487d.exe
qui peut me dire ce qu'est 487d.exe?
Configuration: Windows Vista Firefox 3.5.6
49 réponses
La présence potentielle du fichier 487d.exe sur Windows Vista et Firefox 3.5.6 soulève des questions sur les méthodes pour l’identifier et évaluer s’il agit comme un logiciel malveillant. Des conseils préconisent des outils dédiés, comme ZHPDiag pour l’analyse et la génération de rapports, GMER Scanner pour les rootkits, puis la vérification du MBR avec mbr.exe, avec des instructions d’exécution administrateur et désactivation temporaire. Des précautions supplémentaires soulignent la prudence lors des manipulations sensibles et suggèrent de sauvegarder et transmettre les rapports de scan pour obtenir une aide ultérieure.
-
Contributeur sécuritéBonsoir,
comme ces bestioles ont l'habitude d'inviter des "amis", je te suggère de vérifier ce qu'il en est.
Fais redémarrer l'ordi.
Télécharge la dernière version de ZHPDiag
Enregistre le sur ton Bureau.
Une fois le téléchargement achevé,fais un double clic sur ZHPDiag.exe et suis les instructions.
N'oublie pas de cocher la case qui permet de mettre un raccourci sur le Bureau.
pour Xp :Double clique sur le raccourci ZHPDiag sur ton Bureau.
pour vista et Seven : fais un clic droit sur le raccourci ZHPDiag sur ton Bureau et choisis "exécuter en tant qu'administrateur".
/|\ l'outil a créé 2 icônes ZHPDiag et ZHPFix.
Clique sur la loupe pour lancer l'analyse.
Laisse l'outil travailler, il peut être assez long.
Ferme ZHPDiag en fin d'analyse.
Pour transmettre le rapport clique sur Cijoint
Clique sur Parcourir et cherche le répertoire où est installé ZHPDiag (en général C:\Program Files\ZHPDiag).
Sélectionne le fichier ZHPDiag.txt.
Clique sur "Cliquez ici pour déposer le fichier".
Un lien de cette forme :
http://www.cijoint.fr/cjlink.php?file=cj200905/cijSKAP5fU.txt
est ajouté dans la page.
Copie ce lien dans ta réponse. -
Contributeur sécuritéBonjour,
up (pour voir si ça fait apparaître quelque chose).
Si rien n'apparaît, essaye de transmettre le rapport dans un lien Cijoint :
Pour transmettre le rapport clique sur Cijoint
Clique sur Parcourir et cherche le répertoire où est installé ZHPDiag (en général C:\Program Files\ZHPDiag).
Sélectionne le fichier ZHPDiag.txt.
Clique sur "Cliquez ici pour déposer le fichier".
Un lien de cette forme :
http://www.cijoint.fr/cjlink.php?file=cj200905/cijSKAP5fU.txt
est ajouté dans la page.
Copie ce lien dans ta réponse.
-
pourquoi mon post n'apparaît pas???
-
ok je fais ça et je reviens poster un résultat si il y en a un qui apparaît??? :-)
-
Contributeur sécuritéBonjour,
décoche aussi la case "modules" et réessaye de lancer le scan de gmer. -
L'ordi se coupe (écran bleu et redémarrage) à chaque fin de scan et pas possible de faire un save et de poster le résultat.
-
Contributeur sécuritéRe,
comme je craignais, il reste un truc dans la mbr à vérifier.
Télécharge GMER Scanner de rootkit
- télécharge le .exe sur ton Bureau . Retiens son nom car il est aléatoire.
- exécute le en faisant un double clic sur le fichier créé. Néglige les alertes.
- le chargement va prendre une minute.
- si des rootkits sont décelés, répond non quand on te demande si tu veux faire un scan complet (Full scan).
- règle les paramètres (fenêtre de droite) de la manière suivante :
# Sections : décochée
# IAT/EAT : décochée
# seule la partition système (en général C:\ ) doit rester cochée
# Show All : décochée
clique sur "SCAN" puis patiente...
En fin de traitement clique sur "SAVE" et enregistre sur le Bureau "010110.txt"
Double clique sur "010110.txt" ; le fichier s'ouvre dans le bloc-notes
.
Copie le contenu et colle le dans ta réponse.
-
ComboFix 09-12-31.A1 - GIANNI 01/01/2010 23:17:43.5.1 - x86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6002.2.1252.32.1036.18.895.363 [GMT 1:00]
Lancé depuis: c:\users\GIANNI\Desktop\ComboFix.exe
AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
SP: Avira AntiVir PersonalEdition *enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
SP: VirusScan Enterprise + AntiSpyware Enterprise *enabled* (Updated) {24E45799-D058-4314-AC5D-1B2EE5C3151F}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-12-01 au 2010-01-01 ))))))))))))))))))))))))))))))))))))
.
2010-01-01 22:26 . 2010-01-01 22:26 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-01-01 22:26 . 2010-01-01 22:26 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-12-31 19:41 . 2009-12-31 20:08 -------- d-----w- c:\program files\MyDefrag v4.2.7
2009-12-31 19:41 . 2009-12-16 00:11 935424 ----a-w- c:\windows\system32\MyDefragScreenSaver.exe
2009-12-31 19:41 . 2009-12-15 22:02 93696 ----a-w- c:\windows\system32\MyDefragScreenSaver.scr
2009-12-31 17:46 . 2009-12-31 17:54 -------- d-----w- c:\users\GIANNI\AppData\Roaming\QuickScan
2009-12-31 05:38 . 2010-01-01 16:51 -------- d-sh--w- c:\users\GIANNI\AppData\Roaming\lowsec
2009-12-27 10:01 . 2009-12-27 10:02 -------- d-----w- c:\users\GIANNI\AppData\Roaming\U3
2009-12-26 17:46 . 2009-12-26 17:46 -------- d-----w- c:\users\GIANNI\AppData\Roaming\TuneUp Software
2009-12-24 09:17 . 2009-12-27 15:42 -------- d-----w- c:\program files\VS Revo Group
2009-12-23 22:51 . 2009-12-25 08:53 -------- d-----w- c:\program files\Ad-Remover
2009-12-23 22:42 . 2009-12-24 00:08 -------- d-----w- c:\program files\trend micro
2009-12-23 22:03 . 2009-12-23 22:03 -------- d-----w- c:\users\GIANNI\AppData\Roaming\igraal
2009-12-20 20:11 . 2009-12-29 10:51 -------- d-----w- c:\users\GIANNI\AppData\Roaming\dvdcss
2009-12-19 22:45 . 2009-12-19 22:45 -------- d-sh--w- c:\programdata\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2009-12-19 13:45 . 2009-12-03 15:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-19 13:45 . 2009-12-03 15:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-15 20:19 . 2009-12-15 20:19 3175784 ----a-w- c:\users\GIANNI\AppData\Roaming\Uniblue\RegistryBooster 2010\_temp\ub.exe
2009-12-15 19:23 . 2009-12-15 20:20 -------- d-----w- c:\users\GIANNI\AppData\Roaming\Uniblue
2009-12-14 11:59 . 2008-09-29 07:07 90360 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-12-14 11:59 . 2008-09-29 07:07 74648 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
2009-12-14 11:59 . 2008-09-29 07:07 67904 ----a-w- c:\windows\system32\mfevtps.exe
2009-12-14 11:59 . 2008-09-29 07:07 64432 ----a-w- c:\windows\system32\drivers\mferkdet.sys
2009-12-14 11:59 . 2008-09-29 07:07 62704 ----a-w- c:\windows\system32\drivers\mfetdik.sys
2009-12-14 11:59 . 2008-09-29 07:07 42424 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-12-14 11:59 . 2008-09-29 07:07 340592 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-12-14 11:58 . 2009-12-14 11:58 -------- d-----w- c:\program files\Common Files\McAfee
2009-12-11 13:23 . 2009-11-09 12:31 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-12-11 13:23 . 2009-11-09 10:36 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-12-11 13:23 . 2009-11-09 12:30 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-12-09 21:22 . 2009-08-24 11:36 377344 ----a-w- c:\windows\system32\winhttp.dll
2009-12-09 21:18 . 2009-10-07 11:36 243712 ----a-w- c:\windows\system32\rastls.dll
2009-12-09 11:03 . 2009-12-30 21:36 -------- d-----w- C:\QUARANTINE
2009-12-09 10:53 . 2009-12-09 10:53 -------- d-----w- c:\program files\Common Files\Cisco Systems
2009-12-09 10:53 . 2009-12-14 11:58 -------- d-----w- c:\program files\McAfee
2009-12-06 10:42 . 2009-12-06 10:42 -------- d-----w- c:\users\GIANNI\AppData\Roaming\Malwarebytes
2009-12-06 10:42 . 2009-12-19 13:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-05 13:01 . 2009-12-14 11:59 -------- d-----w- c:\programdata\McAfee
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-01 20:38 . 2009-11-28 16:57 -------- d-----w- c:\users\GIANNI\AppData\Roaming\vlc
2010-01-01 19:10 . 2007-06-12 07:33 -------- d-----w- c:\program files\Java
2009-12-31 19:43 . 2009-11-03 08:12 -------- d-----w- c:\program files\JkDefrag
2009-12-31 05:40 . 2009-10-31 10:28 -------- d-----w- c:\users\GIANNI\AppData\Roaming\uTorrent
2009-12-27 05:56 . 2006-11-02 15:48 669328 ----a-w- c:\windows\system32\perfh00C.dat
2009-12-27 05:56 . 2006-11-02 15:48 123350 ----a-w- c:\windows\system32\perfc00C.dat
2009-12-24 09:30 . 2007-07-04 20:43 -------- d-----w- c:\program files\Messenger Plus! Live
2009-12-22 21:57 . 2009-08-01 08:57 19944 ----a-w- c:\windows\system32\drivers\atapi.sys
2009-12-19 22:47 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-12-10 14:30 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-12-09 11:08 . 2007-12-02 19:47 -------- d-----w- c:\program files\CCleaner
2009-12-07 15:10 . 2009-07-21 16:37 1 ----a-w- c:\users\GIANNI\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-12-06 10:15 . 2009-11-06 15:30 -------- d-----w- c:\programdata\Messenger Plus!
2009-12-02 17:24 . 2009-12-02 17:24 -------- d-----w- c:\program files\uTorrent
2009-12-02 09:28 . 2007-08-01 17:30 -------- d-----w- c:\program files\Common Files\Adobe
2009-11-30 19:22 . 2009-11-30 19:22 -------- d-----w- c:\program files\MSECache
2009-11-21 06:40 . 2009-12-09 21:19 916480 ----a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-09 21:19 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-11-21 06:34 . 2009-12-09 21:19 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-11-21 04:59 . 2009-12-09 21:19 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-11-17 23:26 . 2009-11-17 23:26 -------- d-----w- c:\program files\Windows Portable Devices
2009-11-17 23:25 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-17 23:25 . 2009-11-17 23:25 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-08 16:53 . 2009-11-08 16:53 -------- d-----w- c:\program files\Digital Support
2009-11-08 16:45 . 2007-08-12 10:28 -------- d-----w- c:\users\GIANNI\AppData\Roaming\XnView
2009-11-07 18:43 . 2007-07-04 20:43 -------- d-----w- c:\program files\Windows Live
2009-11-06 15:31 . 2008-08-16 08:14 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-11-06 15:27 . 2008-03-26 12:11 -------- d-----w- c:\program files\Common Files\Sony Ericsson Shared
2009-11-04 15:31 . 2009-11-04 15:31 -------- d-----w- c:\programdata\Malwarebytes
2009-11-03 11:35 . 2009-11-03 11:35 -------- d-----w- c:\program files\Common Files\SupportSoft
2009-11-02 19:42 . 2009-11-02 08:10 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-02 06:53 . 2007-07-11 18:41 8052 ----a-w- c:\users\GIANNI\AppData\Local\d3d9caps.dat
2009-10-29 09:17 . 2009-11-28 11:42 2048 ----a-w- c:\windows\system32\tzres.dll
2009-10-22 19:07 . 2009-10-22 19:07 20768 ----a-w- c:\windows\system32\MFEOtlk.dll
2009-10-11 03:17 . 2008-12-11 08:09 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-08 21:08 . 2009-11-17 19:53 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2009-10-08 21:08 . 2009-11-17 19:53 234496 ----a-w- c:\windows\system32\oleacc.dll
2009-10-08 21:07 . 2009-11-17 19:53 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2008-09-29 07:07 . 2009-12-14 11:59 22576 ----a-w- c:\program files\mozilla firefox\components\Scriptff.dll
2008-04-18 17:18 . 2008-04-18 17:18 5 --sha-w- c:\windows\System32\abffafee_s.dll
2008-04-18 17:00 . 2008-04-18 17:00 23 --sha-w- c:\windows\System32\eddafffc_z.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2008-03-14 136512]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2008-09-29 124240]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-12-03 1394000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\McAfeeEngineService]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-09-04 11:08 935288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 03:08 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-18 21:33 125952 ----a-w- c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2009-05-08 08:35 2780432 ----a-w- c:\program files\Logitech\Logitech WebCam Software\LWS.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2009-12-03 15:14 1394000 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2009-12-03 15:14 429392 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shockwave Updater]
2009-01-16 18:25 460216 ----a-w- c:\windows\System32\Adobe\Shockwave 11\SwHelper_1103472.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28 1233920 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-11 03:17 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-01-09 07:54 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2009-12-05 14:01 289584 ----a-w- c:\program files\uTorrent\uTorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-18 21:33 202240 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WPCUMI]
2006-11-02 12:35 176128 ----a-w- c:\windows\System32\wpcumi.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):52,1e,d3,ec,8c,12,ca,01
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [19/12/2009 14:45 276816]
R2 McAfeeEngineService;McAfee Engine Service;c:\program files\McAfee\VirusScan Enterprise\EngineServer.exe [29/09/2008 8:07 19456]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\System32\mfevtps.exe [14/12/2009 12:59 67904]
R3 MBAMProtector;MBAMProtector;c:\windows\System32\drivers\mbam.sys [19/12/2009 14:45 19160]
S3 FontCache;Service de cache de police Windows;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [4/04/2008 23:20 21504]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\System32\drivers\mferkdet.sys [14/12/2009 12:59 64432]
S3 s115bus;s115bus;c:\windows\System32\drivers\s115bus.sys [26/03/2008 13:16 83208]
S3 s115mdfl;s115mdfl;c:\windows\System32\drivers\s115mdfl.sys [26/03/2008 13:17 15112]
S3 s115mdm;s115mdm;c:\windows\System32\drivers\s115mdm.sys [26/03/2008 13:17 108680]
S3 s115mgmt;s115mgmt;c:\windows\System32\drivers\s115mgmt.sys [26/03/2008 13:19 100488]
S3 s115obex;s115obex;c:\windows\System32\drivers\s115obex.sys [26/03/2008 13:18 98568]
S3 SMCWGU(SMC);SMCWUSB-G 802.11g Wireless USB 2.0 Adapter(SMC);c:\windows\System32\drivers\SMCWGU.sys [29/11/2008 16:39 408064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contenu du dossier 'Tâches planifiées'
2010-01-01 c:\windows\Tasks\User_Feed_Synchronization-{A5599F64-821C-40E3-9000-71BE4A8BFA04}.job
- c:\windows\system32\msfeedssync.exe [2009-12-09 04:59]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.macmurphy11.spaces.live.com/
uSearchMigratedDefaultURL = hxxp://google.cherche.us/Result.php?client=pub-0420647136319153&cof=GIMP%3A009900%3BT%3A000000%3BALC%3A551a8b%3BGFNT%3AB7B7B7%3BLC%3A2200cc%3BBGC%3AFFFFFF%3BVLC%3A551a8b%3BGALT%3A008B45%3BFORID%3A11%3BDIV%3A%23FFFFF0%3B&ie=ISO-8859-1&q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mWindow Title =
FF - ProfilePath - c:\users\GIANNI\AppData\Roaming\Mozilla\Firefox\Profiles\vcyp6mlg.default\
FF - prefs.js: browser.search.defaulturl - hxxp://fr.search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Ask
FF - prefs.js: browser.startup.homepage - hxxp://www.macmurphy11.spaces.live.com
FF - prefs.js: keyword.URL - hxxp://google.cherche.us/Result.php?client=pub-0420647136319153&cof=GIMP%3A009900%3BT%3A000000%3BALC%3A551a8b%3BGFNT%3AB7B7B7%3BLC%3A2200cc%3BBGC%3AFFFFFF%3BVLC%3A551a8b%3BGALT%3A008B45%3BFORID%3A11%3BDIV%3A%23FFFFF0%3B&ie=ISO-8859-1&q=
FF - component: c:\program files\Mozilla Firefox\components\Scriptff.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\GIANNI\AppData\Roaming\Mozilla\plugins\npcoolirisplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-01 23:26
Windows 6.0.6002 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8366F618]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0x8250dd24
\Driver\ACPI -> acpi.sys @ 0x80612d68
\Driver\atapi -> ataport.SYS @ 0x80721a2c
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->user & kernel MBR OK
**************************************************************************
.
Heure de fin: 2010-01-01 23:31:28
ComboFix-quarantined-files.txt 2010-01-01 22:31
ComboFix2.txt 2010-01-01 21:39
ComboFix3.txt 2010-01-01 19:57
Avant-CF: 122.574.872.576 octets libres
Après-CF: 122.581.041.152 octets libres
- - End Of File - - 2CE6A1437C1EC519350E99ADCC919CE3 -
Contributeur sécuritéRe,
Déconnecte toi d'Internet et ferme toutes tes applications.
désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)
double-clique sur combofix.exe et suis les instructions
à la fin, il va produire un rapport C:\ComboFix.txt
réactive ton parefeu, ton antivirus, la garde de ton antispyware
copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.
-
et je dois faire quoi??? suis un peu perdu là....
-
c le drenier rapport oui ....
-
Contributeur sécuritéRe,
c'est le dernier rapport ?
Dans le premier, tu avais aussi :
detected MBR rootkit hooks:
comme dans le rapport de Combofix ? -
effectivement
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK -
Contributeur sécuritéRe,
Télécharge mbr.exe de Gmer ici :
http://www2.gmer.net/mbr/mbr.exe
et enregistre le fichier sur le Bureau.
Merci à Malekal pour le tutoriel
Désactive tes protections et coupe la connexion. (Antivirus et antispywares, HIPS et autre résident)
Lance mbr.exe par clic droit et Exécuter en tant qu'administrateur.
Un rapport sera généré : mbr.log
En cas d'infection, ce message "MBR rootkit code detected" va apparaitre.
Dans le menu Démarrer- Exécuter tape : "%userprofile%\Bureau\mbr" -f
Dans le mbr.log cette ligne apparaitra "original MBR restored successfully !"
Réactive tes protections
Poste ce rapport et supprimes-le ensuite.
Pour vérifier
Désactive tes protections et coupe la connexion. (Antivirus et antispywares, HIPS et autre résident)
Lancer mbr.exe par clic droit et Exécuter en tant qu'administrateur.
Réactive tes protections.
Le nouveau mbr.log devrait être celui-ci :
Stealth MBR rootkit detector 0.2.4 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
kernel: MBR read successfully
user & kernel MBR OK
-
ComboFix 09-12-31.A1 - GIANNI 01/01/2010 22:18:57.4.1 - x86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6002.2.1252.32.1036.18.895.440 [GMT 1:00]
Lancé depuis: c:\users\GIANNI\Desktop\ComboFix.exe
Commutateurs utilisés :: c:\users\GIANNI\Desktop\CFscript.txt
AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning disabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
SP: Avira AntiVir PersonalEdition *enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
SP: VirusScan Enterprise + AntiSpyware Enterprise *disabled* (Updated) {24E45799-D058-4314-AC5D-1B2EE5C3151F}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-12-01 au 2010-01-01 ))))))))))))))))))))))))))))))))))))
.
2010-01-01 21:27 . 2010-01-01 21:27 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-01-01 21:27 . 2010-01-01 21:27 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-12-31 19:41 . 2009-12-31 20:08 -------- d-----w- c:\program files\MyDefrag v4.2.7
2009-12-31 19:41 . 2009-12-16 00:11 935424 ----a-w- c:\windows\system32\MyDefragScreenSaver.exe
2009-12-31 19:41 . 2009-12-15 22:02 93696 ----a-w- c:\windows\system32\MyDefragScreenSaver.scr
2009-12-31 17:46 . 2009-12-31 17:54 -------- d-----w- c:\users\GIANNI\AppData\Roaming\QuickScan
2009-12-31 05:38 . 2010-01-01 16:51 -------- d-sh--w- c:\users\GIANNI\AppData\Roaming\lowsec
2009-12-27 10:01 . 2009-12-27 10:02 -------- d-----w- c:\users\GIANNI\AppData\Roaming\U3
2009-12-26 17:46 . 2009-12-26 17:46 -------- d-----w- c:\users\GIANNI\AppData\Roaming\TuneUp Software
2009-12-24 09:17 . 2009-12-27 15:42 -------- d-----w- c:\program files\VS Revo Group
2009-12-23 22:51 . 2009-12-25 08:53 -------- d-----w- c:\program files\Ad-Remover
2009-12-23 22:42 . 2009-12-24 00:08 -------- d-----w- c:\program files\trend micro
2009-12-23 22:03 . 2009-12-23 22:03 -------- d-----w- c:\users\GIANNI\AppData\Roaming\igraal
2009-12-20 20:11 . 2009-12-29 10:51 -------- d-----w- c:\users\GIANNI\AppData\Roaming\dvdcss
2009-12-19 22:45 . 2009-12-19 22:45 -------- d-sh--w- c:\programdata\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2009-12-19 13:45 . 2009-12-03 15:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-19 13:45 . 2009-12-03 15:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-15 20:19 . 2009-12-15 20:19 3175784 ----a-w- c:\users\GIANNI\AppData\Roaming\Uniblue\RegistryBooster 2010\_temp\ub.exe
2009-12-15 19:23 . 2009-12-15 20:20 -------- d-----w- c:\users\GIANNI\AppData\Roaming\Uniblue
2009-12-14 11:59 . 2008-09-29 07:07 90360 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-12-14 11:59 . 2008-09-29 07:07 74648 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
2009-12-14 11:59 . 2008-09-29 07:07 67904 ----a-w- c:\windows\system32\mfevtps.exe
2009-12-14 11:59 . 2008-09-29 07:07 64432 ----a-w- c:\windows\system32\drivers\mferkdet.sys
2009-12-14 11:59 . 2008-09-29 07:07 62704 ----a-w- c:\windows\system32\drivers\mfetdik.sys
2009-12-14 11:59 . 2008-09-29 07:07 42424 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-12-14 11:59 . 2008-09-29 07:07 340592 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-12-14 11:58 . 2009-12-14 11:58 -------- d-----w- c:\program files\Common Files\McAfee
2009-12-11 13:23 . 2009-11-09 12:31 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-12-11 13:23 . 2009-11-09 10:36 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-12-11 13:23 . 2009-11-09 12:30 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-12-09 21:22 . 2009-08-24 11:36 377344 ----a-w- c:\windows\system32\winhttp.dll
2009-12-09 21:18 . 2009-10-07 11:36 243712 ----a-w- c:\windows\system32\rastls.dll
2009-12-09 11:03 . 2009-12-30 21:36 -------- d-----w- C:\QUARANTINE
2009-12-09 10:53 . 2009-12-09 10:53 -------- d-----w- c:\program files\Common Files\Cisco Systems
2009-12-09 10:53 . 2009-12-14 11:58 -------- d-----w- c:\program files\McAfee
2009-12-06 10:42 . 2009-12-06 10:42 -------- d-----w- c:\users\GIANNI\AppData\Roaming\Malwarebytes
2009-12-06 10:42 . 2009-12-19 13:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-05 13:01 . 2009-12-14 11:59 -------- d-----w- c:\programdata\McAfee
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-01 20:38 . 2009-11-28 16:57 -------- d-----w- c:\users\GIANNI\AppData\Roaming\vlc
2010-01-01 19:10 . 2007-06-12 07:33 -------- d-----w- c:\program files\Java
2009-12-31 19:43 . 2009-11-03 08:12 -------- d-----w- c:\program files\JkDefrag
2009-12-31 05:40 . 2009-10-31 10:28 -------- d-----w- c:\users\GIANNI\AppData\Roaming\uTorrent
2009-12-27 05:56 . 2006-11-02 15:48 669328 ----a-w- c:\windows\system32\perfh00C.dat
2009-12-27 05:56 . 2006-11-02 15:48 123350 ----a-w- c:\windows\system32\perfc00C.dat
2009-12-24 09:30 . 2007-07-04 20:43 -------- d-----w- c:\program files\Messenger Plus! Live
2009-12-22 21:57 . 2009-08-01 08:57 19944 ----a-w- c:\windows\system32\drivers\atapi.sys
2009-12-19 22:47 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-12-10 14:30 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-12-09 11:08 . 2007-12-02 19:47 -------- d-----w- c:\program files\CCleaner
2009-12-07 15:10 . 2009-07-21 16:37 1 ----a-w- c:\users\GIANNI\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-12-06 10:15 . 2009-11-06 15:30 -------- d-----w- c:\programdata\Messenger Plus!
2009-12-02 17:24 . 2009-12-02 17:24 -------- d-----w- c:\program files\uTorrent
2009-12-02 09:28 . 2007-08-01 17:30 -------- d-----w- c:\program files\Common Files\Adobe
2009-11-30 19:22 . 2009-11-30 19:22 -------- d-----w- c:\program files\MSECache
2009-11-21 06:40 . 2009-12-09 21:19 916480 ----a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-09 21:19 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-11-21 06:34 . 2009-12-09 21:19 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-11-21 04:59 . 2009-12-09 21:19 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-11-17 23:26 . 2009-11-17 23:26 -------- d-----w- c:\program files\Windows Portable Devices
2009-11-17 23:25 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-17 23:25 . 2009-11-17 23:25 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-08 16:53 . 2009-11-08 16:53 -------- d-----w- c:\program files\Digital Support
2009-11-08 16:45 . 2007-08-12 10:28 -------- d-----w- c:\users\GIANNI\AppData\Roaming\XnView
2009-11-07 18:43 . 2007-07-04 20:43 -------- d-----w- c:\program files\Windows Live
2009-11-06 15:31 . 2008-08-16 08:14 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-11-06 15:27 . 2008-03-26 12:11 -------- d-----w- c:\program files\Common Files\Sony Ericsson Shared
2009-11-04 15:31 . 2009-11-04 15:31 -------- d-----w- c:\programdata\Malwarebytes
2009-11-03 11:35 . 2009-11-03 11:35 -------- d-----w- c:\program files\Common Files\SupportSoft
2009-11-02 19:42 . 2009-11-02 08:10 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-02 06:53 . 2007-07-11 18:41 8052 ----a-w- c:\users\GIANNI\AppData\Local\d3d9caps.dat
2009-10-29 09:17 . 2009-11-28 11:42 2048 ----a-w- c:\windows\system32\tzres.dll
2009-10-22 19:07 . 2009-10-22 19:07 20768 ----a-w- c:\windows\system32\MFEOtlk.dll
2009-10-11 03:17 . 2008-12-11 08:09 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-08 21:08 . 2009-11-17 19:53 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2009-10-08 21:08 . 2009-11-17 19:53 234496 ----a-w- c:\windows\system32\oleacc.dll
2009-10-08 21:07 . 2009-11-17 19:53 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2008-09-29 07:07 . 2009-12-14 11:59 22576 ----a-w- c:\program files\mozilla firefox\components\Scriptff.dll
2008-04-18 17:18 . 2008-04-18 17:18 5 --sha-w- c:\windows\System32\abffafee_s.dll
2008-04-18 17:00 . 2008-04-18 17:00 23 --sha-w- c:\windows\System32\eddafffc_z.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2008-03-14 136512]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2008-09-29 124240]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-12-03 1394000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\McAfeeEngineService]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-09-04 11:08 935288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 03:08 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-18 21:33 125952 ----a-w- c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2009-05-08 08:35 2780432 ----a-w- c:\program files\Logitech\Logitech WebCam Software\LWS.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2009-12-03 15:14 1394000 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2009-12-03 15:14 429392 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shockwave Updater]
2009-01-16 18:25 460216 ----a-w- c:\windows\System32\Adobe\Shockwave 11\SwHelper_1103472.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28 1233920 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-11 03:17 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-01-09 07:54 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2009-12-05 14:01 289584 ----a-w- c:\program files\uTorrent\uTorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-18 21:33 202240 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WPCUMI]
2006-11-02 12:35 176128 ----a-w- c:\windows\System32\wpcumi.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):52,1e,d3,ec,8c,12,ca,01
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [19/12/2009 14:45 276816]
R2 McAfeeEngineService;McAfee Engine Service;c:\program files\McAfee\VirusScan Enterprise\EngineServer.exe [29/09/2008 8:07 19456]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\System32\mfevtps.exe [14/12/2009 12:59 67904]
R3 MBAMProtector;MBAMProtector;c:\windows\System32\drivers\mbam.sys [19/12/2009 14:45 19160]
S3 FontCache;Service de cache de police Windows;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [4/04/2008 23:20 21504]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\System32\drivers\mferkdet.sys [14/12/2009 12:59 64432]
S3 s115bus;s115bus;c:\windows\System32\drivers\s115bus.sys [26/03/2008 13:16 83208]
S3 s115mdfl;s115mdfl;c:\windows\System32\drivers\s115mdfl.sys [26/03/2008 13:17 15112]
S3 s115mdm;s115mdm;c:\windows\System32\drivers\s115mdm.sys [26/03/2008 13:17 108680]
S3 s115mgmt;s115mgmt;c:\windows\System32\drivers\s115mgmt.sys [26/03/2008 13:19 100488]
S3 s115obex;s115obex;c:\windows\System32\drivers\s115obex.sys [26/03/2008 13:18 98568]
S3 SMCWGU(SMC);SMCWUSB-G 802.11g Wireless USB 2.0 Adapter(SMC);c:\windows\System32\drivers\SMCWGU.sys [29/11/2008 16:39 408064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contenu du dossier 'Tâches planifiées'
2010-01-01 c:\windows\Tasks\User_Feed_Synchronization-{A5599F64-821C-40E3-9000-71BE4A8BFA04}.job
- c:\windows\system32\msfeedssync.exe [2009-12-09 04:59]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.macmurphy11.spaces.live.com/
uSearchMigratedDefaultURL = hxxp://google.cherche.us/Result.php?client=pub-0420647136319153&cof=GIMP%3A009900%3BT%3A000000%3BALC%3A551a8b%3BGFNT%3AB7B7B7%3BLC%3A2200cc%3BBGC%3AFFFFFF%3BVLC%3A551a8b%3BGALT%3A008B45%3BFORID%3A11%3BDIV%3A%23FFFFF0%3B&ie=ISO-8859-1&q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mWindow Title =
FF - ProfilePath - c:\users\GIANNI\AppData\Roaming\Mozilla\Firefox\Profiles\vcyp6mlg.default\
FF - prefs.js: browser.search.defaulturl - hxxp://fr.search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Ask
FF - prefs.js: browser.startup.homepage - hxxp://www.macmurphy11.spaces.live.com
FF - prefs.js: keyword.URL - hxxp://google.cherche.us/Result.php?client=pub-0420647136319153&cof=GIMP%3A009900%3BT%3A000000%3BALC%3A551a8b%3BGFNT%3AB7B7B7%3BLC%3A2200cc%3BBGC%3AFFFFFF%3BVLC%3A551a8b%3BGALT%3A008B45%3BFORID%3A11%3BDIV%3A%23FFFFF0%3B&ie=ISO-8859-1&q=
FF - component: c:\program files\Mozilla Firefox\components\Scriptff.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\GIANNI\AppData\Roaming\Mozilla\plugins\npcoolirisplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-01 22:31
Windows 6.0.6002 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8366F618]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0x8250dd24
\Driver\ACPI -> acpi.sys @ 0x80612d68
\Driver\atapi -> ataport.SYS @ 0x80721a2c
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->user & kernel MBR OK
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\McAfee\Common Framework\FrameworkService.exe
c:\program files\McAfee\VirusScan Enterprise\VsTskMgr.exe
c:\program files\McAfee\Common Framework\naPrdMgr.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\McAfee\VirusScan Enterprise\Mcshield.exe
c:\program files\McAfee\VirusScan Enterprise\mfeann.exe
c:\windows\system32\conime.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\servicing\TrustedInstaller.exe
.
**************************************************************************
.
Heure de fin: 2010-01-01 22:39:00 - La machine a redémarré
ComboFix-quarantined-files.txt 2010-01-01 21:38
ComboFix2.txt 2010-01-01 19:57
Avant-CF: 122.626.899.968 octets libres
Après-CF: 122.547.548.160 octets libres
- - End Of File - - 92DB1D44865E7EC3B0D208C2226FE3B7 -
Contributeur sécuritéRe,
1) le rapport de CF n'était pas complet.
2) tu n'as pas désactivé comme demandé :
AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
SP: Avira AntiVir PersonalEdition *enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
SP: VirusScan Enterprise + AntiSpyware Enterprise *enabled* (Updated) {24E45799-D058-4314-AC5D-1B2EE5C3151F}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
===
Copie ou imprime les instructions avant
Déconnecte toi d'internet et ferme toutes tes applications.
Désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)
Crée un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :Rootkit:: c:\users\GIANNI\AppData\Roaming\sdra64.exe Registry:: [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\userinit] RegLock:: [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}]
Enregistre ce fichier sous le nom CFscript
Fait un glisser/déposer de ce fichier CFscript sur le fichier ComboFix.exe
Clique sur le fichier CFscript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFscrïpt vienne recouvrir l'icône de Combofix. Relache la souris. Combofix va démarrer.
Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
Réactive ton parefeu, ton antivirus, la garde de ton antispyware
Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
Remets aussi un rapport Hijackthis
Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
Attention : cette manip a été fait pour cet ordi. Tout réutilisation peut endommager sévèrement le système d'exploitation.
-
ComboFix 09-12-31.A1 - GIANNI 01/01/2010 20:42:54.3.1 - x86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6002.2.1252.32.1036.18.895.319 [GMT 1:00]
Lancé depuis: c:\users\GIANNI\Desktop\ComboFix.exe
AV: VirusScan Enterprise + AntiSpyware Enterprise *On-access scanning enabled* (Updated) {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
SP: Avira AntiVir PersonalEdition *enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
SP: VirusScan Enterprise + AntiSpyware Enterprise *enabled* (Updated) {24E45799-D058-4314-AC5D-1B2EE5C3151F}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-12-01 au 2010-01-01 ))))))))))))))))))))))))))))))))))))
.
2010-01-01 19:51 . 2010-01-01 19:51 -------- d-----w- c:\users\Default\AppData\Local\temp
2009-12-31 19:41 . 2009-12-31 20:08 -------- d-----w- c:\program files\MyDefrag v4.2.7
2009-12-31 19:41 . 2009-12-16 00:11 935424 ----a-w- c:\windows\system32\MyDefragScreenSaver.exe
2009-12-31 19:41 . 2009-12-15 22:02 93696 ----a-w- c:\windows\system32\MyDefragScreenSaver.scr
2009-12-31 17:46 . 2009-12-31 17:54 -------- d-----w- c:\users\GIANNI\AppData\Roaming\QuickScan
2009-12-31 05:38 . 2010-01-01 16:51 -------- d-sh--w- c:\users\GIANNI\AppData\Roaming\lowsec
2009-12-27 10:01 . 2009-12-27 10:02 -------- d-----w- c:\users\GIANNI\AppData\Roaming\U3
2009-12-26 17:46 . 2009-12-26 17:46 -------- d-----w- c:\users\GIANNI\AppData\Roaming\TuneUp Software
2009-12-24 09:17 . 2009-12-27 15:42 -------- d-----w- c:\program files\VS Revo Group
2009-12-23 22:51 . 2009-12-25 08:53 -------- d-----w- c:\program files\Ad-Remover
2009-12-23 22:42 . 2009-12-24 00:08 -------- d-----w- c:\program files\trend micro
2009-12-23 22:03 . 2009-12-23 22:03 -------- d-----w- c:\users\GIANNI\AppData\Roaming\igraal
2009-12-20 20:11 . 2009-12-29 10:51 -------- d-----w- c:\users\GIANNI\AppData\Roaming\dvdcss
2009-12-19 22:45 . 2009-12-19 22:45 -------- d-sh--w- c:\programdata\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
2009-12-19 13:45 . 2009-12-03 15:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-19 13:45 . 2009-12-03 15:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-15 20:19 . 2009-12-15 20:19 3175784 ----a-w- c:\users\GIANNI\AppData\Roaming\Uniblue\RegistryBooster 2010\_temp\ub.exe
2009-12-15 19:23 . 2009-12-15 20:20 -------- d-----w- c:\users\GIANNI\AppData\Roaming\Uniblue
2009-12-14 11:59 . 2008-09-29 07:07 90360 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-12-14 11:59 . 2008-09-29 07:07 74648 ----a-w- c:\windows\system32\drivers\mfeapfk.sys
2009-12-14 11:59 . 2008-09-29 07:07 67904 ----a-w- c:\windows\system32\mfevtps.exe
2009-12-14 11:59 . 2008-09-29 07:07 64432 ----a-w- c:\windows\system32\drivers\mferkdet.sys
2009-12-14 11:59 . 2008-09-29 07:07 62704 ----a-w- c:\windows\system32\drivers\mfetdik.sys
2009-12-14 11:59 . 2008-09-29 07:07 42424 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-12-14 11:59 . 2008-09-29 07:07 340592 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-12-14 11:58 . 2009-12-14 11:58 -------- d-----w- c:\program files\Common Files\McAfee
2009-12-11 13:23 . 2009-11-09 12:31 24064 ----a-w- c:\windows\system32\nshhttp.dll
2009-12-11 13:23 . 2009-11-09 10:36 411648 ----a-w- c:\windows\system32\drivers\http.sys
2009-12-11 13:23 . 2009-11-09 12:30 30720 ----a-w- c:\windows\system32\httpapi.dll
2009-12-09 21:22 . 2009-08-24 11:36 377344 ----a-w- c:\windows\system32\winhttp.dll
2009-12-09 21:18 . 2009-10-07 11:36 243712 ----a-w- c:\windows\system32\rastls.dll
2009-12-09 11:03 . 2009-12-30 21:36 -------- d-----w- C:\QUARANTINE
2009-12-09 10:53 . 2009-12-09 10:53 -------- d-----w- c:\program files\Common Files\Cisco Systems
2009-12-09 10:53 . 2009-12-14 11:58 -------- d-----w- c:\program files\McAfee
2009-12-06 10:42 . 2009-12-06 10:42 -------- d-----w- c:\users\GIANNI\AppData\Roaming\Malwarebytes
2009-12-06 10:42 . 2009-12-19 13:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-05 13:01 . 2009-12-14 11:59 -------- d-----w- c:\programdata\McAfee
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-01 19:10 . 2007-06-12 07:33 -------- d-----w- c:\program files\Java
2010-01-01 17:48 . 2009-11-28 16:57 -------- d-----w- c:\users\GIANNI\AppData\Roaming\vlc
2009-12-31 19:43 . 2009-11-03 08:12 -------- d-----w- c:\program files\JkDefrag
2009-12-31 05:40 . 2009-10-31 10:28 -------- d-----w- c:\users\GIANNI\AppData\Roaming\uTorrent
2009-12-27 05:56 . 2006-11-02 15:48 669328 ----a-w- c:\windows\system32\perfh00C.dat
2009-12-27 05:56 . 2006-11-02 15:48 123350 ----a-w- c:\windows\system32\perfc00C.dat
2009-12-24 09:30 . 2007-07-04 20:43 -------- d-----w- c:\program files\Messenger Plus! Live
2009-12-22 21:57 . 2009-08-01 08:57 19944 ----a-w- c:\windows\system32\drivers\atapi.sys
2009-12-19 22:47 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
2009-12-10 14:30 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-12-09 11:08 . 2007-12-02 19:47 -------- d-----w- c:\program files\CCleaner
2009-12-07 15:10 . 2009-07-21 16:37 1 ----a-w- c:\users\GIANNI\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-12-06 10:15 . 2009-11-06 15:30 -------- d-----w- c:\programdata\Messenger Plus!
2009-12-02 17:24 . 2009-12-02 17:24 -------- d-----w- c:\program files\uTorrent
2009-12-02 09:28 . 2007-08-01 17:30 -------- d-----w- c:\program files\Common Files\Adobe
2009-11-30 19:22 . 2009-11-30 19:22 -------- d-----w- c:\program files\MSECache
2009-11-21 06:40 . 2009-12-09 21:19 916480 ----a-w- c:\windows\system32\wininet.dll
2009-11-21 06:34 . 2009-12-09 21:19 109056 ----a-w- c:\windows\system32\iesysprep.dll
2009-11-21 06:34 . 2009-12-09 21:19 71680 ----a-w- c:\windows\system32\iesetup.dll
2009-11-21 04:59 . 2009-12-09 21:19 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-11-17 23:26 . 2009-11-17 23:26 -------- d-----w- c:\program files\Windows Portable Devices
2009-11-17 23:25 . 2006-11-02 10:25 665600 ----a-w- c:\windows\inf\drvindex.dat
2009-11-17 23:25 . 2009-11-17 23:25 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_07_00.Wdf
2009-11-08 16:53 . 2009-11-08 16:53 -------- d-----w- c:\program files\Digital Support
2009-11-08 16:45 . 2007-08-12 10:28 -------- d-----w- c:\users\GIANNI\AppData\Roaming\XnView
2009-11-07 18:43 . 2007-07-04 20:43 -------- d-----w- c:\program files\Windows Live
2009-11-06 15:31 . 2008-08-16 08:14 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-11-06 15:27 . 2008-03-26 12:11 -------- d-----w- c:\program files\Common Files\Sony Ericsson Shared
2009-11-04 15:31 . 2009-11-04 15:31 -------- d-----w- c:\programdata\Malwarebytes
2009-11-03 11:35 . 2009-11-03 11:35 -------- d-----w- c:\program files\Common Files\SupportSoft
2009-11-02 19:42 . 2009-11-02 08:10 195456 ------w- c:\windows\system32\MpSigStub.exe
2009-11-02 06:53 . 2007-07-11 18:41 8052 ----a-w- c:\users\GIANNI\AppData\Local\d3d9caps.dat
2009-10-29 09:17 . 2009-11-28 11:42 2048 ----a-w- c:\windows\system32\tzres.dll
2009-10-22 19:07 . 2009-10-22 19:07 20768 ----a-w- c:\windows\system32\MFEOtlk.dll
2009-10-11 03:17 . 2008-12-11 08:09 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-08 21:08 . 2009-11-17 19:53 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2009-10-08 21:08 . 2009-11-17 19:53 234496 ----a-w- c:\windows\system32\oleacc.dll
2009-10-08 21:07 . 2009-11-17 19:53 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2008-09-29 07:07 . 2009-12-14 11:59 22576 ----a-w- c:\program files\mozilla firefox\components\Scriptff.dll
2008-04-18 17:18 . 2008-04-18 17:18 5 --sha-w- c:\windows\System32\abffafee_s.dll
2008-04-18 17:00 . 2008-04-18 17:00 23 --sha-w- c:\windows\System32\eddafffc_z.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2008-03-14 136512]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2008-09-29 124240]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-12-03 1394000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\McAfeeEngineService]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UniblueRegistryBooster
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-09-04 11:08 935288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-03 03:08 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
2008-01-18 21:33 125952 ----a-w- c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
2009-05-08 08:35 2780432 ----a-w- c:\program files\Logitech\Logitech WebCam Software\LWS.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2009-12-03 15:14 1394000 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
2009-12-03 15:14 429392 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shockwave Updater]
2009-01-16 18:25 460216 ----a-w- c:\windows\System32\Adobe\Shockwave 11\SwHelper_1103472.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
2009-04-11 06:28 1233920 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-10-11 03:17 149280 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2009-01-09 07:54 39408 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\userinit]
c:\users\GIANNI\AppData\Roaming\sdra64.exe [BU]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent]
2009-12-05 14:01 289584 ----a-w- c:\program files\uTorrent\uTorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
2008-01-18 21:33 202240 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WPCUMI]
2006-11-02 12:35 176128 ----a-w- c:\windows\System32\wpcumi.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):52,1e,d3,ec,8c,12,ca,01
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [19/12/2009 14:45 276816]
R2 McAfeeEngineService;McAfee Engine Service;c:\program files\McAfee\VirusScan Enterprise\EngineServer.exe [29/09/2008 8:07 19456]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\System32\mfevtps.exe [14/12/2009 12:59 67904]
R3 MBAMProtector;MBAMProtector;c:\windows\System32\drivers\mbam.sys [19/12/2009 14:45 19160]
S3 FontCache;Service de cache de police Windows;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [4/04/2008 23:20 21504]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\System32\drivers\mferkdet.sys [14/12/2009 12:59 64432]
S3 s115bus;s115bus;c:\windows\System32\drivers\s115bus.sys [26/03/2008 13:16 83208]
S3 s115mdfl;s115mdfl;c:\windows\System32\drivers\s115mdfl.sys [26/03/2008 13:17 15112]
S3 s115mdm;s115mdm;c:\windows\System32\drivers\s115mdm.sys [26/03/2008 13:17 108680]
S3 s115mgmt;s115mgmt;c:\windows\System32\drivers\s115mgmt.sys [26/03/2008 13:19 100488]
S3 s115obex;s115obex;c:\windows\System32\drivers\s115obex.sys [26/03/2008 13:18 98568]
S3 SMCWGU(SMC);SMCWUSB-G 802.11g Wireless USB 2.0 Adapter(SMC);c:\windows\System32\drivers\SMCWGU.sys [29/11/2008 16:39 408064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contenu du dossier 'Tâches planifiées'
2010-01-01 c:\windows\Tasks\User_Feed_Synchronization-{A5599F64-821C-40E3-9000-71BE4A8BFA04}.job
- c:\windows\system32\msfeedssync.exe [2009-12-09 04:59]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.macmurphy11.spaces.live.com/
uSearchMigratedDefaultURL = hxxp://google.cherche.us/Result.php?client=pub-0420647136319153&cof=GIMP%3A009900%3BT%3A000000%3BALC%3A551a8b%3BGFNT%3AB7B7B7%3BLC%3A2200cc%3BBGC%3AFFFFFF%3BVLC%3A551a8b%3BGALT%3A008B45%3BFORID%3A11%3BDIV%3A%23FFFFF0%3B&ie=ISO-8859-1&q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mWindow Title =
FF - ProfilePath - c:\users\GIANNI\AppData\Roaming\Mozilla\Firefox\Profiles\vcyp6mlg.default\
FF - prefs.js: browser.search.defaulturl - hxxp://fr.search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Ask
FF - prefs.js: browser.startup.homepage - hxxp://www.macmurphy11.spaces.live.com
FF - prefs.js: keyword.URL - hxxp://google.cherche.us/Result.php?client=pub-0420647136319153&cof=GIMP%3A009900%3BT%3A000000%3BALC%3A551a8b%3BGFNT%3AB7B7B7%3BLC%3A2200cc%3BBGC%3AFFFFFF%3BVLC%3A551a8b%3BGALT%3A008B45%3BFORID%3A11%3BDIV%3A%23FFFFF0%3B&ie=ISO-8859-1&q=
FF - component: c:\program files\Mozilla Firefox\components\Scriptff.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\GIANNI\AppData\Roaming\Mozilla\plugins\npcoolirisplugin.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
FF - user.js: network.http.max-connections-per-server - 8
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-01-01 20:51
Windows 6.0.6002 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys >>UNKNOWN [0x8366A618]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0x8270cd24
\Driver\ACPI -> acpi.sys @ 0x81e0cd68
\Driver\atapi -> ataport.SYS @ 0x81f1ba2c
IoDeviceObjectType ->\Device\Harddisk0\DR0 ->user & kernel MBR OK
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'Explorer.exe'(3512)
c:\program files\McAfee\VirusScan Enterprise\scriptsn.dll
c:\program files\McAfee\VirusScan Enterprise\mytilus3.dll
c:\program files\McAfee\VirusScan Enterprise\mytilus3_worker.dll
c:\program files\McAfee\VirusScan Enterprise\RES0c00\McShield.dll
.
Heure de fin: 2010-01-01 20:57:32
ComboFix-quarantined-files.txt 2010-01-01 19:57
Avant-CF: 122.584.825.856 octets libres
Après-CF: 122.606.710.784 octets libres
- - End Of File - - 866F28CD9A6A82CE750EEC38D2ED233D -
Contributeur sécuritéRe,
relance Combofix en suivant les instruction de cette page web
* Vérifie que tu as fermé/désactivé tous les programmes anti-virus, anti-malware ou anti-spyware afin qu'ils n'interfèrent pas avec le travail de ComboFix.
Envoie le contenu de C:\ComboFix.txt dans ta prochaine réponse afin que je l'examine.
-
le log de combo était complet
-
File size: 23 bytes
MD5...: 6e8da776bdfcfb78a4bd7baff9dd5a70
SHA1..: ecd85ef2425fbe38409cd953f50a408c4fc6c8ec
SHA256: 46b76d54fabdfe1f957661351888cd842a45dff934a59e85349f0c714b1a1b7d
ssdeep: 3:gbTiR8V+pd:gyR8Uz
PEiD..: -
PEInfo: -
RDS...: NSRL Reference Data Set
-
sigcheck:
publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
trid..: Unknown!
pdfid.: -
- 1
- 2
- 3