Encore 2 virus apres Kaspersky scan,

tethys -  
 tethys -
Bonjour,
voilà ce que Kaspersky a trouvé....WIN XP SP2, AVAST, IE6

j'ai dejà demandé de l'aide il y a qqtemps, est ce que je dois retrouver mon post et refaire la meme chose ?

Merci !

autant celui d'avant je sais avoir ouvert un mail qu'il ne fallait pas , autant , ceux là je ne sais pas comment ils sont arrivés...

Tuesday, November 25, 2008 3:40:19 PM
Système d'exploitation : Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version : 5.0.84.2
Dernière mise à jour de la base antivirus Kaspersky : 25/11/2008
Enregistrements dans la base antivirus Kaspersky : 1268005

Paramètres d'analyse
Analyser avec la base antivirus suivante standard
Analyser les archives vrai
Analyser les bases de messagerie vrai

Cible de l'analyse Poste de travail
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\

Statistiques de l'analyse
Total d'objets analysés 51363
Nombre de virus trouvés 2
Nombre d'objets infectés 4 / 0
Nombre d'objets suspects 0
Durée de l'analyse 01:34:22

Nom de l'objet infecté Nom du virus Dernière action
H:\Documents and Settings\kat\Cookies\index.dat L'objet est verrouillé ignoré

H:\Documents and Settings\kat\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré

H:\Documents and Settings\kat\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré

H:\Documents and Settings\kat\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré

H:\Documents and Settings\kat\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré

H:\Documents and Settings\kat\NTUSER.DAT L'objet est verrouillé ignoré

H:\Documents and Settings\kat\NTUSER.DAT.LOG L'objet est verrouillé ignoré

H:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré

H:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré

H:\Documents and Settings\LocalService\NTUSER.DAT L'objet est verrouillé ignoré

H:\Documents and Settings\LocalService\ntuser.dat.LOG L'objet est verrouillé ignoré

H:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré

H:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré

H:\Documents and Settings\NetworkService\NTUSER.DAT L'objet est verrouillé ignoré

H:\Documents and Settings\NetworkService\ntuser.dat.LOG L'objet est verrouillé ignoré

H:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat L'objet est verrouillé ignoré

H:\Program Files\Alwil Software\Avast4\DATA\Avast4.db L'objet est verrouillé ignoré

H:\Program Files\Alwil Software\Avast4\DATA\integ\avast.int L'objet est verrouillé ignoré

H:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws L'objet est verrouillé ignoré

H:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log L'objet est verrouillé ignoré

H:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log L'objet est verrouillé ignoré

H:\Program Files\Alwil Software\Avast4\DATA\log\selfdef.log L'objet est verrouillé ignoré

H:\Program Files\Alwil Software\Avast4\DATA\report\Protection résidente.txt L'objet est verrouillé ignoré

H:\System Volume Information\MountPointManagerRemoteDatabase L'objet est verrouillé ignoré

H:\System Volume Information\_restore{D40B74DA-7724-4332-B5A1-09AC8F27996D}\RP15\change.log L'objet est verrouillé ignoré

H:\System Volume Information\_restore{D40B74DA-7724-4332-B5A1-09AC8F27996D}\RP2\A0000007.sys Infecté : Rootkit.Win32.Small.bs ignoré

H:\WINDOWS\Debug\PASSWD.LOG L'objet est verrouillé ignoré

H:\WINDOWS\SchedLgU.Txt L'objet est verrouillé ignoré

H:\WINDOWS\SoftwareDistribution\ReportingEvents.log L'objet est verrouillé ignoré

H:\WINDOWS\Sti_Trace.log L'objet est verrouillé ignoré

H:\WINDOWS\system32\CatRoot2\edb.log L'objet est verrouillé ignoré

H:\WINDOWS\system32\CatRoot2\tmp.edb L'objet est verrouillé ignoré

H:\WINDOWS\system32\config\Antivirus.Evt L'objet est verrouillé ignoré

H:\WINDOWS\system32\config\AppEvent.Evt L'objet est verrouillé ignoré

H:\WINDOWS\system32\config\default L'objet est verrouillé ignoré

H:\WINDOWS\system32\config\default.LOG L'objet est verrouillé ignoré

H:\WINDOWS\system32\config\SAM L'objet est verrouillé ignoré

H:\WINDOWS\system32\config\SAM.LOG L'objet est verrouillé ignoré

H:\WINDOWS\system32\config\SecEvent.Evt L'objet est verrouillé ignoré

H:\WINDOWS\system32\config\SECURITY L'objet est verrouillé ignoré

H:\WINDOWS\system32\config\SECURITY.LOG L'objet est verrouillé ignoré

H:\WINDOWS\system32\config\software L'objet est verrouillé ignoré

H:\WINDOWS\system32\config\software.LOG L'objet est verrouillé ignoré

H:\WINDOWS\system32\config\SysEvent.Evt L'objet est verrouillé ignoré

H:\WINDOWS\system32\config\system L'objet est verrouillé ignoré

H:\WINDOWS\system32\config\system.LOG L'objet est verrouillé ignoré

H:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR L'objet est verrouillé ignoré

H:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP L'objet est verrouillé ignoré

H:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER L'objet est verrouillé ignoré

H:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP L'objet est verrouillé ignoré

H:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP L'objet est verrouillé ignoré

H:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA L'objet est verrouillé ignoré

H:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP L'objet est verrouillé ignoré

H:\WINDOWS\Temp\Perflib_Perfdata_49c.dat L'objet est verrouillé ignoré

H:\WINDOWS\Temp\_avast4_\Webshlock.txt L'objet est verrouillé ignoré

H:\WINDOWS\wiadebug.log L'objet est verrouillé ignoré

H:\WINDOWS\wiaservc.log L'objet est verrouillé ignoré

H:\WINDOWS\WindowsUpdate.log L'objet est verrouillé ignoré

I:\System Volume Information\MountPointManagerRemoteDatabase L'objet est verrouillé ignoré

I:\System Volume Information\_restore{D40B74DA-7724-4332-B5A1-09AC8F27996D}\RP14\A0000742.exe/data0000.cab/INRHSU~1.EXE Infecté : Trojan.Win32.Agent.aomm ignoré

I:\System Volume Information\_restore{D40B74DA-7724-4332-B5A1-09AC8F27996D}\RP14\A0000742.exe/data0000.cab Infecté : Trojan.Win32.Agent.aomm ignoré

I:\System Volume Information\_restore{D40B74DA-7724-4332-B5A1-09AC8F27996D}\RP14\A0000742.exe Rsrc-Package: infecté - 2 ignoré

Analyse terminée.
Configuration: Windows XP
Internet Explorer 6.0

35 réponses

  • 1
  • 2
Résumé de la discussion

La discussion porte sur une détection antivirus sous Windows XP SP2 (IE6/Avast) révélant deux virus et plusieurs fichiers infectés, dont un rootkit et un trojan. L’analyse Kaspersky signale des éléments verrouillés et des objets dans divers dossiers système, avec des infections notables comme Rootkit.Win32.Small.bs et Trojan.Win32.Agent.aomm dans System Volume Information. Plusieurs répondants préconisent de compléter le diagnostic par RSIT et HijackThis, puis de partager les rapports log et info pour orienter le nettoyage et vérifier les chaînes de démarrage. En cas d'infections lourdes, la présence de fichiers verrouillés et de points de restauration peut nécessiter des mesures avancées et une révision des sauvegardes existantes.

Généré automatiquement par IA
sur la base des meilleures réponses
  1. sherred Messages postés 8605 Statut Membre 351
     
    tu a deux antivirus ?
    desinstalle avast si c'est le cas
    pour l'infection
    I:\System Volume Information\_restore{D40B74DA-7724-4332-B5A1-09AC8F27996D}\R­P14\A0000742.exe/data0000.cab/INRHSU~1.EXE Infecté : Trojan.Win32.Agent.aomm ignoré

    I:\System Volume Information\_restore{D40B74DA-7724-4332-B5A1-09AC8F27996D}\R­P14\A0000742.exe/data0000.cab Infecté : Trojan.Win32.Agent.aomm ignoré

    I:\System Volume Information\_restore{D40B74DA-7724-4332-B5A1-09AC8F27996D}\R­P14\A0000742.exe Rsrc-Package: infecté - 2 ignoré

    elle peu se supprimer plus tard en desactivant provisoirement la restauration

    fait un HijackThis
    télecharge ici https://www.clubic.com/telecharger-fiche17891-hijackthis.html

    Lance HijackThis en double cliquant sur son icône puis cliquez sur le bouton do a system scan and save a logfile

    Le rapport est retranscrit aussitôt apres le scan dans une fenêtre de type Bloc-notes
    il te suffit de realiser un copier/coller et de le poster dans le forum
    0
  2. tethys
     
    je n'ai que Avast, j'ai fait un sca en ligne avecKaspersky comme ça , juste pour voir...

    voici ce que tu as demandé

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 16:29:10, on 25/11/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    H:\WINDOWS\System32\smss.exe
    H:\WINDOWS\system32\winlogon.exe
    H:\WINDOWS\system32\services.exe
    H:\WINDOWS\system32\lsass.exe
    H:\WINDOWS\system32\svchost.exe
    H:\WINDOWS\System32\svchost.exe
    H:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    H:\Program Files\Alwil Software\Avast4\ashServ.exe
    H:\WINDOWS\system32\spoolsv.exe
    H:\WINDOWS\system32\igfxtray.exe
    H:\WINDOWS\system32\hkcmd.exe
    H:\Program Files\Analog Devices\SoundMAX\SMTray.exe
    H:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    H:\Program Files\DS-3200 Wireless Optical Slimline Deskset\MouseDrv.exe
    H:\Program Files\DS-3200 Wireless Optical Slimline Deskset\PS2USBKbdDrv.exe
    H:\Program Files\Fichiers communs\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe
    H:\WINDOWS\system32\PSIService.exe
    H:\PROGRA~1\Magentic\bin\MgApp.exe
    H:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    H:\Program Files\IncrediMail\bin\IMApp.exe
    H:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    H:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    H:\WINDOWS\system32\svchost.exe
    H:\WINDOWS\system32\wuauclt.exe
    H:\Program Files\IncrediMail\bin\IncMail.exe
    H:\WINDOWS\explorer.exe
    H:\Program Files\Internet Explorer\IEXPLORE.EXE
    H:\Program Files\Internet Explorer\IEXPLORE.EXE
    H:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.fr/keyword/%s
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O4 - HKLM\..\Run: [IgfxTray] H:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] H:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Smapp] H:\Program Files\Analog Devices\SoundMAX\SMTray.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "H:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [WireLessMouse] H:\Program Files\DS-3200 Wireless Optical Slimline Deskset\MouseDrv.exe
    O4 - HKLM\..\Run: [WireLessKeyboard] H:\Program Files\DS-3200 Wireless Optical Slimline Deskset\PS2USBKbdDrv.exe
    O4 - HKLM\..\Run: [QuickTime Task] "H:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Corel Photo Downloader] "H:\Program Files\Fichiers communs\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe" -startup
    O4 - HKCU\..\Run: [IncrediMail] H:\Program Files\IncrediMail\bin\IncMail.exe /c
    O4 - HKCU\..\Run: [Magentic] H:\PROGRA~1\Magentic\bin\Magentic.exe /c
    O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
    O4 - Startup: Adobe Gamma.lnk = H:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = H:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://H:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O15 - Trusted Zone: http://www.secuser.com
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O23 - Service: Adobe LM Service - Adobe Systems - H:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - H:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - H:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - H:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - H:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: ProtexisLicensing - Unknown owner - H:\WINDOWS\system32\PSIService.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - H:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    0
  3. sherred Messages postés 8605 Statut Membre 351
     
    redemarre hijacthis
    coche ces lignes
    O4 - HKLM\..\Run: [Corel Photo Downloader] "H:\Program Files\Fichiers communs\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe" -startup

    O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')

    O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')

    O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')

    O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')

    et clic sur fix checked
    redemarre le pc
    refait un hijac
    si ces lignes reaparaissent
    essaye en mode sans echec
    0
  4. tethys
     
    je ne les vois plus..je te poste le rapport quand même et je vais refaire un scan avec Kaspersky;
    peux tu me dire comment ils sont arrivés ?

    Merci de ton aide !
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. tethys
     
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 08:12:07, on 26/11/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    H:\WINDOWS\System32\smss.exe
    H:\WINDOWS\system32\winlogon.exe
    H:\WINDOWS\system32\services.exe
    H:\WINDOWS\system32\lsass.exe
    H:\WINDOWS\system32\svchost.exe
    H:\WINDOWS\System32\svchost.exe
    H:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    H:\Program Files\Alwil Software\Avast4\ashServ.exe
    H:\WINDOWS\Explorer.EXE
    H:\WINDOWS\system32\spoolsv.exe
    H:\WINDOWS\system32\igfxtray.exe
    H:\WINDOWS\system32\hkcmd.exe
    H:\Program Files\Analog Devices\SoundMAX\SMTray.exe
    H:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    H:\Program Files\DS-3200 Wireless Optical Slimline Deskset\MouseDrv.exe
    H:\Program Files\DS-3200 Wireless Optical Slimline Deskset\PS2USBKbdDrv.exe
    H:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    H:\WINDOWS\system32\PSIService.exe
    H:\PROGRA~1\Magentic\bin\MgApp.exe
    H:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    H:\Program Files\IncrediMail\bin\IMApp.exe
    H:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    H:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    H:\Program Files\Internet Explorer\IEXPLORE.EXE
    H:\WINDOWS\system32\wuauclt.exe
    H:\WINDOWS\system32\wuauclt.exe
    H:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.fr/keyword/%s
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O4 - HKLM\..\Run: [IgfxTray] H:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] H:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Smapp] H:\Program Files\Analog Devices\SoundMAX\SMTray.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "H:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [WireLessMouse] H:\Program Files\DS-3200 Wireless Optical Slimline Deskset\MouseDrv.exe
    O4 - HKLM\..\Run: [WireLessKeyboard] H:\Program Files\DS-3200 Wireless Optical Slimline Deskset\PS2USBKbdDrv.exe
    O4 - HKLM\..\Run: [QuickTime Task] "H:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [IncrediMail] H:\Program Files\IncrediMail\bin\IncMail.exe /c
    O4 - HKCU\..\Run: [Magentic] H:\PROGRA~1\Magentic\bin\Magentic.exe /c
    O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user')
    O4 - Startup: Adobe Gamma.lnk = H:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = H:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://H:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O15 - Trusted Zone: http://www.secuser.com
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O23 - Service: Adobe LM Service - Adobe Systems - H:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - H:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - H:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - H:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - H:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: ProtexisLicensing - Unknown owner - H:\WINDOWS\system32\PSIService.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - H:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    0
  7. Utilisateur anonyme
     
    Hi,

    Tu as une infection =>VUNDO.

    Fait ceci STP.

    Combofix. Attention, ce logiciel est très puissant, une mauvaise utilisation peut faire des dégâts...

    Fais exactement ce qui suit :

    Télécharge ComboFix (de sUBs) sur ton Bureau (et pas ailleurs !) :
    Fais un clic droit sur ce lien et choisis "enregistrer la cible sous ... " : dans la fenêtre qui s'ouvre tape C-Fix, choisis le bureau comme destination et valide :

    --------------------------------------------- [ ! ATTENTION ! ] ----------------------------------------------------------
    !! déconnecte toi, ferme toutes tes applications en cours et DESACTIVE TOUTES TES DEFENCES (anti-virus, antispyware, pare-feu) le temps de la manipulation (si jamais tu en as et que je ne les ai pas vu sur le rapport hijackthis....)

    ---> Surtout, si tu rencontres des difficultés à ce niveau là, dis le moi avant de poursuivre...

    Tuto ici : TUTO
    ---------------------------------------------------------------------------------------------------------------------------------

    Ensuite :

    Double-clique sur C-Fix.exe (= combofix.exe ) .

    Appuie sur une touche pour démarrer le scan .

    Attention : n'utilise pas ta souris ni ton clavier pendant que le programme tourne. Cela pourrait figer l'ordi ---> si un message d'erreur windows apparait à un moment : clique sur la croix rouge en haut à droite de la fenêtre pour la fermer

    Le rapport sera crée dans: C:\Combofix.txt , poste le ici stp
    0
  8. tethys
     
    voici!

    ComboFix 08-11-26.03 - kat 2008-11-26 8:33:20.3 - NTFSx86
    Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.282 [GMT 1:00]
    Lancé depuis: h:\documents and settings\kat\Bureau\ComboFix.exe
    * Un nouveau point de restauration a été créé
    .

    ((((((((((((((((((((((((((((( Fichiers créés du 2008-10-26 au 2008-11-26 ))))))))))))))))))))))))))))))))))))
    .

    2008-11-25 13:49 . 2008-11-25 13:49 <REP> d-------- h:\windows\system32\Kaspersky Lab
    2008-11-21 23:18 . 2008-11-21 23:18 8 -r-hs---- h:\windows\system32\296C8A12A0.sys
    2008-11-19 12:34 . 2008-11-19 12:34 <REP> d-------- h:\program files\Fichiers communs\Nero
    2008-11-19 12:32 . 2001-03-08 18:30 24,064 --------- h:\windows\system32\msxml3a.dll
    2008-11-19 12:30 . 2008-11-19 12:30 <REP> d-------- h:\documents and settings\All Users\Application Data\Ahead
    2008-11-08 09:57 . 2008-11-08 09:57 <REP> d-------- h:\windows\AU_Temp
    2008-11-08 09:57 . 2008-11-08 09:57 40 --a------ h:\windows\TSC.INI
    2008-11-08 09:55 . 2008-11-08 09:55 <REP> d-------- h:\windows\AU_Log
    2008-11-08 09:55 . 2008-11-08 09:55 170 --a------ h:\windows\GetServer.ini
    2008-11-07 21:37 . 2008-11-07 21:37 <REP> d-------- h:\program files\Malwarebytes' Anti-Malware
    2008-11-07 21:37 . 2008-11-07 21:37 <REP> d-------- h:\documents and settings\kat\Application Data\Malwarebytes
    2008-11-07 21:37 . 2008-11-07 21:37 <REP> d-------- h:\documents and settings\All Users\Application Data\Malwarebytes
    2008-11-07 21:37 . 2008-10-22 16:10 38,496 --a------ h:\windows\system32\drivers\mbamswissarmy.sys
    2008-11-07 21:37 . 2008-10-22 16:10 15,504 --a------ h:\windows\system32\drivers\mbam.sys
    2008-11-06 18:35 . 2008-11-25 16:28 <REP> d-------- h:\program files\trend micro
    2008-11-06 14:27 . 2008-11-08 09:55 507,904 --a------ h:\windows\TMUPDATE.DLL
    2008-11-06 14:27 . 2008-11-08 09:55 286,720 --a------ h:\windows\PATCH.EXE
    2008-11-06 14:27 . 2008-11-08 09:55 69,689 --a------ h:\windows\UNZIP.DLL
    2008-10-26 18:17 . 2008-11-25 10:45 54,156 --ah----- h:\windows\QTFont.qfn
    2008-10-26 18:17 . 2008-10-26 18:17 1,409 --a------ h:\windows\QTFont.for

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-11-21 22:37 --------- d-----w h:\documents and settings\kat\Application Data\Azureus
    2008-11-21 22:18 2,516 --sha-w h:\windows\system32\KGyGaAvL.sys
    2008-11-19 14:34 --------- d-----w h:\program files\Ahead
    2008-11-07 21:10 --------- d-----w h:\program files\a-squared Free
    2008-11-03 08:05 --------- d-----w h:\program files\Vuze
    2008-10-28 16:49 --------- d-----w h:\program files\eMule
    2008-10-24 11:10 453,632 ----a-w h:\windows\system32\drivers\mrxsmb.sys
    2008-10-17 12:23 --------- d--h--w h:\program files\InstallShield Installation Information
    2008-10-17 12:23 --------- d-----w h:\program files\Serif
    2008-10-16 22:40 --------- d-----w h:\program files\Fichiers communs\InstallShield
    2008-10-01 09:11 --------- d-----w h:\documents and settings\kat\Application Data\AdobeUM
    2008-09-30 15:43 1,286,152 ----a-w h:\windows\system32\msxml4.dll
    2008-09-28 20:49 --------- d-----w h:\program files\IncrediMail
    2008-09-15 15:39 1,846,144 ----a-w h:\windows\system32\win32k.sys
    2008-09-04 16:45 1,106,944 ------w h:\windows\system32\msxml3.dll
    .

    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IncrediMail"="h:\program files\IncrediMail\bin\IncMail.exe" [2008-07-24 243072]
    "Magentic"="h:\progra~1\Magentic\bin\Magentic.exe" [2007-10-09 475180]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IgfxTray"="h:\windows\system32\igfxtray.exe" [2003-07-09 155648]
    "HotKeysCmds"="h:\windows\system32\hkcmd.exe" [2003-07-09 114688]
    "Smapp"="h:\program files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 143360]
    "SunJavaUpdateSched"="h:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
    "WireLessMouse"="h:\program files\DS-3200 Wireless Optical Slimline Deskset\MouseDrv.exe" [2005-08-30 303104]
    "WireLessKeyboard"="h:\program files\DS-3200 Wireless Optical Slimline Deskset\PS2USBKbdDrv.exe" [2005-08-30 319488]
    "QuickTime Task"="h:\program files\QuickTime\qttask.exe" [2008-04-12 413696]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "nlsf"="move" [X]
    "tscuninstall"="h:\windows\system32\tscupgrd.exe" [2004-08-19 44544]

    h:\documents and settings\kat\Menu D‚marrer\Programmes\D‚marrage\
    Adobe Gamma.lnk - h:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]

    h:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
    Lancement rapide d'Adobe Reader.lnk - h:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "MemCheckBoxInRunDlg"= 1 (0x1)
    "NoSMBalloonTip"= 1 (0x1)
    "NoWelcomeScreen"= 1 (0x1)
    "NoStrCmpLogical"= 0 (0x0)

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
    "MemCheckBoxInRunDlg"= 1 (0x1)
    "NoSMBalloonTip"= 1 (0x1)
    "NoWelcomeScreen"= 1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000001
    "FirewallOverride"=dword:00000001
    "AntiVirusDisableNotify"=dword:00000001
    "UpdatesDisableNotify"=dword:00000001
    "DisablePagingExecutive"=dword:00000001
    "SecondLevelDataCache"=dword:00000200

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)
    "DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "h:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
    "h:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
    "h:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
    "h:\\Program Files\\Magentic\\bin\\MgImp.exe"=
    "h:\\Program Files\\Magentic\\bin\\Magentic.exe"=
    "h:\\Program Files\\Magentic\\bin\\MgApp.exe"=
    "h:\\Program Files\\Vuze\\Azureus.exe"=
    "h:\\Program Files\\eMule\\emule.exe"=
    "h:\\Documents and Settings\\kat\\Mes documents\\eMule\\emule.exe"=

    R1 aswSP;avast! Self Protection;h:\windows\system32\drivers\aswSP.sys [2008-04-04 78416]
    R2 aswFsBlk;aswFsBlk;h:\windows\system32\DRIVERS\aswFsBlk.sys [2008-04-04 20560]
    .
    Contenu du dossier 'Tâches planifiées'

    2008-11-20 h:\windows\Tasks\AppleSoftwareUpdate.job
    - h:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-11-26 08:34:47
    Windows 5.1.2600 Service Pack 2 NTFS

    Recherche de processus cachés ...

    Recherche d'éléments en démarrage automatique cachés ...

    Recherche de fichiers cachés ...

    Scan terminé avec succès
    Fichiers cachés: 0

    **************************************************************************
    .
    Heure de fin: 2008-11-26 8:35:38
    ComboFix-quarantined-files.txt 2008-11-26 07:35:35

    Avant-CF: 42 681 733 120 octets libres
    Après-CF: 42,678,820,864 octets libres

    121 --- E O F --- 2008-11-16 22:05:01
    0
  9. Utilisateur anonyme
     
    Hi,

    Refait un hijackthis.

    Alut.
    0
  10. tethys
     
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 08:41:50, on 26/11/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    H:\WINDOWS\System32\smss.exe
    H:\WINDOWS\system32\winlogon.exe
    H:\WINDOWS\system32\services.exe
    H:\WINDOWS\system32\lsass.exe
    H:\WINDOWS\system32\svchost.exe
    H:\WINDOWS\System32\svchost.exe
    H:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    H:\Program Files\Alwil Software\Avast4\ashServ.exe
    H:\WINDOWS\system32\spoolsv.exe
    H:\WINDOWS\system32\igfxtray.exe
    H:\WINDOWS\system32\hkcmd.exe
    H:\Program Files\Analog Devices\SoundMAX\SMTray.exe
    H:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    H:\Program Files\DS-3200 Wireless Optical Slimline Deskset\MouseDrv.exe
    H:\Program Files\DS-3200 Wireless Optical Slimline Deskset\PS2USBKbdDrv.exe
    H:\WINDOWS\system32\PSIService.exe
    H:\PROGRA~1\Magentic\bin\MgApp.exe
    H:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    H:\Program Files\IncrediMail\bin\IMApp.exe
    H:\Program Files\Alwil Software\Avast4\ashDisp.exe
    H:\WINDOWS\explorer.exe
    H:\Program Files\trend micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.fr/keyword/%s
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O4 - HKLM\..\Run: [IgfxTray] H:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] H:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Smapp] H:\Program Files\Analog Devices\SoundMAX\SMTray.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "H:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [WireLessMouse] H:\Program Files\DS-3200 Wireless Optical Slimline Deskset\MouseDrv.exe
    O4 - HKLM\..\Run: [WireLessKeyboard] H:\Program Files\DS-3200 Wireless Optical Slimline Deskset\PS2USBKbdDrv.exe
    O4 - HKLM\..\Run: [QuickTime Task] "H:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [IncrediMail] H:\Program Files\IncrediMail\bin\IncMail.exe /c
    O4 - HKCU\..\Run: [Magentic] H:\PROGRA~1\Magentic\bin\Magentic.exe /c
    O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user')
    O4 - Startup: Adobe Gamma.lnk = H:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = H:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://H:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O15 - Trusted Zone: http://www.secuser.com
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O23 - Service: Adobe LM Service - Adobe Systems - H:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - H:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - H:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - H:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - H:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: ProtexisLicensing - Unknown owner - H:\WINDOWS\system32\PSIService.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - H:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    0
  11. Utilisateur anonyme
     
    Hi,

    -Télécharge et installe MalwareByte's Anti-Malware
    Malwarebyte

    - Mets le à jour

    ---
    - Double clique sur le raccourci de MalwareByte's Anti-Malware qui est sur le bureau.
    - Sélectionne Exécuter un examen complet si ce n'est pas déjà fait
    - clique sur Rechercher

    - Une fois le scan terminé, une fenêtre s'ouvre, clique sur sur Ok

    - Si MalwareByte's n'a rien détecté, clique sur Ok Un rapport va apparaître ferme-le.

    - Si MalwareByte's a détecté des infections, clique sur Afficher les résultats ensuite sur Supprimer la sélection

    - Enregistre le rapport sur ton Bureau comme cela il sera plus facile à retrouver, poste ensuite ce rapport.

    Note : Si MalwareByte's a besoin de redémarrer pour terminer la suppression, accepte en cliquant sur Ok
    0
  12. tethys
     
    j'avais dejà Malwarebytes, mais pas passé depuis 10 jours ?
    j'ai fait un scan complet , il n'y aplus rien !

    Malwarebytes' Anti-Malware 1.30
    Version de la base de données: 1424
    Windows 5.1.2600 Service Pack 2

    26/11/2008 09:08:26
    mbam-log-2008-11-26 (09-08-26).txt

    Type de recherche: Examen complet (H:\|I:\|)
    Eléments examinés: 89290
    Temps écoulé: 13 minute(s), 22 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 0

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    (Aucun élément nuisible détecté)
    0
  13. tethys
     
    au milieu du rapport il s'est arreté avec message "Windows pas de disque " !!!!???
    0
  14. tethys
     
    rapport quand même !
    ComboFix 08-11-26.03 - kat 2008-11-26 9:28:17.4 - NTFSx86
    Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.255 [GMT 1:00]
    Lancé depuis: h:\documents and settings\kat\Bureau\ComboFix.exe
    .

    ((((((((((((((((((((((((((((( Fichiers créés du 2008-10-26 au 2008-11-26 ))))))))))))))))))))))))))))))))))))
    .

    2008-11-25 13:49 . 2008-11-25 13:49 <REP> d-------- h:\windows\system32\Kaspersky Lab
    2008-11-21 23:18 . 2008-11-21 23:18 8 -r-hs---- h:\windows\system32\296C8A12A0.sys
    2008-11-19 12:34 . 2008-11-19 12:34 <REP> d-------- h:\program files\Fichiers communs\Nero
    2008-11-19 12:32 . 2001-03-08 18:30 24,064 --------- h:\windows\system32\msxml3a.dll
    2008-11-19 12:30 . 2008-11-19 12:30 <REP> d-------- h:\documents and settings\All Users\Application Data\Ahead
    2008-11-08 09:57 . 2008-11-08 09:57 <REP> d-------- h:\windows\AU_Temp
    2008-11-08 09:57 . 2008-11-08 09:57 40 --a------ h:\windows\TSC.INI
    2008-11-08 09:55 . 2008-11-08 09:55 <REP> d-------- h:\windows\AU_Log
    2008-11-08 09:55 . 2008-11-08 09:55 170 --a------ h:\windows\GetServer.ini
    2008-11-07 21:37 . 2008-11-07 21:37 <REP> d-------- h:\program files\Malwarebytes' Anti-Malware
    2008-11-07 21:37 . 2008-11-07 21:37 <REP> d-------- h:\documents and settings\kat\Application Data\Malwarebytes
    2008-11-07 21:37 . 2008-11-07 21:37 <REP> d-------- h:\documents and settings\All Users\Application Data\Malwarebytes
    2008-11-07 21:37 . 2008-10-22 16:10 38,496 --a------ h:\windows\system32\drivers\mbamswissarmy.sys
    2008-11-07 21:37 . 2008-10-22 16:10 15,504 --a------ h:\windows\system32\drivers\mbam.sys
    2008-11-06 18:35 . 2008-11-25 16:28 <REP> d-------- h:\program files\trend micro
    2008-11-06 14:27 . 2008-11-08 09:55 507,904 --a------ h:\windows\TMUPDATE.DLL
    2008-11-06 14:27 . 2008-11-08 09:55 286,720 --a------ h:\windows\PATCH.EXE
    2008-11-06 14:27 . 2008-11-08 09:55 69,689 --a------ h:\windows\UNZIP.DLL
    2008-10-26 18:17 . 2008-11-25 10:45 54,156 --ah----- h:\windows\QTFont.qfn
    2008-10-26 18:17 . 2008-10-26 18:17 1,409 --a------ h:\windows\QTFont.for

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-11-21 22:37 --------- d-----w h:\documents and settings\kat\Application Data\Azureus
    2008-11-21 22:18 2,516 --sha-w h:\windows\system32\KGyGaAvL.sys
    2008-11-19 14:34 --------- d-----w h:\program files\Ahead
    2008-11-07 21:10 --------- d-----w h:\program files\a-squared Free
    2008-11-03 08:05 --------- d-----w h:\program files\Vuze
    2008-10-28 16:49 --------- d-----w h:\program files\eMule
    2008-10-24 11:10 453,632 ----a-w h:\windows\system32\drivers\mrxsmb.sys
    2008-10-17 12:23 --------- d--h--w h:\program files\InstallShield Installation Information
    2008-10-17 12:23 --------- d-----w h:\program files\Serif
    2008-10-16 22:40 --------- d-----w h:\program files\Fichiers communs\InstallShield
    2008-10-01 09:11 --------- d-----w h:\documents and settings\kat\Application Data\AdobeUM
    2008-09-30 15:43 1,286,152 ----a-w h:\windows\system32\msxml4.dll
    2008-09-28 20:49 --------- d-----w h:\program files\IncrediMail
    2008-09-15 15:39 1,846,144 ----a-w h:\windows\system32\win32k.sys
    2008-09-04 16:45 1,106,944 ------w h:\windows\system32\msxml3.dll
    .

    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IncrediMail"="h:\program files\IncrediMail\bin\IncMail.exe" [2008-07-24 243072]
    "Magentic"="h:\progra~1\Magentic\bin\Magentic.exe" [2007-10-09 475180]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IgfxTray"="h:\windows\system32\igfxtray.exe" [2003-07-09 155648]
    "HotKeysCmds"="h:\windows\system32\hkcmd.exe" [2003-07-09 114688]
    "Smapp"="h:\program files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 143360]
    "SunJavaUpdateSched"="h:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
    "WireLessMouse"="h:\program files\DS-3200 Wireless Optical Slimline Deskset\MouseDrv.exe" [2005-08-30 303104]
    "WireLessKeyboard"="h:\program files\DS-3200 Wireless Optical Slimline Deskset\PS2USBKbdDrv.exe" [2005-08-30 319488]
    "QuickTime Task"="h:\program files\QuickTime\qttask.exe" [2008-04-12 413696]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "nlsf"="move" [X]
    "tscuninstall"="h:\windows\system32\tscupgrd.exe" [2004-08-19 44544]

    h:\documents and settings\kat\Menu D‚marrer\Programmes\D‚marrage\
    Adobe Gamma.lnk - h:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]

    h:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
    Lancement rapide d'Adobe Reader.lnk - h:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "MemCheckBoxInRunDlg"= 1 (0x1)
    "NoSMBalloonTip"= 1 (0x1)
    "NoWelcomeScreen"= 1 (0x1)
    "NoStrCmpLogical"= 0 (0x0)

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
    "MemCheckBoxInRunDlg"= 1 (0x1)
    "NoSMBalloonTip"= 1 (0x1)
    "NoWelcomeScreen"= 1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000001
    "FirewallOverride"=dword:00000001
    "AntiVirusDisableNotify"=dword:00000001
    "UpdatesDisableNotify"=dword:00000001
    "DisablePagingExecutive"=dword:00000001
    "SecondLevelDataCache"=dword:00000200

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)
    "DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "h:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
    "h:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
    "h:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
    "h:\\Program Files\\Magentic\\bin\\MgImp.exe"=
    "h:\\Program Files\\Magentic\\bin\\Magentic.exe"=
    "h:\\Program Files\\Magentic\\bin\\MgApp.exe"=
    "h:\\Program Files\\Vuze\\Azureus.exe"=
    "h:\\Program Files\\eMule\\emule.exe"=
    "h:\\Documents and Settings\\kat\\Mes documents\\eMule\\emule.exe"=

    R1 aswSP;avast! Self Protection;h:\windows\system32\drivers\aswSP.sys [2008-04-04 78416]
    R2 aswFsBlk;aswFsBlk;h:\windows\system32\DRIVERS\aswFsBlk.sys [2008-04-04 20560]

    *Newly Created Service* - CATCHME
    .
    Contenu du dossier 'Tâches planifiées'

    2008-11-20 h:\windows\Tasks\AppleSoftwareUpdate.job
    - h:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-11-26 09:29:43
    Windows 5.1.2600 Service Pack 2 NTFS

    Recherche de processus cachés ...

    Recherche d'éléments en démarrage automatique cachés ...

    Recherche de fichiers cachés ...

    Scan terminé avec succès
    Fichiers cachés: 0

    **************************************************************************
    .
    Heure de fin: 2008-11-26 9:30:41
    ComboFix-quarantined-files.txt 2008-11-26 08:30:30
    ComboFix2.txt 2008-11-26 07:35:41

    Avant-CF: 42 674 475 008 octets libres
    Après-CF: 42,669,768,704 octets libres

    122 --- E O F --- 2008-11-16 22:05:01
    0
  15. Utilisateur anonyme
     
    Hi,

    Fait un scan avec malwarebyte en mode sans échec.

    Alut.
    0
  16. tethys
     
    je n'arrive pas a me mettre en mode sans echec...quel est le moyern le plus simple ? please....
    0
    1. sherred Messages postés 8605 Statut Membre 351
       
      le mode sans echec ne fonctionne pas ??
      réparer l'accès au mode sans échec, en téléchargeant : SafeBootKeyRepair
      https://download.bleepingcomputer.com/sUBs/SafeBootKeyRepair.exe
      ou allez ici http://www.assistepc.com/forum/reparer-le-mode-sans-echec-de-windows-vt867.html
      0
  17. tethys
     
    j'y suis arrivée avec F8, je le mettais trop tot!
    alors le resulat:

    il y a hijack.Tart Menu HKEY_CURRENT_USER.....
    0
  18. tethys
     
    Sorry ..START menu...je pense que tu avais compris...
    0
  19. tethys
     
    je suis entrain de faire un scan avec Avast qui a dejà trouvé qq chose me diasant de le mettre en quarantaine ..je l'ai fait ; ça continue de scaner;
    je sors, je vous donnerai la reponse du scan en rentrant; Merci pour tout
    a +
    0
  20. Utilisateur anonyme
     
    Hi,

    Je t'avait demander un scan en mode sans échec avec malwarebyte .

    pas d'hijackthis en mode sans échec.

    poste le rapport.

    Alut.
    0
  • 1
  • 2