A voir également:
- Gors probleme apparement crypt xpack.gen
- Vera crypt - Télécharger - Chiffrement
- True crypt - Télécharger - Chiffrement
- Ax crypt - Télécharger - Chiffrement
- Amazon probleme avec la commande n'apparait pas ✓ - Forum Internet / Réseaux sociaux
- Msgstore crypt 14 - Forum Logiciels
79 réponses
manque un morceau le voila la fin
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
(Aucun élément nuisible détecté)
c'etait preferable de prendre le mode sans echec sans prise en charge reseau mais bon !
Si MBAM ne trouve rien alors tu fera combofix
-Ferme tous tes programmes et deconnecte-toi
-Lance combofix
-Ne touche a rien pendant qu'il travaille
-Poste le rapport
Si MBAM ne trouve rien alors tu fera combofix
-Ferme tous tes programmes et deconnecte-toi
-Lance combofix
-Ne touche a rien pendant qu'il travaille
-Poste le rapport
voila le rapport combofix
ComboFix 08-09-26.01 - sandra aubert 2008-09-27 10:53:49.1 - NTFSx86 NETWORK
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.1165 [GMT 2:00]
Lancé depuis: C:\Documents and Settings\sandra aubert\Bureau\ComboFix.exe
Commutateurs utilisés :: C:\Documents and Settings\sandra aubert\Bureau\WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
((((((((((((((((((((((((((((( Fichiers créés du 2008-08-27 au 2008-09-27 ))))))))))))))))))))))))))))))))))))
.
2008-09-27 00:16 . 2008-09-27 00:17 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Spyware Terminator
2008-09-27 00:15 . 2008-09-27 00:15 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Malwarebytes
2008-09-27 00:14 . 2008-08-20 18:39 <REP> d-------- C:\Documents and Settings\Administrateur\WINDOWS
2008-09-27 00:14 . 2008-08-20 12:27 <REP> d-------- C:\Documents and Settings\Administrateur\Voisinage r‚seau
2008-09-27 00:14 . 2005-12-09 08:55 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-09-27 00:14 . 2008-08-20 18:39 <REP> d--h----- C:\Documents and Settings\Administrateur\ModŠles
2008-09-27 00:14 . 2008-08-20 18:39 <REP> dr------- C:\Documents and Settings\Administrateur\Mes documents
2008-09-27 00:14 . 2008-08-20 18:39 <REP> dr------- C:\Documents and Settings\Administrateur\Menu D‚marrer
2008-09-27 00:14 . 2008-08-20 18:39 <REP> dr------- C:\Documents and Settings\Administrateur\Favoris
2008-09-27 00:14 . 2008-09-27 00:25 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2008-09-27 00:14 . 2008-08-20 18:39 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\toshiba
2008-09-27 00:14 . 2005-12-09 12:22 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Symantec
2008-09-27 00:14 . 2008-08-20 18:39 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Sonic
2008-09-27 00:14 . 2008-09-27 00:14 <REP> d-------- C:\Documents and Settings\Administrateur
2008-09-27 00:06 . 2008-09-27 10:20 <REP> d-------- C:\Program Files\Crawler
2008-09-26 23:54 . 2008-09-27 00:38 <REP> d-------- C:\Program Files\Navilog1
2008-09-26 23:43 . 2008-09-26 23:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-09-26 23:42 . 2008-09-26 23:42 <REP> d-------- C:\Program Files\sollab
2008-09-26 23:42 . 2008-09-26 23:42 <REP> d-------- C:\Program Files\Lavasoft
2008-09-26 23:42 . 2008-09-26 23:42 <REP> d-------- C:\Program Files\CCleaner
2008-09-26 23:42 . 2008-09-26 23:42 <REP> d-------- C:\Documents and Settings\sandra aubert\Application Data\InterVideo
2008-09-26 23:42 . 2008-09-26 23:42 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-09-26 23:41 . 2008-09-26 23:42 <REP> d-------- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-26 22:38 . 2008-09-26 22:41 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-09-26 22:36 . 2004-04-27 04:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2008-09-26 22:34 . 2008-09-26 23:43 <REP> d-------- C:\WINDOWS\Internet Logs
2008-09-26 22:29 . 2008-09-26 23:43 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-26 22:29 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-26 22:29 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-26 20:16 . 2008-09-26 23:42 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-09-26 20:08 . 2008-09-27 10:59 <REP> d-------- C:\Program Files\WinClamAVShield
2008-09-26 19:51 . 2008-09-26 23:42 <REP> d-------- C:\Documents and Settings\sandra aubert\Application Data\Spyware Terminator
2008-09-26 19:51 . 2008-09-26 19:51 141,312 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-09-26 19:50 . 2008-09-26 23:43 <REP> d-------- C:\Program Files\Spyware Terminator
2008-09-25 19:09 . 2002-08-14 00:08 264,704 --a------ C:\WINDOWS\system32\MaggiUninstall60.exe
2008-09-25 19:08 . 1999-03-23 09:12 299,520 --a------ C:\WINDOWS\uninst.exe
2008-09-25 18:54 . 2008-09-26 23:42 <REP> d-------- C:\WINDOWS\system32\Adobe
2008-09-20 11:47 . 2008-09-26 23:42 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-09-20 11:47 . 2008-09-26 23:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-20 10:05 . 2008-09-26 23:42 <REP> d-------- C:\Program Files\BarreConfCMCIC
2008-09-18 11:26 . 2008-09-26 23:42 <REP> d-------- C:\Program Files\QuickZip4
2008-09-16 12:22 . 2008-09-26 23:42 <REP> d-------- C:\Program Files\Apple Software Update
2008-09-16 12:19 . 2008-09-26 23:42 <REP> d-------- C:\Program Files\iTunes
2008-09-16 12:19 . 2008-09-26 23:42 <REP> d-------- C:\Program Files\iPod
2008-09-16 12:16 . 2008-09-26 23:41 <REP> d-------- C:\Program Files\QuickTime
2008-09-16 12:08 . 2008-09-26 23:41 <REP> d-------- C:\Program Files\Bonjour
2008-09-15 19:30 . 2008-09-15 19:30 <REP> d-------- C:\Documents and Settings\sandra aubert\Application Data\Malwarebytes
2008-09-15 19:30 . 2008-09-15 19:30 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-15 17:58 . 1997-01-22 15:34 312,320 --a------ C:\WINDOWS\IsUninst.exe
2008-09-15 17:58 . 2008-09-25 19:44 491 --a------ C:\WINDOWS\SStylerProDemo.ini
2008-09-06 15:09 . 2008-09-06 15:09 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-09-06 15:09 . 2008-09-06 15:09 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
2008-09-05 20:45 . 2008-09-05 20:45 <REP> d-------- C:\WINDOWS\system32\fr
2008-09-05 20:45 . 2008-09-05 20:45 <REP> d-------- C:\WINDOWS\system32\bits
2008-09-05 20:45 . 2008-09-05 20:45 <REP> d-------- C:\WINDOWS\l2schemas
2008-09-05 20:39 . 2008-09-05 20:45 <REP> d-------- C:\WINDOWS\ServicePackFiles
2008-09-05 20:23 . 2008-09-05 20:23 <REP> d-------- C:\WINDOWS\EHome
2008-09-04 19:08 . 2004-08-03 22:41 1,041,536 --------- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2008-09-04 19:08 . 2004-08-03 22:41 685,056 --------- C:\WINDOWS\system32\drivers\hsfcxts2.sys
2008-09-04 19:08 . 2004-08-03 22:41 220,032 --------- C:\WINDOWS\system32\drivers\hsfbs2s2.sys
2008-09-04 19:08 . 2004-07-17 22:55 129,045 --------- C:\WINDOWS\system32\drivers\cxthsfs2.cty
2008-09-04 19:08 . 2004-08-03 22:41 11,868 --------- C:\WINDOWS\system32\drivers\mdmxsdk.sys
2008-09-04 17:53 . 2008-09-04 17:53 268 --ah----- C:\sqmdata02.sqm
2008-09-04 17:53 . 2008-09-04 17:53 244 --ah----- C:\sqmnoopt02.sqm
2008-09-03 23:00 . 2008-09-03 23:00 268 --ah----- C:\sqmdata01.sqm
2008-09-03 23:00 . 2008-09-03 23:00 244 --ah----- C:\sqmnoopt01.sqm
2008-09-03 10:41 . 2008-09-03 10:41 <REP> d-------- C:\Program Files\Windows Media Connect 2
2008-09-03 10:24 . 2008-09-03 10:24 <REP> d-------- C:\WINDOWS\system32\LogFiles
2008-09-03 10:24 . 2008-09-03 10:33 <REP> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-09-02 10:34 . 2007-11-30 08:45 644,400 --a------ C:\WINDOWS\system32\MSCOMCT2.OCX
2008-09-01 12:25 . 2008-09-01 12:25 <REP> d-------- C:\Documents and Settings\sandra aubert\Application Data\ArcSoft
2008-08-30 18:34 . 2008-08-30 18:34 <REP> d-------- C:\Documents and Settings\sandra aubert\Application Data\Anuman Interactive
2008-08-30 18:13 . 2004-03-29 15:23 90,112 --a------ C:\WINDOWS\unvise32.exe
2008-08-30 17:12 . 2008-09-08 19:38 <REP> d-------- C:\Program Files\Fichiers communs\PC SOFT
2008-08-30 17:12 . 2008-08-30 17:12 <REP> d-------- C:\Documents and Settings\All Users\Application Data\magasin
2008-08-30 09:43 . 2008-08-30 10:29 <REP> d-------- C:\Documents and Settings\sandra aubert\Application Data\EBP
2008-08-30 09:16 . 2006-05-10 14:18 1,929,216 --a------ C:\WINDOWS\system32\cdintf250.dll
2008-08-30 09:13 . 2008-08-30 17:46 <REP> d-------- C:\Documents and Settings\All Users\Application Data\EBP
2008-08-29 10:18 . 2008-08-29 10:18 87,336 --a------ C:\WINDOWS\system32\dns-sd.exe
2008-08-29 09:53 . 2008-08-29 09:53 61,440 --a------ C:\WINDOWS\system32\dnssd.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-27 09:00 81,984 ----a-w C:\WINDOWS\system32\bdod.bin
2008-09-26 21:42 --------- d-----w C:\Documents and Settings\sandra aubert\Application Data\muvee Technologies
2008-09-25 15:07 316 ----a-w C:\Documents and Settings\sandra aubert\Application Data\wklnhst.dat
2008-09-18 16:39 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-16 10:16 --------- d-----w C:\Program Files\Fichiers communs\Apple
2008-09-10 18:15 --------- d-----w C:\Program Files\Microsoft Works
2008-09-05 20:42 --------- d-----w C:\Program Files\MioNet
2008-09-03 10:35 --------- d-----w C:\Documents and Settings\sandra aubert\Application Data\DivX
2008-09-02 08:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-02 08:34 --------- d-----w C:\Program Files\Google
2008-08-26 18:02 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-08-26 17:58 --------- d-----w C:\Documents and Settings\sandra aubert\Application Data\AdobeUM
2008-08-21 20:37 --------- d-----w C:\Program Files\MSXML 4.0
2008-08-21 05:53 --------- d-----w C:\Program Files\Picasa2
2008-08-20 17:25 --------- d-----w C:\Documents and Settings\sandra aubert\Application Data\Apple Computer
2008-08-20 17:10 --------- d-----w C:\Program Files\Services en ligne
2008-08-20 17:09 --------- d-----w C:\Program Files\Realtek
2008-08-20 17:07 --------- d-----w C:\Program Files\Microsoft.NET
2008-08-20 17:07 --------- d-----w C:\Program Files\microsoft frontpage
2008-08-20 17:07 --------- d-----w C:\Program Files\ltmoh
2008-08-20 17:00 --------- d-----w C:\Program Files\Fichiers communs\Java
2008-08-20 16:59 --------- d-----w C:\Program Files\ATI Technologies
2008-08-20 16:46 --------- d-----w C:\Program Files\DivX
2008-08-20 16:39 --------- d-----w C:\Documents and Settings\sandra aubert\Application Data\toshiba
2008-08-20 16:39 --------- d-----w C:\Documents and Settings\sandra aubert\Application Data\Sonic
2008-08-20 16:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\SBSI
2008-08-20 16:09 --------- d-----w C:\Program Files\ABBYY FineReader 6.0 Sprint
2008-08-20 15:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-20 15:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-08-20 15:43 --------- d-----w C:\Documents and Settings\sandra aubert\Application Data\Yahoo!
2008-08-20 15:28 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-08-20 14:17 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-08-20 13:59 --------- d-----w C:\Documents and Settings\sandra aubert\Application Data\Template
2008-08-20 12:53 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-08-20 12:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\UDL
2008-08-20 12:22 --------- d-----w C:\Program Files\epson
2008-08-20 12:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\EPSON
2008-08-20 11:59 --------- d-----w C:\Program Files\Fichiers communs\Ahead
2008-08-20 11:59 --------- d-----w C:\Program Files\Ahead
2008-08-20 11:54 --------- d-----w C:\Program Files\Philips
2008-08-20 11:52 --------- d-----w C:\Program Files\muvee Technologies
2008-08-20 11:52 --------- d-----w C:\Program Files\Fichiers communs\muvee Technologies
2008-08-20 11:51 --------- d-----w C:\Program Files\ArcSoft
2008-08-20 11:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\muvee Technologies
2008-08-20 11:48 --------- d-----w C:\Documents and Settings\sandra aubert\Application Data\InstallShield
2008-08-20 11:15 --------- d-----w C:\Program Files\Shareaza
2008-08-20 11:15 --------- d-----w C:\Documents and Settings\sandra aubert\Application Data\Shareaza
2008-08-20 11:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\BitDefender
2008-08-20 10:40 --------- d-----w C:\Documents and Settings\sandra aubert\Application Data\BitDefender
2008-08-20 10:39 --------- d-----w C:\Program Files\Fichiers communs\BitDefender
2008-08-20 10:39 --------- d-----w C:\Program Files\BitDefender
2008-08-20 10:38 --------- d-----w C:\Program Files\Windows Live
2008-08-20 10:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-20 10:27 0 --sha-r C:\WINDOWS\system32\drivers\TOSHIBA_Satellite A100_03601-FR_PSAA2E-01700.MRK
2008-08-20 10:25 17,801 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2008-08-20 10:25 --------- d-----w C:\Program Files\Atheros
2008-08-20 09:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-08-20 09:52 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-08-20 09:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\RoboForm
2008-08-20 09:38 --------- d-----w C:\Program Files\Siber Systems
2008-07-25 08:36 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-07-23 16:50 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-07-23 16:50 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2008-07-23 16:50 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2008-07-23 16:50 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2008-07-23 16:48 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-07-23 16:48 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-07-23 16:46 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:28 253,952 ----a-w C:\WINDOWS\system32\es.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-11 65536]
"Shareaza"="C:\Program Files\Shareaza\Shareaza.exe" [2008-01-01 4739072]
"EPSON Stylus DX6000 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBIE.EXE" [2006-09-22 139264]
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2008-08-20 160592]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2008-08-15 443968]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-13 68856]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 2156368]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-15 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-15 688218]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2005-05-19 188416]
"THotkey"="C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe" [2005-12-08 352256]
"Tvs"="C:\Program Files\TOSHIBA\Tvs\TvsTray.exe" [2005-11-30 73728]
"SmoothView"="C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe" [2005-05-17 118784]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2005-08-30 1077328]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-08-01 122940]
"BitDefender Antiphishing Helper"="C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 61440]
"BDAgent"="C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" [2008-09-16 368640]
"BigDogPath"="C:\WINDOWS\VM_STI.exe" [2004-06-09 40960]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-09-06 413696]
"AppleSyncNotifier"="C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-09-26 1783808]
"RTHDCPL"="RTHDCPL.EXE" [2005-11-10 C:\WINDOWS\RTHDCPL.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2005-10-15 C:\WINDOWS\agrsmmsg.exe]
"TPSMain"="TPSMain.exe" [2005-08-03 C:\WINDOWS\system32\TPSMain.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Shareaza\\Shareaza.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Groupement homologue Windows
"3540:UDP"= 3540:UDP:Protocole PNRP (Peer Name Resolution Protocol)
"1700:TCP"= 1700:TCP:MioNet Remote Drive Access
"1641:TCP"= 1641:TCP:MioNet Remote Drive Verification
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2008-09-26 141312]
R2 MioNet;MioNet Service;C:\Program Files\MioNet\MioNetManager.exe [2005-07-15 139264]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\WINDOWS\system32\DRIVERS\bdfndisf.sys [2008-06-02 86792]
S3 p2pgasvc;Authentification de groupe réseau homologue;C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 p2pimsvc;Gestionnaire d'identité réseau homologue;C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 p2psvc;Réseau homologue;C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 PNRPSvc;Protocole de résolution de noms d'homologues;C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contenu du dossier 'Tâches planifiées'
.
.
------- Examen supplémentaire -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.orange.fr/
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
R0 -: HKCU-Main,Default_Search_URL = hxxp://www.google.com/ie
R0 -: HKLM-Main,Start Page = hxxp://fr.yahoo.com
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O8 -: Barre RoboForm - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 -: Crawler Search - tbr:iemenu
O8 -: Enregistrer le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 -: Personnaliser le menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 -: Remplir le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O18 -: Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
O16 -: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://copainsdavant.linternaute.com/framework/lib/objimageuploader/html_include/5.1.1.0/ImageUploader5.cab
C:\WINDOWS\Downloaded Program Files\ImageUploader5.inf
C:\WINDOWS\system32\unicows.dll
C:\WINDOWS\Downloaded Program Files\ImageUploader5.ocx
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-27 10:59:42
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\MioNet\jvm\bin\MioNet.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\Crawler\CToolbar.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
.
**************************************************************************
.
Heure de fin: 2008-09-27 11:07:51 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-09-27 09:07:31
Avant-CF: 60ÿ612ÿ009ÿ984 octets libres
Après-CF: 59,043,483,648 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
314 --- E O F --- 2008-09-10 18:19:35
ComboFix 08-09-26.01 - sandra aubert 2008-09-27 10:53:49.1 - NTFSx86 NETWORK
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.1165 [GMT 2:00]
Lancé depuis: C:\Documents and Settings\sandra aubert\Bureau\ComboFix.exe
Commutateurs utilisés :: C:\Documents and Settings\sandra aubert\Bureau\WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
((((((((((((((((((((((((((((( Fichiers créés du 2008-08-27 au 2008-09-27 ))))))))))))))))))))))))))))))))))))
.
2008-09-27 00:16 . 2008-09-27 00:17 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Spyware Terminator
2008-09-27 00:15 . 2008-09-27 00:15 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Malwarebytes
2008-09-27 00:14 . 2008-08-20 18:39 <REP> d-------- C:\Documents and Settings\Administrateur\WINDOWS
2008-09-27 00:14 . 2008-08-20 12:27 <REP> d-------- C:\Documents and Settings\Administrateur\Voisinage r‚seau
2008-09-27 00:14 . 2005-12-09 08:55 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-09-27 00:14 . 2008-08-20 18:39 <REP> d--h----- C:\Documents and Settings\Administrateur\ModŠles
2008-09-27 00:14 . 2008-08-20 18:39 <REP> dr------- C:\Documents and Settings\Administrateur\Mes documents
2008-09-27 00:14 . 2008-08-20 18:39 <REP> dr------- C:\Documents and Settings\Administrateur\Menu D‚marrer
2008-09-27 00:14 . 2008-08-20 18:39 <REP> dr------- C:\Documents and Settings\Administrateur\Favoris
2008-09-27 00:14 . 2008-09-27 00:25 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2008-09-27 00:14 . 2008-08-20 18:39 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\toshiba
2008-09-27 00:14 . 2005-12-09 12:22 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Symantec
2008-09-27 00:14 . 2008-08-20 18:39 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Sonic
2008-09-27 00:14 . 2008-09-27 00:14 <REP> d-------- C:\Documents and Settings\Administrateur
2008-09-27 00:06 . 2008-09-27 10:20 <REP> d-------- C:\Program Files\Crawler
2008-09-26 23:54 . 2008-09-27 00:38 <REP> d-------- C:\Program Files\Navilog1
2008-09-26 23:43 . 2008-09-26 23:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-09-26 23:42 . 2008-09-26 23:42 <REP> d-------- C:\Program Files\sollab
2008-09-26 23:42 . 2008-09-26 23:42 <REP> d-------- C:\Program Files\Lavasoft
2008-09-26 23:42 . 2008-09-26 23:42 <REP> d-------- C:\Program Files\CCleaner
2008-09-26 23:42 . 2008-09-26 23:42 <REP> d-------- C:\Documents and Settings\sandra aubert\Application Data\InterVideo
2008-09-26 23:42 . 2008-09-26 23:42 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-09-26 23:41 . 2008-09-26 23:42 <REP> d-------- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-26 22:38 . 2008-09-26 22:41 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2008-09-26 22:36 . 2004-04-27 04:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2008-09-26 22:34 . 2008-09-26 23:43 <REP> d-------- C:\WINDOWS\Internet Logs
2008-09-26 22:29 . 2008-09-26 23:43 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-26 22:29 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-26 22:29 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-26 20:16 . 2008-09-26 23:42 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-09-26 20:08 . 2008-09-27 10:59 <REP> d-------- C:\Program Files\WinClamAVShield
2008-09-26 19:51 . 2008-09-26 23:42 <REP> d-------- C:\Documents and Settings\sandra aubert\Application Data\Spyware Terminator
2008-09-26 19:51 . 2008-09-26 19:51 141,312 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-09-26 19:50 . 2008-09-26 23:43 <REP> d-------- C:\Program Files\Spyware Terminator
2008-09-25 19:09 . 2002-08-14 00:08 264,704 --a------ C:\WINDOWS\system32\MaggiUninstall60.exe
2008-09-25 19:08 . 1999-03-23 09:12 299,520 --a------ C:\WINDOWS\uninst.exe
2008-09-25 18:54 . 2008-09-26 23:42 <REP> d-------- C:\WINDOWS\system32\Adobe
2008-09-20 11:47 . 2008-09-26 23:42 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-09-20 11:47 . 2008-09-26 23:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-20 10:05 . 2008-09-26 23:42 <REP> d-------- C:\Program Files\BarreConfCMCIC
2008-09-18 11:26 . 2008-09-26 23:42 <REP> d-------- C:\Program Files\QuickZip4
2008-09-16 12:22 . 2008-09-26 23:42 <REP> d-------- C:\Program Files\Apple Software Update
2008-09-16 12:19 . 2008-09-26 23:42 <REP> d-------- C:\Program Files\iTunes
2008-09-16 12:19 . 2008-09-26 23:42 <REP> d-------- C:\Program Files\iPod
2008-09-16 12:16 . 2008-09-26 23:41 <REP> d-------- C:\Program Files\QuickTime
2008-09-16 12:08 . 2008-09-26 23:41 <REP> d-------- C:\Program Files\Bonjour
2008-09-15 19:30 . 2008-09-15 19:30 <REP> d-------- C:\Documents and Settings\sandra aubert\Application Data\Malwarebytes
2008-09-15 19:30 . 2008-09-15 19:30 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-15 17:58 . 1997-01-22 15:34 312,320 --a------ C:\WINDOWS\IsUninst.exe
2008-09-15 17:58 . 2008-09-25 19:44 491 --a------ C:\WINDOWS\SStylerProDemo.ini
2008-09-06 15:09 . 2008-09-06 15:09 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-09-06 15:09 . 2008-09-06 15:09 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
2008-09-05 20:45 . 2008-09-05 20:45 <REP> d-------- C:\WINDOWS\system32\fr
2008-09-05 20:45 . 2008-09-05 20:45 <REP> d-------- C:\WINDOWS\system32\bits
2008-09-05 20:45 . 2008-09-05 20:45 <REP> d-------- C:\WINDOWS\l2schemas
2008-09-05 20:39 . 2008-09-05 20:45 <REP> d-------- C:\WINDOWS\ServicePackFiles
2008-09-05 20:23 . 2008-09-05 20:23 <REP> d-------- C:\WINDOWS\EHome
2008-09-04 19:08 . 2004-08-03 22:41 1,041,536 --------- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2008-09-04 19:08 . 2004-08-03 22:41 685,056 --------- C:\WINDOWS\system32\drivers\hsfcxts2.sys
2008-09-04 19:08 . 2004-08-03 22:41 220,032 --------- C:\WINDOWS\system32\drivers\hsfbs2s2.sys
2008-09-04 19:08 . 2004-07-17 22:55 129,045 --------- C:\WINDOWS\system32\drivers\cxthsfs2.cty
2008-09-04 19:08 . 2004-08-03 22:41 11,868 --------- C:\WINDOWS\system32\drivers\mdmxsdk.sys
2008-09-04 17:53 . 2008-09-04 17:53 268 --ah----- C:\sqmdata02.sqm
2008-09-04 17:53 . 2008-09-04 17:53 244 --ah----- C:\sqmnoopt02.sqm
2008-09-03 23:00 . 2008-09-03 23:00 268 --ah----- C:\sqmdata01.sqm
2008-09-03 23:00 . 2008-09-03 23:00 244 --ah----- C:\sqmnoopt01.sqm
2008-09-03 10:41 . 2008-09-03 10:41 <REP> d-------- C:\Program Files\Windows Media Connect 2
2008-09-03 10:24 . 2008-09-03 10:24 <REP> d-------- C:\WINDOWS\system32\LogFiles
2008-09-03 10:24 . 2008-09-03 10:33 <REP> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-09-02 10:34 . 2007-11-30 08:45 644,400 --a------ C:\WINDOWS\system32\MSCOMCT2.OCX
2008-09-01 12:25 . 2008-09-01 12:25 <REP> d-------- C:\Documents and Settings\sandra aubert\Application Data\ArcSoft
2008-08-30 18:34 . 2008-08-30 18:34 <REP> d-------- C:\Documents and Settings\sandra aubert\Application Data\Anuman Interactive
2008-08-30 18:13 . 2004-03-29 15:23 90,112 --a------ C:\WINDOWS\unvise32.exe
2008-08-30 17:12 . 2008-09-08 19:38 <REP> d-------- C:\Program Files\Fichiers communs\PC SOFT
2008-08-30 17:12 . 2008-08-30 17:12 <REP> d-------- C:\Documents and Settings\All Users\Application Data\magasin
2008-08-30 09:43 . 2008-08-30 10:29 <REP> d-------- C:\Documents and Settings\sandra aubert\Application Data\EBP
2008-08-30 09:16 . 2006-05-10 14:18 1,929,216 --a------ C:\WINDOWS\system32\cdintf250.dll
2008-08-30 09:13 . 2008-08-30 17:46 <REP> d-------- C:\Documents and Settings\All Users\Application Data\EBP
2008-08-29 10:18 . 2008-08-29 10:18 87,336 --a------ C:\WINDOWS\system32\dns-sd.exe
2008-08-29 09:53 . 2008-08-29 09:53 61,440 --a------ C:\WINDOWS\system32\dnssd.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-27 09:00 81,984 ----a-w C:\WINDOWS\system32\bdod.bin
2008-09-26 21:42 --------- d-----w C:\Documents and Settings\sandra aubert\Application Data\muvee Technologies
2008-09-25 15:07 316 ----a-w C:\Documents and Settings\sandra aubert\Application Data\wklnhst.dat
2008-09-18 16:39 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-16 10:16 --------- d-----w C:\Program Files\Fichiers communs\Apple
2008-09-10 18:15 --------- d-----w C:\Program Files\Microsoft Works
2008-09-05 20:42 --------- d-----w C:\Program Files\MioNet
2008-09-03 10:35 --------- d-----w C:\Documents and Settings\sandra aubert\Application Data\DivX
2008-09-02 08:34 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-02 08:34 --------- d-----w C:\Program Files\Google
2008-08-26 18:02 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-08-26 17:58 --------- d-----w C:\Documents and Settings\sandra aubert\Application Data\AdobeUM
2008-08-21 20:37 --------- d-----w C:\Program Files\MSXML 4.0
2008-08-21 05:53 --------- d-----w C:\Program Files\Picasa2
2008-08-20 17:25 --------- d-----w C:\Documents and Settings\sandra aubert\Application Data\Apple Computer
2008-08-20 17:10 --------- d-----w C:\Program Files\Services en ligne
2008-08-20 17:09 --------- d-----w C:\Program Files\Realtek
2008-08-20 17:07 --------- d-----w C:\Program Files\Microsoft.NET
2008-08-20 17:07 --------- d-----w C:\Program Files\microsoft frontpage
2008-08-20 17:07 --------- d-----w C:\Program Files\ltmoh
2008-08-20 17:00 --------- d-----w C:\Program Files\Fichiers communs\Java
2008-08-20 16:59 --------- d-----w C:\Program Files\ATI Technologies
2008-08-20 16:46 --------- d-----w C:\Program Files\DivX
2008-08-20 16:39 --------- d-----w C:\Documents and Settings\sandra aubert\Application Data\toshiba
2008-08-20 16:39 --------- d-----w C:\Documents and Settings\sandra aubert\Application Data\Sonic
2008-08-20 16:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\SBSI
2008-08-20 16:09 --------- d-----w C:\Program Files\ABBYY FineReader 6.0 Sprint
2008-08-20 15:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-08-20 15:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-08-20 15:43 --------- d-----w C:\Documents and Settings\sandra aubert\Application Data\Yahoo!
2008-08-20 15:28 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-08-20 14:17 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-08-20 13:59 --------- d-----w C:\Documents and Settings\sandra aubert\Application Data\Template
2008-08-20 12:53 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-08-20 12:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\UDL
2008-08-20 12:22 --------- d-----w C:\Program Files\epson
2008-08-20 12:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\EPSON
2008-08-20 11:59 --------- d-----w C:\Program Files\Fichiers communs\Ahead
2008-08-20 11:59 --------- d-----w C:\Program Files\Ahead
2008-08-20 11:54 --------- d-----w C:\Program Files\Philips
2008-08-20 11:52 --------- d-----w C:\Program Files\muvee Technologies
2008-08-20 11:52 --------- d-----w C:\Program Files\Fichiers communs\muvee Technologies
2008-08-20 11:51 --------- d-----w C:\Program Files\ArcSoft
2008-08-20 11:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\muvee Technologies
2008-08-20 11:48 --------- d-----w C:\Documents and Settings\sandra aubert\Application Data\InstallShield
2008-08-20 11:15 --------- d-----w C:\Program Files\Shareaza
2008-08-20 11:15 --------- d-----w C:\Documents and Settings\sandra aubert\Application Data\Shareaza
2008-08-20 11:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\BitDefender
2008-08-20 10:40 --------- d-----w C:\Documents and Settings\sandra aubert\Application Data\BitDefender
2008-08-20 10:39 --------- d-----w C:\Program Files\Fichiers communs\BitDefender
2008-08-20 10:39 --------- d-----w C:\Program Files\BitDefender
2008-08-20 10:38 --------- d-----w C:\Program Files\Windows Live
2008-08-20 10:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-20 10:27 0 --sha-r C:\WINDOWS\system32\drivers\TOSHIBA_Satellite A100_03601-FR_PSAA2E-01700.MRK
2008-08-20 10:25 17,801 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2008-08-20 10:25 --------- d-----w C:\Program Files\Atheros
2008-08-20 09:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-08-20 09:52 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-08-20 09:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\RoboForm
2008-08-20 09:38 --------- d-----w C:\Program Files\Siber Systems
2008-07-25 08:36 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-07-23 16:50 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-07-23 16:50 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2008-07-23 16:50 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2008-07-23 16:50 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2008-07-23 16:48 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-07-23 16:48 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-07-23 16:46 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:28 253,952 ----a-w C:\WINDOWS\system32\es.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-11 65536]
"Shareaza"="C:\Program Files\Shareaza\Shareaza.exe" [2008-01-01 4739072]
"EPSON Stylus DX6000 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBIE.EXE" [2006-09-22 139264]
"RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2008-08-20 160592]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2008-08-15 443968]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-13 68856]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 2156368]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-15 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-15 688218]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2005-05-19 188416]
"THotkey"="C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe" [2005-12-08 352256]
"Tvs"="C:\Program Files\TOSHIBA\Tvs\TvsTray.exe" [2005-11-30 73728]
"SmoothView"="C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe" [2005-05-17 118784]
"PadTouch"="C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe" [2005-08-30 1077328]
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-08-01 122940]
"BitDefender Antiphishing Helper"="C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 61440]
"BDAgent"="C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" [2008-09-16 368640]
"BigDogPath"="C:\WINDOWS\VM_STI.exe" [2004-06-09 40960]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-09-06 413696]
"AppleSyncNotifier"="C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-09-26 1783808]
"RTHDCPL"="RTHDCPL.EXE" [2005-11-10 C:\WINDOWS\RTHDCPL.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2005-10-15 C:\WINDOWS\agrsmmsg.exe]
"TPSMain"="TPSMain.exe" [2005-08-03 C:\WINDOWS\system32\TPSMain.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Shareaza\\Shareaza.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3587:TCP"= 3587:TCP:Groupement homologue Windows
"3540:UDP"= 3540:UDP:Protocole PNRP (Peer Name Resolution Protocol)
"1700:TCP"= 1700:TCP:MioNet Remote Drive Access
"1641:TCP"= 1641:TCP:MioNet Remote Drive Verification
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2008-09-26 141312]
R2 MioNet;MioNet Service;C:\Program Files\MioNet\MioNetManager.exe [2005-07-15 139264]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\WINDOWS\system32\DRIVERS\bdfndisf.sys [2008-06-02 86792]
S3 p2pgasvc;Authentification de groupe réseau homologue;C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 p2pimsvc;Gestionnaire d'identité réseau homologue;C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 p2psvc;Réseau homologue;C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S3 PNRPSvc;Protocole de résolution de noms d'homologues;C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contenu du dossier 'Tâches planifiées'
.
.
------- Examen supplémentaire -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.orange.fr/
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
R0 -: HKCU-Main,Default_Search_URL = hxxp://www.google.com/ie
R0 -: HKLM-Main,Start Page = hxxp://fr.yahoo.com
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O8 -: Barre RoboForm - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 -: Crawler Search - tbr:iemenu
O8 -: Enregistrer le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 -: Personnaliser le menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 -: Remplir le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O18 -: Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
O16 -: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://copainsdavant.linternaute.com/framework/lib/objimageuploader/html_include/5.1.1.0/ImageUploader5.cab
C:\WINDOWS\Downloaded Program Files\ImageUploader5.inf
C:\WINDOWS\system32\unicows.dll
C:\WINDOWS\Downloaded Program Files\ImageUploader5.ocx
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-27 10:59:42
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\acs.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\MioNet\jvm\bin\MioNet.exe
C:\Program Files\TOSHIBA\TOSHIBA Applet\TAPPSRV.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\Crawler\CToolbar.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
.
**************************************************************************
.
Heure de fin: 2008-09-27 11:07:51 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-09-27 09:07:31
Avant-CF: 60ÿ612ÿ009ÿ984 octets libres
Après-CF: 59,043,483,648 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
314 --- E O F --- 2008-09-10 18:19:35
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
ben le soucis de savoir si le truc espion est toujours la surtout et si il a toujours le controle de mon ordi...
-telecharge otmoveit--> http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
-Enregistre le fichier sur le Bureau.
-Double-clique sur le fichier OTMoveIt2.exe pour lancer l'outil.
Assure-toi que la case Unregister Dll's and Ocx's soit bien cochée.
-Copie l'intégralité du texte ci-dessous et colle-le dans la fenêtre intitulée Paste List Of Files/Folders to Move.
C:\Program Files\Crawler
-Clique sur MoveIt! pour lancer la suppression.
Lorsqu'un résultat apparaît dans le cadre Results, clique sur Exit.
Note : Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer. Accepte en cliquant sur YES.
-Poste le rapport de OTMoveIt qui se trouve dans C:\_OTMoveIt\MovedFiles.
-Enregistre le fichier sur le Bureau.
-Double-clique sur le fichier OTMoveIt2.exe pour lancer l'outil.
Assure-toi que la case Unregister Dll's and Ocx's soit bien cochée.
-Copie l'intégralité du texte ci-dessous et colle-le dans la fenêtre intitulée Paste List Of Files/Folders to Move.
C:\Program Files\Crawler
-Clique sur MoveIt! pour lancer la suppression.
Lorsqu'un résultat apparaît dans le cadre Results, clique sur Exit.
Note : Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer. Accepte en cliquant sur YES.
-Poste le rapport de OTMoveIt qui se trouve dans C:\_OTMoveIt\MovedFiles.
voila le rapport
C:\Program Files\Crawler\WSGData\domains moved successfully.
C:\Program Files\Crawler\WSGData moved successfully.
C:\Program Files\Crawler\Update moved successfully.
C:\Program Files\Crawler\TBR5LanguageAct moved successfully.
C:\Program Files\Crawler\STWSGLanguageAct moved successfully.
C:\Program Files\Crawler\Languages moved successfully.
C:\Program Files\Crawler\Download moved successfully.
C:\Program Files\Crawler\Cache\STWSG moved successfully.
C:\Program Files\Crawler\Cache\COMMON moved successfully.
C:\Program Files\Crawler\Cache moved successfully.
Folder move failed. C:\Program Files\Crawler scheduled to be moved on reboot.
OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 09272008_112745
Files moved on Reboot...
C:\Program Files\Crawler moved successfully.
C:\Program Files\Crawler\WSGData\domains moved successfully.
C:\Program Files\Crawler\WSGData moved successfully.
C:\Program Files\Crawler\Update moved successfully.
C:\Program Files\Crawler\TBR5LanguageAct moved successfully.
C:\Program Files\Crawler\STWSGLanguageAct moved successfully.
C:\Program Files\Crawler\Languages moved successfully.
C:\Program Files\Crawler\Download moved successfully.
C:\Program Files\Crawler\Cache\STWSG moved successfully.
C:\Program Files\Crawler\Cache\COMMON moved successfully.
C:\Program Files\Crawler\Cache moved successfully.
Folder move failed. C:\Program Files\Crawler scheduled to be moved on reboot.
OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 09272008_112745
Files moved on Reboot...
C:\Program Files\Crawler moved successfully.
pas de prob la moindre des choses est d attendre si en plus tu prends le temps de m aider je patiente
-Demarrer-->executer--> ecris "regedit" sans les guillemets appuis sur entrée,
-Navigue ensuite jusqu'a ces clés: (si tu les trouves)
HKEY_CLASSES_ROOT\Microsoft Internet Mail Messages
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPRIP
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Iprip
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPRIP
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Iprip
-Navigue ensuite jusqu'a ces clés: (si tu les trouves)
HKEY_CLASSES_ROOT\Microsoft Internet Mail Messages
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPRIP
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Iprip
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_IPRIP
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Iprip