Problème virus DeepScan
RésoluVoilà le message que l'anti-virus me donne:
DeepScan:Generic.PWStealer.D6ACDBA8
<System>==>C:\Windows\system32\svchost.exe [3504] (full dump)
Generic.PWStealer.0E96BF1A
<System>==>C:\Windows\system32\svchost.exe [3504] (memory dump)
Que dois-je faire pour régler le problème, s'il vous plait. Merci d'avance.
Configuration: Windows XP Firefox 2.0.0.6
28 réponses
Plusieurs jours après une détection par BitDefender de deux infections sur un PC Windows XP, l'utilisateur ne parvient pas à les supprimer ni à les mettre en quarantaine. L'échange cite Windows XP Édition familiale Service Pack 2, et des éléments comme DeepScan: Generic.PWStealer et des entrées système liées à svchost.exe apparaissent dans les rapports. Des réponses évoquent notamment la difficulté à supprimer le fichier soqwx32.sys et fournissent des rapports système et analyses (RSIT, HijackThis) pour aider au diagnostic. D'autres éléments mentionnent la cohabitation éventuelle avec d'autres outils de sécurité et des entrées de démarrage potentiellement malveillantes, sans conclusion ni état du fil.
-
j'ai donc relancé le scan sur la totalité et rien trouvé, par contre il y a des éléments ignorés dans le scan, est-ce que c'est normal car sur bit defender 2008 il n'y avait pas cette ligne "élément ignorés", merci d'avance.
-
Alors j'ai désinstallé bit defender 2008 et impossible de le réinstaller, en allant voir mon fournisseur informatique, il m'a dit que le 2008 avait eu de gros probléme mais que la société ne l'aurait pas trop ébruité pour raisons commerciales, j'ai donc acheté le 2010 et je l'installe ce soir.
-
impossible de faire le scan en ligne chez Kaspersky 'ERROR: licence périmée'
-
re,
Commencez par le Mises à jours de ces :
Java : https://www.java.com/fr/download/manual.jsp
Adobe : https://get2.adobe.com/reader/otherversions/
► À utiliser/vérifier aux 30jours.
Important pour prévenir les failles de sécurités des logiciels ayant un accès à Internet.
____________________________________________________________________
Ensute..
Allez faire un scan en ligne chez Kaspersky : https://www.kaspersky.fr/downloads
• Appuyer sur Online scanner Cliquer-ici !
• désactiver votre antivrus,
• Installer le plugin (si requis)
• Appuyer sur acceptez (en bas)
>> Les mises à jours vont avoir lieu (plusieurs minutes)
• Lancer le scanne du C:\... au complet
• Lorsque le scan sera complété -> Sauvegarderez le rapport
>>>>>>> Postez le rapport -
Alors, je suis allé sur un de mes jeux en lignes et j'ai relancé ,aprés avoir fermé internet avec Firefox, Bit defender sur mes archives et de nouveau les deux fichires avec DeepScanStealer sont réapparus, je vais relancé Malwarebyte pour voir.
-
Hier j'ai eu une fenêtre d'un logiciel que je ne connaissais pas "Total security 2009" avec une détection de 30 spywares, trojans, worms et j'en passe, j'ai relancé Malwarebytes qui a tout supprimé et j'ai supprimé aussi "Total security 2009" que je ne conaissais pas et qui été sur C:ProgramFiles. Ai-je bien fait?
De plus je me demande si Bit Defender Total Security 2008 est bien "installé" tout est "vert" mais je me pose des questions car il n'avais rien trouvé comme worms, trojans et compagnie. -
Logfile of random's system information tool 1.06 (written by random/random)
Run by Stéphane at 2009-09-05 14:23:19
Microsoft Windows XP Édition familiale Service Pack 2
System drive C: has 58 GB (24%) free of 238 GB
Total RAM: 3070 MB (87% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:23:24, on 05/09/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Stéphane\Bureau\RSIT.exe
C:\Program Files\trend micro\Stéphane.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
-
Le volume dans le lecteur C s'appelle 447907
Le num‚ro de s‚rie du volume est 844D-5D94
R‚pertoire de C:\WINDOWS\Minidump
31/08/2009 22:36 <REP> .
31/08/2009 22:36 <REP> ..
0 fichier(s) 0 octets
Total des fichiers list‚sÿ:
0 fichier(s) 0 octets
2 R‚p(s) 60ÿ446ÿ789ÿ632 octets libres -
Malwarebytes' Anti-Malware 1.40
Version de la base de données: 2744
Windows 5.1.2600 Service Pack 2
05/09/2009 14:05:15
mbam-log-2009-09-05 (14-05-15).txt
Type de recherche: Examen complet (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|)
Eléments examinés: 297767
Temps écoulé: 1 hour(s), 43 minute(s), 55 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 1
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\Documents and Settings\Stéphane\Application Data\wiaserva.log (Malware.Trace) -> Quarantined and deleted successfully. -
re,
Oui continuer.. -
soqwx32.sys not deleting
soqwx32.sys IS deleting
ikowin32.exe IS deleting
et je continue avec MAlwarebytes -
Et continuer avec les procédures du message #7 pour lesquels ces rapports sont à postez :
- Malwarebytes. (<--IMPORTANT)
- RapDump.txt" du fichier de commande
- Log.txt refait avec Rsit -
poster en même temps, je dois le refaire comme citer à 12h10?
-
soqwx32.sys not deleting
-
Si vous avez pas fait la procédure de la Citation au message précédent.
Utilisez plutôt le contenu de cette Citation :
if exist C:\Rap_Sup.txt del C:\Rap_Sup.txtAttrib -s -h -r C:\Windows\system32\drivers\soqwx32.sys del C:\Windows\system32\drivers\soqwx32.sys if exist "C:\Windows\system32\drivers\soqwx32.sys" (echo soqwx32.sys not deleting >> C:\Rap_Sup.txt) else echo soqwx32.sys IS deleting >> C:\Rap_Sup.txt Attrib -s -h -r "C:\Documents and Settings\Stéphane\Menu Démarrer\Programmes\Démarrage\ikowin32.exe" del "C:\Documents and Settings\Stéphane\Menu Démarrer\Programmes\Démarrage\ikowin32.exe" if exist "C:\Documents and Settings\Stéphane\Menu Démarrer\Programmes\Démarrage\ikowin32.exe" (echo ikowin32.exe not deleting >> C:\Rap_Sup.txt) else echo ikowin32.exe IS deleting >> C:\Rap_Sup.txt Start notepad C:\Rap_Sup.txt
-
re,
Oui supprimer Combofix avec selon la procédure.
Ensuite..
• Ouvrer le Bloc-note dans le Menu Démarrer --> Tout les programmes --> Accessoire,
• Copier/ coller le contenu de la Citation suivante dans le Bloc-Note,
• Dans le bloc-note sélectionner -> Fichier -> Enregistrer sous..
• Sauvegarder le Bloc-Note sous Sup_Fic.Bat (sur le bureau)
• Double-cliquer sur le fichier Sup_Fic.Bat
CitationAttrib -s -h -r C:\Windows\system32\drivers\soqwx32.sys if exist "C:\Windows\system32\drivers\soqwx32.sys" (del "C:\Windows\system32\drivers\soqwx32.sys") else echo soqwx32.sys not deleting > C:\Rap_Sup.txt Attrib -s -h -r "C:\Documents and Settings\Stéphane\Menu Démarrer\Programmes\Démarrage\ikowin32.exe" if exist "C:\Documents and Settings\Stéphane\Menu Démarrer\Programmes\Démarrage\ikowin32.exe" (del "C:\Documents and Settings\Stéphane\Menu Démarrer\Programmes\Démarrage\ikowin32.exe") else echo ikowin32.exe not deleting >> C:\Rap_Sup.txt Start notepad C:\Rap_Sup.txt
► Postez le fichier "Rap_Sup.txt" qui s'ouvrira à l'écran.
_________________________________________________________________
► Et continuer avec les procédures qui suivent au message #7, en postant leurs rapports. -
Pour être vraiment sur voici le contenu que j'ai pris, dites moi si c'est bien celui-ci et si je dois continuer la procédureplus haut "supprimer ComboFix" ou je me suis planter en quelque part?
-
vous entendez quoi par "si'ils y sonr"? sur le contenu? si c'est cela oui j'ai refait u cas où je me sois trompé de contenu quand même et je repost donc le nouveau rapport mais là encore je n'ai pas eu à taper 1 ou 2
ComboFix 09-09-03.02 - Stéphane 05/09/2009 0:54.5.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.33.1036.18.3070.2569 [GMT 2:00]
Running from: c:\documents and settings\Stéphane\Bureau\CB-F.exe
Command switches used :: c:\documents and settings\Stéphane\Bureau\CFScript.txt
AV: Bitdefender Antivirus *On-access scanning disabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: Bitdefender Firewall *disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2009-08-04 to 2009-09-04 )))))))))))))))))))))))))))))))
.
2009-09-04 16:18 . 2009-09-04 16:18 -------- d-----w- c:\program files\trend micro
2009-09-03 17:32 . 2009-09-03 17:32 -------- d-----w- C:\GenProc
2009-09-03 16:28 . 2009-09-03 16:28 -------- d-----w- C:\rsit
2009-08-31 20:29 . 2009-08-31 20:29 -------- d-----w- c:\program files\CCleaner
2009-08-28 23:57 . 2009-08-28 23:57 -------- d-----w- c:\program files\MSXML 6.0
2009-08-28 23:50 . 2009-08-28 23:50 -------- d-----w- c:\windows\ServicePackFiles
2009-08-06 12:48 . 2009-08-06 12:48 -------- d-----w- c:\program files\Paradox Interactive
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-04 22:57 . 2006-06-06 12:38 81984 ----a-w- c:\windows\system32\bdod.bin
2009-09-01 20:04 . 2008-01-25 13:40 86792 ----a-w- c:\windows\system32\drivers\bdfndisf.sys
2009-09-01 19:22 . 2008-04-02 17:03 -------- d-----w- c:\program files\Fichiers communs\BitDefender
2009-08-29 00:03 . 2006-02-24 04:13 86538 ----a-w- c:\windows\system32\perfc00C.dat
2009-08-29 00:03 . 2006-02-24 04:13 513818 ----a-w- c:\windows\system32\perfh00C.dat
2009-08-29 00:00 . 2009-08-29 00:00 -------- d-----w- c:\program files\MSBuild
2009-08-29 00:00 . 2009-08-29 00:00 -------- d-----w- c:\program files\Reference Assemblies
2009-08-21 11:09 . 2008-10-20 11:10 -------- d-----w- c:\program files\ATI
2009-08-05 17:21 . 2008-04-12 09:18 -------- d-----w- c:\program files\Safari
2009-08-05 17:18 . 2009-08-05 17:18 -------- d-----w- c:\program files\iPod
2009-08-05 17:18 . 2009-08-05 17:18 -------- d-----w- c:\program files\iTunes
2009-08-05 17:18 . 2007-07-05 11:39 -------- d-----w- c:\program files\Fichiers communs\Apple
2009-08-05 17:15 . 2007-05-10 11:38 -------- d-----w- c:\program files\QuickTime
2009-08-05 09:06 . 2004-08-05 12:00 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-29 04:53 . 2004-08-05 12:00 82432 ----a-w- c:\windows\system32\fontsub.dll
2009-07-29 04:53 . 2004-08-05 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-27 05:29 . 2008-09-06 18:04 -------- d-----w- c:\program files\BitComet
2009-07-23 12:35 . 2006-11-12 13:46 -------- d-----w- c:\program files\ArtMoney
2009-07-17 18:56 . 2004-08-05 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 21:43 . 2004-08-05 12:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-06-27 14:31 . 2007-09-27 19:36 281760 ----a-w- c:\windows\system32\drivers\atksgt.sys
2009-06-27 14:31 . 2007-09-27 19:36 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
2009-06-26 16:18 . 2004-08-05 12:00 663552 ------w- c:\windows\system32\wininet.dll
2009-06-26 16:18 . 2004-08-05 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
2009-06-25 08:44 . 2004-08-05 12:00 731136 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:44 . 2004-08-05 12:00 59392 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:44 . 2004-08-05 12:00 56320 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:44 . 2004-08-05 12:00 168448 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:44 . 2004-08-05 12:00 133632 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:44 . 2004-08-05 12:00 298496 ----a-w- c:\windows\system32\kerberos.dll
2009-06-22 11:34 . 2004-08-05 12:00 92544 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-15 11:33 . 2004-08-05 12:00 78848 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:23 . 2004-08-05 12:00 85504 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 06:30 . 2004-08-05 12:00 132096 ----a-w- c:\windows\system32\wkssvc.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 61440]
"BDAgent"="c:\program files\BitDefender\BitDefender 2008\bdagent.exe" [2009-09-01 368640]
c:\documents and settings\St‚phane\Menu D‚marrer\Programmes\D‚marrage\
ikowin32.exe [2004-8-5 26112]
c:\documents and settings\St‚phane\Menu D‚marrer\Programmes\D‚marrage\
ikowin32.exe [2004-8-5 26112]
c:\documents and settings\St‚phane\Menu D‚marrer\Programmes\D‚marrage\
ikowin32.exe [2004-8-5 26112]
c:\documents and settings\St‚phane\Menu D‚marrer\Programmes\D‚marrage\
ikowin32.exe [2004-8-5 26112]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\Msmsgs.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords_PitBoss.exe"=
"c:\\Program Files\\Ubisoft\\Funatics\\The Settlers II - 10th Anniversary\\bin\\S2DNG.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Documents and Settings\\Stéphane\\Mes documents\\internet\\abandonware\\warhammer\\wardark\\ENGREL.EXE"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Ubisoft\\THE SETTLERS - Bâtisseurs d'Empire\\base\\bin\\Settlers6.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
"c:\\Program Files\\2K Games\\Firaxis Games\\Sid Meier's Civilization IV Colonization\\Colonization.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Ubisoft\\Related Designs\\ANNO 1404\\Anno4.exe"=
"c:\\Program Files\\Ubisoft\\Related Designs\\ANNO 1404\\tools\\Anno4Web.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Paradox Interactive\\East India Company Demo\\eastindia.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"20817:TCP"= 20817:TCP:BitComet 20817 TCP
"20817:UDP"= 20817:UDP:BitComet 20817 UDP
R2 acedrv11;acedrv11;c:\windows\system32\drivers\ACEDRV11.sys [23/01/2008 10:19 501560]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [25/01/2008 15:40 86792]
S1 soqwx32;soqwx32;\??\c:\windows\system32\drivers\soqwx32.sys --> c:\windows\system32\drivers\soqwx32.sys [?]
S2 FILESpy;FILESpy;\??\c:\program files\Softwin\BitDefender9\filespy.sys --> c:\program files\Softwin\BitDefender9\filespy.sys [?]
S3 FXDRV;FXDRV;\??\d:\fxdrv.sys --> d:\Fxdrv.sys [?]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
.
Contents of the 'Scheduled Tasks' folder
2009-09-02 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-09-04 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 10:20]
.
.
------- Supplementary Scan -------
.
uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-05 00:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bdfsfltr]
"ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bdfsfltr]
"ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-1929738347-3376605301-1782770845-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_USERS\S-1-5-21-1929738347-3376605301-1782770845-1007\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:d2,ec,92,73,00,b0,e6,51,0a,14,4a,a9,6a,c3,a1,17,07,f0,ca,d8,7c,dd,be,
e1,88,52,b8,8d,61,29,e7,dc,cb,32,2d,3a,b4,ac,73,30,40,34,6d,76,2b,12,ce,84,\
"??"=hex:b6,67,2b,cd,ca,15,9f,32,97,f9,4f,4b,0d,95,c6,4b
[HKEY_USERS\S-1-5-21-1929738347-3376605301-1782770845-1007\Software\SecuROM\License information*]
"datasecu"=hex:3d,d1,0b,a4,7f,d4,83,a3,d1,59,ac,1e,3a,f9,ed,48,34,a9,53,90,7a,
13,05,df,06,c2,db,94,09,0d,67,49,f7,24,4f,97,19,9e,7f,e2,a0,64,46,8a,3f,49,\
"rkeysecu"=hex:bd,8f,c9,3d,e7,84,cf,b5,1d,4b,81,c8,ac,8b,3c,6e
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"C040211900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\ð•€|ÿÿÿÿ.•€|ù•9~*]
"C040211900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(956)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(7860)
c:\progra~1\FICHIE~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
c:\program files\Fichiers communs\Microsoft Shared\Web Components\11\1036\OWCI11.DLL
c:\windows\system32\shdoclc.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2009-09-04 0:59
ComboFix-quarantined-files.txt 2009-09-04 22:59
ComboFix2.txt 2009-09-04 22:43
ComboFix3.txt 2009-09-04 19:07
Pre-Run: 57 839 398 912 octets libres
Post-Run: 57 827 897 344 octets libres
171 --- E O F --- 2009-08-29 00:06 -
re,
Vous vérifierez, s'ils y sont, pour suppirmer ces fichiers :
C:\Documents and Settings\Stéphane\Menu Démarrer\Programmes\Démarrage\ikowin32.exe
Et
C:\Windows\system32\drivers\soqwx32.sys ?
Donnez en des nouvelles.. -
par contre je n'ai pas eu la phrase "à vos risque" ni taper 1 ou 2, je n'aurais pas fais une erreur?
- 1
- 2