Infection,trojan spyware virus
Résolu
Setz
Messages postés
76
Statut
Membre
-
Destrio5 Messages postés 99820 Statut Modérateur -
Destrio5 Messages postés 99820 Statut Modérateur -
Bonjour,
salut a vous tous.Je fait appelle a vous car jai des problemes avec mon ordi.a chaque foie que je vais sur internet,plusieur pop up de securiter apparait et mon ordi me signal une infection presente.De plus,jai plusieur pistes sur la source du probleme.premierement, en tapant cmd dans executer.apres jai selectionner mon disque dur,apres jai entrer la command dir.je me suis appercu que javais 3 fichier virus mais jai seulement pu en suprimer un.pour les autres,impossible de les supprimer.Ces fichier provienne de flash adobe.mon ordi est aussi moin performante.Ces fichier porte le nom de nt user.data.LOG et NTUSER.DATA.LOG (en majuscule cette foie).mais se nest pas tout,il y a plusieur programme que je ne reconnait pas dans mon gestion de tache comme par example.jai 7 svchost.exe qui marche en permanance.svchost,un programme concernant le fax et limprimante je crois ne peu etre present 7 fois.Il y a aussi spoolsv.exe mctray.exe igfexpers.exe et naPrDMgr.exe .aucune idee comment suprimer ceux -ci..
je ne peu meme pas faire de mise a jour de microsoft et au demarage,jai 2 fenetre qui souvre en me disant que jai un probleme avec le systeme32.
donc je suis ouvert au suggestion et votre aides serais tres apprecié.Merci de vos reponse
salut a vous tous.Je fait appelle a vous car jai des problemes avec mon ordi.a chaque foie que je vais sur internet,plusieur pop up de securiter apparait et mon ordi me signal une infection presente.De plus,jai plusieur pistes sur la source du probleme.premierement, en tapant cmd dans executer.apres jai selectionner mon disque dur,apres jai entrer la command dir.je me suis appercu que javais 3 fichier virus mais jai seulement pu en suprimer un.pour les autres,impossible de les supprimer.Ces fichier provienne de flash adobe.mon ordi est aussi moin performante.Ces fichier porte le nom de nt user.data.LOG et NTUSER.DATA.LOG (en majuscule cette foie).mais se nest pas tout,il y a plusieur programme que je ne reconnait pas dans mon gestion de tache comme par example.jai 7 svchost.exe qui marche en permanance.svchost,un programme concernant le fax et limprimante je crois ne peu etre present 7 fois.Il y a aussi spoolsv.exe mctray.exe igfexpers.exe et naPrDMgr.exe .aucune idee comment suprimer ceux -ci..
je ne peu meme pas faire de mise a jour de microsoft et au demarage,jai 2 fenetre qui souvre en me disant que jai un probleme avec le systeme32.
donc je suis ouvert au suggestion et votre aides serais tres apprecié.Merci de vos reponse
A voir également:
- Infection,trojan spyware virus
- Virus mcafee - Accueil - Piratage
- Spyware doctor - Télécharger - Antivirus & Antimalwares
- Virus facebook demande d'amis - Accueil - Facebook
- Artemis virus - Forum Virus
- Trojan sms-par google ✓ - Forum Virus
59 réponses
je ne sais pas pourquoi tu dit que les 2 run en meme temps puisque jai deleter mcafee il y a deux jours..apart sa.. mon ordi est il gueri?
sa marche pas.sa dit .. mcafee enterprise sofware detected.cannot continue.please contact mcafee thecnical support
"je ne sais pas pourquoi tu dit que les 2 run en meme temps puisque jai deleter mcafee il y a deux jours"
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
/!\ Seul Setz peut suivre cette procédure /!\
1/
---> Clique sur Démarrer, Exécuter, tape notepad clique sur OK.
---> Copie le texte ci-dessous par sélection puis Ctrl+C :
KillAll::
Folder::
C:\Program Files\McAfee\
---> Colle la sélection dans le bloc-notes
---> Enregistre ce fichier sur le bureau (Impératif)
---> Nom du fichier : CFScript
---> Type du fichier : tous les fichiers
---> Clique sur Enregistrer
---> Quitte le bloc-notes
2/
---> Fait un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe comme sur la capture :
http://www.searchengines.pl/phpbb203/pliki/picasso/virus/programs/combofix/combofix_cfscript.gif
[*] Une fenêtre bleue va apparaître : au message qui apparaît, tu acceptes.
[*] Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises : c'est normal !
Ne touche à rien tant que le scan n'est pas terminé.
[*] Une fois le scan achevé, un rapport va s'afficher : poste-le
[*] Si le fichier ne s'ouvre pas, il se trouve ici C:\ComboFix.txt
1/
---> Clique sur Démarrer, Exécuter, tape notepad clique sur OK.
---> Copie le texte ci-dessous par sélection puis Ctrl+C :
KillAll::
Folder::
C:\Program Files\McAfee\
---> Colle la sélection dans le bloc-notes
---> Enregistre ce fichier sur le bureau (Impératif)
---> Nom du fichier : CFScript
---> Type du fichier : tous les fichiers
---> Clique sur Enregistrer
---> Quitte le bloc-notes
2/
---> Fait un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe comme sur la capture :
http://www.searchengines.pl/phpbb203/pliki/picasso/virus/programs/combofix/combofix_cfscript.gif
[*] Une fenêtre bleue va apparaître : au message qui apparaît, tu acceptes.
[*] Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises : c'est normal !
Ne touche à rien tant que le scan n'est pas terminé.
[*] Une fois le scan achevé, un rapport va s'afficher : poste-le
[*] Si le fichier ne s'ouvre pas, il se trouve ici C:\ComboFix.txt
des mise a jour de microsoft me son apparu.avant je ne pouvais pas faire de update a cause de mes infection..cela veut il dire que mon ordi est clear? voila le rapport pour mcafee
ComboFix 08-10-09.04 - Tomy 2008-10-10 2:08:51.4 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.297 [GMT -4:00]
Running from: C:\Documents and Settings\Tomy\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Tomy\Bureau\CFScript.txt
* Created a new restore point
[COLOR=RED][B]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/B][/COLOR]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\McAfee\
C:\Program Files\McAfee\\Common Framework\[u]0[/u]409\AgentRes.dll
C:\Program Files\McAfee\\Common Framework\[u]0[/u]409\AgentRes64.dll
C:\Program Files\McAfee\\Common Framework\[u]0[/u]409\CmaUIRes.dll
C:\Program Files\McAfee\\Common Framework\[u]0[/u]409\ScrptRes.dll
C:\Program Files\McAfee\\Common Framework\[u]0[/u]409\UpdRes.dll
C:\Program Files\McAfee\\Common Framework\Agent.dll
C:\Program Files\McAfee\\Common Framework\Agent64.dll
C:\Program Files\McAfee\\Common Framework\AgentPlugin.dll
C:\Program Files\McAfee\\Common Framework\applib.dll
C:\Program Files\McAfee\\Common Framework\applib64.dll
C:\Program Files\McAfee\\Common Framework\Cleanup.exe
C:\Program Files\McAfee\\Common Framework\ClientUI.dll
C:\Program Files\McAfee\\Common Framework\cmalib.dll
C:\Program Files\McAfee\\Common Framework\cmalib64.dll
C:\Program Files\McAfee\\Common Framework\CmdAgent.exe
C:\Program Files\McAfee\\Common Framework\ComponentFrameworkCallback64.dll
C:\Program Files\McAfee\\Common Framework\ComponentPolicyEnforcement64.dll
C:\Program Files\McAfee\\Common Framework\ComponentSubSystem.dll
C:\Program Files\McAfee\\Common Framework\ComponentSubSystem64.dll
C:\Program Files\McAfee\\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\\Common Framework\FrmInst.exe
C:\Program Files\McAfee\\Common Framework\FrmPlugin.dll
C:\Program Files\McAfee\\Common Framework\GenEvtInf.dll
C:\Program Files\McAfee\\Common Framework\GenEvtInf64.dll
C:\Program Files\McAfee\\Common Framework\InternetManager.dll
C:\Program Files\McAfee\\Common Framework\InternetManager64.dll
C:\Program Files\McAfee\\Common Framework\JrMac.dll
C:\Program Files\McAfee\\Common Framework\ListenServer.dll
C:\Program Files\McAfee\\Common Framework\Logging.dll
C:\Program Files\McAfee\\Common Framework\Logging64.dll
C:\Program Files\McAfee\\Common Framework\Management.dll
C:\Program Files\McAfee\\Common Framework\Management64.dll
C:\Program Files\McAfee\\Common Framework\McScanCheck.exe
C:\Program Files\McAfee\\Common Framework\McScript.exe
C:\Program Files\McAfee\\Common Framework\McScript_InUse.exe
C:\Program Files\McAfee\\Common Framework\Mctray.exe
C:\Program Files\McAfee\\Common Framework\mcurial.dll
C:\Program Files\McAfee\\Common Framework\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest
C:\Program Files\McAfee\\Common Framework\Microsoft.VC80.CRT\msvcm80.dll
C:\Program Files\McAfee\\Common Framework\Microsoft.VC80.CRT\msvcp80.dll
C:\Program Files\McAfee\\Common Framework\Microsoft.VC80.CRT\msvcr80.dll
C:\Program Files\McAfee\\Common Framework\msvcp71.dll
C:\Program Files\McAfee\\Common Framework\msvcr71.dll
C:\Program Files\McAfee\\Common Framework\naCmnLib64.dll
C:\Program Files\McAfee\\Common Framework\naCmnLib71.dll
C:\Program Files\McAfee\\Common Framework\nagshr32.dll
C:\Program Files\McAfee\\Common Framework\naicrt32.dll
C:\Program Files\McAfee\\Common Framework\nailog.dll
C:\Program Files\McAfee\\Common Framework\nailog64.dll
C:\Program Files\McAfee\\Common Framework\naInet.dll
C:\Program Files\McAfee\\Common Framework\naInet64.dll
C:\Program Files\McAfee\\Common Framework\naisign.dll
C:\Program Files\McAfee\\Common Framework\naitcpp.dll
C:\Program Files\McAfee\\Common Framework\naPolicyManager.dll
C:\Program Files\McAfee\\Common Framework\naPolicyManager64.dll
C:\Program Files\McAfee\\Common Framework\naPrdMgr.exe
C:\Program Files\McAfee\\Common Framework\naPrdMgr64.exe
C:\Program Files\McAfee\\Common Framework\naSPIPE.dll
C:\Program Files\McAfee\\Common Framework\naSPIPE64.dll
C:\Program Files\McAfee\\Common Framework\naXML64.dll
C:\Program Files\McAfee\\Common Framework\naXML71.dll
C:\Program Files\McAfee\\Common Framework\nmcomn32.dll
C:\Program Files\McAfee\\Common Framework\patchw32.dll
C:\Program Files\McAfee\\Common Framework\PcrPlug.dll
C:\Program Files\McAfee\\Common Framework\PoEvtInf.dll
C:\Program Files\McAfee\\Common Framework\Scheduler.dll
C:\Program Files\McAfee\\Common Framework\Scheduler64.dll
C:\Program Files\McAfee\\Common Framework\ScriptSubSys.dll
C:\Program Files\McAfee\\Common Framework\SecureFrameworkFactory.dll
C:\Program Files\McAfee\\Common Framework\SecureFrameworkFactory64.dll
C:\Program Files\McAfee\\Common Framework\TCHelper.dll
C:\Program Files\McAfee\\Common Framework\TCSubSys.dll
C:\Program Files\McAfee\\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\\Common Framework\unicows.dll
C:\Program Files\McAfee\\Common Framework\UpdateSubSys.dll
C:\Program Files\McAfee\\Common Framework\UpdPlug.dll
C:\Program Files\McAfee\\Common Framework\UserSpace.dll
C:\Program Files\McAfee\\Common Framework\XMLWrap.dll
.
((((((((((((((((((((((((( Files Created from 2008-09-10 to 2008-10-10 )))))))))))))))))))))))))))))))
.
2008-10-10 01:30 . 2008-10-10 01:30 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-10 01:30 . 2008-10-10 01:30 <REP> d-------- C:\Documents and Settings\Tomy\Application Data\Malwarebytes
2008-10-10 01:30 . 2008-10-10 01:30 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-10 01:30 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-10 01:30 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-10 00:45 . 2008-10-10 00:45 <REP> d-------- C:\Program Files\Trend Micro
2008-10-09 23:19 . 2008-10-10 00:06 <REP> d-------- C:\WINDOWS\BDOSCAN8
2008-10-09 19:45 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-10-09 19:45 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-10-09 19:45 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-10-09 19:45 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-10-09 19:45 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-10-09 19:45 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-10-09 19:21 . 2007-08-02 06:23 <REP> d--h----- C:\Documents and Settings\Tomy\Voisinage réseau
2008-10-09 19:21 . 2007-08-02 06:23 <REP> d--h----- C:\Documents and Settings\Tomy\Voisinage d'impression
2008-10-09 19:21 . 2007-08-02 10:40 <REP> d--h----- C:\Documents and Settings\Tomy\Modèles
2008-10-09 19:21 . 2008-10-09 19:22 <REP> d---s---- C:\Documents and Settings\Tomy\Mes documents
2008-10-09 19:21 . 2007-08-02 06:23 <REP> dr------- C:\Documents and Settings\Tomy\Menu Démarrer
2008-10-09 19:21 . 2008-10-09 19:22 <REP> d---s---- C:\Documents and Settings\Tomy\Favoris
2008-10-09 19:21 . 2008-10-10 02:08 <REP> d-------- C:\Documents and Settings\Tomy\Bureau
2008-10-09 19:21 . 2008-10-10 01:03 <REP> d-------- C:\Documents and Settings\Tomy
2008-10-07 23:33 . 2008-10-07 23:52 96,976 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-10-07 23:33 . 2008-10-07 23:33 87,855 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-10-07 23:32 . 2008-10-07 23:32 <REP> d-------- C:\Program Files\Kaspersky Lab
2008-10-07 23:32 . 2008-10-09 20:46 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-10-07 23:32 . 2008-10-10 02:10 2,802,720 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-07 23:32 . 2008-10-10 02:10 188,448 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-10-07 23:32 . 2008-10-10 02:10 22,976 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-07 23:32 . 2008-10-10 02:10 1,724 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-10-07 23:30 . 2008-10-07 23:30 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-10-07 23:07 . 2008-10-07 23:08 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb
2008-10-07 23:07 . 2008-10-07 23:08 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb
2008-10-07 22:54 . 2005-03-31 01:06 36,864 --------- C:\WINDOWS\system32\CTCamMgr.dll
2008-10-07 22:48 . 2008-10-07 22:48 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-10-06 17:46 . 2008-10-06 17:46 12 --a------ C:\WINDOWS\system32\pgvmc.dat
2008-10-06 17:37 . 2008-10-06 17:37 733 --a------ C:\WINDOWS\WININIT.INI
2008-10-06 17:37 . 2008-10-06 17:37 123 --a------ C:\WINDOWS\TMPCPYIS.BAT
2008-10-06 17:37 . 2008-10-06 17:37 122 --a------ C:\WINDOWS\TMPDELIS.BAT
2008-10-06 17:37 . 2008-10-06 17:37 26 --a------ C:\WINDOWS\WINSTART.BAT
2008-10-06 17:35 . 2008-10-06 17:35 <REP> d-------- C:\CHARANGA
2008-09-11 19:30 . 2001-08-17 20:20 96,256 --a------ C:\WINDOWS\system32\drivers\ac97intc.sys
2008-09-11 19:30 . 2001-08-17 20:20 96,256 --a--c--- C:\WINDOWS\system32\dllcache\ac97intc.sys
2008-09-11 11:40 . 2008-09-11 11:40 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Creative
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-08 03:06 --------- d-----w C:\Program Files\Fichiers communs\Blizzard Entertainment
2008-10-08 03:00 --------- d-----w C:\Program Files\Windows Live
2008-10-08 02:57 --------- d-----w C:\Program Files\Creative
2008-10-08 02:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-10-08 02:50 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-10-08 02:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-09-11 15:41 --------- d-----w C:\Program Files\SightSpeed
2008-09-11 15:24 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-11 15:20 --------- d-----w C:\Program Files\Fichiers communs\AOL
2008-07-30 00:21 218,376 ----a-w C:\WINDOWS\system32\klogon.dll
2008-07-24 18:59 21,840 ----atw C:\WINDOWS\system32\SIntfNT.dll
2008-07-24 18:59 17,212 ----atw C:\WINDOWS\system32\SIntf32.dll
2008-07-24 18:59 12,067 ----atw C:\WINDOWS\system32\SIntf16.dll
2008-07-24 00:13 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
.
------- Sigcheck -------
2007-06-13 09:22 979456 80a5400514eb32d393654768c4017e46 C:\WINDOWS\explorer.exe
2007-06-13 09:10 1037312 b795475444d6d57a572c14b9e1a29839 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2004-08-05 08:00 1036288 4c33e5b9a6197b6ed215f6cfba0a2daa C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2007-06-13 09:22 979456 80a5400514eb32d393654768c4017e46 C:\WINDOWS\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((( snapshot@2008-10-10_ 1.06.09.18 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 114688]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 32784]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-04-30 24592]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-McAfeeUpdaterUI - C:\Program Files\McAfee\Common Framework\UdaterUI.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-10 02:11:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-10-10 2:13:17 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-10 06:13:14
ComboFix2.txt 2008-10-10 05:46:45
ComboFix3.txt 2008-10-10 05:24:01
ComboFix4.txt 2008-10-10 05:06:37
Pre-Run: 69 062 078 464 octets libres
Post-Run: 69,044,269,056 octets libres
216 --- E O F --- 2008-08-24 01:36:11
ComboFix 08-10-09.04 - Tomy 2008-10-10 2:08:51.4 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.297 [GMT -4:00]
Running from: C:\Documents and Settings\Tomy\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Tomy\Bureau\CFScript.txt
* Created a new restore point
[COLOR=RED][B]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/B][/COLOR]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\McAfee\
C:\Program Files\McAfee\\Common Framework\[u]0[/u]409\AgentRes.dll
C:\Program Files\McAfee\\Common Framework\[u]0[/u]409\AgentRes64.dll
C:\Program Files\McAfee\\Common Framework\[u]0[/u]409\CmaUIRes.dll
C:\Program Files\McAfee\\Common Framework\[u]0[/u]409\ScrptRes.dll
C:\Program Files\McAfee\\Common Framework\[u]0[/u]409\UpdRes.dll
C:\Program Files\McAfee\\Common Framework\Agent.dll
C:\Program Files\McAfee\\Common Framework\Agent64.dll
C:\Program Files\McAfee\\Common Framework\AgentPlugin.dll
C:\Program Files\McAfee\\Common Framework\applib.dll
C:\Program Files\McAfee\\Common Framework\applib64.dll
C:\Program Files\McAfee\\Common Framework\Cleanup.exe
C:\Program Files\McAfee\\Common Framework\ClientUI.dll
C:\Program Files\McAfee\\Common Framework\cmalib.dll
C:\Program Files\McAfee\\Common Framework\cmalib64.dll
C:\Program Files\McAfee\\Common Framework\CmdAgent.exe
C:\Program Files\McAfee\\Common Framework\ComponentFrameworkCallback64.dll
C:\Program Files\McAfee\\Common Framework\ComponentPolicyEnforcement64.dll
C:\Program Files\McAfee\\Common Framework\ComponentSubSystem.dll
C:\Program Files\McAfee\\Common Framework\ComponentSubSystem64.dll
C:\Program Files\McAfee\\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\\Common Framework\FrmInst.exe
C:\Program Files\McAfee\\Common Framework\FrmPlugin.dll
C:\Program Files\McAfee\\Common Framework\GenEvtInf.dll
C:\Program Files\McAfee\\Common Framework\GenEvtInf64.dll
C:\Program Files\McAfee\\Common Framework\InternetManager.dll
C:\Program Files\McAfee\\Common Framework\InternetManager64.dll
C:\Program Files\McAfee\\Common Framework\JrMac.dll
C:\Program Files\McAfee\\Common Framework\ListenServer.dll
C:\Program Files\McAfee\\Common Framework\Logging.dll
C:\Program Files\McAfee\\Common Framework\Logging64.dll
C:\Program Files\McAfee\\Common Framework\Management.dll
C:\Program Files\McAfee\\Common Framework\Management64.dll
C:\Program Files\McAfee\\Common Framework\McScanCheck.exe
C:\Program Files\McAfee\\Common Framework\McScript.exe
C:\Program Files\McAfee\\Common Framework\McScript_InUse.exe
C:\Program Files\McAfee\\Common Framework\Mctray.exe
C:\Program Files\McAfee\\Common Framework\mcurial.dll
C:\Program Files\McAfee\\Common Framework\Microsoft.VC80.CRT\Microsoft.VC80.CRT.manifest
C:\Program Files\McAfee\\Common Framework\Microsoft.VC80.CRT\msvcm80.dll
C:\Program Files\McAfee\\Common Framework\Microsoft.VC80.CRT\msvcp80.dll
C:\Program Files\McAfee\\Common Framework\Microsoft.VC80.CRT\msvcr80.dll
C:\Program Files\McAfee\\Common Framework\msvcp71.dll
C:\Program Files\McAfee\\Common Framework\msvcr71.dll
C:\Program Files\McAfee\\Common Framework\naCmnLib64.dll
C:\Program Files\McAfee\\Common Framework\naCmnLib71.dll
C:\Program Files\McAfee\\Common Framework\nagshr32.dll
C:\Program Files\McAfee\\Common Framework\naicrt32.dll
C:\Program Files\McAfee\\Common Framework\nailog.dll
C:\Program Files\McAfee\\Common Framework\nailog64.dll
C:\Program Files\McAfee\\Common Framework\naInet.dll
C:\Program Files\McAfee\\Common Framework\naInet64.dll
C:\Program Files\McAfee\\Common Framework\naisign.dll
C:\Program Files\McAfee\\Common Framework\naitcpp.dll
C:\Program Files\McAfee\\Common Framework\naPolicyManager.dll
C:\Program Files\McAfee\\Common Framework\naPolicyManager64.dll
C:\Program Files\McAfee\\Common Framework\naPrdMgr.exe
C:\Program Files\McAfee\\Common Framework\naPrdMgr64.exe
C:\Program Files\McAfee\\Common Framework\naSPIPE.dll
C:\Program Files\McAfee\\Common Framework\naSPIPE64.dll
C:\Program Files\McAfee\\Common Framework\naXML64.dll
C:\Program Files\McAfee\\Common Framework\naXML71.dll
C:\Program Files\McAfee\\Common Framework\nmcomn32.dll
C:\Program Files\McAfee\\Common Framework\patchw32.dll
C:\Program Files\McAfee\\Common Framework\PcrPlug.dll
C:\Program Files\McAfee\\Common Framework\PoEvtInf.dll
C:\Program Files\McAfee\\Common Framework\Scheduler.dll
C:\Program Files\McAfee\\Common Framework\Scheduler64.dll
C:\Program Files\McAfee\\Common Framework\ScriptSubSys.dll
C:\Program Files\McAfee\\Common Framework\SecureFrameworkFactory.dll
C:\Program Files\McAfee\\Common Framework\SecureFrameworkFactory64.dll
C:\Program Files\McAfee\\Common Framework\TCHelper.dll
C:\Program Files\McAfee\\Common Framework\TCSubSys.dll
C:\Program Files\McAfee\\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\\Common Framework\unicows.dll
C:\Program Files\McAfee\\Common Framework\UpdateSubSys.dll
C:\Program Files\McAfee\\Common Framework\UpdPlug.dll
C:\Program Files\McAfee\\Common Framework\UserSpace.dll
C:\Program Files\McAfee\\Common Framework\XMLWrap.dll
.
((((((((((((((((((((((((( Files Created from 2008-09-10 to 2008-10-10 )))))))))))))))))))))))))))))))
.
2008-10-10 01:30 . 2008-10-10 01:30 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-10 01:30 . 2008-10-10 01:30 <REP> d-------- C:\Documents and Settings\Tomy\Application Data\Malwarebytes
2008-10-10 01:30 . 2008-10-10 01:30 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-10 01:30 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-10 01:30 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-10 00:45 . 2008-10-10 00:45 <REP> d-------- C:\Program Files\Trend Micro
2008-10-09 23:19 . 2008-10-10 00:06 <REP> d-------- C:\WINDOWS\BDOSCAN8
2008-10-09 19:45 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-10-09 19:45 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-10-09 19:45 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-10-09 19:45 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-10-09 19:45 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-10-09 19:45 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-10-09 19:21 . 2007-08-02 06:23 <REP> d--h----- C:\Documents and Settings\Tomy\Voisinage réseau
2008-10-09 19:21 . 2007-08-02 06:23 <REP> d--h----- C:\Documents and Settings\Tomy\Voisinage d'impression
2008-10-09 19:21 . 2007-08-02 10:40 <REP> d--h----- C:\Documents and Settings\Tomy\Modèles
2008-10-09 19:21 . 2008-10-09 19:22 <REP> d---s---- C:\Documents and Settings\Tomy\Mes documents
2008-10-09 19:21 . 2007-08-02 06:23 <REP> dr------- C:\Documents and Settings\Tomy\Menu Démarrer
2008-10-09 19:21 . 2008-10-09 19:22 <REP> d---s---- C:\Documents and Settings\Tomy\Favoris
2008-10-09 19:21 . 2008-10-10 02:08 <REP> d-------- C:\Documents and Settings\Tomy\Bureau
2008-10-09 19:21 . 2008-10-10 01:03 <REP> d-------- C:\Documents and Settings\Tomy
2008-10-07 23:33 . 2008-10-07 23:52 96,976 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-10-07 23:33 . 2008-10-07 23:33 87,855 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-10-07 23:32 . 2008-10-07 23:32 <REP> d-------- C:\Program Files\Kaspersky Lab
2008-10-07 23:32 . 2008-10-09 20:46 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-10-07 23:32 . 2008-10-10 02:10 2,802,720 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-07 23:32 . 2008-10-10 02:10 188,448 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-10-07 23:32 . 2008-10-10 02:10 22,976 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-07 23:32 . 2008-10-10 02:10 1,724 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-10-07 23:30 . 2008-10-07 23:30 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-10-07 23:07 . 2008-10-07 23:08 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb
2008-10-07 23:07 . 2008-10-07 23:08 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb
2008-10-07 22:54 . 2005-03-31 01:06 36,864 --------- C:\WINDOWS\system32\CTCamMgr.dll
2008-10-07 22:48 . 2008-10-07 22:48 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-10-06 17:46 . 2008-10-06 17:46 12 --a------ C:\WINDOWS\system32\pgvmc.dat
2008-10-06 17:37 . 2008-10-06 17:37 733 --a------ C:\WINDOWS\WININIT.INI
2008-10-06 17:37 . 2008-10-06 17:37 123 --a------ C:\WINDOWS\TMPCPYIS.BAT
2008-10-06 17:37 . 2008-10-06 17:37 122 --a------ C:\WINDOWS\TMPDELIS.BAT
2008-10-06 17:37 . 2008-10-06 17:37 26 --a------ C:\WINDOWS\WINSTART.BAT
2008-10-06 17:35 . 2008-10-06 17:35 <REP> d-------- C:\CHARANGA
2008-09-11 19:30 . 2001-08-17 20:20 96,256 --a------ C:\WINDOWS\system32\drivers\ac97intc.sys
2008-09-11 19:30 . 2001-08-17 20:20 96,256 --a--c--- C:\WINDOWS\system32\dllcache\ac97intc.sys
2008-09-11 11:40 . 2008-09-11 11:40 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Creative
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-08 03:06 --------- d-----w C:\Program Files\Fichiers communs\Blizzard Entertainment
2008-10-08 03:00 --------- d-----w C:\Program Files\Windows Live
2008-10-08 02:57 --------- d-----w C:\Program Files\Creative
2008-10-08 02:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-10-08 02:50 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-10-08 02:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-09-11 15:41 --------- d-----w C:\Program Files\SightSpeed
2008-09-11 15:24 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-11 15:20 --------- d-----w C:\Program Files\Fichiers communs\AOL
2008-07-30 00:21 218,376 ----a-w C:\WINDOWS\system32\klogon.dll
2008-07-24 18:59 21,840 ----atw C:\WINDOWS\system32\SIntfNT.dll
2008-07-24 18:59 17,212 ----atw C:\WINDOWS\system32\SIntf32.dll
2008-07-24 18:59 12,067 ----atw C:\WINDOWS\system32\SIntf16.dll
2008-07-24 00:13 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
.
------- Sigcheck -------
2007-06-13 09:22 979456 80a5400514eb32d393654768c4017e46 C:\WINDOWS\explorer.exe
2007-06-13 09:10 1037312 b795475444d6d57a572c14b9e1a29839 C:\WINDOWS\$hf_mig$\KB938828\SP2QFE\explorer.exe
2004-08-05 08:00 1036288 4c33e5b9a6197b6ed215f6cfba0a2daa C:\WINDOWS\$NtUninstallKB938828$\explorer.exe
2007-06-13 09:22 979456 80a5400514eb32d393654768c4017e46 C:\WINDOWS\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((( snapshot@2008-10-10_ 1.06.09.18 )))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 114688]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\WINDOWS\system32\drivers\klbg.sys [2008-01-29 32784]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-04-30 24592]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-McAfeeUpdaterUI - C:\Program Files\McAfee\Common Framework\UdaterUI.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-10 02:11:12
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-10-10 2:13:17 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-10 06:13:14
ComboFix2.txt 2008-10-10 05:46:45
ComboFix3.txt 2008-10-10 05:24:01
ComboFix4.txt 2008-10-10 05:06:37
Pre-Run: 69 062 078 464 octets libres
Post-Run: 69,044,269,056 octets libres
216 --- E O F --- 2008-08-24 01:36:11
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:20:03, on 2008-10-10
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.update.microsoft.com/windowsupdate/v6/default.aspx
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://www.catalog.update.microsoft.com/ClientControl/en/x86/MuCatalogWebControl.cab?1210628943500
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-CA/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15030/CTPID.cab
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe (file missing)
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
Scan saved at 02:20:03, on 2008-10-10
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.update.microsoft.com/windowsupdate/v6/default.aspx
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://www.catalog.update.microsoft.com/ClientControl/en/x86/MuCatalogWebControl.cab?1210628943500
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-CA/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15030/CTPID.cab
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe (file missing)
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
---> Menu démarrer > Exécuter
---> Tape cmd et valide par Entrée
---> Dans la fenêtre noire, tape sc delete McAfeeFramework et valide par Entrée
---> Poste un dernier rapport HijackThis
---> Tape cmd et valide par Entrée
---> Dans la fenêtre noire, tape sc delete McAfeeFramework et valide par Entrée
---> Poste un dernier rapport HijackThis
mais linstalation du programme ses fait sur un autre profil..je sais pas si sa change quelques choses
On va procéder autrement alors.
---> Relance HijackThis et choisis Do a system scan only
---> Coche les cases qui sont devant les lignes suivantes :
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe (file missing)
---> Clique en bas sur Fix checked. Mets oui si HijackThis te demande quelque chose.
---> Redémarre ton PC et poste un nouveau rapport HijackThis
---> Relance HijackThis et choisis Do a system scan only
---> Coche les cases qui sont devant les lignes suivantes :
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe (file missing)
---> Clique en bas sur Fix checked. Mets oui si HijackThis te demande quelque chose.
---> Redémarre ton PC et poste un nouveau rapport HijackThis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:34:01, on 2008-10-10
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.update.microsoft.com/windowsupdate/v6/default.aspx
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://www.catalog.update.microsoft.com/ClientControl/en/x86/MuCatalogWebControl.cab?1210628943500
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-CA/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15030/CTPID.cab
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe (file missing)
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
Scan saved at 02:34:01, on 2008-10-10
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.update.microsoft.com/windowsupdate/v6/default.aspx
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://www.catalog.update.microsoft.com/ClientControl/en/x86/MuCatalogWebControl.cab?1210628943500
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-CA/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su2/CTL_V02002/ocx/15030/CTPID.cab
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe (file missing)
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
---> Menu démarrer > Exécuter
---> Tape services.msc et valide par Entrée
---> Cherche McAfee Framework Service (McAfeeFramework) et mets-le en Désactivé
---> Tape services.msc et valide par Entrée
---> Cherche McAfee Framework Service (McAfeeFramework) et mets-le en Désactivé
[ Rapport ToolsCleaner version 2.2.3 (par A.Rothstein & dj QUIOU) ]
-->- Recherche:
C:\Combofix.txt: trouvé !
C:\Qoobox: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
C:\Documents and Settings\Tomy\Bureau\HijackThis.lnk: trouvé !
C:\Documents and Settings\Tomy\Bureau\ComboFix.exe: trouvé !
C:\Documents and Settings\Tomy\Bureau\SmitFraudFix.exe: trouvé !
C:\Documents and Settings\Tomy\Bureau\SmitFraudfix: trouvé !
C:\Program Files\Trend Micro\HijackThis: trouvé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
---------------------------------
-->- Suppression:
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
C:\Documents and Settings\Tomy\Bureau\HijackThis.lnk: supprimé !
C:\Documents and Settings\Tomy\Bureau\ComboFix.exe: ERREUR DE SUPPRESSION !!
C:\Documents and Settings\Tomy\Bureau\SmitFraudFix.exe: supprimé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
C:\Combofix.txt: supprimé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
C:\Qoobox: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
C:\Documents and Settings\Tomy\Bureau\SmitFraudfix: supprimé !
C:\Program Files\Trend Micro\HijackThis: supprimé !
-->- Recherche:
C:\Combofix.txt: trouvé !
C:\Qoobox: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
C:\Documents and Settings\Tomy\Bureau\HijackThis.lnk: trouvé !
C:\Documents and Settings\Tomy\Bureau\ComboFix.exe: trouvé !
C:\Documents and Settings\Tomy\Bureau\SmitFraudFix.exe: trouvé !
C:\Documents and Settings\Tomy\Bureau\SmitFraudfix: trouvé !
C:\Program Files\Trend Micro\HijackThis: trouvé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
---------------------------------
-->- Suppression:
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
C:\Documents and Settings\Tomy\Bureau\HijackThis.lnk: supprimé !
C:\Documents and Settings\Tomy\Bureau\ComboFix.exe: ERREUR DE SUPPRESSION !!
C:\Documents and Settings\Tomy\Bureau\SmitFraudFix.exe: supprimé !
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
C:\Combofix.txt: supprimé !
C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
C:\Qoobox: supprimé !
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
C:\Documents and Settings\Tomy\Bureau\SmitFraudfix: supprimé !
C:\Program Files\Trend Micro\HijackThis: supprimé !