Pub cid
Des pubs CID s'affichent sans arrêt quand j'ouvre une page internet. Il y a quelques jours, elles s'ouvraient en rafale.. J'ai regardé sur des forums pour résoudre le problème mais j'ai pas vraiment compris comment il fallait s'y prendre. Pouvez vous m'aider? Merci d'avance.
Configuration: Windows XP Internet Explorer 7.0
47 réponses
Des publicités CID s'affichent de manière répétée lors de l'ouverture de pages et apparaissent en rafale, indiquant une infection potentielle ou une configuration publicitaire indésirable. Plusieurs solutions ont été proposées, notamment l’utilisation d’outils de diagnostic et de nettoyage tels que HijackThis, SDFix et des scans avec ComboFix ou Malwarebytes, pour identifier et supprimer les éléments indésirables. Les échanges précisent des détails pratiques: exécuter les outils, enregistrer et partager les rapports, puis déconnecter d’internet et désactiver temporairement l’antivirus lors de l’utilisation de ComboFix. En dernier élément, un test avec Malwarebytes a donné des résultats négatifs sur les éléments malveillants détectables, signalant que l’infection n’était pas nécessairement présente dans le système à ce moment-là.
-
Contributeur sécuritésalut
Attention aux cracks, c'est un important vecteur d'infection (télécharger un crack ou même visiter un site de crack a de grandes chances d'infecter l'ordinateur) : plus de 40%des infections
1-IMPORTANT :
je rappelle que bagle est amené par un crack et qu'il se relance dès que tu te sers de celui ci; même si tu ne sers pas, il peut se relancer de lui même au démarrage de ton PC . En claire :
Essayes surtout de te rappeler si récemment tu n' as pas clicker sur un "patch" ou un "keygen" pour installer un logiciel, un jeu cracké ou avoir une version complète d'un soft , et qu'il ne se soit rien passé de particulier ... C'est la que les bagles s'infiltrent ! Si tu retrouves ce crack en particulier ,scratch tout ( le crack, le soft ou encore les zip concernés). Si tu ne te rappelles plus trop , je te conseille fortement de supprimer tous les cracks qui sont sur ton PC ... ;)
https://forum.malekal.com/viewtopic.php?f=33&t=893
Si tu en as, il faut les supprimer, ou il vont réinfecter continuellement ton pc...
fait un scan antivirus en ligne içi
https://www.trendmicro.com/en_us/forHome/products/housecall.html
et içi pour finir
http://www.bitdefender.fr/scan_fr/scan8/ie.html
-
voila le 2eme rappor
"C:\Documents and Settings\HP_Administrateur\Bureau\ToolBar SD\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 16/04/2009|12:12 )
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.msn.com/fr-fr"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Default_Search_URL"="http://ie.redirect.hp.com/..."
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.msn.com/fr-fr/"
"Search Bar"="http://ie.redirect.hp.com/..."
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\HP_ADM~1\Mes documents\Ma musique\Rockin' Squat - Too Hot For TV-2007-BY POPOF\05 Crack game.mp3
1 - "C:\Documents and Settings\HP_Administrateur\Bureau\ToolBar SD\ToolBar SD\TB_1.txt" - 15/04/2009| 7:19 - Option : [1]
2 - "C:\Documents and Settings\HP_Administrateur\Bureau\ToolBar SD\ToolBar SD\TB_2.txt" - 15/04/2009| 7:21 - Option : [2]
3 - "C:\Documents and Settings\HP_Administrateur\Bureau\ToolBar SD\ToolBar SD\TB_3.txt" - 16/04/2009|12:12 - Option : [2]
-----------\\ Fin du rapport a 12:12:51,14 -
salut, voici le rapport
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3500+ )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : HP_Administrateur ( Administrator )
BOOT : Normal boot
Antivirus : Bitdefender Antivirus 8.0 (Activated)
Firewall : Bitdefender Firewall 8.0 (Activated)
C:\ (Local Disk) - NTFS - Total:142 Go (Free:76 Go)
D:\ (Local Disk) - FAT32 - Total:6 Go (Free:1 Go)
E:\ (CD or DVD)
G:\ (USB)
H:\ (USB)
I:\ (USB)
J:\ (USB)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 16/04/2009|12:09 )
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.msn.com/fr-fr"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Default_Search_URL"="https://fr.search.yahoo.com/?fr=cb-hp06"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="https://www.msn.com/fr-fr/"
"Search Bar"="https://fr.search.yahoo.com/?fr=cb-hp06"
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\HP_ADM~1\Bureau\ToolBar SD\ToolBar SD\Crack.txt
C:\DOCUME~1\HP_ADM~1\Mes documents\Ma musique\Rockin' Squat - Too Hot For TV-2007-BY POPOF\05 Crack game.mp3
1 - "C:\ToolBar SD\TB_1.txt" - 16/04/2009|12:10 - Option : [1]
-----------\\ Fin du rapport a 12:10:22,56 -
Contributeur sécuritéOK y'a du mieux on s'occupe du reste après
Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2
* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de Toolbar-S&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
* Poste le rapport généré. (C:\TB.txt)
* Relance Toolbar-S&D en double-cliquant sur son raccourci situé sur le Bureau. Tape sur "2" puis valide en appuyant sur "Entrée". Ne ferme pas la fenêtre lors de la suppression. Un rapport sera généré, sauvegarde-le.
-
salut, voici le rapport Combofix
ComboFix 09-04-14.09 - HP_Administrateur 14/04/2009 19:43.3 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.958.642 [GMT 2:00]
Lancé depuis: c:\documents and settings\HP_Administrateur\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\HP_Administrateur\Bureau\CFScript.txt..txt
AV: Bitdefender Antivirus *On-access scanning enabled* (Updated)
FW: Bitdefender Firewall *enabled*
* Un nouveau point de restauration a été créé
FILE ::
c:\program files\Uninstall Ask Toolbar.dll
c:\temp\atmp8
c:\windows\QTFont.for
c:\windows\QTFont.qfn
c:\windows\system32\biruwuta.dll
c:\windows\system32\bitipote.dll
c:\windows\system32\bowafefi.dll
c:\windows\system32\dadopuga.dll
c:\windows\system32\delopeha.dll
c:\windows\system32\dewozuzi.dll
c:\windows\system32\firotapa.dll
c:\windows\system32\fizipime.dll
c:\windows\system32\gakewake.dll
c:\windows\system32\gukevewi.dll
c:\windows\system32\honimava.dll
c:\windows\system32\jedepona.dll
c:\windows\system32\jezosudo.dll
c:\windows\system32\jobavito.dll
c:\windows\system32\jojesira.dll
c:\windows\system32\juyimebo.dll
c:\windows\system32\kidapita.dll
c:\windows\system32\lasobemo.dll
c:\windows\system32\lowopami.dll
c:\windows\system32\malufige.dll
c:\windows\system32\minutara.dll
c:\windows\system32\nevibuni.dll
c:\windows\system32\nilejonu.dll
c:\windows\system32\notabage.exe
c:\windows\system32\nuwiyidi.dll
c:\windows\system32\pelozeho.dll
c:\windows\system32\pemivubu.dll
c:\windows\system32\perfc00C.dat
c:\windows\system32\perfh00C.dat
c:\windows\system32\powipogi.exe
c:\windows\system32\pulemebo.dll
c:\windows\system32\razoriti.dll
c:\windows\system32\rojideze.exe
c:\windows\system32\rupibemo.dll
c:\windows\system32\rusahene.exe
c:\windows\system32\ruyebana.dll
c:\windows\system32\sayoroso.dll
c:\windows\system32\seratewa.dll
c:\windows\system32\serubifa.exe
c:\windows\system32\sikezovo.dll
c:\windows\system32\tayufazu.dll
c:\windows\system32\tisawipu.dll
c:\windows\system32\vezeyege.dll
c:\windows\system32\vodarowo.dll
c:\windows\system32\vosubupa.dll
c:\windows\system32\yabuvasu.dll
c:\windows\system32\yapigifa.dll
c:\windows\system32\yuvukina.dll
c:\windows\system32\yuwegiju.dll
c:\windows\system32\zafugiho.dll
c:\windows\system32\zitajalu.dll
c:\windows\system32\zubadira.dll
c:\windows\system32\zulelolo.dll
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Uninstall Ask Toolbar.dll
c:\temp\atmp8
c:\temp\atmp8\ead.log
c:\windows\system32\biruwuta.dll
c:\windows\system32\bitipote.dll
c:\windows\system32\bowafefi.dll
c:\windows\system32\dadopuga.dll
c:\windows\system32\delopeha.dll
c:\windows\system32\dewozuzi.dll
c:\windows\system32\firotapa.dll
c:\windows\system32\fizipime.dll
c:\windows\system32\gakewake.dll
c:\windows\system32\gukevewi.dll
c:\windows\system32\jedepona.dll
c:\windows\system32\jezosudo.dll
c:\windows\system32\jobavito.dll
c:\windows\system32\jojesira.dll
c:\windows\system32\juyimebo.dll
c:\windows\system32\kidapita.dll
c:\windows\system32\lasobemo.dll
c:\windows\system32\lowopami.dll
c:\windows\system32\malufige.dll
c:\windows\system32\minutara.dll
c:\windows\system32\nevibuni.dll
c:\windows\system32\nilejonu.dll
c:\windows\system32\notabage.exe
c:\windows\system32\pelozeho.dll
c:\windows\system32\perfc00C.dat
c:\windows\system32\perfh00C.dat
c:\windows\system32\powipogi.exe
c:\windows\system32\pulemebo.dll
c:\windows\system32\razoriti.dll
c:\windows\system32\rojideze.exe
c:\windows\system32\rupibemo.dll
c:\windows\system32\rusahene.exe
c:\windows\system32\ruyebana.dll
c:\windows\system32\sayoroso.dll
c:\windows\system32\seratewa.dll
c:\windows\system32\serubifa.exe
c:\windows\system32\sikezovo.dll
c:\windows\system32\tayufazu.dll
c:\windows\system32\vezeyege.dll
c:\windows\system32\vodarowo.dll
c:\windows\system32\vosubupa.dll
c:\windows\system32\yabuvasu.dll
c:\windows\system32\yapigifa.dll
c:\windows\system32\yuvukina.dll
c:\windows\system32\zafugiho.dll
c:\windows\system32\zitajalu.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-03-14 au 2009-04-14 ))))))))))))))))))))))))))))))))))))
.
2009-04-10 11:50 . 2009-04-10 11:50 579584 ----a-w c:\windows\system32\dllcache\user32.dll
2009-04-10 11:47 . 2009-04-11 14:33 -------- d-----w C:\SDFix
2009-04-10 11:37 . 2009-04-10 11:37 -------- d-----w c:\windows\ERUNT
2009-04-02 08:06 . 2009-03-26 14:49 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-02 08:06 . 2009-03-26 14:49 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-30 07:18 . 2009-03-30 07:18 -------- d-----w c:\documents and settings\HP_Administrateur\Application Data\Malwarebytes
2009-03-30 07:18 . 2009-04-11 14:33 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-03-30 07:18 . 2009-03-30 07:18 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-29 08:26 . 2009-03-30 07:33 -------- d-----w c:\program files\Lopxp
2009-03-28 13:48 . 2009-03-30 07:47 -------- d-----w C:\Lop SD
2009-03-27 17:34 . 2009-03-28 12:26 -------- d-----w c:\program files\Navilog1
2009-03-27 12:48 . 2009-03-27 12:48 -------- d-----w c:\program files\Trend Micro
2009-03-27 11:10 . 2009-03-27 11:10 -------- d-sh--w c:\documents and settings\LocalService\IETldCache
2009-03-27 11:08 . 2009-03-27 11:08 -------- d-sh--w c:\documents and settings\HP_Administrateur\IECompatCache
2009-03-27 11:07 . 2009-03-27 11:07 -------- d-sh--w c:\documents and settings\HP_Administrateur\PrivacIE
2009-03-27 11:03 . 2009-03-27 11:03 -------- d-sh--w c:\documents and settings\HP_Administrateur\IETldCache
2009-03-27 10:38 . 2009-03-27 10:42 -------- dc-h--w c:\windows\ie8
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-13 09:00 . 2009-02-17 14:12 -------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-03-30 07:49 . 2009-03-28 13:49 17097 ----a-w C:\lopR.txt
2009-03-29 12:35 . 2008-10-04 10:11 -------- d-----w c:\documents and settings\HP_Administrateur\Application Data\OpenOffice.org2
2009-03-28 12:17 . 2009-03-28 12:01 2763 ----a-w C:\cleannavi.txt
2009-03-28 12:01 . 2009-03-27 17:36 2689 ----a-w C:\fixnavi.txt
2009-03-28 09:30 . 2007-06-22 08:23 81984 ----a-w c:\windows\system32\bdod.bin
2009-03-24 06:00 . 2007-02-01 22:54 -------- d-----w c:\program files\AskTBar
2009-03-22 12:50 . 2006-08-14 14:25 -------- d-----w c:\program files\Google
2009-03-22 12:35 . 2007-08-03 09:47 -------- d-----w c:\program files\Windows Live
2009-03-22 12:31 . 2006-08-14 14:05 -------- d--h--w c:\program files\InstallShield Installation Information
2009-03-22 12:31 . 2006-08-14 14:07 -------- d-----w c:\program files\Fichiers communs\muvee Technologies
2009-03-22 12:30 . 2008-12-20 19:01 -------- d-----w c:\program files\Veetle
2009-03-22 12:28 . 2008-11-28 12:51 -------- d-----w c:\documents and settings\HP_Administrateur\Application Data\Samsung
2009-03-21 12:25 . 2007-06-22 18:45 -------- d-----w c:\program files\Windows Live Safety Center
2009-03-20 20:13 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\vulabiro.dll
2009-03-20 20:13 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\sogoruro.dll
2009-03-20 20:13 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\pokefige.dll
2009-03-20 08:24 . 2006-12-04 16:10 24758 ----a-w c:\documents and settings\HP_Administrateur\Application Data\wklnhst.dat
2009-03-14 08:11 . 2009-03-14 08:11 -------- d-----w c:\program files\Microsoft
2009-03-14 08:10 . 2009-03-14 08:10 -------- d-----w c:\program files\Windows Live SkyDrive
2009-03-08 13:09 . 2004-08-10 11:00 638816 ----a-w c:\windows\system32\dllcache\iexplore.exe
2009-03-08 13:09 . 2004-08-10 11:00 391536 ----a-w c:\windows\system32\dllcache\iedkcs32.dll
2009-03-08 03:41 . 2004-08-10 11:00 5937152 ----a-w c:\windows\system32\dllcache\mshtml.dll
2009-03-08 03:39 . 2007-04-25 07:39 11063808 ----a-w c:\windows\system32\dllcache\ieframe.dll
2009-03-08 03:34 . 2004-08-10 11:00 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 03:34 . 2004-08-10 11:00 914944 ----a-w c:\windows\system32\dllcache\wininet.dll
2009-03-08 03:34 . 2004-08-10 11:00 1206784 ----a-w c:\windows\system32\dllcache\urlmon.dll
2009-03-08 03:34 . 2004-08-10 11:00 236544 ----a-w c:\windows\system32\dllcache\webcheck.dll
2009-03-08 03:34 . 2004-08-10 11:00 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 03:34 . 2004-08-10 11:00 43008 ----a-w c:\windows\system32\dllcache\licmgr10.dll
2009-03-08 03:34 . 2004-08-10 11:00 105984 ----a-w c:\windows\system32\dllcache\url.dll
2009-03-08 03:34 . 2004-08-10 11:00 193536 ----a-w c:\windows\system32\dllcache\msrating.dll
2009-03-08 03:34 . 2004-08-10 11:00 109568 ----a-w c:\windows\system32\dllcache\occache.dll
2009-03-08 03:33 . 2004-08-10 11:00 759296 ----a-w c:\windows\system32\dllcache\VGX.dll
2009-03-08 03:33 . 2009-03-08 03:33 18944 ------w c:\windows\system32\dllcache\corpol.dll
2009-03-08 03:33 . 2004-08-10 11:00 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 03:33 . 2004-08-10 11:00 25600 ----a-w c:\windows\system32\dllcache\jsproxy.dll
2009-03-08 03:33 . 2008-05-09 10:55 726528 ----a-w c:\windows\system32\dllcache\jscript.dll
2009-03-08 03:33 . 2004-08-10 11:00 229376 ----a-w c:\windows\system32\dllcache\ieaksie.dll
2009-03-08 03:33 . 2008-05-09 10:55 420352 ----a-w c:\windows\system32\dllcache\vbscript.dll
2009-03-08 03:33 . 2004-08-10 11:00 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 03:33 . 2004-08-10 11:00 125952 ----a-w c:\windows\system32\dllcache\ieakeng.dll
2009-03-08 03:32 . 2004-08-10 11:00 72704 ----a-w c:\windows\system32\dllcache\admparse.dll
2009-03-08 03:32 . 2004-08-10 11:00 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 03:32 . 2004-08-10 11:00 173056 ----a-w c:\windows\system32\dllcache\ie4uinit.exe
2009-03-08 03:32 . 2004-08-10 04:00 163840 ----a-w c:\windows\system32\dllcache\ieakui.dll
2009-03-08 03:32 . 2004-08-10 11:00 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 03:32 . 2004-08-10 11:00 71680 ----a-w c:\windows\system32\dllcache\iesetup.dll
2009-03-08 03:32 . 2004-08-10 11:00 55808 ----a-w c:\windows\system32\dllcache\iernonce.dll
2009-03-08 03:32 . 2004-08-10 11:00 128512 ----a-w c:\windows\system32\dllcache\advpack.dll
2009-03-08 03:32 . 2004-08-10 11:00 94720 ----a-w c:\windows\system32\dllcache\inseng.dll
2009-03-08 03:32 . 2007-04-25 07:39 594432 ----a-w c:\windows\system32\dllcache\msfeeds.dll
2009-03-08 03:32 . 2007-04-25 07:39 1985024 ----a-w c:\windows\system32\dllcache\iertutil.dll
2009-03-08 03:32 . 2004-08-10 11:00 611840 ----a-w c:\windows\system32\dllcache\mstime.dll
2009-03-08 03:24 . 2004-08-10 11:00 68608 ----a-w c:\windows\system32\dllcache\hmmapi.dll
2009-03-08 03:22 . 2004-08-10 04:00 156160 ----a-w c:\windows\system32\msls31.dll
2009-03-08 03:22 . 2004-08-10 04:00 156160 ----a-w c:\windows\system32\dllcache\msls31.dll
2009-03-08 03:11 . 2007-04-25 07:38 445952 ----a-w c:\windows\system32\dllcache\ieapfltr.dll
2009-02-28 09:31 . 2008-11-22 16:13 -------- d-----w c:\program files\Microsoft Silverlight
2009-02-26 15:54 . 2007-05-16 17:40 -------- d-----w c:\program files\eMule
2009-02-09 14:05 . 2008-10-15 06:58 1846912 ------w c:\windows\system32\dllcache\win32k.sys
2009-02-09 14:05 . 2004-08-10 11:00 1846912 ----a-w c:\windows\system32\win32k.sys
2009-02-06 20:07 . 2007-04-17 09:32 3698584 ----a-w c:\windows\system32\dllcache\ieapfltr.dat
2009-02-06 17:52 . 2009-02-06 17:52 49504 ----a-w c:\windows\system32\sirenacm.dll
2008-11-22 16:21 . 2006-11-15 17:08 63872 ----a-w c:\documents and settings\HP_Administrateur\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-09-14 10:45 . 2008-08-09 09:53 47360 ----a-w c:\documents and settings\HP_Administrateur\Application Data\pcouffin.sys
2006-11-15 21:14 . 2007-06-22 07:22 140 ----a-w c:\documents and settings\HP_Administrateur\Local Settings\Application Data\fusioncache.dat
2006-08-14 13:32 . 2006-08-14 13:32 137 ----a-w c:\documents and settings\Administrateur\Local Settings\Application Data\fusioncache.dat
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\temp\atmp8 ----
2009-03-16 08:06 . 2009-03-16 08:06 1858 ----a-w c:\temp\atmp8\ead.log
((((((((((((((((((((((((((((( SnapShot@2009-04-13_10.50.41.60 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-14 17:47 . 2009-04-14 17:47 16384 c:\windows\Temp\Perflib_Perfdata_7d4.dat
+ 2009-04-14 17:45 . 2005-10-20 18:02 163328 c:\windows\ERDNT\subs\ERDNT.EXE
- 2009-04-13 08:46 . 2005-10-20 18:02 163328 c:\windows\ERDNT\subs\ERDNT.EXE
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [BU]
"Configuration de la neuf Box"="c:\program files\neuf telecom\neuf Box\Wizard\QuickAccess.exe" [BU]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-14 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" [BU]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"BDAgent"="c:\program files\BitDefender\BitDefender 2008\bdagent.exe" [2008-09-16 368640]
"BDOESRV"="c:\program files\Softwin\BitDefender9\bdoesrv.exe" [2005-03-11 90112]
"BigDogPath"="c:\windows\VM_STI.EXE" [2004-06-09 40960]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 61440]
"DMAScheduler"="c:\program files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 90112]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 249856]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [BU]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-09 7311360]
"PCDrProfiler"="c:\program files\PC-Doctor 5 for Windows\RunProfiler.exe" [BU]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-27 282624]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-22 237568]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2004-12-14 663552]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-08 136600]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-08-14 180269]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" - c:\windows\arpwrmsg.exe [2005-08-03 77312]
"ftutil2"="ftutil2.dll" - c:\windows\system32\ftutil2.dll [2004-06-07 106496]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-05-09 1519616]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2006-06-14 16239616]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
TrayMin210.exe.lnk - c:\program files\Philips\Philips SPC210NC Webcam\TrayMin210.exe [2007-6-6 278528]
Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2007-2-5 118784]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Program Files\\TVAnts\\Tvants.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Fichiers communs\\BitDefender\\BitDefender Update Service\\livesrv.exe"=
R2 FILESpy;FILESpy; [x]
R2 gupdate1c99109e78fbed3;Service Google Update (gupdate1c99109e78fbed3);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-17 133104]
R3 SG760_XP;SAGEM 802.11g XG760 1211 Driver;c:\windows\system32\DRIVERS\WlanUZXP.sys [2005-07-13 260608]
S3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\bdfndisf.sys [2008-06-24 86792]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
.
Contenu du dossier 'Tâches planifiées'
2009-03-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 13:42]
2009-04-14 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-27 19:01]
2009-03-28 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-17 14:13]
.
.
------- Examen supplémentaire -------
.
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/support/chrome/bin/request.py?hl=en-US&contact_type=uninstall&crversion=1.0.154.48&os=5.1.2600
uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
IE: Liens de téléchargement avec Mega Manager... - c:\program files\Megaupload\Mega Manager\mm_file.htm
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-14 19:52
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(384)
c:\program files\Softwin\BitDefender9\bdoe.dll
c:\windows\system32\XCOMM.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Fichiers communs\LightScribe\LSSrvc.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
.
**************************************************************************
.
Heure de fin: ~,10time:~,-3machine was rebootedCombobatch-by
ComboFix-quarantined-files.txt 2009-04-14 17:56
ComboFix2.txt 2009-04-13 09:11
ComboFix3.txt 2009-04-13 08:51
ComboFix4.txt 2009-04-11 13:41
Avant-CF: 82 424 365 056 octets libres
Après-CF: 82 481 786 880 octets libres
354 --- E O F --- 2009-03-15 09:30
Et le rapport Hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:13:46, on 14/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\Program Files\Softwin\BitDefender9\bdoesrv.exe
C:\WINDOWS\VM_STI.EXE
C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\explorer.exe
c:\windows\system\hpsysdrv.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://fr.search.yahoo.com/?fr=cb-hp06
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://fr.search.yahoo.com/?fr=cb-hp06
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\Run: [BDOESRV] "C:\Program Files\Softwin\BitDefender9\bdoesrv.exe"
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Philips SPC210NC Webcam
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [PCDrProfiler] "C:\Program Files\PC-Doctor 5 for Windows\RunProfiler.exe" -r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Configuration de la neuf Box] C:\Program Files\neuf telecom\neuf Box\Wizard\QuickAccess.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: TrayMin210.exe.lnk = C:\Program Files\Philips\Philips SPC210NC Webcam\TrayMin210.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Liens de téléchargement avec Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: Service Google Update (gupdate1c99109e78fbed3) (gupdate1c99109e78fbed3) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
-
Contributeur sécurité/!\ Manip crée spécialement pour cet utilisateur , ne pas reproduire chez soi ... /!\
Ouvre le Bloc-Notes (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
Copie ce texte ( en gras )d'une traite ( CTRL+C pour copier ) puis colle-le ( CTRL+V dans le bloc-note )
File::
c:\windows\system32\honimava.dll
c:\windows\system32\zulelolo.dll
c:\windows\system32\tisawipu.dll
c:\windows\system32\nuwiyidi.dll
c:\program files\Uninstall Ask Toolbar.dll
c:\windows\system32\zubadira.dll
c:\windows\system32\yuwegiju.dll
c:\windows\system32\pemivubu.dll
c:\windows\QTFont.qfn
c:\windows\QTFont.for
c:\temp\atmp8
c:\windows\system32\perfc00C.dat
c:\windows\system32\perfh00C.dat
c:\windows\system32\serubifa.exe
c:\windows\system32\serubifa.exe
c:\windows\system32\notabage.exe
c:\windows\system32\notabage.exe
c:\windows\system32\rojideze.exe
c:\windows\system32\rojideze.exe
c:\windows\system32\powipogi.exe
c:\windows\system32\powipogi.exe
c:\windows\system32\rusahene.exe
c:\windows\system32\rusahene.exe
c:\windows\system32\kidapita.dll
c:\windows\system32\bowafefi.dll
c:\windows\system32\vodarowo.dll
c:\windows\system32\ruyebana.dll
c:\windows\system32\jedepona.dll
c:\windows\system32\yabuvasu.dll
c:\windows\system32\lowopami.dll
c:\windows\system32\seratewa.dll
c:\windows\system32\nilejonu.dll
c:\windows\system32\lasobemo.dll
c:\windows\system32\nevibuni.dll
c:\windows\system32\malufige.dll
c:\windows\system32\gakewake.dll
c:\windows\system32\sikezovo.dll
c:\windows\system32\vosubupa.dll
c:\windows\system32\dewozuzi.dll
c:\windows\system32\razoriti.dll
c:\windows\system32\sayoroso.dll
c:\windows\system32\bitipote.dll
c:\windows\system32\yuvukina.dll
c:\windows\system32\rupibemo.dll
c:\windows\system32\delopeha.dll
c:\windows\system32\vezeyege.dll
c:\windows\system32\jojesira.dll
c:\windows\system32\firotapa.dll
c:\windows\system32\fizipime.dll
c:\windows\system32\biruwuta.dll
c:\windows\system32\pelozeho.dll
c:\windows\system32\minutara.dll
c:\windows\system32\zafugiho.dll
c:\windows\system32\tayufazu.dll
c:\windows\system32\jobavito.dll
c:\windows\system32\jezosudo.dll
c:\windows\system32\dadopuga.dll
c:\windows\system32\pulemebo.dll
c:\windows\system32\gukevewi.dll
c:\windows\system32\yapigifa.dll
c:\windows\system32\juyimebo.dll
c:\windows\system32\zitajalu.dll
Folder::
c:\temp\atmp8
DirLook::
c:\temp\atmp8
Sauvegarde ce fichier sur ton bureau sous le nom de CFScript.txt.
Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :
http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
Cela va relancer Combofix,
Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.
S'il n'y a pas de rédémarrage, poste quand même les rapports.
Par Manque De Curiosité On Risque De Mourir Ignorant;Tu es libre de penser que tu es C..,
Mais C.. de penser que tu es libre...Merci a australe13 -
non pas du tout, c'est pas une blague
-
Contributeur sécuritésalut
c'est pas possible c'est un concours a qui pourrit son pc le premier tu va entrer dans le guiness record
c'est un gag la ?
LOL -
salut, voila le rapport
ComboFix 09-04-13.A0 - HP_Administrateur 2009-04-13 10:41.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.958.649 [GMT 2:00]
Lancé depuis: c:\documents and settings\HP_Administrateur\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\HP_Administrateur\Bureau\CFScript.txt
AV: Bitdefender Antivirus *On-access scanning enabled* (Updated)
FW: Bitdefender Firewall *enabled*
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\HP_Administrateur\Application Data\inst.exe
c:\program files\outlook
c:\windows\system32\avohirew.ini
c:\windows\system32\bszip.dll
c:\windows\system32\emezetef.ini
c:\windows\system32\eyujazot.ini
c:\windows\system32\gotiyewi.dll
c:\windows\system32\hekewufu.dll
c:\windows\system32\hujepaka.dll
c:\windows\system32\huzitala.dll
c:\windows\system32\jonefede.dll
c:\windows\system32\rugakeju.dll
c:\windows\system32\udokalul.ini
c:\windows\system32\yegegeyo.dll
c:\windows\winhelp.ini
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DHLP
((((((((((((((((((((((((((((( Fichiers créés du 2009-03-13 au 2009-04-13 ))))))))))))))))))))))))))))))))))))
.
2009-04-10 11:50 . 2009-04-10 11:50 579584 ----a-w c:\windows\system32\dllcache\user32.dll
2009-04-10 11:47 . 2009-04-11 14:33 -------- d-----w C:\SDFix
2009-04-10 11:37 . 2009-04-10 11:37 -------- d-----w c:\windows\ERUNT
2009-04-02 08:06 . 2009-03-26 14:49 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-04-02 08:06 . 2009-03-26 14:49 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-30 07:18 . 2009-03-30 07:18 -------- d-----w c:\documents and settings\HP_Administrateur\Application Data\Malwarebytes
2009-03-30 07:18 . 2009-04-11 14:33 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-03-30 07:18 . 2009-03-30 07:18 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-29 08:26 . 2009-03-30 07:33 -------- d-----w c:\program files\Lopxp
2009-03-28 13:48 . 2009-03-30 07:47 -------- d-----w C:\Lop SD
2009-03-27 17:34 . 2009-03-28 12:26 -------- d-----w c:\program files\Navilog1
2009-03-27 12:48 . 2009-03-27 12:48 -------- d-----w c:\program files\Trend Micro
2009-03-27 11:10 . 2009-03-27 11:10 -------- d-sh--w c:\documents and settings\LocalService\IETldCache
2009-03-27 11:08 . 2009-03-27 11:08 -------- d-sh--w c:\documents and settings\HP_Administrateur\IECompatCache
2009-03-27 11:07 . 2009-03-27 11:07 -------- d-sh--w c:\documents and settings\HP_Administrateur\PrivacIE
2009-03-27 11:03 . 2009-03-27 11:03 -------- d-sh--w c:\documents and settings\HP_Administrateur\IETldCache
2009-03-27 10:38 . 2009-03-27 10:42 -------- dc-h--w c:\windows\ie8
2009-03-24 19:28 . 2009-03-24 19:28 5297 --sh--w c:\windows\system32\honimava.dll
2009-03-23 19:32 . 2009-03-23 19:32 912 --sh--w c:\windows\system32\zulelolo.dll
2009-03-23 19:32 . 2009-03-23 19:32 912 --sh--w c:\windows\system32\tisawipu.dll
2009-03-23 19:32 . 2009-03-23 19:37 912 ----a-w c:\windows\system32\nuwiyidi.dll
2009-03-23 07:38 . 2008-03-08 09:42 245760 ----a-w c:\program files\Uninstall Ask Toolbar.dll
2009-03-23 07:36 . 2009-03-23 08:36 912 ----a-w c:\windows\system32\zubadira.dll
2009-03-23 07:36 . 2009-03-23 07:36 912 --sh--w c:\windows\system32\yuwegiju.dll
2009-03-23 07:36 . 2009-03-23 08:36 912 ----a-w c:\windows\system32\pemivubu.dll
2009-03-22 12:51 . 2009-03-22 12:51 54156 ---ha-w c:\windows\QTFont.qfn
2009-03-22 12:51 . 2009-03-22 12:51 1409 ----a-w c:\windows\QTFont.for
2009-03-16 08:05 . 2009-03-16 08:06 -------- d-----w c:\temp\atmp8
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-11 14:40 . 2005-10-10 11:39 85258 ----a-w c:\windows\system32\perfc00C.dat
2009-04-11 14:40 . 2005-10-10 11:39 492556 ----a-w c:\windows\system32\perfh00C.dat
2009-03-30 07:49 . 2009-03-28 13:49 17097 ----a-w C:\lopR.txt
2009-03-29 12:35 . 2008-10-04 10:11 -------- d-----w c:\documents and settings\HP_Administrateur\Application Data\OpenOffice.org2
2009-03-29 07:30 . 1601-01-01 00:12 61440 --sha-w c:\windows\system32\serubifa.exe
2009-03-29 07:30 . 1601-01-01 00:12 61440 --sha-w c:\windows\system32\serubifa.exe
2009-03-28 19:29 . 1601-01-01 00:12 61440 --sha-w c:\windows\system32\notabage.exe
2009-03-28 19:29 . 1601-01-01 00:12 61440 --sha-w c:\windows\system32\notabage.exe
2009-03-28 12:17 . 2009-03-28 12:01 2763 ----a-w C:\cleannavi.txt
2009-03-28 12:01 . 2009-03-27 17:36 2689 ----a-w C:\fixnavi.txt
2009-03-28 09:30 . 2007-06-22 08:23 81984 ----a-w c:\windows\system32\bdod.bin
2009-03-28 07:29 . 1601-01-01 00:12 61440 --sha-w c:\windows\system32\rojideze.exe
2009-03-28 07:29 . 1601-01-01 00:12 61440 --sha-w c:\windows\system32\rojideze.exe
2009-03-27 19:29 . 1601-01-01 00:12 61440 --sha-w c:\windows\system32\powipogi.exe
2009-03-27 19:29 . 1601-01-01 00:12 61440 --sha-w c:\windows\system32\powipogi.exe
2009-03-27 09:17 . 2009-02-17 14:12 -------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-03-27 07:28 . 1601-01-01 00:12 61440 --sha-w c:\windows\system32\rusahene.exe
2009-03-27 07:28 . 1601-01-01 00:12 61440 --sha-w c:\windows\system32\rusahene.exe
2009-03-26 19:28 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\kidapita.dll
2009-03-26 07:28 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\bowafefi.dll
2009-03-25 07:27 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\vodarowo.dll
2009-03-25 07:27 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\ruyebana.dll
2009-03-25 07:27 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\jedepona.dll
2009-03-24 07:27 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\yabuvasu.dll
2009-03-24 07:27 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\lowopami.dll
2009-03-24 06:00 . 2007-02-01 22:54 -------- d-----w c:\program files\AskTBar
2009-03-22 12:50 . 2006-08-14 14:25 -------- d-----w c:\program files\Google
2009-03-22 12:35 . 2007-08-03 09:47 -------- d-----w c:\program files\Windows Live
2009-03-22 12:31 . 2006-08-14 14:05 -------- d--h--w c:\program files\InstallShield Installation Information
2009-03-22 12:31 . 2006-08-14 14:07 -------- d-----w c:\program files\Fichiers communs\muvee Technologies
2009-03-22 12:30 . 2008-12-20 19:01 -------- d-----w c:\program files\Veetle
2009-03-22 12:28 . 2008-11-28 12:51 -------- d-----w c:\documents and settings\HP_Administrateur\Application Data\Samsung
2009-03-22 12:26 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\seratewa.dll
2009-03-22 12:26 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\nilejonu.dll
2009-03-22 12:26 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\lasobemo.dll
2009-03-21 22:40 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\nevibuni.dll
2009-03-21 22:40 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\malufige.dll
2009-03-21 22:40 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\gakewake.dll
2009-03-21 12:25 . 2007-06-22 18:45 -------- d-----w c:\program files\Windows Live Safety Center
2009-03-20 20:13 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\vulabiro.dll
2009-03-20 20:13 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\sogoruro.dll
2009-03-20 20:13 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\pokefige.dll
2009-03-20 08:24 . 2006-12-04 16:10 24758 ----a-w c:\documents and settings\HP_Administrateur\Application Data\wklnhst.dat
2009-03-20 08:13 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\sikezovo.dll
2009-03-20 08:13 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\vosubupa.dll
2009-03-20 08:13 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\dewozuzi.dll
2009-03-19 20:13 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\razoriti.dll
2009-03-19 20:12 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\sayoroso.dll
2009-03-19 20:12 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\bitipote.dll
2009-03-19 08:12 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\yuvukina.dll
2009-03-19 08:12 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\rupibemo.dll
2009-03-19 08:12 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\delopeha.dll
2009-03-18 20:12 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\vezeyege.dll
2009-03-18 20:12 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\jojesira.dll
2009-03-18 20:12 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\firotapa.dll
2009-03-18 08:12 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\fizipime.dll
2009-03-18 08:12 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\biruwuta.dll
2009-03-18 08:12 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\pelozeho.dll
2009-03-17 20:11 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\minutara.dll
2009-03-17 20:11 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\zafugiho.dll
2009-03-17 08:15 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\tayufazu.dll
2009-03-17 08:15 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\jobavito.dll
2009-03-17 08:15 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\jezosudo.dll
2009-03-16 20:11 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\dadopuga.dll
2009-03-16 20:11 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\pulemebo.dll
2009-03-16 20:11 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\gukevewi.dll
2009-03-16 08:11 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\yapigifa.dll
2009-03-16 08:11 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\juyimebo.dll
2009-03-16 08:11 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\zitajalu.dll
2009-03-14 08:11 . 2009-03-14 08:11 -------- d-----w c:\program files\Microsoft
2009-03-14 08:10 . 2009-03-14 08:10 -------- d-----w c:\program files\Windows Live SkyDrive
2009-03-08 13:09 . 2004-08-10 11:00 638816 ----a-w c:\windows\system32\dllcache\iexplore.exe
2009-03-08 13:09 . 2004-08-10 11:00 391536 ----a-w c:\windows\system32\dllcache\iedkcs32.dll
2009-03-08 03:41 . 2004-08-10 11:00 5937152 ----a-w c:\windows\system32\dllcache\mshtml.dll
2009-03-08 03:39 . 2007-04-25 07:39 11063808 ----a-w c:\windows\system32\dllcache\ieframe.dll
2009-03-08 03:34 . 2004-08-10 11:00 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 03:34 . 2004-08-10 11:00 914944 ----a-w c:\windows\system32\dllcache\wininet.dll
2009-03-08 03:34 . 2004-08-10 11:00 1206784 ----a-w c:\windows\system32\dllcache\urlmon.dll
2009-03-08 03:34 . 2004-08-10 11:00 236544 ----a-w c:\windows\system32\dllcache\webcheck.dll
2009-03-08 03:34 . 2004-08-10 11:00 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 03:34 . 2004-08-10 11:00 43008 ----a-w c:\windows\system32\dllcache\licmgr10.dll
2009-03-08 03:34 . 2004-08-10 11:00 105984 ----a-w c:\windows\system32\dllcache\url.dll
2009-03-08 03:34 . 2004-08-10 11:00 193536 ----a-w c:\windows\system32\dllcache\msrating.dll
2009-03-08 03:34 . 2004-08-10 11:00 109568 ----a-w c:\windows\system32\dllcache\occache.dll
2009-03-08 03:33 . 2004-08-10 11:00 759296 ----a-w c:\windows\system32\dllcache\VGX.dll
2009-03-08 03:33 . 2009-03-08 03:33 18944 ------w c:\windows\system32\dllcache\corpol.dll
2009-03-08 03:33 . 2004-08-10 11:00 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 03:33 . 2004-08-10 11:00 25600 ----a-w c:\windows\system32\dllcache\jsproxy.dll
2009-03-08 03:33 . 2008-05-09 10:55 726528 ----a-w c:\windows\system32\dllcache\jscript.dll
2009-03-08 03:33 . 2004-08-10 11:00 229376 ----a-w c:\windows\system32\dllcache\ieaksie.dll
2009-03-08 03:33 . 2008-05-09 10:55 420352 ----a-w c:\windows\system32\dllcache\vbscript.dll
2009-03-08 03:33 . 2004-08-10 11:00 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 03:33 . 2004-08-10 11:00 125952 ----a-w c:\windows\system32\dllcache\ieakeng.dll
2009-03-08 03:32 . 2004-08-10 11:00 72704 ----a-w c:\windows\system32\dllcache\admparse.dll
2009-03-08 03:32 . 2004-08-10 11:00 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 03:32 . 2004-08-10 11:00 173056 ----a-w c:\windows\system32\dllcache\ie4uinit.exe
2009-03-08 03:32 . 2004-08-10 04:00 163840 ----a-w c:\windows\system32\dllcache\ieakui.dll
2009-03-08 03:32 . 2004-08-10 11:00 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 03:32 . 2004-08-10 11:00 71680 ----a-w c:\windows\system32\dllcache\iesetup.dll
2009-03-08 03:32 . 2004-08-10 11:00 55808 ----a-w c:\windows\system32\dllcache\iernonce.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-14 68856]
"Configuration de la neuf Box"="c:\program files\neuf telecom\neuf Box\Wizard\QuickAccess.exe" [BU]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [BU]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-08-14 180269]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-08 136600]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2004-12-14 663552]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-22 237568]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-27 282624]
"PCDrProfiler"="c:\program files\PC-Doctor 5 for Windows\RunProfiler.exe" [BU]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-10 7311360]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [BU]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 249856]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"DMAScheduler"="c:\program files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 90112]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 61440]
"BigDogPath"="c:\windows\VM_STI.EXE" [2004-06-09 40960]
"BDOESRV"="c:\program files\Softwin\BitDefender9\bdoesrv.exe" [2005-03-11 90112]
"BDAgent"="c:\program files\BitDefender\BitDefender 2008\bdagent.exe" [2008-09-16 368640]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" [BU]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-14 c:\windows\RTHDCPL.EXE]
"nwiz"="nwiz.exe" [2006-05-10 c:\windows\system32\nwiz.exe]
"ftutil2"="ftutil2.dll" [2004-06-07 c:\windows\system32\ftutil2.dll]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 c:\windows\arpwrmsg.exe]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
TrayMin210.exe.lnk - c:\program files\Philips\Philips SPC210NC Webcam\TrayMin210.exe [2007-06-06 278528]
Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2007-02-05 118784]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Program Files\\TVAnts\\Tvants.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Fichiers communs\\BitDefender\\BitDefender Update Service\\livesrv.exe"=
R2 FILESpy;FILESpy; [x]
R2 gupdate1c99109e78fbed3;Service Google Update (gupdate1c99109e78fbed3);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-17 133104]
R3 SG760_XP;SAGEM 802.11g XG760 1211 Driver;c:\windows\system32\DRIVERS\WlanUZXP.sys [2005-07-13 260608]
S3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\bdfndisf.sys [2008-06-24 86792]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{381a841a-d73f-11dd-bee7-0018f36f024d}]
\Shell\AutoRun\command - f:\wd_windows_tools\Setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c64e4e58-114f-11de-bf36-0018f36f024d}]
\Shell\Auto\command - F:\Start.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
.
Contenu du dossier 'Tâches planifiées'
2009-03-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42]
2009-04-13 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-22 21:01]
2009-03-28 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-17 16:13]
.
- - - - ORPHELINS SUPPRIMES - - - -
WebBrowser-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)
.
------- Examen supplémentaire -------
.
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/support/chrome/bin/request.py?hl=en-US&contact_type=uninstall&crversion=1.0.154.48&os=5.1.2600
uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
IE: Liens de téléchargement avec Mega Manager... - c:\program files\Megaupload\Mega Manager\mm_file.htm
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-13 10:47
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(2888)
c:\program files\Softwin\BitDefender9\bdoe.dll
c:\windows\system32\XCOMM.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Fichiers communs\LightScribe\LSSrvc.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
.
**************************************************************************
.
Heure de fin: 2009-04-13 10:51 - La machine a redémarré [HP_Administrateur]
ComboFix-quarantined-files.txt 2009-04-13 08:51
ComboFix2.txt 2009-04-11 13:41
Avant-CF: 82 506 194 944 octets libres
Après-CF: 82,569,945,088 octets libres
304 --- E O F --- 2009-03-15 09:30 -
Contributeur sécurité> Avec Combofix :
- Crée un nouveau document texte : clic droit de souris sur le bureau => Nouveau => Document Texte, et copie/colle dedans les lignes suivantes :
Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{381a841a-d73f-11dd-bee7-0018f36f024d}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c64e4e58-114f-11de-bf36-0018f36f024d}]
File::
c:\windows\system32\honimava.dll
c:\windows\system32\zulelolo.dll
c:\windows\system32\tisawipu.dll
c:\windows\system32\nuwiyidi.dll
c:\windows\system32\zubadira.dll
c:\windows\system32\yuwegiju.dll
c:\windows\system32\pemivubu.dll
c:\windows\QTFont.qfn
c:\windows\QTFont.for
- Enregistre ce fichier sous le nom CFScript (Type du fichier : tous les fichiers)
- Ferme tous tes navigateurs web (donc copie ou imprime les instructions suivantes avant si besoin est).
- Désactive ton antivirus et tes autres protections résidentes (ex : Spybot) si tu en as (c'est important).
- Fait un glisser/déposer de ce fichier CFScript sur le programme ComboFix.exe
(Explications du glisser/coller : Clique sur le fichier CFScript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFScript vienne recouvrir l'icône de Combofix. Relâche alors le bouton de la souris).
- Combofix va démarrer puis une fenêtre bleue va apparaître. Au message qui s'affiche (Type 1 to continue, or 2 to abort) : tape 1 puis valide.
- Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises: c'est normal !
- Ne touche à rien tant que le scan n'est pas terminé sinon le PC peut planter !
- Une fois le scan achevé, un rapport va s'afficher: poste le stp.
PS : Si le fichier ne s'ouvre pas, il se trouve ici => C:\ComboFix.txt
Par Manque De Curiosité On Risque De Mourir Ignorant;Tu es libre de penser que tu es C..,
Mais C.. de penser que tu es libre...Merci a australe13 -
salut voila le rapport
ComboFix 09-04-04.01 - HP_Administrateur 2009-04-11 15:31:22.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.958.606 [GMT 2:00]
Lancé depuis: c:\documents and settings\HP_Administrateur\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\HP_Administrateur\Application Data\inst.exe
c:\program files\INSTALL.LOG
c:\program files\outlook
c:\windows\system32\avohirew.ini
c:\windows\system32\bszip.dll
c:\windows\system32\emezetef.ini
c:\windows\system32\eyujazot.ini
c:\windows\system32\gotiyewi.dll
c:\windows\system32\hekewufu.dll
c:\windows\system32\hujepaka.dll
c:\windows\system32\huzitala.dll
c:\windows\system32\jonefede.dll
c:\windows\system32\rugakeju.dll
c:\windows\system32\udokalul.ini
c:\windows\system32\yegegeyo.dll
c:\windows\winhelp.ini
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DHLP
((((((((((((((((((((((((((((( Fichiers créés du 2009-03-11 au 2009-04-11 ))))))))))))))))))))))))))))))))))))
.
2009-04-10 13:50 . 2009-04-10 13:50 579,584 --a------ c:\windows\system32\dllcache\user32.dll
2009-04-10 13:47 . 2009-04-11 13:16 <REP> d-------- C:\SDFix
2009-04-10 13:37 . 2009-04-10 13:37 <REP> d-------- c:\windows\ERUNT
2009-04-02 10:06 . 2009-03-26 16:49 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-02 10:06 . 2009-03-26 16:49 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-30 09:18 . 2009-04-11 13:15 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-30 09:18 . 2009-03-30 09:18 <REP> d-------- c:\documents and settings\HP_Administrateur\Application Data\Malwarebytes
2009-03-30 09:18 . 2009-03-30 09:18 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-29 10:26 . 2009-03-30 09:33 <REP> d-------- c:\program files\Lopxp
2009-03-28 15:48 . 2009-03-30 09:47 <REP> d-------- C:\Lop SD
2009-03-27 19:34 . 2009-03-28 14:26 <REP> d-------- c:\program files\Navilog1
2009-03-27 14:48 . 2009-03-27 14:48 <REP> d-------- c:\program files\Trend Micro
2009-03-27 13:10 . 2009-03-27 13:10 <REP> d--hs---- c:\documents and settings\LocalService\IETldCache
2009-03-27 13:08 . 2009-03-27 13:08 <REP> d--hs---- c:\documents and settings\HP_Administrateur\IECompatCache
2009-03-27 13:07 . 2009-03-27 13:07 <REP> d--hs---- c:\documents and settings\HP_Administrateur\PrivacIE
2009-03-27 13:03 . 2009-03-27 13:03 <REP> d--hs---- c:\documents and settings\HP_Administrateur\IETldCache
2009-03-27 12:38 . 2009-03-27 12:42 <REP> d--h-c--- c:\windows\ie8
2009-03-24 21:28 . 2009-03-24 21:28 5,297 ---hs---- c:\windows\system32\honimava.dll
2009-03-23 21:32 . 2009-03-23 21:32 912 ---hs---- c:\windows\system32\zulelolo.dll
2009-03-23 21:32 . 2009-03-23 21:32 912 ---hs---- c:\windows\system32\tisawipu.dll
2009-03-23 21:32 . 2009-03-23 21:37 912 --a------ c:\windows\system32\nuwiyidi.dll
2009-03-23 09:38 . 2008-03-08 11:42 245,760 --a------ c:\program files\Uninstall Ask Toolbar.dll
2009-03-23 09:36 . 2009-03-23 10:36 912 --a------ c:\windows\system32\zubadira.dll
2009-03-23 09:36 . 2009-03-23 09:36 912 ---hs---- c:\windows\system32\yuwegiju.dll
2009-03-23 09:36 . 2009-03-23 10:36 912 --a------ c:\windows\system32\pemivubu.dll
2009-03-22 14:51 . 2009-03-22 14:51 54,156 --ah----- c:\windows\QTFont.qfn
2009-03-22 14:51 . 2009-03-22 14:51 1,409 --a------ c:\windows\QTFont.for
2009-03-16 10:05 . 2009-03-16 10:06 <REP> d-------- c:\temp\atmp8
2009-03-14 10:36 . 2009-04-11 09:05 <REP> d-------- c:\documents and settings\HP_Administrateur\Tracing
2009-03-14 10:11 . 2009-03-14 10:11 <REP> d-------- c:\program files\Microsoft
2009-03-14 10:10 . 2009-03-14 10:10 <REP> d-------- c:\program files\Windows Live SkyDrive
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-29 12:35 --------- d-----w c:\documents and settings\HP_Administrateur\Application Data\OpenOffice.org2
2009-03-27 09:17 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-03-24 06:00 --------- d-----w c:\program files\AskTBar
2009-03-22 12:50 --------- d-----w c:\program files\Google
2009-03-22 12:35 --------- d-----w c:\program files\Windows Live
2009-03-22 12:31 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-22 12:31 --------- d-----w c:\program files\Fichiers communs\muvee Technologies
2009-03-22 12:30 --------- d-----w c:\program files\Veetle
2009-03-22 12:28 --------- d-----w c:\documents and settings\HP_Administrateur\Application Data\Samsung
2009-03-21 12:25 --------- d-----w c:\program files\Windows Live Safety Center
2009-03-20 08:24 24,758 ----a-w c:\documents and settings\HP_Administrateur\Application Data\wklnhst.dat
2009-02-28 09:31 --------- d-----w c:\program files\Microsoft Silverlight
2009-02-26 15:54 --------- d-----w c:\program files\eMule
2008-09-14 10:45 47,360 ----a-w c:\documents and settings\HP_Administrateur\Application Data\pcouffin.sys
2008-09-05 18:02 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008090520080906\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-14 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-08-14 180269]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-08 136600]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2004-12-14 663552]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-22 237568]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-27 282624]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-10 7311360]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 249856]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"DMAScheduler"="c:\program files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 90112]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 61440]
"BigDogPath"="c:\windows\VM_STI.EXE" [2004-06-09 40960]
"BDOESRV"="c:\program files\Softwin\BitDefender9\bdoesrv.exe" [2005-03-11 90112]
"BDAgent"="c:\program files\BitDefender\BitDefender 2008\bdagent.exe" [2008-09-16 368640]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-14 c:\windows\RTHDCPL.EXE]
"nwiz"="nwiz.exe" [2006-05-10 c:\windows\system32\nwiz.exe]
"ftutil2"="ftutil2.dll" [2004-06-07 c:\windows\system32\ftutil2.dll]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 c:\windows\arpwrmsg.exe]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
TrayMin210.exe.lnk - c:\program files\Philips\Philips SPC210NC Webcam\TrayMin210.exe [2007-06-06 278528]
Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2007-02-05 118784]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Program Files\\TVAnts\\Tvants.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Fichiers communs\\BitDefender\\BitDefender Update Service\\livesrv.exe"=
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [2008-01-25 86792]
S2 FILESpy;FILESpy;\??\c:\program files\Softwin\BitDefender9\filespy.sys --> c:\program files\Softwin\BitDefender9\filespy.sys [?]
S2 gupdate1c99109e78fbed3;Service Google Update (gupdate1c99109e78fbed3);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-17 133104]
S3 SG760_XP;SAGEM 802.11g XG760 1211 Driver;c:\windows\system32\drivers\WlanUZXP.sys [2008-12-20 260608]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{381a841a-d73f-11dd-bee7-0018f36f024d}]
\Shell\AutoRun\command - f:\wd_windows_tools\Setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c64e4e58-114f-11de-bf36-0018f36f024d}]
\Shell\Auto\command - F:\Start.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
.
Contenu du dossier 'Tâches planifiées'
2009-03-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42]
2009-04-11 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-22 21:01]
2009-03-28 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-17 16:13]
.
- - - - ORPHELINS SUPPRIMES - - - -
WebBrowser-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)
HKCU-Run-Configuration de la neuf Box - c:\program files\neuf telecom\neuf Box\Wizard\QuickAccess.exe
HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
HKLM-Run-PCDrProfiler - c:\program files\PC-Doctor 5 for Windows\RunProfiler.exe
HKLM-Run-NBKeyScan - c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
HKLM-Run-Adobe Photo Downloader - c:\program files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
.
------- Examen supplémentaire -------
.
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
uInternet Connection Wizard,ShellNext = hxxp://www.google.com/support/chrome/bin/request.py?hl=en-US&contact_type=uninstall&crversion=1.0.154.48&os=5.1.2600
uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
IE: Liens de téléchargement avec Mega Manager... - c:\program files\Megaupload\Mega Manager\mm_file.htm
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-11 15:37:00
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Fichiers communs\LightScribe\LSSrvc.exe
c:\windows\system\hpsysdrv.exe
.
**************************************************************************
.
Heure de fin: 2009-04-11 15:41:02 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-04-11 13:40:40
Avant-CF: 81 252 315 136 octets libres
Après-CF: 82,951,286,784 octets libres
208 --- E O F --- 2009-03-15 09:30:58 -
Contributeur sécuritésalut regarde pour restaurer a une date ultérieure et on désinfectera si elle est infecter
içi un tuto bien expliquer
https://www.vulgarisation-informatique.com/restauration-systeme-restaurer.php
-
Salut, vu que mon pc est en mode diagnostic l'antivirus ne marche pas. J'ai BitDefender 2008
-
Contributeur sécuritésalut
suit bien les instruction qui vont suivre car la les infections tu les collectionnes
Telecharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
-> Double clique combofix.exe.
-> Tape sur la touche 1 (Yes) pour démarrer le scan.
-> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
NOTE : Le rapport se trouve également ici : C:\Combofix.txt
Avant d'utiliser ComboFix :
-> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.
-> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.
Une fois fait, sur ton bureau double-clic sur Combofix.exe.
- Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.
-Attention Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes. risque de figer l'ordi
- En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.
- Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)
-> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.
-> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.
!\ Ne touche à rien tant que le scan n'est pas terminé. /!\ : risque de figer l'ordi (plantage complet)
::Si combofix demande a faire mise a jour tu refuse
::Si combofix detecte quelque chose et de demande a redemarer tu accepte
-
Salut, voila le rapport
[b]SDFix: Version 1.240 [/b]
Run by HP_Administrateur on 10/04/2009 at 13:50
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
[b]Checking Services [/b]:
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files [/b]:
Trojan Files Found:
C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\TMP1C.tmp - Deleted
Folder C:\VirusGarde - Removed
Removing Temp Files
[b]ADS Check [/b]:
[b]Final Check [/b]:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-10 13:58:47
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services [/b]:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\AOL 9.0\\waol.exe"="C:\\Program Files\\AOL 9.0\\waol.exe:*:Enabled:AOL France"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Documents and Settings\\HP_Administrateur\\Local Settings\\Temp\\Rar$EX00.578\\emule.exe"="C:\\Documents and Settings\\HP_Administrateur\\Local Settings\\Temp\\Rar$EX00.578\\emule.exe:*:Disabled:eMule"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\TVUPlayer\\TVUPlayer.exe"="C:\\Program Files\\TVUPlayer\\TVUPlayer.exe:*:Enabled:TVUPlayer Component"
"C:\\Program Files\\TVAnts\\Tvants.exe"="C:\\Program Files\\TVAnts\\Tvants.exe:*:Enabled:TVAnts"
"C:\\Program Files\\SopCast\\adv\\SopAdver.exe"="C:\\Program Files\\SopCast\\adv\\SopAdver.exe:*:Enabled:SopCast Adver"
"C:\\Program Files\\SopCast\\SopCast.exe"="C:\\Program Files\\SopCast\\SopCast.exe:*:Enabled:SopCast Main Application"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\WINDOWS\\explorer.exe"="C:\\WINDOWS\\explorer.exe:*:Enabled:Explorer"
"C:\\Program Files\\Fichiers communs\\BitDefender\\BitDefender Update Service\\livesrv.exe"="C:\\Program Files\\Fichiers communs\\BitDefender\\BitDefender Update Service\\livesrv.exe:*:Enabled:livesrv"
"C:\\WINDOWS\\system32\\winlogon.exe"="C:\\WINDOWS\\system32\\winlogon.exe:*:Enabled:winlogon"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
[b]Remaining Files [/b]:
File Backups: - C:\SDFix\backups\backups.zip
[b]Files with Hidden Attributes [/b]:
Fri 22 Jun 2007 211 A.SHR --- "C:\BOOT.BAK"
Mon 14 Apr 2008 60,416 A.SH. --- "C:\Program Files\Outlook Express\msimn.exe"
Wed 18 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\biruwuta.dll"
Thu 19 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\bitipote.dll"
Thu 26 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\bowafefi.dll"
Mon 16 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\dadopuga.dll"
Thu 19 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\delopeha.dll"
Fri 20 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\dewozuzi.dll"
Wed 18 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\firotapa.dll"
Wed 18 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\fizipime.dll"
Sun 22 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\gakewake.dll"
Thu 26 Mar 2009 84,992 A.SH. --- "C:\WINDOWS\system32\gotiyewi.dll"
Mon 16 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\gukevewi.dll"
Fri 27 Mar 2009 84,992 A.SH. --- "C:\WINDOWS\system32\hekewufu.dll"
Tue 24 Mar 2009 5,297 ..SH. --- "C:\WINDOWS\system32\honimava.dll"
Wed 25 Mar 2009 84,992 A.SH. --- "C:\WINDOWS\system32\hujepaka.dll"
Thu 26 Mar 2009 84,992 A.SH. --- "C:\WINDOWS\system32\huzitala.dll"
Wed 25 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\jedepona.dll"
Tue 17 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\jezosudo.dll"
Tue 17 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\jobavito.dll"
Wed 18 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\jojesira.dll"
Sat 28 Mar 2009 84,992 A.SH. --- "C:\WINDOWS\system32\jonefede.dll"
Mon 16 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\juyimebo.dll"
Thu 26 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\kidapita.dll"
Sun 22 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\lasobemo.dll"
Tue 24 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\lowopami.dll"
Sun 22 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\malufige.dll"
Tue 17 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\minutara.dll"
Sun 22 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\nevibuni.dll"
Sun 22 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\nilejonu.dll"
Sat 28 Mar 2009 61,440 A.SH. --- "C:\WINDOWS\system32\notabage.exe"
Wed 18 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\pelozeho.dll"
Fri 20 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\pokefige.dll"
Fri 27 Mar 2009 61,440 A.SH. --- "C:\WINDOWS\system32\powipogi.exe"
Mon 16 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\pulemebo.dll"
Thu 19 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\razoriti.dll"
Sat 28 Mar 2009 61,440 A.SH. --- "C:\WINDOWS\system32\rojideze.exe"
Sat 28 Mar 2009 84,992 A.SH. --- "C:\WINDOWS\system32\rugakeju.dll"
Thu 19 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\rupibemo.dll"
Fri 27 Mar 2009 61,440 A.SH. --- "C:\WINDOWS\system32\rusahene.exe"
Wed 25 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\ruyebana.dll"
Thu 19 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\sayoroso.dll"
Sun 22 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\seratewa.dll"
Sun 29 Mar 2009 61,440 A.SH. --- "C:\WINDOWS\system32\serubifa.exe"
Fri 20 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\sikezovo.dll"
Fri 20 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\sogoruro.dll"
Tue 17 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\tayufazu.dll"
Mon 23 Mar 2009 912 ..SH. --- "C:\WINDOWS\system32\tisawipu.dll"
Wed 18 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\vezeyege.dll"
Wed 25 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\vodarowo.dll"
Fri 20 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\vosubupa.dll"
Fri 20 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\vulabiro.dll"
Tue 24 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\yabuvasu.dll"
Mon 16 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\yapigifa.dll"
Fri 27 Mar 2009 84,992 A.SH. --- "C:\WINDOWS\system32\yegegeyo.dll"
Thu 19 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\yuvukina.dll"
Mon 23 Mar 2009 912 ..SH. --- "C:\WINDOWS\system32\yuwegiju.dll"
Tue 17 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\zafugiho.dll"
Mon 16 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\zitajalu.dll"
Mon 23 Mar 2009 912 ..SH. --- "C:\WINDOWS\system32\zulelolo.dll"
Fri 22 Jun 2007 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sun 23 Dec 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Thu 7 Dec 2006 3,096,576 A..H. --- "C:\Documents and Settings\HP_Administrateur\Application Data\U3\temp\Launchpad Removal.exe"
[b]Finished![/b] -
Contributeur sécuritésalut
1) Télécharge SDFix d' AndyManchesta
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe sur ton Bureau.
Double clique sur SDFix.exe et choisis Install. L'outil sera extrait à la racine du lecteur système (généralement le C:\)
N y touche pas pour l instant.
2) Redémarre en mode sans échec pour cela (tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter)
3) SDFix
* Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
* Appuie sur Y pour commencer le processus de nettoyage.
* Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
* Appuie sur une touche pour redémarrer le PC.
* Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
* Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
* Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
· Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
--------------------------
Si SDfix ne se lance pas (ça arrive!)
* Démarrer->Exécuter
* Copie/colle ceci dans la fenêtre :
%systemroot%\system32\cmd.exe /K %systemdrive%\SDFix\apps\FixPath.exe
* Clique sur ok, et valide.
* Redémarre et essaye de nouveau de lancer SDfix.
-
Salut,
ça ne fonctionne pas. Un message d'erreur s'affiche:
Script: C\DocumentsandSettings\HP_Administrateur\Bureau\GenProc\outils\message.vbs
Ligne: 2
Caract.: 1
Erreur: Le service ne peut être démarré parce qu'il est désactivé ou qu'aucun périphérique activé ne lui est associé
Code: 80070422
Source: (null) -
Contributeur sécuritésalut
comment sa vide normalement tous ton pc est répertorier a cette endroit
télécharge GenProc http://www.alt-shift-return.org/Info/Fichiers/GenProc.zip sur ton bureau
dézippe le dossier, double-clique sur GenProc.bat et poste le contenu du rapport qui s'ouvre
Aide en images : http://www.alt-shift-return.org/Info/GenProc-HowTo.html
-
Salut
Il n'y a rien qui s'affiche dans le gestionnaire des périphériques, c'est vide... -
Contributeur sécuritésalut a toi
clic droit sur le raccourcie du poste de travail puis tu clic sur propriété puis tu clic sur matériel et tu fini par gestionnaire de périphérique
- 1
- 2
- 3