Warning! Dangerous Spyware - Page 2

Précédent
  • 1
  • 2
  1. Utilisateur anonyme
     
    Copie le texte ci-dessous :

    File::
    c:\windows\system32\tmp.reg
    c:\windows\system32\SrchSTS.exe
    c:\windows\system32\VACFix.exe
    c:\windows\system32\o4Patch.exe
    c:\windows\system32\IEDFix.exe
    c:\windows\system32\IEDFix.C.exe
    c:\windows\system32\404Fix.exe
    c:\windows\system32\Process.exe
    c:\windows\system32\dumphive.exe
    c:\windows\system32\WS2Fix.exe
    c:\windows\system32\frmwrk32.exe
    c:\windows\system32\warning.gif

    Folder::
    c:\program files\Fichiers communs\BOONTY Shared
    c:\program files\Boonty
    C:\ToolBar SD

    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Framework Windows"=-


    Ouvre le Bloc-Notes puis colle le texte copié.
    (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
    Sauvegarde ce fichier sous le nom de CFScript.txt

    Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ceci :

    Cela va relancer Combofix,

    Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

    Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

    Ne touche à rien tant que le scan n'est pas terminé.

    Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.

    S'il n'y a pas de rédémarrage, poste quand même les rapports.
    0
  2. Autumn1608 Messages postés 88 Date d'inscription   Statut Membre Dernière intervention   2
     
    Il n'y a pas eu de redemarrage.

    Rapport Combofix :

    ComboFix 08-11-30.01 - Autumn_2 2008-11-30 20:26:51.4 - NTFSx86
    Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.1196 [GMT 1:00]
    Lancé depuis: c:\documents and settings\Autumn_2\Bureau\ComboFix.exe
    Commutateurs utilisés :: c:\documents and settings\Autumn_2\Bureau\CFScript.txt
    * Un nouveau point de restauration a été créé

    FILE ::
    c:\windows\system32\404Fix.exe
    c:\windows\system32\dumphive.exe
    c:\windows\system32\frmwrk32.exe
    c:\windows\system32\IEDFix.C.exe
    c:\windows\system32\IEDFix.exe
    c:\windows\system32\o4Patch.exe
    c:\windows\system32\Process.exe
    c:\windows\system32\SrchSTS.exe
    c:\windows\system32\tmp.reg
    c:\windows\system32\VACFix.exe
    c:\windows\system32\warning.gif
    c:\windows\system32\WS2Fix.exe
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\program files\Boonty
    c:\program files\Fichiers communs\BOONTY Shared
    c:\program files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
    C:\ToolBar SD
    c:\toolbar sd\AutrInf.cmd
    c:\toolbar sd\Back.cmd
    c:\toolbar sd\Backup-TB\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\Dealio Deskbar.lnk
    c:\toolbar sd\Backup-TB\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\Help.url
    c:\toolbar sd\Backup-TB\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\Seekmo Customer Support Center.lnk
    c:\toolbar sd\Backup-TB\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\Uninstall.lnk
    c:\toolbar sd\Backup-TB\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\What is Dealio.url
    c:\toolbar sd\Backup-TB\DOCUME~1\Autumn_2\Cookies\autumn_2@bananalotto[1].txt
    c:\toolbar sd\Backup-TB\DOCUME~1\Autumn_2\Cookies\autumn_2@www.bananalotto[2].txt
    c:\toolbar sd\Backup-TB\Program Files\Dealio\Dealio Deskbar.exe
    c:\toolbar sd\Backup-TB\Program Files\Dealio\Dealio.dll
    c:\toolbar sd\Backup-TB\Program Files\Dealio\DealioAU.exe
    c:\toolbar sd\Backup-TB\Program Files\Dealio\DealioRes409.dll
    c:\toolbar sd\Backup-TB\Program Files\Dealio\SearchSettingsKit.exe
    c:\toolbar sd\Backup-TB\Program Files\Search Settings\SearchSettings.dll
    c:\toolbar sd\Backup-TB\Program Files\Search Settings\SearchSettings.exe
    c:\toolbar sd\Backup-TB\Program Files\Search Settings\SearchSettingsRes409.dll
    c:\toolbar sd\Backup-TB\Reg\HKCU_Run.reg
    c:\toolbar sd\Backup-TB\Reg\HKLM_BHO.reg
    c:\toolbar sd\Backup-TB\Reg\HKLM_Classes.reg
    c:\toolbar sd\Backup-TB\Reg\HKLM_Run.reg
    c:\toolbar sd\Backup-TB\Reg\HKLM_ToolBar.reg
    c:\toolbar sd\Backup-TB\Reg\HKLM_Uninstall.reg
    c:\toolbar sd\Backup-TB\WINDOWS\Prefetch\BUILDALOT2.EXE-0E791682.pf
    c:\toolbar sd\Backup-TB\WINDOWS\Prefetch\SEARCHSETTINGS.EXE-253CB611.pf
    c:\toolbar sd\Changelog ToolBar.txt
    c:\toolbar sd\Crack.txt
    c:\toolbar sd\DemP.cmd
    c:\toolbar sd\DirectFix.cmd
    c:\toolbar sd\Discl_en.vbs
    c:\toolbar sd\Discl_fr.vbs
    c:\toolbar sd\Discl_sp.vbs
    c:\toolbar sd\Doss.tbsd
    c:\toolbar sd\Fich.cmd
    c:\toolbar sd\FixExt.cmd
    c:\toolbar sd\iNv.exe
    c:\toolbar sd\Kill.cmd
    c:\toolbar sd\Langues.cmd
    c:\toolbar sd\Orph.egd
    c:\toolbar sd\OsV.exe
    c:\toolbar sd\paths.bat
    c:\toolbar sd\pv.exe
    c:\toolbar sd\Rech.cmd
    c:\toolbar sd\RegP2.txt
    c:\toolbar sd\RegP3.txt
    c:\toolbar sd\RegP4.txt
    c:\toolbar sd\RegP5.txt
    c:\toolbar sd\RegPCU.txt
    c:\toolbar sd\RegPLM.txt
    c:\toolbar sd\RegTBSD.reg
    c:\toolbar sd\Rkeys.txt
    c:\toolbar sd\RKit.lsd
    c:\toolbar sd\RoGUeS.lsd
    c:\toolbar sd\RunTool.txt
    c:\toolbar sd\sed.exe
    c:\toolbar sd\setpath.exe
    c:\toolbar sd\TB_1.txt
    c:\toolbar sd\TB_2.txt
    c:\toolbar sd\ToolBarSD.cmd
    c:\toolbar sd\ToolBarSD.ico
    c:\toolbar sd\Uninstal.exe
    c:\windows\system32\404Fix.exe
    c:\windows\system32\dumphive.exe
    c:\windows\system32\frmwrk32.exe
    c:\windows\system32\IEDFix.C.exe
    c:\windows\system32\IEDFix.exe
    c:\windows\system32\o4Patch.exe
    c:\windows\system32\Process.exe
    c:\windows\system32\SrchSTS.exe
    c:\windows\system32\tmp.reg
    c:\windows\system32\VACFix.exe
    c:\windows\system32\warning.gif
    c:\windows\system32\WS2Fix.exe

    .
    ((((((((((((((((((((((((((((( Fichiers créés du 2008-10-28 au 2008-11-30 ))))))))))))))))))))))))))))))))))))
    .

    2008-11-30 17:05 . 2007-09-05 23:22 289,144 --a------ c:\windows\system32\VCCLSID.exe
    2008-11-29 23:22 . 2008-11-30 20:00 3,104 --a------ c:\windows\system32\ntdll64.exe
    2008-11-29 23:22 . 2008-11-30 20:00 1,349 --a------ c:\windows\system32\ahtn.htm
    2008-11-29 23:22 . 2008-11-29 23:22 1 --a------ c:\windows\system32\uniq.tll
    2008-11-29 23:22 . 2008-11-29 23:22 1 --a------ c:\windows\system32\test.ttt
    2008-11-26 17:06 . 2008-11-26 17:06 410,976 --a------ c:\windows\system32\deploytk.dll
    2008-11-26 10:58 . 2008-11-26 10:58 297,697 --a------ c:\windows\system32\SpywareRemover.exe
    2008-11-24 10:45 . 2008-11-24 10:45 <REP> d-------- c:\windows\Zodiac Tower
    2008-11-24 10:45 . 2008-11-24 10:45 <REP> d-------- c:\program files\Zodiac Tower
    2008-11-24 10:44 . 2008-11-24 12:05 <REP> d-------- c:\program files\Ancient Zodiac Tower
    2008-11-23 18:23 . 2008-11-23 20:44 54,156 --ah----- c:\windows\QTFont.qfn
    2008-11-23 18:23 . 2008-11-23 18:23 1,409 --a------ c:\windows\QTFont.for
    2008-11-23 17:59 . 2008-11-23 18:19 <REP> d-------- c:\documents and settings\Autumn_2\Application Data\SecondLife
    2008-11-23 17:58 . 2008-11-23 18:00 <REP> d-------- c:\program files\SecondLife
    2008-11-23 10:25 . 2008-11-23 10:25 <REP> d-------- c:\program files\Build-Lot2.Town
    2008-11-23 10:25 . 2008-11-23 10:25 <REP> d-------- c:\program files\Build-a-lot 2 Town of the Year
    2008-11-23 00:23 . 2008-11-23 00:23 <REP> d-------- c:\program files\ReflexiveArcade
    2008-11-23 00:16 . 2007-10-02 21:01 56,098,816 --a------ c:\program files\Build A Lot_FULLversion.exe
    2008-11-23 00:15 . 2008-11-23 00:20 <REP> d-------- c:\program files\DragonStone
    2008-11-21 15:31 . 2008-04-14 04:33 159,232 --a------ c:\windows\system32\ptpusd.dll
    2008-11-21 15:31 . 2001-08-23 17:47 5,632 --a------ c:\windows\system32\ptpusb.dll
    2008-11-19 22:45 . 2008-11-25 11:44 <REP> d-------- c:\documents and settings\All Users\Application Data\HipSoft
    2008-11-19 21:20 . 2008-11-19 21:20 <REP> d-------- c:\documents and settings\All Users\Application Data\Trymedia
    2008-11-19 21:19 . 2008-11-20 17:33 <REP> d-------- c:\program files\BFG
    2008-11-16 21:01 . 2008-11-16 21:01 <REP> d-------- c:\documents and settings\All Users\Application Data\PlayPond
    2008-11-15 16:22 . 2008-11-15 16:22 <REP> d-------- c:\program files\Secrets Of Olympus
    2008-11-14 07:07 . 2008-11-14 07:07 <REP> d-------- c:\program files\MSXML 4.0
    2008-11-13 10:32 . 2008-09-04 18:16 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
    2008-11-13 10:32 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
    2008-11-10 17:47 . 2008-11-10 17:47 <REP> d-------- c:\documents and settings\Autumn_2\Application Data\Ahead
    2008-11-07 23:42 . 2008-11-07 23:42 <REP> d-------- c:\program files\Heroes of Hellas
    2008-11-07 21:59 . 2008-11-07 21:59 13 --a------ c:\windows\popcinfo.dat
    2008-11-07 13:51 . 2008-11-07 13:51 <REP> d-------- c:\documents and settings\All Users\Application Data\n7-89-o9-3r-4t-r9
    2008-11-06 11:52 . 2008-11-06 11:52 193 --a------ c:\windows\cncscore.ini
    2008-11-06 11:51 . 2008-11-06 13:54 <REP> d-------- C:\Olltwit
    2008-11-06 11:51 . 2008-11-06 11:51 281,088 --a------ c:\windows\system32\cncs232.dll
    2008-11-06 10:45 . 2008-11-17 23:48 <REP> d-------- c:\program files\Mirror Magic
    2008-11-04 22:27 . 2008-11-04 22:27 15,872 --------- c:\windows\system32\winskfr.dll
    2008-11-03 14:20 . 2008-11-03 14:20 <REP> d-------- C:\CaffeLatte
    2008-11-02 15:52 . 2008-11-02 16:03 <REP> d-------- c:\program files\Téléchargeur de Beach Life
    2008-10-29 08:08 . 2008-10-29 08:08 <REP> d--hs---- c:\windows\ftpcache
    2008-10-28 19:43 . 2008-10-28 19:43 <REP> d-------- c:\documents and settings\Autumn_2\Application Data\TuneUp Software
    2008-10-28 10:10 . 2008-10-28 10:10 <REP> d-------- c:\documents and settings\All Users\Application Data\SugarGames
    2008-10-24 06:11 . 2008-10-15 17:35 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
    2008-10-22 22:05 . 2008-10-22 22:05 <REP> d-------- c:\documents and settings\All Users\Application Data\MythPeople
    2008-10-19 19:45 . 2008-10-19 19:45 <REP> d-------- c:\documents and settings\All Users\Application Data\GameHouse
    2008-10-17 21:03 . 2008-10-17 21:03 4,096 --a------ c:\windows\d3dx.dat
    2008-10-17 11:21 . 2008-10-17 11:21 <REP> d-------- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
    2008-10-17 09:11 . 2008-10-17 09:11 <REP> d-------- c:\program files\Tumblebugs 2
    2008-10-15 22:54 . 2008-09-08 11:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
    2008-10-15 22:53 . 2008-08-14 14:23 2,191,232 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
    2008-10-15 22:53 . 2008-08-14 14:23 2,147,328 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
    2008-10-15 22:53 . 2008-08-14 14:23 2,068,096 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
    2008-10-15 22:53 . 2008-08-14 14:23 2,025,984 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
    2008-10-15 22:53 . 2008-09-15 16:26 1,846,528 -----c--- c:\windows\system32\dllcache\win32k.sys
    2008-10-13 22:44 . 2008-10-13 22:44 <REP> d-------- c:\program files\Around the World in 80 Days
    2008-10-02 22:54 . 2008-10-02 22:54 <REP> d-------- c:\program files\Fichiers communs\Skype

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-11-30 17:41 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
    2008-11-30 16:19 --------- d-----w c:\program files\Google
    2008-11-29 22:20 --------- d-----w c:\program files\eMule
    2008-11-26 16:06 --------- d-----w c:\program files\Java
    2008-11-25 10:46 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
    2008-11-23 22:27 --------- d-----w c:\program files\Zylom Games
    2008-11-22 19:02 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
    2008-11-16 21:52 --------- d-----w c:\documents and settings\All Users\Application Data\SecretsOfOlympus
    2008-11-14 06:11 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
    2008-11-07 12:33 --------- d-----w c:\program files\Fichiers communs\Adobe
    2008-11-05 21:00 --------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst
    2008-10-31 14:58 --------- d-----w c:\program files\PhotoFiltre Studio
    2008-10-28 11:23 --------- d-----w c:\program files\BoontyGames
    2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
    2008-10-19 11:49 --------- d-----w c:\program files\Free FLV Converter
    2008-10-17 08:11 --------- d-----w c:\program files\Tumblebugs 2
    2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
    2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
    2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
    2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
    2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
    2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
    2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
    2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
    2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
    2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
    2008-10-14 21:34 270,336 ----a-w c:\windows\system32\TubeFinder.exe
    2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
    2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
    2008-09-10 01:15 1,307,648 ----a-w c:\windows\system32\msxml6.dll
    2008-09-04 17:16 1,106,944 ----a-w c:\windows\system32\msxml3.dll
    2008-08-29 09:30 107,888 ----a-w c:\windows\system32\CmdLineExt.dll
    2008-08-26 08:11 826,368 ----a-w c:\windows\system32\wininet.dll
    2008-08-25 10:08 374,272 ----a-w c:\windows\system32\mss32.dll
    2008-08-25 10:06 372,736 ----a-w c:\windows\system32\IJL15.DLL
    2008-08-14 13:23 2,147,328 ----a-w c:\windows\system32\ntoskrnl.exe
    2008-08-14 13:23 2,025,984 ----a-w c:\windows\system32\ntkrnlpa.exe
    2006-03-02 12:00 73,728 -csh--w c:\windows\RegisteredPackages\{DD90D410-1823-43EB-9A16-A2331BF08799}$BACKUP$\System\wmplayer.exe
    2008-06-27 13:50 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008062720080628\index.dat
    .

    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-25 68856]
    "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-03-28 413696]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-26 136600]
    "avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-18 266497]
    "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
    "SpywareCleaner"="c:\windows\system32\SpywareRemover.exe" [2008-11-26 297697]
    "RTHDCPL"="RTHDCPL.EXE" [2006-08-24 c:\windows\RTHDCPL.exe]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

    c:\documents and settings\Autumn_2\Menu D‚marrer\Programmes\D‚marrage\Around the World in 80 Days
    Around the World in 80 Days.lnk - c:\program files\Around the World in 80 Days\Around the World in 80 Days.exe [2008-03-01 331776]
    Starfors.Net.lnk - c:\program files\Around the World in 80 Days\starfors.net.html [2008-01-29 1763]
    à„…‰†¡Š†.lnk - c:\program files\Around the World in 80 Days\Uninstall.exe [2008-03-01 69868]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
    --a------ 2007-06-11 10:25 6731312 c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    --a------ 2008-10-15 01:04 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
    --a------ 2008-04-14 03:33 15360 c:\windows\system32\ctfmon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
    --a------ 2007-08-24 06:00 33648 c:\program files\Microsoft Office\Office12\GrooveMonitor.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
    -ra------ 2007-06-13 07:16 528384 c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    --a------ 2007-04-25 12:34 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
    --a------ 2005-05-04 01:43 69632 c:\windows\Alcmtr.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
    "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" /background
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
    "Lexmark 1200 Series"="c:\program files\Lexmark 1200 Series\lxczbmgr.exe"
    "ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe"
    "PCMService"="c:\apps\Powercinema\PCMService.exe"
    "NeroFilterCheck"=c:\windows\system32\NeroCheck.exe
    "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    "WinampAgent"="c:\program files\Winamp\Winampa.exe"
    "au"=c:\program files\Dealio\DealioAU.exe
    "Itch ford four knob"=c:\documents and settings\All Users\Application Data\third lies itch ford\Ante Road.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\APPS\\Powercinema\\PowerCinema.exe"=
    "c:\\APPS\\Powercinema\\PCMService.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\eMule\\eMule.exe"=
    "c:\\WINDOWS\\system32\\LEXPPS.EXE"=
    "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
    "c:\\WINDOWS\\system32\\mcoinstall.exe"=
    "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
    "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
    "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
    "c:\\Program Files\\Ares\\Ares.exe"=
    "c:\\CaffeLatte\\CafeClient\\CafeProtocol.exe"=
    "c:\\Program Files\\SecondLife\\SLVoice.exe"=
    "c:\\Program Files\\SecondLife\\SecondLife.exe"=

    S3 MBAMCatchMe;MBAMCatchMe;\??\c:\windows\system32\drivers\mbamcatchme.sys [2008-06-04 34296]
    S3 s125bus;Sony Ericsson Device 125 driver (WDM);c:\windows\system32\DRIVERS\s125bus.sys [2008-05-23 83336]
    S3 s125mdfl;Sony Ericsson Device 125 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s125mdfl.sys [2008-05-23 15112]
    S3 s125mdm;Sony Ericsson Device 125 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s125mdm.sys [2008-05-23 108680]
    S3 s125mgmt;Sony Ericsson Device 125 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s125mgmt.sys [2008-05-23 100488]
    S3 s125obex;Sony Ericsson Device 125 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s125obex.sys [2008-05-23 98696]

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    UxTuneUp
    .
    - - - - ORPHELINS SUPPRIMES - - - -

    HKLM-Run-Framework Windows - frmwrk32.exe

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-11-30 20:28:35
    Windows 5.1.2600 Service Pack 3 NTFS

    Recherche de processus cachés ...

    Recherche d'éléments en démarrage automatique cachés ...

    Recherche de fichiers cachés ...

    Scan terminé avec succès
    Fichiers cachés: 0

    **************************************************************************
    .
    --------------------- DLLs chargées dans les processus actifs ---------------------

    - - - - - - - > 'winlogon.exe'(564)
    c:\windows\system32\Ati2evxx.dll
    .
    Heure de fin: 2008-11-30 20:30:20
    ComboFix-quarantined-files.txt 2008-11-30 19:29:14
    ComboFix2.txt 2008-11-30 18:34:05
    ComboFix3.txt 2008-06-06 10:49:03

    Avant-CF: 73.833.684.992 octets libres
    Après-CF: 73,781,526,528 octets libres

    304 --- E O F --- 2008-11-14 06:11:55
    0
  3. Autumn1608 Messages postés 88 Date d'inscription   Statut Membre Dernière intervention   2
     
    Rapport Hijack :

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 20:31:56, on 30/11/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16735)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
    c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\WINDOWS\system32\oodag.exe
    C:\WINDOWS\system32\svchost.exe
    c:\APPS\Powercinema\Kernel\TV\CLSched.exe
    C:\WINDOWS\system32\wbem\wmiapsrv.exe
    C:\WINDOWS\explorer.exe
    C:\Documents and Settings\Autumn_2\Bureau\HiJackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=71067
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
    O2 - BHO: BHO pour Compagnon Web Encarta - {955BE0B8-BC85-4CAF-856E-8E0D8B610560} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\2007\ENCWCBAR.DLL
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
    O3 - Toolbar: Compagnon Web Encarta - {147D6308-0614-4112-89B1-31402F9B82C4} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Web Companion\2007\ENCWCBAR.DLL
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SpywareCleaner] C:\WINDOWS\system32\SpywareRemover.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Around the World in 80 Days
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
    O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O9 - Extra button: Barre de recherche Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
    O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Alex\Menu Démarrer\Programmes\IMVU\Run IMVU.lnk
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
    O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
    O23 - Service: CyberLink Media Library Service - Cyberlink - c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe
    O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\Logitech\SrvLnch\SrvLnch.exe
    O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
    0
  4. Utilisateur anonyme
     
    Rends toi sur ce site :

    https://www.virustotal.com/gui/

    Clique sur parcourir et cherche ce fichier :c:\windows\system32\ntdll64.exe

    Clique sur Send File.

    Un rapport va s'élaborer ligne à ligne.

    Attends la fin. Il doit comprendre la taille du fichier envoyé.

    Sauvegarde le rapport avec le bloc-note.

    Copie le dans ta réponse.
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Autumn1608 Messages postés 88 Date d'inscription   Statut Membre Dernière intervention   2
     
    Antivirus Version Dernière mise à jour Résultat

    AhnLab-V3 2008.11.27.4 2008.11.27 -
    AntiVir 7.9.0.35 2008.11.27 -
    Authentium 5.1.0.4 2008.11.27 -
    Avast 4.8.1281.0 2008.11.27 -
    AVG 8.0.0.199 2008.11.27 -
    BitDefender 7.2 2008.11.27 -
    CAT-QuickHeal 10.00 2008.11.27 -
    ClamAV 0.94.1 2008.11.27 -
    DrWeb 4.44.0.09170 2008.11.27 -
    eSafe 7.0.17.0 2008.11.27 Suspicious File
    eTrust-Vet 31.6.6233 2008.11.27 -
    Ewido 4.0 2008.11.27 -
    F-Prot 4.4.4.56 2008.11.27 -
    F-Secure 8.0.14332.0 2008.11.27 -
    Fortinet 3.117.0.0 2008.11.27 -
    GData 19 2008.11.27 -
    Ikarus T3.1.1.45.0 2008.11.27 -
    K7AntiVirus 7.10.536 2008.11.27 -
    Kaspersky 7.0.0.125 2008.11.27 -
    McAfee 5447 2008.11.27 -
    McAfee+Artemis 5447 2008.11.27 -
    Microsoft 1.4104 2008.11.27 -
    NOD32 3646 2008.11.27 -
    Norman 5.80.02 2008.11.27 -
    Panda 9.0.0.4 2008.11.27 Suspicious file
    PCTools 4.4.2.0 2008.11.27 -
    Prevx1 V2 2008.11.27 -
    Rising 21.05.32.00 2008.11.27 -
    SecureWeb-Gateway 6.7.6 2008.11.27 -
    Sophos 4.35.0 2008.11.27 -
    Sunbelt 3.1.1832.2 2008.11.27 -
    Symantec 10 2008.11.27 -
    TheHacker 6.3.1.1.165 2008.11.27 -
    TrendMicro 8.700.0.1004 2008.11.27 TROJ_DLOADER.IRQ
    VBA32 3.12.8.9 2008.11.27 -
    ViRobot 2008.11.27.1489 2008.11.27 -
    VirusBuster 4.5.11.0 2008.11.27 -

    Information additionnelle
    File size: 3104 bytes
    MD5...: 7799f5780bbf17c8eaf92204058c7b4b
    SHA1..: 024e68c46eabce36af98ef46a52e0caaae69aa54
    SHA256: f6189c67e8285c14619fc427a74d5e8cc86ef60b6ea8c1e1c02cd6c32bc34ddc
    SHA512: bde7d4b371a8e42b033bf6911e4e127d2102a8fc9b7b633899add7b39cd3190e
    b3864f33625a884c3dfb6978ff36a08de6c50939ede048aabef9e71cbd1699f3
    ssdeep: 24:etGScskkti01fyCQcmUXjaJ0Siqx8RwyC68oOX0CbXLpCoEAYccPbJpB7:6tk
    kpfESEZawySoOW9
    PEiD..: -
    TrID..: File type identification
    Win32 Executable Generic (38.3%)
    Win32 Dynamic Link Library (generic) (34.1%)
    Win16/32 Executable Delphi generic (9.3%)
    Generic Win/DOS Executable (9.0%)
    DOS Executable Generic (9.0%)
    PEInfo: PE Structure information

    ( base data )
    entrypointaddress.: 0x401219
    timedatestamp.....: 0x492dbb6f (Wed Nov 26 21:11:11 2008)
    machinetype.......: 0x14c (I386)

    ( 4 sections )
    name viradd virsiz rawdsiz ntrpy md5
    .text 0x1000 0x398 0x398 5.72 3302f7aab115619b045b4ae0dab4c00d
    .bss 0x2000 0x4 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
    .data 0x3000 0x98 0x98 0.47 7090eeb671c7375de6577d7efb3a11ad
    .idata 0x4000 0x1e4 0x1e4 3.27 61805270d4dee9b4937c0ed03b4a9304

    ( 3 imports )
    > KERNEL32.dll: GetCommandLineA, GetModuleHandleA, RtlUnwind
    > USER32.DLL: DefWindowProcA
    > CRTDLL.DLL: __GetMainArgs, exit, raise, signal, strchr

    ( 0 exports )
    CWSandbox info: http://research.sunbelt-software.com/...
    0
Précédent
  • 1
  • 2