Sos spyware secure
merci pr vs reponses
Search Navipromo version 3.3.6 commencé le 08/12/2007 à 10:08:57,34
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!
Outil exécuté depuis C:\Program Files\navilog1
Mise à jour le 14.11.2007 à 18h00 par IL-MAFIOSO
Microsoft Windows Vista 6.0.6000
Internet Explorer : 7.0.6000.16546
*** Recherche Programmes installés ***
*** Recherche dossiers dans C:\Windows ***
*** Recherche dossiers dans C:\Program Files ***
*** Recherche dossiers dans C:\ProgramData ***
*** Recherche dossiers dans C:\ProgramData\Microsoft\Windows\Start Menu\Programs ***
*** Recherche dossiers dans C:\USERS\BIZOUX\APPDATA\ROAMING\MICROS~1\WINDOWS\STARTM~1\PROGRAMS ***
*** Recherche dossiers dans C:\Users\bizoux\AppData\Local\virtualstore\Program Files ***
*** Recherche dossiers dans C:\Users\bizoux\AppData\Roaming ***
*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net
Fichier(s) caché(s) :
C:\Users\bizoux\AppData\Local\zfsgshlekx.dat
C:\Users\bizoux\AppData\Local\zfsgshlekx.exe
C:\Users\bizoux\AppData\Local\zfsgshlekx_nav.dat
C:\Users\bizoux\AppData\Local\zfsgshlekx_navps.dat
Processus caché(s) :
C:\Users\bizoux\AppData\Local\zfsgshlekx.exe
*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!
* Recherche dans C:\Windows\system32 *
* Recherche dans C:\Users\bizoux\AppData\Local\Microsoft *
* Recherche dans C:\Users\bizoux\AppData\Local\virtualstore\windows\system32 *
* Recherche dans C:\Users\bizoux\AppData\Local *
Fichiers trouvés :
zfsgshlekx.exe trouvé !
zfsgshlekx.dat trouvé !
zfsgshlekx_nav.dat trouvé !
zfsgshlekx_navps.dat trouvé !
*** Recherche fichiers ***
C:\Windows\system32\nvs2.inf trouvé !
*** Recherche clés spécifiques dans le Registre ***
HKEY_CURRENT_USER\Software\Lanconfig trouvé !
*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Recherche fichiers connus:
2)Recherche Heuristique :
C:\Users\bizoux\AppData\Local\zfsgshlekx.dat trouvé !
C:\Users\bizoux\AppData\Local\zfsgshlekx_nav.dat trouvé !
3)Recherche Certificats :
Certificat Egroup trouvé !
*** Analyse terminée le 08/12/2007 à 10:10:11,48 ***
Configuration: Windows Vista Internet Explorer 7.0
25 réponses
Une analyse Navilog1 sur Windows Vista signale des éléments potentiellement malware et des fichiers et clés de registre suspects, dont zfsgshlekx.exe et des entrées autostart, nécessitant une vérification approfondie avant suppression. Des outils de détection, tels que Catchme et ComboFix, apparaissent comme éléments centraux pour confirmer les fichiers suspects et préparer les suppressions sécurisées, avec la création d’un point de restauration. Des réponses suggèrent des scans complémentaires (Bitdefender Online, Avast) et des limites liées à Vista pour certains outils antivirus, tout en discutant les risques de suppression manuelle. En cas d’incertitude, le fil encourage à partager le rapport pour analyse et à éviter la désinfection sans conseil expert, tout en documentant les éléments détectés et les composants système impliqués.
-
Contributeuroui en effet il faudra reprendre le rapport combo
-
citation
selectionne ceci
registry::
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{06955f 46-9bf0-11dc-b961-001c252f163f}]
\shell\Auto\command - ufpyzntyt.exe
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL ufpyzntyt.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0c7c5 96-92d8-11dc-b60e-001c252f163f}]
\shell\Auto\command - ufpyzntyt.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e44ef4 fa-9abc-11dc-a4de-001c252f163f}]
\shell\Auto\command - F:\hhbgkpudh.exe
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\hhbgkpudh.exe
pas de commande donc ça peut pas marcher
[-HKEY_CURRENT_USER..... -
merci
-
Contributeurhttps://www.bitdefender.fr/
voici le lien -
hello
j'ai viré bitdefender
souci!!! -
Contributeurressaye quand même bitdefender
normalement il passe avec vista
@+ -
Contributeurok je cherche un scan valable pour vista
@+ -
CA NE MARCHE PAS CAR KASPERSKY N'EST PAS CONFIGURé POUR VISTA! Par contre si tu as autrre chose jsui open
-
Contributeuressaye ici
https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
tuto
http://www.infos-du-net.com/forum/267224-11-scan-ligne-kaspersky -
il me met scan failed impossible d'analyser l'ordinateur contre les virus
-
Contributeurton anti virus est avast
le scan en ligne de bitdefender
n'est en aucun cas gênant avec ton anti virus
donc il faut faire le scan
@+ -
j'ai désinstaler bit defender car j'ai avast?que faire
-
ContributeurFais un scan antivirus en ligne avec Internet Explorer
https://www.bitdefender.fr/
et copie colle le résultat ici
= En bas, à gauche de la fenêtre, clique sur BitDefender SCAN ONLINE
= Dans la nouvelle fenêtre, clique sur I agree
= La fenêtre change encore, clique sur Click here to scan
= Les signatures se chargent, etc.
tuto en image
http://pageperso.aol.fr/rginformatique/mapage/defender.htm
et
reposte un nouveau rapport hijackthis -
ComboFix 07-12-08.1 - bizoux 2007-12-08 22:52:15.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.68 [GMT 1:00]
Running from: C:\Users\bizoux\Desktop\ComboFix.exe
Command switches used :: C:\Users\bizoux\Documents\CFScript.txt
* Created a new restore point
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
K:\Autorun.inf
.
((((((((((((((((((((((((((((( Fichiers créés 2007-11-08 to 2007-12-08 ))))))))))))))))))))))))))))))))))))
.
2007-12-08 14:19 . 2007-12-08 14:19 <REP> d-------- C:\Program Files\PowerISO
2007-12-08 12:30 . 2007-12-08 12:30 <REP> d-------- C:\Program Files\test.exe
2007-12-08 12:29 . 2007-12-08 12:29 <REP> d-------- C:\Program Files\Trend Micro
2007-12-08 10:47 . 2007-12-08 10:47 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Media Player Classic
2007-12-08 10:33 . 2007-12-08 10:36 <REP> d-------- C:\Program Files\a-squared FreeTROJAN
2007-12-08 10:27 . 2007-12-08 10:27 6,479,600 --a------ C:\Users\bizoux\sunbelt-personal-firewall.exe
2007-12-08 10:06 . 2007-12-08 12:24 <REP> d-------- C:\Program Files\Navilog1
2007-12-08 10:04 . 2007-12-08 10:04 557,992 --a------ C:\Users\bizoux\Navilog1.exe
2007-12-02 20:17 . 2007-12-02 20:22 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Winamp
2007-12-02 20:17 . 2007-12-02 20:18 <REP> d-------- C:\Program Files\Winamp
2007-12-02 20:17 . 2007-03-08 00:51 129,784 --------- C:\Windows\System32\pxafs.dll
2007-11-30 20:44 . 2007-11-30 20:44 <REP> d-------- C:\Users\bizoux\AppData\Roaming\eSobi
2007-11-25 14:54 . 2007-11-25 14:54 <REP> d-------- C:\Users\All Users\LightScribe
2007-11-25 14:54 . 2007-11-25 14:54 <REP> d-------- C:\ProgramData\LightScribe
2007-11-24 19:40 . 2007-09-06 12:00 95,608 --a------ C:\Windows\System32\AvastSS.scr
2007-11-24 19:40 . 2007-09-06 12:02 42,912 --a------ C:\Windows\System32\drivers\aswTdi.sys
2007-11-24 19:40 . 2007-09-06 12:03 23,152 --a------ C:\Windows\System32\drivers\aswRdr.sys
2007-11-24 19:39 . 2007-11-24 19:39 <REP> d-------- C:\Program Files\Alwil Software
2007-11-24 19:39 . 2007-09-06 12:09 801,144 --a------ C:\Windows\System32\aswBoot.exe
2007-11-24 19:39 . 2004-01-09 11:13 380,928 --a------ C:\Windows\System32\actskin4.ocx
2007-11-24 19:39 . 2007-09-06 12:02 45,648 --a------ C:\Windows\System32\drivers\aswMonFlt.sys
2007-11-24 17:06 . 2006-10-05 03:42 2,560 --------- C:\Windows\System32\drivers\cdralw2k.sys
2007-11-24 17:06 . 2006-10-05 03:42 2,432 --------- C:\Windows\System32\drivers\cdr4_xp.sys
2007-11-24 17:05 . 2007-11-24 17:06 <REP> d-------- C:\Program Files\Picasa2
2007-11-24 17:05 . 2007-11-24 17:05 <REP> d-------- C:\Program Files\Google
2007-11-24 16:29 . 2007-11-24 17:25 <REP> d-------- C:\Program Files\BitComet
2007-11-24 16:26 . 2007-11-24 16:26 <REP> d-------- C:\Program Files\CCleaner
2007-11-24 16:25 . 2007-11-24 16:25 <REP> d-------- C:\Program Files\RegCleaner
2007-11-22 22:08 . 2007-11-22 22:10 <REP> d-------- C:\Program Files\Spyware-Secure
2007-11-19 19:50 . 2007-11-19 19:50 <REP> d-------- C:\Program Files\ARCHPR
2007-11-19 19:50 . 2007-11-19 19:53 1,201 --a------ C:\Windows\ARCHPR.INI
2007-11-19 19:30 . 2007-11-19 19:30 <REP> d-------- C:\HiTRUSTDrive
2007-11-18 21:30 . 2007-11-18 21:30 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Nero
2007-11-18 21:21 . 2007-11-18 21:21 <REP> d-------- C:\Users\All Users\Nero
2007-11-18 21:21 . 2007-11-18 21:21 <REP> d-------- C:\ProgramData\Nero
2007-11-18 21:21 . 2007-11-18 21:21 <REP> d-------- C:\Program Files\Nero
2007-11-18 21:21 . 2007-11-18 21:25 <REP> d-------- C:\Program Files\Common Files\Nero
2007-11-17 13:14 . 2006-04-05 02:05 73,216 --a------ C:\Windows\System32\E_FLBBVE.DLL
2007-11-17 13:14 . 2005-04-11 02:01 62,976 --a------ C:\Windows\System32\E_FD4BBVE.DLL
2007-11-17 13:10 . 2004-09-10 20:12 49,152 --a------ C:\Windows\System32\E_DCINST.DLL
2007-11-17 13:08 . 2007-11-17 13:12 <REP> d-------- C:\Users\All Users\EPSON
2007-11-17 13:08 . 2007-11-17 13:12 <REP> d-------- C:\ProgramData\EPSON
2007-11-17 12:39 . 2007-11-17 13:15 <REP> d-------- C:\Program Files\epson
2007-11-17 12:39 . 2006-03-20 00:00 63,488 --a------ C:\Windows\System32\escwiad.dll
2007-11-17 12:39 . 2007-11-17 12:39 25 --a------ C:\Windows\CDE DX5000EFDG.ini
2007-11-16 22:11 . 2007-11-16 22:11 <REP> d-------- C:\Users\bizoux\AppData\Roaming\vlc
2007-11-16 22:04 . 2007-11-16 22:04 <REP> d-------- C:\Program Files\K-Lite Codec Pack
2007-11-16 22:03 . 2007-11-16 22:03 <REP> d-------- C:\Program Files\VideoLAN
2007-11-15 23:44 . 2007-11-15 23:45 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Creative
2007-11-15 23:41 . 2000-05-22 09:58 647,872 --------- C:\Windows\System32\Mscomct2.ocx
2007-11-15 23:41 . 1999-10-10 18:00 41,984 --------- C:\Windows\Ctregrun.exe
2007-11-15 23:40 . 2007-11-30 20:43 <REP> d-------- C:\Program Files\Audible
2007-11-15 23:40 . 2001-08-17 22:43 24,576 --------- C:\Windows\System32\msxml3a.dll
2007-11-15 23:37 . 1999-12-12 18:01 44,032 --------- C:\Windows\System32\CTSVCCDA.EXE
2007-11-15 23:37 . 1999-11-17 18:00 25,088 --------- C:\Windows\System32\CTSVCCTL.EXE
2007-11-15 23:36 . 2007-11-15 23:39 <REP> d--h----- C:\Program Files\Creative Installation Information
2007-11-15 23:36 . 2007-11-15 23:36 <REP> d-------- C:\Program Files\Common Files\Creative
2007-11-15 23:35 . 2007-11-15 23:35 <REP> d-------- C:\Users\All Users\Creative
2007-11-15 23:35 . 2007-11-15 23:35 <REP> d-------- C:\ProgramData\Creative
2007-11-15 23:33 . 2007-11-15 23:41 <REP> d-------- C:\Program Files\Creative
2007-11-15 23:24 . 2007-11-15 23:24 <REP> d-------- C:\Users\bizoux\AppData\Roaming\CyberLink
2007-11-14 22:45 . 2007-11-14 22:45 <REP> d-------- C:\Users\bizoux\AppData\Roaming\AdobeUM
2007-11-14 21:59 . 2007-12-08 22:57 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Azureus
2007-11-14 21:53 . 2007-09-24 23:31 69,632 --a------ C:\Windows\System32\javacpl.cpl
2007-11-14 21:52 . 2007-11-14 21:53 <REP> d-------- C:\Program Files\Java
2007-11-14 21:51 . 2007-11-14 21:51 <REP> d-------- C:\Program Files\Common Files\Java
2007-11-14 21:48 . 2007-11-14 21:48 <REP> d-------- C:\Program Files\Azureus
2007-11-14 19:53 . 2007-11-14 19:53 <REP> d-------- C:\Users\All Users\Yahoo! Companion
2007-11-14 19:53 . 2007-11-14 19:53 <REP> d-------- C:\ProgramData\Yahoo! Companion
2007-11-14 08:25 . 2007-11-14 08:25 205,824 --a------ C:\Windows\System32\msoeacct.dll
2007-11-14 08:25 . 2007-11-14 08:25 87,040 --a------ C:\Windows\System32\msoert2.dll
2007-11-14 08:25 . 2007-11-14 08:25 39,424 --a------ C:\Windows\System32\ACCTRES.dll
2007-11-14 08:24 . 2007-11-14 08:24 376,320 --a------ C:\Windows\System32\winsrv.dll
2007-11-14 08:24 . 2007-11-14 08:24 49,664 --a------ C:\Windows\System32\csrsrv.dll
2007-11-14 08:22 . 2007-11-14 08:22 414,208 --a------ C:\Windows\System32\msscp.dll
2007-11-14 08:22 . 2007-11-14 08:22 2,048 --a------ C:\Windows\System32\tzres.dll
2007-11-14 08:21 . 2007-11-14 08:21 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-11-14 08:21 . 2007-11-14 08:21 396,800 --a------ C:\Windows\System32\MPSSVC.dll
2007-11-14 08:21 . 2007-11-14 08:21 392,192 --a------ C:\Windows\System32\FirewallAPI.dll
2007-11-14 08:21 . 2007-11-14 08:21 178,688 --a------ C:\Windows\System32\iphlpsvc.dll
2007-11-14 08:21 . 2007-11-14 08:21 86,016 --a------ C:\Windows\System32\icfupgd.dll
2007-11-14 08:21 . 2007-11-14 08:21 63,488 --a------ C:\Windows\System32\drivers\mpsdrv.sys
2007-11-14 08:21 . 2007-11-14 08:21 61,952 --a------ C:\Windows\System32\cmifw.dll
2007-11-14 08:21 . 2007-11-14 08:21 23,040 --a------ C:\Windows\System32\drivers\tunnel.sys
2007-11-14 08:21 . 2007-11-14 08:21 16,896 --a------ C:\Windows\System32\wfapigp.dll
2007-11-14 08:21 . 2007-11-14 08:21 15,360 --a------ C:\Windows\System32\drivers\TUNMP.SYS
2007-11-14 08:20 . 2007-11-14 08:20 8,147,968 --a------ C:\Windows\System32\wmploc.DLL
2007-11-14 08:20 . 2007-11-14 08:20 1,191,936 --a------ C:\Windows\System32\msxml3.dll
2007-11-14 08:20 . 2007-11-14 08:20 7,680 --a------ C:\Windows\System32\spwmp.dll
2007-11-14 08:20 . 2007-11-14 08:20 4,096 --a------ C:\Windows\System32\msdxm.ocx
2007-11-14 08:20 . 2007-11-14 08:20 4,096 --a------ C:\Windows\System32\dxmasf.dll
2007-11-14 08:20 . 2007-11-14 08:20 2,048 --a------ C:\Windows\System32\msxml3r.dll
2007-11-14 08:19 . 2007-11-14 08:19 1,383,424 --a------ C:\Windows\System32\mshtml.tlb
2007-11-14 08:17 . 2007-11-14 08:17 1,335,296 --a------ C:\Windows\System32\msxml6.dll
2007-11-14 08:17 . 2007-11-14 08:17 737,792 --a------ C:\Windows\System32\inetcomm.dll
2007-11-14 08:17 . 2007-11-14 08:17 84,480 --a------ C:\Windows\System32\INETRES.dll
2007-11-14 08:17 . 2007-11-14 08:17 2,048 --a------ C:\Windows\System32\msxml6r.dll
2007-11-14 08:16 . 2007-11-14 08:16 788,992 --a------ C:\Windows\System32\rpcrt4.dll
2007-11-14 08:16 . 2007-11-14 08:16 152,576 --a------ C:\Windows\System32\imagehlp.dll
2007-11-14 08:16 . 2007-11-14 08:16 12,800 --a------ C:\Windows\System32\drivers\fs_rec.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-08 16:45 --------- d-----w C:\ProgramData\Microsoft Help
2007-12-02 18:38 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-01 18:04 --------- d-----w C:\Program Files\Common Files\NewTech Infosystems
2007-11-30 19:46 --------- d-----w C:\Program Files\eSobi
2007-11-30 19:43 --------- d-----w C:\ProgramData\eSobi
2007-11-18 10:28 --------- d-----w C:\Program Files\Acer Arcade Live
2007-11-18 10:23 --------- d-----w C:\ProgramData\CyberLink
2007-11-14 17:54 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-11-14 17:53 --------- d-----w C:\ProgramData\Symantec
2007-11-14 07:31 --------- d-----w C:\Program Files\Windows Mail
2007-11-14 07:18 56,320 ----a-w C:\Windows\System32\iesetup.dll
2007-11-14 07:18 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2007-11-14 07:18 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2007-11-13 22:05 --------- d-sh--w C:\ProgramData\Modèles
2007-11-13 22:05 --------- d-sh--w C:\ProgramData\Menu Démarrer
2007-11-13 22:05 --------- d-sh--w C:\ProgramData\Favoris
2007-11-13 22:05 --------- d-sh--w C:\ProgramData\Bureau
2007-11-13 22:05 --------- d-sh--w C:\Program Files\Fichiers communs
2007-10-18 10:31 51,224 ----a-w C:\Windows\System32\sirenacm.dll
2007-09-28 17:07 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll
2007-09-28 17:05 81,920 ----a-w C:\Windows\System32\dpl100.dll
2007-09-28 17:05 739,840 ----a-w C:\Windows\System32\divx.dll
2006-11-02 12:50 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((( snapshot@2007-12-08_13.16.48,36 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-12-08 11:23:34 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2007-12-08 15:13:21 67,584 --s-a-w C:\Windows\bootstat.dat
- 2007-12-08 11:25:11 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2007-12-08 15:15:57 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2007-12-08 15:15:57 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2007-12-08 11:25:16 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2007-12-08 15:15:52 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2007-12-08 15:15:52 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2007-12-08 11:24:05 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2007-12-08 19:30:29 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2007-12-08 11:24:05 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-08 19:30:29 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-12-08 11:24:05 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-12-08 19:30:29 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-08-07 00:15:07 33,052 ----a-w C:\Windows\System32\drivers\scdemu.sys
- 2007-12-08 08:57:57 103,726 ----a-w C:\Windows\System32\perfc009.dat
+ 2007-12-08 14:06:51 103,726 ----a-w C:\Windows\System32\perfc009.dat
- 2007-12-08 08:57:57 117,366 ----a-w C:\Windows\System32\perfc00C.dat
+ 2007-12-08 14:06:52 117,366 ----a-w C:\Windows\System32\perfc00C.dat
- 2007-12-08 08:57:57 609,944 ----a-w C:\Windows\System32\perfh009.dat
+ 2007-12-08 14:06:52 609,944 ----a-w C:\Windows\System32\perfh009.dat
- 2007-12-08 08:57:58 690,594 ----a-w C:\Windows\System32\perfh00C.dat
+ 2007-12-08 14:06:52 690,594 ----a-w C:\Windows\System32\perfh00C.dat
- 2007-12-08 11:25:32 6,422 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-37221999-100896607-4100886726-1000_UserData.bin
+ 2007-12-08 15:16:56 6,462 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-37221999-100896607-4100886726-1000_UserData.bin
- 2007-12-08 11:25:32 52,574 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2007-12-08 15:16:54 52,756 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2007-12-08 11:25:31 46,522 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2007-12-08 13:26:19 47,010 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2006-11-02 13:35]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-23 12:04 C:\Windows\RtHDVCpl.exe]
"Acer Tour"="" []
"WarReg_PopUp"="C:\Acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 20:48]
"eRecoveryService"="" []
"Acer Tour Reminder"="C:\Acer\AcerTour\Reminder.exe" [2007-02-15 17:39]
"Apanel"="C:\ACERSW\config\NewSetApanel.cmd" []
"SystrayORAHSS"="C:\Program Files\Orange HSS\Systray\SystrayApp.exe" [2007-07-24 19:55]
"ORAHSSSessionManager"="C:\Program Files\Orange HSS\SessionManager\SessionManager.exe" [2007-07-24 19:03]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 15:57]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-08-08 09:25]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 12:06]
"MSConfig"="C:\Windows\system32\msconfig.exe" [2006-11-02 10:45]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-08-07 01:05]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 11:35]
"Acer Tour Reminder"="C:\Acer\AcerTour\Reminder.exe" [2007-02-15 17:39]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2007-05-06 20:28:40]
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 03:44:06]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
C:\Program Files\Windows Defender\MSASCui.exe -hide
R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys
R2 int15;int15;\??\C:\Acer\Empowering Technology\eRecovery\int15.sys
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3;C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys
R3 PCASp50;PCASp50 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCASp50.sys
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys
S3 PCAMp50;PCAMp50 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCAMp50.sys
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{06955f46-9bf0-11dc-b961-001c252f163f}]
\shell\Auto\command - ufpyzntyt.exe
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL ufpyzntyt.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0c7c596-92d8-11dc-b60e-001c252f163f}]
\shell\Auto\command - ufpyzntyt.exe
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL K:\
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e44ef4fa-9abc-11dc-a4de-001c252f163f}]
\shell\Auto\command - F:\hhbgkpudh.exe
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\hhbgkpudh.exe
.
**************************************************************************
catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-08 22:57:19
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-08 22:59:23
C:\ComboFix2.txt ... 2007-12-08 13:19
.
--- E O F --- -
Contributeurselectionne ceci
registry::
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{06955f 46-9bf0-11dc-b961-001c252f163f}]
\shell\Auto\command - ufpyzntyt.exe
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL ufpyzntyt.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0c7c5 96-92d8-11dc-b60e-001c252f163f}]
\shell\Auto\command - ufpyzntyt.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e44ef4 fa-9abc-11dc-a4de-001c252f163f}]
\shell\Auto\command - F:\hhbgkpudh.exe
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\hhbgkpudh.exe
* Copie le texte sélectionné (CTRL+C).
* Ouvre le bloc-notes (programme>Accessoires >bloc-notes).
* Colle le texte copié dans ce bloc-notes (CTRL+V).
* Sauvegarde ce fichier sous le nom de CFScript.txt
* Fais un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe
* Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
* Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises : c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
* Une fois le scan achevé, un rapport va s'afficher : Poste son contenu.
* Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
@+ -
merci d'avance
-
Contributeurj'analyse ton rapport
et je te répond un peu plus tard
@+ -
ComboFix 07-12-08.1 - bizoux 2007-12-08 13:12:00.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.116 [GMT 1:00]
Running from: C:\Users\bizoux\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((( Fichiers créés 2007-11-08 to 2007-12-08 ))))))))))))))))))))))))))))))))))))
.
2007-12-08 12:30 . 2007-12-08 12:30 <REP> d-------- C:\Program Files\test.exe
2007-12-08 12:29 . 2007-12-08 12:29 <REP> d-------- C:\Program Files\Trend Micro
2007-12-08 10:47 . 2007-12-08 10:47 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Media Player Classic
2007-12-08 10:33 . 2007-12-08 10:36 <REP> d-------- C:\Program Files\a-squared FreeTROJAN
2007-12-08 10:27 . 2007-12-08 10:27 6,479,600 --a------ C:\Users\bizoux\sunbelt-personal-firewall.exe
2007-12-08 10:06 . 2007-12-08 12:24 <REP> d-------- C:\Program Files\Navilog1
2007-12-08 10:04 . 2007-12-08 10:04 557,992 --a------ C:\Users\bizoux\Navilog1.exe
2007-12-02 20:17 . 2007-12-02 20:22 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Winamp
2007-12-02 20:17 . 2007-12-02 20:18 <REP> d-------- C:\Program Files\Winamp
2007-12-02 20:17 . 2007-03-08 00:51 129,784 --------- C:\Windows\System32\pxafs.dll
2007-11-30 20:44 . 2007-11-30 20:44 <REP> d-------- C:\Users\bizoux\AppData\Roaming\eSobi
2007-11-25 14:54 . 2007-11-25 14:54 <REP> d-------- C:\Users\All Users\LightScribe
2007-11-25 14:54 . 2007-11-25 14:54 <REP> d-------- C:\ProgramData\LightScribe
2007-11-24 19:40 . 2007-09-06 12:00 95,608 --a------ C:\Windows\System32\AvastSS.scr
2007-11-24 19:40 . 2007-09-06 12:02 42,912 --a------ C:\Windows\System32\drivers\aswTdi.sys
2007-11-24 19:40 . 2007-09-06 12:03 23,152 --a------ C:\Windows\System32\drivers\aswRdr.sys
2007-11-24 19:39 . 2007-11-24 19:39 <REP> d-------- C:\Program Files\Alwil Software
2007-11-24 19:39 . 2007-09-06 12:09 801,144 --a------ C:\Windows\System32\aswBoot.exe
2007-11-24 19:39 . 2004-01-09 11:13 380,928 --a------ C:\Windows\System32\actskin4.ocx
2007-11-24 19:39 . 2007-09-06 12:02 45,648 --a------ C:\Windows\System32\drivers\aswMonFlt.sys
2007-11-24 17:06 . 2006-10-05 03:42 2,560 --------- C:\Windows\System32\drivers\cdralw2k.sys
2007-11-24 17:06 . 2006-10-05 03:42 2,432 --------- C:\Windows\System32\drivers\cdr4_xp.sys
2007-11-24 17:05 . 2007-11-24 17:06 <REP> d-------- C:\Program Files\Picasa2
2007-11-24 17:05 . 2007-11-24 17:05 <REP> d-------- C:\Program Files\Google
2007-11-24 16:29 . 2007-11-24 17:25 <REP> d-------- C:\Program Files\BitComet
2007-11-24 16:26 . 2007-11-24 16:26 <REP> d-------- C:\Program Files\CCleaner
2007-11-24 16:25 . 2007-11-24 16:25 <REP> d-------- C:\Program Files\RegCleaner
2007-11-22 22:08 . 2007-11-22 22:10 <REP> d-------- C:\Program Files\Spyware-Secure
2007-11-19 19:50 . 2007-11-19 19:50 <REP> d-------- C:\Program Files\ARCHPR
2007-11-19 19:50 . 2007-11-19 19:53 1,201 --a------ C:\Windows\ARCHPR.INI
2007-11-19 19:30 . 2007-11-19 19:30 <REP> d-------- C:\HiTRUSTDrive
2007-11-18 21:30 . 2007-11-18 21:30 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Nero
2007-11-18 21:21 . 2007-11-18 21:21 <REP> d-------- C:\Users\All Users\Nero
2007-11-18 21:21 . 2007-11-18 21:21 <REP> d-------- C:\ProgramData\Nero
2007-11-18 21:21 . 2007-11-18 21:21 <REP> d-------- C:\Program Files\Nero
2007-11-18 21:21 . 2007-11-18 21:25 <REP> d-------- C:\Program Files\Common Files\Nero
2007-11-17 13:14 . 2006-04-05 02:05 73,216 --a------ C:\Windows\System32\E_FLBBVE.DLL
2007-11-17 13:14 . 2005-04-11 02:01 62,976 --a------ C:\Windows\System32\E_FD4BBVE.DLL
2007-11-17 13:10 . 2004-09-10 20:12 49,152 --a------ C:\Windows\System32\E_DCINST.DLL
2007-11-17 13:08 . 2007-11-17 13:12 <REP> d-------- C:\Users\All Users\EPSON
2007-11-17 13:08 . 2007-11-17 13:12 <REP> d-------- C:\ProgramData\EPSON
2007-11-17 12:39 . 2007-11-17 13:15 <REP> d-------- C:\Program Files\epson
2007-11-17 12:39 . 2006-03-20 00:00 63,488 --a------ C:\Windows\System32\escwiad.dll
2007-11-17 12:39 . 2007-11-17 12:39 25 --a------ C:\Windows\CDE DX5000EFDG.ini
2007-11-16 22:11 . 2007-11-16 22:11 <REP> d-------- C:\Users\bizoux\AppData\Roaming\vlc
2007-11-16 22:04 . 2007-11-16 22:04 <REP> d-------- C:\Program Files\K-Lite Codec Pack
2007-11-16 22:03 . 2007-11-16 22:03 <REP> d-------- C:\Program Files\VideoLAN
2007-11-15 23:44 . 2007-11-15 23:45 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Creative
2007-11-15 23:41 . 2000-05-22 09:58 647,872 --------- C:\Windows\System32\Mscomct2.ocx
2007-11-15 23:41 . 1999-10-10 18:00 41,984 --------- C:\Windows\Ctregrun.exe
2007-11-15 23:40 . 2007-11-30 20:43 <REP> d-------- C:\Program Files\Audible
2007-11-15 23:40 . 2001-08-17 22:43 24,576 --------- C:\Windows\System32\msxml3a.dll
2007-11-15 23:37 . 1999-12-12 18:01 44,032 --------- C:\Windows\System32\CTSVCCDA.EXE
2007-11-15 23:37 . 1999-11-17 18:00 25,088 --------- C:\Windows\System32\CTSVCCTL.EXE
2007-11-15 23:36 . 2007-11-15 23:39 <REP> d--h----- C:\Program Files\Creative Installation Information
2007-11-15 23:36 . 2007-11-15 23:36 <REP> d-------- C:\Program Files\Common Files\Creative
2007-11-15 23:35 . 2007-11-15 23:35 <REP> d-------- C:\Users\All Users\Creative
2007-11-15 23:35 . 2007-11-15 23:35 <REP> d-------- C:\ProgramData\Creative
2007-11-15 23:33 . 2007-11-15 23:41 <REP> d-------- C:\Program Files\Creative
2007-11-15 23:24 . 2007-11-15 23:24 <REP> d-------- C:\Users\bizoux\AppData\Roaming\CyberLink
2007-11-14 22:45 . 2007-11-14 22:45 <REP> d-------- C:\Users\bizoux\AppData\Roaming\AdobeUM
2007-11-14 21:59 . 2007-12-08 13:16 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Azureus
2007-11-14 21:53 . 2007-09-24 23:31 69,632 --a------ C:\Windows\System32\javacpl.cpl
2007-11-14 21:52 . 2007-11-14 21:53 <REP> d-------- C:\Program Files\Java
2007-11-14 21:51 . 2007-11-14 21:51 <REP> d-------- C:\Program Files\Common Files\Java
2007-11-14 21:48 . 2007-11-14 21:48 <REP> d-------- C:\Program Files\Azureus
2007-11-14 19:53 . 2007-11-14 19:53 <REP> d-------- C:\Users\All Users\Yahoo! Companion
2007-11-14 19:53 . 2007-11-14 19:53 <REP> d-------- C:\ProgramData\Yahoo! Companion
2007-11-14 08:25 . 2007-11-14 08:25 205,824 --a------ C:\Windows\System32\msoeacct.dll
2007-11-14 08:25 . 2007-11-14 08:25 87,040 --a------ C:\Windows\System32\msoert2.dll
2007-11-14 08:25 . 2007-11-14 08:25 39,424 --a------ C:\Windows\System32\ACCTRES.dll
2007-11-14 08:24 . 2007-11-14 08:24 376,320 --a------ C:\Windows\System32\winsrv.dll
2007-11-14 08:24 . 2007-11-14 08:24 49,664 --a------ C:\Windows\System32\csrsrv.dll
2007-11-14 08:22 . 2007-11-14 08:22 414,208 --a------ C:\Windows\System32\msscp.dll
2007-11-14 08:22 . 2007-11-14 08:22 2,048 --a------ C:\Windows\System32\tzres.dll
2007-11-14 08:21 . 2007-11-14 08:21 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-11-14 08:21 . 2007-11-14 08:21 396,800 --a------ C:\Windows\System32\MPSSVC.dll
2007-11-14 08:21 . 2007-11-14 08:21 392,192 --a------ C:\Windows\System32\FirewallAPI.dll
2007-11-14 08:21 . 2007-11-14 08:21 178,688 --a------ C:\Windows\System32\iphlpsvc.dll
2007-11-14 08:21 . 2007-11-14 08:21 86,016 --a------ C:\Windows\System32\icfupgd.dll
2007-11-14 08:21 . 2007-11-14 08:21 63,488 --a------ C:\Windows\System32\drivers\mpsdrv.sys
2007-11-14 08:21 . 2007-11-14 08:21 61,952 --a------ C:\Windows\System32\cmifw.dll
2007-11-14 08:21 . 2007-11-14 08:21 23,040 --a------ C:\Windows\System32\drivers\tunnel.sys
2007-11-14 08:21 . 2007-11-14 08:21 16,896 --a------ C:\Windows\System32\wfapigp.dll
2007-11-14 08:21 . 2007-11-14 08:21 15,360 --a------ C:\Windows\System32\drivers\TUNMP.SYS
2007-11-14 08:20 . 2007-11-14 08:20 8,147,968 --a------ C:\Windows\System32\wmploc.DLL
2007-11-14 08:20 . 2007-11-14 08:20 1,191,936 --a------ C:\Windows\System32\msxml3.dll
2007-11-14 08:20 . 2007-11-14 08:20 7,680 --a------ C:\Windows\System32\spwmp.dll
2007-11-14 08:20 . 2007-11-14 08:20 4,096 --a------ C:\Windows\System32\msdxm.ocx
2007-11-14 08:20 . 2007-11-14 08:20 4,096 --a------ C:\Windows\System32\dxmasf.dll
2007-11-14 08:20 . 2007-11-14 08:20 2,048 --a------ C:\Windows\System32\msxml3r.dll
2007-11-14 08:19 . 2007-11-14 08:19 1,383,424 --a------ C:\Windows\System32\mshtml.tlb
2007-11-14 08:17 . 2007-11-14 08:17 1,335,296 --a------ C:\Windows\System32\msxml6.dll
2007-11-14 08:17 . 2007-11-14 08:17 737,792 --a------ C:\Windows\System32\inetcomm.dll
2007-11-14 08:17 . 2007-11-14 08:17 84,480 --a------ C:\Windows\System32\INETRES.dll
2007-11-14 08:17 . 2007-11-14 08:17 2,048 --a------ C:\Windows\System32\msxml6r.dll
2007-11-14 08:16 . 2007-11-14 08:16 788,992 --a------ C:\Windows\System32\rpcrt4.dll
2007-11-14 08:16 . 2007-11-14 08:16 152,576 --a------ C:\Windows\System32\imagehlp.dll
2007-11-14 08:16 . 2007-11-14 08:16 12,800 --a------ C:\Windows\System32\drivers\fs_rec.sys
2007-11-14 08:16 . 2007-11-14 08:16 5,120 --a------ C:\Windows\System32\wmi.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-02 18:38 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-01 18:04 --------- d-----w C:\Program Files\Common Files\NewTech Infosystems
2007-11-30 19:46 --------- d-----w C:\Program Files\eSobi
2007-11-30 19:43 --------- d-----w C:\ProgramData\eSobi
2007-11-18 10:28 --------- d-----w C:\Program Files\Acer Arcade Live
2007-11-18 10:23 --------- d-----w C:\ProgramData\CyberLink
2007-11-14 17:54 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-11-14 17:53 --------- d-----w C:\ProgramData\Symantec
2007-11-14 07:31 --------- d-----w C:\Program Files\Windows Mail
2007-11-14 07:25 --------- d-----w C:\ProgramData\Microsoft Help
2007-11-14 07:18 56,320 ----a-w C:\Windows\System32\iesetup.dll
2007-11-14 07:18 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2007-11-14 07:18 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2007-11-13 22:05 --------- d-sh--w C:\ProgramData\Modèles
2007-11-13 22:05 --------- d-sh--w C:\ProgramData\Menu Démarrer
2007-11-13 22:05 --------- d-sh--w C:\ProgramData\Favoris
2007-11-13 22:05 --------- d-sh--w C:\ProgramData\Bureau
2007-11-13 22:05 --------- d-sh--w C:\Program Files\Fichiers communs
2007-10-18 10:31 51,224 ----a-w C:\Windows\System32\sirenacm.dll
2007-09-28 17:07 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll
2007-09-28 17:05 81,920 ----a-w C:\Windows\System32\dpl100.dll
2007-09-28 17:05 739,840 ----a-w C:\Windows\System32\divx.dll
2006-11-02 12:50 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2006-11-02 13:35]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-23 12:04 C:\Windows\RtHDVCpl.exe]
"Acer Tour"="" []
"WarReg_PopUp"="C:\Acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 20:48]
"eRecoveryService"="" []
"Acer Tour Reminder"="C:\Acer\AcerTour\Reminder.exe" [2007-02-15 17:39]
"Apanel"="C:\ACERSW\config\NewSetApanel.cmd" []
"SystrayORAHSS"="C:\Program Files\Orange HSS\Systray\SystrayApp.exe" [2007-07-24 19:55]
"ORAHSSSessionManager"="C:\Program Files\Orange HSS\SessionManager\SessionManager.exe" [2007-07-24 19:03]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 15:57]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-08-08 09:25]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 12:06]
"MSConfig"="C:\Windows\system32\msconfig.exe" [2006-11-02 10:45]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 11:35]
"Acer Tour Reminder"="C:\Acer\AcerTour\Reminder.exe" [2007-02-15 17:39]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2007-05-06 20:28:40]
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 03:44:06]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
C:\Program Files\Windows Defender\MSASCui.exe -hide
R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys
R2 int15;int15;\??\C:\Acer\Empowering Technology\eRecovery\int15.sys
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3;C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys
R3 PCASp50;PCASp50 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCASp50.sys
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys
S3 PCAMp50;PCAMp50 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCAMp50.sys
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{06955f46-9bf0-11dc-b961-001c252f163f}]
\shell\Auto\command - ufpyzntyt.exe
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL ufpyzntyt.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0c7c596-92d8-11dc-b60e-001c252f163f}]
\shell\Auto\command - ufpyzntyt.exe
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL K:\
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e44ef4fa-9abc-11dc-a4de-001c252f163f}]
\shell\Auto\command - F:\hhbgkpudh.exe
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\hhbgkpudh.exe
*Newly Created Service* - PROCEXP90
voila le résultat
.
**************************************************************************
catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-08 13:16:12
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-08 13:19:22
.
--- E O F --- -
ok
-
ContributeurTélécharge Combofix sUBs : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
et sauvegarde le sur ton bureau et pas ailleurs!
Double-clic sur combofix,
Attends que combofix ait terminé, un rapport sera créé. Poste le rapport.
- 1
- 2