Warning dangerous spyware - Page 2

Résolu
Précédent
  • 1
  • 2
  1. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    Ferme tous tes navigateurs (donc copie ou imprime les instructions avant)

    Crée un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :

    Driver ::
    spttseng32

    File::
    c:\windows\system32\spttseng32.dll
    c:\windows\system32\spttseng32.dll,ozob

    Registry::
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\spttseng32]

    Enregistre ce fichier sous le nom CFscript

    Fait un glisser/déposer de ce fichier CFscrïpt sur le fichier ComboFix.exe

    Clique sur le fichier CFScript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFScript vienne recouvrir l'icône de Combofix. Relache la souris. Combofix va démarrer.

    Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

    Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

    Ne touche à rien tant que le scan n'est pas terminé.

    Une fois le scan achevé, un rapport va s'afficher: poste son contenu.

    Remets aussi un rapport Hijackthis

    Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
    0
    1. mumu5938 Messages postés 31 Statut Membre
       
      ok je fais çà merci
      0
  2. mumu5938 Messages postés 31 Statut Membre
     
    ComboFix 08-12-06.06 - ISABELLE 2008-12-08 14:56:19.2 - NTFSx86
    Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.196 [GMT 1:00]
    LancÚ depuis: c:\documents and settings\ISABELLE\Bureau\ComboFix.exe
    Commutateurs utilisÚs :: c:\documents and settings\ISABELLE\Bureau\CFscript.txt
    * Un nouveau point de restauration a ÚtÚ crÚÚ
    * Resident AV is active

    FILE ::
    c:\windows\system32\spttseng32.dll
    c:\windows\system32\spttseng32.dll,ozob
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\system32\actaegdg.ini
    c:\windows\system32\hnlndukr.ini
    c:\windows\system32\spttseng32.dll

    .
    ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_SPTTSENG32
    -------\Service_spttseng32

    ((((((((((((((((((((((((((((( Fichiers créés du 2008-11-08 au 2008-12-08 ))))))))))))))))))))))))))))))))))))
    .

    2008-12-08 13:48 . 2008-12-08 13:48 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Malwarebytes
    2008-12-08 13:47 . 2008-12-08 13:48 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
    2008-12-08 13:47 . 2008-12-08 13:47 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
    2008-12-08 13:47 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
    2008-12-08 13:47 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
    2008-12-08 11:58 . 2008-12-08 12:25 <REP> d-------- C:\ToolBar SD
    2008-12-08 11:42 . 2008-12-08 11:42 <REP> d-------- C:\rsit
    2008-12-08 11:42 . 2008-12-08 11:42 <REP> d-------- c:\program files\trend micro
    2008-12-08 01:29 . 2008-12-08 01:29 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
    2008-12-07 13:35 . 2008-12-07 13:35 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PC Tools
    2008-12-07 13:34 . 2008-12-08 13:12 <REP> d-------- c:\program files\PC Tools AntiVirus
    2008-12-07 13:34 . 2007-12-06 16:51 28,568 --a------ c:\windows\system32\drivers\AVHook.sys
    2008-12-07 13:34 . 2007-12-06 16:51 21,912 --a------ c:\windows\system32\drivers\AVRec.sys
    2008-12-07 13:34 . 2008-02-12 11:44 21,904 --a------ c:\windows\system32\drivers\AVFilter.sys
    2008-12-06 20:59 . 2008-12-06 21:02 <REP> d-------- c:\program files\CCleaner
    2008-12-06 00:56 . 2008-12-06 00:56 <REP> d-------- c:\documents and settings\All Users\Application Data\TheRace_dev
    2008-12-06 00:42 . 2008-12-06 00:42 <REP> d-------- c:\program files\Fichiers communs\SWF Studio
    2008-12-05 23:28 . 2008-12-05 23:28 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\iWin
    2008-12-05 23:28 . 2008-12-05 23:28 <REP> d-------- c:\documents and settings\All Users\Application Data\iWin
    2008-12-05 22:42 . 2008-12-05 22:42 <REP> d-------- c:\documents and settings\All Users\Application Data\Gogii
    2008-12-05 22:28 . 2008-12-05 22:28 <REP> d-------- c:\documents and settings\All Users\Application Data\Intenium
    2008-12-04 23:49 . 2008-12-04 23:49 <REP> d-------- c:\documents and settings\LocalService\Application Data\PCToolsSpamMonitorPlus
    2008-12-04 23:49 . 2008-12-04 23:49 <REP> d-------- c:\documents and settings\LocalService\Application Data\PCToolsFirewallPlus
    2008-12-04 19:55 . 2008-12-04 19:55 <REP> d--h----- c:\windows\PIF
    2008-12-03 04:12 . 2008-12-06 00:39 <REP> d-------- c:\documents and settings\All Users\Application Data\Playrix Entertainment
    2008-12-02 12:44 . 2008-12-02 12:44 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PCToolsFirewallPlus
    2008-12-02 12:43 . 2008-12-02 12:43 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PCToolsSpamMonitorPlus
    2008-12-02 12:35 . 2008-12-07 13:34 <REP> d-------- c:\documents and settings\All Users\Application Data\PC Tools
    2008-12-02 08:54 . 2008-12-02 08:54 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Twain
    2008-12-01 23:27 . 2008-12-01 23:27 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Games
    2008-12-01 23:12 . 2008-12-01 23:26 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\FarmerJane
    2008-12-01 22:57 . 2008-12-01 22:57 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Gaijin Ent
    2008-12-01 21:43 . 2008-12-01 21:43 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Valusoft
    2008-12-01 21:43 . 2008-12-01 21:43 <REP> d-------- c:\documents and settings\All Users\Application Data\Valusoft
    2008-12-01 20:56 . 2008-12-01 20:56 <REP> d-------- c:\documents and settings\All Users\Application Data\Arkadium
    2008-12-01 20:00 . 2008-12-07 10:22 268 --a------ c:\windows\wininit.ini
    2008-12-01 13:46 . 2008-12-08 11:29 461 --a------ c:\windows\system32\win32hlp.cnf
    2008-12-01 10:28 . 2008-12-01 10:28 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\AlterLab
    2008-12-01 09:06 . 2008-12-01 15:51 <REP> d-------- c:\program files\Spybot - Search & Destroy
    2008-12-01 09:06 . 2008-12-08 10:29 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2008-11-28 20:48 . 2008-11-29 18:25 5 --a------ c:\windows\sbacknt.bin
    2008-11-28 20:46 . 2008-11-29 19:24 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\vghd
    2008-11-28 20:46 . 2008-11-28 20:46 152,904 --a------ c:\windows\system32\vghd.scr
    2008-11-28 20:46 . 2008-12-02 08:43 4 --a------ c:\windows\system32\test.ttt
    2008-11-28 19:30 . 2008-11-28 19:30 <REP> d-------- c:\documents and settings\All Users\Application Data\FreshGames
    2008-11-28 16:47 . 2008-11-28 16:47 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Meridian93
    2008-11-28 16:07 . 2008-11-30 17:43 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Shopping Blocks
    2008-11-28 14:59 . 2008-11-28 15:05 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Ancient Quest of Saqqarah__gamehouse
    2008-11-26 00:55 . 2008-11-28 19:30 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Zylom
    2008-11-25 22:09 . 2008-11-25 22:09 <REP> d--hs---- c:\windows\ftpcache
    2008-11-25 21:05 . 2008-11-25 21:05 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\SulusGames
    2008-11-25 16:52 . 2008-11-26 13:45 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\funkitron
    2008-11-25 16:51 . 2008-11-25 16:51 <REP> d-------- c:\program files\Slingo Quest
    2008-11-25 14:35 . 2008-11-25 14:36 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PetShowCraze
    2008-11-25 02:36 . 2008-11-25 02:36 <REP> d-------- c:\documents and settings\All Users\Application Data\QB9 S.R.L
    2008-11-24 20:48 . 2008-11-24 20:48 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\cerasus
    2008-11-24 17:24 . 2008-12-07 21:44 <REP> d---s---- c:\documents and settings\ISABELLE\UserData
    2008-11-23 18:30 . 2008-11-23 18:30 <REP> d-------- c:\documents and settings\All Users\Application Data\FarmFrenzy2
    2008-11-23 18:23 . 103,634 c:\windows\system32\drivers\30668e04.sys
    2008-11-23 16:31 . 2008-11-23 16:31 <REP> d-------- c:\documents and settings\ISABELLE\Contacts
    2008-11-22 22:56 . 2008-11-23 03:02 <REP> d--h----- c:\windows\$hf_mig$
    2008-11-22 22:55 . 2008-11-22 22:55 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\AVG7
    2008-11-22 22:54 . 2008-12-08 14:58 <REP> d-------- c:\windows\apppatch
    2008-11-22 22:54 . 2008-11-22 22:54 <REP> d--h----- c:\documents and settings\ISABELLE\Voisinage d'impression
    2008-11-22 22:54 . 2008-11-22 22:54 <REP> dr------- c:\documents and settings\ISABELLE\Menu Démarrer
    2008-11-22 22:54 . 2008-11-22 22:54 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\You've Got Pictures Screensaver
    2008-11-22 22:54 . 2008-11-22 22:54 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\DivX
    2008-11-21 22:14 . 2008-11-21 22:14 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\LuckyTender
    2008-11-21 20:15 . 2008-12-06 02:55 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\cerasus.media
    2008-11-21 19:09 . 2008-12-06 00:18 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PlayFirst
    2008-11-21 12:38 . 2008-11-21 12:39 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Magic Academy
    2008-11-21 11:36 . 2008-12-07 13:27 <REP> d-------- c:\program files\Fichiers communs\PC Tools
    2008-11-20 21:55 . 2008-11-20 21:55 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Flood Light Games
    2008-11-20 20:33 . 2006-02-24 22:56 <REP> d--h----- c:\documents and settings\ISABELLE\Voisinage réseau
    2008-11-20 20:33 . 2008-11-22 22:54 <REP> d--h----- c:\documents and settings\ISABELLE\Modèles
    2008-11-20 20:33 . 2008-12-07 21:43 <REP> dr------- c:\documents and settings\ISABELLE\Mes documents
    2008-11-20 20:33 . 2008-12-08 11:22 <REP> dr------- c:\documents and settings\ISABELLE\Favoris
    2008-11-20 20:33 . 2008-12-08 14:56 <REP> dr------- c:\documents and settings\ISABELLE\Bureau
    2008-11-20 20:33 . 2008-12-08 10:28 <REP> d-a------ c:\documents and settings\ISABELLE
    2008-11-18 11:31 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
    2008-11-18 11:31 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
    2008-11-18 11:31 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
    2008-11-17 22:26 . 2008-11-23 18:24 <REP> d-------- c:\program files\myBabylon_English
    2008-11-17 14:36 . 2008-11-17 14:36 <REP> d--hsc--- c:\program files\Fichiers communs\WindowsLiveInstaller
    2008-11-17 14:35 . 2008-11-17 14:36 <REP> d-------- c:\program files\Windows Live
    2008-11-17 14:35 . 2008-11-17 14:35 <REP> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
    2008-11-17 14:21 . 2008-10-24 12:21 455,296 --------- c:\windows\system32\dllcache\mrxsmb.sys
    2008-11-17 14:20 . 2008-09-04 18:16 1,106,944 --------- c:\windows\system32\dllcache\msxml3.dll

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-12-08 13:54 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
    2008-12-08 09:58 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
    2008-12-07 22:43 6,384 ----a-w C:\GETDRIVE.EXE
    2008-12-07 21:02 --------- d-----w c:\program files\Zylom Games
    2008-12-07 20:52 --------- d-----w c:\program files\DivX
    2008-12-06 20:01 --------- d-----w c:\program files\Yahoo!
    2008-12-05 23:18 --------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst
    2008-12-05 21:26 --------- d-----w c:\program files\eMule
    2008-11-26 00:02 --------- d-----w c:\program files\LuckyTender
    2008-11-25 23:26 --------- d-----w c:\documents and settings\All Users\Application Data\HipSoft
    2008-11-23 15:22 --------- d-----w c:\program files\Google
    2008-11-23 12:28 --------- d-----w c:\program files\Wanadoo
    2008-11-23 01:01 --------- d-----w c:\documents and settings\All Users\Application Data\MysteryChronicles
    2008-11-22 21:56 --------- d-----w c:\program files\Fichiers communs\Adobe
    2008-11-22 21:55 --------- d-----w c:\program files\Cluedo
    2008-11-22 21:55 --------- d-----w c:\documents and settings\All Users\Application Data\avg7
    2008-11-20 19:18 --------- d-----w c:\program files\Packard Bell EverSafe
    2008-11-04 21:34 --------- d-----w c:\documents and settings\All Users\Application Data\EscapeTheMuseum
    2008-11-03 23:04 --------- d-----w c:\documents and settings\All Users\Application Data\Fugazo
    2008-11-03 18:45 --------- d-----w c:\documents and settings\All Users\Application Data\MissTeriTale2
    2008-11-03 15:13 --------- d-----w c:\documents and settings\All Users\Application Data\MythPeople
    2008-10-30 16:11 --------- d-----w c:\documents and settings\All Users\Application Data\SpinTop Games
    2008-10-30 04:19 --------- d-----w c:\documents and settings\All Users\Application Data\Oberon Media
    2008-10-28 20:08 --------- d-----w c:\documents and settings\All Users\Application Data\n7-89-o9-3r-4t-r9
    2008-10-27 09:05 --------- d-----w c:\documents and settings\All Users\Application Data\JollyBear
    2008-10-27 06:42 --------- d-----w c:\documents and settings\All Users\Application Data\SugarGames
    2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
    2008-10-20 17:09 --------- d-----w c:\documents and settings\All Users\Application Data\Zylom
    2008-10-20 13:42 --------- d-----w c:\documents and settings\All Users\Application Data\GameHouse
    2008-10-19 08:38 --------- d-----w c:\program files\ReflexiveArcade
    2008-10-19 06:15 --------- d-----w c:\program files\QuickTime
    2008-10-18 06:26 --------- d-----w c:\documents and settings\All Users\Application Data\Flood Light Games
    2008-10-18 05:59 --------- d-----w c:\program files\Share_Accelerator_MM
    2008-10-18 05:59 --------- d-----w c:\program files\Conduit
    2008-10-17 15:24 --------- d--h--w c:\program files\InstallShield Installation Information
    2008-10-17 10:12 --------- d-----w c:\documents and settings\All Users\Application Data\FloodLightGames
    2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
    2008-10-16 13:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
    2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
    2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
    2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
    2008-10-16 13:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
    2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
    2008-10-16 13:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
    2008-10-16 13:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
    2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
    2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
    2008-10-16 13:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
    2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
    2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
    2008-10-16 13:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
    2008-10-16 07:06 --------- d-----w c:\documents and settings\All Users\Application Data\BOONTY
    2008-10-16 04:58 --------- d-----w c:\program files\Java
    2008-10-15 16:35 337,408 ------w c:\windows\system32\dllcache\netapi32.dll
    2008-10-08 14:08 --------- d-----w c:\program files\Lx_cats
    2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
    2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
    2008-09-15 15:26 1,846,528 ------w c:\windows\system32\dllcache\win32k.sys
    2008-09-10 01:15 1,307,648 ------w c:\windows\system32\msxml6.dll
    2008-09-10 01:15 1,307,648 ------w c:\windows\system32\dllcache\msxml6.dll
    2008-09-08 10:41 333,824 ------w c:\windows\system32\dllcache\srv.sys
    2006-02-24 20:37 3,308,767 ----a-w c:\program files\Shareaza_2.2.1.0.exe
    2006-02-24 19:32 1,525,216 -c--a-w c:\program files\Antispam.exe
    .

    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-02-03 68856]
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
    "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
    "WOOKIT"="c:\progra~1\Wanadoo\Shell.exe" [BU]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-10-19 413696]
    "TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-02-03 185632]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
    "SpywareCleaner"="c:\windows\system32\SpywareRemover.exe" [BU]
    "ISTray"="c:\program files\PC Tools Internet Security\pctsTray.exe" [BU]
    "Microsoft WinUpdate"="c:\windows\system32\msupdte.exe" [BU]
    "6425bd6f"="c:\windows\system32\gdgeatca.dll" [BU]
    "Framework Windows"="frmwrk32.exe" [BU]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=ykaeuo.dll xsqhhr.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
    @=""

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\eMule\\emule.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\WINDOWS\\system32\\mmc.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "8767:TCP"= 8767:TCP:messenger
    "8387:TCP"= 8387:TCP:messenger
    "7313:TCP"= 7313:TCP:messenger
    "6216:TCP"= 6216:TCP:messenger
    "6358:TCP"= 6358:TCP:messenger
    "5282:TCP"= 5282:TCP:messenger
    "2311:TCP"= 2311:TCP:messenger
    "2764:TCP"= 2764:TCP:messenger
    "8147:TCP"= 8147:TCP:messenger
    "7464:TCP"= 7464:TCP:messenger
    "8138:TCP"= 8138:TCP:messenger
    "4641:TCP"= 4641:TCP:messenger
    "4246:TCP"= 4246:TCP:messenger
    "5737:TCP"= 5737:TCP:messenger
    "5852:TCP"= 5852:TCP:messenger
    "4816:TCP"= 4816:TCP:messenger
    "4455:TCP"= 4455:TCP:messenger
    "4635:TCP"= 4635:TCP:messenger
    "8451:TCP"= 8451:TCP:messenger
    "5158:TCP"= 5158:TCP:messenger
    "2455:TCP"= 2455:TCP:messenger
    "1132:TCP"= 1132:TCP:messenger
    "3456:TCP"= 3456:TCP:messenger
    "5124:TCP"= 5124:TCP:messenger
    "5684:TCP"= 5684:TCP:messenger
    "7474:TCP"= 7474:TCP:messenger
    "1616:TCP"= 1616:TCP:messenger
    "7522:TCP"= 7522:TCP:messenger

    R1 Asapi;Asapi;c:\windows\system32\drivers\Asapi.sys [2004-11-01 11264]
    R2 MTC0005_MTCDIO;Wireless HotKey Driver;c:\windows\system32\drivers\MTCDIO.sys [2004-11-01 11316]
    R2 NwSapAgent;Agent SAP;c:\windows\System32\svchost.exe -k netsvcs [2002-09-30 14336]
    R3 EMCR;EMCR;c:\windows\system32\DRIVERS\EMCR7SK.sys [1980-01-01 68224]
    S1 aswSP;avast! Self Protection; []
    S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys []
    S2 MTCDIO;MTCDIO;c:\windows\system32\DRIVERS\MTCDIO.sys [2004-11-01 11316]
    S3 fbxusb;Carte réseau virtuelle FreeBox USB;c:\windows\system32\DRIVERS\fbxusb32.sys [2006-08-21 21344]
    S3 PhTVTune;Cap7134 TVTuner;c:\windows\system32\DRIVERS\PhTVTune.sys [2004-06-15 42080]
    .
    Contenu du dossier 'Tâches planifiées'

    2008-10-30 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 12:42]

    2006-02-24 c:\windows\Tasks\Rappel d'enregistrement 3.job
    - c:\windows\System32\OOBE\oobebaln.exe [2008-04-14 03:34]
    .
    - - - - ORPHELINS SUPPRIMES - - - -

    Toolbar-{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - (no file)
    WebBrowser-{B2E293EE-FD7E-4C71-A714-5F4750D8D7B7} - (no file)
    Notify-spttseng32 - spttseng32.dll

    .
    ------- Examen supplémentaire -------
    .
    uSearch Page = hxxp://www.google.com
    uStart Page = hxxp://www.orange.fr/
    uSearch Bar = hxxp://www.google.com/ie
    mDefault_Search_URL = hxxp://www.google.com/ie
    mStart Page = hxxp://lo.st
    mWindow Title =
    uInternet Connection Wizard,ShellNext = hxxp://celaia.daxon.fr/vente-en-ligne/panier/panier.aspx
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    mSearchAssistant = hxxp://www.google.com/ie
    LSP: c:\program files\Fichiers communs\PC Tools\Lsp\PCTLsp.dll

    O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
    c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd

    O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
    c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

    c:\windows\Downloaded Program Files\CookingDashWeb.1.0.0.9.dll - O16 -: {195B4BBF-E1E4-4020-9773-0A8C6F65EA35}
    hxxp://webgames.d.tmsrv.com/c=57c218bb5298e374b3c5e9f078cabd4f/aff=t_25oa_frca_wg/p/release/playfirst/wg_cookingdash/cookingdash/CookingDashWeb.1.0.0.9.cab
    c:\windows\Downloaded Program Files\CookingDashWeb.1.0.0.9.inf

    c:\windows\Downloaded Program Files\zenerchi.1.0.0.10.dll - O16 -: {bac761d3-dffd-4db4-a01d-173346e090a7}
    hxxp://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--5bca0d7d-3ef6-4521-bd1b-5d981bd14ff1/online/zenerchi/fr/ZenerchiWeb.1.0.0.10.cab
    c:\windows\Downloaded Program Files\zenerchi.1.0.0.10.inf

    c:\windows\Downloaded Program Files\OberonGameHost.dll - O16 -: {D0C0F75C-683A-4390-A791-1ACFD5599AB8}
    hxxp://jeuxenligne.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
    c:\windows\Downloaded Program Files\OberonGameHost_dbg.inf
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-12-08 15:02:06
    Windows 5.1.2600 Service Pack 3 NTFS

    Recherche de processus cachés ...

    Recherche d'éléments en démarrage automatique cachés ...

    Recherche de fichiers cachés ...

    Scan terminé avec succès
    Fichiers cachés: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySqlInventime]
    "ImagePath"="c:\mysql\bin\mysqld-max-nt MySqlInventime"

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\30668e04]
    "ImagePath"="\SystemRoot\System32\drivers\30668e04.sys"
    .
    --------------------- DLLs chargées dans les processus actifs ---------------------

    - - - - - - - > 'winlogon.exe'(896)
    c:\program files\PC Tools AntiVirus\PCTAVHook.dll

    - - - - - - - > 'lsass.exe'(952)
    c:\program files\Fichiers communs\PC Tools\Lsp\PCTLsp.dll
    c:\program files\PC Tools AntiVirus\PCTAVHook.dll

    - - - - - - - > 'csrss.exe'(872)
    c:\program files\PC Tools AntiVirus\PCTAVHook.dll
    .
    ------------------------ Autres processus actifs ------------------------
    .
    c:\windows\system32\ati2evxx.exe
    c:\progra~1\FICHIE~1\AOL\ACS\AOLacsd.exe
    c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
    c:\program files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
    c:\program files\PC Tools AntiVirus\PCTAVSvc.exe
    .
    **************************************************************************
    .
    Heure de fin: 2008-12-08 15:05:12 - La machine a redémarré
    ComboFix-quarantined-files.txt 2008-12-08 14:05:07

    Avant-CF: 24 203 284 480 octets libres
    Après-CF: 24,212,541,440 octets libres

    328 --- E O F --- 2008-11-24 09:41:45
    0
  3. mumu5938 Messages postés 31 Statut Membre
     
    comment dois je faire pour le rapport Hijackthis ? merci bcp pour votre aide
    0
  4. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    mets RSIT alors
    0
    1. mumu5938 Messages postés 31 Statut Membre
       
      ok mais je fais comment?
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    comme en 2

    Télécharge ici :

    http://images.malwareremoval.com/random/RSIT.exe

    random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

    Double-clique sur RSIT.exe afin de lancer RSIT.

    Clique Continue à l'écran Disclaimer.

    Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

    Poste le contenu de log.txt (<<qui sera affiché)
    ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

    NB : Les rapports sont sauvegardés dans le dossier C:\rsit
    0
    1. mumu5938 Messages postés 31 Statut Membre
       
      Logfile of random's system information tool 1.04 (written by random/random)
      Run by ISABELLE at 2008-12-08 15:20:41
      Microsoft Windows XP Édition familiale Service Pack 3
      System drive C: has 23 GB (43%) free of 53 GB
      Total RAM: 511 MB (40% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 15:20:50, on 08/12/2008
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\System32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\alg.exe
      C:\WINDOWS\explorer.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\WINDOWS\system32\NOTEPAD.EXE
      C:\Documents and Settings\ISABELLE\Bureau\RSIT.exe
      C:\WINDOWS\System32\wbem\wmiprvse.exe
      C:\Program Files\trend micro\ISABELLE.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://lo.st
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.balsamik.fr/
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: (no name) - software - (no file)
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: Google Toolbar Helper - {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
      O3 - Toolbar: (no name) - {4596013b-6c31-408b-a266-deae5c086dc2} - (no file)
      O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O3 - Toolbar: (no name) - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - (no file)
      O3 - Toolbar: (no name) - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - (no file)
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [SpywareCleaner] C:\WINDOWS\system32\SpywareRemover.exe
      O4 - HKLM\..\Run: [ISTray] "C:\Program Files\PC Tools Internet Security\pctsTray.exe"
      O4 - HKLM\..\Run: [Microsoft WinUpdate] C:\WINDOWS\system32\msupdte.exe
      O4 - HKLM\..\Run: [Framework Windows] frmwrk32.exe
      O4 - HKLM\..\Run: [6425bd6f] rundll32.exe "C:\WINDOWS\system32\gdgeatca.dll",b
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
      O4 - HKCU\..\Run: [gadcom] "C:\Documents and Settings\ISABELLE\Application Data\gadcom\gadcom.exe" 61A847B5BBF72810339E3F466188719AB689201522886B092CBD44BD8689220221DD3257
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
      O9 - Extra button: (no name) - software - (no file)
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
      O9 - Extra button: (no name) - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
      O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
      O16 - DPF: {195B4BBF-E1E4-4020-9773-0A8C6F65EA35} (CPlayFirstCookingDasControl Object) - http://webgames.d.tmsrv.com/c=57c218bb5298e374b3c5e9f078cabd4f/aff=t_25oa_frca_wg/p/release/playfirst/wg_cookingdash/cookingdash/CookingDashWeb.1.0.0.9.cab
      O16 - DPF: {bac761d3-dffd-4db4-a01d-173346e090a7} (CPlayFirstzenerchiControl Object) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--5bca0d7d-3ef6-4521-bd1b-5d981bd14ff1/online/zenerchi/fr/ZenerchiWeb.1.0.0.10.cab
      O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
      O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxenligne.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
      O16 - DPF: {ea6246b4-f380-443f-8727-9aea3371146c} (CPlayFirstWeddingDashControl Object) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--d66a432b-38e7-468a-b329-33657f1af599/online/wedding_dash/fr/WeddingDash.1.0.0.47.cab
      O20 - AppInit_DLLs: ykaeuo.dll xsqhhr.dll
      O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
      O23 - Service: MySqlInventime - Unknown owner - c:\mysql\bin\mysqld-max-nt.exe
      O23 - Service: PC Tools AntiVirus Engine (pctavsvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
      O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
      0
  7. mumu5938 Messages postés 31 Statut Membre
     
    je n'ai pas info.txt
    0
  8. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    analyse ces 4 fichiers sur virus total et colle moi les rapports: https://www.virustotal.com/gui/

    c:\windows\system32\SpywareRemover.exe
    c:\windows\system32\gdgeatca.dll
    C:\WINDOWS\system32\frmwrk32.exe
    c:\windows\system32\msupdte.exe

    ________________

    je me mets ceci de coté

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SpywareCleaner"=-
    "Microsoft WinUpdate"=-
    "6425bd6f"=-
    "Framework Windows"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=-

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://lo.st
    O2 - BHO: (no name) - software - (no file)
    O3 - Toolbar: (no name) - {4596013b-6c31-408b-a266-deae5c086dc2} - (no file)
    O3 - Toolbar: (no name) - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - (no file)
    O3 - Toolbar: (no name) - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SpywareCleaner] C:\WINDOWS\system32\SpywareRemover.exe
    O4 - HKLM\..\Run: [Microsoft WinUpdate] C:\WINDOWS\system32\msupdte.exe
    O4 - HKLM\..\Run: [Framework Windows] frmwrk32.exe
    O4 - HKLM\..\Run: [6425bd6f] rundll32.exe "C:\WINDOWS\system32\gdgeatca.dll",b
    O4 - HKCU\..\Run: [gadcom] "C:\Documents and Settings\ISABELLE\Application Data\gadcom\gadcom.exe" 61A847B5BBF72810339E3F466188719AB689201522886B092CBD44BD8689220221DD3257
    O9 - Extra button: (no name) - software - (no file)
    O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxenligne.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
    O20 - AppInit_DLLs: ykaeuo.dll xsqhhr.dll
    0
    1. mumu5938 Messages postés 31 Statut Membre
       
      ca ne fonctionne pas pour analyser les quatre fichiers il ne les trouve pas
      0
    2. mumu5938 Messages postés 31 Statut Membre
       
      0 bytes size received / Se ha recibido un archivo vacio
      0
  9. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    ok o size c'est donc bien une cochonnerie!

    _____________

    Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked".

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://lo.st
    O2 - BHO: (no name) - software - (no file)
    O3 - Toolbar: (no name) - {4596013b-6c31-408b-a266-deae5c086dc2} - (no file)
    O3 - Toolbar: (no name) - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - (no file)
    O3 - Toolbar: (no name) - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SpywareCleaner] C:\WINDOWS\system32\SpywareRemover.exe
    O4 - HKLM\..\Run: [Microsoft WinUpdate] C:\WINDOWS\system32\msupdte.exe
    O4 - HKLM\..\Run: [Framework Windows] frmwrk32.exe
    O4 - HKLM\..\Run: [6425bd6f] rundll32.exe "C:\WINDOWS\system32\gdgeatca.dll",b
    O4 - HKCU\..\Run: [gadcom] "C:\Documents and Settings\ISABELLE\Application Data\gadcom\gadcom.exe" 61A847B5BBF72810339E3F466188719AB689201522886B092CBD44BD8689220221DD3257
    O9 - Extra button: (no name) - software - (no file)
    O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxenligne.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
    O20 - AppInit_DLLs: ykaeuo.dll xsqhhr.dll

    __________________

    Ferme tous tes navigateurs (donc copie ou imprime les instructions avant)

    Crée un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :

    File::
    c:\windows\system32\SpywareRemover.exe
    c:\windows\system32\gdgeatca.dll
    C:\WINDOWS\system32\frmwrk32.exe
    c:\windows\system32\msupdte.exe
    c:\windows\Downloaded Program Files\OberonGameHost.dll
    c:\windows\Downloaded Program Files\OberonGameHost_dbg.inf
    C:\Documents and Settings\ISABELLE\Application Data\gadcom\gadcom.exe

    Registry::
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersio­n\Run]
    "SpywareCleaner"=-
    "Microsoft WinUpdate"=-
    "6425bd6f"=-
    "Framework Windows"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=-

    Enregistre ce fichier sous le nom CFscript

    Fait un glisser/déposer de ce fichier CFscrïpt sur le fichier ComboFix.exe

    Clique sur le fichier CFScript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFScript vienne recouvrir l'icône de Combofix. Relache la souris. Combofix va démarrer.

    Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

    Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

    Ne touche à rien tant que le scan n'est pas terminé.

    Une fois le scan achevé, un rapport va s'afficher: poste son contenu.

    Remets aussi un rapport Hijackthis ou RSIT

    Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
    0
  10. mumu5938 Messages postés 31 Statut Membre
     
    vous croyez qu'on va s'en sortir?
    0
  11. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    OUI
    0
    1. mumu5938 Messages postés 31 Statut Membre
       
      ComboFix 08-12-06.06 - ISABELLE 2008-12-08 16:25:41.3 - NTFSx86
      Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.247 [GMT 1:00]
      Lancé depuis: c:\documents and settings\ISABELLE\Bureau\ComboFix.exe
      Commutateurs utilisés :: c:\documents and settings\ISABELLE\Bureau\cfscript.txt
      * Un nouveau point de restauration a été créé
      * Resident AV is active


      FILE ::
      c:\documents and settings\ISABELLE\Application Data\gadcom\gadcom.exe
      c:\windows\Downloaded Program Files\OberonGameHost.dll
      c:\windows\Downloaded Program Files\OberonGameHost_dbg.inf
      c:\windows\system32\frmwrk32.exe
      c:\windows\system32\gdgeatca.dll
      c:\windows\system32\msupdte.exe
      c:\windows\system32\SpywareRemover.exe
      .

      ((((((((((((((((((((((((((((( Fichiers créés du 2008-11-08 au 2008-12-08 ))))))))))))))))))))))))))))))))))))
      .

      2008-12-08 13:48 . 2008-12-08 13:48 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Malwarebytes
      2008-12-08 13:47 . 2008-12-08 13:48 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
      2008-12-08 13:47 . 2008-12-08 13:47 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
      2008-12-08 13:47 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
      2008-12-08 13:47 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
      2008-12-08 11:58 . 2008-12-08 12:25 <REP> d-------- C:\ToolBar SD
      2008-12-08 11:42 . 2008-12-08 11:42 <REP> d-------- C:\rsit
      2008-12-08 11:42 . 2008-12-08 16:12 <REP> d-------- c:\program files\trend micro
      2008-12-08 01:29 . 2008-12-08 01:29 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
      2008-12-07 13:35 . 2008-12-07 13:35 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PC Tools
      2008-12-07 13:34 . 2008-12-08 15:02 <REP> d-------- c:\program files\PC Tools AntiVirus
      2008-12-07 13:34 . 2007-12-06 16:51 28,568 --a------ c:\windows\system32\drivers\AVHook.sys
      2008-12-07 13:34 . 2007-12-06 16:51 21,912 --a------ c:\windows\system32\drivers\AVRec.sys
      2008-12-07 13:34 . 2008-02-12 11:44 21,904 --a------ c:\windows\system32\drivers\AVFilter.sys
      2008-12-06 20:59 . 2008-12-06 21:02 <REP> d-------- c:\program files\CCleaner
      2008-12-06 00:56 . 2008-12-06 00:56 <REP> d-------- c:\documents and settings\All Users\Application Data\TheRace_dev
      2008-12-06 00:42 . 2008-12-06 00:42 <REP> d-------- c:\program files\Fichiers communs\SWF Studio
      2008-12-05 23:28 . 2008-12-05 23:28 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\iWin
      2008-12-05 23:28 . 2008-12-05 23:28 <REP> d-------- c:\documents and settings\All Users\Application Data\iWin
      2008-12-05 22:42 . 2008-12-05 22:42 <REP> d-------- c:\documents and settings\All Users\Application Data\Gogii
      2008-12-05 22:28 . 2008-12-05 22:28 <REP> d-------- c:\documents and settings\All Users\Application Data\Intenium
      2008-12-04 23:49 . 2008-12-04 23:49 <REP> d-------- c:\documents and settings\LocalService\Application Data\PCToolsSpamMonitorPlus
      2008-12-04 23:49 . 2008-12-04 23:49 <REP> d-------- c:\documents and settings\LocalService\Application Data\PCToolsFirewallPlus
      2008-12-04 19:55 . 2008-12-04 19:55 <REP> d--h----- c:\windows\PIF
      2008-12-03 04:12 . 2008-12-06 00:39 <REP> d-------- c:\documents and settings\All Users\Application Data\Playrix Entertainment
      2008-12-02 12:44 . 2008-12-02 12:44 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PCToolsFirewallPlus
      2008-12-02 12:43 . 2008-12-02 12:43 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PCToolsSpamMonitorPlus
      2008-12-02 12:35 . 2008-12-07 13:34 <REP> d-------- c:\documents and settings\All Users\Application Data\PC Tools
      2008-12-02 08:54 . 2008-12-02 08:54 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Twain
      2008-12-01 23:27 . 2008-12-01 23:27 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Games
      2008-12-01 23:12 . 2008-12-01 23:26 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\FarmerJane
      2008-12-01 22:57 . 2008-12-01 22:57 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Gaijin Ent
      2008-12-01 21:43 . 2008-12-01 21:43 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Valusoft
      2008-12-01 21:43 . 2008-12-01 21:43 <REP> d-------- c:\documents and settings\All Users\Application Data\Valusoft
      2008-12-01 20:56 . 2008-12-01 20:56 <REP> d-------- c:\documents and settings\All Users\Application Data\Arkadium
      2008-12-01 20:00 . 2008-12-07 10:22 268 --a------ c:\windows\wininit.ini
      2008-12-01 13:46 . 2008-12-08 11:29 461 --a------ c:\windows\system32\win32hlp.cnf
      2008-12-01 10:28 . 2008-12-01 10:28 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\AlterLab
      2008-12-01 09:06 . 2008-12-01 15:51 <REP> d-------- c:\program files\Spybot - Search & Destroy
      2008-12-01 09:06 . 2008-12-08 10:29 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
      2008-11-28 20:48 . 2008-11-29 18:25 5 --a------ c:\windows\sbacknt.bin
      2008-11-28 20:46 . 2008-11-29 19:24 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\vghd
      2008-11-28 20:46 . 2008-11-28 20:46 152,904 --a------ c:\windows\system32\vghd.scr
      2008-11-28 20:46 . 2008-12-02 08:43 4 --a------ c:\windows\system32\test.ttt
      2008-11-28 19:30 . 2008-11-28 19:30 <REP> d-------- c:\documents and settings\All Users\Application Data\FreshGames
      2008-11-28 16:47 . 2008-11-28 16:47 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Meridian93
      2008-11-28 16:07 . 2008-11-30 17:43 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Shopping Blocks
      2008-11-28 14:59 . 2008-11-28 15:05 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Ancient Quest of Saqqarah__gamehouse
      2008-11-26 00:55 . 2008-11-28 19:30 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Zylom
      2008-11-25 22:09 . 2008-11-25 22:09 <REP> d--hs---- c:\windows\ftpcache
      2008-11-25 21:05 . 2008-11-25 21:05 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\SulusGames
      2008-11-25 16:52 . 2008-11-26 13:45 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\funkitron
      2008-11-25 16:51 . 2008-11-25 16:51 <REP> d-------- c:\program files\Slingo Quest
      2008-11-25 14:35 . 2008-11-25 14:36 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PetShowCraze
      2008-11-25 02:36 . 2008-11-25 02:36 <REP> d-------- c:\documents and settings\All Users\Application Data\QB9 S.R.L
      2008-11-24 20:48 . 2008-11-24 20:48 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\cerasus
      2008-11-24 17:24 . 2008-12-07 21:44 <REP> d---s---- c:\documents and settings\ISABELLE\UserData
      2008-11-23 18:30 . 2008-11-23 18:30 <REP> d-------- c:\documents and settings\All Users\Application Data\FarmFrenzy2
      2008-11-23 18:23 . 103,634 c:\windows\system32\drivers\30668e04.sys
      2008-11-23 16:31 . 2008-11-23 16:31 <REP> d-------- c:\documents and settings\ISABELLE\Contacts
      2008-11-22 22:56 . 2008-11-23 03:02 <REP> d--h----- c:\windows\$hf_mig$
      2008-11-22 22:55 . 2008-11-22 22:55 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\AVG7
      2008-11-22 22:54 . 2008-12-08 16:27 <REP> d-------- c:\windows\apppatch
      2008-11-22 22:54 . 2008-11-22 22:54 <REP> d--h----- c:\documents and settings\ISABELLE\Voisinage d'impression
      2008-11-22 22:54 . 2008-11-22 22:54 <REP> dr------- c:\documents and settings\ISABELLE\Menu Démarrer
      2008-11-22 22:54 . 2008-11-22 22:54 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\You've Got Pictures Screensaver
      2008-11-22 22:54 . 2008-11-22 22:54 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\DivX
      2008-11-21 22:14 . 2008-11-21 22:14 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\LuckyTender
      2008-11-21 20:15 . 2008-12-06 02:55 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\cerasus.media
      2008-11-21 19:09 . 2008-12-06 00:18 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PlayFirst
      2008-11-21 12:38 . 2008-11-21 12:39 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Magic Academy
      2008-11-21 11:36 . 2008-12-07 13:27 <REP> d-------- c:\program files\Fichiers communs\PC Tools
      2008-11-20 21:55 . 2008-11-20 21:55 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Flood Light Games
      2008-11-20 20:33 . 2006-02-24 22:56 <REP> d--h----- c:\documents and settings\ISABELLE\Voisinage réseau
      2008-11-20 20:33 . 2008-11-22 22:54 <REP> d--h----- c:\documents and settings\ISABELLE\Modèles
      2008-11-20 20:33 . 2008-12-07 21:43 <REP> dr------- c:\documents and settings\ISABELLE\Mes documents
      2008-11-20 20:33 . 2008-12-08 11:22 <REP> dr------- c:\documents and settings\ISABELLE\Favoris
      2008-11-20 20:33 . 2008-12-08 16:25 <REP> dr------- c:\documents and settings\ISABELLE\Bureau
      2008-11-20 20:33 . 2008-12-08 10:28 <REP> d-a------ c:\documents and settings\ISABELLE
      2008-11-18 11:31 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
      2008-11-18 11:31 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
      2008-11-18 11:31 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
      2008-11-17 22:26 . 2008-11-23 18:24 <REP> d-------- c:\program files\myBabylon_English
      2008-11-17 14:36 . 2008-11-17 14:36 <REP> d--hsc--- c:\program files\Fichiers communs\WindowsLiveInstaller
      2008-11-17 14:35 . 2008-11-17 14:36 <REP> d-------- c:\program files\Windows Live
      2008-11-17 14:35 . 2008-11-17 14:35 <REP> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
      2008-11-17 14:21 . 2008-10-24 12:21 455,296 --------- c:\windows\system32\dllcache\mrxsmb.sys
      2008-11-17 14:20 . 2008-09-04 18:16 1,106,944 --------- c:\windows\system32\dllcache\msxml3.dll

      .
      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2008-12-08 13:54 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
      2008-12-08 09:58 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
      2008-12-07 22:43 6,384 ----a-w C:\GETDRIVE.EXE
      2008-12-07 21:02 --------- d-----w c:\program files\Zylom Games
      2008-12-07 20:52 --------- d-----w c:\program files\DivX
      2008-12-06 20:01 --------- d-----w c:\program files\Yahoo!
      2008-12-05 23:18 --------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst
      2008-12-05 21:26 --------- d-----w c:\program files\eMule
      2008-11-26 00:02 --------- d-----w c:\program files\LuckyTender
      2008-11-25 23:26 --------- d-----w c:\documents and settings\All Users\Application Data\HipSoft
      2008-11-23 15:22 --------- d-----w c:\program files\Google
      2008-11-23 12:28 --------- d-----w c:\program files\Wanadoo
      2008-11-23 01:01 --------- d-----w c:\documents and settings\All Users\Application Data\MysteryChronicles
      2008-11-22 21:56 --------- d-----w c:\program files\Fichiers communs\Adobe
      2008-11-22 21:55 --------- d-----w c:\program files\Cluedo
      2008-11-22 21:55 --------- d-----w c:\documents and settings\All Users\Application Data\avg7
      2008-11-20 19:18 --------- d-----w c:\program files\Packard Bell EverSafe
      2008-11-04 21:34 --------- d-----w c:\documents and settings\All Users\Application Data\EscapeTheMuseum
      2008-11-03 23:04 --------- d-----w c:\documents and settings\All Users\Application Data\Fugazo
      2008-11-03 18:45 --------- d-----w c:\documents and settings\All Users\Application Data\MissTeriTale2
      2008-11-03 15:13 --------- d-----w c:\documents and settings\All Users\Application Data\MythPeople
      2008-10-30 16:11 --------- d-----w c:\documents and settings\All Users\Application Data\SpinTop Games
      2008-10-30 04:19 --------- d-----w c:\documents and settings\All Users\Application Data\Oberon Media
      2008-10-28 20:08 --------- d-----w c:\documents and settings\All Users\Application Data\n7-89-o9-3r-4t-r9
      2008-10-27 09:05 --------- d-----w c:\documents and settings\All Users\Application Data\JollyBear
      2008-10-27 06:42 --------- d-----w c:\documents and settings\All Users\Application Data\SugarGames
      2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
      2008-10-20 17:09 --------- d-----w c:\documents and settings\All Users\Application Data\Zylom
      2008-10-20 13:42 --------- d-----w c:\documents and settings\All Users\Application Data\GameHouse
      2008-10-19 08:38 --------- d-----w c:\program files\ReflexiveArcade
      2008-10-19 06:15 --------- d-----w c:\program files\QuickTime
      2008-10-18 06:26 --------- d-----w c:\documents and settings\All Users\Application Data\Flood Light Games
      2008-10-18 05:59 --------- d-----w c:\program files\Share_Accelerator_MM
      2008-10-18 05:59 --------- d-----w c:\program files\Conduit
      2008-10-17 15:24 --------- d--h--w c:\program files\InstallShield Installation Information
      2008-10-17 10:12 --------- d-----w c:\documents and settings\All Users\Application Data\FloodLightGames
      2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
      2008-10-16 13:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
      2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
      2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
      2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
      2008-10-16 13:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
      2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
      2008-10-16 13:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
      2008-10-16 13:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
      2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
      2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
      2008-10-16 13:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
      2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
      2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
      2008-10-16 13:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
      2008-10-16 07:06 --------- d-----w c:\documents and settings\All Users\Application Data\BOONTY
      2008-10-16 04:58 --------- d-----w c:\program files\Java
      2008-10-15 16:35 337,408 ------w c:\windows\system32\dllcache\netapi32.dll
      2008-10-08 14:08 --------- d-----w c:\program files\Lx_cats
      2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
      2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
      2008-09-15 15:26 1,846,528 ------w c:\windows\system32\dllcache\win32k.sys
      2008-09-10 01:15 1,307,648 ------w c:\windows\system32\msxml6.dll
      2008-09-10 01:15 1,307,648 ------w c:\windows\system32\dllcache\msxml6.dll
      2008-09-08 10:41 333,824 ------w c:\windows\system32\dllcache\srv.sys
      2006-02-24 20:37 3,308,767 ----a-w c:\program files\Shareaza_2.2.1.0.exe
      2006-02-24 19:32 1,525,216 -c--a-w c:\program files\Antispam.exe
      .

      ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
      REGEDIT4

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-02-03 68856]
      "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
      "SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
      "WOOKIT"="c:\progra~1\Wanadoo\Shell.exe" [BU]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-02-03 185632]
      "ISTray"="c:\program files\PC Tools Internet Security\pctsTray.exe" [BU]

      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
      @=""

      [HKEY_LOCAL_MACHINE\software\microsoft\security center]
      "AntiVirusOverride"=dword:00000001

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\system32\\sessmgr.exe"=
      "c:\\Program Files\\Messenger\\msmsgs.exe"=
      "c:\\Program Files\\eMule\\emule.exe"=
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "c:\\WINDOWS\\system32\\mmc.exe"=
      "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
      "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
      "8767:TCP"= 8767:TCP:messenger
      "8387:TCP"= 8387:TCP:messenger
      "7313:TCP"= 7313:TCP:messenger
      "6216:TCP"= 6216:TCP:messenger
      "6358:TCP"= 6358:TCP:messenger
      "5282:TCP"= 5282:TCP:messenger
      "2311:TCP"= 2311:TCP:messenger
      "2764:TCP"= 2764:TCP:messenger
      "8147:TCP"= 8147:TCP:messenger
      "7464:TCP"= 7464:TCP:messenger
      "8138:TCP"= 8138:TCP:messenger
      "4641:TCP"= 4641:TCP:messenger
      "4246:TCP"= 4246:TCP:messenger
      "5737:TCP"= 5737:TCP:messenger
      "5852:TCP"= 5852:TCP:messenger
      "4816:TCP"= 4816:TCP:messenger
      "4455:TCP"= 4455:TCP:messenger
      "4635:TCP"= 4635:TCP:messenger
      "8451:TCP"= 8451:TCP:messenger
      "5158:TCP"= 5158:TCP:messenger
      "2455:TCP"= 2455:TCP:messenger
      "1132:TCP"= 1132:TCP:messenger
      "3456:TCP"= 3456:TCP:messenger
      "5124:TCP"= 5124:TCP:messenger
      "5684:TCP"= 5684:TCP:messenger
      "7474:TCP"= 7474:TCP:messenger
      "1616:TCP"= 1616:TCP:messenger
      "7522:TCP"= 7522:TCP:messenger

      R1 Asapi;Asapi;c:\windows\system32\drivers\Asapi.sys [2004-11-01 11264]
      R2 MTC0005_MTCDIO;Wireless HotKey Driver;c:\windows\system32\drivers\MTCDIO.sys [2004-11-01 11316]
      R2 NwSapAgent;Agent SAP;c:\windows\System32\svchost.exe -k netsvcs [2002-09-30 14336]
      R3 EMCR;EMCR;c:\windows\system32\DRIVERS\EMCR7SK.sys [1980-01-01 68224]
      S1 aswSP;avast! Self Protection; []
      S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys []
      S2 MTCDIO;MTCDIO;c:\windows\system32\DRIVERS\MTCDIO.sys [2004-11-01 11316]
      S3 fbxusb;Carte réseau virtuelle FreeBox USB;c:\windows\system32\DRIVERS\fbxusb32.sys [2006-08-21 21344]
      S3 PhTVTune;Cap7134 TVTuner;c:\windows\system32\DRIVERS\PhTVTune.sys [2004-06-15 42080]

      *Newly Created Service* - catchme
      .
      Contenu du dossier 'Tâches planifiées'

      2008-10-30 c:\windows\Tasks\AppleSoftwareUpdate.job
      - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 12:42]

      2006-02-24 c:\windows\Tasks\Rappel d'enregistrement 3.job
      - c:\windows\System32\OOBE\oobebaln.exe [2008-04-14 03:34]
      .
      - - - - ORPHELINS SUPPRIMES - - - -

      WebBrowser-{B2E293EE-FD7E-4C71-A714-5F4750D8D7B7} - (no file)


      .
      ------- Examen supplémentaire -------
      .
      uSearch Page = hxxp://www.google.com
      uStart Page = hxxp://www.orange.fr/
      uSearch Bar = hxxp://www.google.com/ie
      mWindow Title =
      uInternet Connection Wizard,ShellNext = hxxp://celaia.daxon.fr/vente-en-ligne/panier/panier.aspx
      uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
      LSP: c:\program files\Fichiers communs\PC Tools\Lsp\PCTLsp.dll

      O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
      c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd

      O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
      c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd

      c:\windows\Downloaded Program Files\CookingDashWeb.1.0.0.9.dll - O16 -: {195B4BBF-E1E4-4020-9773-0A8C6F65EA35}
      hxxp://webgames.d.tmsrv.com/c=57c218bb5298e374b3c5e9f078cabd4f/aff=t_25oa_frca_wg/p/release/playfirst/wg_cookingdash/cookingdash/CookingDashWeb.1.0.0.9.cab
      c:\windows\Downloaded Program Files\CookingDashWeb.1.0.0.9.inf

      c:\windows\Downloaded Program Files\zenerchi.1.0.0.10.dll - O16 -: {bac761d3-dffd-4db4-a01d-173346e090a7}
      hxxp://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--5bca0d7d-3ef6-4521-bd1b-5d981bd14ff1/online/zenerchi/fr/ZenerchiWeb.1.0.0.10.cab
      c:\windows\Downloaded Program Files\zenerchi.1.0.0.10.inf
      .

      **************************************************************************

      catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-12-08 16:29:08
      Windows 5.1.2600 Service Pack 3 NTFS

      Recherche de processus cachés ...

      Recherche d'éléments en démarrage automatique cachés ...

      Recherche de fichiers cachés ...

      Scan terminé avec succès
      Fichiers cachés: 0

      **************************************************************************

      [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MySqlInventime]
      "ImagePath"="c:\mysql\bin\mysqld-max-nt MySqlInventime"

      [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\30668e04]
      "ImagePath"="\SystemRoot\System32\drivers\30668e04.sys"
      .
      --------------------- DLLs chargées dans les processus actifs ---------------------

      - - - - - - - > 'winlogon.exe'(896)
      c:\program files\PC Tools AntiVirus\PCTAVHook.dll

      - - - - - - - > 'lsass.exe'(952)
      c:\program files\Fichiers communs\PC Tools\Lsp\PCTLsp.dll
      c:\program files\PC Tools AntiVirus\PCTAVHook.dll

      - - - - - - - > 'csrss.exe'(872)
      c:\program files\PC Tools AntiVirus\PCTAVHook.dll
      .
      Heure de fin: 2008-12-08 16:30:17
      ComboFix-quarantined-files.txt 2008-12-08 15:30:14
      ComboFix2.txt 2008-12-08 14:05:13

      Avant-CF: 24 168 558 592 octets libres
      Après-CF: 24,179,494,912 octets libres

      297 --- E O F --- 2008-11-24 09:41:45
      0
    2. mumu5938 Messages postés 31 Statut Membre
       
      Logfile of random's system information tool 1.04 (written by random/random)
      Run by ISABELLE at 2008-12-08 16:33:10
      Microsoft Windows XP Édition familiale Service Pack 3
      System drive C: has 23 GB (43%) free of 53 GB
      Total RAM: 511 MB (36% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 16:33:18, on 08/12/2008
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\System32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\alg.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\WINDOWS\explorer.exe
      C:\WINDOWS\system32\notepad.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Documents and Settings\ISABELLE\Bureau\HiJackThis.exe
      C:\Documents and Settings\ISABELLE\Bureau\RSIT.exe
      C:\WINDOWS\System32\wbem\wmiprvse.exe
      C:\Documents and Settings\ISABELLE\Bureau\ISABELLE.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.balsamik.fr/
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: (no name) - software - (no file)
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: Google Toolbar Helper - {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
      O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [ISTray] "C:\Program Files\PC Tools Internet Security\pctsTray.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
      O4 - HKCU\..\Run: [gadcom] "C:\Documents and Settings\ISABELLE\Application Data\gadcom\gadcom.exe" 61A847B5BBF72810339E3F466188719AB689201522886B092CBD44BD8689220221DD3257
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
      O9 - Extra button: (no name) - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
      O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
      O16 - DPF: {195B4BBF-E1E4-4020-9773-0A8C6F65EA35} (CPlayFirstCookingDasControl Object) - http://webgames.d.tmsrv.com/c=57c218bb5298e374b3c5e9f078cabd4f/aff=t_25oa_frca_wg/p/release/playfirst/wg_cookingdash/cookingdash/CookingDashWeb.1.0.0.9.cab
      O16 - DPF: {bac761d3-dffd-4db4-a01d-173346e090a7} (CPlayFirstzenerchiControl Object) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--5bca0d7d-3ef6-4521-bd1b-5d981bd14ff1/online/zenerchi/fr/ZenerchiWeb.1.0.0.10.cab
      O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
      O16 - DPF: {d0c0f75c-683a-4390-a791-1acfd5599ab8} -
      O16 - DPF: {ea6246b4-f380-443f-8727-9aea3371146c} (CPlayFirstWeddingDashControl Object) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--d66a432b-38e7-468a-b329-33657f1af599/online/wedding_dash/fr/WeddingDash.1.0.0.47.cab
      O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
      O23 - Service: MySqlInventime - Unknown owner - c:\mysql\bin\mysqld-max-nt.exe
      O23 - Service: PC Tools AntiVirus Engine (pctavsvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
      O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
      0
  12. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    ok parfait encore des soucis????

    télécharge OTMoveIt
    http://oldtimer.geekstogo.com/OTMoveIt3.exe (de Old_Timer) sur ton Bureau.

    double-clique sur OTMoveIt.exe pour le lancer.
    copie la liste qui se trouve en citation ci-dessous,
    et colle-la dans le cadre de gauche de OTMoveIt :Paste instruction for items to be moved.
    (attention bien mettre :files)

    :files
    C:\Documents and Settings\ISABELLE\Application Data\gadcom\gadcom.exe

    clique sur MoveIt! pour lancer la suppression.
    le résultat apparaitra dans le cadre "Results".
    clique sur Exit pour fermer.
    poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

    il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

    ________________

    pour dernière vérification :

    colle le rapport d'un scan en ligne
    avec un des suivants:

    Kaspersky en ligne
    https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr

    Panda en ligne :
    http://pandasoftware.fr
    0
    1. mumu5938 Messages postés 31 Statut Membre
       
      ========== FILES ==========
      File/Folder C:\Documents and Settings\ISABELLE\Application Data\gadcom\gadcom.exe not found.

      OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 12082008_164438
      0
  13. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    ok fais le scan en ligne
    et dis moi si encore des soucis?
    0
    1. mumu5938 Messages postés 31 Statut Membre
       
      le scan en ligne est en train de se faire
      apparement plus de soucis
      merci encore pour ta patience !
      et pour spybot j'autorise ou refuse les modifications?
      et quels logiciels que tu m'as dis de télécharger puis je effacer
      merci
      0
  14. mumu5938
     
    Cookie/Xiti Cookie de surveillance Latent(e) Afficher +Infos
    1. C:\Documents and Settings\ISABELLE\Cookies\isabelle@xiti[1].txt

    Cookie/Serving... Cookie de surveillance Latent(e) Afficher +Infos
    1. C:\Documents and Settings\ISABELLE\Cookies\isabelle@bs.serving-sys[2].txt

    Cookie/Smartad... Cookie de surveillance Latent(e) Afficher +Infos
    1. C:\Documents and Settings\ISABELLE\Cookies\isabelle@smartadserver[1].txt

    Cookie/YieldMa... Cookie de surveillance Latent(e) Afficher +Infos
    1. C:\Documents and Settings\ISABELLE\Cookies\isabelle@ad.yieldmanager[1].txt

    Cookie/Serving... Cookie de surveillance Latent(e) Afficher +Infos
    1. C:\Documents and Settings\ISABELLE\Cookies\isabelle@serving-sys[1].txt

    Cookie/Weboram... Cookie de surveillance Latent(e) Afficher +Infos
    1. C:\Documents and Settings\ISABELLE\Cookies\isabelle@weborama[1].txt

    Cookie/RealMed... Cookie de surveillance Latent(e) Afficher +Infos
    1. C:\Documents and Settings\ISABELLE\Cookies\isabelle@247realmedia[1].txt

    Cookie/Atlas D... Cookie de surveillance Latent(e) Afficher +Infos
    1. C:\Documents and Settings\ISABELLE\Cookies\isabelle@atdmt[1].txt

    Cookie/Doublec... Cookie de surveillance Latent(e) Afficher +Infos
    0
  15. mumu5938
     
    [ Rapport ToolsCleaner version 2.2.6 (par A.Rothstein & dj QUIOU) ]

    -->- Recherche:

    C:\Documents and Settings\ISABELLE\Bureau\ComboFix.exe: trouvé !
    C:\Documents and Settings\ISABELLE\Bureau\HijackThis.exe: trouvé !

    ---------------------------------
    -->- Suppression:

    C:\Documents and Settings\ISABELLE\Bureau\ComboFix.exe: ERREUR DE SUPPRESSION !!
    C:\Documents and Settings\ISABELLE\Bureau\HijackThis.exe: ERREUR DE SUPPRESSION !!
    0
  16. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    si juste un dernier truc

    pour virer les virus qui seraient dans ta restauration : désactive la puis redemarre ton ordi puis réactive là

    https://www.informatruc.com

    bonne suite
    0
  17. mumu5938 Messages postés 31 Statut Membre
     
    parfait merci encore
    bonne soirée
    0
Précédent
  • 1
  • 2