Pc rame
j'ai mon pc qui est tres souvent et qui le reste longtemps a100%
je vous remercies pour votre aide
--
j'essaie d'apporter mon aide
33 réponses
Le problème principal est qu'un PC fonctionnant sous Windows XP affiche une utilisation CPU à 100% de manière répétée et prolongée, entraînant une lenteur et des comportements instables. Des réponses suggèrent des solutions anti-malware, notamment l'utilisation de ZHPDiag pour le diagnostic et la génération de rapports, puis l'envoi des résultats via des liens de partage afin d'identifier des éléments indésirables. Des analyses complémentaires reprennent des outils comme ComboFix et Ad-Remover pour nettoyer le système, avec des rapports détaillant les fichiers et clés de registre supprimés, notamment Conduit Engine et les barres d'outils associées. Par ailleurs, les éléments d'analyse dénotent des composants démarrage et des logiciels persistants, indiquant une remédiation potentielle complexe nécessitant une réinitialisation soignée du système.
-
N'importe quoi cette procédure est bien inutile, surtout beaucoup trop long, il y a bien plus simple ^^' Tu t'es juste bien compliquer la vie mon gars.
-
salut oui
-
est ce normal qu'au bout de 4heures j'en etait a peine a la moitie??
-
▶ Télécharge Dr Web CureIt sur ton Bureau :
▶ redemarre en mode sans échec
▶- Double clique (clic droit "en tant qu'admin" sous Vista) <drweb-cureit.exe> et ensuite clique sur <Analyse>;
▶- Clique <Ok> à l'invite de l'analyse rapide. S'il trouve des processus infectés alors clique le bouton <Oui>.
Note : une fenêtre s'ouvrira avec options pour "Commander" ou "50% de réduction" : Quitte en cliquant le "X".
▶- Lorsque le scan rapide est terminé, clique sur le menu <Options> puis <Changer la configuration> ; Choisis l'onglet <Scanner>, et décoche <Analyse heuristique>. Clique ensuite sur <Ok>.
▶- De retour à la fenêtre principale : clique pour activer <Analyse complète>
selectionne tous les disques
▶- Clique le bouton avec flèche verte sur la droite, et le scan débutera.
▶- Clique <Oui> pour tout à l'invite "Désinfecter ?" lorsqu'un fichier est détecté, et ensuite clique "Désinfecter".
▶- Lorsque le scan sera complété, regarde si tu peux cliquer sur l' icône, adjacente aux fichiers détectés (plusieurs feuilles l'une sur l'autre). Si oui, alors clique dessus et ensuite clique sur l'icône <Suivant>, au dessous, et choisis <Déplacer en quarantaine l'objet indésirable>.
▶- Du menu principal de l'outil, au haut à gauche, clique sur le menu <Fichier> et choisis <Enregistrer le rapport>. Sauvegarde le rapport sur ton Bureau. Ce dernier se nommera DrWeb.csv
▶-pour le rapport tu l enregistres sur ton bureau , tu clic droit dessus /envoyer vers / dossiers compresses
ensuite :
tu m'envoies l'archive comme ceci :
clique sur ce lien : http://www.cijoint.fr/
▶ Clique sur Parcourir et cherche le fichier ci-dessus.
▶ Clique sur Ouvrir.
▶ Clique sur "Cliquez ici pour déposer le fichier".
Un lien de cette forme :
http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt
est ajouté dans la page.
▶ Copie ce lien dans ta réponse.
▶- Ferme Dr.Web Cureit
▶- Redémarre ton ordi (important car certains fichiers peuvent être déplacés/réparés au redémarrage).
-
si je l'ai fait je sais ce n'est pas noter sur le log mais je l'ai bien fait ( peut etre apres avoir fait le log )
et sinon le pc a quoi?? -
pourquoi t'as pas supprimé avec malwarebytes au fait ?
-
le pc est tourne toujours autant a 100% et maintenant lorsque j'ouvre le pc le dossiers "mes documents" s"ouvre , lorsque j'ouvre google chrome il marque "" aie aie aie""
il y avait quoi ??
un grand merci pour ton aide -
ok encore des soucis ?
-
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org
Version de la base de données: 7392
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
06/08/2011 14:59:31
mbam-log-2011-08-06 (14-59-19).txt
Type d'examen: Examen complet (C:\|D:\|Q:\|)
Elément(s) analysé(s): 298479
Temps écoulé: 1 heure(s), 30 minute(s), 28 seconde(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 3
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
c:\documents and settings\hp_propriétaire.nom-eb85c523610\mes documents\téléchargements\everest poker.fr.exe (PUP.Casino) -> No action taken.
c:\system volume information\_restore{f75eec69-6e97-419b-93b4-6a3a275301c4}\RP6\A0003432.exe (Adware.Agent) -> No action taken.
c:\documents and settings\hp_propriétaire.nom-eb85c523610\Bureau\winlogon.exe (Heuristics.Reserved.Word.Exploit) -> No action taken.
-
je ne sais pas suivant l'heure...j'ai un concert à jouer de main soir donc probable que je ne revienne pas avant dimanche journée
-
ok merci pour ton aide je reviens ici demain apres midi
-
bien sur !
-
le netoyage avec malwerebyte est long et je taf demain puis je fermer le pc et finir demain??
-
fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.
▶ Télécharge ici :
Malwarebytes
▶ Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .
(NB : Si tu as un message d'erreur t'indiquant qu'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX
▶ Potasses le Tuto pour te familiariser avec le prg :
( cela dit, il est très simple d'utilisation ).
relance malwarebytes en suivant scrupuleusement ces consignes :
! Déconnecte toi et ferme toutes applications en cours !
▶ Lance Malwarebyte's .
Fais un examen dit "Complet" .
▶ Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
▶ à la fin tu cliques sur "résultat" .
▶ Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .
▶ Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !
▶ Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)
-
--ComboFix 11-08-05.02 - HP_Propriétaire 06/08/2011 1:52.2.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.2047.1392 [GMT 2:00]
Lancé depuis: c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Bureau\laurent.exe
Commutateurs utilisés :: c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Bureau\CFScript.txt
AV: BitDefender Antivirus *Disabled/Updated* {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: BitDefender Pare-feu *Disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
.
FILE ::
"c:\windows\is-BND7O.exe"
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\is-BND7O.exe
.
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_CDISKDUN
-------\Service_cdiskdun
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2011-07-06 au 2011-08-06 ))))))))))))))))))))))))))))))))))))
.
.
2011-08-05 23:00 . 2011-08-05 23:00 -------- d--h--w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Voisinage d'impression
2011-08-05 22:40 . 2011-08-05 22:40 512 ----a-w- C:\PhysicalDisk0_MBR.bin
2011-08-05 22:18 . 2011-08-05 22:40 -------- d-----w- C:\ZHP
2011-08-05 16:25 . 2011-08-05 16:26 -------- d-----w- c:\program files\Ad-Remover
2011-08-05 14:59 . 2011-08-05 15:11 -------- d-----w- C:\Kill'em
2011-08-04 08:52 . 2011-08-04 08:52 -------- d-----w- c:\documents and settings\Default User\Menu Démarrer
2011-08-01 15:37 . 2011-08-05 23:14 -------- d-----w- c:\program files\Smart File Advisor
2011-08-01 15:37 . 2011-08-01 15:37 -------- d-----w- c:\program files\Smart Projects
2011-08-01 14:51 . 2011-08-02 20:24 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Local Settings\Application Data\uTorrentBar_FR
2011-08-01 14:51 . 2011-08-01 14:51 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Local Settings\Application Data\Temp
2011-08-01 14:50 . 2011-08-05 23:35 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Application Data\uTorrent
2011-08-01 14:16 . 2011-08-01 14:16 -------- d-----w- c:\program files\eChanblard
2011-08-01 13:53 . 2011-08-01 13:53 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Local Settings\Application Data\SoftGrid Client
2011-08-01 13:53 . 2011-08-01 14:09 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Application Data\SoftGrid Client
2011-08-01 13:52 . 2011-08-01 13:52 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\{90140011-0061-040C-0000-0000000FF1CE}
2011-08-01 13:52 . 2011-08-05 23:11 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\SoftGrid Client
2011-08-01 13:50 . 2011-08-04 08:52 -------- d-----w- c:\program files\Microsoft Application Virtualization Client
2011-08-01 13:50 . 2011-08-01 13:50 -------- d-----w- c:\documents and settings\All Users\Microsoft
2011-07-29 19:54 . 2011-08-05 22:11 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Application Data\Skype
2011-07-29 19:54 . 2011-07-29 19:54 -------- d-----r- c:\program files\Skype
2011-07-29 19:54 . 2011-07-29 19:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2011-07-11 09:13 . 2011-07-11 09:13 3727360 ----a-w- c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2011-07-10 13:53 . 2011-07-10 14:13 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\DoctorWeb
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-06 17:52 . 2008-12-05 16:10 22712 -c--a-w- c:\windows\system32\drivers\mbam.sys
2011-07-06 17:52 . 2008-12-05 16:10 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-26 20:11 . 2011-06-26 20:11 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-06 11:35 . 2010-03-06 17:18 1859072 ----a-w- c:\windows\system32\win32k.sys
2011-05-14 13:15 . 2005-11-07 14:18 73728 -c--a-w- c:\windows\ALCFDRTM.VER
.
.
((((((((((((((((((((((((((((( SnapShot@2011-08-05_23.13.40 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-08-06 00:05 . 2011-08-06 00:05 16384 c:\windows\Temp\Perflib_Perfdata_9e4.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}]
2010-07-19 16:32 165184 ----a-w- c:\program files\SFR\Kit\SFRNavErrorHelper.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-05-10 94208]
"BDAgent"="c:\program files\BitDefender\BitDefender 2010\bdagent.exe" [2011-05-14 1198048]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2010\IEShow.exe" [2009-10-19 71152]
"B2C_AGENT"="c:\documents and settings\All Users\Application Data\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe" [2011-06-14 404568]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
"Smart File Advisor"="c:\program files\Smart File Advisor\sfa.exe" [2011-04-04 280824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoStrCmpLogical"= 1 (0x1)
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Agent Serveur Média.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Agent Serveur Média.lnk
backup=c:\windows\pss\Agent Serveur Média.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech SetPoint.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus DX4000 Series]
2006-02-21 04:00 131072 -c--a-w- c:\windows\system32\spool\drivers\w32x86\3\E_FATIBEE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
2005-01-18 15:37 217088 -c--a-w- c:\program files\Logitech\Video\LogiTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-13 18:34 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"RDSessMgr"=3 (0x3)
"RasMan"=2 (0x2)
"mnmsrvc"=3 (0x3)
"helpsvc"=2 (0x2)
"ERSvc"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"LogitechVideoRepair"=c:\program files\Logitech\Video\ISStart.exe
"Start WingMan Profiler"=c:\program files\Logitech\Gaming Software\LWEMon.exe /noui
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Nero\\Nero8\\Nero Home\\NeroHome.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Orange\\RIM\\fscommand\\RIM.exe"=
"c:\\Program Files\\Orange\\RIM\\fscommand\\CKSocketServer.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Documents and Settings\\HP_Propriétaire.NOM-EB85C523610\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\eChanblard\\emule.exe"=
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [19/09/2007 17:04 639224]
R2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2010\bdvedisk.sys [22/09/2009 08:22 85128]
R2 cvhsvc;Client Virtualization Handler;c:\program files\Fichiers communs\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [28/02/2010 02:33 821664]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [27/07/2008 15:30 3712]
R2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [24/04/2010 01:10 483688]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [19/10/2009 16:04 111312]
R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfsxp.sys [02/12/2009 22:23 554344]
R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplayxp.sys [02/12/2009 22:23 211432]
R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirxp.sys [02/12/2009 22:23 20584]
R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvolxp.sys [02/12/2009 22:23 18280]
R3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [24/04/2010 01:10 209768]
S2 Arrakis3;BitDefender Serveur Arrakis;c:\program files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [19/10/2009 16:06 183880]
S2 maconfservice;Ma-Config Service;"c:\program files\ma-config.com\maconfservice.exe" --> c:\program files\ma-config.com\maconfservice.exe [?]
S2 PS3 Media Server;PS3 Media Server;c:\program files\PS3 Media Server\win32\service\wrapper.exe [13/01/2010 01:24 217088]
S3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [07/12/2009 18:46 153448]
S3 fsbl;F-Secure BlackLight Engine Driver;\??\c:\program files\AntivirusFirewall\Anti-Virus\fsbl5380.sys --> c:\program files\AntivirusFirewall\Anti-Virus\fsbl5380.sys [?]
S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [01/12/2010 22:27 33792]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [05/12/2008 18:10 22712]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [05/12/2008 18:10 41272]
S3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [05/08/2004 20:00 14336]
S3 osppsvc;Office Software Protection Platform;c:\program files\Fichiers communs\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09/01/2010 21:37 4640000]
S3 XPADFL02;XPAD Filter Service 02;c:\windows\system32\drivers\xPADFL02.sys [01/12/2010 22:28 27904]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
bdx REG_MULTI_SZ scan
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contenu du dossier 'Tâches planifiées'
.
2011-08-06 c:\windows\Tasks\User_Feed_Synchronization-{397C0F84-B55C-4781-AE45-D8685C6C4773}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
.
------- Examen supplémentaire -------
.
uInternet Settings,ProxyOverride = *.local
IE: ajouter cette page à vos favoris Orange - c:\docume~1\HP_PRO~1.NOM\LOCALS~1\Temp\cce125E.html
IE: Envoyer au périphérique &Bluetooth... - c:\program files\Belkin\Bluetooth Software\btsendto_ie_ctx.htm
IE: traduire la page - c:\docume~1\HP_PRO~1.NOM\LOCALS~1\Temp\cce125C.html
IE: traduire le texte sélectionné - c:\docume~1\HP_PRO~1.NOM\LOCALS~1\Temp\cce125D.html
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
FF - ProfilePath - c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Application Data\Mozilla\Firefox\Profiles\cbj9aost.default\
FF - prefs.js: browser.startup.homepage - hxxp://messagerie-11.sfr.fr/webmail/mailbox.html#
FF - prefs.js: keyword.URL - hxxp://redirecterror.sfr.fr/?q=
FF - user.js: keyword.URL - hxxp://redirecterror.sfr.fr/?q=
.
- - - - ORPHELINS SUPPRIMES - - - -
.
URLSearchHooks-{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - c:\program files\uTorrentBar_FR\prxtbuTor.dll
BHO-{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - c:\program files\uTorrentBar_FR\prxtbuTor.dll
Toolbar-{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e} - c:\program files\uTorrentBar_FR\prxtbuTor.dll
WebBrowser-{05EEB91A-AEF7-4F8A-978F-FB83E7B03F8E} - c:\program files\uTorrentBar_FR\prxtbuTor.dll
HKCU-Run-uTorrent - c:\program files\uTorrent\uTorrent.exe
AddRemove-uTorrentBar_FR Toolbar - c:\program files\uTorrentBar_FR\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-06 02:05
Windows 5.1.2600 Service Pack 3 NTFS
.
Recherche de processus cachés ...
.
Recherche d'éléments en démarrage automatique cachés ...
.
Recherche de fichiers cachés ...
.
Scan terminé avec succès
Fichiers cachés: 0
.
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
.
- - - - - - - > 'winlogon.exe'(1204)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(3688)
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\System32\SCardSvr.exe
c:\windows\system32\netdde.exe
c:\windows\system32\msdtc.exe
c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
c:\program files\Belkin\Bluetooth Software\bin\btwdins.exe
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
c:\windows\system32\msiexec.exe
c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
c:\program files\Fichiers communs\Nero\Lib\NMIndexingService.exe
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\windows\system32\IoctlSvc.exe
c:\windows\system32\locator.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\system32\SearchProtocolHost.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\SearchFilterHost.exe
.
**************************************************************************
.
Heure de fin: 2011-08-06 02:08:48 - La machine a redémarré
ComboFix-quarantined-files.txt 2011-08-06 00:08
.
Avant-CF: 87 429 152 768 octets libres
Après-CF: 87 489 523 712 octets libres
.
- - End Of File - - 11672960D73EF0A1FDA051D79CE9752E
j'essaie d'apporter mon aide -
la suite
-
je l'ai vire depuis programesfiles
-
utorrentbar ne se desinstalle pas j'ai viré utorrent mais ca n'a rien changer
-
tu n'as pas desintallé utorrentBar
vire-la
========================
vire aussi adobe reader 9
=========================
__________________________________________________
=>/!\Le script qui suit a été écrit spécialement cet ordinateur/!\ <=
=>il est fort déconseillé de le transposer sur un autre ordinateur !<=
----------------------------------------------------------------------------
Toujours avec toutes les protections désactivées, fais ceci :
▶ Ouvre le bloc-notes (Menu démarrer --> programmes --> accessoires --> bloc-notes)
▶ Copie/colle dans le bloc-notes ce qui entre les lignes ci dessous (sans les lignes) :
----------------------------------------------------------
KillAll::
File::
c:\windows\is-BND7O.exe
Rootkit::
c:\documents and settings\HP_PROPRIETAIRE\LOCAL SETTINGS\Temp\cdiskdun.sys
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] => Microsoft Policies Explorer
"NoStrCmpLogical"=0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=-
Driver::
cdiskdun
------------------------------------------------------------------
▶ Enregistre ce fichier sur ton Bureau (et pas ailleurs !) sous le nom CFScript.txt
▶ Quitte le Bloc Notes
▶ Fais un glisser/déposer de ce fichier CFScript sur le fichier combofix
▶ Patiente le temps du scan. Le Bureau va disparaître à plusieurs reprises : c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
▶ Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
▶ Si le fichier ne s'ouvre pas, il se trouve ici => C:\ComboFix.txt
-
ComboFix 11-08-05.02 - HP_Propriétaire 06/08/2011 1:03.1.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.2047.1408 [GMT 2:00]
Lancé depuis: c:\documents and settings\HP_PropriÚtaire.NOM-EB85C523610\Bureau\laurent.exe
AV: BitDefender Antivirus *Disabled/Updated* {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
FW: BitDefender Pare-feu *Disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\dfinstall.log
c:\windows\iun6002.exe
c:\windows\regedit.com
c:\windows\system32\config\systemprofile\WINDOWS
c:\windows\system32\drivers\etc\lmhosts
c:\windows\system32\paypal.url
c:\windows\system32\ps2.bat
c:\windows\system32\tmp.reg
c:\windows\system32\VIRepair
c:\windows\system32\VIRepair\vi.sif
c:\windows\system32\winx.url
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2011-07-05 au 2011-08-05 ))))))))))))))))))))))))))))))))))))
.
.
2011-08-05 23:00 . 2011-08-05 23:00 -------- d--h--w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Voisinage d'impression
2011-08-05 22:40 . 2011-08-05 22:40 512 ----a-w- C:\PhysicalDisk0_MBR.bin
2011-08-05 22:18 . 2011-08-05 22:40 -------- d-----w- C:\ZHP
2011-08-05 16:25 . 2011-08-05 16:26 -------- d-----w- c:\program files\Ad-Remover
2011-08-05 14:59 . 2011-08-05 15:11 -------- d-----w- C:\Kill'em
2011-08-04 08:52 . 2011-08-04 08:52 -------- d-----w- c:\documents and settings\Default User\Menu Démarrer
2011-08-01 15:37 . 2011-08-01 15:37 -------- d-----w- c:\program files\Smart File Advisor
2011-08-01 15:37 . 2011-08-01 15:37 -------- d-----w- c:\program files\Smart Projects
2011-08-01 14:51 . 2011-08-01 14:51 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Local Settings\Application Data\Temp
2011-08-01 14:50 . 2011-08-01 14:50 -------- d-----w- c:\program files\uTorrent
2011-08-01 14:50 . 2011-08-05 23:13 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Application Data\uTorrent
2011-08-01 14:50 . 2011-08-01 14:50 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Local Settings\Application Data\uTorrent
2011-08-01 14:16 . 2011-08-01 14:16 -------- d-----w- c:\program files\eChanblard
2011-08-01 13:53 . 2011-08-01 13:53 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Local Settings\Application Data\SoftGrid Client
2011-08-01 13:53 . 2011-08-01 14:09 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Application Data\SoftGrid Client
2011-08-01 13:52 . 2011-08-01 13:52 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\{90140011-0061-040C-0000-0000000FF1CE}
2011-08-01 13:52 . 2011-08-05 23:11 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\SoftGrid Client
2011-08-01 13:50 . 2011-08-04 08:52 -------- d-----w- c:\program files\Microsoft Application Virtualization Client
2011-08-01 13:50 . 2011-08-01 13:50 -------- d-----w- c:\documents and settings\All Users\Microsoft
2011-08-01 08:21 . 2011-08-01 08:21 709968 ----a-w- c:\windows\is-BND7O.exe
2011-07-29 19:54 . 2011-08-05 22:11 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Application Data\Skype
2011-07-29 19:54 . 2011-07-29 19:54 -------- d-----r- c:\program files\Skype
2011-07-29 19:54 . 2011-07-29 19:54 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2011-07-11 09:13 . 2011-07-11 09:13 3727360 ----a-w- c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}\components\SkypeFfComponent.dll
2011-07-10 13:53 . 2011-07-10 14:13 -------- d-----w- c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\DoctorWeb
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-06 17:52 . 2008-12-05 16:10 22712 -c--a-w- c:\windows\system32\drivers\mbam.sys
2011-07-06 17:52 . 2008-12-05 16:10 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-06-26 20:11 . 2011-06-26 20:11 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-06 11:35 . 2010-03-06 17:18 1859072 ----a-w- c:\windows\system32\win32k.sys
2011-05-14 13:15 . 2005-11-07 14:18 73728 -c--a-w- c:\windows\ALCFDRTM.VER
.
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e}"= "c:\program files\uTorrentBar_FR\prxtbuTor.dll" [2011-03-28 176936]
.
[HKEY_CLASSES_ROOT\clsid\{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e}]
2011-03-28 16:22 176936 ----a-w- c:\program files\uTorrentBar_FR\prxtbuTor.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}]
2010-07-19 16:32 165184 ----a-w- c:\program files\SFR\Kit\SFRNavErrorHelper.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e}"= "c:\program files\uTorrentBar_FR\prxtbuTor.dll" [2011-03-28 176936]
.
[HKEY_CLASSES_ROOT\clsid\{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{05EEB91A-AEF7-4F8A-978F-FB83E7B03F8E}"= "c:\program files\uTorrentBar_FR\prxtbuTor.dll" [2011-03-28 176936]
.
[HKEY_CLASSES_ROOT\clsid\{05eeb91a-aef7-4f8a-978f-fb83e7b03f8e}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-08-01 639864]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-05-10 94208]
"BDAgent"="c:\program files\BitDefender\BitDefender 2010\bdagent.exe" [2011-05-14 1198048]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2010\IEShow.exe" [2009-10-19 71152]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"B2C_AGENT"="c:\documents and settings\All Users\Application Data\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe" [2011-06-14 404568]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
"Smart File Advisor"="c:\program files\Smart File Advisor\sfa.exe" [2011-04-04 280824]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoStrCmpLogical"= 1 (0x1)
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Agent Serveur Média.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Agent Serveur Média.lnk
backup=c:\windows\pss\Agent Serveur Média.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech SetPoint.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus DX4000 Series]
2006-02-21 04:00 131072 -c--a-w- c:\windows\system32\spool\drivers\w32x86\3\E_FATIBEE.EXE
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
2005-01-18 15:37 217088 -c--a-w- c:\program files\Logitech\Video\LogiTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-13 18:34 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"RDSessMgr"=3 (0x3)
"RasMan"=2 (0x2)
"mnmsrvc"=3 (0x3)
"helpsvc"=2 (0x2)
"ERSvc"=2 (0x2)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"LogitechVideoRepair"=c:\program files\Logitech\Video\ISStart.exe
"Start WingMan Profiler"=c:\program files\Logitech\Gaming Software\LWEMon.exe /noui
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Nero\\Nero8\\Nero Home\\NeroHome.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Orange\\RIM\\fscommand\\RIM.exe"=
"c:\\Program Files\\Orange\\RIM\\fscommand\\CKSocketServer.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Documents and Settings\\HP_Propriétaire.NOM-EB85C523610\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\eChanblard\\emule.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
.
R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [19/09/2007 17:04 639224]
R2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2010\bdvedisk.sys [22/09/2009 08:22 85128]
R2 cvhsvc;Client Virtualization Handler;c:\program files\Fichiers communs\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [28/02/2010 02:33 821664]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [27/07/2008 15:30 3712]
R2 sftlist;Application Virtualization Client;c:\program files\Microsoft Application Virtualization Client\sftlist.exe [24/04/2010 01:10 483688]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [07/12/2009 18:46 153448]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [19/10/2009 16:04 111312]
R3 Sftfs;Sftfs;c:\windows\system32\drivers\Sftfsxp.sys [02/12/2009 22:23 554344]
R3 Sftplay;Sftplay;c:\windows\system32\drivers\Sftplayxp.sys [02/12/2009 22:23 211432]
R3 Sftredir;Sftredir;c:\windows\system32\drivers\Sftredirxp.sys [02/12/2009 22:23 20584]
R3 Sftvol;Sftvol;c:\windows\system32\drivers\Sftvolxp.sys [02/12/2009 22:23 18280]
R3 sftvsa;Application Virtualization Service Agent;c:\program files\Microsoft Application Virtualization Client\sftvsa.exe [24/04/2010 01:10 209768]
S2 Arrakis3;BitDefender Serveur Arrakis;c:\program files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\arrakis3.exe [19/10/2009 16:06 183880]
S2 maconfservice;Ma-Config Service;"c:\program files\ma-config.com\maconfservice.exe" --> c:\program files\ma-config.com\maconfservice.exe [?]
S2 PS3 Media Server;PS3 Media Server;c:\program files\PS3 Media Server\win32\service\wrapper.exe [13/01/2010 01:24 217088]
S3 cdiskdun;cdiskdun;\??\c:\docume~1\HP_PRO~1\LOCALS~1\Temp\cdiskdun.sys --> c:\docume~1\HP_PRO~1\LOCALS~1\Temp\cdiskdun.sys [?]
S3 fsbl;F-Secure BlackLight Engine Driver;\??\c:\program files\AntivirusFirewall\Anti-Virus\fsbl5380.sys --> c:\program files\AntivirusFirewall\Anti-Virus\fsbl5380.sys [?]
S3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [01/12/2010 22:27 33792]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [05/12/2008 18:10 22712]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [05/12/2008 18:10 41272]
S3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [05/08/2004 20:00 14336]
S3 osppsvc;Office Software Protection Platform;c:\program files\Fichiers communs\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [09/01/2010 21:37 4640000]
S3 XPADFL02;XPAD Filter Service 02;c:\windows\system32\drivers\xPADFL02.sys [01/12/2010 22:28 27904]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
bdx REG_MULTI_SZ scan
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contenu du dossier 'Tâches planifiées'
.
2011-08-05 c:\windows\Tasks\User_Feed_Synchronization-{397C0F84-B55C-4781-AE45-D8685C6C4773}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
.
------- Examen supplémentaire -------
.
uInternet Settings,ProxyOverride = *.local
IE: ajouter cette page à vos favoris Orange - c:\docume~1\HP_PRO~1.NOM\LOCALS~1\Temp\cce125E.html
IE: Envoyer au périphérique &Bluetooth... - c:\program files\Belkin\Bluetooth Software\btsendto_ie_ctx.htm
IE: traduire la page - c:\docume~1\HP_PRO~1.NOM\LOCALS~1\Temp\cce125C.html
IE: traduire le texte sélectionné - c:\docume~1\HP_PRO~1.NOM\LOCALS~1\Temp\cce125D.html
DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
FF - ProfilePath - c:\documents and settings\HP_Propriétaire.NOM-EB85C523610\Application Data\Mozilla\Firefox\Profiles\cbj9aost.default\
FF - prefs.js: browser.startup.homepage - hxxp://messagerie-11.sfr.fr/webmail/mailbox.html#
FF - prefs.js: keyword.URL - hxxp://redirecterror.sfr.fr/?q=
FF - user.js: keyword.URL - hxxp://redirecterror.sfr.fr/?q=
.
- - - - ORPHELINS SUPPRIMES - - - -
.
ShellExecuteHooks-{56F9679E-7826-4C84-81F3-532071A8BCC5} - (no file)
SafeBoot-AVG Anti-Spyware Driver
SafeBoot-AVG Anti-Spyware Guard
AddRemove-WBFS Manager 3.0 - c:\program files\WBFS\WBFS Manager 3.0\uninstall.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-08-06 01:17
Windows 5.1.2600 Service Pack 3 NTFS
.
Recherche de processus cachés ...
.
Recherche d'éléments en démarrage automatique cachés ...
.
Recherche de fichiers cachés ...
.
Scan terminé avec succès
Fichiers cachés: 0
.
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
.
- - - - - - - > 'winlogon.exe'(1204)
c:\windows\system32\Ati2evxx.dll
.
- - - - - - - > 'explorer.exe'(5728)
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\windows\System32\SCardSvr.exe
c:\windows\system32\netdde.exe
c:\windows\system32\msdtc.exe
c:\windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
c:\program files\Belkin\Bluetooth Software\bin\btwdins.exe
c:\windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
c:\program files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
c:\windows\system32\msiexec.exe
c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
c:\program files\Fichiers communs\Nero\Lib\NMIndexingService.exe
c:\program files\NVIDIA Corporation\nTune\nTuneService.exe
c:\windows\system32\IoctlSvc.exe
c:\windows\system32\locator.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\system32\SearchProtocolHost.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\SearchFilterHost.exe
.
**************************************************************************
.
Heure de fin: 2011-08-06 01:20:57 - La machine a redémarré
ComboFix-quarantined-files.txt 2011-08-05 23:20
.
Avant-CF: 87 152 644 096 octets libres
Après-CF: 87 339 094 016 octets libres
.
- - End Of File - - 0ABB971A3C204A7F1BF75A965F164C47
- 1
- 2