Virus Bagle
Squatt
Messages postés
64
Statut
Membre
-
Squatt Messages postés 64 Statut Membre -
Squatt Messages postés 64 Statut Membre -
Bonjour,
j'ai le virus Rookit Bagle j'aimerai savoir comment le supprimer, je ne peu plus utilisé spybot ni ad aware ni antivir! Je l'ai détecté avec malawarebytes!
J'ai vraiment besoin d'aide SVP! Merci.
j'ai le virus Rookit Bagle j'aimerai savoir comment le supprimer, je ne peu plus utilisé spybot ni ad aware ni antivir! Je l'ai détecté avec malawarebytes!
J'ai vraiment besoin d'aide SVP! Merci.
A voir également:
- Virus Bagle
- Virus mcafee - Accueil - Piratage
- Virus informatique - Guide
- Panda anti virus gratuit - Télécharger - Antivirus & Antimalwares
- Undisclosed-recipients virus - Guide
- Ordinateur bloqué virus - Accueil - Arnaque
47 réponses
ComboFix 08-12-05.02 - Squatt 2008-12-05 23:02:39.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.166 [GMT 1:00]
Lancé depuis: c:\users\Squatt\Desktop\ComboFix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Packard Bell\SetUpMyPC\SmpSys.exe
c:\windows\system32\hpowiax5.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SK9OU0S
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-05 au 2008-12-05 ))))))))))))))))))))))))))))))))))))
.
2008-12-05 22:31 . 2008-12-05 22:39 <REP> d-------- c:\program files\FindyKill
2008-12-04 11:55 . 2008-12-04 12:01 <REP> d-------- c:\users\Squatt\AppData\Roaming\ArcSoft
2008-12-04 11:55 . 1995-08-01 04:44 212,480 --a------ c:\windows\PCDLIB32.DLL
2008-12-04 11:55 . 2006-11-10 15:05 18,688 --a------ c:\windows\System32\drivers\afc.sys
2008-12-03 07:55 . 2008-10-16 22:13 1,809,944 --a------ c:\windows\System32\wuaueng.dll
2008-12-03 07:55 . 2008-10-16 21:56 1,524,736 --a------ c:\windows\System32\wucltux.dll
2008-12-03 07:55 . 2008-10-16 22:09 51,224 --a------ c:\windows\System32\wuauclt.exe
2008-12-03 07:55 . 2008-10-16 22:09 43,544 --a------ c:\windows\System32\wups2.dll
2008-12-03 07:54 . 2008-10-16 22:12 561,688 --a------ c:\windows\System32\wuapi.dll
2008-12-03 07:54 . 2008-10-16 14:08 162,064 --a------ c:\windows\System32\wuwebv.dll
2008-12-03 07:54 . 2008-10-16 21:55 83,456 --a------ c:\windows\System32\wudriver.dll
2008-12-03 07:54 . 2008-10-16 22:08 34,328 --a------ c:\windows\System32\wups.dll
2008-12-03 07:54 . 2008-10-16 13:56 31,232 --a------ c:\windows\System32\wuapp.exe
2008-11-13 20:33 . 2008-11-13 20:33 <REP> dr------- c:\windows\System32\config\systemprofile\Saved Games
2008-11-13 20:33 . 2008-11-13 20:33 <REP> dr------- c:\windows\System32\config\systemprofile\Links
2008-11-13 20:33 . 2008-11-13 20:33 <REP> d-------- c:\users\Squatt\AppData\Roaming\InstallShield
2008-11-13 20:32 . 2008-11-13 20:32 <REP> dr------- c:\windows\System32\config\systemprofile\Searches
2008-11-12 20:24 . 2008-11-12 20:24 <REP> d-------- C:\_OTMoveIt
2008-11-12 16:46 . 2008-11-12 16:46 <REP> d-------- C:\rsit
2008-11-12 16:07 . 2008-11-12 16:07 <REP> d-------- c:\users\Squatt\AppData\Roaming\Malwarebytes
2008-11-12 16:06 . 2008-11-12 16:06 <REP> d-------- c:\users\All Users\Malwarebytes
2008-11-12 16:06 . 2008-12-05 21:57 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-12 16:06 . 2008-11-12 16:06 <REP> d-------- c:\progra~2\Malwarebytes
2008-11-12 16:06 . 2008-12-03 19:52 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2008-11-12 16:06 . 2008-12-03 19:52 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2008-11-12 15:28 . 2008-11-12 16:00 <REP> d-------- C:\ToolBar SD
2008-11-12 15:26 . 2008-11-12 15:26 <REP> d-------- c:\users\All Users\NortonInstaller
2008-11-12 15:26 . 2008-11-12 15:26 <REP> d-------- c:\progra~2\NortonInstaller
2008-11-12 10:01 . 2008-09-10 04:40 1,334,272 --a------ c:\windows\System32\msxml6.dll
2008-11-12 10:01 . 2008-09-05 06:14 1,191,936 --a------ c:\windows\System32\msxml3.dll
2008-11-12 10:01 . 2008-08-27 02:05 212,480 --a------ c:\windows\System32\drivers\mrxsmb10.sys
2008-11-12 03:18 . 2008-11-12 14:38 <REP> d-------- c:\program files\Navilog1
2008-11-11 19:31 . 2008-11-11 19:31 <REP> d-------- c:\users\All Users\Avira
2008-11-11 19:31 . 2008-11-11 19:31 <REP> d-------- c:\program files\Avira
2008-11-11 19:31 . 2008-11-11 19:31 <REP> d-------- c:\progra~2\Avira
2008-11-11 19:20 . 2008-11-11 19:20 <REP> d-------- C:\Downloads
2008-11-11 13:23 . 2008-12-05 22:32 <REP> d-------- c:\users\Squatt\AppData\Roaming\Free Download Manager
2008-11-11 13:23 . 2008-11-11 13:23 <REP> d-------- c:\program files\Free Download Manager
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-05 22:08 --------- d-----w c:\progra~2\Sonic
2008-12-04 11:03 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-20 20:57 --------- d-----w c:\progra~2\Roxio
2008-11-12 03:38 --------- d-----w c:\program files\Java
2008-11-12 03:29 --------- d-----w c:\program files\Common Files\Adobe
2008-11-06 15:36 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-03 01:07 --------- d-----w c:\progra~2\NVIDIA
2008-11-03 01:01 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-02 21:36 --------- d-----w c:\users\Squatt\AppData\Roaming\HP
2008-10-30 01:26 --------- d-----w c:\progra~2\HP
2008-10-29 22:45 --------- d-----w c:\progra~2\Hewlett-Packard
2008-10-29 22:44 --------- d-----w c:\progra~2\HPSSUPPLY
2008-10-29 22:27 --------- d-----w c:\program files\HP
2008-10-29 22:27 --------- d-----w c:\progra~2\HP Product Assistant
2008-10-29 22:26 --------- d-----w c:\program files\Hewlett-Packard
2008-10-29 22:26 --------- d-----w c:\program files\Common Files\Hewlett-Packard
2008-10-29 22:25 --------- d-----w c:\program files\Common Files\HP
2008-10-25 02:21 --------- d-----w c:\program files\AviSynth 2.5
2008-10-16 12:55 --------- d-----w c:\program files\inKline Global
2008-10-15 18:04 --------- d-----w c:\progra~2\Messenger Plus!
2008-10-15 14:45 --------- d-----w c:\program files\Messenger Plus! Live
2008-10-15 14:41 --------- d-----w c:\program files\Windows Live
2008-10-15 14:37 --------- d-----w c:\progra~2\WLInstaller
2008-10-08 19:09 --------- d-----w c:\progra~2\Spybot - Search & Destroy
2008-10-07 17:42 --------- d-----w c:\program files\Image-Line
2008-10-07 17:42 --------- d-----w c:\program files\ASIO4ALL v2
2008-10-07 17:41 --------- d-----w c:\program files\VstPlugins
2008-10-07 17:40 --------- d-----w c:\program files\Outsim
2008-10-07 14:06 --------- d-----w c:\users\Squatt\AppData\Roaming\MAGIX
2008-10-07 14:04 --------- d-----w c:\program files\MAGIX
2008-10-07 14:04 --------- d-----w c:\progra~2\MAGIX
2008-10-02 03:49 827,392 ----a-w c:\windows\System32\wininet.dll
2008-09-30 15:43 1,286,152 ----a-w c:\windows\System32\msxml4.dll
2008-09-18 05:09 3,601,464 ----a-w c:\windows\System32\ntkrnlpa.exe
2008-09-18 05:09 3,549,240 ----a-w c:\windows\System32\ntoskrnl.exe
2008-09-18 02:16 2,032,640 ----a-w c:\windows\System32\win32k.sys
2008-06-02 01:09 174 --sha-w c:\program files\desktop.ini
2008-03-19 17:07 47,360 ----a-w c:\users\Squatt\AppData\Roaming\pcouffin.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Free Download Manager"="c:\program files\Free Download Manager\fdm.exe" [2008-05-20 2474031]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 205480]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-19 c:\windows\System32\oobefldr.dll]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-01-11 232184]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-25 29744]
"toolbar_eula_launcher"="c:\program files\Packard Bell\GOOGLE_EULA\EULALauncher.exe" [2007-02-20 28672]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-07-08 185896]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-20 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-20 92704]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-12-05 266497]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2008-12-03 1265296]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-01 c:\windows\RtHDVCpl.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 443968]
c:\progra~2\MICROS~1\Windows\STARTM~1\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"FilterAdministratorToken"= 1 (0x1)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~3\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.i420"= i420vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-329090536-52843620-3910971160-1002]
"EnableNotificationsRef"=dword:00000003
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{A9B39C82-7011-40A1-A297-9E048CEB886C}"= UDP:c:\program files\Skype\Phone\Skype.exe:Skype
"{E424D81B-3E83-40BE-B8E2-D095BCE5F8B4}"= TCP:c:\program files\Skype\Phone\Skype.exe:Skype
"{C59BBE90-5AC3-4B4E-A135-92FB12F7017A}"= Profile=Public|c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{BC9193DF-196E-4783-BAA0-2720603F8A03}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{98DC424B-D7FD-45CF-BA6D-E43951766533}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule
"TCP Query User{446F546E-FC50-4FB6-AFDA-118F9496F1FC}c:\\program files\\packard bell\\updator\\pbupdator.exe"= UDP:c:\program files\packard bell\updator\pbupdator.exe:Packard Bell Updator
"UDP Query User{C2BC3F04-1B4A-4BE1-ADD2-1AD6BF263F2A}c:\\program files\\packard bell\\updator\\pbupdator.exe"= TCP:c:\program files\packard bell\updator\pbupdator.exe:Packard Bell Updator
"{825B8C1C-67E2-43BF-A866-4AB4E99B3332}"= UDP:c:\program files\uTorrent\utorrent.exe:µTorrent
"{2D63BFBE-E95C-4E6C-B099-3DE00DA5C62F}"= TCP:c:\program files\uTorrent\utorrent.exe:µTorrent
"{6AF29CA8-2746-492E-9ED1-CAA6AE09B840}"= Profile=Public|c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{79B1AFC7-8F3A-45DB-87B5-CFF7A6D15FDC}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{23F7EF9B-BF7F-47BD-8876-0E99A50F9379}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{ECA1FF3D-A6D4-4DBB-AF86-3A3E6E93D277}c:\\users\\squatt\\appdata\\local\\temp\\temp2_emule0.48a.zip\\emule0.48a\\emule.exe"= UDP:c:\users\squatt\appdata\local\temp\temp2_emule0.48a.zip\emule0.48a\emule.exe:emule.exe
"UDP Query User{C9DDEEBD-578C-4C1E-97D4-96A60D1EE7B9}c:\\users\\squatt\\appdata\\local\\temp\\temp2_emule0.48a.zip\\emule0.48a\\emule.exe"= TCP:c:\users\squatt\appdata\local\temp\temp2_emule0.48a.zip\emule0.48a\emule.exe:emule.exe
"{3301D5B7-9B28-4AF0-95C2-92BD2B5575BA}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{CC4F599A-D05F-452E-8B01-A9A63FB3EB1D}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{CB8F61BC-BA37-4106-A9E6-EA593FC54B74}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{6212630E-DFE3-4F55-AAE3-4FC55EEE7688}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{55648135-22DD-4F17-BD4C-11812B606D6E}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{FE8CEE7B-7E85-4D31-8767-F0AC31820366}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
"{DE805AAF-09C7-4AC8-8B7B-6C3FC24F4F2B}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
"{AA3FB602-BFEC-486F-AA22-7E70301EAD07}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
"{FFB05617-DBA0-4E31-994B-00065CDB96E7}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
"{6DF3FD3D-6229-4EC5-BF48-2787E5A586C8}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpofxm08.exe:hpofxm08.exe
"{0EBB349E-E6BC-4FA9-868D-C909AA287A60}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpofxm08.exe:hpofxm08.exe
"{4C4C3460-BCA2-4E59-B4E7-464D840E601B}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hposfx08.exe:hposfx08.exe
"{FDB53D6F-79A7-451D-AFDD-E1D2DB96831F}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hposfx08.exe:hposfx08.exe
"{538752E6-3C26-42C6-BCCC-C439CD0651A8}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
"{BABCD562-C849-431C-8667-C50229103408}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
"{E0291052-C4AB-483E-803B-D22908B3123F}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpzwiz01.exe:hpzwiz01.exe
"{CBE549E0-4E23-4A31-B3FE-7E1AC1AD7B87}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpzwiz01.exe:hpzwiz01.exe
"{911BE016-6F69-4D37-9D4B-52F00673269E}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpoews01.exe:hpoews01.exe
"{6EFEB3A2-F9CB-43F8-BB90-0A66B9E34817}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpoews01.exe:hpoews01.exe
"{D8828968-85FA-4C49-BC95-06A5F404937E}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpiscnapp.exe:hpiscnapp.exe
"{DDFA4BD5-083B-4F3E-8BD4-047EAEBCEA3C}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpiscnapp.exe:hpiscnapp.exe
"{9CC7D7ED-976A-45BD-8664-40AF47F0284B}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
"{81A2D6BD-2C48-4827-89D4-BE7AFAF56E24}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
"{6B08055A-9138-4F8C-9FB7-CF2082FFA00D}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{CE2896C6-5760-4EA0-AAAB-DA1163B75E4F}"= UDP:c:\users\Squatt\AppData\Local\Temp\WZSE0.TMP\SymNRT.exe:Norton Removal Tool
"{9017A110-EC4D-4D88-BCEC-50C4A09B8189}"= TCP:c:\users\Squatt\AppData\Local\Temp\WZSE0.TMP\SymNRT.exe:Norton Removal Tool
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2008-02-09 809296]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\MAGIX\Common\Database\bin\fbserver.exe [2008-10-07 1527900]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-08-29 31592]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;"c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-06-16 29744]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-SmpcSys - c:\program files\Packard Bell\SetUpMyPC\SmpSys.exe
HKLM-Run-SpywareTerminator - c:\program files\Spyware Terminator\SpywareTerminatorShield.exe
HKLM-Run-NWEReboot - (no file)
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
mWindow Title =
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Tout télécharger avec Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
IE: Télécharger avec Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
IE: Télécharger la sélection avec Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
IE: Télécharger la vidéo avec Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
FireFox -: Profile - c:\users\Squatt\AppData\Roaming\Mozilla\Firefox\Profiles\hdzpwve9.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://search.shareazaweb.com/fr/
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-05 23:08:48
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\rundll32.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
c:\windows\System32\conime.exe
c:\windows\System32\rundll32.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\ehome\ehmsas.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
c:\windows\System32\dllhost.exe
.
**************************************************************************
.
Heure de fin: 2008-12-05 23:12:53 - La machine a redémarré [Squatt]
ComboFix-quarantined-files.txt 2008-12-05 22:12:22
Avant-CF: 148,821,643,264 octets libres
Après-CF: 148,882,538,496 octets libres
256 --- E O F --- 2008-12-02 12:34:40
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.166 [GMT 1:00]
Lancé depuis: c:\users\Squatt\Desktop\ComboFix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Packard Bell\SetUpMyPC\SmpSys.exe
c:\windows\system32\hpowiax5.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SK9OU0S
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-05 au 2008-12-05 ))))))))))))))))))))))))))))))))))))
.
2008-12-05 22:31 . 2008-12-05 22:39 <REP> d-------- c:\program files\FindyKill
2008-12-04 11:55 . 2008-12-04 12:01 <REP> d-------- c:\users\Squatt\AppData\Roaming\ArcSoft
2008-12-04 11:55 . 1995-08-01 04:44 212,480 --a------ c:\windows\PCDLIB32.DLL
2008-12-04 11:55 . 2006-11-10 15:05 18,688 --a------ c:\windows\System32\drivers\afc.sys
2008-12-03 07:55 . 2008-10-16 22:13 1,809,944 --a------ c:\windows\System32\wuaueng.dll
2008-12-03 07:55 . 2008-10-16 21:56 1,524,736 --a------ c:\windows\System32\wucltux.dll
2008-12-03 07:55 . 2008-10-16 22:09 51,224 --a------ c:\windows\System32\wuauclt.exe
2008-12-03 07:55 . 2008-10-16 22:09 43,544 --a------ c:\windows\System32\wups2.dll
2008-12-03 07:54 . 2008-10-16 22:12 561,688 --a------ c:\windows\System32\wuapi.dll
2008-12-03 07:54 . 2008-10-16 14:08 162,064 --a------ c:\windows\System32\wuwebv.dll
2008-12-03 07:54 . 2008-10-16 21:55 83,456 --a------ c:\windows\System32\wudriver.dll
2008-12-03 07:54 . 2008-10-16 22:08 34,328 --a------ c:\windows\System32\wups.dll
2008-12-03 07:54 . 2008-10-16 13:56 31,232 --a------ c:\windows\System32\wuapp.exe
2008-11-13 20:33 . 2008-11-13 20:33 <REP> dr------- c:\windows\System32\config\systemprofile\Saved Games
2008-11-13 20:33 . 2008-11-13 20:33 <REP> dr------- c:\windows\System32\config\systemprofile\Links
2008-11-13 20:33 . 2008-11-13 20:33 <REP> d-------- c:\users\Squatt\AppData\Roaming\InstallShield
2008-11-13 20:32 . 2008-11-13 20:32 <REP> dr------- c:\windows\System32\config\systemprofile\Searches
2008-11-12 20:24 . 2008-11-12 20:24 <REP> d-------- C:\_OTMoveIt
2008-11-12 16:46 . 2008-11-12 16:46 <REP> d-------- C:\rsit
2008-11-12 16:07 . 2008-11-12 16:07 <REP> d-------- c:\users\Squatt\AppData\Roaming\Malwarebytes
2008-11-12 16:06 . 2008-11-12 16:06 <REP> d-------- c:\users\All Users\Malwarebytes
2008-11-12 16:06 . 2008-12-05 21:57 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-12 16:06 . 2008-11-12 16:06 <REP> d-------- c:\progra~2\Malwarebytes
2008-11-12 16:06 . 2008-12-03 19:52 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2008-11-12 16:06 . 2008-12-03 19:52 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2008-11-12 15:28 . 2008-11-12 16:00 <REP> d-------- C:\ToolBar SD
2008-11-12 15:26 . 2008-11-12 15:26 <REP> d-------- c:\users\All Users\NortonInstaller
2008-11-12 15:26 . 2008-11-12 15:26 <REP> d-------- c:\progra~2\NortonInstaller
2008-11-12 10:01 . 2008-09-10 04:40 1,334,272 --a------ c:\windows\System32\msxml6.dll
2008-11-12 10:01 . 2008-09-05 06:14 1,191,936 --a------ c:\windows\System32\msxml3.dll
2008-11-12 10:01 . 2008-08-27 02:05 212,480 --a------ c:\windows\System32\drivers\mrxsmb10.sys
2008-11-12 03:18 . 2008-11-12 14:38 <REP> d-------- c:\program files\Navilog1
2008-11-11 19:31 . 2008-11-11 19:31 <REP> d-------- c:\users\All Users\Avira
2008-11-11 19:31 . 2008-11-11 19:31 <REP> d-------- c:\program files\Avira
2008-11-11 19:31 . 2008-11-11 19:31 <REP> d-------- c:\progra~2\Avira
2008-11-11 19:20 . 2008-11-11 19:20 <REP> d-------- C:\Downloads
2008-11-11 13:23 . 2008-12-05 22:32 <REP> d-------- c:\users\Squatt\AppData\Roaming\Free Download Manager
2008-11-11 13:23 . 2008-11-11 13:23 <REP> d-------- c:\program files\Free Download Manager
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-05 22:08 --------- d-----w c:\progra~2\Sonic
2008-12-04 11:03 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-20 20:57 --------- d-----w c:\progra~2\Roxio
2008-11-12 03:38 --------- d-----w c:\program files\Java
2008-11-12 03:29 --------- d-----w c:\program files\Common Files\Adobe
2008-11-06 15:36 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-03 01:07 --------- d-----w c:\progra~2\NVIDIA
2008-11-03 01:01 --------- d-----w c:\program files\Common Files\InstallShield
2008-11-02 21:36 --------- d-----w c:\users\Squatt\AppData\Roaming\HP
2008-10-30 01:26 --------- d-----w c:\progra~2\HP
2008-10-29 22:45 --------- d-----w c:\progra~2\Hewlett-Packard
2008-10-29 22:44 --------- d-----w c:\progra~2\HPSSUPPLY
2008-10-29 22:27 --------- d-----w c:\program files\HP
2008-10-29 22:27 --------- d-----w c:\progra~2\HP Product Assistant
2008-10-29 22:26 --------- d-----w c:\program files\Hewlett-Packard
2008-10-29 22:26 --------- d-----w c:\program files\Common Files\Hewlett-Packard
2008-10-29 22:25 --------- d-----w c:\program files\Common Files\HP
2008-10-25 02:21 --------- d-----w c:\program files\AviSynth 2.5
2008-10-16 12:55 --------- d-----w c:\program files\inKline Global
2008-10-15 18:04 --------- d-----w c:\progra~2\Messenger Plus!
2008-10-15 14:45 --------- d-----w c:\program files\Messenger Plus! Live
2008-10-15 14:41 --------- d-----w c:\program files\Windows Live
2008-10-15 14:37 --------- d-----w c:\progra~2\WLInstaller
2008-10-08 19:09 --------- d-----w c:\progra~2\Spybot - Search & Destroy
2008-10-07 17:42 --------- d-----w c:\program files\Image-Line
2008-10-07 17:42 --------- d-----w c:\program files\ASIO4ALL v2
2008-10-07 17:41 --------- d-----w c:\program files\VstPlugins
2008-10-07 17:40 --------- d-----w c:\program files\Outsim
2008-10-07 14:06 --------- d-----w c:\users\Squatt\AppData\Roaming\MAGIX
2008-10-07 14:04 --------- d-----w c:\program files\MAGIX
2008-10-07 14:04 --------- d-----w c:\progra~2\MAGIX
2008-10-02 03:49 827,392 ----a-w c:\windows\System32\wininet.dll
2008-09-30 15:43 1,286,152 ----a-w c:\windows\System32\msxml4.dll
2008-09-18 05:09 3,601,464 ----a-w c:\windows\System32\ntkrnlpa.exe
2008-09-18 05:09 3,549,240 ----a-w c:\windows\System32\ntoskrnl.exe
2008-09-18 02:16 2,032,640 ----a-w c:\windows\System32\win32k.sys
2008-06-02 01:09 174 --sha-w c:\program files\desktop.ini
2008-03-19 17:07 47,360 ----a-w c:\users\Squatt\AppData\Roaming\pcouffin.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"Free Download Manager"="c:\program files\Free Download Manager\fdm.exe" [2008-05-20 2474031]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 205480]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-19 c:\windows\System32\oobefldr.dll]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-01-11 232184]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-09-25 29744]
"toolbar_eula_launcher"="c:\program files\Packard Bell\GOOGLE_EULA\EULALauncher.exe" [2007-02-20 28672]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-07-08 185896]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-06-20 13535776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-06-20 92704]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-12-05 266497]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2008-12-03 1265296]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-01 c:\windows\RtHDVCpl.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 443968]
c:\progra~2\MICROS~1\Windows\STARTM~1\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"FilterAdministratorToken"= 1 (0x1)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~3\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.i420"= i420vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-329090536-52843620-3910971160-1002]
"EnableNotificationsRef"=dword:00000003
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{A9B39C82-7011-40A1-A297-9E048CEB886C}"= UDP:c:\program files\Skype\Phone\Skype.exe:Skype
"{E424D81B-3E83-40BE-B8E2-D095BCE5F8B4}"= TCP:c:\program files\Skype\Phone\Skype.exe:Skype
"{C59BBE90-5AC3-4B4E-A135-92FB12F7017A}"= Profile=Public|c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{BC9193DF-196E-4783-BAA0-2720603F8A03}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule
"UDP Query User{98DC424B-D7FD-45CF-BA6D-E43951766533}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule
"TCP Query User{446F546E-FC50-4FB6-AFDA-118F9496F1FC}c:\\program files\\packard bell\\updator\\pbupdator.exe"= UDP:c:\program files\packard bell\updator\pbupdator.exe:Packard Bell Updator
"UDP Query User{C2BC3F04-1B4A-4BE1-ADD2-1AD6BF263F2A}c:\\program files\\packard bell\\updator\\pbupdator.exe"= TCP:c:\program files\packard bell\updator\pbupdator.exe:Packard Bell Updator
"{825B8C1C-67E2-43BF-A866-4AB4E99B3332}"= UDP:c:\program files\uTorrent\utorrent.exe:µTorrent
"{2D63BFBE-E95C-4E6C-B099-3DE00DA5C62F}"= TCP:c:\program files\uTorrent\utorrent.exe:µTorrent
"{6AF29CA8-2746-492E-9ED1-CAA6AE09B840}"= Profile=Public|c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{79B1AFC7-8F3A-45DB-87B5-CFF7A6D15FDC}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{23F7EF9B-BF7F-47BD-8876-0E99A50F9379}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{ECA1FF3D-A6D4-4DBB-AF86-3A3E6E93D277}c:\\users\\squatt\\appdata\\local\\temp\\temp2_emule0.48a.zip\\emule0.48a\\emule.exe"= UDP:c:\users\squatt\appdata\local\temp\temp2_emule0.48a.zip\emule0.48a\emule.exe:emule.exe
"UDP Query User{C9DDEEBD-578C-4C1E-97D4-96A60D1EE7B9}c:\\users\\squatt\\appdata\\local\\temp\\temp2_emule0.48a.zip\\emule0.48a\\emule.exe"= TCP:c:\users\squatt\appdata\local\temp\temp2_emule0.48a.zip\emule0.48a\emule.exe:emule.exe
"{3301D5B7-9B28-4AF0-95C2-92BD2B5575BA}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{CC4F599A-D05F-452E-8B01-A9A63FB3EB1D}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{CB8F61BC-BA37-4106-A9E6-EA593FC54B74}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{6212630E-DFE3-4F55-AAE3-4FC55EEE7688}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{55648135-22DD-4F17-BD4C-11812B606D6E}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{FE8CEE7B-7E85-4D31-8767-F0AC31820366}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
"{DE805AAF-09C7-4AC8-8B7B-6C3FC24F4F2B}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqtra08.exe:hpqtra08.exe
"{AA3FB602-BFEC-486F-AA22-7E70301EAD07}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
"{FFB05617-DBA0-4E31-994B-00065CDB96E7}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqste08.exe:hpqste08.exe
"{6DF3FD3D-6229-4EC5-BF48-2787E5A586C8}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpofxm08.exe:hpofxm08.exe
"{0EBB349E-E6BC-4FA9-868D-C909AA287A60}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpofxm08.exe:hpofxm08.exe
"{4C4C3460-BCA2-4E59-B4E7-464D840E601B}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hposfx08.exe:hposfx08.exe
"{FDB53D6F-79A7-451D-AFDD-E1D2DB96831F}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hposfx08.exe:hposfx08.exe
"{538752E6-3C26-42C6-BCCC-C439CD0651A8}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
"{BABCD562-C849-431C-8667-C50229103408}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hposid01.exe:hposid01.exe
"{E0291052-C4AB-483E-803B-D22908B3123F}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpzwiz01.exe:hpzwiz01.exe
"{CBE549E0-4E23-4A31-B3FE-7E1AC1AD7B87}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpzwiz01.exe:hpzwiz01.exe
"{911BE016-6F69-4D37-9D4B-52F00673269E}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpoews01.exe:hpoews01.exe
"{6EFEB3A2-F9CB-43F8-BB90-0A66B9E34817}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpoews01.exe:hpoews01.exe
"{D8828968-85FA-4C49-BC95-06A5F404937E}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpiscnapp.exe:hpiscnapp.exe
"{DDFA4BD5-083B-4F3E-8BD4-047EAEBCEA3C}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpiscnapp.exe:hpiscnapp.exe
"{9CC7D7ED-976A-45BD-8664-40AF47F0284B}"= Disabled:UDP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
"{81A2D6BD-2C48-4827-89D4-BE7AFAF56E24}"= Disabled:TCP:c:\program files\HP\Digital Imaging\bin\hpqkygrp.exe:hpqkygrp.exe
"{6B08055A-9138-4F8C-9FB7-CF2082FFA00D}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{CE2896C6-5760-4EA0-AAAB-DA1163B75E4F}"= UDP:c:\users\Squatt\AppData\Local\Temp\WZSE0.TMP\SymNRT.exe:Norton Removal Tool
"{9017A110-EC4D-4D88-BCEC-50C4A09B8189}"= TCP:c:\users\Squatt\AppData\Local\Temp\WZSE0.TMP\SymNRT.exe:Norton Removal Tool
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2008-02-09 809296]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\program files\MAGIX\Common\Database\bin\fbserver.exe [2008-10-07 1527900]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-08-29 31592]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;"c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-06-16 29744]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-SmpcSys - c:\program files\Packard Bell\SetUpMyPC\SmpSys.exe
HKLM-Run-SpywareTerminator - c:\program files\Spyware Terminator\SpywareTerminatorShield.exe
HKLM-Run-NWEReboot - (no file)
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
mWindow Title =
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Tout télécharger avec Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
IE: Télécharger avec Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
IE: Télécharger la sélection avec Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
IE: Télécharger la vidéo avec Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
FireFox -: Profile - c:\users\Squatt\AppData\Roaming\Mozilla\Firefox\Profiles\hdzpwve9.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://search.shareazaweb.com/fr/
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-05 23:08:48
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\nvvsvc.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\rundll32.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\CDBurnerXP\NMSAccessU.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
c:\windows\System32\conime.exe
c:\windows\System32\rundll32.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\ehome\ehmsas.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
c:\windows\System32\dllhost.exe
.
**************************************************************************
.
Heure de fin: 2008-12-05 23:12:53 - La machine a redémarré [Squatt]
ComboFix-quarantined-files.txt 2008-12-05 22:12:22
Avant-CF: 148,821,643,264 octets libres
Après-CF: 148,882,538,496 octets libres
256 --- E O F --- 2008-12-02 12:34:40
Tu vas peu être me prendre pour un naze mais j'comprend pas la!!!!
"---> Réinstalle les applications qui ont été infectées."
"---> Réinstalle les applications qui ont été infectées."
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Ok ça marche!
AD Aware m'indique error 1810 service is online! Je suppose que ça veut dire la même chose. J'vais faire tout ça.
AD Aware m'indique error 1810 service is online! Je suppose que ça veut dire la même chose. J'vais faire tout ça.
Voilà j'ai désinstaller antivir, ad aware et spybot! je dois faire un scan ou je réinstalle tout de nouveau?
- Fais un scan en ligne ici https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr (Avec Internet Explorer).
- En bas à droite, clique sur Démarrer Online-scanner.
- Dans la nouvelle fenêtre qui s'affiche, clique sur J'accepte.
- Accepte les Contrôles ActiveX.
- Choisis Poste de travail pour le scan.
- Celui-ci terminé, sauvegarde (Choisis fichier texte) et poste le rapport.
- Pour t'aider à utiliser le scan en ligne :
https://www.malekal.com/scan-antivirus-ligne-nod32/#mozTocId291566
NOTE : Si tu reçois le message La licence de Kaspersky On-line Scanner est périmée, va dans Ajout/Suppression de programmes puis désinstalle On-Line Scanner, reconnecte-toi sur le site de Kaspersky pour retenter le scan en ligne.
- Lis ceci en cas de problème d'installation du Contrôle ActiveX :
http://cybersecurite.xooit.com/t123-Les-controles-ActiveX.htm
- En bas à droite, clique sur Démarrer Online-scanner.
- Dans la nouvelle fenêtre qui s'affiche, clique sur J'accepte.
- Accepte les Contrôles ActiveX.
- Choisis Poste de travail pour le scan.
- Celui-ci terminé, sauvegarde (Choisis fichier texte) et poste le rapport.
- Pour t'aider à utiliser le scan en ligne :
https://www.malekal.com/scan-antivirus-ligne-nod32/#mozTocId291566
NOTE : Si tu reçois le message La licence de Kaspersky On-line Scanner est périmée, va dans Ajout/Suppression de programmes puis désinstalle On-Line Scanner, reconnecte-toi sur le site de Kaspersky pour retenter le scan en ligne.
- Lis ceci en cas de problème d'installation du Contrôle ActiveX :
http://cybersecurite.xooit.com/t123-Les-controles-ActiveX.htm
Le scan en ligne ne fonctionne pas, je sais pas si ça viens de chez moi ou c'est le site qui a un problème! Quand j'active "active X" il se passe rien du tout ça reviens à la page précédente!
Je n'ai pas one-line dans mes programmes!
Je n'ai pas one-line dans mes programmes!
Compatibilité avec Windows Vista en cours de développement.
Bientôt disponible...
C'est peu être du à ça non????
Bientôt disponible...
C'est peu être du à ça non????