Sos spyware secure
Bonjour, g fait analyse ac navilog et il me demand de transmetre le appor et apres que faire vp
merci pr vs reponses
Search Navipromo version 3.3.6 commencé le 08/12/2007 à 10:08:57,34
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!
Outil exécuté depuis C:\Program Files\navilog1
Mise à jour le 14.11.2007 à 18h00 par IL-MAFIOSO
Microsoft Windows Vista 6.0.6000
Internet Explorer : 7.0.6000.16546
*** Recherche Programmes installés ***
*** Recherche dossiers dans C:\Windows ***
*** Recherche dossiers dans C:\Program Files ***
*** Recherche dossiers dans C:\ProgramData ***
*** Recherche dossiers dans C:\ProgramData\Microsoft\Windows\Start Menu\Programs ***
*** Recherche dossiers dans C:\USERS\BIZOUX\APPDATA\ROAMING\MICROS~1\WINDOWS\STARTM~1\PROGRAMS ***
*** Recherche dossiers dans C:\Users\bizoux\AppData\Local\virtualstore\Program Files ***
*** Recherche dossiers dans C:\Users\bizoux\AppData\Roaming ***
*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net
Fichier(s) caché(s) :
C:\Users\bizoux\AppData\Local\zfsgshlekx.dat
C:\Users\bizoux\AppData\Local\zfsgshlekx.exe
C:\Users\bizoux\AppData\Local\zfsgshlekx_nav.dat
C:\Users\bizoux\AppData\Local\zfsgshlekx_navps.dat
Processus caché(s) :
C:\Users\bizoux\AppData\Local\zfsgshlekx.exe
*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!
* Recherche dans C:\Windows\system32 *
* Recherche dans C:\Users\bizoux\AppData\Local\Microsoft *
* Recherche dans C:\Users\bizoux\AppData\Local\virtualstore\windows\system32 *
* Recherche dans C:\Users\bizoux\AppData\Local *
Fichiers trouvés :
zfsgshlekx.exe trouvé !
zfsgshlekx.dat trouvé !
zfsgshlekx_nav.dat trouvé !
zfsgshlekx_navps.dat trouvé !
*** Recherche fichiers ***
C:\Windows\system32\nvs2.inf trouvé !
*** Recherche clés spécifiques dans le Registre ***
HKEY_CURRENT_USER\Software\Lanconfig trouvé !
*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Recherche fichiers connus:
2)Recherche Heuristique :
C:\Users\bizoux\AppData\Local\zfsgshlekx.dat trouvé !
C:\Users\bizoux\AppData\Local\zfsgshlekx_nav.dat trouvé !
3)Recherche Certificats :
Certificat Egroup trouvé !
*** Analyse terminée le 08/12/2007 à 10:10:11,48 ***
merci pr vs reponses
Search Navipromo version 3.3.6 commencé le 08/12/2007 à 10:08:57,34
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!
Outil exécuté depuis C:\Program Files\navilog1
Mise à jour le 14.11.2007 à 18h00 par IL-MAFIOSO
Microsoft Windows Vista 6.0.6000
Internet Explorer : 7.0.6000.16546
*** Recherche Programmes installés ***
*** Recherche dossiers dans C:\Windows ***
*** Recherche dossiers dans C:\Program Files ***
*** Recherche dossiers dans C:\ProgramData ***
*** Recherche dossiers dans C:\ProgramData\Microsoft\Windows\Start Menu\Programs ***
*** Recherche dossiers dans C:\USERS\BIZOUX\APPDATA\ROAMING\MICROS~1\WINDOWS\STARTM~1\PROGRAMS ***
*** Recherche dossiers dans C:\Users\bizoux\AppData\Local\virtualstore\Program Files ***
*** Recherche dossiers dans C:\Users\bizoux\AppData\Roaming ***
*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net
Fichier(s) caché(s) :
C:\Users\bizoux\AppData\Local\zfsgshlekx.dat
C:\Users\bizoux\AppData\Local\zfsgshlekx.exe
C:\Users\bizoux\AppData\Local\zfsgshlekx_nav.dat
C:\Users\bizoux\AppData\Local\zfsgshlekx_navps.dat
Processus caché(s) :
C:\Users\bizoux\AppData\Local\zfsgshlekx.exe
*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!
* Recherche dans C:\Windows\system32 *
* Recherche dans C:\Users\bizoux\AppData\Local\Microsoft *
* Recherche dans C:\Users\bizoux\AppData\Local\virtualstore\windows\system32 *
* Recherche dans C:\Users\bizoux\AppData\Local *
Fichiers trouvés :
zfsgshlekx.exe trouvé !
zfsgshlekx.dat trouvé !
zfsgshlekx_nav.dat trouvé !
zfsgshlekx_navps.dat trouvé !
*** Recherche fichiers ***
C:\Windows\system32\nvs2.inf trouvé !
*** Recherche clés spécifiques dans le Registre ***
HKEY_CURRENT_USER\Software\Lanconfig trouvé !
*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Recherche fichiers connus:
2)Recherche Heuristique :
C:\Users\bizoux\AppData\Local\zfsgshlekx.dat trouvé !
C:\Users\bizoux\AppData\Local\zfsgshlekx_nav.dat trouvé !
3)Recherche Certificats :
Certificat Egroup trouvé !
*** Analyse terminée le 08/12/2007 à 10:10:11,48 ***
Configuration: Windows Vista Internet Explorer 7.0
25 réponses
-
Contributeuroui en effet il faudra reprendre le rapport combo
-
citation
selectionne ceci
registry::
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{06955f 46-9bf0-11dc-b961-001c252f163f}]
\shell\Auto\command - ufpyzntyt.exe
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL ufpyzntyt.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0c7c5 96-92d8-11dc-b60e-001c252f163f}]
\shell\Auto\command - ufpyzntyt.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e44ef4 fa-9abc-11dc-a4de-001c252f163f}]
\shell\Auto\command - F:\hhbgkpudh.exe
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\hhbgkpudh.exe
pas de commande donc ça peut pas marcher
[-HKEY_CURRENT_USER..... -
merci
-
Contributeurhttps://www.bitdefender.fr/
voici le lien -
hello
j'ai viré bitdefender
souci!!! -
Contributeurressaye quand même bitdefender
normalement il passe avec vista
@+ -
Contributeurok je cherche un scan valable pour vista
@+ -
CA NE MARCHE PAS CAR KASPERSKY N'EST PAS CONFIGURé POUR VISTA! Par contre si tu as autrre chose jsui open
-
Contributeuressaye ici
https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
tuto
http://www.infos-du-net.com/forum/267224-11-scan-ligne-kaspersky -
il me met scan failed impossible d'analyser l'ordinateur contre les virus
-
Contributeurton anti virus est avast
le scan en ligne de bitdefender
n'est en aucun cas gênant avec ton anti virus
donc il faut faire le scan
@+ -
j'ai désinstaler bit defender car j'ai avast?que faire
-
ContributeurFais un scan antivirus en ligne avec Internet Explorer
https://www.bitdefender.fr/
et copie colle le résultat ici
= En bas, à gauche de la fenêtre, clique sur BitDefender SCAN ONLINE
= Dans la nouvelle fenêtre, clique sur I agree
= La fenêtre change encore, clique sur Click here to scan
= Les signatures se chargent, etc.
tuto en image
http://pageperso.aol.fr/rginformatique/mapage/defender.htm
et
reposte un nouveau rapport hijackthis -
ComboFix 07-12-08.1 - bizoux 2007-12-08 22:52:15.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.68 [GMT 1:00]
Running from: C:\Users\bizoux\Desktop\ComboFix.exe
Command switches used :: C:\Users\bizoux\Documents\CFScript.txt
* Created a new restore point
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
K:\Autorun.inf
.
((((((((((((((((((((((((((((( Fichiers créés 2007-11-08 to 2007-12-08 ))))))))))))))))))))))))))))))))))))
.
2007-12-08 14:19 . 2007-12-08 14:19 <REP> d-------- C:\Program Files\PowerISO
2007-12-08 12:30 . 2007-12-08 12:30 <REP> d-------- C:\Program Files\test.exe
2007-12-08 12:29 . 2007-12-08 12:29 <REP> d-------- C:\Program Files\Trend Micro
2007-12-08 10:47 . 2007-12-08 10:47 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Media Player Classic
2007-12-08 10:33 . 2007-12-08 10:36 <REP> d-------- C:\Program Files\a-squared FreeTROJAN
2007-12-08 10:27 . 2007-12-08 10:27 6,479,600 --a------ C:\Users\bizoux\sunbelt-personal-firewall.exe
2007-12-08 10:06 . 2007-12-08 12:24 <REP> d-------- C:\Program Files\Navilog1
2007-12-08 10:04 . 2007-12-08 10:04 557,992 --a------ C:\Users\bizoux\Navilog1.exe
2007-12-02 20:17 . 2007-12-02 20:22 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Winamp
2007-12-02 20:17 . 2007-12-02 20:18 <REP> d-------- C:\Program Files\Winamp
2007-12-02 20:17 . 2007-03-08 00:51 129,784 --------- C:\Windows\System32\pxafs.dll
2007-11-30 20:44 . 2007-11-30 20:44 <REP> d-------- C:\Users\bizoux\AppData\Roaming\eSobi
2007-11-25 14:54 . 2007-11-25 14:54 <REP> d-------- C:\Users\All Users\LightScribe
2007-11-25 14:54 . 2007-11-25 14:54 <REP> d-------- C:\ProgramData\LightScribe
2007-11-24 19:40 . 2007-09-06 12:00 95,608 --a------ C:\Windows\System32\AvastSS.scr
2007-11-24 19:40 . 2007-09-06 12:02 42,912 --a------ C:\Windows\System32\drivers\aswTdi.sys
2007-11-24 19:40 . 2007-09-06 12:03 23,152 --a------ C:\Windows\System32\drivers\aswRdr.sys
2007-11-24 19:39 . 2007-11-24 19:39 <REP> d-------- C:\Program Files\Alwil Software
2007-11-24 19:39 . 2007-09-06 12:09 801,144 --a------ C:\Windows\System32\aswBoot.exe
2007-11-24 19:39 . 2004-01-09 11:13 380,928 --a------ C:\Windows\System32\actskin4.ocx
2007-11-24 19:39 . 2007-09-06 12:02 45,648 --a------ C:\Windows\System32\drivers\aswMonFlt.sys
2007-11-24 17:06 . 2006-10-05 03:42 2,560 --------- C:\Windows\System32\drivers\cdralw2k.sys
2007-11-24 17:06 . 2006-10-05 03:42 2,432 --------- C:\Windows\System32\drivers\cdr4_xp.sys
2007-11-24 17:05 . 2007-11-24 17:06 <REP> d-------- C:\Program Files\Picasa2
2007-11-24 17:05 . 2007-11-24 17:05 <REP> d-------- C:\Program Files\Google
2007-11-24 16:29 . 2007-11-24 17:25 <REP> d-------- C:\Program Files\BitComet
2007-11-24 16:26 . 2007-11-24 16:26 <REP> d-------- C:\Program Files\CCleaner
2007-11-24 16:25 . 2007-11-24 16:25 <REP> d-------- C:\Program Files\RegCleaner
2007-11-22 22:08 . 2007-11-22 22:10 <REP> d-------- C:\Program Files\Spyware-Secure
2007-11-19 19:50 . 2007-11-19 19:50 <REP> d-------- C:\Program Files\ARCHPR
2007-11-19 19:50 . 2007-11-19 19:53 1,201 --a------ C:\Windows\ARCHPR.INI
2007-11-19 19:30 . 2007-11-19 19:30 <REP> d-------- C:\HiTRUSTDrive
2007-11-18 21:30 . 2007-11-18 21:30 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Nero
2007-11-18 21:21 . 2007-11-18 21:21 <REP> d-------- C:\Users\All Users\Nero
2007-11-18 21:21 . 2007-11-18 21:21 <REP> d-------- C:\ProgramData\Nero
2007-11-18 21:21 . 2007-11-18 21:21 <REP> d-------- C:\Program Files\Nero
2007-11-18 21:21 . 2007-11-18 21:25 <REP> d-------- C:\Program Files\Common Files\Nero
2007-11-17 13:14 . 2006-04-05 02:05 73,216 --a------ C:\Windows\System32\E_FLBBVE.DLL
2007-11-17 13:14 . 2005-04-11 02:01 62,976 --a------ C:\Windows\System32\E_FD4BBVE.DLL
2007-11-17 13:10 . 2004-09-10 20:12 49,152 --a------ C:\Windows\System32\E_DCINST.DLL
2007-11-17 13:08 . 2007-11-17 13:12 <REP> d-------- C:\Users\All Users\EPSON
2007-11-17 13:08 . 2007-11-17 13:12 <REP> d-------- C:\ProgramData\EPSON
2007-11-17 12:39 . 2007-11-17 13:15 <REP> d-------- C:\Program Files\epson
2007-11-17 12:39 . 2006-03-20 00:00 63,488 --a------ C:\Windows\System32\escwiad.dll
2007-11-17 12:39 . 2007-11-17 12:39 25 --a------ C:\Windows\CDE DX5000EFDG.ini
2007-11-16 22:11 . 2007-11-16 22:11 <REP> d-------- C:\Users\bizoux\AppData\Roaming\vlc
2007-11-16 22:04 . 2007-11-16 22:04 <REP> d-------- C:\Program Files\K-Lite Codec Pack
2007-11-16 22:03 . 2007-11-16 22:03 <REP> d-------- C:\Program Files\VideoLAN
2007-11-15 23:44 . 2007-11-15 23:45 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Creative
2007-11-15 23:41 . 2000-05-22 09:58 647,872 --------- C:\Windows\System32\Mscomct2.ocx
2007-11-15 23:41 . 1999-10-10 18:00 41,984 --------- C:\Windows\Ctregrun.exe
2007-11-15 23:40 . 2007-11-30 20:43 <REP> d-------- C:\Program Files\Audible
2007-11-15 23:40 . 2001-08-17 22:43 24,576 --------- C:\Windows\System32\msxml3a.dll
2007-11-15 23:37 . 1999-12-12 18:01 44,032 --------- C:\Windows\System32\CTSVCCDA.EXE
2007-11-15 23:37 . 1999-11-17 18:00 25,088 --------- C:\Windows\System32\CTSVCCTL.EXE
2007-11-15 23:36 . 2007-11-15 23:39 <REP> d--h----- C:\Program Files\Creative Installation Information
2007-11-15 23:36 . 2007-11-15 23:36 <REP> d-------- C:\Program Files\Common Files\Creative
2007-11-15 23:35 . 2007-11-15 23:35 <REP> d-------- C:\Users\All Users\Creative
2007-11-15 23:35 . 2007-11-15 23:35 <REP> d-------- C:\ProgramData\Creative
2007-11-15 23:33 . 2007-11-15 23:41 <REP> d-------- C:\Program Files\Creative
2007-11-15 23:24 . 2007-11-15 23:24 <REP> d-------- C:\Users\bizoux\AppData\Roaming\CyberLink
2007-11-14 22:45 . 2007-11-14 22:45 <REP> d-------- C:\Users\bizoux\AppData\Roaming\AdobeUM
2007-11-14 21:59 . 2007-12-08 22:57 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Azureus
2007-11-14 21:53 . 2007-09-24 23:31 69,632 --a------ C:\Windows\System32\javacpl.cpl
2007-11-14 21:52 . 2007-11-14 21:53 <REP> d-------- C:\Program Files\Java
2007-11-14 21:51 . 2007-11-14 21:51 <REP> d-------- C:\Program Files\Common Files\Java
2007-11-14 21:48 . 2007-11-14 21:48 <REP> d-------- C:\Program Files\Azureus
2007-11-14 19:53 . 2007-11-14 19:53 <REP> d-------- C:\Users\All Users\Yahoo! Companion
2007-11-14 19:53 . 2007-11-14 19:53 <REP> d-------- C:\ProgramData\Yahoo! Companion
2007-11-14 08:25 . 2007-11-14 08:25 205,824 --a------ C:\Windows\System32\msoeacct.dll
2007-11-14 08:25 . 2007-11-14 08:25 87,040 --a------ C:\Windows\System32\msoert2.dll
2007-11-14 08:25 . 2007-11-14 08:25 39,424 --a------ C:\Windows\System32\ACCTRES.dll
2007-11-14 08:24 . 2007-11-14 08:24 376,320 --a------ C:\Windows\System32\winsrv.dll
2007-11-14 08:24 . 2007-11-14 08:24 49,664 --a------ C:\Windows\System32\csrsrv.dll
2007-11-14 08:22 . 2007-11-14 08:22 414,208 --a------ C:\Windows\System32\msscp.dll
2007-11-14 08:22 . 2007-11-14 08:22 2,048 --a------ C:\Windows\System32\tzres.dll
2007-11-14 08:21 . 2007-11-14 08:21 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-11-14 08:21 . 2007-11-14 08:21 396,800 --a------ C:\Windows\System32\MPSSVC.dll
2007-11-14 08:21 . 2007-11-14 08:21 392,192 --a------ C:\Windows\System32\FirewallAPI.dll
2007-11-14 08:21 . 2007-11-14 08:21 178,688 --a------ C:\Windows\System32\iphlpsvc.dll
2007-11-14 08:21 . 2007-11-14 08:21 86,016 --a------ C:\Windows\System32\icfupgd.dll
2007-11-14 08:21 . 2007-11-14 08:21 63,488 --a------ C:\Windows\System32\drivers\mpsdrv.sys
2007-11-14 08:21 . 2007-11-14 08:21 61,952 --a------ C:\Windows\System32\cmifw.dll
2007-11-14 08:21 . 2007-11-14 08:21 23,040 --a------ C:\Windows\System32\drivers\tunnel.sys
2007-11-14 08:21 . 2007-11-14 08:21 16,896 --a------ C:\Windows\System32\wfapigp.dll
2007-11-14 08:21 . 2007-11-14 08:21 15,360 --a------ C:\Windows\System32\drivers\TUNMP.SYS
2007-11-14 08:20 . 2007-11-14 08:20 8,147,968 --a------ C:\Windows\System32\wmploc.DLL
2007-11-14 08:20 . 2007-11-14 08:20 1,191,936 --a------ C:\Windows\System32\msxml3.dll
2007-11-14 08:20 . 2007-11-14 08:20 7,680 --a------ C:\Windows\System32\spwmp.dll
2007-11-14 08:20 . 2007-11-14 08:20 4,096 --a------ C:\Windows\System32\msdxm.ocx
2007-11-14 08:20 . 2007-11-14 08:20 4,096 --a------ C:\Windows\System32\dxmasf.dll
2007-11-14 08:20 . 2007-11-14 08:20 2,048 --a------ C:\Windows\System32\msxml3r.dll
2007-11-14 08:19 . 2007-11-14 08:19 1,383,424 --a------ C:\Windows\System32\mshtml.tlb
2007-11-14 08:17 . 2007-11-14 08:17 1,335,296 --a------ C:\Windows\System32\msxml6.dll
2007-11-14 08:17 . 2007-11-14 08:17 737,792 --a------ C:\Windows\System32\inetcomm.dll
2007-11-14 08:17 . 2007-11-14 08:17 84,480 --a------ C:\Windows\System32\INETRES.dll
2007-11-14 08:17 . 2007-11-14 08:17 2,048 --a------ C:\Windows\System32\msxml6r.dll
2007-11-14 08:16 . 2007-11-14 08:16 788,992 --a------ C:\Windows\System32\rpcrt4.dll
2007-11-14 08:16 . 2007-11-14 08:16 152,576 --a------ C:\Windows\System32\imagehlp.dll
2007-11-14 08:16 . 2007-11-14 08:16 12,800 --a------ C:\Windows\System32\drivers\fs_rec.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-08 16:45 --------- d-----w C:\ProgramData\Microsoft Help
2007-12-02 18:38 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-01 18:04 --------- d-----w C:\Program Files\Common Files\NewTech Infosystems
2007-11-30 19:46 --------- d-----w C:\Program Files\eSobi
2007-11-30 19:43 --------- d-----w C:\ProgramData\eSobi
2007-11-18 10:28 --------- d-----w C:\Program Files\Acer Arcade Live
2007-11-18 10:23 --------- d-----w C:\ProgramData\CyberLink
2007-11-14 17:54 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-11-14 17:53 --------- d-----w C:\ProgramData\Symantec
2007-11-14 07:31 --------- d-----w C:\Program Files\Windows Mail
2007-11-14 07:18 56,320 ----a-w C:\Windows\System32\iesetup.dll
2007-11-14 07:18 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2007-11-14 07:18 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2007-11-13 22:05 --------- d-sh--w C:\ProgramData\Modèles
2007-11-13 22:05 --------- d-sh--w C:\ProgramData\Menu Démarrer
2007-11-13 22:05 --------- d-sh--w C:\ProgramData\Favoris
2007-11-13 22:05 --------- d-sh--w C:\ProgramData\Bureau
2007-11-13 22:05 --------- d-sh--w C:\Program Files\Fichiers communs
2007-10-18 10:31 51,224 ----a-w C:\Windows\System32\sirenacm.dll
2007-09-28 17:07 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll
2007-09-28 17:05 81,920 ----a-w C:\Windows\System32\dpl100.dll
2007-09-28 17:05 739,840 ----a-w C:\Windows\System32\divx.dll
2006-11-02 12:50 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((( snapshot@2007-12-08_13.16.48,36 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-12-08 11:23:34 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2007-12-08 15:13:21 67,584 --s-a-w C:\Windows\bootstat.dat
- 2007-12-08 11:25:11 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2007-12-08 15:15:57 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2007-12-08 15:15:57 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2007-12-08 11:25:16 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2007-12-08 15:15:52 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2007-12-08 15:15:52 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2007-12-08 11:24:05 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2007-12-08 19:30:29 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2007-12-08 11:24:05 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-08 19:30:29 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-12-08 11:24:05 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-12-08 19:30:29 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-08-07 00:15:07 33,052 ----a-w C:\Windows\System32\drivers\scdemu.sys
- 2007-12-08 08:57:57 103,726 ----a-w C:\Windows\System32\perfc009.dat
+ 2007-12-08 14:06:51 103,726 ----a-w C:\Windows\System32\perfc009.dat
- 2007-12-08 08:57:57 117,366 ----a-w C:\Windows\System32\perfc00C.dat
+ 2007-12-08 14:06:52 117,366 ----a-w C:\Windows\System32\perfc00C.dat
- 2007-12-08 08:57:57 609,944 ----a-w C:\Windows\System32\perfh009.dat
+ 2007-12-08 14:06:52 609,944 ----a-w C:\Windows\System32\perfh009.dat
- 2007-12-08 08:57:58 690,594 ----a-w C:\Windows\System32\perfh00C.dat
+ 2007-12-08 14:06:52 690,594 ----a-w C:\Windows\System32\perfh00C.dat
- 2007-12-08 11:25:32 6,422 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-37221999-100896607-4100886726-1000_UserData.bin
+ 2007-12-08 15:16:56 6,462 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-37221999-100896607-4100886726-1000_UserData.bin
- 2007-12-08 11:25:32 52,574 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2007-12-08 15:16:54 52,756 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2007-12-08 11:25:31 46,522 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2007-12-08 13:26:19 47,010 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2006-11-02 13:35]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-23 12:04 C:\Windows\RtHDVCpl.exe]
"Acer Tour"="" []
"WarReg_PopUp"="C:\Acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 20:48]
"eRecoveryService"="" []
"Acer Tour Reminder"="C:\Acer\AcerTour\Reminder.exe" [2007-02-15 17:39]
"Apanel"="C:\ACERSW\config\NewSetApanel.cmd" []
"SystrayORAHSS"="C:\Program Files\Orange HSS\Systray\SystrayApp.exe" [2007-07-24 19:55]
"ORAHSSSessionManager"="C:\Program Files\Orange HSS\SessionManager\SessionManager.exe" [2007-07-24 19:03]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 15:57]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-08-08 09:25]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 12:06]
"MSConfig"="C:\Windows\system32\msconfig.exe" [2006-11-02 10:45]
"PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-08-07 01:05]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 11:35]
"Acer Tour Reminder"="C:\Acer\AcerTour\Reminder.exe" [2007-02-15 17:39]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2007-05-06 20:28:40]
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 03:44:06]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
C:\Program Files\Windows Defender\MSASCui.exe -hide
R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys
R2 int15;int15;\??\C:\Acer\Empowering Technology\eRecovery\int15.sys
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3;C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys
R3 PCASp50;PCASp50 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCASp50.sys
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys
S3 PCAMp50;PCAMp50 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCAMp50.sys
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{06955f46-9bf0-11dc-b961-001c252f163f}]
\shell\Auto\command - ufpyzntyt.exe
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL ufpyzntyt.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0c7c596-92d8-11dc-b60e-001c252f163f}]
\shell\Auto\command - ufpyzntyt.exe
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL K:\
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e44ef4fa-9abc-11dc-a4de-001c252f163f}]
\shell\Auto\command - F:\hhbgkpudh.exe
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\hhbgkpudh.exe
.
**************************************************************************
catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-08 22:57:19
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-08 22:59:23
C:\ComboFix2.txt ... 2007-12-08 13:19
.
--- E O F --- -
Contributeurselectionne ceci
registry::
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{06955f 46-9bf0-11dc-b961-001c252f163f}]
\shell\Auto\command - ufpyzntyt.exe
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL ufpyzntyt.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0c7c5 96-92d8-11dc-b60e-001c252f163f}]
\shell\Auto\command - ufpyzntyt.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e44ef4 fa-9abc-11dc-a4de-001c252f163f}]
\shell\Auto\command - F:\hhbgkpudh.exe
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\hhbgkpudh.exe
* Copie le texte sélectionné (CTRL+C).
* Ouvre le bloc-notes (programme>Accessoires >bloc-notes).
* Colle le texte copié dans ce bloc-notes (CTRL+V).
* Sauvegarde ce fichier sous le nom de CFScript.txt
* Fais un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe
* Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
* Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises : c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
* Une fois le scan achevé, un rapport va s'afficher : Poste son contenu.
* Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
@+ -
merci d'avance
-
Contributeurj'analyse ton rapport
et je te répond un peu plus tard
@+ -
ComboFix 07-12-08.1 - bizoux 2007-12-08 13:12:00.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.116 [GMT 1:00]
Running from: C:\Users\bizoux\Desktop\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((( Fichiers créés 2007-11-08 to 2007-12-08 ))))))))))))))))))))))))))))))))))))
.
2007-12-08 12:30 . 2007-12-08 12:30 <REP> d-------- C:\Program Files\test.exe
2007-12-08 12:29 . 2007-12-08 12:29 <REP> d-------- C:\Program Files\Trend Micro
2007-12-08 10:47 . 2007-12-08 10:47 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Media Player Classic
2007-12-08 10:33 . 2007-12-08 10:36 <REP> d-------- C:\Program Files\a-squared FreeTROJAN
2007-12-08 10:27 . 2007-12-08 10:27 6,479,600 --a------ C:\Users\bizoux\sunbelt-personal-firewall.exe
2007-12-08 10:06 . 2007-12-08 12:24 <REP> d-------- C:\Program Files\Navilog1
2007-12-08 10:04 . 2007-12-08 10:04 557,992 --a------ C:\Users\bizoux\Navilog1.exe
2007-12-02 20:17 . 2007-12-02 20:22 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Winamp
2007-12-02 20:17 . 2007-12-02 20:18 <REP> d-------- C:\Program Files\Winamp
2007-12-02 20:17 . 2007-03-08 00:51 129,784 --------- C:\Windows\System32\pxafs.dll
2007-11-30 20:44 . 2007-11-30 20:44 <REP> d-------- C:\Users\bizoux\AppData\Roaming\eSobi
2007-11-25 14:54 . 2007-11-25 14:54 <REP> d-------- C:\Users\All Users\LightScribe
2007-11-25 14:54 . 2007-11-25 14:54 <REP> d-------- C:\ProgramData\LightScribe
2007-11-24 19:40 . 2007-09-06 12:00 95,608 --a------ C:\Windows\System32\AvastSS.scr
2007-11-24 19:40 . 2007-09-06 12:02 42,912 --a------ C:\Windows\System32\drivers\aswTdi.sys
2007-11-24 19:40 . 2007-09-06 12:03 23,152 --a------ C:\Windows\System32\drivers\aswRdr.sys
2007-11-24 19:39 . 2007-11-24 19:39 <REP> d-------- C:\Program Files\Alwil Software
2007-11-24 19:39 . 2007-09-06 12:09 801,144 --a------ C:\Windows\System32\aswBoot.exe
2007-11-24 19:39 . 2004-01-09 11:13 380,928 --a------ C:\Windows\System32\actskin4.ocx
2007-11-24 19:39 . 2007-09-06 12:02 45,648 --a------ C:\Windows\System32\drivers\aswMonFlt.sys
2007-11-24 17:06 . 2006-10-05 03:42 2,560 --------- C:\Windows\System32\drivers\cdralw2k.sys
2007-11-24 17:06 . 2006-10-05 03:42 2,432 --------- C:\Windows\System32\drivers\cdr4_xp.sys
2007-11-24 17:05 . 2007-11-24 17:06 <REP> d-------- C:\Program Files\Picasa2
2007-11-24 17:05 . 2007-11-24 17:05 <REP> d-------- C:\Program Files\Google
2007-11-24 16:29 . 2007-11-24 17:25 <REP> d-------- C:\Program Files\BitComet
2007-11-24 16:26 . 2007-11-24 16:26 <REP> d-------- C:\Program Files\CCleaner
2007-11-24 16:25 . 2007-11-24 16:25 <REP> d-------- C:\Program Files\RegCleaner
2007-11-22 22:08 . 2007-11-22 22:10 <REP> d-------- C:\Program Files\Spyware-Secure
2007-11-19 19:50 . 2007-11-19 19:50 <REP> d-------- C:\Program Files\ARCHPR
2007-11-19 19:50 . 2007-11-19 19:53 1,201 --a------ C:\Windows\ARCHPR.INI
2007-11-19 19:30 . 2007-11-19 19:30 <REP> d-------- C:\HiTRUSTDrive
2007-11-18 21:30 . 2007-11-18 21:30 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Nero
2007-11-18 21:21 . 2007-11-18 21:21 <REP> d-------- C:\Users\All Users\Nero
2007-11-18 21:21 . 2007-11-18 21:21 <REP> d-------- C:\ProgramData\Nero
2007-11-18 21:21 . 2007-11-18 21:21 <REP> d-------- C:\Program Files\Nero
2007-11-18 21:21 . 2007-11-18 21:25 <REP> d-------- C:\Program Files\Common Files\Nero
2007-11-17 13:14 . 2006-04-05 02:05 73,216 --a------ C:\Windows\System32\E_FLBBVE.DLL
2007-11-17 13:14 . 2005-04-11 02:01 62,976 --a------ C:\Windows\System32\E_FD4BBVE.DLL
2007-11-17 13:10 . 2004-09-10 20:12 49,152 --a------ C:\Windows\System32\E_DCINST.DLL
2007-11-17 13:08 . 2007-11-17 13:12 <REP> d-------- C:\Users\All Users\EPSON
2007-11-17 13:08 . 2007-11-17 13:12 <REP> d-------- C:\ProgramData\EPSON
2007-11-17 12:39 . 2007-11-17 13:15 <REP> d-------- C:\Program Files\epson
2007-11-17 12:39 . 2006-03-20 00:00 63,488 --a------ C:\Windows\System32\escwiad.dll
2007-11-17 12:39 . 2007-11-17 12:39 25 --a------ C:\Windows\CDE DX5000EFDG.ini
2007-11-16 22:11 . 2007-11-16 22:11 <REP> d-------- C:\Users\bizoux\AppData\Roaming\vlc
2007-11-16 22:04 . 2007-11-16 22:04 <REP> d-------- C:\Program Files\K-Lite Codec Pack
2007-11-16 22:03 . 2007-11-16 22:03 <REP> d-------- C:\Program Files\VideoLAN
2007-11-15 23:44 . 2007-11-15 23:45 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Creative
2007-11-15 23:41 . 2000-05-22 09:58 647,872 --------- C:\Windows\System32\Mscomct2.ocx
2007-11-15 23:41 . 1999-10-10 18:00 41,984 --------- C:\Windows\Ctregrun.exe
2007-11-15 23:40 . 2007-11-30 20:43 <REP> d-------- C:\Program Files\Audible
2007-11-15 23:40 . 2001-08-17 22:43 24,576 --------- C:\Windows\System32\msxml3a.dll
2007-11-15 23:37 . 1999-12-12 18:01 44,032 --------- C:\Windows\System32\CTSVCCDA.EXE
2007-11-15 23:37 . 1999-11-17 18:00 25,088 --------- C:\Windows\System32\CTSVCCTL.EXE
2007-11-15 23:36 . 2007-11-15 23:39 <REP> d--h----- C:\Program Files\Creative Installation Information
2007-11-15 23:36 . 2007-11-15 23:36 <REP> d-------- C:\Program Files\Common Files\Creative
2007-11-15 23:35 . 2007-11-15 23:35 <REP> d-------- C:\Users\All Users\Creative
2007-11-15 23:35 . 2007-11-15 23:35 <REP> d-------- C:\ProgramData\Creative
2007-11-15 23:33 . 2007-11-15 23:41 <REP> d-------- C:\Program Files\Creative
2007-11-15 23:24 . 2007-11-15 23:24 <REP> d-------- C:\Users\bizoux\AppData\Roaming\CyberLink
2007-11-14 22:45 . 2007-11-14 22:45 <REP> d-------- C:\Users\bizoux\AppData\Roaming\AdobeUM
2007-11-14 21:59 . 2007-12-08 13:16 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Azureus
2007-11-14 21:53 . 2007-09-24 23:31 69,632 --a------ C:\Windows\System32\javacpl.cpl
2007-11-14 21:52 . 2007-11-14 21:53 <REP> d-------- C:\Program Files\Java
2007-11-14 21:51 . 2007-11-14 21:51 <REP> d-------- C:\Program Files\Common Files\Java
2007-11-14 21:48 . 2007-11-14 21:48 <REP> d-------- C:\Program Files\Azureus
2007-11-14 19:53 . 2007-11-14 19:53 <REP> d-------- C:\Users\All Users\Yahoo! Companion
2007-11-14 19:53 . 2007-11-14 19:53 <REP> d-------- C:\ProgramData\Yahoo! Companion
2007-11-14 08:25 . 2007-11-14 08:25 205,824 --a------ C:\Windows\System32\msoeacct.dll
2007-11-14 08:25 . 2007-11-14 08:25 87,040 --a------ C:\Windows\System32\msoert2.dll
2007-11-14 08:25 . 2007-11-14 08:25 39,424 --a------ C:\Windows\System32\ACCTRES.dll
2007-11-14 08:24 . 2007-11-14 08:24 376,320 --a------ C:\Windows\System32\winsrv.dll
2007-11-14 08:24 . 2007-11-14 08:24 49,664 --a------ C:\Windows\System32\csrsrv.dll
2007-11-14 08:22 . 2007-11-14 08:22 414,208 --a------ C:\Windows\System32\msscp.dll
2007-11-14 08:22 . 2007-11-14 08:22 2,048 --a------ C:\Windows\System32\tzres.dll
2007-11-14 08:21 . 2007-11-14 08:21 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-11-14 08:21 . 2007-11-14 08:21 396,800 --a------ C:\Windows\System32\MPSSVC.dll
2007-11-14 08:21 . 2007-11-14 08:21 392,192 --a------ C:\Windows\System32\FirewallAPI.dll
2007-11-14 08:21 . 2007-11-14 08:21 178,688 --a------ C:\Windows\System32\iphlpsvc.dll
2007-11-14 08:21 . 2007-11-14 08:21 86,016 --a------ C:\Windows\System32\icfupgd.dll
2007-11-14 08:21 . 2007-11-14 08:21 63,488 --a------ C:\Windows\System32\drivers\mpsdrv.sys
2007-11-14 08:21 . 2007-11-14 08:21 61,952 --a------ C:\Windows\System32\cmifw.dll
2007-11-14 08:21 . 2007-11-14 08:21 23,040 --a------ C:\Windows\System32\drivers\tunnel.sys
2007-11-14 08:21 . 2007-11-14 08:21 16,896 --a------ C:\Windows\System32\wfapigp.dll
2007-11-14 08:21 . 2007-11-14 08:21 15,360 --a------ C:\Windows\System32\drivers\TUNMP.SYS
2007-11-14 08:20 . 2007-11-14 08:20 8,147,968 --a------ C:\Windows\System32\wmploc.DLL
2007-11-14 08:20 . 2007-11-14 08:20 1,191,936 --a------ C:\Windows\System32\msxml3.dll
2007-11-14 08:20 . 2007-11-14 08:20 7,680 --a------ C:\Windows\System32\spwmp.dll
2007-11-14 08:20 . 2007-11-14 08:20 4,096 --a------ C:\Windows\System32\msdxm.ocx
2007-11-14 08:20 . 2007-11-14 08:20 4,096 --a------ C:\Windows\System32\dxmasf.dll
2007-11-14 08:20 . 2007-11-14 08:20 2,048 --a------ C:\Windows\System32\msxml3r.dll
2007-11-14 08:19 . 2007-11-14 08:19 1,383,424 --a------ C:\Windows\System32\mshtml.tlb
2007-11-14 08:17 . 2007-11-14 08:17 1,335,296 --a------ C:\Windows\System32\msxml6.dll
2007-11-14 08:17 . 2007-11-14 08:17 737,792 --a------ C:\Windows\System32\inetcomm.dll
2007-11-14 08:17 . 2007-11-14 08:17 84,480 --a------ C:\Windows\System32\INETRES.dll
2007-11-14 08:17 . 2007-11-14 08:17 2,048 --a------ C:\Windows\System32\msxml6r.dll
2007-11-14 08:16 . 2007-11-14 08:16 788,992 --a------ C:\Windows\System32\rpcrt4.dll
2007-11-14 08:16 . 2007-11-14 08:16 152,576 --a------ C:\Windows\System32\imagehlp.dll
2007-11-14 08:16 . 2007-11-14 08:16 12,800 --a------ C:\Windows\System32\drivers\fs_rec.sys
2007-11-14 08:16 . 2007-11-14 08:16 5,120 --a------ C:\Windows\System32\wmi.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-02 18:38 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-01 18:04 --------- d-----w C:\Program Files\Common Files\NewTech Infosystems
2007-11-30 19:46 --------- d-----w C:\Program Files\eSobi
2007-11-30 19:43 --------- d-----w C:\ProgramData\eSobi
2007-11-18 10:28 --------- d-----w C:\Program Files\Acer Arcade Live
2007-11-18 10:23 --------- d-----w C:\ProgramData\CyberLink
2007-11-14 17:54 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-11-14 17:53 --------- d-----w C:\ProgramData\Symantec
2007-11-14 07:31 --------- d-----w C:\Program Files\Windows Mail
2007-11-14 07:25 --------- d-----w C:\ProgramData\Microsoft Help
2007-11-14 07:18 56,320 ----a-w C:\Windows\System32\iesetup.dll
2007-11-14 07:18 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2007-11-14 07:18 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2007-11-13 22:05 --------- d-sh--w C:\ProgramData\Modèles
2007-11-13 22:05 --------- d-sh--w C:\ProgramData\Menu Démarrer
2007-11-13 22:05 --------- d-sh--w C:\ProgramData\Favoris
2007-11-13 22:05 --------- d-sh--w C:\ProgramData\Bureau
2007-11-13 22:05 --------- d-sh--w C:\Program Files\Fichiers communs
2007-10-18 10:31 51,224 ----a-w C:\Windows\System32\sirenacm.dll
2007-09-28 17:07 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll
2007-09-28 17:05 81,920 ----a-w C:\Windows\System32\dpl100.dll
2007-09-28 17:05 739,840 ----a-w C:\Windows\System32\divx.dll
2006-11-02 12:50 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2006-11-02 13:35]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-23 12:04 C:\Windows\RtHDVCpl.exe]
"Acer Tour"="" []
"WarReg_PopUp"="C:\Acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 20:48]
"eRecoveryService"="" []
"Acer Tour Reminder"="C:\Acer\AcerTour\Reminder.exe" [2007-02-15 17:39]
"Apanel"="C:\ACERSW\config\NewSetApanel.cmd" []
"SystrayORAHSS"="C:\Program Files\Orange HSS\Systray\SystrayApp.exe" [2007-07-24 19:55]
"ORAHSSSessionManager"="C:\Program Files\Orange HSS\SessionManager\SessionManager.exe" [2007-07-24 19:03]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 15:57]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-08-08 09:25]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 12:06]
"MSConfig"="C:\Windows\system32\msconfig.exe" [2006-11-02 10:45]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 11:35]
"Acer Tour Reminder"="C:\Acer\AcerTour\Reminder.exe" [2007-02-15 17:39]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2007-05-06 20:28:40]
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 03:44:06]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
C:\Program Files\Windows Defender\MSASCui.exe -hide
R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys
R2 int15;int15;\??\C:\Acer\Empowering Technology\eRecovery\int15.sys
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3;C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys
R3 PCASp50;PCASp50 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCASp50.sys
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys
S3 PCAMp50;PCAMp50 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCAMp50.sys
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{06955f46-9bf0-11dc-b961-001c252f163f}]
\shell\Auto\command - ufpyzntyt.exe
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL ufpyzntyt.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0c7c596-92d8-11dc-b60e-001c252f163f}]
\shell\Auto\command - ufpyzntyt.exe
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL K:\
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e44ef4fa-9abc-11dc-a4de-001c252f163f}]
\shell\Auto\command - F:\hhbgkpudh.exe
\shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\hhbgkpudh.exe
*Newly Created Service* - PROCEXP90
voila le résultat
.
**************************************************************************
catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-08 13:16:12
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-08 13:19:22
.
--- E O F --- -
ok
-
ContributeurTélécharge Combofix sUBs : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
et sauvegarde le sur ton bureau et pas ailleurs!
Double-clic sur combofix,
Attends que combofix ait terminé, un rapport sera créé. Poste le rapport.
- 1
- 2
Suivant