Antiviris XP pro = virus
j'ai antivirus Xp qui s'est installé et impossible de l'enlever, de la pub vient tout le temps et je peux rien faire en fait c'est un virus !! comment on le supprime ?? aidez moi svp c'est urgent
Configuration: Windows XP Firefox 3.0.7
67 réponses
Une infection d'antivirus Xp sur Windows XP provoque des publicités persistantes et bloque l’utilisation normale de l’ordinateur, nécessitant une procédure de suppression rapide et structurée. Plusieurs utilisateurs recommandent Malwarebytes' Anti-Malware, FindyKill et RSIT pour établir des rapports d’infection, puis une suppression guidée par FindyKill, avec deux redémarrages prévus et la vérification des éléments résiduels. Des étapes complémentaires mobilisent CCleaner et ComboFix, parfois via un script CFscript, et exigent de fermer les navigateurs, sauvegarder les instructions et privilégier une analyse depuis un support externe pour éviter la réinfection. En outre, le processus insiste sur l’utilisation des rapports de malware obtenus et sur la gestion des éléments de démarrage et des tâches planifiées afin de prévenir de futures intrusions.
-
Contributeur sécuritéTélécharge OTMoveIt
http://oldtimer.geekstogo.com/OTMoveIt3.exe (de Old_Timer) sur ton Bureau.
double-clique sur OTMoveIt.exe pour le lancer.
copie la liste qui se trouve en citation ci-dessous,
et colle-la dans le cadre de gauche de OTMoveIt :Paste instruction for items to be moved.
(attention bien mettre :files)
:files
hkey_local_machine\software\microsoft\windows\currentversion\uninstall\switch
C:\WINDOWS\system32\nDler.exe
C:\WINDOWS\system32\mschr.exe
\\?\globalroot\systemroot\system32\mschr.exe
clique sur MoveIt! pour lancer la suppression.
le résultat apparaitra dans le cadre "Results".
clique sur Exit pour fermer.
poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.
_______________________
puis
Désactive ta restauration systeme puis redemarre ton ordi puis réactive là comme ceci:
https://www.informatruc.com
_______________
pour virer ce qui a été utilisé
Télécharge ToolsCleaner sur ton bureau.
--> https://www.commentcamarche.net/telecharger/ 34055291 toolscleaner
# Clique sur Recherche et laisse le scan agir ...
# Clique sur Suppression pour finaliser.
# Tu peux, si tu le souhaites, te servir des Options facultatives.
# Clique sur Quitter pour obtenir le rapport.
# Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
__________________
si encore des soucis:
colle un rapport avec kaspersky en ligne
https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr -
ok ba on fini alors parce que il n'a rien changé enfaite ça bugg toujours autant
-
Contributeur sécuritéok dommage on etait a la fin
-
laisse tombé l'informaticien est venu :D
-
Contributeur sécuritétu fais entierement le message 58 et tu mets les rapports
-
ok merci tout est bon
mais pour le rest des virus je fais quoi ? -
Contributeur sécuritéinitialise firefox
http://www.commentcamarche.net/faq/sujet 9525 reinitialiser firefox reset
ou réinstalle le si l'initialisation n'a pas marché -
... j'attends des réponses
-
c'est bon mais quand je lance firefox ça bugg alors je ferme et je relance ça met restaurer la session précedente ou une nouvelle session ... j'ai testé les deux plusieurs fois et je dois refermer a chaque fois !!! je fais comment ??
-
Contributeur sécuritétélécharge OTMoveIt
http://oldtimer.geekstogo.com/OTMoveIt3.exe (de Old_Timer) sur ton Bureau.
double-clique sur OTMoveIt.exe pour le lancer.
copie la liste qui se trouve en citation ci-dessous,
et colle-la dans le cadre de gauche de OTMoveIt :Paste instruction for items to be moved.
(attention bien mettre :files)
:files
hkey_local_machine\software\microsoft\windows\currentversion\uninstall\switch
C:\WINDOWS\system32\nDler.exe
C:\WINDOWS\system32\mschr.exe
\\?\globalroot\systemroot\system32\mschr.exe
clique sur MoveIt! pour lancer la suppression.
le résultat apparaitra dans le cadre "Results".
clique sur Exit pour fermer.
poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.
_______________________
puis
Désactive ta restauration systeme puis redemarre ton ordi puis réactive là comme ceci:
https://www.informatruc.com
_______________
pour virer ce qui a été utilisé
Télécharge ToolsCleaner sur ton bureau.
--> https://www.commentcamarche.net/telecharger/ 34055291 toolscleaner
# Clique sur Recherche et laisse le scan agir ...
# Clique sur Suppression pour finaliser.
# Tu peux, si tu le souhaites, te servir des Options facultatives.
# Clique sur Quitter pour obtenir le rapport.
# Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\). -
j'ai cliqué sur désinfecter et voilà mais je fais quoi maintenant ?
-
je peux plus lancer firefox ça bugg tout le temps !!
-
;***********************************************************************************************************************************************************************************
ANALYSIS: 2009-03-23 16:21:21
PROTECTIONS: 1
MALWARE: 7
SUSPECTS: 0
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
avast! antivirus 4.8.1229 [VPS 080731-0] 4.8.1229 Yes No
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00034347 dialer.su Dialers No 0 Yes No hkey_local_machine\software\microsoft\windows\currentversion\uninstall\switch
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\Rémi\Cookies\rémi@atdmt[2].txt
00167704 Cookie/Xiti TrackingCookie No 0 Yes No C:\Documents and Settings\Rémi\Cookies\rémi@xiti[1].txt
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Rémi\Cookies\rémi@serving-sys[1].txt
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No C:\Documents and Settings\Rémi\Cookies\rémi@bs.serving-sys[1].txt
05238469 Adware/AccesMembre Adware No 0 Yes No C:\WINDOWS\system32\nDler.exe
05249759 W32/Sohanat.AS.worm Virus/Worm No 1 Yes No C:\WINDOWS\system32\mschr.exe
05249759 W32/Sohanat.AS.worm Virus/Worm Yes 2 Yes No \\?\globalroot\systemroot\system32\mschr.exe
;===================================================================================================================================================================================
SUSPECTS
Sent Location D
;===================================================================================================================================================================================
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description D
;===================================================================================================================================================================================
;=================================================================================================================================================================================== -
Contributeur sécuritéok j'attends le scan
-
un scan en ligne ça en ai a 38% et il y a 8 fichiers infectés
-
j'ai encore des virus :S
-
Contributeur sécuritéok cela devrait etre bon
vérifie avec un scan en ligne qu'il reste rien
________________
puis
Désactive ta restauration systeme puis redemarre ton ordi puis réactive là comme ceci:
https://www.informatruc.com
_______________
pour virer ce qui a été utilisé
Télécharge ToolsCleaner sur ton bureau.
--> http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
# Clique sur Recherche et laisse le scan agir ...
# Clique sur Suppression pour finaliser.
# Tu peux, si tu le souhaites, te servir des Options facultatives.
# Clique sur Quitter pour obtenir le rapport.
# Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\). -
========== FILES ==========
File/Folder c:\windows\TEMP\mc23.tmp not found.
========== REGISTRY ==========
Registry key HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run not found.
Registry key HKEY_LOCAL_MACHINE\System\ControlSet002\Services\mchInjDrv\\ deleted successfully.
HKEY_LOCAL_MACHINE\System\ControlSet002\Services\mchInjDrv\\"ImagePath"|"\??\c:\windows\TEMP\mc23.tmp" /E : value set successfully!
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\RMI~1\LOCALS~1\Temp\etilqs_0isOwTQ1wbzxIdvKexfF scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\RMI~1\LOCALS~1\Temp\fla63.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\RMI~1\LOCALS~1\Temp\fla6A.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\RMI~1\LOCALS~1\Temp\fla6B.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\RMI~1\LOCALS~1\Temp\fla6C.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\RMI~1\LOCALS~1\Temp\fla6E.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\RMI~1\LOCALS~1\Temp\fla71.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\RMI~1\LOCALS~1\Temp\fla72.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\RMI~1\LOCALS~1\Temp\fla78.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\RMI~1\LOCALS~1\Temp\fla7C.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\RMI~1\LOCALS~1\Temp\~DFBD98.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_344.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_4e8.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Rémi\Local Settings\Application Data\Mozilla\Firefox\Profiles\am9c3y3q.default\Cache\1C8AB3DEd01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Rémi\Local Settings\Application Data\Mozilla\Firefox\Profiles\am9c3y3q.default\Cache\1D41B3DDd01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Rémi\Local Settings\Application Data\Mozilla\Firefox\Profiles\am9c3y3q.default\Cache\4C98CC25d01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Rémi\Local Settings\Application Data\Mozilla\Firefox\Profiles\am9c3y3q.default\Cache\CC3CBC5Fd01 scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Rémi\Local Settings\Application Data\Mozilla\Firefox\Profiles\am9c3y3q.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Rémi\Local Settings\Application Data\Mozilla\Firefox\Profiles\am9c3y3q.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Rémi\Local Settings\Application Data\Mozilla\Firefox\Profiles\am9c3y3q.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Rémi\Local Settings\Application Data\Mozilla\Firefox\Profiles\am9c3y3q.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Rémi\Local Settings\Application Data\Mozilla\Firefox\Profiles\am9c3y3q.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.9.0 log created on 03232009_155437
Files moved on Reboot...
File C:\DOCUME~1\RMI~1\LOCALS~1\Temp\etilqs_0isOwTQ1wbzxIdvKexfF not found!
File C:\DOCUME~1\RMI~1\LOCALS~1\Temp\fla63.tmp not found!
File C:\DOCUME~1\RMI~1\LOCALS~1\Temp\fla6A.tmp not found!
File C:\DOCUME~1\RMI~1\LOCALS~1\Temp\fla6B.tmp not found!
File C:\DOCUME~1\RMI~1\LOCALS~1\Temp\fla6C.tmp not found!
File C:\DOCUME~1\RMI~1\LOCALS~1\Temp\fla6E.tmp not found!
File C:\DOCUME~1\RMI~1\LOCALS~1\Temp\fla71.tmp not found!
File C:\DOCUME~1\RMI~1\LOCALS~1\Temp\fla72.tmp not found!
File C:\DOCUME~1\RMI~1\LOCALS~1\Temp\fla78.tmp not found!
File C:\DOCUME~1\RMI~1\LOCALS~1\Temp\fla7C.tmp not found!
C:\DOCUME~1\RMI~1\LOCALS~1\Temp\~DFBD98.tmp moved successfully.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File C:\WINDOWS\temp\Perflib_Perfdata_344.dat not found!
C:\WINDOWS\temp\Perflib_Perfdata_4e8.dat moved successfully.
C:\Documents and Settings\Rémi\Local Settings\Application Data\Mozilla\Firefox\Profiles\am9c3y3q.default\Cache\1C8AB3DEd01 moved successfully.
C:\Documents and Settings\Rémi\Local Settings\Application Data\Mozilla\Firefox\Profiles\am9c3y3q.default\Cache\1D41B3DDd01 moved successfully.
C:\Documents and Settings\Rémi\Local Settings\Application Data\Mozilla\Firefox\Profiles\am9c3y3q.default\Cache\4C98CC25d01 moved successfully.
C:\Documents and Settings\Rémi\Local Settings\Application Data\Mozilla\Firefox\Profiles\am9c3y3q.default\Cache\CC3CBC5Fd01 moved successfully.
C:\Documents and Settings\Rémi\Local Settings\Application Data\Mozilla\Firefox\Profiles\am9c3y3q.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Rémi\Local Settings\Application Data\Mozilla\Firefox\Profiles\am9c3y3q.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Rémi\Local Settings\Application Data\Mozilla\Firefox\Profiles\am9c3y3q.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Rémi\Local Settings\Application Data\Mozilla\Firefox\Profiles\am9c3y3q.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Rémi\Local Settings\Application Data\Mozilla\Firefox\Profiles\am9c3y3q.default\urlclassifier3.sqlite moved successfully. -
Contributeur sécuritétélécharge OTMoveIt
http://oldtimer.geekstogo.com/OTMoveIt3.exe (de Old_Timer) sur ton Bureau.
double-clique sur OTMoveIt.exe pour le lancer.
copie la liste qui se trouve en citation ci-dessous,
et colle-la dans le cadre de gauche de OTMoveIt :Paste instruction for items to be moved.
(attention bien mettre :files)
:files
c:\windows\TEMP\mc23.tmp
:reg
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Java S1"=-
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\mchInjDrv]
"ImagePath"="\??\c:\windows\TEMP\mc23.tmp"
:commands
[purity]
[emptytemp]
[start explorer]
clique sur MoveIt! pour lancer la suppression.
le résultat apparaitra dans le cadre "Results".
clique sur Exit pour fermer.
poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.
___________________
Télécharge ToolsCleaner sur ton bureau.
--> http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
# Clique sur Recherche et laisse le scan agir ...
# Clique sur Suppression pour finaliser.
# Tu peux, si tu le souhaites, te servir des Options facultatives.
# Clique sur Quitter pour obtenir le rapport.
# Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
____________________
colle le rapport d'un scan en ligne
avec un des suivants:
bitdefender en ligne :
http://www.bitdefender.fr/scan_fr/scan8/ie.html
Panda en ligne :
http://pandasoftware.fr
Kaspersky en ligne
https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr -
oui g tout viré tkt
voilà la suite
c:\documents and settings\Rémi\Application Data\HbTools\v3.0\HostOI\static\DownLoad\linkpathlegal.xip
c:\documents and settings\Rémi\Application Data\HbTools\v3.0\HostOI\static\DownLoad\localcontent.xip
c:\documents and settings\Rémi\Application Data\HbTools\v3.0\HostOI\static\DownLoad\progress.xip
c:\documents and settings\Rémi\Application Data\HbTools\v3.0\HostOI\static\DownLoad\treexml.xip
c:\documents and settings\Rémi\Menu Démarrer\Programmes\AntivirusXP
c:\documents and settings\Rémi\Menu Démarrer\Programmes\AntivirusXP\AntivirusXP.lnk
c:\program files\Microsoft Common
c:\program files\Microsoft Common\svchost.exe
c:\windows\fxsteller.exe
c:\windows\patch.exe
c:\windows\Plaheb.dll
c:\windows\system32\1000.exe
c:\windows\system32\303369.exe
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\ahtn.htm
c:\windows\system32\drivers\senekaulkdqxwk.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\frmwrk32.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\KuzSmall.exe
c:\windows\system32\ntdll64.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\senekabeedyscx.dat
c:\windows\system32\senekajkdksqcw.dll
c:\windows\system32\senekanmfveovr.dll
c:\windows\system32\senekawxupauwy.dat
c:\windows\system32\senekaybwrtudp.dll
c:\windows\system32\SrchSTS.exe
c:\windows\system32\stera.log
c:\windows\system32\tmp.reg
c:\windows\system32\uniq.tll
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\warning.gif
c:\windows\system32\win32hlp.cnf
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_BOONTY_GAMES
-------\Legacy_FOPN
-------\Legacy_FWSVC
-------\Legacy_VSPF
-------\Legacy_VSPF_HK
-------\Service_Boonty Games
-------\Service_seneka
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-23 au 2009-03-23 ))))))))))))))))))))))))))))))))))))
.
2009-03-23 09:18 . 2009-03-23 09:18 <REP> d-------- c:\windows\system32\NtmsData
2009-03-21 21:58 . 2009-03-21 21:58 <REP> d--hs---- C:\found.000
2009-03-20 18:43 . 2009-03-20 18:43 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-20 18:43 . 2009-03-22 15:37 <REP> d-------- c:\program files\FindyKill
2009-03-20 18:43 . 2009-03-20 18:43 <REP> d-------- c:\documents and settings\Rémi\Application Data\Malwarebytes
2009-03-20 18:43 . 2009-03-20 18:43 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-20 18:43 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-20 18:43 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-17 20:48 . 2009-03-22 15:21 <REP> d-------- c:\program files\Navilog1
2009-03-17 19:38 . 2009-03-17 19:39 <REP> d-------- C:\rsit
2009-03-17 19:38 . 2009-03-22 15:46 <REP> d-------- c:\program files\trend micro
2009-03-13 21:13 . 2009-03-17 20:39 <REP> d-------- c:\program files\RogueRemover FREE
2009-03-13 20:59 . 2009-03-13 20:59 456,734 --a------ c:\windows\system32\mschr.exe
2009-03-13 20:59 . 2009-03-13 20:59 36,864 --a------ c:\windows\system32\nDler.exe
2009-03-13 20:32 . 2009-03-13 20:51 <REP> d-------- c:\program files\MSNFix
2009-03-13 20:05 . 2009-03-13 20:05 <REP> d-------- c:\program files\Fichiers communs\Windows Live
2009-03-13 18:52 . 2009-03-13 18:51 104,960 --a--c--- c:\windows\system32\dllcache\userinit.exe
2009-02-27 21:25 . 2009-02-27 21:25 <REP> d-------- c:\program files\Blender Foundation
2009-02-27 21:25 . 2009-02-27 21:25 <REP> d-------- c:\documents and settings\Rémi\Application Data\Blender Foundation
2009-02-26 19:21 . 2009-03-04 16:51 <REP> d-------- c:\documents and settings\Laurane\Application Data\Apple Computer
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-23 10:55 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-03-22 13:29 --------- d-----w c:\program files\MessengerDiscovery
2009-03-21 19:57 --------- d-----w c:\documents and settings\All Users\Application Data\TrackMania
2009-03-20 17:52 --------- d-----w c:\program files\Microsoft SQL Server
2009-03-19 17:19 --------- d-----w c:\program files\adslTV
2009-03-19 11:17 --------- d-----w c:\program files\QuickTime
2009-03-17 18:21 --------- d-----w c:\program files\Windows Live Safety Center
2009-03-17 16:53 --------- d-----w c:\program files\LimeWire
2009-03-17 16:53 --------- d-----w c:\program files\Alexandra Ledermann - La colline aux chevaux sauvages
2009-03-15 17:35 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-10 16:41 --------- d-----w c:\program files\eMule
2009-03-07 17:27 --------- d-----w c:\documents and settings\Rémi\Application Data\LimeWire
2009-02-26 16:54 --------- d-----w c:\program files\Microsoft Silverlight
2009-02-22 19:41 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-22 19:39 --------- d-----w c:\program files\Activision
2009-02-20 18:50 921,600 ----a-w C:\SQ.bin
2009-02-18 18:14 --------- d-----w c:\documents and settings\LocalService\Application Data\agi
2009-02-18 18:14 --------- d-----w c:\documents and settings\Laurane\Application Data\agi
2009-02-18 18:13 --------- d-----w c:\program files\Kiwee Toolbar
2009-02-13 14:01 --------- d-----w c:\program files\Dofus
2009-02-10 16:20 --------- d-----w c:\program files\Google
2009-02-04 17:56 --------- d-----w c:\documents and settings\Rémi\Application Data\Nvu
2009-02-04 17:13 --------- d-----w c:\program files\WebSite X5 Evolution
2009-02-04 16:06 --------- d-----w c:\program files\XWebDesignor
2009-02-04 16:05 --------- d-----w c:\program files\Nvu
2009-02-04 16:02 --------- d-----w c:\program files\Lauyan
2009-02-01 18:56 --------- d-----w c:\program files\Namo
2009-02-01 18:55 --------- d-----w c:\documents and settings\Rémi\Application Data\InstallShield
2009-01-31 17:48 --------- d-----w c:\program files\Intuisphere
2009-01-31 10:58 --------- d-----w c:\program files\Ubisoft
2009-01-30 08:09 --------- d-----w c:\program files\Metin2_France
2009-01-30 08:09 --------- d-----w c:\program files\Cheat Engine
2009-01-29 13:09 --------- d-----w c:\documents and settings\Rémi\Application Data\codeblocks
2009-01-29 13:07 --------- d-----w c:\program files\CodeBlocks
2009-01-29 13:02 --------- d-----w c:\program files\poEdit
2009-01-29 12:59 --------- d-----w c:\program files\codeblocks-fr
2009-01-25 09:51 --------- d-----w c:\documents and settings\Rémi\Application Data\Dev-Cpp
2008-04-07 16:53 80,864 -c--a-w c:\documents and settings\Rémi\Application Data\GDIPFONTCACHEV1.DAT
2008-03-16 15:41 0 -c--a-w c:\program files\temp01
2006-04-14 07:17 0 -c--a-w c:\documents and settings\Rémi\Application Data\wklnhst.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-17 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-12-01 7311360]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-21 136600]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-04-23 185896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Java S1"="\\?\globalroot\systemroot\system32\mschr.exe" [?]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Spyware Doctor"="c:\program files\Spyware Doctor\swdoctor.exe" [2006-12-11 2115728]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
"NoActiveDesktopChanges"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.iv41"= ir41_32.dll
"VIDC.X264"= x264vfw.dll
"VIDC.3iv2"= 3ivxVfWCodec.dll
"msvideo9"= SDVC03.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\[u]0/u?????
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
backup=c:\windows\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech SetPoint.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Rémi^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 2.3.lnk]
path=c:\documents and settings\Rémi\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 2.3.lnk
backup=c:\windows\pss\OpenOffice.org 2.3.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Rémi^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 3.0.lnk]
path=c:\documents and settings\Rémi\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 3.0.lnk
backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
--a------ 2007-03-16 10:45 63712 c:\program files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-10-15 01:04 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-14 03:33 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2007-05-08 16:24 54840 c:\program files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-11-20 13:20 290088 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
--a------ 2007-03-10 13:11 67128 c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
--a--c--- 2005-05-03 09:22 53248 c:\program files\MUSICMATCH\Musicmatch Jukebox\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
--a------ 2005-05-03 09:22 135168 c:\program files\MUSICMATCH\Musicmatch Jukebox\mm_tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2007-10-18 11:34 5724184 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2005-12-01 13:02 7311360 c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-11-04 10:30 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spyware Doctor]
--a------ 2006-12-11 15:35 2115728 c:\program files\Spyware Doctor\swdoctor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\STICAP]
--a------ 2004-11-05 08:59 155648 c:\windows\twain_32\USB2.0Camera\SnapTrap.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2009-01-21 18:20 136600 c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-06-17 10:16 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-04-23 19:35 185896 c:\program files\Fichiers communs\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
--a------ 2008-09-26 19:14 3660848 c:\program files\Veoh Networks\Veoh\VeohClient.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeohPlugin]
--a------ 2008-10-09 23:11 3502840 c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
--a------ 2005-05-20 14:46 28160 c:\windows\KHALMNPR.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2005-12-01 13:02 1519616 c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
--a------ 2005-11-11 14:07 90112 c:\windows\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\MessengerDiscovery\\MessengerDiscovery Live.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-04-01 78416]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-04-01 20560]
S2 gupdate1c98b9abbe953e8;Google Update Service (gupdate1c98b9abbe953e8);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-10 133104]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-03-20 38496]
S3 PLCMP532;PLCMP532 NDIS Protocol Driver;c:\windows\system32\Drivers\PLCMP532.sys --> c:\windows\system32\Drivers\PLCMP532.sys [?]
S3 PLCND532;PLCND532 NDIS Protocol Driver;c:\windows\system32\drivers\PLCND532.sys [2007-02-07 26656]
S3 SDVC05;USB SDVC05;c:\windows\system32\drivers\SDVC05.sys [2007-08-17 18088]
S3 SQTECH930B;USB 2.0 PC CAMERA;c:\windows\system32\drivers\Capt930b.sys [2006-05-06 247325]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - mchInjDrv
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\I]
\Shell\AutoRun\command - I:\Launch.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f3e8462a-baec-11dc-93ba-0015f2585dd2}]
\Shell\AutoRun\command - D:\Imageviewer.exe
.
Contenu du dossier 'Tâches planifiées'
2009-03-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-03-23 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-23 09:08]
2009-03-23 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-10 17:15]
2009-03-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2849272039-2815165872-511180383-1007.job
- c:\documents and settings\Francis\Local Settings\Application Data\Google\Update\GoogleUpdate.exe []
2009-02-27 c:\windows\Tasks\Norton Security Scan.job
- c:\program files\Norton Security Scan\Nss.exe [2007-04-19 22:42]
2009-03-23 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE []
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-Nxuyagogagimogo - c:\windows\Plaheb.dll
MSConfigStartUp-fsc-reminder - c:\windows\reminder\fsc-reminder.exe
MSConfigStartUp-Steam - c:\program files\Steam\Steam.exe
MSConfigStartUp-Yahoo! Pager - c:\program files\Yahoo!\Messenger\ypager.exe
.
------- Examen supplémentaire -------
.
uInternet Settings,ProxyOverride = *.local
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Add to AMV Convert Tool... - c:\program files\MP3 Player Utilities 3.79\AMVConverter\grab.html
IE: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
IE: MediaManager tool grab multimedia file - c:\program files\MP3 Player Utilities 3.79\MediaManager\grab.html
TCP: {C06439F4-A9EC-433E-A511-08C6186E6ADE} = 212.30.96.108,213.203.124.146
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} - hxxps://secure.gopetslive.com/dev/GoPetsWeb.cab
FF - ProfilePath - c:\documents and settings\Rémi\Application Data\Mozilla\Firefox\Profiles\am9c3y3q.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
FF - prefs.js: browser.search.selectedEngine - Search the Web
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - prefs.js: keyword.URL - hxxp://search.freecause.com/search?fr=freecause&ourmark=3&type=59831&ei=utf-8&yahoo_domain=search.yahoo.com&p=
FF - component: c:\documents and settings\Rémi\Application Data\Mozilla\Firefox\Profiles\am9c3y3q.default\extensions\{d3b6a240-5dc8-4180-8ce9-492ebe2ba75b}\components\Engine.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\program files\Google\Google Earth Plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Microsoft Silverlight\2.0.40115.0\npctrl.1.0.20926.0.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF - plugin: c:\program files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-23 14:56:30
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\mchInjDrv]
"ImagePath"="\??\c:\windows\TEMP\mc23.tmp"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-2849272039-2815165872-511180383-1009\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:67,0f,8b,48,62,20,1e,a2,69,51,34,28,cf,82,6e,17,9a,46,f7,30,44,8c,46,
70,08,03,7c,4c,aa,fe,68,2c,91,39,58,d6,67,11,7d,6b,5b,39,59,fc,57,b3,ff,72,\
"??"=hex:14,f5,c2,7f,8d,87,57,1a,eb,18,de,19,76,27,e9,94
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"C040211900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Spyware Doctor\sdhelp.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Alwil Software\Avast4\ashDisp.exe
c:\program files\MessengerDiscovery\MessengerDiscovery Live.exe
c:\program files\Mozilla Firefox\firefox.exe
.
**************************************************************************
.
Heure de fin: 2009-03-23 15:02:34 - La machine a redémarré [Rémi]
ComboFix-quarantined-files.txt 2009-03-23 14:02:30
Avant-CF: 178,959,970,304 octets libres
Après-CF: 179,683,360,768 octets libres
1304 --- E O F --- 2009-03-21 19:53:18
- 1
- 2
- 3
- 4