler
2008-07-07 23:16 --------- d-----w C:\ProgramData\Yahoo! Companion
2008-07-07 23:12 --------- d-----w C:\Program Files\Yahoo!
2008-07-07 23:00 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Auslogics
2008-07-07 23:00 --------- d-----w C:\Program Files\Auslogics
2008-07-07 21:47 --------- d-----w C:\Program Files\Project64 1.6
2008-07-07 18:23 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Download Manager
2008-07-05 09:26 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Uniblue
2008-07-03 18:47 107,888 ----a-w C:\Windows\System32\CmdLineExt.dll
2008-07-03 18:29 --------- d-----w C:\Program Files\KONAMI
2008-07-03 14:04 --------- d-----w C:\Users\Cyrille\AppData\Roaming\ESTsoft
2008-07-03 14:04 --------- d-----w C:\Program Files\ESTsoft
2008-07-02 15:45 --------- d-----w C:\Users\Cyrille\AppData\Roaming\ImgBurn
2008-07-02 10:56 --------- d-----w C:\Users\Cyrille\AppData\Roaming\ErrorSmart
2008-07-02 10:43 --------- d-----w C:\Program Files\Azureus
2008-07-02 08:34 --------- d-----w C:\Program Files\Common Files\Logitech
.
((((((((((((((((((((((((((((( snapshot@2008-08-28_14.26.40.11 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-08-28 12:23:38 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-08-28 14:19:47 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-08-28 14:19:47 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2008-08-28 12:23:38 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-08-28 14:19:57 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-08-28 14:19:57 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-08-28 11:07:50 101,052 ----a-w C:\Windows\System32\perfc009.dat
+ 2008-08-28 14:13:45 101,052 ----a-w C:\Windows\System32\perfc009.dat
- 2008-08-28 11:07:50 123,350 ----a-w C:\Windows\System32\perfc00C.dat
+ 2008-08-28 14:13:45 123,350 ----a-w C:\Windows\System32\perfc00C.dat
- 2008-08-28 11:07:50 586,980 ----a-w C:\Windows\System32\perfh009.dat
+ 2008-08-28 14:13:45 586,980 ----a-w C:\Windows\System32\perfh009.dat
- 2008-08-28 11:07:50 669,328 ----a-w C:\Windows\System32\perfh00C.dat
+ 2008-08-28 14:13:45 669,328 ----a-w C:\Windows\System32\perfh00C.dat
- 2008-08-28 10:21:50 8,706 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2583701152-1007577926-4045379130-1000_UserData.bin
+ 2008-08-28 13:03:04 8,918 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2583701152-1007577926-4045379130-1000_UserData.bin
- 2008-08-28 11:05:16 69,916 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-08-28 13:03:03 70,358 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-08-28 11:05:11 49,026 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-08-28 13:03:03 49,830 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 09:33 125952]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UpdateService\isuspm.exe" [2004-08-09 06:03 221184]
"mceguuo"="c:\users\cyrille\appdata\local\mceguuo.exe" [BU]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-08-14 17:22 341824]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 16:33 563984]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 16:37 2178832]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2008-04-23 01:52 2616512]
"AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" [2008-04-22 22:02 909096]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [2008-04-22 19:26 136472]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 03:01 32768]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [BU]
"avast!"="C:\Program Files\Alwil Software\Avast4\ashDisp.exe" [2008-08-28 12:42 75392]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 14:28 266497]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 relog_ap
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2583701152-1007577926-4045379130-1000]
"EnableNotificationsRef"=dword:00000005
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{43D61948-2FC2-452E-838C-C25AAE296EC1}C:\\users\\cyrille\\desktop\\windows.old\\program files\\echanblard\\emule.exe"= UDP:C:\users\cyrille\desktop\windows.old\program files\echanblard\emule.exe:eMule
"UDP Query User{2342DF4A-153D-4830-9C23-0C3C4645E7A4}C:\\users\\cyrille\\desktop\\windows.old\\program files\\echanblard\\emule.exe"= TCP:C:\users\cyrille\desktop\windows.old\program files\echanblard\emule.exe:eMule
"{7079FD9A-53B0-4EA8-B925-4E1A3A992DD6}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{62A2CDC3-7680-44CD-BB01-E95B2A5D6588}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{9C6DA761-0EB3-4810-B019-01E03B5725E4}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
"TCP Query User{0D43D2C3-E070-42B7-9AC7-E5032EB92840}C:\\program files\\echanblard\\emule.exe"= UDP:C:\program files\echanblard\emule.exe:eMule
"UDP Query User{E10AE7DB-CA15-4A3C-ACE1-FC43B85C0FB5}C:\\program files\\echanblard\\emule.exe"= TCP:C:\program files\echanblard\emule.exe:eMule
"{7B128BC2-3370-4EE9-8A83-EFFFBB69D5B3}"= UDP:443:TCP port 443 ooVoo
"{F7156248-62DA-4ED5-BB7B-CEACAC555968}"= TCP:443:UDP port 443 ooVoo
"{56144CB5-78C5-4244-8D6A-B1D8572E18BB}"= UDP:37674:TCP port 37674 ooVoo
"{5E17F1AE-ABE1-4605-9F88-BC5E204052E1}"= TCP:37674:UDP port 37674 ooVoo
"{DC1748BA-253F-4712-AA6A-BBE29F948CD6}"= TCP:37675:UDP port 37675 ooVoo
"TCP Query User{54CF68EC-BBD5-4934-ABDA-5B2F46C14945}C:\\program files\\oovoo\\oovoo.exe"= UDP:C:\program files\oovoo\oovoo.exe:ooVoo
"UDP Query User{59DC3A1F-E9ED-4A07-8FC8-F51AE997B755}C:\\program files\\oovoo\\oovoo.exe"= TCP:C:\program files\oovoo\oovoo.exe:ooVoo
"TCP Query User{A833043F-809A-4EA7-A161-364CF42D3F38}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus
"UDP Query User{F54341D5-414A-481E-BA1A-4614A7C7F54A}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus
"{56C5105B-0218-4F53-9C09-1CE3CCAC1985}"= UDP:C:\Program Files\DNA\btdna.exe:DNA
"{533237A3-47BB-4BA7-9F17-DACE5A4858DD}"= TCP:C:\Program Files\DNA\btdna.exe:DNA
"{EC19D54E-7FBD-4F60-A93F-F6E44C23095A}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{E9A6FC66-8627-498F-B919-06EC708C0CA9}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{E152F4BB-2D84-41E9-9839-E11C643BD5A3}C:\\users\\cyrille\\program files\\dna\\btdna.exe"= UDP:C:\users\cyrille\program files\dna\btdna.exe:btdna.exe
"UDP Query User{5414075E-02BB-4EEE-AD54-93EFC6C2E07B}C:\\users\\cyrille\\program files\\dna\\btdna.exe"= TCP:C:\users\cyrille\program files\dna\btdna.exe:btdna.exe
"{EF3DC8C4-97DA-406F-B03B-FECFDE85339B}"= UDP:C:\Users\Cyrille\Desktop\PES2008\PES2008.exe:Pro Evolution Soccer 2008
"{9F6B3A59-7009-4043-8144-3266EBB3C92B}"= TCP:C:\Users\Cyrille\Desktop\PES2008\PES2008.exe:Pro Evolution Soccer 2008
"{8B2BCDC4-6CEF-465B-B84A-7220170199D1}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{A3215C7B-3E1D-4C62-A655-17F002FFF498}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"TCP Query User{5E356094-14A8-49E8-8ABC-C8B2F40ADF55}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{C3A23C3B-4971-411E-9BBD-AA6B41E04A12}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
"TCP Query User{776116FA-A024-4AA7-9F66-8C236BAFB58F}C:\\program files\\echanblard\\emule.exe"= UDP:C:\program files\echanblard\emule.exe:eMule
"UDP Query User{A39051B9-2DE9-4144-B971-DD0C66A89475}C:\\program files\\echanblard\\emule.exe"= TCP:C:\program files\echanblard\emule.exe:eMule
"TCP Query User{39EBCCC4-9CE8-4A93-9013-CF1C387629BC}C:\\users\\cyrille\\appdata\\local\\emule\\emule.exe"= UDP:C:\users\cyrille\appdata\local\emule\emule.exe:emule.exe
"UDP Query User{A235952F-1E04-4DE8-AB59-74BC28E8DC9B}C:\\users\\cyrille\\appdata\\local\\emule\\emule.exe"= TCP:C:\users\cyrille\appdata\local\emule\emule.exe:emule.exe
"{E5769D4F-0E2B-4322-895A-1157D46E4F36}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{E4C6AA67-AF67-4F26-8FCE-6E1368E040C9}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{FCE88D98-9C06-4116-BEB9-F41580EA5D3A}C:\\users\\cyrille\\program files\\bittorrent\\bittorrent.exe"= UDP:C:\users\cyrille\program files\bittorrent\bittorrent.exe:bittorrent.exe
"UDP Query User{C91B18AF-60AB-4054-AD66-F704FE73B35B}C:\\users\\cyrille\\program files\\bittorrent\\bittorrent.exe"= TCP:C:\users\cyrille\program files\bittorrent\bittorrent.exe:bittorrent.exe
"{1B5AD8FD-D1EF-486F-8DCB-1AF27C1BC9EE}"= UDP:C:\Program Files\DNA\btdna.exe:DNA (TCP-In)
"{421C8B02-767B-48FF-AF09-14E63734AEF0}"= TCP:C:\Program Files\DNA\btdna.exe:DNA (UDP-In)
"{40737326-508B-40B2-A9CA-B2D38F7E2CF3}"= UDP:C:\Users\Cyrille\Desktop\Jeux pc\PES2008.exe:Pro Evolution Soccer 2008
"{650F0099-5465-410D-9B77-D0ECC8D809F7}"= TCP:C:\Users\Cyrille\Desktop\Jeux pc\PES2008.exe:Pro Evolution Soccer 2008
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R0 tdrpman;Acronis Try&Decide and Restore Points filter;C:\Windows\system32\DRIVERS\tdrpman.sys [2008-07-25 15:30]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2007-04-30 17:39]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\Windows\system32\drivers\LMIRfsDriver.sys [2008-03-07 13:39]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R2 TryAndDecideService;Acronis Try And Decide Service;C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe [2008-04-23 02:22]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-06-27 04:00]
S2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5a8ebe45-5394-11dd-aa14-001d60b428b0}]
\shell\AutoRun\command - K:\autorun.exe
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
2008-06-21 C:\Windows\Tasks\Norton Security Scan.job
- C:\Program Files\Norton Security Scan\Nss.exe [2007-09-18 23:42]
2008-07-03 C:\Windows\Tasks\Schedule Task Weekly.job
- C:\Program Files\Registry Easy\RE.exe []
.
- - - - ORPHANS REMOVED - - - -
SSODL-okmdepgb-{CF9E9AE5-8725-4630-977C-D8CCC4735B60} - (no file)
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-28 17:03:57
Windows 6.0.6001 Service Pack 1 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
C:\Users\Cyrille\AppData\Local\Microsoft\Portable Devices\wpdlog02.sqm 472 bytes
C:\Users\Cyrille\AppData\Local\Microsoft\Portable Devices\wpdlog03.sqm 472 bytes
Scan termin‚ avec succŠs
Les fichiers cach‚s: 2
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\System32\Ati2evxx.exe
C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
C:\Windows\System32\audiodg.exe
C:\Windows\System32\Ati2evxx.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\FolderSize\FolderSizeSvc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files\Windows Defender\MpCmdRun.exe
C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\wbem\unsecapp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe
C:\Windows\System32\dllhost.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-08-28 17:06:05 - machine was rebooted [Cyrille]
ComboFix-quarantined-files.txt 2008-08-28 15:06:00
Pre-Run: Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
Post-Run: 277,661,507,584 octets libres
318 --- E O F --- 2008-08-23 23:09:01
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2200 [GMT 2:00]
Endroit: C:\Users\Cyrille\Downloads\ComboFix.exe
Command switches used :: C:\Users\Cyrille\Desktop\CFScript.txt
* Création d'un nouveau point de restauration
FILE ::
C:\Windows\_MSRSTRT.EXE
C:\ntdetect.com :#:
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\Conduit
C:\Program Files\Conduit\Community Alerts\Alert.dll
C:\Program Files\Secured eMule
C:\Program Files\Secured eMule\secp.exe
C:\Program Files\securedie
C:\Program Files\securedie\INSTALL.LOG
C:\Program Files\securedie\tbsecu.dll
C:\Program Files\securedie\toolbar.cfg
C:\Program Files\securedie\UNWISE.EXE
C:\Windows\_MSRSTRT.EXE
.
---- Previous Run -------
.
C:\Program Files\PCHealthCenter
C:\Program Files\PCHealthCenter\[u]0/u.exe
C:\Program Files\PCHealthCenter\[u]0/u.gif
C:\Program Files\PCHealthCenter\1.gif
C:\Program Files\PCHealthCenter\2.gif
C:\Program Files\PCHealthCenter\3.gif
C:\Program Files\PCHealthCenter\sc.html
C:\Program Files\PCHealthCenter\sex1.ico
C:\Program Files\PCHealthCenter\sex2.ico
C:\Users\Cyrille\AppData\Local\mceguuo.dat
C:\Users\Cyrille\AppData\Local\mceguuo.exe
C:\Users\Cyrille\AppData\Local\mceguuo_nav.dat
C:\Users\Cyrille\AppData\Local\mceguuo_navps.dat
C:\Windows\eqbx.exe
C:\Windows\system32\aeeadae7_z.dll
C:\Windows\system32\bfbnsdpi.ini
C:\Windows\system32\fwcomgif.ini
C:\Windows\system32\gddgsxkd.ini
C:\Windows\system32\lirkwkmf.ini
C:\Windows\system32\olvhpmng.ini
C:\Windows\system32\rtl60.bpl
C:\Windows\system32\vnplpiey.ini
C:\Windows\system32\xxxnphmn.ini
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SROSA
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-07-28 to 2008-08-28 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier cr‚‚ dans cet espace de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-28 14:04 --------- d-----w C:\Users\Cyrille\AppData\Roaming\DNA
2008-08-28 12:51 --------- d-----w C:\Program Files\CCleaner
2008-08-28 11:33 --------- d-----w C:\ProgramData\Avira
2008-08-28 11:33 --------- d-----w C:\Program Files\Avira
2008-08-28 11:28 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-28 11:27 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-08-28 11:22 --------- d-----w C:\Program Files\Trend Micro
2008-08-28 05:32 --------- d-----w C:\ProgramData\Google Updater
2008-08-28 00:52 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-28 00:47 --------- d-----w C:\Program Files\Norton Security Scan
2008-08-28 00:44 --------- d-----w C:\Program Files\Rockstar Games
2008-08-27 23:23 --------- d-----w C:\ProgramData\Lavasoft
2008-08-26 19:30 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Azureus
2008-08-25 22:03 --------- d-----w C:\Program Files\Microsoft Virtual PC
2008-08-25 22:01 --------- d-----w C:\ProgramData\avg8
2008-08-25 21:57 --------- d-----w C:\Program Files\eChanblard
2008-08-24 14:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-24 14:38 --------- d-----w C:\Users\Cyrille\AppData\Roaming\InstallShield
2008-08-23 10:07 --------- d-----w C:\Users\Cyrille\AppData\Roaming\BitTorrent
2008-08-22 21:02 --------- d---a-w C:\ProgramData\TEMP
2008-08-20 22:27 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-08-14 15:23 --------- d-----w C:\Program Files\BitTorrent
2008-08-14 15:22 --------- d-----w C:\Program Files\DNA
2008-08-13 10:01 --------- d-----w C:\Program Files\Windows Mail
2008-08-13 08:47 --------- d-----w C:\ProgramData\Microsoft Help
2008-08-11 20:48 --------- d-----w C:\Users\Cyrille\AppData\Roaming\PeerNetworking
2008-08-09 22:11 --------- d-----w C:\ProgramData\Downloaded Installations
2008-08-09 09:07 --------- d-----w C:\ProgramData\WindowsSearch
2008-08-09 00:02 --------- d-----w C:\Program Files\DAEMON Tools Lite
2008-08-07 22:55 --------- d-----w C:\Program Files\Runtime Software
2008-08-07 19:26 --------- d-----w C:\Program Files\Google
2008-08-06 11:56 --------- d-----w C:\ProgramData\Media Center Programs
2008-08-05 10:30 --------- d-----w C:\Program Files\CyberLink
2008-08-03 10:34 --------- d-----w C:\Program Files\Ubisoft
2008-08-01 15:10 0 ---ha-w C:\Windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-07-29 15:57 --------- d-----w C:\Program Files\FTPExpert
2008-07-28 00:32 --------- d-----w C:\Program Files\Common Files\AVSMedia
2008-07-28 00:13 --------- d-----w C:\Users\Cyrille\AppData\Roaming\STOIK
2008-07-25 22:21 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Acronis
2008-07-25 13:31 --------- d-----w C:\ProgramData\Acronis
2008-07-25 13:30 441,760 ----a-w C:\Windows\system32\drivers\timntr.sys
2008-07-25 13:30 44,384 ----a-w C:\Windows\system32\drivers\tifsfilt.sys
2008-07-25 13:30 368,480 ----a-w C:\Windows\system32\drivers\tdrpman.sys
2008-07-25 13:30 132,224 ----a-w C:\Windows\system32\drivers\snapman.sys
2008-07-25 13:30 --------- d-----w C:\Program Files\Common Files\Acronis
2008-07-25 13:30 --------- d-----w C:\Program Files\Acronis
2008-07-25 13:25 --------- d-----w C:\Program Files\AviSynth 2.5
2008-07-23 13:27 --------- d-----w C:\Program Files\SoftwarePassport
2008-07-23 13:26 --------- d-----w C:\Program Files\Mindscape
2008-07-22 21:41 131,072 ----a-r C:\Windows\System32\VMSB1.BIN
2008-07-22 21:41 131,072 ----a-r C:\Windows\System32\VMS.BIN
2008-07-22 11:34 --------- d-----w C:\Program Files\IZArc
2008-07-22 11:09 --------- d-----w C:\Program Files\Microsoft Visual Studio 8
2008-07-21 18:08 --------- d-----w C:\ProgramData\InstallShield
2008-07-21 18:07 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-07-19 23:50 --------- d-----w C:\Program Files\OpenOffice.org 2.4
2008-07-19 23:49 --------- d-----w C:\Program Files\Java
2008-07-19 23:48 --------- d-----w C:\Users\Cyrille\AppData\Roaming\LimeWire
2008-07-18 23:47 --------- d-----w C:\Program Files\Common Files\Java
2008-07-18 18:39 587,264 ---ha-w C:\Windows\WLXPGSS.SCR
2008-07-16 01:32 2,048 ----a-w C:\Windows\System32\tzres.dll
2008-07-15 10:43 --------- d-----w C:\Program Files\SlySoft
2008-07-14 14:48 --------- d-----w C:\Users\Cyrille\AppData\Roaming\GRETECH
2008-07-14 14:48 --------- d-----w C:\ProgramData\GRETECH
2008-07-14 14:47 --------- d-----w C:\Program Files\GRETECH
2008-07-12 20:38 --------- d-----w C:\Program Files\Creative
2008-07-12 20:37 --------- d-----w C:\Program Files\Mafia
2008-07-11 22:13 --------- d-----w C:\Program Files\Piratrax
2008-07-11 18:02 --------- dc----w C:\Program Files\Common Files\WindowsLiveInstaller
2008-07-11 18:02 --------- d-----w C:\Program Files\Pcsx2_0.9.4
2008-07-11 17:41 --------- d-----w C:\Users\Cyrille\AppData\Roaming\BSplayer
2008-07-11 17:31 --------- d-----w C:\Program Files\Registry Easy
2008-07-11 15:31 --------- d-----w C:\Program Files\Common Files\Adobe AIR
2008-07-11 14:39 --------- d-----w C:\Users\Cyrille\AppData\Roaming\BSplayer Pro
2008-07-10 23:37 --------- d-----w C:\Users\Cyrille\AppData\Roaming\fltk.org
2008-07-10 22:35 --------- d-----w C:\Program Files\RomStation
2008-07-10 09:16 --------- d-----w C:\Users\Cyrille\AppData\Roaming\InterTrust
2008-07-10 09:16 --------- d-----w C:\Program Files\Common Files\Adobe
2008-07-09 18:08 --------- d-----w C:\ProgramData\Ubisoft
2008-07-09 11:27 --------- d-----w C:\Program Files\MSBuild
2008-07-09 11:27 --------- d-----w C:\Program Files\Microsoft Works
2008-07-09 11:26 --------- d-----w C:\Program Files\Microsoft.NET
2008-07-09 00:17 --------- d-----w C:\ProgramData\Symantec
2008-07-08 16:30 --------- d-----w C:\Program Files\FolderSize
2008-07-08 12:32 --------- d-----w C:\Program Files\Defraggler
2008-07-07 23:16 --------- d-----w C:\ProgramData\Yahoo! Companion
2008-07-07 23:12 --------- d-----w C:\Program Files\Yahoo!
2008-07-07 23:00 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Auslogics
2008-07-07 23:00 --------- d-----w C:\Program Files\Auslogics
2008-07-07 21:47 --------- d-----w C:\Program Files\Project64 1.6
2008-07-07 18:23 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Download Manager
2008-07-05 09:26 --------- d-----w C:\Users\Cyrille\AppData\Roaming\Uniblue
2008-07-03 18:47 107,888 ----a-w C:\Windows\System32\CmdLineExt.dll
2008-07-03 18:29 --------- d-----w C:\Program Files\KONAMI
2008-07-03 14:04 --------- d-----w C:\Users\Cyrille\AppData\Roaming\ESTsoft
2008-07-03 14:04 --------- d-----w C:\Program Files\ESTsoft
2008-07-02 15:45 --------- d-----w C:\Users\Cyrille\AppData\Roaming\ImgBurn
2008-07-02 10:56 --------- d-----w C:\Users\Cyrille\AppData\Roaming\ErrorSmart
2008-07-02 10:43 --------- d-----w C:\Program Files\Azureus
2008-07-02 08:34 --------- d-----w C:\Program Files\Common Files\Logitech
.
((((((((((((((((((((((((((((( snapshot@2008-08-28_14.26.40.11 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-08-28 12:23:38 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-08-28 14:19:47 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-08-28 14:19:47 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2008-08-28 12:23:38 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-08-28 14:19:57 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-08-28 14:19:57 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-08-28 11:07:50 101,052 ----a-w C:\Windows\System32\perfc009.dat
+ 2008-08-28 14:13:45 101,052 ----a-w C:\Windows\System32\perfc009.dat
- 2008-08-28 11:07:50 123,350 ----a-w C:\Windows\System32\perfc00C.dat
+ 2008-08-28 14:13:45 123,350 ----a-w C:\Windows\System32\perfc00C.dat
- 2008-08-28 11:07:50 586,980 ----a-w C:\Windows\System32\perfh009.dat
+ 2008-08-28 14:13:45 586,980 ----a-w C:\Windows\System32\perfh009.dat
- 2008-08-28 11:07:50 669,328 ----a-w C:\Windows\System32\perfh00C.dat
+ 2008-08-28 14:13:45 669,328 ----a-w C:\Windows\System32\perfh00C.dat
- 2008-08-28 10:21:50 8,706 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2583701152-1007577926-4045379130-1000_UserData.bin
+ 2008-08-28 13:03:04 8,918 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2583701152-1007577926-4045379130-1000_UserData.bin
- 2008-08-28 11:05:16 69,916 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-08-28 13:03:03 70,358 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-08-28 11:05:11 49,026 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-08-28 13:03:03 49,830 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 09:33 125952]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UpdateService\isuspm.exe" [2004-08-09 06:03 221184]
"mceguuo"="c:\users\cyrille\appdata\local\mceguuo.exe" [BU]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-08-14 17:22 341824]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 16:33 563984]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 16:37 2178832]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2008-04-23 01:52 2616512]
"AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" [2008-04-22 22:02 909096]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [2008-04-22 19:26 136472]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 03:01 32768]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [BU]
"avast!"="C:\Program Files\Alwil Software\Avast4\ashDisp.exe" [2008-08-28 12:42 75392]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 14:28 266497]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
"msacm.divxa32"= msaud32_divx.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 relog_ap
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-2583701152-1007577926-4045379130-1000]
"EnableNotificationsRef"=dword:00000005
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{43D61948-2FC2-452E-838C-C25AAE296EC1}C:\\users\\cyrille\\desktop\\windows.old\\program files\\echanblard\\emule.exe"= UDP:C:\users\cyrille\desktop\windows.old\program files\echanblard\emule.exe:eMule
"UDP Query User{2342DF4A-153D-4830-9C23-0C3C4645E7A4}C:\\users\\cyrille\\desktop\\windows.old\\program files\\echanblard\\emule.exe"= TCP:C:\users\cyrille\desktop\windows.old\program files\echanblard\emule.exe:eMule
"{7079FD9A-53B0-4EA8-B925-4E1A3A992DD6}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{62A2CDC3-7680-44CD-BB01-E95B2A5D6588}C:\\program files\\emule\\emule.exe"= UDP:C:\program files\emule\emule.exe:eMule
"UDP Query User{9C6DA761-0EB3-4810-B019-01E03B5725E4}C:\\program files\\emule\\emule.exe"= TCP:C:\program files\emule\emule.exe:eMule
"TCP Query User{0D43D2C3-E070-42B7-9AC7-E5032EB92840}C:\\program files\\echanblard\\emule.exe"= UDP:C:\program files\echanblard\emule.exe:eMule
"UDP Query User{E10AE7DB-CA15-4A3C-ACE1-FC43B85C0FB5}C:\\program files\\echanblard\\emule.exe"= TCP:C:\program files\echanblard\emule.exe:eMule
"{7B128BC2-3370-4EE9-8A83-EFFFBB69D5B3}"= UDP:443:TCP port 443 ooVoo
"{F7156248-62DA-4ED5-BB7B-CEACAC555968}"= TCP:443:UDP port 443 ooVoo
"{56144CB5-78C5-4244-8D6A-B1D8572E18BB}"= UDP:37674:TCP port 37674 ooVoo
"{5E17F1AE-ABE1-4605-9F88-BC5E204052E1}"= TCP:37674:UDP port 37674 ooVoo
"{DC1748BA-253F-4712-AA6A-BBE29F948CD6}"= TCP:37675:UDP port 37675 ooVoo
"TCP Query User{54CF68EC-BBD5-4934-ABDA-5B2F46C14945}C:\\program files\\oovoo\\oovoo.exe"= UDP:C:\program files\oovoo\oovoo.exe:ooVoo
"UDP Query User{59DC3A1F-E9ED-4A07-8FC8-F51AE997B755}C:\\program files\\oovoo\\oovoo.exe"= TCP:C:\program files\oovoo\oovoo.exe:ooVoo
"TCP Query User{A833043F-809A-4EA7-A161-364CF42D3F38}C:\\program files\\azureus\\azureus.exe"= UDP:C:\program files\azureus\azureus.exe:Azureus
"UDP Query User{F54341D5-414A-481E-BA1A-4614A7C7F54A}C:\\program files\\azureus\\azureus.exe"= TCP:C:\program files\azureus\azureus.exe:Azureus
"{56C5105B-0218-4F53-9C09-1CE3CCAC1985}"= UDP:C:\Program Files\DNA\btdna.exe:DNA
"{533237A3-47BB-4BA7-9F17-DACE5A4858DD}"= TCP:C:\Program Files\DNA\btdna.exe:DNA
"{EC19D54E-7FBD-4F60-A93F-F6E44C23095A}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{E9A6FC66-8627-498F-B919-06EC708C0CA9}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{E152F4BB-2D84-41E9-9839-E11C643BD5A3}C:\\users\\cyrille\\program files\\dna\\btdna.exe"= UDP:C:\users\cyrille\program files\dna\btdna.exe:btdna.exe
"UDP Query User{5414075E-02BB-4EEE-AD54-93EFC6C2E07B}C:\\users\\cyrille\\program files\\dna\\btdna.exe"= TCP:C:\users\cyrille\program files\dna\btdna.exe:btdna.exe
"{EF3DC8C4-97DA-406F-B03B-FECFDE85339B}"= UDP:C:\Users\Cyrille\Desktop\PES2008\PES2008.exe:Pro Evolution Soccer 2008
"{9F6B3A59-7009-4043-8144-3266EBB3C92B}"= TCP:C:\Users\Cyrille\Desktop\PES2008\PES2008.exe:Pro Evolution Soccer 2008
"{8B2BCDC4-6CEF-465B-B84A-7220170199D1}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{A3215C7B-3E1D-4C62-A655-17F002FFF498}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"TCP Query User{5E356094-14A8-49E8-8ABC-C8B2F40ADF55}C:\\program files\\limewire\\limewire.exe"= UDP:C:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{C3A23C3B-4971-411E-9BBD-AA6B41E04A12}C:\\program files\\limewire\\limewire.exe"= TCP:C:\program files\limewire\limewire.exe:LimeWire
"TCP Query User{776116FA-A024-4AA7-9F66-8C236BAFB58F}C:\\program files\\echanblard\\emule.exe"= UDP:C:\program files\echanblard\emule.exe:eMule
"UDP Query User{A39051B9-2DE9-4144-B971-DD0C66A89475}C:\\program files\\echanblard\\emule.exe"= TCP:C:\program files\echanblard\emule.exe:eMule
"TCP Query User{39EBCCC4-9CE8-4A93-9013-CF1C387629BC}C:\\users\\cyrille\\appdata\\local\\emule\\emule.exe"= UDP:C:\users\cyrille\appdata\local\emule\emule.exe:emule.exe
"UDP Query User{A235952F-1E04-4DE8-AB59-74BC28E8DC9B}C:\\users\\cyrille\\appdata\\local\\emule\\emule.exe"= TCP:C:\users\cyrille\appdata\local\emule\emule.exe:emule.exe
"{E5769D4F-0E2B-4322-895A-1157D46E4F36}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{E4C6AA67-AF67-4F26-8FCE-6E1368E040C9}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"TCP Query User{FCE88D98-9C06-4116-BEB9-F41580EA5D3A}C:\\users\\cyrille\\program files\\bittorrent\\bittorrent.exe"= UDP:C:\users\cyrille\program files\bittorrent\bittorrent.exe:bittorrent.exe
"UDP Query User{C91B18AF-60AB-4054-AD66-F704FE73B35B}C:\\users\\cyrille\\program files\\bittorrent\\bittorrent.exe"= TCP:C:\users\cyrille\program files\bittorrent\bittorrent.exe:bittorrent.exe
"{1B5AD8FD-D1EF-486F-8DCB-1AF27C1BC9EE}"= UDP:C:\Program Files\DNA\btdna.exe:DNA (TCP-In)
"{421C8B02-767B-48FF-AF09-14E63734AEF0}"= TCP:C:\Program Files\DNA\btdna.exe:DNA (UDP-In)
"{40737326-508B-40B2-A9CA-B2D38F7E2CF3}"= UDP:C:\Users\Cyrille\Desktop\Jeux pc\PES2008.exe:Pro Evolution Soccer 2008
"{650F0099-5465-410D-9B77-D0ECC8D809F7}"= TCP:C:\Users\Cyrille\Desktop\Jeux pc\PES2008.exe:Pro Evolution Soccer 2008
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R0 tdrpman;Acronis Try&Decide and Restore Points filter;C:\Windows\system32\DRIVERS\tdrpman.sys [2008-07-25 15:30]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2007-04-30 17:39]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\Windows\system32\drivers\LMIRfsDriver.sys [2008-03-07 13:39]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
R2 TryAndDecideService;Acronis Try And Decide Service;C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe [2008-04-23 02:22]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-06-27 04:00]
S2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5a8ebe45-5394-11dd-aa14-001d60b428b0}]
\shell\AutoRun\command - K:\autorun.exe
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
2008-06-21 C:\Windows\Tasks\Norton Security Scan.job
- C:\Program Files\Norton Security Scan\Nss.exe [2007-09-18 23:42]
2008-07-03 C:\Windows\Tasks\Schedule Task Weekly.job
- C:\Program Files\Registry Easy\RE.exe []
.
- - - - ORPHANS REMOVED - - - -
SSODL-okmdepgb-{CF9E9AE5-8725-4630-977C-D8CCC4735B60} - (no file)
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-28 17:03:57
Windows 6.0.6001 Service Pack 1 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
C:\Users\Cyrille\AppData\Local\Microsoft\Portable Devices\wpdlog02.sqm 472 bytes
C:\Users\Cyrille\AppData\Local\Microsoft\Portable Devices\wpdlog03.sqm 472 bytes
Scan termin‚ avec succŠs
Les fichiers cach‚s: 2
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\System32\Ati2evxx.exe
C:\Program Files\Common Files\logishrd\LVMVFM\LVPrcSrv.exe
C:\Windows\System32\audiodg.exe
C:\Windows\System32\Ati2evxx.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\FolderSize\FolderSizeSvc.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files\Windows Defender\MpCmdRun.exe
C:\Program Files\Common Files\logishrd\LVCOMSER\LVComSer.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\wbem\unsecapp.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Common Files\logishrd\LQCVFX\COCIManager.exe
C:\Windows\System32\dllhost.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-08-28 17:06:05 - machine was rebooted [Cyrille]
ComboFix-quarantined-files.txt 2008-08-28 15:06:00
Pre-Run: Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
Post-Run: 277,661,507,584 octets libres
318 --- E O F --- 2008-08-23 23:09:01
tu t es trompé de rapport il faut : TCleaner.txt
va dans ordinateur, entre dans le disques c et post le rapport TCleaner.txt ou dis moi si hijackthis combofix ont disparu
va dans ordinateur, entre dans le disques c et post le rapport TCleaner.txt ou dis moi si hijackthis combofix ont disparu
-->- Recherche:
C:\Qoobox: trouvé !
C:\Program Files\Trend Micro\HijackThis: trouvé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
C:\System Volume Information\SystemRestore\FRStaging\ProgramData\Application Data\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
C:\System Volume Information\SystemRestore\FRStaging\ProgramData\Application Data\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
C:\System Volume Information\SystemRestore\FRStaging\ProgramData\Application Data\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
C:\System Volume Information\SystemRestore\FRStaging\ProgramData\Menu Démarrer\Programmes\HijackThis: trouvé !
C:\System Volume Information\SystemRestore\FRStaging\ProgramData\Menu Démarrer\Programs\HijackThis: trouvé !
C:\System Volume Information\SystemRestore\FRStaging\ProgramData\Menu Démarrer\Programs\HijackThis\HijackThis.lnk: trouvé !
C:\System Volume Information\SystemRestore\FRStaging\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
C:\System Volume Information\SystemRestore\FRStaging\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis\HijackThis.lnk: trouvé !
C:\System Volume Information\SystemRestore\FRStaging\ProgramData\Start Menu\Programmes\HijackThis: trouvé !
C:\System Volume Information\SystemRestore\FRStaging\ProgramData\Start Menu\Programs\HijackThis: trouvé !
C:\System Volume Information\SystemRestore\FRStaging\ProgramData\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
C:\Users\All Users\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
C:\Users\Cyrille\Desktop\Raccourcis\HijackThis.lnk: trouvé !
C:\Users\Cyrille\Downloads\ComboFix.exe: trouvé !
C:\Users\Cyrille\Downloads\HJTInstall.exe: trouvé !
---------------------------------
-->- Suppression:
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: supprimé !
C:\Users\Cyrille\Desktop\Raccourcis\HijackThis.lnk: supprimé !
C:\Users\Cyrille\Downloads\ComboFix.exe: Erreur de suppression !
C:\Users\Cyrille\Downloads\HJTInstall.exe: supprimé !
C:\Qoobox: supprimé !
C:\Program Files\Trend Micro\HijackThis: supprimé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: Erreur de suppression !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: supprimé !
C:\Qoobox: trouvé !
C:\Program Files\Trend Micro\HijackThis: trouvé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
C:\System Volume Information\SystemRestore\FRStaging\ProgramData\Application Data\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
C:\System Volume Information\SystemRestore\FRStaging\ProgramData\Application Data\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
C:\System Volume Information\SystemRestore\FRStaging\ProgramData\Application Data\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
C:\System Volume Information\SystemRestore\FRStaging\ProgramData\Menu Démarrer\Programmes\HijackThis: trouvé !
C:\System Volume Information\SystemRestore\FRStaging\ProgramData\Menu Démarrer\Programs\HijackThis: trouvé !
C:\System Volume Information\SystemRestore\FRStaging\ProgramData\Menu Démarrer\Programs\HijackThis\HijackThis.lnk: trouvé !
C:\System Volume Information\SystemRestore\FRStaging\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
C:\System Volume Information\SystemRestore\FRStaging\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis\HijackThis.lnk: trouvé !
C:\System Volume Information\SystemRestore\FRStaging\ProgramData\Start Menu\Programmes\HijackThis: trouvé !
C:\System Volume Information\SystemRestore\FRStaging\ProgramData\Start Menu\Programs\HijackThis: trouvé !
C:\System Volume Information\SystemRestore\FRStaging\ProgramData\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
C:\Users\All Users\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
C:\Users\Cyrille\Desktop\Raccourcis\HijackThis.lnk: trouvé !
C:\Users\Cyrille\Downloads\ComboFix.exe: trouvé !
C:\Users\Cyrille\Downloads\HJTInstall.exe: trouvé !
---------------------------------
-->- Suppression:
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: supprimé !
C:\Users\Cyrille\Desktop\Raccourcis\HijackThis.lnk: supprimé !
C:\Users\Cyrille\Downloads\ComboFix.exe: Erreur de suppression !
C:\Users\Cyrille\Downloads\HJTInstall.exe: supprimé !
C:\Qoobox: supprimé !
C:\Program Files\Trend Micro\HijackThis: supprimé !
C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: Erreur de suppression !
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: supprimé !
si tu n as pas d autres soucis change le statut du sujet en resolu stp
http://www.commentcamarche.net/faq/sujet 11365 marquer un fil de discussion comme etant resolu
http://www.commentcamarche.net/faq/sujet 11365 marquer un fil de discussion comme etant resolu