Infecté par plusieurs virus et trojan
rowane
Messages postés
20
Statut
Membre
-
rowane Messages postés 20 Statut Membre -
rowane Messages postés 20 Statut Membre -
Bonjour,
j'ai besoin d'aide!!! Mon ordinateur portable est infecté par plusieur trojan et virus.
Mon antivirus est avaast ... et mon pare feu est celui de windows.
Voici les divers trojan et virus détecter:
Trojan-clicker.win32.tiny.h
Trojan-spy.html.bankfraud.dq
Trojan-spy.win32.greenscreen
win32:trojan-gen
et sur mon fond d'ecran, maintenant j'ai un warning:
win32/Adware.Virtumonde et
win32/PrivacyRmover.M64
j'espère que quelquun pourra m'apporter son aide je ne sais pas quoi faire ...
Merci de m'apporter votre aide...
j'ai besoin d'aide!!! Mon ordinateur portable est infecté par plusieur trojan et virus.
Mon antivirus est avaast ... et mon pare feu est celui de windows.
Voici les divers trojan et virus détecter:
Trojan-clicker.win32.tiny.h
Trojan-spy.html.bankfraud.dq
Trojan-spy.win32.greenscreen
win32:trojan-gen
et sur mon fond d'ecran, maintenant j'ai un warning:
win32/Adware.Virtumonde et
win32/PrivacyRmover.M64
j'espère que quelquun pourra m'apporter son aide je ne sais pas quoi faire ...
Merci de m'apporter votre aide...
A voir également:
- Infecté par plusieurs virus et trojan
- Virus mcafee - Accueil - Piratage
- Artemis virus - Forum Virus
- Virus informatique - Guide
- Softonic virus ✓ - Forum Virus
- Panda anti virus gratuit - Télécharger - Antivirus & Antimalwares
21 réponses
voici le rapport:
ComboFix 08-09-05.14 - Tony 2008-09-11 21:00:49.2 - NTFSx86
Endroit: C:\Documents and Settings\Tony\Bureau\ComboFix.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.
((((((((((((((((((((((((((((( Fichiers créés 2008-08-11 to 2008-09-11 ))))))))))))))))))))))))))))))))))))
.
2008-09-10 22:39 . 2008-09-10 22:39 <REP> d-------- C:\Documents and Settings\Tony\Application Data\TuneUp Software
2008-09-10 22:39 . 2008-09-10 22:39 355,584 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-09-10 22:39 . 2008-05-29 09:28 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-09-10 22:38 . 2008-09-10 22:40 <REP> d-------- C:\Program Files\TuneUp Utilities 2008
2008-09-10 22:38 . 2008-09-10 22:38 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-09-10 22:37 . 2008-09-10 22:37 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-09-10 22:32 . 2008-09-10 22:32 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-09-10 22:27 . 2008-09-10 22:27 <REP> d-------- C:\Program Files\Yahoo!
2008-09-10 22:27 . 2008-09-10 22:27 <REP> d-------- C:\Program Files\CCleaner
2008-09-09 19:30 . 2008-09-09 19:30 <REP> d-------- C:\WINDOWS\system32\fr
2008-09-09 19:30 . 2008-09-09 19:30 <REP> d-------- C:\WINDOWS\system32\bits
2008-09-09 19:30 . 2008-09-09 19:30 <REP> d-------- C:\WINDOWS\l2schemas
2008-09-09 19:26 . 2008-09-09 19:31 <REP> d-------- C:\WINDOWS\ServicePackFiles
2008-09-09 19:15 . 2008-09-09 19:15 <REP> d-------- C:\WINDOWS\EHome
2008-09-09 18:31 . 2004-07-17 22:55 129,045 --------- C:\WINDOWS\system32\drivers\cxthsfs2.cty
2008-09-08 23:38 . 2008-09-08 23:38 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-09-08 21:33 . 2008-09-08 21:33 <REP> d-------- C:\WINDOWS\ERUNT
2008-09-08 21:31 . 2008-09-08 21:47 <REP> d-------- C:\SDFix
2008-09-08 20:13 . 2008-09-08 20:18 <REP> d-------- C:\Program Files\Navilog1
2008-09-08 18:54 . 2008-06-14 19:33 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-09-08 18:54 . 2008-06-14 19:33 272,768 --------- C:\WINDOWS\system32\dllcache\bthport.sys
2008-09-08 18:54 . 2008-05-08 16:02 203,136 --------- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-09-08 18:53 . 2008-04-11 21:05 691,712 --------- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-09-08 18:53 . 2008-05-01 16:36 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll
2008-09-08 18:45 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-09-08 18:45 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-09-08 18:45 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-09-07 22:36 . 2008-09-07 22:36 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-09-07 21:00 . 2008-09-07 21:00 <REP> d-------- C:\Documents and Settings\Tony\Application Data\Malwarebytes
2008-09-07 21:00 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-07 21:00 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-07 20:59 . 2008-09-10 19:07 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-07 20:59 . 2008-09-07 20:59 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-07 20:24 . 2008-09-07 20:24 <REP> d-------- C:\Program Files\Trend Micro
2008-09-06 19:19 . 2008-09-06 19:19 <REP> d-------- C:\Program Files\Enigma Software Group
2008-09-05 21:20 . 2008-09-10 19:56 <REP> d-------- C:\Program Files\xrwgxue
2008-09-05 21:19 . 2008-09-05 21:19 <REP> d-------- C:\Documents and Settings\All Users\Application Data\lapmnohw
2008-09-05 21:19 . 2008-09-05 21:19 90,112 --a------ C:\WINDOWS\system32\slwfqrun.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-10 19:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-02 19:35 --------- d-----w C:\Program Files\Zylom Games
2008-08-02 17:26 --------- d-----w C:\Documents and Settings\Tony\Application Data\Samsung
2008-08-02 17:21 5,632 ----a-w C:\WINDOWS\system32\drivers\StarOpen.sys
2008-08-02 17:10 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-02 16:59 --------- d-----w C:\Program Files\Samsung
2008-08-01 10:12 --------- d-----w C:\Documents and Settings\Tony\Application Data\Zylom
2008-08-01 10:12 --------- d-----w C:\Documents and Settings\Tony\Application Data\Sandlot Games
2008-08-01 09:54 --------- d-----w C:\Program Files\MSN Games
2008-08-01 09:53 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-01 08:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\FreshGames
2008-07-30 16:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Farm Frenzy
2008-07-30 10:24 --------- d-----w C:\Documents and Settings\Tony\Application Data\Gaijin Ent
2008-07-28 09:41 --------- d-----w C:\Documents and Settings\Tony\Application Data\PlayFirst
2008-07-28 09:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\PlayFirst
2008-07-28 08:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sandlot Games
2008-07-27 11:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\HipSoft
2008-07-27 10:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Zylom
2008-07-26 18:52 --------- d-----w C:\Program Files\Easy Internet signup
2008-07-26 18:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Fashion Solitaire 1.2
2008-07-26 15:56 --------- d-----w C:\Documents and Settings\Tony\Application Data\My Games
2008-07-24 12:05 --------- d-----w C:\Documents and Settings\Tony\Application Data\Total Eclipse
2008-07-22 09:09 --------- d-----w C:\Documents and Settings\Tony\Application Data\Jane s Hotel
2008-07-07 20:28 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:28 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
2008-06-24 16:44 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 16:44 74,240 ------w C:\WINDOWS\system32\dllcache\mscms.dll
2008-06-24 16:12 295,936 ------w C:\WINDOWS\system32\wmpeffects.dll
2008-06-24 08:28 3,592,192 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-06-23 09:21 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-06-23 09:21 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-06-23 09:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-06-21 05:23 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-06-20 17:47 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:47 247,808 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:47 147,968 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 11:51 361,600 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 11:40 138,496 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 11:08 225,856 ------w C:\WINDOWS\system32\dllcache\tcpip6.sys
2006-05-15 16:38 11,132,160 ----a-w C:\Program Files\setupfre.exe
2006-03-05 13:59 9,955,781 ----a-w C:\Program Files\PACK CLINS D'OEIL & IMAGES PERSO MSN - INSTALLA TION AUTOMAT.EXE
.
((((((((((((((((((((((((((((( snapshot@2008-09-10_21.11.36.60 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-09-10 17:57:26 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_600.dat
+ 2008-09-11 18:17:01 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_600.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-11 68856]
"ShCmd"="C:\WINDOWS\system32\slwfqrun.exe" [2008-09-05 90112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-11 339968]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-04-01 794624]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-02 102492]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-02 692316]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 49152]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-10-13 278528]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-04-29 98304]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 290816]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2005-02-17 233534]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
"SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2006-01-01 40960]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"Autoconfigurateur WiFi Neuf"="C:\Program Files\Neuf\Kit\WiFi\9wifi.exe" [2007-06-28 181488]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]
C:\Documents and Settings\Administrateur\Menu D‚marrer\Programmes\D‚marrage\
AutoTBar.exe [2003-09-30 57344]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
HP Digital Imaging Monitor.lnk - C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe [2004-11-04 258048]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 UxTuneUp;TuneUp Extension de thème;C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2004-12-15 200192]
R3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys [2005-11-19 20096]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-09-10 355584]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{baf7e2a2-ab3b-11dc-9a68-0016360bdac8}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
*Newly Created Service* - TUNEUP.DEFRAG
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = go.microsoft.com/fwlink/?LinkId=69157
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-11 21:04:25
Windows 5.1.2600 Service Pack 3 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????5?9?5?2??p???? ???B?????????????hLC? ??????
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-09-11 21:06:29
ComboFix-quarantined-files.txt 2008-09-11 19:06:20
ComboFix2.txt 2008-09-10 19:12:05
Pre-Run: 34,520,571,904 octets libres
Post-Run: 34,509,193,216 octets libres
174 --- E O F --- 2008-09-10 17:00:17
voila le rapport et la fenetre vient encore de s'ouvrir
ComboFix 08-09-05.14 - Tony 2008-09-11 21:00:49.2 - NTFSx86
Endroit: C:\Documents and Settings\Tony\Bureau\ComboFix.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.
((((((((((((((((((((((((((((( Fichiers créés 2008-08-11 to 2008-09-11 ))))))))))))))))))))))))))))))))))))
.
2008-09-10 22:39 . 2008-09-10 22:39 <REP> d-------- C:\Documents and Settings\Tony\Application Data\TuneUp Software
2008-09-10 22:39 . 2008-09-10 22:39 355,584 --a------ C:\WINDOWS\system32\TuneUpDefragService.exe
2008-09-10 22:39 . 2008-05-29 09:28 28,416 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-09-10 22:38 . 2008-09-10 22:40 <REP> d-------- C:\Program Files\TuneUp Utilities 2008
2008-09-10 22:38 . 2008-09-10 22:38 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-09-10 22:37 . 2008-09-10 22:37 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-09-10 22:32 . 2008-09-10 22:32 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-09-10 22:27 . 2008-09-10 22:27 <REP> d-------- C:\Program Files\Yahoo!
2008-09-10 22:27 . 2008-09-10 22:27 <REP> d-------- C:\Program Files\CCleaner
2008-09-09 19:30 . 2008-09-09 19:30 <REP> d-------- C:\WINDOWS\system32\fr
2008-09-09 19:30 . 2008-09-09 19:30 <REP> d-------- C:\WINDOWS\system32\bits
2008-09-09 19:30 . 2008-09-09 19:30 <REP> d-------- C:\WINDOWS\l2schemas
2008-09-09 19:26 . 2008-09-09 19:31 <REP> d-------- C:\WINDOWS\ServicePackFiles
2008-09-09 19:15 . 2008-09-09 19:15 <REP> d-------- C:\WINDOWS\EHome
2008-09-09 18:31 . 2004-07-17 22:55 129,045 --------- C:\WINDOWS\system32\drivers\cxthsfs2.cty
2008-09-08 23:38 . 2008-09-08 23:38 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-09-08 21:33 . 2008-09-08 21:33 <REP> d-------- C:\WINDOWS\ERUNT
2008-09-08 21:31 . 2008-09-08 21:47 <REP> d-------- C:\SDFix
2008-09-08 20:13 . 2008-09-08 20:18 <REP> d-------- C:\Program Files\Navilog1
2008-09-08 18:54 . 2008-06-14 19:33 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-09-08 18:54 . 2008-06-14 19:33 272,768 --------- C:\WINDOWS\system32\dllcache\bthport.sys
2008-09-08 18:54 . 2008-05-08 16:02 203,136 --------- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-09-08 18:53 . 2008-04-11 21:05 691,712 --------- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-09-08 18:53 . 2008-05-01 16:36 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll
2008-09-08 18:45 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-09-08 18:45 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-09-08 18:45 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-09-07 22:36 . 2008-09-07 22:36 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-09-07 21:00 . 2008-09-07 21:00 <REP> d-------- C:\Documents and Settings\Tony\Application Data\Malwarebytes
2008-09-07 21:00 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-07 21:00 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-07 20:59 . 2008-09-10 19:07 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-07 20:59 . 2008-09-07 20:59 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-07 20:24 . 2008-09-07 20:24 <REP> d-------- C:\Program Files\Trend Micro
2008-09-06 19:19 . 2008-09-06 19:19 <REP> d-------- C:\Program Files\Enigma Software Group
2008-09-05 21:20 . 2008-09-10 19:56 <REP> d-------- C:\Program Files\xrwgxue
2008-09-05 21:19 . 2008-09-05 21:19 <REP> d-------- C:\Documents and Settings\All Users\Application Data\lapmnohw
2008-09-05 21:19 . 2008-09-05 21:19 90,112 --a------ C:\WINDOWS\system32\slwfqrun.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-10 19:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-02 19:35 --------- d-----w C:\Program Files\Zylom Games
2008-08-02 17:26 --------- d-----w C:\Documents and Settings\Tony\Application Data\Samsung
2008-08-02 17:21 5,632 ----a-w C:\WINDOWS\system32\drivers\StarOpen.sys
2008-08-02 17:10 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-02 16:59 --------- d-----w C:\Program Files\Samsung
2008-08-01 10:12 --------- d-----w C:\Documents and Settings\Tony\Application Data\Zylom
2008-08-01 10:12 --------- d-----w C:\Documents and Settings\Tony\Application Data\Sandlot Games
2008-08-01 09:54 --------- d-----w C:\Program Files\MSN Games
2008-08-01 09:53 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-01 08:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\FreshGames
2008-07-30 16:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Farm Frenzy
2008-07-30 10:24 --------- d-----w C:\Documents and Settings\Tony\Application Data\Gaijin Ent
2008-07-28 09:41 --------- d-----w C:\Documents and Settings\Tony\Application Data\PlayFirst
2008-07-28 09:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\PlayFirst
2008-07-28 08:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sandlot Games
2008-07-27 11:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\HipSoft
2008-07-27 10:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Zylom
2008-07-26 18:52 --------- d-----w C:\Program Files\Easy Internet signup
2008-07-26 18:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Fashion Solitaire 1.2
2008-07-26 15:56 --------- d-----w C:\Documents and Settings\Tony\Application Data\My Games
2008-07-24 12:05 --------- d-----w C:\Documents and Settings\Tony\Application Data\Total Eclipse
2008-07-22 09:09 --------- d-----w C:\Documents and Settings\Tony\Application Data\Jane s Hotel
2008-07-07 20:28 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:28 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
2008-06-24 16:44 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 16:44 74,240 ------w C:\WINDOWS\system32\dllcache\mscms.dll
2008-06-24 16:12 295,936 ------w C:\WINDOWS\system32\wmpeffects.dll
2008-06-24 08:28 3,592,192 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-06-23 09:21 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-06-23 09:21 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-06-23 09:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-06-21 05:23 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-06-20 17:47 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:47 247,808 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:47 147,968 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 11:51 361,600 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 11:40 138,496 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 11:08 225,856 ------w C:\WINDOWS\system32\dllcache\tcpip6.sys
2006-05-15 16:38 11,132,160 ----a-w C:\Program Files\setupfre.exe
2006-03-05 13:59 9,955,781 ----a-w C:\Program Files\PACK CLINS D'OEIL & IMAGES PERSO MSN - INSTALLA TION AUTOMAT.EXE
.
((((((((((((((((((((((((((((( snapshot@2008-09-10_21.11.36.60 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-09-10 17:57:26 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_600.dat
+ 2008-09-11 18:17:01 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_600.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-11 68856]
"ShCmd"="C:\WINDOWS\system32\slwfqrun.exe" [2008-09-05 90112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-04-11 339968]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2005-04-01 794624]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-02 102492]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-02 692316]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 49152]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2004-10-13 278528]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-04-29 98304]
"eabconfg.cpl"="C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe" [2004-12-03 290816]
"Cpqset"="C:\Program Files\HPQ\Default Settings\cpqset.exe" [2005-02-17 233534]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
"SweetIM"="C:\Program Files\Macrogaming\SweetIM\SweetIM.exe" [2006-01-01 40960]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"Autoconfigurateur WiFi Neuf"="C:\Program Files\Neuf\Kit\WiFi\9wifi.exe" [2007-06-28 181488]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]
C:\Documents and Settings\Administrateur\Menu D‚marrer\Programmes\D‚marrage\
AutoTBar.exe [2003-09-30 57344]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
HP Digital Imaging Monitor.lnk - C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe [2004-11-04 258048]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 UxTuneUp;TuneUp Extension de thème;C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R3 HSFHWATI;HSFHWATI;C:\WINDOWS\system32\DRIVERS\HSFHWATI.sys [2004-12-15 200192]
R3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys [2005-11-19 20096]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-09-10 355584]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{baf7e2a2-ab3b-11dc-9a68-0016360bdac8}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
*Newly Created Service* - TUNEUP.DEFRAG
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = go.microsoft.com/fwlink/?LinkId=69157
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-11 21:04:25
Windows 5.1.2600 Service Pack 3 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\HPQ\Default Settings\cpqset.exe????????5?9?5?2??p???? ???B?????????????hLC? ??????
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-09-11 21:06:29
ComboFix-quarantined-files.txt 2008-09-11 19:06:20
ComboFix2.txt 2008-09-10 19:12:05
Pre-Run: 34,520,571,904 octets libres
Post-Run: 34,509,193,216 octets libres
174 --- E O F --- 2008-09-10 17:00:17
voila le rapport et la fenetre vient encore de s'ouvrir
je reviens.....
a+