Warning dangerous spyware
Résolu
mumu5938
Messages postés
31
Statut
Membre
-
mumu5938 Messages postés 31 Statut Membre -
mumu5938 Messages postés 31 Statut Membre -
Bonjour,
depuis quelques jours, au lieu de l'arrière plan de mon bureau, j'ai un écran noir avec le message: "warning dangerous spyware....", malgré mon anti virus pctools, spybot search&destroy et ccleaner, je n'arrive pas à m'en débarrasser.
que dois je faire merci d'avance
depuis quelques jours, au lieu de l'arrière plan de mon bureau, j'ai un écran noir avec le message: "warning dangerous spyware....", malgré mon anti virus pctools, spybot search&destroy et ccleaner, je n'arrive pas à m'en débarrasser.
que dois je faire merci d'avance
A voir également:
- Warning dangerous spyware
- Spyware doctor - Télécharger - Antivirus & Antimalwares
- Warning zone telechargement - Accueil - Outils
- Spyware terminator - Télécharger - Antivirus & Antimalwares
- Spyware blaster - Télécharger - Antivirus & Antimalwares
- Anti spyware gratuit - Télécharger - Antivirus & Antimalwares
36 réponses
Ferme tous tes navigateurs (donc copie ou imprime les instructions avant)
Crée un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :
Driver ::
spttseng32
File::
c:\windows\system32\spttseng32.dll
c:\windows\system32\spttseng32.dll,ozob
Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\spttseng32]
Enregistre ce fichier sous le nom CFscript
Fait un glisser/déposer de ce fichier CFscrïpt sur le fichier ComboFix.exe
Clique sur le fichier CFScript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFScript vienne recouvrir l'icône de Combofix. Relache la souris. Combofix va démarrer.
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
Remets aussi un rapport Hijackthis
Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
Crée un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :
Driver ::
spttseng32
File::
c:\windows\system32\spttseng32.dll
c:\windows\system32\spttseng32.dll,ozob
Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\spttseng32]
Enregistre ce fichier sous le nom CFscript
Fait un glisser/déposer de ce fichier CFscrïpt sur le fichier ComboFix.exe
Clique sur le fichier CFScript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFScript vienne recouvrir l'icône de Combofix. Relache la souris. Combofix va démarrer.
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
Remets aussi un rapport Hijackthis
Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
mumu5938
Messages postés
31
Statut
Membre
ok je fais çà merci
ComboFix 08-12-06.06 - ISABELLE 2008-12-08 14:56:19.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.196 [GMT 1:00]
LancÚ depuis: c:\documents and settings\ISABELLE\Bureau\ComboFix.exe
Commutateurs utilisÚs :: c:\documents and settings\ISABELLE\Bureau\CFscript.txt
* Un nouveau point de restauration a ÚtÚ crÚÚ
* Resident AV is active
FILE ::
c:\windows\system32\spttseng32.dll
c:\windows\system32\spttseng32.dll,ozob
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\actaegdg.ini
c:\windows\system32\hnlndukr.ini
c:\windows\system32\spttseng32.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SPTTSENG32
-------\Service_spttseng32
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-08 au 2008-12-08 ))))))))))))))))))))))))))))))))))))
.
2008-12-08 13:48 . 2008-12-08 13:48 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Malwarebytes
2008-12-08 13:47 . 2008-12-08 13:48 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-08 13:47 . 2008-12-08 13:47 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-08 13:47 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-08 13:47 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-08 11:58 . 2008-12-08 12:25 <REP> d-------- C:\ToolBar SD
2008-12-08 11:42 . 2008-12-08 11:42 <REP> d-------- C:\rsit
2008-12-08 11:42 . 2008-12-08 11:42 <REP> d-------- c:\program files\trend micro
2008-12-08 01:29 . 2008-12-08 01:29 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-07 13:35 . 2008-12-07 13:35 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PC Tools
2008-12-07 13:34 . 2008-12-08 13:12 <REP> d-------- c:\program files\PC Tools AntiVirus
2008-12-07 13:34 . 2007-12-06 16:51 28,568 --a------ c:\windows\system32\drivers\AVHook.sys
2008-12-07 13:34 . 2007-12-06 16:51 21,912 --a------ c:\windows\system32\drivers\AVRec.sys
2008-12-07 13:34 . 2008-02-12 11:44 21,904 --a------ c:\windows\system32\drivers\AVFilter.sys
2008-12-06 20:59 . 2008-12-06 21:02 <REP> d-------- c:\program files\CCleaner
2008-12-06 00:56 . 2008-12-06 00:56 <REP> d-------- c:\documents and settings\All Users\Application Data\TheRace_dev
2008-12-06 00:42 . 2008-12-06 00:42 <REP> d-------- c:\program files\Fichiers communs\SWF Studio
2008-12-05 23:28 . 2008-12-05 23:28 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\iWin
2008-12-05 23:28 . 2008-12-05 23:28 <REP> d-------- c:\documents and settings\All Users\Application Data\iWin
2008-12-05 22:42 . 2008-12-05 22:42 <REP> d-------- c:\documents and settings\All Users\Application Data\Gogii
2008-12-05 22:28 . 2008-12-05 22:28 <REP> d-------- c:\documents and settings\All Users\Application Data\Intenium
2008-12-04 23:49 . 2008-12-04 23:49 <REP> d-------- c:\documents and settings\LocalService\Application Data\PCToolsSpamMonitorPlus
2008-12-04 23:49 . 2008-12-04 23:49 <REP> d-------- c:\documents and settings\LocalService\Application Data\PCToolsFirewallPlus
2008-12-04 19:55 . 2008-12-04 19:55 <REP> d--h----- c:\windows\PIF
2008-12-03 04:12 . 2008-12-06 00:39 <REP> d-------- c:\documents and settings\All Users\Application Data\Playrix Entertainment
2008-12-02 12:44 . 2008-12-02 12:44 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PCToolsFirewallPlus
2008-12-02 12:43 . 2008-12-02 12:43 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PCToolsSpamMonitorPlus
2008-12-02 12:35 . 2008-12-07 13:34 <REP> d-------- c:\documents and settings\All Users\Application Data\PC Tools
2008-12-02 08:54 . 2008-12-02 08:54 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Twain
2008-12-01 23:27 . 2008-12-01 23:27 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Games
2008-12-01 23:12 . 2008-12-01 23:26 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\FarmerJane
2008-12-01 22:57 . 2008-12-01 22:57 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Gaijin Ent
2008-12-01 21:43 . 2008-12-01 21:43 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Valusoft
2008-12-01 21:43 . 2008-12-01 21:43 <REP> d-------- c:\documents and settings\All Users\Application Data\Valusoft
2008-12-01 20:56 . 2008-12-01 20:56 <REP> d-------- c:\documents and settings\All Users\Application Data\Arkadium
2008-12-01 20:00 . 2008-12-07 10:22 268 --a------ c:\windows\wininit.ini
2008-12-01 13:46 . 2008-12-08 11:29 461 --a------ c:\windows\system32\win32hlp.cnf
2008-12-01 10:28 . 2008-12-01 10:28 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\AlterLab
2008-12-01 09:06 . 2008-12-01 15:51 <REP> d-------- c:\program files\Spybot - Search & Destroy
2008-12-01 09:06 . 2008-12-08 10:29 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-28 20:48 . 2008-11-29 18:25 5 --a------ c:\windows\sbacknt.bin
2008-11-28 20:46 . 2008-11-29 19:24 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\vghd
2008-11-28 20:46 . 2008-11-28 20:46 152,904 --a------ c:\windows\system32\vghd.scr
2008-11-28 20:46 . 2008-12-02 08:43 4 --a------ c:\windows\system32\test.ttt
2008-11-28 19:30 . 2008-11-28 19:30 <REP> d-------- c:\documents and settings\All Users\Application Data\FreshGames
2008-11-28 16:47 . 2008-11-28 16:47 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Meridian93
2008-11-28 16:07 . 2008-11-30 17:43 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Shopping Blocks
2008-11-28 14:59 . 2008-11-28 15:05 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Ancient Quest of Saqqarah__gamehouse
2008-11-26 00:55 . 2008-11-28 19:30 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Zylom
2008-11-25 22:09 . 2008-11-25 22:09 <REP> d--hs---- c:\windows\ftpcache
2008-11-25 21:05 . 2008-11-25 21:05 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\SulusGames
2008-11-25 16:52 . 2008-11-26 13:45 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\funkitron
2008-11-25 16:51 . 2008-11-25 16:51 <REP> d-------- c:\program files\Slingo Quest
2008-11-25 14:35 . 2008-11-25 14:36 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PetShowCraze
2008-11-25 02:36 . 2008-11-25 02:36 <REP> d-------- c:\documents and settings\All Users\Application Data\QB9 S.R.L
2008-11-24 20:48 . 2008-11-24 20:48 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\cerasus
2008-11-24 17:24 . 2008-12-07 21:44 <REP> d---s---- c:\documents and settings\ISABELLE\UserData
2008-11-23 18:30 . 2008-11-23 18:30 <REP> d-------- c:\documents and settings\All Users\Application Data\FarmFrenzy2
2008-11-23 18:23 . 103,634 c:\windows\system32\drivers\30668e04.sys
2008-11-23 16:31 . 2008-11-23 16:31 <REP> d-------- c:\documents and settings\ISABELLE\Contacts
2008-11-22 22:56 . 2008-11-23 03:02 <REP> d--h----- c:\windows\$hf_mig$
2008-11-22 22:55 . 2008-11-22 22:55 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\AVG7
2008-11-22 22:54 . 2008-12-08 14:58 <REP> d-------- c:\windows\apppatch
2008-11-22 22:54 . 2008-11-22 22:54 <REP> d--h----- c:\documents and settings\ISABELLE\Voisinage d'impression
2008-11-22 22:54 . 2008-11-22 22:54 <REP> dr------- c:\documents and settings\ISABELLE\Menu Démarrer
2008-11-22 22:54 . 2008-11-22 22:54 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\You've Got Pictures Screensaver
2008-11-22 22:54 . 2008-11-22 22:54 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\DivX
2008-11-21 22:14 . 2008-11-21 22:14 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\LuckyTender
2008-11-21 20:15 . 2008-12-06 02:55 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\cerasus.media
2008-11-21 19:09 . 2008-12-06 00:18 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PlayFirst
2008-11-21 12:38 . 2008-11-21 12:39 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Magic Academy
2008-11-21 11:36 . 2008-12-07 13:27 <REP> d-------- c:\program files\Fichiers communs\PC Tools
2008-11-20 21:55 . 2008-11-20 21:55 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Flood Light Games
2008-11-20 20:33 . 2006-02-24 22:56 <REP> d--h----- c:\documents and settings\ISABELLE\Voisinage réseau
2008-11-20 20:33 . 2008-11-22 22:54 <REP> d--h----- c:\documents and settings\ISABELLE\Modèles
2008-11-20 20:33 . 2008-12-07 21:43 <REP> dr------- c:\documents and settings\ISABELLE\Mes documents
2008-11-20 20:33 . 2008-12-08 11:22 <REP> dr------- c:\documents and settings\ISABELLE\Favoris
2008-11-20 20:33 . 2008-12-08 14:56 <REP> dr------- c:\documents and settings\ISABELLE\Bureau
2008-11-20 20:33 . 2008-12-08 10:28 <REP> d-a------ c:\documents and settings\ISABELLE
2008-11-18 11:31 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2008-11-18 11:31 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
2008-11-18 11:31 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2008-11-17 22:26 . 2008-11-23 18:24 <REP> d-------- c:\program files\myBabylon_English
2008-11-17 14:36 . 2008-11-17 14:36 <REP> d--hsc--- c:\program files\Fichiers communs\WindowsLiveInstaller
2008-11-17 14:35 . 2008-11-17 14:36 <REP> d-------- c:\program files\Windows Live
2008-11-17 14:35 . 2008-11-17 14:35 <REP> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
2008-11-17 14:21 . 2008-10-24 12:21 455,296 --------- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-17 14:20 . 2008-09-04 18:16 1,106,944 --------- c:\windows\system32\dllcache\msxml3.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-08 13:54 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-08 09:58 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2008-12-07 22:43 6,384 ----a-w C:\GETDRIVE.EXE
2008-12-07 21:02 --------- d-----w c:\program files\Zylom Games
2008-12-07 20:52 --------- d-----w c:\program files\DivX
2008-12-06 20:01 --------- d-----w c:\program files\Yahoo!
2008-12-05 23:18 --------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst
2008-12-05 21:26 --------- d-----w c:\program files\eMule
2008-11-26 00:02 --------- d-----w c:\program files\LuckyTender
2008-11-25 23:26 --------- d-----w c:\documents and settings\All Users\Application Data\HipSoft
2008-11-23 15:22 --------- d-----w c:\program files\Google
2008-11-23 12:28 --------- d-----w c:\program files\Wanadoo
2008-11-23 01:01 --------- d-----w c:\documents and settings\All Users\Application Data\MysteryChronicles
2008-11-22 21:56 --------- d-----w c:\program files\Fichiers communs\Adobe
2008-11-22 21:55 --------- d-----w c:\program files\Cluedo
2008-11-22 21:55 --------- d-----w c:\documents and settings\All Users\Application Data\avg7
2008-11-20 19:18 --------- d-----w c:\program files\Packard Bell EverSafe
2008-11-04 21:34 --------- d-----w c:\documents and settings\All Users\Application Data\EscapeTheMuseum
2008-11-03 23:04 --------- d-----w c:\documents and settings\All Users\Application Data\Fugazo
2008-11-03 18:45 --------- d-----w c:\documents and settings\All Users\Application Data\MissTeriTale2
2008-11-03 15:13 --------- d-----w c:\documents and settings\All Users\Application Data\MythPeople
2008-10-30 16:11 --------- d-----w c:\documents and settings\All Users\Application Data\SpinTop Games
2008-10-30 04:19 --------- d-----w c:\documents and settings\All Users\Application Data\Oberon Media
2008-10-28 20:08 --------- d-----w c:\documents and settings\All Users\Application Data\n7-89-o9-3r-4t-r9
2008-10-27 09:05 --------- d-----w c:\documents and settings\All Users\Application Data\JollyBear
2008-10-27 06:42 --------- d-----w c:\documents and settings\All Users\Application Data\SugarGames
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-20 17:09 --------- d-----w c:\documents and settings\All Users\Application Data\Zylom
2008-10-20 13:42 --------- d-----w c:\documents and settings\All Users\Application Data\GameHouse
2008-10-19 08:38 --------- d-----w c:\program files\ReflexiveArcade
2008-10-19 06:15 --------- d-----w c:\program files\QuickTime
2008-10-18 06:26 --------- d-----w c:\documents and settings\All Users\Application Data\Flood Light Games
2008-10-18 05:59 --------- d-----w c:\program files\Share_Accelerator_MM
2008-10-18 05:59 --------- d-----w c:\program files\Conduit
2008-10-17 15:24 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-17 10:12 --------- d-----w c:\documents and settings\All Users\Application Data\FloodLightGames
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 07:06 --------- d-----w c:\documents and settings\All Users\Application Data\BOONTY
2008-10-16 04:58 --------- d-----w c:\program files\Java
2008-10-15 16:35 337,408 ------w c:\windows\system32\dllcache\netapi32.dll
2008-10-08 14:08 --------- d-----w c:\program files\Lx_cats
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
2008-09-15 15:26 1,846,528 ------w c:\windows\system32\dllcache\win32k.sys
2008-09-10 01:15 1,307,648 ------w c:\windows\system32\msxml6.dll
2008-09-10 01:15 1,307,648 ------w c:\windows\system32\dllcache\msxml6.dll
2008-09-08 10:41 333,824 ------w c:\windows\system32\dllcache\srv.sys
2006-02-24 20:37 3,308,767 ----a-w c:\program files\Shareaza_2.2.1.0.exe
2006-02-24 19:32 1,525,216 -c--a-w c:\program files\Antispam.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-02-03 68856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"WOOKIT"="c:\progra~1\Wanadoo\Shell.exe" [BU]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-10-19 413696]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-02-03 185632]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SpywareCleaner"="c:\windows\system32\SpywareRemover.exe" [BU]
"ISTray"="c:\program files\PC Tools Internet Security\pctsTray.exe" [BU]
"Microsoft WinUpdate"="c:\windows\system32\msupdte.exe" [BU]
"6425bd6f"="c:\windows\system32\gdgeatca.dll" [BU]
"Framework Windows"="frmwrk32.exe" [BU]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=ykaeuo.dll xsqhhr.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8767:TCP"= 8767:TCP:messenger
"8387:TCP"= 8387:TCP:messenger
"7313:TCP"= 7313:TCP:messenger
"6216:TCP"= 6216:TCP:messenger
"6358:TCP"= 6358:TCP:messenger
"5282:TCP"= 5282:TCP:messenger
"2311:TCP"= 2311:TCP:messenger
"2764:TCP"= 2764:TCP:messenger
"8147:TCP"= 8147:TCP:messenger
"7464:TCP"= 7464:TCP:messenger
"8138:TCP"= 8138:TCP:messenger
"4641:TCP"= 4641:TCP:messenger
"4246:TCP"= 4246:TCP:messenger
"5737:TCP"= 5737:TCP:messenger
"5852:TCP"= 5852:TCP:messenger
"4816:TCP"= 4816:TCP:messenger
"4455:TCP"= 4455:TCP:messenger
"4635:TCP"= 4635:TCP:messenger
"8451:TCP"= 8451:TCP:messenger
"5158:TCP"= 5158:TCP:messenger
"2455:TCP"= 2455:TCP:messenger
"1132:TCP"= 1132:TCP:messenger
"3456:TCP"= 3456:TCP:messenger
"5124:TCP"= 5124:TCP:messenger
"5684:TCP"= 5684:TCP:messenger
"7474:TCP"= 7474:TCP:messenger
"1616:TCP"= 1616:TCP:messenger
"7522:TCP"= 7522:TCP:messenger
R1 Asapi;Asapi;c:\windows\system32\drivers\Asapi.sys [2004-11-01 11264]
R2 MTC0005_MTCDIO;Wireless HotKey Driver;c:\windows\system32\drivers\MTCDIO.sys [2004-11-01 11316]
R2 NwSapAgent;Agent SAP;c:\windows\System32\svchost.exe -k netsvcs [2002-09-30 14336]
R3 EMCR;EMCR;c:\windows\system32\DRIVERS\EMCR7SK.sys [1980-01-01 68224]
S1 aswSP;avast! Self Protection; []
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys []
S2 MTCDIO;MTCDIO;c:\windows\system32\DRIVERS\MTCDIO.sys [2004-11-01 11316]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;c:\windows\system32\DRIVERS\fbxusb32.sys [2006-08-21 21344]
S3 PhTVTune;Cap7134 TVTuner;c:\windows\system32\DRIVERS\PhTVTune.sys [2004-06-15 42080]
.
Contenu du dossier 'Tâches planifiées'
2008-10-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 12:42]
2006-02-24 c:\windows\Tasks\Rappel d'enregistrement 3.job
- c:\windows\System32\OOBE\oobebaln.exe [2008-04-14 03:34]
.
- - - - ORPHELINS SUPPRIMES - - - -
Toolbar-{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - (no file)
WebBrowser-{B2E293EE-FD7E-4C71-A714-5F4750D8D7B7} - (no file)
Notify-spttseng32 - spttseng32.dll
.
------- Examen supplémentaire -------
.
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.orange.fr/
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://lo.st
mWindow Title =
uInternet Connection Wizard,ShellNext = hxxp://celaia.daxon.fr/vente-en-ligne/panier/panier.aspx
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
LSP: c:\program files\Fichiers communs\PC Tools\Lsp\PCTLsp.dll
O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd
O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
c:\windows\Downloaded Program Files\CookingDashWeb.1.0.0.9.dll - O16 -: {195B4BBF-E1E4-4020-9773-0A8C6F65EA35}
hxxp://webgames.d.tmsrv.com/c=57c218bb5298e374b3c5e9f078cabd4f/aff=t_25oa_frca_wg/p/release/playfirst/wg_cookingdash/cookingdash/CookingDashWeb.1.0.0.9.cab
c:\windows\Downloaded Program Files\CookingDashWeb.1.0.0.9.inf
c:\windows\Downloaded Program Files\zenerchi.1.0.0.10.dll - O16 -: {bac761d3-dffd-4db4-a01d-173346e090a7}
hxxp://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--5bca0d7d-3ef6-4521-bd1b-5d981bd14ff1/online/zenerchi/fr/ZenerchiWeb.1.0.0.10.cab
c:\windows\Downloaded Program Files\zenerchi.1.0.0.10.inf
c:\windows\Downloaded Program Files\OberonGameHost.dll - O16 -: {D0C0F75C-683A-4390-A791-1ACFD5599AB8}
hxxp://jeuxenligne.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
c:\windows\Downloaded Program Files\OberonGameHost_dbg.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-08 15:02:06
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySqlInventime]
"ImagePath"="c:\mysql\bin\mysqld-max-nt MySqlInventime"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\30668e04]
"ImagePath"="\SystemRoot\System32\drivers\30668e04.sys"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(896)
c:\program files\PC Tools AntiVirus\PCTAVHook.dll
- - - - - - - > 'lsass.exe'(952)
c:\program files\Fichiers communs\PC Tools\Lsp\PCTLsp.dll
c:\program files\PC Tools AntiVirus\PCTAVHook.dll
- - - - - - - > 'csrss.exe'(872)
c:\program files\PC Tools AntiVirus\PCTAVHook.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\progra~1\FICHIE~1\AOL\ACS\AOLacsd.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\PC Tools AntiVirus\PCTAVSvc.exe
.
**************************************************************************
.
Heure de fin: 2008-12-08 15:05:12 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-12-08 14:05:07
Avant-CF: 24 203 284 480 octets libres
Après-CF: 24,212,541,440 octets libres
328 --- E O F --- 2008-11-24 09:41:45
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.196 [GMT 1:00]
LancÚ depuis: c:\documents and settings\ISABELLE\Bureau\ComboFix.exe
Commutateurs utilisÚs :: c:\documents and settings\ISABELLE\Bureau\CFscript.txt
* Un nouveau point de restauration a ÚtÚ crÚÚ
* Resident AV is active
FILE ::
c:\windows\system32\spttseng32.dll
c:\windows\system32\spttseng32.dll,ozob
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\actaegdg.ini
c:\windows\system32\hnlndukr.ini
c:\windows\system32\spttseng32.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SPTTSENG32
-------\Service_spttseng32
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-08 au 2008-12-08 ))))))))))))))))))))))))))))))))))))
.
2008-12-08 13:48 . 2008-12-08 13:48 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Malwarebytes
2008-12-08 13:47 . 2008-12-08 13:48 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-08 13:47 . 2008-12-08 13:47 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-08 13:47 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-08 13:47 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-08 11:58 . 2008-12-08 12:25 <REP> d-------- C:\ToolBar SD
2008-12-08 11:42 . 2008-12-08 11:42 <REP> d-------- C:\rsit
2008-12-08 11:42 . 2008-12-08 11:42 <REP> d-------- c:\program files\trend micro
2008-12-08 01:29 . 2008-12-08 01:29 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-07 13:35 . 2008-12-07 13:35 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PC Tools
2008-12-07 13:34 . 2008-12-08 13:12 <REP> d-------- c:\program files\PC Tools AntiVirus
2008-12-07 13:34 . 2007-12-06 16:51 28,568 --a------ c:\windows\system32\drivers\AVHook.sys
2008-12-07 13:34 . 2007-12-06 16:51 21,912 --a------ c:\windows\system32\drivers\AVRec.sys
2008-12-07 13:34 . 2008-02-12 11:44 21,904 --a------ c:\windows\system32\drivers\AVFilter.sys
2008-12-06 20:59 . 2008-12-06 21:02 <REP> d-------- c:\program files\CCleaner
2008-12-06 00:56 . 2008-12-06 00:56 <REP> d-------- c:\documents and settings\All Users\Application Data\TheRace_dev
2008-12-06 00:42 . 2008-12-06 00:42 <REP> d-------- c:\program files\Fichiers communs\SWF Studio
2008-12-05 23:28 . 2008-12-05 23:28 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\iWin
2008-12-05 23:28 . 2008-12-05 23:28 <REP> d-------- c:\documents and settings\All Users\Application Data\iWin
2008-12-05 22:42 . 2008-12-05 22:42 <REP> d-------- c:\documents and settings\All Users\Application Data\Gogii
2008-12-05 22:28 . 2008-12-05 22:28 <REP> d-------- c:\documents and settings\All Users\Application Data\Intenium
2008-12-04 23:49 . 2008-12-04 23:49 <REP> d-------- c:\documents and settings\LocalService\Application Data\PCToolsSpamMonitorPlus
2008-12-04 23:49 . 2008-12-04 23:49 <REP> d-------- c:\documents and settings\LocalService\Application Data\PCToolsFirewallPlus
2008-12-04 19:55 . 2008-12-04 19:55 <REP> d--h----- c:\windows\PIF
2008-12-03 04:12 . 2008-12-06 00:39 <REP> d-------- c:\documents and settings\All Users\Application Data\Playrix Entertainment
2008-12-02 12:44 . 2008-12-02 12:44 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PCToolsFirewallPlus
2008-12-02 12:43 . 2008-12-02 12:43 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PCToolsSpamMonitorPlus
2008-12-02 12:35 . 2008-12-07 13:34 <REP> d-------- c:\documents and settings\All Users\Application Data\PC Tools
2008-12-02 08:54 . 2008-12-02 08:54 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Twain
2008-12-01 23:27 . 2008-12-01 23:27 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Games
2008-12-01 23:12 . 2008-12-01 23:26 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\FarmerJane
2008-12-01 22:57 . 2008-12-01 22:57 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Gaijin Ent
2008-12-01 21:43 . 2008-12-01 21:43 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Valusoft
2008-12-01 21:43 . 2008-12-01 21:43 <REP> d-------- c:\documents and settings\All Users\Application Data\Valusoft
2008-12-01 20:56 . 2008-12-01 20:56 <REP> d-------- c:\documents and settings\All Users\Application Data\Arkadium
2008-12-01 20:00 . 2008-12-07 10:22 268 --a------ c:\windows\wininit.ini
2008-12-01 13:46 . 2008-12-08 11:29 461 --a------ c:\windows\system32\win32hlp.cnf
2008-12-01 10:28 . 2008-12-01 10:28 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\AlterLab
2008-12-01 09:06 . 2008-12-01 15:51 <REP> d-------- c:\program files\Spybot - Search & Destroy
2008-12-01 09:06 . 2008-12-08 10:29 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-28 20:48 . 2008-11-29 18:25 5 --a------ c:\windows\sbacknt.bin
2008-11-28 20:46 . 2008-11-29 19:24 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\vghd
2008-11-28 20:46 . 2008-11-28 20:46 152,904 --a------ c:\windows\system32\vghd.scr
2008-11-28 20:46 . 2008-12-02 08:43 4 --a------ c:\windows\system32\test.ttt
2008-11-28 19:30 . 2008-11-28 19:30 <REP> d-------- c:\documents and settings\All Users\Application Data\FreshGames
2008-11-28 16:47 . 2008-11-28 16:47 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Meridian93
2008-11-28 16:07 . 2008-11-30 17:43 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Shopping Blocks
2008-11-28 14:59 . 2008-11-28 15:05 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Ancient Quest of Saqqarah__gamehouse
2008-11-26 00:55 . 2008-11-28 19:30 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Zylom
2008-11-25 22:09 . 2008-11-25 22:09 <REP> d--hs---- c:\windows\ftpcache
2008-11-25 21:05 . 2008-11-25 21:05 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\SulusGames
2008-11-25 16:52 . 2008-11-26 13:45 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\funkitron
2008-11-25 16:51 . 2008-11-25 16:51 <REP> d-------- c:\program files\Slingo Quest
2008-11-25 14:35 . 2008-11-25 14:36 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PetShowCraze
2008-11-25 02:36 . 2008-11-25 02:36 <REP> d-------- c:\documents and settings\All Users\Application Data\QB9 S.R.L
2008-11-24 20:48 . 2008-11-24 20:48 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\cerasus
2008-11-24 17:24 . 2008-12-07 21:44 <REP> d---s---- c:\documents and settings\ISABELLE\UserData
2008-11-23 18:30 . 2008-11-23 18:30 <REP> d-------- c:\documents and settings\All Users\Application Data\FarmFrenzy2
2008-11-23 18:23 . 103,634 c:\windows\system32\drivers\30668e04.sys
2008-11-23 16:31 . 2008-11-23 16:31 <REP> d-------- c:\documents and settings\ISABELLE\Contacts
2008-11-22 22:56 . 2008-11-23 03:02 <REP> d--h----- c:\windows\$hf_mig$
2008-11-22 22:55 . 2008-11-22 22:55 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\AVG7
2008-11-22 22:54 . 2008-12-08 14:58 <REP> d-------- c:\windows\apppatch
2008-11-22 22:54 . 2008-11-22 22:54 <REP> d--h----- c:\documents and settings\ISABELLE\Voisinage d'impression
2008-11-22 22:54 . 2008-11-22 22:54 <REP> dr------- c:\documents and settings\ISABELLE\Menu Démarrer
2008-11-22 22:54 . 2008-11-22 22:54 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\You've Got Pictures Screensaver
2008-11-22 22:54 . 2008-11-22 22:54 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\DivX
2008-11-21 22:14 . 2008-11-21 22:14 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\LuckyTender
2008-11-21 20:15 . 2008-12-06 02:55 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\cerasus.media
2008-11-21 19:09 . 2008-12-06 00:18 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PlayFirst
2008-11-21 12:38 . 2008-11-21 12:39 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Magic Academy
2008-11-21 11:36 . 2008-12-07 13:27 <REP> d-------- c:\program files\Fichiers communs\PC Tools
2008-11-20 21:55 . 2008-11-20 21:55 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Flood Light Games
2008-11-20 20:33 . 2006-02-24 22:56 <REP> d--h----- c:\documents and settings\ISABELLE\Voisinage réseau
2008-11-20 20:33 . 2008-11-22 22:54 <REP> d--h----- c:\documents and settings\ISABELLE\Modèles
2008-11-20 20:33 . 2008-12-07 21:43 <REP> dr------- c:\documents and settings\ISABELLE\Mes documents
2008-11-20 20:33 . 2008-12-08 11:22 <REP> dr------- c:\documents and settings\ISABELLE\Favoris
2008-11-20 20:33 . 2008-12-08 14:56 <REP> dr------- c:\documents and settings\ISABELLE\Bureau
2008-11-20 20:33 . 2008-12-08 10:28 <REP> d-a------ c:\documents and settings\ISABELLE
2008-11-18 11:31 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2008-11-18 11:31 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
2008-11-18 11:31 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2008-11-17 22:26 . 2008-11-23 18:24 <REP> d-------- c:\program files\myBabylon_English
2008-11-17 14:36 . 2008-11-17 14:36 <REP> d--hsc--- c:\program files\Fichiers communs\WindowsLiveInstaller
2008-11-17 14:35 . 2008-11-17 14:36 <REP> d-------- c:\program files\Windows Live
2008-11-17 14:35 . 2008-11-17 14:35 <REP> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
2008-11-17 14:21 . 2008-10-24 12:21 455,296 --------- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-17 14:20 . 2008-09-04 18:16 1,106,944 --------- c:\windows\system32\dllcache\msxml3.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-08 13:54 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-08 09:58 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2008-12-07 22:43 6,384 ----a-w C:\GETDRIVE.EXE
2008-12-07 21:02 --------- d-----w c:\program files\Zylom Games
2008-12-07 20:52 --------- d-----w c:\program files\DivX
2008-12-06 20:01 --------- d-----w c:\program files\Yahoo!
2008-12-05 23:18 --------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst
2008-12-05 21:26 --------- d-----w c:\program files\eMule
2008-11-26 00:02 --------- d-----w c:\program files\LuckyTender
2008-11-25 23:26 --------- d-----w c:\documents and settings\All Users\Application Data\HipSoft
2008-11-23 15:22 --------- d-----w c:\program files\Google
2008-11-23 12:28 --------- d-----w c:\program files\Wanadoo
2008-11-23 01:01 --------- d-----w c:\documents and settings\All Users\Application Data\MysteryChronicles
2008-11-22 21:56 --------- d-----w c:\program files\Fichiers communs\Adobe
2008-11-22 21:55 --------- d-----w c:\program files\Cluedo
2008-11-22 21:55 --------- d-----w c:\documents and settings\All Users\Application Data\avg7
2008-11-20 19:18 --------- d-----w c:\program files\Packard Bell EverSafe
2008-11-04 21:34 --------- d-----w c:\documents and settings\All Users\Application Data\EscapeTheMuseum
2008-11-03 23:04 --------- d-----w c:\documents and settings\All Users\Application Data\Fugazo
2008-11-03 18:45 --------- d-----w c:\documents and settings\All Users\Application Data\MissTeriTale2
2008-11-03 15:13 --------- d-----w c:\documents and settings\All Users\Application Data\MythPeople
2008-10-30 16:11 --------- d-----w c:\documents and settings\All Users\Application Data\SpinTop Games
2008-10-30 04:19 --------- d-----w c:\documents and settings\All Users\Application Data\Oberon Media
2008-10-28 20:08 --------- d-----w c:\documents and settings\All Users\Application Data\n7-89-o9-3r-4t-r9
2008-10-27 09:05 --------- d-----w c:\documents and settings\All Users\Application Data\JollyBear
2008-10-27 06:42 --------- d-----w c:\documents and settings\All Users\Application Data\SugarGames
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-20 17:09 --------- d-----w c:\documents and settings\All Users\Application Data\Zylom
2008-10-20 13:42 --------- d-----w c:\documents and settings\All Users\Application Data\GameHouse
2008-10-19 08:38 --------- d-----w c:\program files\ReflexiveArcade
2008-10-19 06:15 --------- d-----w c:\program files\QuickTime
2008-10-18 06:26 --------- d-----w c:\documents and settings\All Users\Application Data\Flood Light Games
2008-10-18 05:59 --------- d-----w c:\program files\Share_Accelerator_MM
2008-10-18 05:59 --------- d-----w c:\program files\Conduit
2008-10-17 15:24 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-17 10:12 --------- d-----w c:\documents and settings\All Users\Application Data\FloodLightGames
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 07:06 --------- d-----w c:\documents and settings\All Users\Application Data\BOONTY
2008-10-16 04:58 --------- d-----w c:\program files\Java
2008-10-15 16:35 337,408 ------w c:\windows\system32\dllcache\netapi32.dll
2008-10-08 14:08 --------- d-----w c:\program files\Lx_cats
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
2008-09-15 15:26 1,846,528 ------w c:\windows\system32\dllcache\win32k.sys
2008-09-10 01:15 1,307,648 ------w c:\windows\system32\msxml6.dll
2008-09-10 01:15 1,307,648 ------w c:\windows\system32\dllcache\msxml6.dll
2008-09-08 10:41 333,824 ------w c:\windows\system32\dllcache\srv.sys
2006-02-24 20:37 3,308,767 ----a-w c:\program files\Shareaza_2.2.1.0.exe
2006-02-24 19:32 1,525,216 -c--a-w c:\program files\Antispam.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-02-03 68856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"WOOKIT"="c:\progra~1\Wanadoo\Shell.exe" [BU]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-10-19 413696]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-02-03 185632]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"SpywareCleaner"="c:\windows\system32\SpywareRemover.exe" [BU]
"ISTray"="c:\program files\PC Tools Internet Security\pctsTray.exe" [BU]
"Microsoft WinUpdate"="c:\windows\system32\msupdte.exe" [BU]
"6425bd6f"="c:\windows\system32\gdgeatca.dll" [BU]
"Framework Windows"="frmwrk32.exe" [BU]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=ykaeuo.dll xsqhhr.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8767:TCP"= 8767:TCP:messenger
"8387:TCP"= 8387:TCP:messenger
"7313:TCP"= 7313:TCP:messenger
"6216:TCP"= 6216:TCP:messenger
"6358:TCP"= 6358:TCP:messenger
"5282:TCP"= 5282:TCP:messenger
"2311:TCP"= 2311:TCP:messenger
"2764:TCP"= 2764:TCP:messenger
"8147:TCP"= 8147:TCP:messenger
"7464:TCP"= 7464:TCP:messenger
"8138:TCP"= 8138:TCP:messenger
"4641:TCP"= 4641:TCP:messenger
"4246:TCP"= 4246:TCP:messenger
"5737:TCP"= 5737:TCP:messenger
"5852:TCP"= 5852:TCP:messenger
"4816:TCP"= 4816:TCP:messenger
"4455:TCP"= 4455:TCP:messenger
"4635:TCP"= 4635:TCP:messenger
"8451:TCP"= 8451:TCP:messenger
"5158:TCP"= 5158:TCP:messenger
"2455:TCP"= 2455:TCP:messenger
"1132:TCP"= 1132:TCP:messenger
"3456:TCP"= 3456:TCP:messenger
"5124:TCP"= 5124:TCP:messenger
"5684:TCP"= 5684:TCP:messenger
"7474:TCP"= 7474:TCP:messenger
"1616:TCP"= 1616:TCP:messenger
"7522:TCP"= 7522:TCP:messenger
R1 Asapi;Asapi;c:\windows\system32\drivers\Asapi.sys [2004-11-01 11264]
R2 MTC0005_MTCDIO;Wireless HotKey Driver;c:\windows\system32\drivers\MTCDIO.sys [2004-11-01 11316]
R2 NwSapAgent;Agent SAP;c:\windows\System32\svchost.exe -k netsvcs [2002-09-30 14336]
R3 EMCR;EMCR;c:\windows\system32\DRIVERS\EMCR7SK.sys [1980-01-01 68224]
S1 aswSP;avast! Self Protection; []
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys []
S2 MTCDIO;MTCDIO;c:\windows\system32\DRIVERS\MTCDIO.sys [2004-11-01 11316]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;c:\windows\system32\DRIVERS\fbxusb32.sys [2006-08-21 21344]
S3 PhTVTune;Cap7134 TVTuner;c:\windows\system32\DRIVERS\PhTVTune.sys [2004-06-15 42080]
.
Contenu du dossier 'Tâches planifiées'
2008-10-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 12:42]
2006-02-24 c:\windows\Tasks\Rappel d'enregistrement 3.job
- c:\windows\System32\OOBE\oobebaln.exe [2008-04-14 03:34]
.
- - - - ORPHELINS SUPPRIMES - - - -
Toolbar-{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - (no file)
WebBrowser-{B2E293EE-FD7E-4C71-A714-5F4750D8D7B7} - (no file)
Notify-spttseng32 - spttseng32.dll
.
------- Examen supplémentaire -------
.
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.orange.fr/
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://lo.st
mWindow Title =
uInternet Connection Wizard,ShellNext = hxxp://celaia.daxon.fr/vente-en-ligne/panier/panier.aspx
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
LSP: c:\program files\Fichiers communs\PC Tools\Lsp\PCTLsp.dll
O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd
O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
c:\windows\Downloaded Program Files\CookingDashWeb.1.0.0.9.dll - O16 -: {195B4BBF-E1E4-4020-9773-0A8C6F65EA35}
hxxp://webgames.d.tmsrv.com/c=57c218bb5298e374b3c5e9f078cabd4f/aff=t_25oa_frca_wg/p/release/playfirst/wg_cookingdash/cookingdash/CookingDashWeb.1.0.0.9.cab
c:\windows\Downloaded Program Files\CookingDashWeb.1.0.0.9.inf
c:\windows\Downloaded Program Files\zenerchi.1.0.0.10.dll - O16 -: {bac761d3-dffd-4db4-a01d-173346e090a7}
hxxp://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--5bca0d7d-3ef6-4521-bd1b-5d981bd14ff1/online/zenerchi/fr/ZenerchiWeb.1.0.0.10.cab
c:\windows\Downloaded Program Files\zenerchi.1.0.0.10.inf
c:\windows\Downloaded Program Files\OberonGameHost.dll - O16 -: {D0C0F75C-683A-4390-A791-1ACFD5599AB8}
hxxp://jeuxenligne.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
c:\windows\Downloaded Program Files\OberonGameHost_dbg.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-08 15:02:06
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySqlInventime]
"ImagePath"="c:\mysql\bin\mysqld-max-nt MySqlInventime"
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\30668e04]
"ImagePath"="\SystemRoot\System32\drivers\30668e04.sys"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(896)
c:\program files\PC Tools AntiVirus\PCTAVHook.dll
- - - - - - - > 'lsass.exe'(952)
c:\program files\Fichiers communs\PC Tools\Lsp\PCTLsp.dll
c:\program files\PC Tools AntiVirus\PCTAVHook.dll
- - - - - - - > 'csrss.exe'(872)
c:\program files\PC Tools AntiVirus\PCTAVHook.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\progra~1\FICHIE~1\AOL\ACS\AOLacsd.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\PC Tools AntiVirus\PCTAVSvc.exe
.
**************************************************************************
.
Heure de fin: 2008-12-08 15:05:12 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-12-08 14:05:07
Avant-CF: 24 203 284 480 octets libres
Après-CF: 24,212,541,440 octets libres
328 --- E O F --- 2008-11-24 09:41:45
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
comme en 2
Télécharge ici :
http://images.malwareremoval.com/random/RSIT.exe
random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.
Double-clique sur RSIT.exe afin de lancer RSIT.
Clique Continue à l'écran Disclaimer.
Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.
Poste le contenu de log.txt (<<qui sera affiché)
ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).
NB : Les rapports sont sauvegardés dans le dossier C:\rsit
Télécharge ici :
http://images.malwareremoval.com/random/RSIT.exe
random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.
Double-clique sur RSIT.exe afin de lancer RSIT.
Clique Continue à l'écran Disclaimer.
Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.
Poste le contenu de log.txt (<<qui sera affiché)
ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).
NB : Les rapports sont sauvegardés dans le dossier C:\rsit
Logfile of random's system information tool 1.04 (written by random/random)
Run by ISABELLE at 2008-12-08 15:20:41
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 23 GB (43%) free of 53 GB
Total RAM: 511 MB (40% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:20:50, on 08/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\ISABELLE\Bureau\RSIT.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\trend micro\ISABELLE.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://lo.st
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.balsamik.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - software - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
O3 - Toolbar: (no name) - {4596013b-6c31-408b-a266-deae5c086dc2} - (no file)
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: (no name) - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - (no file)
O3 - Toolbar: (no name) - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SpywareCleaner] C:\WINDOWS\system32\SpywareRemover.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\PC Tools Internet Security\pctsTray.exe"
O4 - HKLM\..\Run: [Microsoft WinUpdate] C:\WINDOWS\system32\msupdte.exe
O4 - HKLM\..\Run: [Framework Windows] frmwrk32.exe
O4 - HKLM\..\Run: [6425bd6f] rundll32.exe "C:\WINDOWS\system32\gdgeatca.dll",b
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKCU\..\Run: [gadcom] "C:\Documents and Settings\ISABELLE\Application Data\gadcom\gadcom.exe" 61A847B5BBF72810339E3F466188719AB689201522886B092CBD44BD8689220221DD3257
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - software - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {195B4BBF-E1E4-4020-9773-0A8C6F65EA35} (CPlayFirstCookingDasControl Object) - http://webgames.d.tmsrv.com/c=57c218bb5298e374b3c5e9f078cabd4f/aff=t_25oa_frca_wg/p/release/playfirst/wg_cookingdash/cookingdash/CookingDashWeb.1.0.0.9.cab
O16 - DPF: {bac761d3-dffd-4db4-a01d-173346e090a7} (CPlayFirstzenerchiControl Object) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--5bca0d7d-3ef6-4521-bd1b-5d981bd14ff1/online/zenerchi/fr/ZenerchiWeb.1.0.0.10.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxenligne.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
O16 - DPF: {ea6246b4-f380-443f-8727-9aea3371146c} (CPlayFirstWeddingDashControl Object) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--d66a432b-38e7-468a-b329-33657f1af599/online/wedding_dash/fr/WeddingDash.1.0.0.47.cab
O20 - AppInit_DLLs: ykaeuo.dll xsqhhr.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: MySqlInventime - Unknown owner - c:\mysql\bin\mysqld-max-nt.exe
O23 - Service: PC Tools AntiVirus Engine (pctavsvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
Run by ISABELLE at 2008-12-08 15:20:41
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 23 GB (43%) free of 53 GB
Total RAM: 511 MB (40% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:20:50, on 08/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\ISABELLE\Bureau\RSIT.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\trend micro\ISABELLE.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = file://C:\APPS\IE\offline\fr.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://lo.st
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.balsamik.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - software - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
O3 - Toolbar: (no name) - {4596013b-6c31-408b-a266-deae5c086dc2} - (no file)
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: (no name) - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - (no file)
O3 - Toolbar: (no name) - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SpywareCleaner] C:\WINDOWS\system32\SpywareRemover.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\PC Tools Internet Security\pctsTray.exe"
O4 - HKLM\..\Run: [Microsoft WinUpdate] C:\WINDOWS\system32\msupdte.exe
O4 - HKLM\..\Run: [Framework Windows] frmwrk32.exe
O4 - HKLM\..\Run: [6425bd6f] rundll32.exe "C:\WINDOWS\system32\gdgeatca.dll",b
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKCU\..\Run: [gadcom] "C:\Documents and Settings\ISABELLE\Application Data\gadcom\gadcom.exe" 61A847B5BBF72810339E3F466188719AB689201522886B092CBD44BD8689220221DD3257
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - software - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {195B4BBF-E1E4-4020-9773-0A8C6F65EA35} (CPlayFirstCookingDasControl Object) - http://webgames.d.tmsrv.com/c=57c218bb5298e374b3c5e9f078cabd4f/aff=t_25oa_frca_wg/p/release/playfirst/wg_cookingdash/cookingdash/CookingDashWeb.1.0.0.9.cab
O16 - DPF: {bac761d3-dffd-4db4-a01d-173346e090a7} (CPlayFirstzenerchiControl Object) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--5bca0d7d-3ef6-4521-bd1b-5d981bd14ff1/online/zenerchi/fr/ZenerchiWeb.1.0.0.10.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxenligne.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
O16 - DPF: {ea6246b4-f380-443f-8727-9aea3371146c} (CPlayFirstWeddingDashControl Object) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--d66a432b-38e7-468a-b329-33657f1af599/online/wedding_dash/fr/WeddingDash.1.0.0.47.cab
O20 - AppInit_DLLs: ykaeuo.dll xsqhhr.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: MySqlInventime - Unknown owner - c:\mysql\bin\mysqld-max-nt.exe
O23 - Service: PC Tools AntiVirus Engine (pctavsvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
analyse ces 4 fichiers sur virus total et colle moi les rapports: https://www.virustotal.com/gui/
c:\windows\system32\SpywareRemover.exe
c:\windows\system32\gdgeatca.dll
C:\WINDOWS\system32\frmwrk32.exe
c:\windows\system32\msupdte.exe
________________
je me mets ceci de coté
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpywareCleaner"=-
"Microsoft WinUpdate"=-
"6425bd6f"=-
"Framework Windows"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=-
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://lo.st
O2 - BHO: (no name) - software - (no file)
O3 - Toolbar: (no name) - {4596013b-6c31-408b-a266-deae5c086dc2} - (no file)
O3 - Toolbar: (no name) - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - (no file)
O3 - Toolbar: (no name) - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SpywareCleaner] C:\WINDOWS\system32\SpywareRemover.exe
O4 - HKLM\..\Run: [Microsoft WinUpdate] C:\WINDOWS\system32\msupdte.exe
O4 - HKLM\..\Run: [Framework Windows] frmwrk32.exe
O4 - HKLM\..\Run: [6425bd6f] rundll32.exe "C:\WINDOWS\system32\gdgeatca.dll",b
O4 - HKCU\..\Run: [gadcom] "C:\Documents and Settings\ISABELLE\Application Data\gadcom\gadcom.exe" 61A847B5BBF72810339E3F466188719AB689201522886B092CBD44BD8689220221DD3257
O9 - Extra button: (no name) - software - (no file)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxenligne.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
O20 - AppInit_DLLs: ykaeuo.dll xsqhhr.dll
c:\windows\system32\SpywareRemover.exe
c:\windows\system32\gdgeatca.dll
C:\WINDOWS\system32\frmwrk32.exe
c:\windows\system32\msupdte.exe
________________
je me mets ceci de coté
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpywareCleaner"=-
"Microsoft WinUpdate"=-
"6425bd6f"=-
"Framework Windows"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=-
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://lo.st
O2 - BHO: (no name) - software - (no file)
O3 - Toolbar: (no name) - {4596013b-6c31-408b-a266-deae5c086dc2} - (no file)
O3 - Toolbar: (no name) - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - (no file)
O3 - Toolbar: (no name) - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SpywareCleaner] C:\WINDOWS\system32\SpywareRemover.exe
O4 - HKLM\..\Run: [Microsoft WinUpdate] C:\WINDOWS\system32\msupdte.exe
O4 - HKLM\..\Run: [Framework Windows] frmwrk32.exe
O4 - HKLM\..\Run: [6425bd6f] rundll32.exe "C:\WINDOWS\system32\gdgeatca.dll",b
O4 - HKCU\..\Run: [gadcom] "C:\Documents and Settings\ISABELLE\Application Data\gadcom\gadcom.exe" 61A847B5BBF72810339E3F466188719AB689201522886B092CBD44BD8689220221DD3257
O9 - Extra button: (no name) - software - (no file)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxenligne.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
O20 - AppInit_DLLs: ykaeuo.dll xsqhhr.dll
ok o size c'est donc bien une cochonnerie!
_____________
Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked".
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://lo.st
O2 - BHO: (no name) - software - (no file)
O3 - Toolbar: (no name) - {4596013b-6c31-408b-a266-deae5c086dc2} - (no file)
O3 - Toolbar: (no name) - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - (no file)
O3 - Toolbar: (no name) - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SpywareCleaner] C:\WINDOWS\system32\SpywareRemover.exe
O4 - HKLM\..\Run: [Microsoft WinUpdate] C:\WINDOWS\system32\msupdte.exe
O4 - HKLM\..\Run: [Framework Windows] frmwrk32.exe
O4 - HKLM\..\Run: [6425bd6f] rundll32.exe "C:\WINDOWS\system32\gdgeatca.dll",b
O4 - HKCU\..\Run: [gadcom] "C:\Documents and Settings\ISABELLE\Application Data\gadcom\gadcom.exe" 61A847B5BBF72810339E3F466188719AB689201522886B092CBD44BD8689220221DD3257
O9 - Extra button: (no name) - software - (no file)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxenligne.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
O20 - AppInit_DLLs: ykaeuo.dll xsqhhr.dll
__________________
Ferme tous tes navigateurs (donc copie ou imprime les instructions avant)
Crée un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :
File::
c:\windows\system32\SpywareRemover.exe
c:\windows\system32\gdgeatca.dll
C:\WINDOWS\system32\frmwrk32.exe
c:\windows\system32\msupdte.exe
c:\windows\Downloaded Program Files\OberonGameHost.dll
c:\windows\Downloaded Program Files\OberonGameHost_dbg.inf
C:\Documents and Settings\ISABELLE\Application Data\gadcom\gadcom.exe
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpywareCleaner"=-
"Microsoft WinUpdate"=-
"6425bd6f"=-
"Framework Windows"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=-
Enregistre ce fichier sous le nom CFscript
Fait un glisser/déposer de ce fichier CFscrïpt sur le fichier ComboFix.exe
Clique sur le fichier CFScript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFScript vienne recouvrir l'icône de Combofix. Relache la souris. Combofix va démarrer.
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
Remets aussi un rapport Hijackthis ou RSIT
Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
_____________
Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked".
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://lo.st
O2 - BHO: (no name) - software - (no file)
O3 - Toolbar: (no name) - {4596013b-6c31-408b-a266-deae5c086dc2} - (no file)
O3 - Toolbar: (no name) - {b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} - (no file)
O3 - Toolbar: (no name) - {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SpywareCleaner] C:\WINDOWS\system32\SpywareRemover.exe
O4 - HKLM\..\Run: [Microsoft WinUpdate] C:\WINDOWS\system32\msupdte.exe
O4 - HKLM\..\Run: [Framework Windows] frmwrk32.exe
O4 - HKLM\..\Run: [6425bd6f] rundll32.exe "C:\WINDOWS\system32\gdgeatca.dll",b
O4 - HKCU\..\Run: [gadcom] "C:\Documents and Settings\ISABELLE\Application Data\gadcom\gadcom.exe" 61A847B5BBF72810339E3F466188719AB689201522886B092CBD44BD8689220221DD3257
O9 - Extra button: (no name) - software - (no file)
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://jeuxenligne.orange.fr/Gameshell/GameHost/1.0/OberonGameHost.cab
O20 - AppInit_DLLs: ykaeuo.dll xsqhhr.dll
__________________
Ferme tous tes navigateurs (donc copie ou imprime les instructions avant)
Crée un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :
File::
c:\windows\system32\SpywareRemover.exe
c:\windows\system32\gdgeatca.dll
C:\WINDOWS\system32\frmwrk32.exe
c:\windows\system32\msupdte.exe
c:\windows\Downloaded Program Files\OberonGameHost.dll
c:\windows\Downloaded Program Files\OberonGameHost_dbg.inf
C:\Documents and Settings\ISABELLE\Application Data\gadcom\gadcom.exe
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpywareCleaner"=-
"Microsoft WinUpdate"=-
"6425bd6f"=-
"Framework Windows"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=-
Enregistre ce fichier sous le nom CFscript
Fait un glisser/déposer de ce fichier CFscrïpt sur le fichier ComboFix.exe
Clique sur le fichier CFScript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFScript vienne recouvrir l'icône de Combofix. Relache la souris. Combofix va démarrer.
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
Remets aussi un rapport Hijackthis ou RSIT
Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
ComboFix 08-12-06.06 - ISABELLE 2008-12-08 16:25:41.3 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.247 [GMT 1:00]
Lancé depuis: c:\documents and settings\ISABELLE\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\ISABELLE\Bureau\cfscript.txt
* Un nouveau point de restauration a été créé
* Resident AV is active
FILE ::
c:\documents and settings\ISABELLE\Application Data\gadcom\gadcom.exe
c:\windows\Downloaded Program Files\OberonGameHost.dll
c:\windows\Downloaded Program Files\OberonGameHost_dbg.inf
c:\windows\system32\frmwrk32.exe
c:\windows\system32\gdgeatca.dll
c:\windows\system32\msupdte.exe
c:\windows\system32\SpywareRemover.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-08 au 2008-12-08 ))))))))))))))))))))))))))))))))))))
.
2008-12-08 13:48 . 2008-12-08 13:48 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Malwarebytes
2008-12-08 13:47 . 2008-12-08 13:48 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-08 13:47 . 2008-12-08 13:47 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-08 13:47 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-08 13:47 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-08 11:58 . 2008-12-08 12:25 <REP> d-------- C:\ToolBar SD
2008-12-08 11:42 . 2008-12-08 11:42 <REP> d-------- C:\rsit
2008-12-08 11:42 . 2008-12-08 16:12 <REP> d-------- c:\program files\trend micro
2008-12-08 01:29 . 2008-12-08 01:29 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-07 13:35 . 2008-12-07 13:35 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PC Tools
2008-12-07 13:34 . 2008-12-08 15:02 <REP> d-------- c:\program files\PC Tools AntiVirus
2008-12-07 13:34 . 2007-12-06 16:51 28,568 --a------ c:\windows\system32\drivers\AVHook.sys
2008-12-07 13:34 . 2007-12-06 16:51 21,912 --a------ c:\windows\system32\drivers\AVRec.sys
2008-12-07 13:34 . 2008-02-12 11:44 21,904 --a------ c:\windows\system32\drivers\AVFilter.sys
2008-12-06 20:59 . 2008-12-06 21:02 <REP> d-------- c:\program files\CCleaner
2008-12-06 00:56 . 2008-12-06 00:56 <REP> d-------- c:\documents and settings\All Users\Application Data\TheRace_dev
2008-12-06 00:42 . 2008-12-06 00:42 <REP> d-------- c:\program files\Fichiers communs\SWF Studio
2008-12-05 23:28 . 2008-12-05 23:28 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\iWin
2008-12-05 23:28 . 2008-12-05 23:28 <REP> d-------- c:\documents and settings\All Users\Application Data\iWin
2008-12-05 22:42 . 2008-12-05 22:42 <REP> d-------- c:\documents and settings\All Users\Application Data\Gogii
2008-12-05 22:28 . 2008-12-05 22:28 <REP> d-------- c:\documents and settings\All Users\Application Data\Intenium
2008-12-04 23:49 . 2008-12-04 23:49 <REP> d-------- c:\documents and settings\LocalService\Application Data\PCToolsSpamMonitorPlus
2008-12-04 23:49 . 2008-12-04 23:49 <REP> d-------- c:\documents and settings\LocalService\Application Data\PCToolsFirewallPlus
2008-12-04 19:55 . 2008-12-04 19:55 <REP> d--h----- c:\windows\PIF
2008-12-03 04:12 . 2008-12-06 00:39 <REP> d-------- c:\documents and settings\All Users\Application Data\Playrix Entertainment
2008-12-02 12:44 . 2008-12-02 12:44 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PCToolsFirewallPlus
2008-12-02 12:43 . 2008-12-02 12:43 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PCToolsSpamMonitorPlus
2008-12-02 12:35 . 2008-12-07 13:34 <REP> d-------- c:\documents and settings\All Users\Application Data\PC Tools
2008-12-02 08:54 . 2008-12-02 08:54 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Twain
2008-12-01 23:27 . 2008-12-01 23:27 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Games
2008-12-01 23:12 . 2008-12-01 23:26 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\FarmerJane
2008-12-01 22:57 . 2008-12-01 22:57 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Gaijin Ent
2008-12-01 21:43 . 2008-12-01 21:43 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Valusoft
2008-12-01 21:43 . 2008-12-01 21:43 <REP> d-------- c:\documents and settings\All Users\Application Data\Valusoft
2008-12-01 20:56 . 2008-12-01 20:56 <REP> d-------- c:\documents and settings\All Users\Application Data\Arkadium
2008-12-01 20:00 . 2008-12-07 10:22 268 --a------ c:\windows\wininit.ini
2008-12-01 13:46 . 2008-12-08 11:29 461 --a------ c:\windows\system32\win32hlp.cnf
2008-12-01 10:28 . 2008-12-01 10:28 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\AlterLab
2008-12-01 09:06 . 2008-12-01 15:51 <REP> d-------- c:\program files\Spybot - Search & Destroy
2008-12-01 09:06 . 2008-12-08 10:29 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-28 20:48 . 2008-11-29 18:25 5 --a------ c:\windows\sbacknt.bin
2008-11-28 20:46 . 2008-11-29 19:24 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\vghd
2008-11-28 20:46 . 2008-11-28 20:46 152,904 --a------ c:\windows\system32\vghd.scr
2008-11-28 20:46 . 2008-12-02 08:43 4 --a------ c:\windows\system32\test.ttt
2008-11-28 19:30 . 2008-11-28 19:30 <REP> d-------- c:\documents and settings\All Users\Application Data\FreshGames
2008-11-28 16:47 . 2008-11-28 16:47 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Meridian93
2008-11-28 16:07 . 2008-11-30 17:43 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Shopping Blocks
2008-11-28 14:59 . 2008-11-28 15:05 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Ancient Quest of Saqqarah__gamehouse
2008-11-26 00:55 . 2008-11-28 19:30 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Zylom
2008-11-25 22:09 . 2008-11-25 22:09 <REP> d--hs---- c:\windows\ftpcache
2008-11-25 21:05 . 2008-11-25 21:05 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\SulusGames
2008-11-25 16:52 . 2008-11-26 13:45 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\funkitron
2008-11-25 16:51 . 2008-11-25 16:51 <REP> d-------- c:\program files\Slingo Quest
2008-11-25 14:35 . 2008-11-25 14:36 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PetShowCraze
2008-11-25 02:36 . 2008-11-25 02:36 <REP> d-------- c:\documents and settings\All Users\Application Data\QB9 S.R.L
2008-11-24 20:48 . 2008-11-24 20:48 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\cerasus
2008-11-24 17:24 . 2008-12-07 21:44 <REP> d---s---- c:\documents and settings\ISABELLE\UserData
2008-11-23 18:30 . 2008-11-23 18:30 <REP> d-------- c:\documents and settings\All Users\Application Data\FarmFrenzy2
2008-11-23 18:23 . 103,634 c:\windows\system32\drivers\30668e04.sys
2008-11-23 16:31 . 2008-11-23 16:31 <REP> d-------- c:\documents and settings\ISABELLE\Contacts
2008-11-22 22:56 . 2008-11-23 03:02 <REP> d--h----- c:\windows\$hf_mig$
2008-11-22 22:55 . 2008-11-22 22:55 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\AVG7
2008-11-22 22:54 . 2008-12-08 16:27 <REP> d-------- c:\windows\apppatch
2008-11-22 22:54 . 2008-11-22 22:54 <REP> d--h----- c:\documents and settings\ISABELLE\Voisinage d'impression
2008-11-22 22:54 . 2008-11-22 22:54 <REP> dr------- c:\documents and settings\ISABELLE\Menu Démarrer
2008-11-22 22:54 . 2008-11-22 22:54 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\You've Got Pictures Screensaver
2008-11-22 22:54 . 2008-11-22 22:54 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\DivX
2008-11-21 22:14 . 2008-11-21 22:14 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\LuckyTender
2008-11-21 20:15 . 2008-12-06 02:55 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\cerasus.media
2008-11-21 19:09 . 2008-12-06 00:18 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PlayFirst
2008-11-21 12:38 . 2008-11-21 12:39 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Magic Academy
2008-11-21 11:36 . 2008-12-07 13:27 <REP> d-------- c:\program files\Fichiers communs\PC Tools
2008-11-20 21:55 . 2008-11-20 21:55 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Flood Light Games
2008-11-20 20:33 . 2006-02-24 22:56 <REP> d--h----- c:\documents and settings\ISABELLE\Voisinage réseau
2008-11-20 20:33 . 2008-11-22 22:54 <REP> d--h----- c:\documents and settings\ISABELLE\Modèles
2008-11-20 20:33 . 2008-12-07 21:43 <REP> dr------- c:\documents and settings\ISABELLE\Mes documents
2008-11-20 20:33 . 2008-12-08 11:22 <REP> dr------- c:\documents and settings\ISABELLE\Favoris
2008-11-20 20:33 . 2008-12-08 16:25 <REP> dr------- c:\documents and settings\ISABELLE\Bureau
2008-11-20 20:33 . 2008-12-08 10:28 <REP> d-a------ c:\documents and settings\ISABELLE
2008-11-18 11:31 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2008-11-18 11:31 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
2008-11-18 11:31 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2008-11-17 22:26 . 2008-11-23 18:24 <REP> d-------- c:\program files\myBabylon_English
2008-11-17 14:36 . 2008-11-17 14:36 <REP> d--hsc--- c:\program files\Fichiers communs\WindowsLiveInstaller
2008-11-17 14:35 . 2008-11-17 14:36 <REP> d-------- c:\program files\Windows Live
2008-11-17 14:35 . 2008-11-17 14:35 <REP> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
2008-11-17 14:21 . 2008-10-24 12:21 455,296 --------- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-17 14:20 . 2008-09-04 18:16 1,106,944 --------- c:\windows\system32\dllcache\msxml3.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-08 13:54 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-08 09:58 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2008-12-07 22:43 6,384 ----a-w C:\GETDRIVE.EXE
2008-12-07 21:02 --------- d-----w c:\program files\Zylom Games
2008-12-07 20:52 --------- d-----w c:\program files\DivX
2008-12-06 20:01 --------- d-----w c:\program files\Yahoo!
2008-12-05 23:18 --------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst
2008-12-05 21:26 --------- d-----w c:\program files\eMule
2008-11-26 00:02 --------- d-----w c:\program files\LuckyTender
2008-11-25 23:26 --------- d-----w c:\documents and settings\All Users\Application Data\HipSoft
2008-11-23 15:22 --------- d-----w c:\program files\Google
2008-11-23 12:28 --------- d-----w c:\program files\Wanadoo
2008-11-23 01:01 --------- d-----w c:\documents and settings\All Users\Application Data\MysteryChronicles
2008-11-22 21:56 --------- d-----w c:\program files\Fichiers communs\Adobe
2008-11-22 21:55 --------- d-----w c:\program files\Cluedo
2008-11-22 21:55 --------- d-----w c:\documents and settings\All Users\Application Data\avg7
2008-11-20 19:18 --------- d-----w c:\program files\Packard Bell EverSafe
2008-11-04 21:34 --------- d-----w c:\documents and settings\All Users\Application Data\EscapeTheMuseum
2008-11-03 23:04 --------- d-----w c:\documents and settings\All Users\Application Data\Fugazo
2008-11-03 18:45 --------- d-----w c:\documents and settings\All Users\Application Data\MissTeriTale2
2008-11-03 15:13 --------- d-----w c:\documents and settings\All Users\Application Data\MythPeople
2008-10-30 16:11 --------- d-----w c:\documents and settings\All Users\Application Data\SpinTop Games
2008-10-30 04:19 --------- d-----w c:\documents and settings\All Users\Application Data\Oberon Media
2008-10-28 20:08 --------- d-----w c:\documents and settings\All Users\Application Data\n7-89-o9-3r-4t-r9
2008-10-27 09:05 --------- d-----w c:\documents and settings\All Users\Application Data\JollyBear
2008-10-27 06:42 --------- d-----w c:\documents and settings\All Users\Application Data\SugarGames
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-20 17:09 --------- d-----w c:\documents and settings\All Users\Application Data\Zylom
2008-10-20 13:42 --------- d-----w c:\documents and settings\All Users\Application Data\GameHouse
2008-10-19 08:38 --------- d-----w c:\program files\ReflexiveArcade
2008-10-19 06:15 --------- d-----w c:\program files\QuickTime
2008-10-18 06:26 --------- d-----w c:\documents and settings\All Users\Application Data\Flood Light Games
2008-10-18 05:59 --------- d-----w c:\program files\Share_Accelerator_MM
2008-10-18 05:59 --------- d-----w c:\program files\Conduit
2008-10-17 15:24 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-17 10:12 --------- d-----w c:\documents and settings\All Users\Application Data\FloodLightGames
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 07:06 --------- d-----w c:\documents and settings\All Users\Application Data\BOONTY
2008-10-16 04:58 --------- d-----w c:\program files\Java
2008-10-15 16:35 337,408 ------w c:\windows\system32\dllcache\netapi32.dll
2008-10-08 14:08 --------- d-----w c:\program files\Lx_cats
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
2008-09-15 15:26 1,846,528 ------w c:\windows\system32\dllcache\win32k.sys
2008-09-10 01:15 1,307,648 ------w c:\windows\system32\msxml6.dll
2008-09-10 01:15 1,307,648 ------w c:\windows\system32\dllcache\msxml6.dll
2008-09-08 10:41 333,824 ------w c:\windows\system32\dllcache\srv.sys
2006-02-24 20:37 3,308,767 ----a-w c:\program files\Shareaza_2.2.1.0.exe
2006-02-24 19:32 1,525,216 -c--a-w c:\program files\Antispam.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-02-03 68856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"WOOKIT"="c:\progra~1\Wanadoo\Shell.exe" [BU]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-02-03 185632]
"ISTray"="c:\program files\PC Tools Internet Security\pctsTray.exe" [BU]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8767:TCP"= 8767:TCP:messenger
"8387:TCP"= 8387:TCP:messenger
"7313:TCP"= 7313:TCP:messenger
"6216:TCP"= 6216:TCP:messenger
"6358:TCP"= 6358:TCP:messenger
"5282:TCP"= 5282:TCP:messenger
"2311:TCP"= 2311:TCP:messenger
"2764:TCP"= 2764:TCP:messenger
"8147:TCP"= 8147:TCP:messenger
"7464:TCP"= 7464:TCP:messenger
"8138:TCP"= 8138:TCP:messenger
"4641:TCP"= 4641:TCP:messenger
"4246:TCP"= 4246:TCP:messenger
"5737:TCP"= 5737:TCP:messenger
"5852:TCP"= 5852:TCP:messenger
"4816:TCP"= 4816:TCP:messenger
"4455:TCP"= 4455:TCP:messenger
"4635:TCP"= 4635:TCP:messenger
"8451:TCP"= 8451:TCP:messenger
"5158:TCP"= 5158:TCP:messenger
"2455:TCP"= 2455:TCP:messenger
"1132:TCP"= 1132:TCP:messenger
"3456:TCP"= 3456:TCP:messenger
"5124:TCP"= 5124:TCP:messenger
"5684:TCP"= 5684:TCP:messenger
"7474:TCP"= 7474:TCP:messenger
"1616:TCP"= 1616:TCP:messenger
"7522:TCP"= 7522:TCP:messenger
R1 Asapi;Asapi;c:\windows\system32\drivers\Asapi.sys [2004-11-01 11264]
R2 MTC0005_MTCDIO;Wireless HotKey Driver;c:\windows\system32\drivers\MTCDIO.sys [2004-11-01 11316]
R2 NwSapAgent;Agent SAP;c:\windows\System32\svchost.exe -k netsvcs [2002-09-30 14336]
R3 EMCR;EMCR;c:\windows\system32\DRIVERS\EMCR7SK.sys [1980-01-01 68224]
S1 aswSP;avast! Self Protection; []
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys []
S2 MTCDIO;MTCDIO;c:\windows\system32\DRIVERS\MTCDIO.sys [2004-11-01 11316]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;c:\windows\system32\DRIVERS\fbxusb32.sys [2006-08-21 21344]
S3 PhTVTune;Cap7134 TVTuner;c:\windows\system32\DRIVERS\PhTVTune.sys [2004-06-15 42080]
*Newly Created Service* - catchme
.
Contenu du dossier 'Tâches planifiées'
2008-10-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 12:42]
2006-02-24 c:\windows\Tasks\Rappel d'enregistrement 3.job
- c:\windows\System32\OOBE\oobebaln.exe [2008-04-14 03:34]
.
- - - - ORPHELINS SUPPRIMES - - - -
WebBrowser-{B2E293EE-FD7E-4C71-A714-5F4750D8D7B7} - (no file)
.
------- Examen supplémentaire -------
.
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.orange.fr/
uSearch Bar = hxxp://www.google.com/ie
mWindow Title =
uInternet Connection Wizard,ShellNext = hxxp://celaia.daxon.fr/vente-en-ligne/panier/panier.aspx
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
LSP: c:\program files\Fichiers communs\PC Tools\Lsp\PCTLsp.dll
O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd
O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
c:\windows\Downloaded Program Files\CookingDashWeb.1.0.0.9.dll - O16 -: {195B4BBF-E1E4-4020-9773-0A8C6F65EA35}
hxxp://webgames.d.tmsrv.com/c=57c218bb5298e374b3c5e9f078cabd4f/aff=t_25oa_frca_wg/p/release/playfirst/wg_cookingdash/cookingdash/CookingDashWeb.1.0.0.9.cab
c:\windows\Downloaded Program Files\CookingDashWeb.1.0.0.9.inf
c:\windows\Downloaded Program Files\zenerchi.1.0.0.10.dll - O16 -: {bac761d3-dffd-4db4-a01d-173346e090a7}
hxxp://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--5bca0d7d-3ef6-4521-bd1b-5d981bd14ff1/online/zenerchi/fr/ZenerchiWeb.1.0.0.10.cab
c:\windows\Downloaded Program Files\zenerchi.1.0.0.10.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-08 16:29:08
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MySqlInventime]
"ImagePath"="c:\mysql\bin\mysqld-max-nt MySqlInventime"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\30668e04]
"ImagePath"="\SystemRoot\System32\drivers\30668e04.sys"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(896)
c:\program files\PC Tools AntiVirus\PCTAVHook.dll
- - - - - - - > 'lsass.exe'(952)
c:\program files\Fichiers communs\PC Tools\Lsp\PCTLsp.dll
c:\program files\PC Tools AntiVirus\PCTAVHook.dll
- - - - - - - > 'csrss.exe'(872)
c:\program files\PC Tools AntiVirus\PCTAVHook.dll
.
Heure de fin: 2008-12-08 16:30:17
ComboFix-quarantined-files.txt 2008-12-08 15:30:14
ComboFix2.txt 2008-12-08 14:05:13
Avant-CF: 24 168 558 592 octets libres
Après-CF: 24,179,494,912 octets libres
297 --- E O F --- 2008-11-24 09:41:45
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.247 [GMT 1:00]
Lancé depuis: c:\documents and settings\ISABELLE\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\ISABELLE\Bureau\cfscript.txt
* Un nouveau point de restauration a été créé
* Resident AV is active
FILE ::
c:\documents and settings\ISABELLE\Application Data\gadcom\gadcom.exe
c:\windows\Downloaded Program Files\OberonGameHost.dll
c:\windows\Downloaded Program Files\OberonGameHost_dbg.inf
c:\windows\system32\frmwrk32.exe
c:\windows\system32\gdgeatca.dll
c:\windows\system32\msupdte.exe
c:\windows\system32\SpywareRemover.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-08 au 2008-12-08 ))))))))))))))))))))))))))))))))))))
.
2008-12-08 13:48 . 2008-12-08 13:48 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Malwarebytes
2008-12-08 13:47 . 2008-12-08 13:48 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-08 13:47 . 2008-12-08 13:47 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-08 13:47 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-08 13:47 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-08 11:58 . 2008-12-08 12:25 <REP> d-------- C:\ToolBar SD
2008-12-08 11:42 . 2008-12-08 11:42 <REP> d-------- C:\rsit
2008-12-08 11:42 . 2008-12-08 16:12 <REP> d-------- c:\program files\trend micro
2008-12-08 01:29 . 2008-12-08 01:29 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-07 13:35 . 2008-12-07 13:35 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PC Tools
2008-12-07 13:34 . 2008-12-08 15:02 <REP> d-------- c:\program files\PC Tools AntiVirus
2008-12-07 13:34 . 2007-12-06 16:51 28,568 --a------ c:\windows\system32\drivers\AVHook.sys
2008-12-07 13:34 . 2007-12-06 16:51 21,912 --a------ c:\windows\system32\drivers\AVRec.sys
2008-12-07 13:34 . 2008-02-12 11:44 21,904 --a------ c:\windows\system32\drivers\AVFilter.sys
2008-12-06 20:59 . 2008-12-06 21:02 <REP> d-------- c:\program files\CCleaner
2008-12-06 00:56 . 2008-12-06 00:56 <REP> d-------- c:\documents and settings\All Users\Application Data\TheRace_dev
2008-12-06 00:42 . 2008-12-06 00:42 <REP> d-------- c:\program files\Fichiers communs\SWF Studio
2008-12-05 23:28 . 2008-12-05 23:28 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\iWin
2008-12-05 23:28 . 2008-12-05 23:28 <REP> d-------- c:\documents and settings\All Users\Application Data\iWin
2008-12-05 22:42 . 2008-12-05 22:42 <REP> d-------- c:\documents and settings\All Users\Application Data\Gogii
2008-12-05 22:28 . 2008-12-05 22:28 <REP> d-------- c:\documents and settings\All Users\Application Data\Intenium
2008-12-04 23:49 . 2008-12-04 23:49 <REP> d-------- c:\documents and settings\LocalService\Application Data\PCToolsSpamMonitorPlus
2008-12-04 23:49 . 2008-12-04 23:49 <REP> d-------- c:\documents and settings\LocalService\Application Data\PCToolsFirewallPlus
2008-12-04 19:55 . 2008-12-04 19:55 <REP> d--h----- c:\windows\PIF
2008-12-03 04:12 . 2008-12-06 00:39 <REP> d-------- c:\documents and settings\All Users\Application Data\Playrix Entertainment
2008-12-02 12:44 . 2008-12-02 12:44 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PCToolsFirewallPlus
2008-12-02 12:43 . 2008-12-02 12:43 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PCToolsSpamMonitorPlus
2008-12-02 12:35 . 2008-12-07 13:34 <REP> d-------- c:\documents and settings\All Users\Application Data\PC Tools
2008-12-02 08:54 . 2008-12-02 08:54 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Twain
2008-12-01 23:27 . 2008-12-01 23:27 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Games
2008-12-01 23:12 . 2008-12-01 23:26 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\FarmerJane
2008-12-01 22:57 . 2008-12-01 22:57 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Gaijin Ent
2008-12-01 21:43 . 2008-12-01 21:43 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Valusoft
2008-12-01 21:43 . 2008-12-01 21:43 <REP> d-------- c:\documents and settings\All Users\Application Data\Valusoft
2008-12-01 20:56 . 2008-12-01 20:56 <REP> d-------- c:\documents and settings\All Users\Application Data\Arkadium
2008-12-01 20:00 . 2008-12-07 10:22 268 --a------ c:\windows\wininit.ini
2008-12-01 13:46 . 2008-12-08 11:29 461 --a------ c:\windows\system32\win32hlp.cnf
2008-12-01 10:28 . 2008-12-01 10:28 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\AlterLab
2008-12-01 09:06 . 2008-12-01 15:51 <REP> d-------- c:\program files\Spybot - Search & Destroy
2008-12-01 09:06 . 2008-12-08 10:29 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-28 20:48 . 2008-11-29 18:25 5 --a------ c:\windows\sbacknt.bin
2008-11-28 20:46 . 2008-11-29 19:24 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\vghd
2008-11-28 20:46 . 2008-11-28 20:46 152,904 --a------ c:\windows\system32\vghd.scr
2008-11-28 20:46 . 2008-12-02 08:43 4 --a------ c:\windows\system32\test.ttt
2008-11-28 19:30 . 2008-11-28 19:30 <REP> d-------- c:\documents and settings\All Users\Application Data\FreshGames
2008-11-28 16:47 . 2008-11-28 16:47 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Meridian93
2008-11-28 16:07 . 2008-11-30 17:43 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Shopping Blocks
2008-11-28 14:59 . 2008-11-28 15:05 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Ancient Quest of Saqqarah__gamehouse
2008-11-26 00:55 . 2008-11-28 19:30 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Zylom
2008-11-25 22:09 . 2008-11-25 22:09 <REP> d--hs---- c:\windows\ftpcache
2008-11-25 21:05 . 2008-11-25 21:05 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\SulusGames
2008-11-25 16:52 . 2008-11-26 13:45 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\funkitron
2008-11-25 16:51 . 2008-11-25 16:51 <REP> d-------- c:\program files\Slingo Quest
2008-11-25 14:35 . 2008-11-25 14:36 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PetShowCraze
2008-11-25 02:36 . 2008-11-25 02:36 <REP> d-------- c:\documents and settings\All Users\Application Data\QB9 S.R.L
2008-11-24 20:48 . 2008-11-24 20:48 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\cerasus
2008-11-24 17:24 . 2008-12-07 21:44 <REP> d---s---- c:\documents and settings\ISABELLE\UserData
2008-11-23 18:30 . 2008-11-23 18:30 <REP> d-------- c:\documents and settings\All Users\Application Data\FarmFrenzy2
2008-11-23 18:23 . 103,634 c:\windows\system32\drivers\30668e04.sys
2008-11-23 16:31 . 2008-11-23 16:31 <REP> d-------- c:\documents and settings\ISABELLE\Contacts
2008-11-22 22:56 . 2008-11-23 03:02 <REP> d--h----- c:\windows\$hf_mig$
2008-11-22 22:55 . 2008-11-22 22:55 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\AVG7
2008-11-22 22:54 . 2008-12-08 16:27 <REP> d-------- c:\windows\apppatch
2008-11-22 22:54 . 2008-11-22 22:54 <REP> d--h----- c:\documents and settings\ISABELLE\Voisinage d'impression
2008-11-22 22:54 . 2008-11-22 22:54 <REP> dr------- c:\documents and settings\ISABELLE\Menu Démarrer
2008-11-22 22:54 . 2008-11-22 22:54 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\You've Got Pictures Screensaver
2008-11-22 22:54 . 2008-11-22 22:54 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\DivX
2008-11-21 22:14 . 2008-11-21 22:14 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\LuckyTender
2008-11-21 20:15 . 2008-12-06 02:55 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\cerasus.media
2008-11-21 19:09 . 2008-12-06 00:18 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\PlayFirst
2008-11-21 12:38 . 2008-11-21 12:39 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Magic Academy
2008-11-21 11:36 . 2008-12-07 13:27 <REP> d-------- c:\program files\Fichiers communs\PC Tools
2008-11-20 21:55 . 2008-11-20 21:55 <REP> d-------- c:\documents and settings\ISABELLE\Application Data\Flood Light Games
2008-11-20 20:33 . 2006-02-24 22:56 <REP> d--h----- c:\documents and settings\ISABELLE\Voisinage réseau
2008-11-20 20:33 . 2008-11-22 22:54 <REP> d--h----- c:\documents and settings\ISABELLE\Modèles
2008-11-20 20:33 . 2008-12-07 21:43 <REP> dr------- c:\documents and settings\ISABELLE\Mes documents
2008-11-20 20:33 . 2008-12-08 11:22 <REP> dr------- c:\documents and settings\ISABELLE\Favoris
2008-11-20 20:33 . 2008-12-08 16:25 <REP> dr------- c:\documents and settings\ISABELLE\Bureau
2008-11-20 20:33 . 2008-12-08 10:28 <REP> d-a------ c:\documents and settings\ISABELLE
2008-11-18 11:31 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2008-11-18 11:31 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
2008-11-18 11:31 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2008-11-17 22:26 . 2008-11-23 18:24 <REP> d-------- c:\program files\myBabylon_English
2008-11-17 14:36 . 2008-11-17 14:36 <REP> d--hsc--- c:\program files\Fichiers communs\WindowsLiveInstaller
2008-11-17 14:35 . 2008-11-17 14:36 <REP> d-------- c:\program files\Windows Live
2008-11-17 14:35 . 2008-11-17 14:35 <REP> d-------- c:\documents and settings\All Users\Application Data\WLInstaller
2008-11-17 14:21 . 2008-10-24 12:21 455,296 --------- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-17 14:20 . 2008-09-04 18:16 1,106,944 --------- c:\windows\system32\dllcache\msxml3.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-08 13:54 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-12-08 09:58 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2008-12-07 22:43 6,384 ----a-w C:\GETDRIVE.EXE
2008-12-07 21:02 --------- d-----w c:\program files\Zylom Games
2008-12-07 20:52 --------- d-----w c:\program files\DivX
2008-12-06 20:01 --------- d-----w c:\program files\Yahoo!
2008-12-05 23:18 --------- d-----w c:\documents and settings\All Users\Application Data\PlayFirst
2008-12-05 21:26 --------- d-----w c:\program files\eMule
2008-11-26 00:02 --------- d-----w c:\program files\LuckyTender
2008-11-25 23:26 --------- d-----w c:\documents and settings\All Users\Application Data\HipSoft
2008-11-23 15:22 --------- d-----w c:\program files\Google
2008-11-23 12:28 --------- d-----w c:\program files\Wanadoo
2008-11-23 01:01 --------- d-----w c:\documents and settings\All Users\Application Data\MysteryChronicles
2008-11-22 21:56 --------- d-----w c:\program files\Fichiers communs\Adobe
2008-11-22 21:55 --------- d-----w c:\program files\Cluedo
2008-11-22 21:55 --------- d-----w c:\documents and settings\All Users\Application Data\avg7
2008-11-20 19:18 --------- d-----w c:\program files\Packard Bell EverSafe
2008-11-04 21:34 --------- d-----w c:\documents and settings\All Users\Application Data\EscapeTheMuseum
2008-11-03 23:04 --------- d-----w c:\documents and settings\All Users\Application Data\Fugazo
2008-11-03 18:45 --------- d-----w c:\documents and settings\All Users\Application Data\MissTeriTale2
2008-11-03 15:13 --------- d-----w c:\documents and settings\All Users\Application Data\MythPeople
2008-10-30 16:11 --------- d-----w c:\documents and settings\All Users\Application Data\SpinTop Games
2008-10-30 04:19 --------- d-----w c:\documents and settings\All Users\Application Data\Oberon Media
2008-10-28 20:08 --------- d-----w c:\documents and settings\All Users\Application Data\n7-89-o9-3r-4t-r9
2008-10-27 09:05 --------- d-----w c:\documents and settings\All Users\Application Data\JollyBear
2008-10-27 06:42 --------- d-----w c:\documents and settings\All Users\Application Data\SugarGames
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-20 17:09 --------- d-----w c:\documents and settings\All Users\Application Data\Zylom
2008-10-20 13:42 --------- d-----w c:\documents and settings\All Users\Application Data\GameHouse
2008-10-19 08:38 --------- d-----w c:\program files\ReflexiveArcade
2008-10-19 06:15 --------- d-----w c:\program files\QuickTime
2008-10-18 06:26 --------- d-----w c:\documents and settings\All Users\Application Data\Flood Light Games
2008-10-18 05:59 --------- d-----w c:\program files\Share_Accelerator_MM
2008-10-18 05:59 --------- d-----w c:\program files\Conduit
2008-10-17 15:24 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-17 10:12 --------- d-----w c:\documents and settings\All Users\Application Data\FloodLightGames
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 07:06 --------- d-----w c:\documents and settings\All Users\Application Data\BOONTY
2008-10-16 04:58 --------- d-----w c:\program files\Java
2008-10-15 16:35 337,408 ------w c:\windows\system32\dllcache\netapi32.dll
2008-10-08 14:08 --------- d-----w c:\program files\Lx_cats
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
2008-09-15 15:26 1,846,528 ------w c:\windows\system32\dllcache\win32k.sys
2008-09-10 01:15 1,307,648 ------w c:\windows\system32\msxml6.dll
2008-09-10 01:15 1,307,648 ------w c:\windows\system32\dllcache\msxml6.dll
2008-09-08 10:41 333,824 ------w c:\windows\system32\dllcache\srv.sys
2006-02-24 20:37 3,308,767 ----a-w c:\program files\Shareaza_2.2.1.0.exe
2006-02-24 19:32 1,525,216 -c--a-w c:\program files\Antispam.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-02-03 68856]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"WOOKIT"="c:\progra~1\Wanadoo\Shell.exe" [BU]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-02-03 185632]
"ISTray"="c:\program files\PC Tools Internet Security\pctsTray.exe" [BU]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8767:TCP"= 8767:TCP:messenger
"8387:TCP"= 8387:TCP:messenger
"7313:TCP"= 7313:TCP:messenger
"6216:TCP"= 6216:TCP:messenger
"6358:TCP"= 6358:TCP:messenger
"5282:TCP"= 5282:TCP:messenger
"2311:TCP"= 2311:TCP:messenger
"2764:TCP"= 2764:TCP:messenger
"8147:TCP"= 8147:TCP:messenger
"7464:TCP"= 7464:TCP:messenger
"8138:TCP"= 8138:TCP:messenger
"4641:TCP"= 4641:TCP:messenger
"4246:TCP"= 4246:TCP:messenger
"5737:TCP"= 5737:TCP:messenger
"5852:TCP"= 5852:TCP:messenger
"4816:TCP"= 4816:TCP:messenger
"4455:TCP"= 4455:TCP:messenger
"4635:TCP"= 4635:TCP:messenger
"8451:TCP"= 8451:TCP:messenger
"5158:TCP"= 5158:TCP:messenger
"2455:TCP"= 2455:TCP:messenger
"1132:TCP"= 1132:TCP:messenger
"3456:TCP"= 3456:TCP:messenger
"5124:TCP"= 5124:TCP:messenger
"5684:TCP"= 5684:TCP:messenger
"7474:TCP"= 7474:TCP:messenger
"1616:TCP"= 1616:TCP:messenger
"7522:TCP"= 7522:TCP:messenger
R1 Asapi;Asapi;c:\windows\system32\drivers\Asapi.sys [2004-11-01 11264]
R2 MTC0005_MTCDIO;Wireless HotKey Driver;c:\windows\system32\drivers\MTCDIO.sys [2004-11-01 11316]
R2 NwSapAgent;Agent SAP;c:\windows\System32\svchost.exe -k netsvcs [2002-09-30 14336]
R3 EMCR;EMCR;c:\windows\system32\DRIVERS\EMCR7SK.sys [1980-01-01 68224]
S1 aswSP;avast! Self Protection; []
S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys []
S2 MTCDIO;MTCDIO;c:\windows\system32\DRIVERS\MTCDIO.sys [2004-11-01 11316]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;c:\windows\system32\DRIVERS\fbxusb32.sys [2006-08-21 21344]
S3 PhTVTune;Cap7134 TVTuner;c:\windows\system32\DRIVERS\PhTVTune.sys [2004-06-15 42080]
*Newly Created Service* - catchme
.
Contenu du dossier 'Tâches planifiées'
2008-10-30 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-06-03 12:42]
2006-02-24 c:\windows\Tasks\Rappel d'enregistrement 3.job
- c:\windows\System32\OOBE\oobebaln.exe [2008-04-14 03:34]
.
- - - - ORPHELINS SUPPRIMES - - - -
WebBrowser-{B2E293EE-FD7E-4C71-A714-5F4750D8D7B7} - (no file)
.
------- Examen supplémentaire -------
.
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.orange.fr/
uSearch Bar = hxxp://www.google.com/ie
mWindow Title =
uInternet Connection Wizard,ShellNext = hxxp://celaia.daxon.fr/vente-en-ligne/panier/panier.aspx
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
LSP: c:\program files\Fichiers communs\PC Tools\Lsp\PCTLsp.dll
O16 -: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
c:\windows\Downloaded Program Files\DirectAnimation Java Classes.osd
O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
c:\windows\Downloaded Program Files\CookingDashWeb.1.0.0.9.dll - O16 -: {195B4BBF-E1E4-4020-9773-0A8C6F65EA35}
hxxp://webgames.d.tmsrv.com/c=57c218bb5298e374b3c5e9f078cabd4f/aff=t_25oa_frca_wg/p/release/playfirst/wg_cookingdash/cookingdash/CookingDashWeb.1.0.0.9.cab
c:\windows\Downloaded Program Files\CookingDashWeb.1.0.0.9.inf
c:\windows\Downloaded Program Files\zenerchi.1.0.0.10.dll - O16 -: {bac761d3-dffd-4db4-a01d-173346e090a7}
hxxp://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--5bca0d7d-3ef6-4521-bd1b-5d981bd14ff1/online/zenerchi/fr/ZenerchiWeb.1.0.0.10.cab
c:\windows\Downloaded Program Files\zenerchi.1.0.0.10.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-08 16:29:08
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MySqlInventime]
"ImagePath"="c:\mysql\bin\mysqld-max-nt MySqlInventime"
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\30668e04]
"ImagePath"="\SystemRoot\System32\drivers\30668e04.sys"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(896)
c:\program files\PC Tools AntiVirus\PCTAVHook.dll
- - - - - - - > 'lsass.exe'(952)
c:\program files\Fichiers communs\PC Tools\Lsp\PCTLsp.dll
c:\program files\PC Tools AntiVirus\PCTAVHook.dll
- - - - - - - > 'csrss.exe'(872)
c:\program files\PC Tools AntiVirus\PCTAVHook.dll
.
Heure de fin: 2008-12-08 16:30:17
ComboFix-quarantined-files.txt 2008-12-08 15:30:14
ComboFix2.txt 2008-12-08 14:05:13
Avant-CF: 24 168 558 592 octets libres
Après-CF: 24,179,494,912 octets libres
297 --- E O F --- 2008-11-24 09:41:45
Logfile of random's system information tool 1.04 (written by random/random)
Run by ISABELLE at 2008-12-08 16:33:10
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 23 GB (43%) free of 53 GB
Total RAM: 511 MB (36% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:33:18, on 08/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\ISABELLE\Bureau\HiJackThis.exe
C:\Documents and Settings\ISABELLE\Bureau\RSIT.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Documents and Settings\ISABELLE\Bureau\ISABELLE.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.balsamik.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - software - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\PC Tools Internet Security\pctsTray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKCU\..\Run: [gadcom] "C:\Documents and Settings\ISABELLE\Application Data\gadcom\gadcom.exe" 61A847B5BBF72810339E3F466188719AB689201522886B092CBD44BD8689220221DD3257
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {195B4BBF-E1E4-4020-9773-0A8C6F65EA35} (CPlayFirstCookingDasControl Object) - http://webgames.d.tmsrv.com/c=57c218bb5298e374b3c5e9f078cabd4f/aff=t_25oa_frca_wg/p/release/playfirst/wg_cookingdash/cookingdash/CookingDashWeb.1.0.0.9.cab
O16 - DPF: {bac761d3-dffd-4db4-a01d-173346e090a7} (CPlayFirstzenerchiControl Object) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--5bca0d7d-3ef6-4521-bd1b-5d981bd14ff1/online/zenerchi/fr/ZenerchiWeb.1.0.0.10.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O16 - DPF: {d0c0f75c-683a-4390-a791-1acfd5599ab8} -
O16 - DPF: {ea6246b4-f380-443f-8727-9aea3371146c} (CPlayFirstWeddingDashControl Object) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--d66a432b-38e7-468a-b329-33657f1af599/online/wedding_dash/fr/WeddingDash.1.0.0.47.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: MySqlInventime - Unknown owner - c:\mysql\bin\mysqld-max-nt.exe
O23 - Service: PC Tools AntiVirus Engine (pctavsvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
Run by ISABELLE at 2008-12-08 16:33:10
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 23 GB (43%) free of 53 GB
Total RAM: 511 MB (36% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:33:18, on 08/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\ISABELLE\Bureau\HiJackThis.exe
C:\Documents and Settings\ISABELLE\Bureau\RSIT.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Documents and Settings\ISABELLE\Bureau\ISABELLE.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.balsamik.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - software - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6f74-2d53-2644-206d7942484f} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {aa58ed58-01dd-4d91-8333-cf10577473f7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: PDFCreator Toolbar - {31CF9EBE-5755-4A1D-AC25-2834D952D9B4} - C:\Program Files\PDFCreator Toolbar\v3.0.0.0\PDFCreator_Toolbar.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\PC Tools Internet Security\pctsTray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKCU\..\Run: [gadcom] "C:\Documents and Settings\ISABELLE\Application Data\gadcom\gadcom.exe" 61A847B5BBF72810339E3F466188719AB689201522886B092CBD44BD8689220221DD3257
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {dfb852a3-47f8-48c4-a200-58cab36fd2a2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {195B4BBF-E1E4-4020-9773-0A8C6F65EA35} (CPlayFirstCookingDasControl Object) - http://webgames.d.tmsrv.com/c=57c218bb5298e374b3c5e9f078cabd4f/aff=t_25oa_frca_wg/p/release/playfirst/wg_cookingdash/cookingdash/CookingDashWeb.1.0.0.9.cab
O16 - DPF: {bac761d3-dffd-4db4-a01d-173346e090a7} (CPlayFirstzenerchiControl Object) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--5bca0d7d-3ef6-4521-bd1b-5d981bd14ff1/online/zenerchi/fr/ZenerchiWeb.1.0.0.10.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O16 - DPF: {d0c0f75c-683a-4390-a791-1acfd5599ab8} -
O16 - DPF: {ea6246b4-f380-443f-8727-9aea3371146c} (CPlayFirstWeddingDashControl Object) - http://jeuxenligne.orange.fr/orange2.0/games/channel--110167437/lc--fr/room--d66a432b-38e7-468a-b329-33657f1af599/online/wedding_dash/fr/WeddingDash.1.0.0.47.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: lxcg_device - - C:\WINDOWS\system32\lxcgcoms.exe
O23 - Service: MySqlInventime - Unknown owner - c:\mysql\bin\mysqld-max-nt.exe
O23 - Service: PC Tools AntiVirus Engine (pctavsvc) - PC Tools Research Pty Ltd - C:\Program Files\PC Tools AntiVirus\PCTAVSvc.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
ok parfait encore des soucis????
télécharge OTMoveIt
http://oldtimer.geekstogo.com/OTMoveIt3.exe (de Old_Timer) sur ton Bureau.
double-clique sur OTMoveIt.exe pour le lancer.
copie la liste qui se trouve en citation ci-dessous,
et colle-la dans le cadre de gauche de OTMoveIt :Paste instruction for items to be moved.
(attention bien mettre :files)
:files
C:\Documents and Settings\ISABELLE\Application Data\gadcom\gadcom.exe
clique sur MoveIt! pour lancer la suppression.
le résultat apparaitra dans le cadre "Results".
clique sur Exit pour fermer.
poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.
________________
pour dernière vérification :
colle le rapport d'un scan en ligne
avec un des suivants:
Kaspersky en ligne
https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
Panda en ligne :
http://pandasoftware.fr
télécharge OTMoveIt
http://oldtimer.geekstogo.com/OTMoveIt3.exe (de Old_Timer) sur ton Bureau.
double-clique sur OTMoveIt.exe pour le lancer.
copie la liste qui se trouve en citation ci-dessous,
et colle-la dans le cadre de gauche de OTMoveIt :Paste instruction for items to be moved.
(attention bien mettre :files)
:files
C:\Documents and Settings\ISABELLE\Application Data\gadcom\gadcom.exe
clique sur MoveIt! pour lancer la suppression.
le résultat apparaitra dans le cadre "Results".
clique sur Exit pour fermer.
poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.
________________
pour dernière vérification :
colle le rapport d'un scan en ligne
avec un des suivants:
Kaspersky en ligne
https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
Panda en ligne :
http://pandasoftware.fr
Cookie/Xiti Cookie de surveillance Latent(e) Afficher +Infos
1. C:\Documents and Settings\ISABELLE\Cookies\isabelle@xiti[1].txt
Cookie/Serving... Cookie de surveillance Latent(e) Afficher +Infos
1. C:\Documents and Settings\ISABELLE\Cookies\isabelle@bs.serving-sys[2].txt
Cookie/Smartad... Cookie de surveillance Latent(e) Afficher +Infos
1. C:\Documents and Settings\ISABELLE\Cookies\isabelle@smartadserver[1].txt
Cookie/YieldMa... Cookie de surveillance Latent(e) Afficher +Infos
1. C:\Documents and Settings\ISABELLE\Cookies\isabelle@ad.yieldmanager[1].txt
Cookie/Serving... Cookie de surveillance Latent(e) Afficher +Infos
1. C:\Documents and Settings\ISABELLE\Cookies\isabelle@serving-sys[1].txt
Cookie/Weboram... Cookie de surveillance Latent(e) Afficher +Infos
1. C:\Documents and Settings\ISABELLE\Cookies\isabelle@weborama[1].txt
Cookie/RealMed... Cookie de surveillance Latent(e) Afficher +Infos
1. C:\Documents and Settings\ISABELLE\Cookies\isabelle@247realmedia[1].txt
Cookie/Atlas D... Cookie de surveillance Latent(e) Afficher +Infos
1. C:\Documents and Settings\ISABELLE\Cookies\isabelle@atdmt[1].txt
Cookie/Doublec... Cookie de surveillance Latent(e) Afficher +Infos
1. C:\Documents and Settings\ISABELLE\Cookies\isabelle@xiti[1].txt
Cookie/Serving... Cookie de surveillance Latent(e) Afficher +Infos
1. C:\Documents and Settings\ISABELLE\Cookies\isabelle@bs.serving-sys[2].txt
Cookie/Smartad... Cookie de surveillance Latent(e) Afficher +Infos
1. C:\Documents and Settings\ISABELLE\Cookies\isabelle@smartadserver[1].txt
Cookie/YieldMa... Cookie de surveillance Latent(e) Afficher +Infos
1. C:\Documents and Settings\ISABELLE\Cookies\isabelle@ad.yieldmanager[1].txt
Cookie/Serving... Cookie de surveillance Latent(e) Afficher +Infos
1. C:\Documents and Settings\ISABELLE\Cookies\isabelle@serving-sys[1].txt
Cookie/Weboram... Cookie de surveillance Latent(e) Afficher +Infos
1. C:\Documents and Settings\ISABELLE\Cookies\isabelle@weborama[1].txt
Cookie/RealMed... Cookie de surveillance Latent(e) Afficher +Infos
1. C:\Documents and Settings\ISABELLE\Cookies\isabelle@247realmedia[1].txt
Cookie/Atlas D... Cookie de surveillance Latent(e) Afficher +Infos
1. C:\Documents and Settings\ISABELLE\Cookies\isabelle@atdmt[1].txt
Cookie/Doublec... Cookie de surveillance Latent(e) Afficher +Infos
[ Rapport ToolsCleaner version 2.2.6 (par A.Rothstein & dj QUIOU) ]
-->- Recherche:
C:\Documents and Settings\ISABELLE\Bureau\ComboFix.exe: trouvé !
C:\Documents and Settings\ISABELLE\Bureau\HijackThis.exe: trouvé !
---------------------------------
-->- Suppression:
C:\Documents and Settings\ISABELLE\Bureau\ComboFix.exe: ERREUR DE SUPPRESSION !!
C:\Documents and Settings\ISABELLE\Bureau\HijackThis.exe: ERREUR DE SUPPRESSION !!
-->- Recherche:
C:\Documents and Settings\ISABELLE\Bureau\ComboFix.exe: trouvé !
C:\Documents and Settings\ISABELLE\Bureau\HijackThis.exe: trouvé !
---------------------------------
-->- Suppression:
C:\Documents and Settings\ISABELLE\Bureau\ComboFix.exe: ERREUR DE SUPPRESSION !!
C:\Documents and Settings\ISABELLE\Bureau\HijackThis.exe: ERREUR DE SUPPRESSION !!
si juste un dernier truc
pour virer les virus qui seraient dans ta restauration : désactive la puis redemarre ton ordi puis réactive là
https://www.informatruc.com
bonne suite
pour virer les virus qui seraient dans ta restauration : désactive la puis redemarre ton ordi puis réactive là
https://www.informatruc.com
bonne suite