Netoyage à effectuer ?
RésoluJ'ai un PC assez ralentis, y a-t-il un netoyage de fin d'été à réaliser sur la machine ?
Rien détecté sous Malwarebytes.
Merci de votre aide !
Rapport Hijackthis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:35:29, on 31/08/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Fichiers communs\Nikon\Monitor\NkMonitor.exe
E:\iTunes\iTunesHelper.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\VIA\RAID\vialogsv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?fdr=lc&toHttps=1&redig=FA6AD360E0BE4C719380F8C470A3D3A8
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.footbel.com/fr.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.bing.com/spresults.aspx
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.google.be/?gws_rd=ssl
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
R3 - URLSearchHook: (no name) - {9b339f6e-ddcd-401b-8764-230adbd01761} - (no file)
R3 - URLSearchHook: Messenger Plus Live Belgium Toolbar - {d1a1c8f1-e3d9-48df-802f-20201061ef61} - C:\Program Files\Messenger_Plus_Live_Belgium\tbMes0.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:\Program Files\Dealio\kb127\Dealio.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: UrlHelper Class - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareIEHelper.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9b339f6e-ddcd-401b-8764-230adbd01761} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Messenger Plus Live Belgium Toolbar - {d1a1c8f1-e3d9-48df-802f-20201061ef61} - C:\Program Files\Messenger_Plus_Live_Belgium\tbMes0.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: WinAVI FLVSense - {E8DF67A1-B618-4F3F-9E7C-CBE175ADEF5B} - E:\Nouveau dossier\WinAVI FLV Converter\FLVTune.dll
O2 - BHO: UrlHelper Class - {EA35911C-1B6A-4AF3-B803-913BA025C271} - C:\Program Files\Lphant Applications\Lphant MediaBar\LphantIEHelper.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Program Files\Dealio\kb127\Dealio.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll
O3 - Toolbar: Lphant MediaBar - {7FED05BE-14FB-4A41-B0D9-79ABBC36FEE4} - C:\Program Files\Lphant Applications\Lphant MediaBar\LphantMediaBar.dll
O3 - Toolbar: (no name) - {9b339f6e-ddcd-401b-8764-230adbd01761} - (no file)
O3 - Toolbar: Messenger Plus Live Belgium Toolbar - {d1a1c8f1-e3d9-48df-802f-20201061ef61} - C:\Program Files\Messenger_Plus_Live_Belgium\tbMes0.dll
O3 - Toolbar: LimeWire Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [VIARaidUtl] C:\Program Files\VIA\RAID\raid_tool.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [au] C:\Program Files\Dealio\DealioAU.exe
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [Nikon Transfer Monitor] C:\Program Files\Fichiers communs\Nikon\Monitor\NkMonitor.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "E:\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: ZDWLan Utility.lnk = C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
O8 - Extra context menu item: &Télécharger le FLV avec WinAVI... - E:\Nouveau dossier\WinAVI FLV Converter\flv_link.htm
O8 - Extra context menu item: Compare Prices with &Dealio - C:\Documents and Settings\klein\Application Data\Dealio\kb127\res\DealioSearch.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: WinAVI FLV Manager - {DE365254-2F9B-4908-9E3A-7AAA6EC90BCC} - E:\Nouveau dossier\WinAVI FLV Converter\FLVTune.dll
O9 - Extra 'Tools' menuitem: WinAVI FLV Manager - {DE365254-2F9B-4908-9E3A-7AAA6EC90BCC} - E:\Nouveau dossier\WinAVI FLV Converter\FLVTune.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll
O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/fr/uno1/GAME_UNO1.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Service Google Update (gupdate1c9c013bc09c1fc) (gupdate1c9c013bc09c1fc) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: VRAID Log Service - Unknown owner - C:\Program Files\VIA\RAID\vialogsv.exe
--
End of file - 14426 bytes
25 réponses
Problème de lenteur d'un PC Windows XP SP3 se pose et l'utilisateur cherche s'il existe un nettoyage de fin d'été à réaliser, Malwarebytes ne détectant aucune anomalie. Des éléments du rapport HijackThis fourni en fin de message indiquent de nombreuses entrées et modules autoruns, extensions et services potentiellement indésirables, sans démontrer une menace claire. Pour guider l'analyse, la discussion mentionne des éléments tels que les barres d'outils, les moteurs de recherche modifiés et les programmes au démarrage, mais sans verdict sur l'infection. En cas de poursuite, des mesures possibles incluent le nettoyage manuel des entrées de démarrage et la vérification des composants tiers, tout en privilégiant des mises à jour de sécurité et une analyse complémentaire.
-
ça vient de logitech si j'ai bien lu non ?
pour le reste, c'est fait :)
je n'ai plus qu'à utiliser ZHP pour désinstaller tout
merci encore ! -
Contributeur sécuritéc'est vrai qu'il s'accroche souvent celui là
pour le reste des manips tu dois pouvoir te passer de moi je suppose
donc résolu
bonne continuation -
je crois qu'il y a eu des problèmes pour désistaller certains composant (ressource réseau non disponible, c'était pour un ou les Search Settings)
rapport :
Rapport de ZHPFix v1.12.3141 par Nicolas Coolman, Update du 27/08/2010
Fichier d'export Registre :
Run by klein at 2/09/2010 10:27:57
Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
Contact : nicolascoolman@yahoo.fr
========== Elément(s) de donnée du Registre ==========
[HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: Modified => Donnée supprimée avec succès
========== Logiciel(s) ==========
O42 - Logiciel: Search Settings 1.2 - (.Pas de propriétaire.) [HKLM] -- {D0C73318-7B4A-4D16-A0C4-3B83F075EA88} => Logiciel supprimé avec succès
========== Récapitulatif ==========
1 : Elément(s) de donnée du Registre
1 : Logiciel(s)
End of the scan -
Contributeur sécuritéOn termine donc proprement
1)
Copie tout le texte présent en gras ci-dessous ( tu le selectionnes avec ta souris / Clique droit dessus et choisis "copier" ou fait Ctrl+C )
[HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: Modified
O42 - Logiciel: Search Settings 1.2 - (.Pas de propriétaire.) [HKLM] -- {D0C73318-7B4A-4D16-A0C4-3B83F075EA88}
O42 - Logiciel: Search Settings 1.2 - (.Pas de propriétaire.) [HKLM] -- {D0C73318-7B4A-4D16-A0C4-3B83F075EA88}
Puis Lance ZHPFix depuis le raccourci du bureau .
* Une fois l'outil ZHPFix ouvert , clique sur le bouton [ H ] ( "coller les lignes Helper" ) .
* Dans l'encadré principal tu verras donc les lignes que tu as copié précédemment apparaitrent .
Vérifie que toutes les lignes que je t'ai demandé de copier (et seulement elles) sont dans la fenêtre.
Clique sur " Ok " , puis " Tous " et enfin " Nettoyer ".
Copie/Colle le rapport à l'écran dans ton prochain message
le rapport se trouve dans le dossier de zhpdiag dans program files sous le nom de ZHPFixReport
.......................
2)
Mettre à jour internet explorer (même si tu ne l'utlises pas)
https://support.microsoft.com/fr-fr/allproducts
..........................
3)
Mettre à jour la Console Java ? :
https://www.java.com/fr/download/uninstalltool.jsp
et installer la nouvelle version si besoin est (dans ce cas désinstalle avant l'ancienne version).
voici pour desinstaller :
JavaRa
http://raproducts.org/click/click.php?id=1
Décompresse le fichier sur le Bureau (Clic droit > Extraire tout).
* Double-clique (clic droit "en tant qu'administrateur" pour Vista) sur le répertoire JavaRa.
* Puis double-clique sur le fichier JavaRa.exe (le exe peut ne pas s'afficher).
* Choisis Français puis clique sur Select.
* Clique sur Recherche de mises à jour.
* Sélectionne Mettre à jour via jucheck.exe puis clique sur Rechercher.
* Autorise le processus à se connecter s'il le demande, clique sur Installer et suis les instructions d'installation qui prennent quelques minutes.
* L'installation est terminée, reviens à l'écran de JavaRa et clique sur Effacer les anciennes versions.
* Clique sur Oui pour confirmer. Laisse travailler et clique ensuite sur OK, puis une deuxième fois sur OK.
* Un rapport va s'ouvrir. Poste-le dans ta prochaine réponse.
* Ferme l'application.
Note : le rapport se trouve aussi dans C:\ sous le nom JavaRa.log.
.............
4)
* Lancez Adobe Reader
* Cliquez sur Edition --> Préférences --> JavaScript
* Décochez "Activer Acrobat JavaScript"
* Validez
....................
5)
IMPORTANT
Purger la restauration systeme XP
http://www.bibou0007.com/windows-xp-f101/purger-la-restauration-du-systeme-sous-windows-xp-t151.htm
.................
6)
Clique droit sur l'icône ZHPFix.exe sur ton Bureau,
puis sélectionne 'Exécuter en tant qu'administrateur'.
Clique sur le A rouge (Nettoyeur de Tools).
Clique sur Nettoyer.
Fais redémarrer l'ordi pour terminer le nettoyage.
.................................................
Recommandations pour l'avenir
Tu es la meilleure protection pour ton pc que tout autre antivirus, si tu admets un minimum de rigueur dans son utilisation...Les virus sont vigilants et pénètrent ta machine par toutes les portes que tu laisseras ouvertes...
- logiciels non à jour (windows, internet explorer, java, adobe reader etc)
- installation de toolbar
- fréquentation de sites piégés
- P2P
- Application de cracks
- Supports usb
Pour t'aider dans cette tâche, voici quelques pistes
Pour naviguer sur internet plus en sécurité et à l'abri des publicités, je te conseille vivement d'installer et d'utiliser le navigateur firefox
http://www.mozilla-europe.org/fr/firefox/
Une fois que c'est fait, lances le et installe l'extension de sécurité adblock plus
pour bloquer les publicités
http://www.clubic.com/telecharger-fiche45912-adblock-plus.html
............................
WOT - Extension pour ton navigateur internet :
Voici une extension à télécharger qui te permettra, en faisant tes recherches sur google, de savoir si le site proposé lors de tes recherches est un site de confiance ou un site à éviter car il pourrait infecter ton PC :
Pour Firefox : https://addons.mozilla.org/fr/firefox/addon/wot-safe-browsing-tool/
Pour internet explorer : https://chrome.google.com/webstore/detail/wot-web-of-trust-website/bhmmomiinigofkjcapegjjndpbikblnp
........................
Pour éviter une infection toolbar, il faut tout lire attentivement lorsque tu installes un programme gratuit, et décocher tous les programmes additionnels qui sont proposés, en particulier les barres d'outils !
..........................
Vaccines tes disques amovibles à l'aide de USBFix (de Chiquitine29 et C_XX)
http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
Au menu principal, choisis l'option 3 (Vaccination).
............................
garder Malwarebytes et faire un examen de temps en temps ton PC, avec mise à jour avant chaque scan
.......................
Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :
https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/
* Lance-le.(clic droit "en tant qu'administrateur" pour Vista) Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
* Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
* Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs tant de fois qu il en trouve a l analyse
..........................
utilitaire pour défragmenter , utilises pour ce faire Defraggler https://www.clubic.com/telecharger-fiche44314-defraggler.html
........................
A lire pour mieux comprendre l'environnement qui t'entoure
http://assiste.com.free.fr/p/abc/a/zombies_et_botnets.html
https://www.malekal.com/fichiers/projetantimalwares/ProjetAntiMalware-courte.pdf
http://www.libellules.ch/...
-
Contributeur sécuritéok
comment va le pc ?
fais un nouveau rapport ZHPdiag et poste le lien de ci joint stp -
je suis en train de lui faire faire un mbam complet pour voir s'il plante pendant (puisque c'était un des trucs qui le faisait planter)
je te dis quoi
merci pour ton aide précieuse !-
-
-
1h 1min de scan, pas de plantage, voila quelque chose de bien
il a juste trouvé un truc, voila le rapport :
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Version de la base de données: 4513
Windows 5.1.2600 Service Pack 3
Internet Explorer 6.0.2900.5512
2/09/2010 0:06:43
mbam-log-2010-09-02 (00-06-43).txt
Type d'examen: Examen complet (C:\|)
Elément(s) analysé(s): 264228
Temps écoulé: 1 heure(s), 1 minute(s), 53 seconde(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 1
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
(Aucun élément nuisible détecté)
-
-
Contributeur sécuritéok
apres Ccleaner
dis moi comment se comporte le pc ? -
après le redémarage demandé par combofix, il y a un installateur qui n'arrive pas à instyaller ce qu'il veut (PSSWCORE => il ne trouve pas PSSWCORE.msi, ça semble venir d'un truc HP (imprimante) )
rapport combofix :
ComboFix 10-09-01.02 - klein 01/09/2010 20:26:24.3.1 - x86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.32.1036.18.1023.597 [GMT 2:00]
Lancé depuis: c:\documents and settings\klein\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\klein\Bureau\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FILE ::
"c:\windows\temp\Perflib_Perfdata_894.dat"
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-08-01 au 2010-09-01 ))))))))))))))))))))))))))))))))))))
.
2010-09-01 17:51 . 2010-09-01 17:55 -------- d-----w- c:\program files\SEAF
2010-09-01 14:03 . 2010-09-01 17:06 -------- d-----w- C:\Kill'em
2010-09-01 14:02 . 2010-09-01 17:23 -------- d-----w- c:\program files\List_Kill'em
2010-08-31 11:23 . 2010-08-31 11:23 -------- d-----w- c:\documents and settings\klein\Local Settings\Application Data\Conduit
2010-08-31 11:20 . 2010-08-31 12:00 -------- d-----w- c:\program files\ZHPDiag
2010-08-31 10:50 . 2010-08-31 10:54 -------- d-----w- c:\program files\Ad-Remover
2010-08-31 10:35 . 2010-08-31 10:35 -------- d-----w- c:\documents and settings\klein\Local Settings\Application Data\GHISLER
2010-08-31 10:35 . 2010-08-31 10:35 -------- d-----w- c:\program files\Trend Micro
2010-08-31 10:30 . 2010-08-31 10:30 -------- d-----w- c:\windows\nvidia icons
2010-08-31 10:29 . 2008-04-30 15:27 442368 ----a-w- c:\windows\system32\NVUNINST.EXE
2010-08-31 10:26 . 2010-08-31 10:26 -------- d-----w- c:\program files\SystemRequirementsLab
2010-08-30 21:48 . 2010-06-28 20:32 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-08-30 21:48 . 2010-06-28 20:37 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-08-30 21:48 . 2010-06-28 20:33 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-08-30 21:48 . 2010-06-28 20:37 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-08-30 21:48 . 2010-06-28 20:32 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-08-30 21:48 . 2010-06-28 20:32 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-08-30 21:48 . 2010-06-28 20:32 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-08-30 21:47 . 2010-06-28 20:57 38848 ----a-w- c:\windows\avastSS.scr
2010-08-30 21:47 . 2010-06-28 20:57 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-08-30 21:47 . 2010-08-30 21:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-08-30 21:21 . 2010-08-30 21:21 -------- d-----w- C:\totalcmd
2010-08-30 21:21 . 2010-08-30 21:21 -------- d-----w- c:\documents and settings\klein\Application Data\GHISLER
2010-08-30 21:08 . 2010-08-31 10:51 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-08-30 21:08 . 2010-08-30 21:09 -------- d-----w- c:\program files\SpywareBlaster
2010-08-30 21:06 . 2010-08-30 21:06 -------- d-----w- c:\documents and settings\klein\Application Data\Malwarebytes
2010-08-30 21:06 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-30 21:06 . 2010-08-30 21:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-08-30 21:06 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-08-30 21:06 . 2010-08-30 21:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-01 17:54 . 2009-03-23 22:36 -------- d-----w- c:\documents and settings\klein\Application Data\HPAppData
2010-09-01 14:28 . 2010-09-01 14:28 -------- d-----w- c:\documents and settings\Administrateur\Application Data\GHISLER
2010-09-01 07:16 . 2009-04-18 10:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2010-09-01 07:15 . 2008-12-24 04:28 -------- d-----w- c:\program files\LogMeIn
2010-08-31 10:25 . 2008-12-23 23:08 -------- d-----w- c:\program files\Fichiers communs\Java
2010-08-31 10:25 . 2008-12-23 23:09 -------- d-----w- c:\program files\Java
2010-08-30 21:47 . 2008-12-24 04:16 -------- d-----w- c:\program files\Alwil Software
2010-08-30 20:53 . 2008-12-23 23:06 -------- d-----w- c:\program files\CCleaner
2010-08-30 12:34 . 2010-05-07 16:58 -------- d-----w- c:\program files\Messenger_Plus_Live_Belgium
2010-08-13 06:37 . 2010-04-01 19:12 -------- d-----w- c:\program files\Messenger Plus! Live
2010-08-12 15:04 . 2002-02-28 21:58 80856 ----a-w- c:\windows\system32\perfc00C.dat
2010-08-12 15:04 . 2002-02-28 21:58 500814 ----a-w- c:\windows\system32\perfh00C.dat
2010-08-03 12:53 . 2010-08-03 12:53 503808 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5cdea610-n\msvcp71.dll
2010-08-03 12:53 . 2010-08-03 12:53 499712 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5cdea610-n\jmc.dll
2010-08-03 12:53 . 2010-08-03 12:53 348160 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5cdea610-n\msvcr71.dll
2010-08-03 12:53 . 2010-08-03 12:53 61440 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1dd7bc75-n\decora-sse.dll
2010-08-03 12:53 . 2010-08-03 12:53 12800 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1dd7bc75-n\decora-d3d.dll
2010-07-29 09:17 . 2008-12-24 04:25 -------- d-----w- c:\documents and settings\klein\Application Data\LimeWire
2010-07-28 09:25 . 2009-01-10 19:19 -------- d-----w- c:\documents and settings\klein\Application Data\Apple Computer
2010-07-28 09:18 . 2010-07-28 09:17 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-07-28 09:18 . 2010-07-28 09:18 -------- d-----w- c:\program files\iPod
2010-07-28 09:17 . 2009-01-10 19:15 -------- d-----w- c:\program files\Fichiers communs\Apple
2010-07-28 09:16 . 2010-07-28 09:15 -------- d-----w- c:\program files\QuickTime
2010-07-28 09:11 . 2010-07-28 09:11 -------- d-----w- c:\program files\Bonjour
2010-07-28 09:08 . 2010-07-28 09:08 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe
2010-07-23 12:53 . 2010-07-23 12:53 503808 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-56a3ac07-n\msvcp71.dll
2010-07-23 12:53 . 2010-07-23 12:53 499712 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-56a3ac07-n\jmc.dll
2010-07-23 12:53 . 2010-07-23 12:53 348160 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-56a3ac07-n\msvcr71.dll
2010-07-23 12:53 . 2010-07-23 12:53 61440 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-56e3ac03-n\decora-sse.dll
2010-07-23 12:53 . 2010-07-23 12:53 12800 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-56e3ac03-n\decora-d3d.dll
2010-07-17 03:00 . 2010-07-23 12:53 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-06-30 12:32 . 2008-04-13 17:33 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-24 12:10 . 2008-04-13 17:33 671232 ----a-w- c:\windows\system32\wininet.dll
2010-06-24 12:10 . 2008-04-13 17:33 81920 ----a-w- c:\windows\system32\ieencode.dll
2010-06-24 09:02 . 2008-04-13 16:58 1852032 ----a-w- c:\windows\system32\win32k.sys
2010-06-22 19:38 . 2008-12-24 12:30 64560 ----a-w- c:\documents and settings\klein\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-21 15:27 . 2008-04-13 10:15 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2008-04-13 17:33 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2008-12-23 22:17 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:42 . 2008-04-13 17:33 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-06-11 15:32 . 2008-12-24 04:28 83360 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2010-06-11 15:32 . 2008-12-24 04:28 29568 ----a-w- c:\windows\system32\LMIport.dll
2010-06-11 15:32 . 2008-12-24 04:28 87424 ----a-w- c:\windows\system32\LMIinit.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-09-01_09.26.49 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-09-01 18:33 . 2010-09-01 18:33 16384 c:\windows\temp\Perflib_Perfdata_400.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{d1a1c8f1-e3d9-48df-802f-20201061ef61}"= "c:\program files\Messenger_Plus_Live_Belgium\tbMes0.dll" [2010-08-30 2734688]
[HKEY_CLASSES_ROOT\clsid\{d1a1c8f1-e3d9-48df-802f-20201061ef61}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d1a1c8f1-e3d9-48df-802f-20201061ef61}]
2010-08-30 12:34 2734688 ----a-w- c:\program files\Messenger_Plus_Live_Belgium\tbMes0.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{d1a1c8f1-e3d9-48df-802f-20201061ef61}"= "c:\program files\Messenger_Plus_Live_Belgium\tbMes0.dll" [2010-08-30 2734688]
[HKEY_CLASSES_ROOT\clsid\{d1a1c8f1-e3d9-48df-802f-20201061ef61}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D1A1C8F1-E3D9-48DF-802F-20201061EF61}"= "c:\program files\Messenger_Plus_Live_Belgium\tbMes0.dll" [2010-08-30 2734688]
[HKEY_CLASSES_ROOT\clsid\{d1a1c8f1-e3d9-48df-802f-20201061ef61}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-18 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VIARaidUtl"="c:\program files\VIA\RAID\raid_tool.exe" [2008-09-24 4918936]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 32768]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-02-28 63048]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
"nwiz"="nwiz.exe" [2008-05-03 1630208]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"fssui"="c:\program files\Windows Live\Family Safety\fsui.exe" [2009-08-05 647520]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2003-05-14 188416]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"ArcSoft Connection Service"="c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]
"Nikon Transfer Monitor"="c:\program files\Fichiers communs\Nikon\Monitor\NkMonitor.exe" [2009-09-15 479232]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
"iTunesHelper"="e:\itunes\iTunesHelper.exe" [2010-07-21 141608]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2010-05-14 248552]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 86016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\All Users\Menu D'marrer\Programmes\D'marrage\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
ZDWLan Utility.lnk - c:\program files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe [2008-12-24 487424]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2010-06-11 15:32 87424 ----a-w- c:\windows\system32\LMIinit.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"e:\\Emul\\eMule\\emule.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"e:\\Nouveau dossier (3)\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"e:\\iTunes\\iTunes.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [30/08/2010 23:48 165456]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [30/08/2010 23:48 17744]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [28/02/2008 16:31 12856]
R2 VRAID Log Service;VRAID Log Service;c:\program files\VIA\RAID\vialogsv.exe [24/12/2008 0:51 52888]
S2 gupdate1c9c013bc09c1fc;Service Google Update (gupdate1c9c013bc09c1fc);c:\program files\Google\Update\GoogleUpdate.exe [18/04/2009 12:52 133104]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [15/03/2009 10:34 216232]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenu du dossier 'Tâches planifiées'
2010-08-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-09-01 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-18 10:51]
2010-09-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-18 10:52]
2010-09-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-18 10:52]
2010-09-01 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 14:07]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = hxxp://www.google.be/
uInternet Settings,ProxyOverride = *.local
IE: &Télécharger le FLV avec WinAVI... - e:\nouveau dossier\WinAVI FLV Converter\flv_link.htm
IE: Compare Prices with &Dealio - c:\documents and settings\klein\Application Data\Dealio\kb127\res\DealioSearch.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-01 20:35
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
VIARaidUtl = c:\program files\VIA\RAID\raid_tool.exe?ouveau dos
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h-€|ÿÿÿÿ¤*€|ù*9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(652)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
- - - - - - - > 'explorer.exe'(1824)
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\program files\LogMeIn\x86\RaMaint.exe
c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ArcCon.ac
c:\windows\system32\RUNDLL32.EXE
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\MsiExec.exe
.
**************************************************************************
.
Heure de fin: 2010-09-01 20:40:05 - La machine a redémarré
ComboFix-quarantined-files.txt 2010-09-01 18:40
ComboFix2.txt 2010-09-01 11:07
ComboFix3.txt 2010-09-01 09:32
Avant-CF: 125.702.303.744 octets libres
Après-CF: 125.693.571.072 octets libres
- - End Of File - - F6B4E63E0AFA900A3A83C13ECC2231B8 -
Contributeur sécurité1)
/!\ ATTENTION /!\ Le script qui suit a été écrit spécialement pour Pimz08, il n'est pas transposable sur un autre ordinateur !
crées un sur ton bureau un nouveau fichier bloc note que tu nommeras CFScript
Copies y ce texte dedans et enregistres le
KillAll::
File::
c:\WINDOWS\temp\Perflib_Perfdata_894.dat
* Désactive tes logiciels de protection
* Fais un glisser/déposer de ce fichier CFScript.txt sur le fichier Combofix.exe (comme le lien suivant)
http://apu.mabul.org/up/apu/2008/09/06/ ... 35my8h.gif
* Patiente le temps du scan. Le Bureau va disparaître à plusieurs reprises : c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
* Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
* Si le fichier ne s'ouvre pas, il se trouve ici ? C:\ComboFix.txt
...................
2)
Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :
https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/
* Lance-le.(clic droit "en tant qu'administrateur" pour Vista) Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
* Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
* Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs tant de fois qu il en trouve a l analyse
-
seaf :
1. ========================= SEAF 1.0.0.7 - C_XX
2.
3. Commencé à: 19:54:41 le 01/09/2010
4.
5. Valeur(s) recherchée(s):
6.
7. Perflib_Perfdata
8.
9. (!) --- Calcul du Hash "MD5"
10. (!) --- Affichage des ADS
11. (!) --- Informations supplémentaires
12. (!) --- Recherche registre
13.
14. ====== Fichier(s) (TC: Date de création, TM: Date de modification, DA, Dernier accès) ======
15.
16. "c:\WINDOWS\temp\Perflib_Perfdata_894.dat" [ ----AT---- | 16384 ]
17. TC: 01/09/2010,19:03:58 | TM: 01/09/2010,19:03:58 | DA: 01/09/2010,19:03:58
18. MD5: DENIED
19.
20.
21.
22. =========================
23.
24. ====== Dossier(s) (TC: Date de création, TM: Date de modification, DA, Dernier accès) ======
25.
26. Aucun dossier trouvé
27.
28.
29. ====== Entrée(s) du registre ======
30.
31.
32.
33. [HKEY_CURRENT_USER\Software\Messenger_Plus_Live_Belgium\toolbar\settings\FindBar\History]
34. "Value0"="Perflib_Perfdata_580.dat"
35.
36. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*]
37. "a"="C:\WINDOWS\temp\Perflib_Perfdata_c3c.dat"
38.
39. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*]
40. "g"="C:\WINDOWS\temp\Perflib_Perfdata_580.dat"
41.
42. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\dat]
43. "a"="C:\WINDOWS\temp\Perflib_Perfdata_580.dat"
44.
45. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\dat]
46. "b"="C:\WINDOWS\temp\Perflib_Perfdata_c3c.dat"
47.
48. [HKEY_USERS\S-1-5-21-1275210071-2146652945-1417001333-1003\Software\Messenger_Plus_Live_Belgium\toolbar\settings\FindBar\History]
49. "Value0"="Perflib_Perfdata_580.dat"
50.
51. [HKEY_USERS\S-1-5-21-1275210071-2146652945-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*]
52. "a"="C:\WINDOWS\temp\Perflib_Perfdata_c3c.dat"
53.
54. [HKEY_USERS\S-1-5-21-1275210071-2146652945-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*]
55. "g"="C:\WINDOWS\temp\Perflib_Perfdata_580.dat"
56.
57. [HKEY_USERS\S-1-5-21-1275210071-2146652945-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\dat]
58. "a"="C:\WINDOWS\temp\Perflib_Perfdata_580.dat"
59.
60. [HKEY_USERS\S-1-5-21-1275210071-2146652945-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\dat]
61. "b"="C:\WINDOWS\temp\Perflib_Perfdata_c3c.dat"
62.
63. =========================
64.
65. Fin à: 19:55:32 le 01/09/2010 ( E.O.F ) -
Contributeur sécuritéok
apres le clean
Télécharge SEAF ( de C__XX ) sur ton bureau :
ici http://pagesperso-orange.fr/NosTools/C_XX/SEAF.exe
* Double clique sur "SEAF.exe" ( clique droit et "Exécuter en tant qu'administrateur" pour Vista / 7 ) pour lancer l'outil.
* Dans l'encardré blanc " Entrez ci dessous...." copie/colle ceci :
Perflib_Perfdata_898.dat
* Au niveau des " options des fichiers ", fait les réglages suivant :
> A "Calculer le checksum" , choisis : MD5
> Coche la case devant " Info. supplémentaire ".
> Coche la case devant " Afficher les ADS "
* Au niveau des " options du registre " :
> coche " chercher également dans le registre "
( ne touche à aucun autre réglage )
* Clique sur " Lancer la recherche " et laisse travailler l'outil ...
( cela peut-être plus ou moins long suivant les cas ).
--> Une fois terminé, une fenêtre avec un log .txt va s'afficher. Enregistre ce rapport de façon à le retrouver facilement ( sur le bureau par exemple ). Sinon il sera en outre sauvegardé à la racine de ton disque dur ( ici > C:\SEAFLog.txt )
-
kill'em :
¤¤¤¤¤¤¤¤¤¤ Kill'em by g3n-h@ckm@n 2.1.0.2 ¤¤¤¤¤¤¤¤¤¤
User : klein (Administrateurs)
Update on 30/08/2010 by g3n-h@ckm@n ::::: 15.00
Start at: 19:06:22 | 1/09/2010
AMD Athlon(tm) XP 2200+
Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 6.0.2900.5512
Windows Firewall Status : Disabled
AV : avast! Antivirus 5.0.83886674 [ (!) Disabled | Updated ]
A:\ -> Lecteur de disquettes 3 ½ pouces
C:\ -> Disque fixe local | 149,04 Go (117,06 Go free) | NTFS
D:\ -> Disque CD-ROM
E:\ -> Disque fixe local | 37,27 Go (22,8 Go free) [Nouveau nom] | NTFS
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes ------- Memory(Ko)
C:\WINDOWS\System32\smss.exe ----400 Ko
C:\WINDOWS\system32\csrss.exe ----4456 Ko
C:\WINDOWS\system32\winlogon.exe ----4848 Ko
C:\WINDOWS\system32\services.exe ----3568 Ko
C:\WINDOWS\system32\lsass.exe ----6116 Ko
C:\WINDOWS\system32\svchost.exe ----5280 Ko
C:\WINDOWS\system32\svchost.exe ----4696 Ko
C:\WINDOWS\System32\svchost.exe ----20472 Ko
C:\WINDOWS\system32\svchost.exe ----3484 Ko
C:\WINDOWS\system32\svchost.exe ----3780 Ko
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe ----22212 Ko
C:\WINDOWS\Explorer.EXE ----24420 Ko
C:\Program Files\VIA\RAID\raid_tool.exe ----5768 Ko
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe ----2908 Ko
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe ----6604 Ko
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe ----2508 Ko
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe ----1932 Ko
C:\Program Files\Fichiers communs\Nikon\Monitor\NkMonitor.exe ----3324 Ko
E:\iTunes\iTunesHelper.exe ----12740 Ko
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe ----5188 Ko
C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe ----2388 Ko
C:\WINDOWS\system32\RUNDLL32.EXE ----3380 Ko
C:\Program Files\LogMeIn\x86\LMIGuardian.exe ----2220 Ko
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe ----10992 Ko
C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe ----5032 Ko
C:\WINDOWS\system32\spoolsv.exe ----6036 Ko
C:\WINDOWS\system32\svchost.exe ----3440 Ko
C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe ----2304 Ko
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe ----2628 Ko
C:\Program Files\Bonjour\mDNSResponder.exe ----3652 Ko
C:\WINDOWS\system32\svchost.exe ----9536 Ko
C:\Program Files\Java\jre6\bin\jqs.exe ----1380 Ko
C:\Program Files\LogMeIn\x86\RaMaint.exe ----3224 Ko
C:\Program Files\LogMeIn\x86\LogMeIn.exe ----12224 Ko
C:\Program Files\LogMeIn\x86\LMIGuardian.exe ----2220 Ko
C:\WINDOWS\System32\svchost.exe ----2848 Ko
C:\WINDOWS\system32\nvsvc32.exe ----4092 Ko
C:\WINDOWS\System32\svchost.exe ----3176 Ko
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe ----7808 Ko
C:\WINDOWS\system32\svchost.exe ----4296 Ko
C:\Program Files\VIA\RAID\vialogsv.exe ----3720 Ko
C:\WINDOWS\system32\wbem\wmiprvse.exe ----5292 Ko
C:\WINDOWS\system32\wuauclt.exe ----8060 Ko
C:\WINDOWS\system32\wbem\wmiprvse.exe ----8088 Ko
C:\Program Files\Windows Live\Toolbar\wltuser.exe ----6352 Ko
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe ----3980 Ko
C:\Program Files\iPod\bin\iPodService.exe ----3904 Ko
C:\WINDOWS\system32\wscntfy.exe ----1972 Ko
C:\WINDOWS\system32\wbem\wmiapsrv.exe ----4448 Ko
C:\WINDOWS\System32\alg.exe ----3492 Ko
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe ----8540 Ko
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe ----3644 Ko
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe ----7044 Ko
C:\WINDOWS\system32\wuauclt.exe ----4012 Ko
C:\WINDOWS\system32\cmd.exe ----2876 Ko
C:\Program Files\List_Kill'em\ERUNT.EXE ----3096 Ko
C:\Program Files\List_Kill'em\pv.exe ----2704 Ko
¤¤¤¤¤¤¤¤¤¤ Files/folders :
Quarantined & Deleted !! : C:\Program Files\Samsung\Samsung PC Studio 3\Update\util\UnZipTemp\OrgLoadD500.exe
Quarantined & Deleted !! : C:\Program Files\Samsung\Samsung PC Studio 3\Update\util\UnZipTemp\OrgLoadX800.exe
Quarantined & Deleted !! : C:\Program Files\Samsung\Samsung PC Studio 3\Update\util\UnZipTemp\OrgLoadZ510.exe
Quarantined & Deleted !! : C:\WINDOWS\SET3.tmp
Quarantined & Deleted !! : C:\WINDOWS\SET4.tmp
Quarantined & Deleted !! : C:\WINDOWS\SET8.tmp
Quarantined & Deleted !! : C:\WINDOWS\system32\AbaleZip.dll
Quarantined & Deleted !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
Quarantined & Deleted !! : C:\WINDOWS\System32\SET169.tmp
Quarantined & Deleted !! : C:\WINDOWS\System32\SET175.tmp
Quarantined & Deleted !! : C:\WINDOWS\System32\SET17E.tmp
Quarantined & Deleted !! : C:\WINDOWS\System32\SET17F.tmp
Quarantined & Deleted !! : C:\WINDOWS\System32\SET180.tmp
Quarantined & Deleted !! : C:\WINDOWS\System32\SET183.tmp
¤¤¤¤¤¤¤¤¤¤ Hosts ¤¤¤¤¤¤¤¤¤¤
127.0.0.1 localhost
¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤
Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser : {0E5CBF21-D15F-11D0-8301-00AA005B4383}
Deleted : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer : NoDrives
Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer : NoDrives
Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
Deleted : HKCR\Interface\{f9c23cd1-6da9-4e0b-8367-c6f9f1f78baf}
Deleted : HKCU\Software\Conduit
Deleted : HKLM\software\classes\installer\Products\A28B4D68DEBAA244EB686953B7074FEF
Deleted : HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8
Deleted : HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01
Deleted : HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED
Deleted : HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472
Deleted : HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296
Deleted : HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888
Deleted : HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF
¤¤¤¤¤¤¤¤¤¤ Internet Explorer ¤¤¤¤¤¤¤¤¤¤
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page = https://www.msn.com/fr-fr/?ocid=iehp
Local Page = C:\WINDOWS\system32\blank.htm
Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page = https://www.google.com/?gws_rd=ssl
Local Page = C:\WINDOWS\system32\blank.htm
Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
¤¤¤¤¤¤¤¤¤¤ Security Center ¤¤¤¤¤¤¤¤¤¤
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
FirstRunDisabled = 1 ()
AntiVirusDisableNotify = 0 (0x0)
FirewallDisableNotify = 0 (0x0)
UpdatesDisableNotify = 0 (0x0)
AntiVirusOverride = 0 (0x0)
FirewallOverride = 0 (0x0)
¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤
Ndisuio : Start = 3
EapHost : Start = 2
Ip6Fw : Start = 2
SharedAccess : Start = 2
wuauserv : Start = 2
wscsvc : Start = 2
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
Disk Cleaned
anti-ver blaster : OK
Prefetch cleaned
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
FEATURE_BROWSER_EMULATION | svchost :
====================================
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys videX32.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ ( EOF ) ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
-
-
Contributeur sécurité1)
pour virus total
copie colle le lien de la page
.................
2)
Relance List_Kill'em(soit en clic droit pour vista/7),avec le raccourci sur ton bureau.
mais cette fois-ci :
choisis l'option CLEAN
ton PC va redemarrer,
laisse travailler l'outil.
en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,
colle le contenu dans ta reponse
-
je ne sais pas réaliser la manipulation avec virustotal, il ne crée pas le rapport (j'ai essayer de copier le fichier sur le bureau mais c'est impossible, fichier illisible)
more.txt : http://www.cijoint.fr/cjlink.php?file=cj201009/cijDx5oHWy.txt
list'em.txt : http://www.cijoint.fr/cjlink.php?file=cj201009/cijxiOardX.txt -
Contributeur sécuritéok
1)
Rends toi sur ce site :
https://www.virustotal.com/gui/
Clique sur parcourir et cherche ce fichier :
c:\windows\temp\Perflib_Perfdata_898.dat
Clique sur Send File.
Un rapport va s'élaborer ligne à ligne.
Attends la fin. Il doit comprendre la taille du fichier envoyé.
Sauvegarde le rapport avec le bloc-note.
Copie le dans ta réponse.
Si tu ne trouves pas le fichier alors
Affiche tous les fichiers et dossiers :
Pour cela :
Clique sur démarrer/panneau de configuration/option des dossiers/affichage
Cocher afficher les dossiers cachés
Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"
Décocher masquer les extensions dont le type est connu
Puis fais «appliquer» pour valider les changements.
Et OK
tuto pour t'aider
http://www.bibou0007.com/scans-en-ligne-f75/tutorial-sur-virustotal-t190.htm
......................
2)
DESACTIVE TON ANTIVIRUS ET TON PAREFEU SI PRESENTS !!!!!(car il est detecté a tort comme infection)
Télécharge ici :List_Kill'em et enregistre le sur ton bureau
http://sd-4.archive-host.com/membres/up/829108531491024/Mes_Tools/List_Killem_Install.exe
ou
http://www.archive-host.com
si tu as XP => double clique
si tu as Vista ou windows 7 => clic droit "executer en tant que...."
sur le raccourci sur ton bureau pour lancer l'installation
Laisse coché :
Executer List_Kill'em
une fois terminée , clic sur "terminer" et le programme se lancera seul
choisis l'option Search
laisse travailler l'outil
il se peut qu'une boite de dialogue s'ouvre , dans ce cas clique sur "ok" ou "Agree"
à l'apparition de la fenetre blanche , c'est un peu long , c'est normal ,c'est une recherche supplementaire de fichiers cachés , le programme n'est pas bloqué.
Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"
NE LE POSTE PAS SUR LE FORUM
Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/
Clique sur Parcourir et cherche le fichier ci-dessus.
Clique sur Ouvrir.
Clique sur "Cliquez ici pour déposer le fichier".
Un lien de cette forme :
http://www.cijoint.fr/cjlink.php?file=265368/cijSKAP5fU.txt
est ajouté dans la page.
Copie ce lien dans ta réponse.
Fais de même avec more.txt qui se trouve sur ton bureau
-
ComboFix 10-08-31.02 - klein 01/09/2010 12:52:33.2.1 - x86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.32.1036.18.1023.593 [GMT 2:00]
Lancé depuis: c:\documents and settings\klein\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\klein\Bureau\CFScript.txt
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FILE ::
"c:\windows\ARJ.PIF"
"c:\windows\LHA.PIF"
"c:\windows\NOCLOSE.PIF"
"c:\windows\PKUNZIP.PIF"
"c:\windows\PKZIP.PIF"
"c:\windows\RAR.PIF"
"c:\windows\UC.PIF"
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\ARJ.PIF
c:\windows\LHA.PIF
c:\windows\NOCLOSE.PIF
c:\windows\PKUNZIP.PIF
c:\windows\PKZIP.PIF
c:\windows\RAR.PIF
c:\windows\UC.PIF
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-08-01 au 2010-09-01 ))))))))))))))))))))))))))))))))))))
.
2010-08-31 11:23 . 2010-08-31 11:23 -------- d-----w- c:\documents and settings\klein\Local Settings\Application Data\Conduit
2010-08-31 11:20 . 2010-08-31 12:00 -------- d-----w- c:\program files\ZHPDiag
2010-08-31 10:50 . 2010-08-31 10:54 -------- d-----w- c:\program files\Ad-Remover
2010-08-31 10:35 . 2010-08-31 10:35 -------- d-----w- c:\documents and settings\klein\Local Settings\Application Data\GHISLER
2010-08-31 10:35 . 2010-08-31 10:35 -------- d-----w- c:\program files\Trend Micro
2010-08-31 10:30 . 2010-08-31 10:30 -------- d-----w- c:\windows\nvidia icons
2010-08-31 10:29 . 2008-04-30 15:27 442368 ----a-w- c:\windows\system32\NVUNINST.EXE
2010-08-31 10:26 . 2010-08-31 10:26 -------- d-----w- c:\program files\SystemRequirementsLab
2010-08-30 21:48 . 2010-06-28 20:32 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-08-30 21:48 . 2010-06-28 20:37 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-08-30 21:48 . 2010-06-28 20:33 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-08-30 21:48 . 2010-06-28 20:37 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-08-30 21:48 . 2010-06-28 20:32 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-08-30 21:48 . 2010-06-28 20:32 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-08-30 21:48 . 2010-06-28 20:32 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-08-30 21:47 . 2010-06-28 20:57 38848 ----a-w- c:\windows\avastSS.scr
2010-08-30 21:47 . 2010-06-28 20:57 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-08-30 21:47 . 2010-08-30 21:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-08-30 21:21 . 2010-08-30 21:21 -------- d-----w- C:\totalcmd
2010-08-30 21:21 . 2010-08-30 21:21 -------- d-----w- c:\documents and settings\klein\Application Data\GHISLER
2010-08-30 21:08 . 2010-08-31 10:51 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-08-30 21:08 . 2010-08-30 21:09 -------- d-----w- c:\program files\SpywareBlaster
2010-08-30 21:06 . 2010-08-30 21:06 -------- d-----w- c:\documents and settings\klein\Application Data\Malwarebytes
2010-08-30 21:06 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-30 21:06 . 2010-08-30 21:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-08-30 21:06 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-08-30 21:06 . 2010-08-30 21:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-01 10:49 . 2009-03-23 22:36 -------- d-----w- c:\documents and settings\klein\Application Data\HPAppData
2010-09-01 07:16 . 2009-04-18 10:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2010-09-01 07:15 . 2008-12-24 04:28 -------- d-----w- c:\program files\LogMeIn
2010-08-31 10:25 . 2008-12-23 23:08 -------- d-----w- c:\program files\Fichiers communs\Java
2010-08-31 10:25 . 2008-12-23 23:09 -------- d-----w- c:\program files\Java
2010-08-30 21:47 . 2008-12-24 04:16 -------- d-----w- c:\program files\Alwil Software
2010-08-30 20:53 . 2008-12-23 23:06 -------- d-----w- c:\program files\CCleaner
2010-08-30 12:34 . 2010-05-07 16:58 -------- d-----w- c:\program files\Messenger_Plus_Live_Belgium
2010-08-13 06:37 . 2010-04-01 19:12 -------- d-----w- c:\program files\Messenger Plus! Live
2010-08-12 15:04 . 2002-02-28 21:58 80856 ----a-w- c:\windows\system32\perfc00C.dat
2010-08-12 15:04 . 2002-02-28 21:58 500814 ----a-w- c:\windows\system32\perfh00C.dat
2010-08-03 12:53 . 2010-08-03 12:53 503808 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5cdea610-n\msvcp71.dll
2010-08-03 12:53 . 2010-08-03 12:53 499712 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5cdea610-n\jmc.dll
2010-08-03 12:53 . 2010-08-03 12:53 348160 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5cdea610-n\msvcr71.dll
2010-08-03 12:53 . 2010-08-03 12:53 61440 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1dd7bc75-n\decora-sse.dll
2010-08-03 12:53 . 2010-08-03 12:53 12800 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1dd7bc75-n\decora-d3d.dll
2010-07-29 09:17 . 2008-12-24 04:25 -------- d-----w- c:\documents and settings\klein\Application Data\LimeWire
2010-07-28 09:25 . 2009-01-10 19:19 -------- d-----w- c:\documents and settings\klein\Application Data\Apple Computer
2010-07-28 09:18 . 2010-07-28 09:17 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-07-28 09:18 . 2010-07-28 09:18 -------- d-----w- c:\program files\iPod
2010-07-28 09:17 . 2009-01-10 19:15 -------- d-----w- c:\program files\Fichiers communs\Apple
2010-07-28 09:16 . 2010-07-28 09:15 -------- d-----w- c:\program files\QuickTime
2010-07-28 09:11 . 2010-07-28 09:11 -------- d-----w- c:\program files\Bonjour
2010-07-28 09:08 . 2010-07-28 09:08 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe
2010-07-23 12:53 . 2010-07-23 12:53 503808 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-56a3ac07-n\msvcp71.dll
2010-07-23 12:53 . 2010-07-23 12:53 499712 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-56a3ac07-n\jmc.dll
2010-07-23 12:53 . 2010-07-23 12:53 348160 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-56a3ac07-n\msvcr71.dll
2010-07-23 12:53 . 2010-07-23 12:53 61440 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-56e3ac03-n\decora-sse.dll
2010-07-23 12:53 . 2010-07-23 12:53 12800 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-56e3ac03-n\decora-d3d.dll
2010-07-17 03:00 . 2010-07-23 12:53 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-06-30 12:32 . 2008-04-13 17:33 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-24 12:10 . 2008-04-13 17:33 671232 ----a-w- c:\windows\system32\wininet.dll
2010-06-24 12:10 . 2008-04-13 17:33 81920 ----a-w- c:\windows\system32\ieencode.dll
2010-06-24 09:02 . 2008-04-13 16:58 1852032 ----a-w- c:\windows\system32\win32k.sys
2010-06-22 19:38 . 2008-12-24 12:30 64560 ----a-w- c:\documents and settings\klein\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-21 15:27 . 2008-04-13 10:15 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2008-04-13 17:33 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2008-12-23 22:17 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:42 . 2008-04-13 17:33 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-06-11 15:32 . 2008-12-24 04:28 83360 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2010-06-11 15:32 . 2008-12-24 04:28 29568 ----a-w- c:\windows\system32\LMIport.dll
2010-06-11 15:32 . 2008-12-24 04:28 87424 ----a-w- c:\windows\system32\LMIinit.dll
.
((((((((((((((((((((((((((((( SnapShot@2010-09-01_09.26.49 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-09-01 11:00 . 2010-09-01 11:00 16384 c:\windows\temp\Perflib_Perfdata_898.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{d1a1c8f1-e3d9-48df-802f-20201061ef61}"= "c:\program files\Messenger_Plus_Live_Belgium\tbMes0.dll" [2010-08-30 2734688]
[HKEY_CLASSES_ROOT\clsid\{d1a1c8f1-e3d9-48df-802f-20201061ef61}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d1a1c8f1-e3d9-48df-802f-20201061ef61}]
2010-08-30 12:34 2734688 ----a-w- c:\program files\Messenger_Plus_Live_Belgium\tbMes0.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{d1a1c8f1-e3d9-48df-802f-20201061ef61}"= "c:\program files\Messenger_Plus_Live_Belgium\tbMes0.dll" [2010-08-30 2734688]
[HKEY_CLASSES_ROOT\clsid\{d1a1c8f1-e3d9-48df-802f-20201061ef61}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D1A1C8F1-E3D9-48DF-802F-20201061EF61}"= "c:\program files\Messenger_Plus_Live_Belgium\tbMes0.dll" [2010-08-30 2734688]
[HKEY_CLASSES_ROOT\clsid\{d1a1c8f1-e3d9-48df-802f-20201061ef61}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-18 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VIARaidUtl"="c:\program files\VIA\RAID\raid_tool.exe" [2008-09-24 4918936]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 32768]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-02-28 63048]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
"nwiz"="nwiz.exe" [2008-05-03 1630208]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"fssui"="c:\program files\Windows Live\Family Safety\fsui.exe" [2009-08-05 647520]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2003-05-14 188416]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"ArcSoft Connection Service"="c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]
"Nikon Transfer Monitor"="c:\program files\Fichiers communs\Nikon\Monitor\NkMonitor.exe" [2009-09-15 479232]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
"iTunesHelper"="e:\itunes\iTunesHelper.exe" [2010-07-21 141608]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2010-05-14 248552]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 86016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\All Users\Menu D'marrer\Programmes\D'marrage\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
ZDWLan Utility.lnk - c:\program files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe [2008-12-24 487424]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2010-06-11 15:32 87424 ----a-w- c:\windows\system32\LMIinit.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"e:\\Emul\\eMule\\emule.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"e:\\Nouveau dossier (3)\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"e:\\iTunes\\iTunes.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [30/08/2010 23:48 165456]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [30/08/2010 23:48 17744]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [28/02/2008 16:31 12856]
R2 VRAID Log Service;VRAID Log Service;c:\program files\VIA\RAID\vialogsv.exe [24/12/2008 0:51 52888]
S2 gupdate1c9c013bc09c1fc;Service Google Update (gupdate1c9c013bc09c1fc);c:\program files\Google\Update\GoogleUpdate.exe [18/04/2009 12:52 133104]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [15/03/2009 10:34 216232]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenu du dossier 'Tâches planifiées'
2010-08-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-09-01 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-18 10:51]
2010-09-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-18 10:52]
2010-09-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-18 10:52]
2010-09-01 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 14:07]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.footbel.com/fr.html
uInternet Connection Wizard,ShellNext = hxxp://www.google.be/
uInternet Settings,ProxyOverride = *.local
IE: &Télécharger le FLV avec WinAVI... - e:\nouveau dossier\WinAVI FLV Converter\flv_link.htm
IE: Compare Prices with &Dealio - c:\documents and settings\klein\Application Data\Dealio\kb127\res\DealioSearch.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-01 13:03
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
VIARaidUtl = c:\program files\VIA\RAID\raid_tool.exe?ouveau dos
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h-€|ÿÿÿÿ¤*€|ù*9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(644)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
- - - - - - - > 'explorer.exe'(4020)
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\LogMeIn\x86\RaMaint.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Heure de fin: 2010-09-01 13:07:06 - La machine a redémarré
ComboFix-quarantined-files.txt 2010-09-01 11:07
ComboFix2.txt 2010-09-01 09:32
Avant-CF: 125.713.920.000 octets libres
Après-CF: 125.705.990.144 octets libres
- - End Of File - - 11FC43E12472DE1F72C9EAA2CB3E9820 -
Contributeur sécurité/!\ ATTENTION /!\ Le script qui suit a été écrit spécialement pour Pimz08, il n'est pas transposable sur un autre ordinateur !
crées un sur ton bureau un nouveau fichier bloc note que tu nommeras CFScript
Copies y ce texte dedans et enregistres le
KillAll::
File::
c:\windows\UC.PIF
c:\windows\RAR.PIF
c:\windows\PKZIP.PIF
c:\windows\PKUNZIP.PIF
c:\windows\NOCLOSE.PIF
c:\windows\LHA.PIF
c:\windows\ARJ.PIF
* Désactive tes logiciels de protection
* Fais un glisser/déposer de ce fichier CFScript.txt sur le fichier Combofix.exe
* Patiente le temps du scan. Le Bureau va disparaître à plusieurs reprises : c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
* Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
* Si le fichier ne s'ouvre pas, il se trouve ici ? C:\ComboFix.txt
-
ComboFix 10-08-31.02 - klein 01/09/2010 11:20:07.1.1 - x86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.32.1036.18.1023.624 [GMT 2:00]
Lancé depuis: c:\documents and settings\klein\Bureau\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Lphant Applications\Lphant MediaBar\LphantIEHelper.dll
c:\program files\Lphant Applications\Lphant MediaBar\LphantMediaBar.dll
c:\windows\system32\scrrnfr.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-08-01 au 2010-09-01 ))))))))))))))))))))))))))))))))))))
.
2010-08-31 11:23 . 2010-08-31 11:23 -------- d-----w- c:\documents and settings\klein\Local Settings\Application Data\Conduit
2010-08-31 11:20 . 2010-08-31 12:00 -------- d-----w- c:\program files\ZHPDiag
2010-08-31 10:50 . 2010-08-31 10:54 -------- d-----w- c:\program files\Ad-Remover
2010-08-31 10:35 . 2010-08-31 10:35 -------- d-----w- c:\documents and settings\klein\Local Settings\Application Data\GHISLER
2010-08-31 10:35 . 2010-08-31 10:35 -------- d-----w- c:\program files\Trend Micro
2010-08-31 10:30 . 2010-08-31 10:30 -------- d-----w- c:\windows\nvidia icons
2010-08-31 10:29 . 2008-04-30 15:27 442368 ----a-w- c:\windows\system32\NVUNINST.EXE
2010-08-31 10:26 . 2010-08-31 10:26 -------- d-----w- c:\program files\SystemRequirementsLab
2010-08-30 21:48 . 2010-06-28 20:32 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-08-30 21:48 . 2010-06-28 20:37 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-08-30 21:48 . 2010-06-28 20:33 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-08-30 21:48 . 2010-06-28 20:37 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-08-30 21:48 . 2010-06-28 20:32 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-08-30 21:48 . 2010-06-28 20:32 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-08-30 21:48 . 2010-06-28 20:32 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-08-30 21:47 . 2010-06-28 20:57 38848 ----a-w- c:\windows\avastSS.scr
2010-08-30 21:47 . 2010-06-28 20:57 165032 ----a-w- c:\windows\system32\aswBoot.exe
2010-08-30 21:47 . 2010-08-30 21:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-08-30 21:21 . 2010-08-30 21:21 -------- d-----w- C:\totalcmd
2010-08-30 21:21 . 2010-08-30 21:21 -------- d-----w- c:\documents and settings\klein\Application Data\GHISLER
2010-08-30 21:21 . 2010-07-07 05:55 545 ----a-w- c:\windows\UC.PIF
2010-08-30 21:21 . 2010-07-07 05:55 545 ----a-w- c:\windows\RAR.PIF
2010-08-30 21:21 . 2010-07-07 05:55 545 ----a-w- c:\windows\PKZIP.PIF
2010-08-30 21:21 . 2010-07-07 05:55 545 ----a-w- c:\windows\PKUNZIP.PIF
2010-08-30 21:21 . 2010-07-07 05:55 545 ----a-w- c:\windows\NOCLOSE.PIF
2010-08-30 21:21 . 2010-07-07 05:55 545 ----a-w- c:\windows\LHA.PIF
2010-08-30 21:21 . 2010-07-07 05:55 545 ----a-w- c:\windows\ARJ.PIF
2010-08-30 21:08 . 2010-08-31 10:51 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-08-30 21:08 . 2010-08-30 21:09 -------- d-----w- c:\program files\SpywareBlaster
2010-08-30 21:06 . 2010-08-30 21:06 -------- d-----w- c:\documents and settings\klein\Application Data\Malwarebytes
2010-08-30 21:06 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-30 21:06 . 2010-08-30 21:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-08-30 21:06 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-08-30 21:06 . 2010-08-30 21:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-08-03 12:53 . 2010-08-03 12:53 503808 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5cdea610-n\msvcp71.dll
2010-08-03 12:53 . 2010-08-03 12:53 499712 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5cdea610-n\jmc.dll
2010-08-03 12:53 . 2010-08-03 12:53 348160 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5cdea610-n\msvcr71.dll
2010-08-03 12:53 . 2010-08-03 12:53 61440 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1dd7bc75-n\decora-sse.dll
2010-08-03 12:53 . 2010-08-03 12:53 12800 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1dd7bc75-n\decora-d3d.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-01 09:04 . 2009-03-23 22:36 -------- d-----w- c:\documents and settings\klein\Application Data\HPAppData
2010-09-01 07:16 . 2009-04-18 10:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2010-09-01 07:15 . 2008-12-24 04:28 -------- d-----w- c:\program files\LogMeIn
2010-08-31 10:25 . 2008-12-23 23:08 -------- d-----w- c:\program files\Fichiers communs\Java
2010-08-31 10:25 . 2008-12-23 23:09 -------- d-----w- c:\program files\Java
2010-08-30 21:47 . 2008-12-24 04:16 -------- d-----w- c:\program files\Alwil Software
2010-08-30 20:53 . 2008-12-23 23:06 -------- d-----w- c:\program files\CCleaner
2010-08-30 12:34 . 2010-05-07 16:58 -------- d-----w- c:\program files\Messenger_Plus_Live_Belgium
2010-08-13 06:37 . 2010-04-01 19:12 -------- d-----w- c:\program files\Messenger Plus! Live
2010-08-12 15:04 . 2002-02-28 21:58 80856 ----a-w- c:\windows\system32\perfc00C.dat
2010-08-12 15:04 . 2002-02-28 21:58 500814 ----a-w- c:\windows\system32\perfh00C.dat
2010-07-29 09:17 . 2008-12-24 04:25 -------- d-----w- c:\documents and settings\klein\Application Data\LimeWire
2010-07-28 09:25 . 2009-01-10 19:19 -------- d-----w- c:\documents and settings\klein\Application Data\Apple Computer
2010-07-28 09:18 . 2010-07-28 09:17 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-07-28 09:18 . 2010-07-28 09:18 -------- d-----w- c:\program files\iPod
2010-07-28 09:17 . 2009-01-10 19:15 -------- d-----w- c:\program files\Fichiers communs\Apple
2010-07-28 09:16 . 2010-07-28 09:15 -------- d-----w- c:\program files\QuickTime
2010-07-28 09:11 . 2010-07-28 09:11 -------- d-----w- c:\program files\Bonjour
2010-07-28 09:08 . 2010-07-28 09:08 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe
2010-07-23 12:53 . 2010-07-23 12:53 503808 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-56a3ac07-n\msvcp71.dll
2010-07-23 12:53 . 2010-07-23 12:53 499712 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-56a3ac07-n\jmc.dll
2010-07-23 12:53 . 2010-07-23 12:53 348160 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-56a3ac07-n\msvcr71.dll
2010-07-23 12:53 . 2010-07-23 12:53 61440 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-56e3ac03-n\decora-sse.dll
2010-07-23 12:53 . 2010-07-23 12:53 12800 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-56e3ac03-n\decora-d3d.dll
2010-07-17 03:00 . 2010-07-23 12:53 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-06-30 12:32 . 2008-04-13 17:33 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-24 12:10 . 2008-04-13 17:33 671232 ----a-w- c:\windows\system32\wininet.dll
2010-06-24 12:10 . 2008-04-13 17:33 81920 ----a-w- c:\windows\system32\ieencode.dll
2010-06-24 09:02 . 2008-04-13 16:58 1852032 ----a-w- c:\windows\system32\win32k.sys
2010-06-22 19:38 . 2008-12-24 12:30 64560 ----a-w- c:\documents and settings\klein\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-21 15:27 . 2008-04-13 10:15 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2008-04-13 17:33 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2008-12-23 22:17 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:42 . 2008-04-13 17:33 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-06-11 15:32 . 2008-12-24 04:28 83360 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2010-06-11 15:32 . 2008-12-24 04:28 29568 ----a-w- c:\windows\system32\LMIport.dll
2010-06-11 15:32 . 2008-12-24 04:28 87424 ----a-w- c:\windows\system32\LMIinit.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{d1a1c8f1-e3d9-48df-802f-20201061ef61}"= "c:\program files\Messenger_Plus_Live_Belgium\tbMes0.dll" [2010-08-30 2734688]
[HKEY_CLASSES_ROOT\clsid\{d1a1c8f1-e3d9-48df-802f-20201061ef61}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d1a1c8f1-e3d9-48df-802f-20201061ef61}]
2010-08-30 12:34 2734688 ----a-w- c:\program files\Messenger_Plus_Live_Belgium\tbMes0.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{d1a1c8f1-e3d9-48df-802f-20201061ef61}"= "c:\program files\Messenger_Plus_Live_Belgium\tbMes0.dll" [2010-08-30 2734688]
[HKEY_CLASSES_ROOT\clsid\{d1a1c8f1-e3d9-48df-802f-20201061ef61}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{D1A1C8F1-E3D9-48DF-802F-20201061EF61}"= "c:\program files\Messenger_Plus_Live_Belgium\tbMes0.dll" [2010-08-30 2734688]
[HKEY_CLASSES_ROOT\clsid\{d1a1c8f1-e3d9-48df-802f-20201061ef61}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-18 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VIARaidUtl"="c:\program files\VIA\RAID\raid_tool.exe" [2008-09-24 4918936]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 32768]
"LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-02-28 63048]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
"nwiz"="nwiz.exe" [2008-05-03 1630208]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"fssui"="c:\program files\Windows Live\Family Safety\fsui.exe" [2009-08-05 647520]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2003-05-14 188416]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
"ArcSoft Connection Service"="c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]
"Nikon Transfer Monitor"="c:\program files\Fichiers communs\Nikon\Monitor\NkMonitor.exe" [2009-09-15 479232]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
"iTunesHelper"="e:\itunes\iTunesHelper.exe" [2010-07-21 141608]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2010-05-14 248552]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 86016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\All Users\Menu D'marrer\Programmes\D'marrage\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
ZDWLan Utility.lnk - c:\program files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe [2008-12-24 487424]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2010-06-11 15:32 87424 ----a-w- c:\windows\system32\LMIinit.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"e:\\Emul\\eMule\\emule.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"e:\\Nouveau dossier (3)\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"e:\\iTunes\\iTunes.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [30/08/2010 23:48 165456]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [30/08/2010 23:48 17744]
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [28/02/2008 16:31 12856]
R2 VRAID Log Service;VRAID Log Service;c:\program files\VIA\RAID\vialogsv.exe [24/12/2008 0:51 52888]
S2 gupdate1c9c013bc09c1fc;Service Google Update (gupdate1c9c013bc09c1fc);c:\program files\Google\Update\GoogleUpdate.exe [18/04/2009 12:52 133104]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [15/03/2009 10:34 216232]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenu du dossier 'Tâches planifiées'
2010-08-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-09-01 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-18 10:51]
2010-09-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-18 10:52]
2010-08-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-18 10:52]
2010-09-01 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 14:07]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.footbel.com/fr.html
uInternet Connection Wizard,ShellNext = hxxp://www.google.be/
uInternet Settings,ProxyOverride = *.local
IE: &Télécharger le FLV avec WinAVI... - e:\nouveau dossier\WinAVI FLV Converter\flv_link.htm
IE: Compare Prices with &Dealio - c:\documents and settings\klein\Application Data\Dealio\kb127\res\DealioSearch.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
- - - - ORPHELINS SUPPRIMES - - - -
URLSearchHooks-{9b339f6e-ddcd-401b-8764-230adbd01761} - (no file)
BHO-{9b339f6e-ddcd-401b-8764-230adbd01761} - (no file)
Toolbar-{9b339f6e-ddcd-401b-8764-230adbd01761} - (no file)
WebBrowser-{9B339F6E-DDCD-401B-8764-230ADBD01761} - (no file)
HKLM-Run-Cmaudio - cmicnfg.cpl
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-09-01 11:29
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
VIARaidUtl = c:\program files\VIA\RAID\raid_tool.exe?ouveau dos
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h-€|ÿÿÿÿ¤*€|ù*9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(648)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
- - - - - - - > 'explorer.exe'(2560)
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\RUNDLL32.EXE
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\LogMeIn\x86\RaMaint.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\program files\LogMeIn\x86\LMIGuardian.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\nvsvc32.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
.
**************************************************************************
.
Heure de fin: 2010-09-01 11:32:39 - La machine a redémarré
ComboFix-quarantined-files.txt 2010-09-01 09:32
Avant-CF: 125.579.198.464 octets libres
Après-CF: 125.710.671.872 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
- - End Of File - - E406FF64DA21D94E3A8C9677933EE735 -
Contributeur sécuritépas convaincu
puisque tu es pret à formater, alors autant pas se priver
Attention, avant de commencer, lit attentivement la procédure, et imprime la
Aide à l'utilisation
https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
Télécharge ComboFix de sUBs sur ton Bureau :
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
/!\ Déconnecte-toi du net et <gras>DESACTIVES TOUTES LES DEFENSES, antivirus et antispyware y compris /!\ </gras>
---> Double-clique sur ComboFix.exe
Un "pop-up" va apparaître qui dit que ComboFix est utilisé à vos risques et avec aucune garantie... Clique sur oui pour accepter
SURTOUT INSTALLES LA CONSOLE DE RECUPERATION
(si il te propose de l'installer remets internet)
---> Mets-le en langue française F
Tape sur la touche 1 (Yes) pour démarrer le scan.
Ne touche à rien(souris, clavier) tant que le scan n'est pas terminé, car tu risques de planter ton PC
En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.
Une fois le scan achevé, un rapport va s'afficher : Poste son contenu
/!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\
Note : Le rapport se trouve également là : C:\ComboFix.txt
-
virustotal :
Antivirus Version Last Update Result
AhnLab-V3 2010.09.01.00 2010.09.01 -
AntiVir 8.2.4.46 2010.09.01 -
Antiy-AVL 2.0.3.7 2010.09.01 -
Authentium 5.2.0.5 2010.09.01 -
Avast 4.8.1351.0 2010.09.01 -
Avast5 5.0.594.0 2010.09.01 -
AVG 9.0.0.851 2010.08.31 -
BitDefender 7.2 2010.09.01 -
CAT-QuickHeal 11.00 2010.09.01 -
ClamAV 0.96.2.0-git 2010.09.01 -
Comodo 5931 2010.09.01 -
DrWeb 5.0.2.03300 2010.09.01 -
Emsisoft 5.0.0.37 2010.09.01 -
eSafe 7.0.17.0 2010.08.30 -
eTrust-Vet 36.1.7830 2010.09.01 -
F-Prot 4.6.1.107 2010.08.31 -
F-Secure 9.0.15370.0 2010.09.01 -
Fortinet 4.1.143.0 2010.08.31 -
GData 21 2010.09.01 -
Ikarus T3.1.1.88.0 2010.09.01 -
Jiangmin 13.0.900 2010.08.30 -
K7AntiVirus 9.63.2406 2010.08.31 -
Kaspersky 7.0.0.125 2010.09.01 -
McAfee 5.400.0.1158 2010.09.01 -
McAfee-GW-Edition 2010.1B 2010.09.01 -
Microsoft 1.6103 2010.09.01 -
NOD32 5414 2010.09.01 -
Norman 6.05.11 2010.08.31 -
nProtect 2010-09-01.01 2010.09.01 -
Panda 10.0.2.7 2010.08.31 -
PCTools 7.0.3.5 2010.09.01 -
Prevx 3.0 2010.09.01 -
Rising 22.63.02.04 2010.09.01 -
Sophos 4.56.0 2010.09.01 -
Sunbelt 6820 2010.09.01 -
SUPERAntiSpyware 4.40.0.1006 2010.09.01 -
Symantec 20101.1.1.7 2010.09.01 -
TheHacker 6.5.2.1.360 2010.09.01 -
TrendMicro 9.120.0.1004 2010.09.01 -
TrendMicro-HouseCall 9.120.0.1004 2010.09.01 -
VBA32 3.12.14.0 2010.08.31 -
ViRobot 2010.8.31.4017 2010.09.01 -
VirusBuster 5.0.27.0 2010.08.31 -
Additional informationShow all
MD5 : a79594bc46ada0e4b7af852d3b2c7713
SHA1 : 86dbe686efe57d607716739c1dc5b3dbcaa4ed18
SHA256: c1f00ca28d1aa26f1588e0939b482f001b8679f8850d40ee669d7a6ac3565498 -
Contributeur sécuritéattend avant de formater
poste moi le rapport et
Rends toi sur ce site :
https://www.virustotal.com/gui/
Clique sur parcourir et cherche ce fichier :
C:\WINDOWS\PKUNZIP.PIF
Clique sur Send File.
Un rapport va s'élaborer ligne à ligne.
Attends la fin. Il doit comprendre la taille du fichier envoyé.
Sauvegarde le rapport avec le bloc-note.
Copie le dans ta réponse.
Si tu ne trouves pas le fichier alors
Affiche tous les fichiers et dossiers :
Pour cela :
Clique sur démarrer/panneau de configuration/option des dossiers/affichage
Cocher afficher les dossiers cachés
Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"
Décocher masquer les extensions dont le type est connu
Puis fais «appliquer» pour valider les changements.
Et OK
tuto pour t'aider
http://www.bibou0007.com/scans-en-ligne-f75/tutorial-sur-virustotal-t190.htm
- 1
- 2