Problèmes de ralentissements + pubs
Résoluj'ai depuis quelques mois quelques gros ralentissements sur mon PC, tant au niveau internet qu'au niveau jeux...
Je reçois également énormément de pub en navigant sur internet (une page de pub pour 2 pages ouvertes...).
Si quelqu'un aurait la gentillesse de donner un peu de temps à un autre quelqu'un un peu découragé... Ca serait très sympa.
Merci d'avance.
Configuration: Windows XP Firefox 2.0.0.11
52 réponses
Ralentissements importants sur le PC et affichage excessif de publicités lors de la navigation, sur une configuration Windows XP et Firefox 2.0.0.11, sont les symptômes décrits. Des éléments de réponse proposent des scans en mode sans échec et l’utilisation d’outils dédiés comme VundoFix, VirtumundoBeGone, ComboFix, HijackThis et ADS Spy pour détecter et supprimer les malwares. Les procédures incluent ensuite le redémarrage, l’obtention de rapports de scan (vundofix.txt, Combofix.txt ou logs HijackThis) et la publication des résultats pour identifier les éléments à retirer. En parallèle, certains messages suggèrent des étapes complémentaires et des vérifications liées aux extensions et BHO susceptibles d’aggraver les pubs, sans conclure sur une solution unique.
-
Eh ben merci beaucoup! Et à bientôt ;-)
-
ModérateurSalut
c'est tout bon ;-)
++ -
Voila...
http://krambeul.free.fr/hijackthis%203.log -
ModérateurSalut
poste un nouveau rapport hijackthis stp
++ -
Me revoila... Je ne sais pas trop s'il reste des choses à faire (l'état de mon ordinateur s'est déjà bien amélioré), mais si oui, je suis prêt!
-
Modérateurbon voyage ! :)
++ -
Désolé de ne pas avoir répondu plus tôt, je n'étais pas chez moi...
Donc une fois qu'on a tout supprimer, on ne peux pas enregistrer de rapport (mais il n'y a plus rien)
Je repart en Australie demain, jusqu'à mercredi dans 10 jours... Je ne pourrais donc pas trop effectuer tout ce qu'il y a à effectuer ! ;-)
Bonne semaine (et encore merci) -
Modérateurcomme tu veux, as toi de voir !
++ -
Faut-il décocher la case quick scan?
-
Modérateurok,
HijackThis, clique sur "Open the misc tools section" -> "Open ADS Spy..." -> "Scan" -> Coche tout -> Clique sur "Remove selected".
ensuite, refais ceci :
Exécute hijackthis et clique sur "Open the misc tools section" -> "Open ADS Spy..." -> "Scan" -> "Save log..." -> Copie/colle ici le texte ouvert avec le bloc note.
++ -
Voila pour le rapport HJT:http://krambeul.free.fr/hijackthis%202.log
-
Donc, j'ai renommé l'éxécutable, décoché la case quick scan, et obtenu plein de fichiers (des favoris internets, principalement...)
Log : http://krambeul.free.fr/adsspy.txt -
Modérateursupprime tout ce qui concerne hijack !
puis, Télécharge le ici :
Lien : http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis
Démo : http://pageperso.aol.fr/balltrap34/demohijack.htm
Choisir l'option "do a scan and a logfile", et faire un copier/coller du rapport ainsi générer sur le forum.
++ -
J'ai fait le scan en laissant hijackthis nommé en scanner, il n'a rien trouvé... Je le renomme en HijackThis.exe? Et je trouve pas le log une fois sauvegardé... C'est la suite de Hijackthis.log?
-
Modérateuroups ! pas tout à fait, je parlais de hijackthis ! :)
++ -
ComboFix 08-01-16.4 - xxx 2008-01-17 17:07:29.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.446 [GMT 1:00]
Running from: C:\Documents and Settings\xxx\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\xxx\Bureau\CFScript.txt
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
((((((((((((((((((((((((((((( Fichiers créés 2007-12-17 to 2008-01-17 ))))))))))))))))))))))))))))))))))))
.
2008-01-17 18:17 . 2008-01-17 18:19 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-01-17 17:38 . 2008-01-17 17:38 1,291,102 --a------ C:\upload_moi_DARLING.tar.gz
2008-01-17 14:22 . 2008-01-16 22:23 2,115,616 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-17 14:22 . 2008-01-16 19:02 17,636 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-17 14:05 . 2008-01-17 14:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-01-17 14:05 . 2007-12-13 19:27 42,384 --a------ C:\WINDOWS\zllsputility_loc040c.dll
2008-01-17 14:05 . 2007-12-13 19:27 21,904 --a------ C:\WINDOWS\system32\imsinstall_loc040c.dll
2008-01-17 14:05 . 2007-12-13 19:27 17,808 --a------ C:\WINDOWS\system32\imslsp_install_loc040c.dll
2008-01-17 14:04 . 2007-12-13 19:27 75,248 --a------ C:\WINDOWS\zllsputility.exe
2008-01-17 14:04 . 2004-04-27 04:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2008-01-17 14:03 . 2007-12-13 19:27 1,086,952 --a------ C:\WINDOWS\system32\zpeng24.dll
2008-01-17 13:15 . 2008-01-17 17:10 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-17 13:15 . 2008-01-17 13:15 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-16 20:51 . 2008-01-16 20:53 <REP> d-------- C:\Program Files\Dofus
2008-01-16 19:04 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-16 18:15 . 2008-01-16 18:15 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2008-01-16 17:22 . 2008-01-16 18:14 <REP> d-------- C:\VundoFix Backups
2008-01-15 18:47 . 2008-01-16 07:09 <REP> d-------- C:\WINDOWS\BDOSCAN8
2008-01-15 18:25 . 2008-01-15 18:25 <REP> d-------- C:\Program Files\Trend Micro
2008-01-14 18:36 . 2008-01-14 18:36 <REP> d-------- C:\Documents and Settings\xxx\Application Data\ubi.com
2008-01-13 16:21 . 2008-01-16 21:46 <REP> d-------- C:\Documents and Settings\xxxx\Application Data\BitTorrent
2008-01-09 13:00 . 2008-01-09 13:00 <REP> d-------- C:\Program Files\NAMCO BANDAI Games
2008-01-09 12:18 . 2008-01-09 12:18 20,480 --a------ C:\WINDOWS\system32\H@tKeysH@@k.DLL
2008-01-09 12:06 . 2008-01-09 12:06 <REP> d-------- C:\Program Files\DNA
2008-01-09 12:06 . 2008-01-09 12:06 <REP> d-------- C:\Program Files\BitTorrent
2008-01-09 12:06 . 2008-01-17 17:19 <REP> d-------- C:\Documents and Settings\xxx\Application Data\DNA
2008-01-09 12:06 . 2008-01-17 17:16 <REP> d-------- C:\Documents and Settings\xxx\Application Data\BitTorrent
2008-01-02 11:24 . 2008-01-02 11:24 <REP> d-------- C:\Documents and Settings\xxxx\Application Data\Apple Computer
2008-01-02 11:23 . 2008-01-02 11:23 <REP> d-------- C:\Program Files\iTunes
2008-01-02 11:23 . 2008-01-02 11:23 <REP> d-------- C:\Program Files\iPod
2008-01-02 11:20 . 2008-01-02 11:20 <REP> d-------- C:\Program Files\Fichiers communs\Apple
2008-01-02 11:20 . 2008-01-02 11:20 <REP> d-------- C:\Program Files\Apple Software Update
2008-01-02 11:20 . 2008-01-02 11:20 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-01-02 11:20 . 2007-10-31 14:09 30,464 --a------ C:\WINDOWS\system32\drivers\usbaapl.sys
2007-12-24 23:44 . 2008-01-16 15:47 65 --a------ C:\WINDOWS\FISHUI.INI
2007-12-24 21:37 . 2007-12-24 21:37 <REP> d-------- C:\Documents and Settings\xxx\Application Data\DataCast
2007-12-24 21:36 . 2007-08-23 21:06 110,592 --a------ C:\WINDOWS\system32\TG_DUMP0708.DLL
2007-12-24 21:34 . 2007-12-24 21:34 <REP> d-------- C:\Program Files\Lame MP3 Codec
2007-12-24 21:34 . 2002-12-03 22:13 1,048,576 --a------ C:\WINDOWS\system32\lameACM.acm
2007-12-24 21:34 . 2005-05-03 09:33 299,008 --a------ C:\WINDOWS\system32\LAME_MP3.dll
2007-12-24 21:34 . 2004-12-10 21:29 401 --a------ C:\WINDOWS\system32\lame_acm.xml
2007-12-24 21:33 . 2007-12-24 21:33 <REP> d-------- C:\Program Files\XviD
2007-12-24 21:33 . 2007-12-24 21:33 65,024 --a------ C:\WINDOWS\IFinst26.exe
2007-12-24 21:32 . 2007-12-24 21:32 <REP> d-------- C:\Program Files\Samsung
2007-12-24 21:32 . 2007-12-24 21:32 <REP> d-------- C:\Program Files\MarkAny
2007-12-24 21:31 . 2007-12-24 21:31 <REP> d-------- C:\Documents and Settings\xxx\Application Data\InstallShield
2007-12-24 15:52 . 2007-12-24 15:52 1,409 --a------ C:\WINDOWS\system32\tmpC444F.FOT
2007-12-24 15:52 . 2007-12-24 15:52 1,409 --a------ C:\WINDOWS\system32\tmp9774F.FOT
2007-12-24 15:52 . 2007-12-24 15:52 1,409 --a------ C:\WINDOWS\system32\tmp5084F.FOT
2007-12-24 15:51 . 2007-12-24 15:51 96,864 --a------ C:\WINDOWS\~GLC0000.TMP
2007-12-19 18:01 . 2007-12-19 18:01 <REP> d-------- C:\Documents and Settings\xxxx\Application Data\Sites
2007-12-19 18:01 . 2007-12-19 18:01 <REP> d-------- C:\Documents and Settings\xxxx\Application Data\Dynamique
2007-12-19 18:01 . 2007-12-19 18:02 <REP> d-------- C:\Documents and Settings\xxxx\Application Data\Classes de site
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-17 17:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-01-17 16:15 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-17 15:58 --------- d-----w C:\Program Files\Intel
2008-01-17 13:41 --------- d-----w C:\Program Files\Microsoft Games
2008-01-15 18:31 --------- d-----w C:\Documents and Settings\xxx\Application Data\Apple Computer
2008-01-15 15:05 --------- d-----w C:\Program Files\Black Thorn
2008-01-13 15:38 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-01-13 15:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-01-09 11:59 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-09 11:57 --------- d-----w C:\Program Files\Ubisoft
2008-01-09 11:26 --------- d-----w C:\Program Files\THQ
2008-01-09 11:08 --------- d-----w C:\Program Files\uTorrent
2008-01-09 11:07 --------- d-----w C:\Documents and Settings\xxx\Application Data\uTorrent
2008-01-02 10:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-01-02 10:22 --------- d-----w C:\Program Files\QuickTime
2007-12-24 15:06 --------- d-----w C:\Program Files\Papyrus
2007-12-24 14:51 96,864 ----a-w C:\WINDOWS\~GLC0000.TMP
2007-12-19 14:34 --------- d-----w C:\Documents and Settings\xxx\Application Data\foobar2000
2007-12-19 14:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-19 14:25 --------- d-----w C:\Documents and Settings\xxx\Application Data\Free Download Manager
2007-12-14 16:19 40,960 ------w C:\WINDOWS\system32\MAMACExtract.dll
2007-12-13 18:27 54,672 ----a-w C:\WINDOWS\system32\vsutil_loc040c.dll
2007-12-12 17:23 --------- d-----w C:\Documents and Settings\xxx\Application Data\Sites
2007-12-12 17:23 --------- d-----w C:\Documents and Settings\xxx\Application Data\Classes de site
2007-12-08 21:00 --------- d-----w C:\Program Files\Fraps
2007-12-08 13:17 --------- d-----w C:\Program Files\Codemasters
2007-12-06 19:53 --------- d-----w C:\Documents and Settings\xxx\Application Data\Creative
2007-12-06 19:00 --------- d-----w C:\Program Files\Creative
2007-12-06 15:58 --------- d-----w C:\Program Files\Avast4
2007-12-05 19:41 --------- d-----w C:\Program Files\TrackMania Nations ESWC
2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
2007-11-28 19:30 --------- d-----w C:\Documents and Settings\xxxx\Application Data\DivX
2007-11-27 20:30 --------- d-----w C:\Program Files\Flac
2007-11-27 20:18 --------- d-----w C:\Program Files\foobar2000
2007-11-27 20:05 --------- d-----w C:\Documents and Settings\xxx\Application Data\F4
2007-11-27 20:00 409,600 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2007-11-27 20:00 114,688 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2007-11-27 14:33 684,313 ----a-w C:\WINDOWS\unins000.exe
2007-11-27 12:49 --------- d-----w C:\Documents and Settings\xxx\Application Data\DivX
2007-11-27 12:35 --------- d-----w C:\Program Files\Free Download Manager
2007-11-27 12:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\FreeDownloadManager.ORG
2007-11-26 18:05 --------- d-----w C:\Program Files\DivX
2007-11-26 17:59 13,146 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-11-26 17:33 --------- d-----w C:\Program Files\Java
2007-11-25 13:32 --------- d-----w C:\Program Files\Virtual Dub
2007-11-25 11:09 --------- d-----w C:\Program Files\Fantastic Flame Screensaver
2007-11-24 21:41 --------- d-----w C:\Program Files\GameSpy Arcade
2007-11-23 21:07 --------- d-----w C:\Program Files\ThiWeb Live 2
2007-11-23 20:48 --------- d-----w C:\Program Files\MilkShape 3D 1.7.7a
2007-11-23 19:54 --------- d-----w C:\Program Files\Half-Life Model Viewer
2007-11-20 14:36 118,784 ----a-w C:\WINDOWS\system32\MaDRM.dll
2007-11-09 17:24 103,736 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2007-11-07 12:49 108,144 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-11-07 09:28 728,576 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:28 728,576 ----a-w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-30 17:20 360,064 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-29 22:36 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:36 1,293,824 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-25 16:43 8,516,608 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-25 09:26 53,248 ----a-w C:\WINDOWS\bdoscandel.exe
2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-20 00:56 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-10-20 00:56 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-10-20 00:56 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-10-20 00:56 129,784 ------w C:\WINDOWS\system32\pxafs.dll
2007-10-20 00:56 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
2007-10-20 00:56 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2007-10-20 00:56 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-10-20 00:54 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-10-20 00:54 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-10-20 00:54 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-10-20 00:54 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-10-20 00:54 739,840 ----a-w C:\WINDOWS\system32\DivX.dll
2007-10-20 00:54 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-10-18 10:31 51,224 ----a-w C:\WINDOWS\system32\sirenacm.dll
2007-10-18 09:06 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
2007-10-18 09:03 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-10-18 09:03 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-10-18 09:03 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-10-18 09:03 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-10-18 09:03 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-10-18 09:03 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-10-18 09:02 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-05-16 05:36 579,826 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2007-05-14 19:27 17,644 -c--a-w C:\Documents and Settings\xxxx\Application Data\wklnhst.dat
2007-05-01 11:46 1,488 -c--a-w C:\Documents and Settings\xxxx\Application Data\wklnhst.dat
2007-04-25 10:29 3,330 -c--a-w C:\Documents and Settings\xxxx\Application Data\wklnhst.dat
2006-02-19 08:28 12,288 ----a-w C:\WINDOWS\Fonts\RandFont.dll
.
((((((((((((((((((((((((((((( snapshot@2008-01-16_19.33.43.75 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-16 18:05:26 1,396,736 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0[/u]0000001\NTUSER.DAT
+ 2008-01-17 16:06:26 1,396,736 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0[/u]0000001\NTUSER.DAT
- 2008-01-16 18:05:26 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0[/u]0000002\UsrClass.dat
+ 2008-01-17 16:06:26 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0[/u]0000002\UsrClass.dat
- 2008-01-16 18:05:27 7,745,536 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0[/u]0000003\NTUSER.DAT
+ 2008-01-17 16:06:26 1,396,736 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0[/u]0000003\NTUSER.DAT
- 2008-01-16 18:05:27 307,200 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0[/u]0000004\UsrClass.dat
+ 2008-01-17 16:06:26 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0[/u]0000004\UsrClass.dat
+ 2008-01-17 16:06:27 7,766,016 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0[/u]0000005\NTUSER.DAT
+ 2008-01-17 16:06:27 307,200 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0[/u]0000006\UsrClass.dat
+ 2008-01-17 15:57:57 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_1f4.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 12:00 15360]
"µTorrent"="C:\Program Files\uTorrent\utorrent.exe" [ ]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 18:03 152872]
"Free Uploader Oe Integration"="C:\Program Files\Free Download Manager\FUM\fumoei.exe" [2007-06-10 18:02 40960]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 18:23 102400]
"BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-01-09 12:06 290112]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [2007-11-27 23:45 588080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-10-04 17:14 8491008]
"SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2005-06-03 07:16 81920]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-09-19 05:19 180269]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-22 00:56 16261632 C:\WINDOWS\RTHDCPL.EXE]
"nwiz"="nwiz.exe" [2007-10-04 17:14 1626112 C:\WINDOWS\system32\nwiz.exe]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-02-22 01:59 143360]
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 21:34 249856]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2005-02-17 05:11 49152]
"ftutil2"="ftutil2.dll" [2004-06-07 13:05 106496 C:\WINDOWS\system32\ftutil2.dll]
"DMAScheduler"="c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 08:05 90112]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-11-29 20:50 196608]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"avast!"="C:\PROGRA~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"SPC500NC_Monitor"="C:\WINDOWS\Philips\SPC500NC\Monitor.exe" [2006-11-03 10:01 319488]
"NeroFilterCheck"="C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2007-03-01 14:57 153136]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 19:34 64512]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-10-04 17:14 81920]
"SMSTray"="C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe" [2007-09-20 08:23 132624]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-12-13 19:27 919016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 12:00 15360]
C:\Documents and Settings\xxxx\Menu D‚marrer\Programmes\D‚marrage\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-09-19 04:47:45]
PinMcLnk.lnk - C:\hp\bin\cloaker.exe [2006-09-19 04:47:45]
C:\Documents and Settings\xxxx\Menu D‚marrer\Programmes\D‚marrage\
Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-09-19 04:47:45]
PinMcLnk.lnk - C:\hp\bin\cloaker.exe [2006-09-19 04:47:45]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSetFolders"= 0 (0x0)
"NoFavoritesMenu"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
"NoUserNameInStartMenu"= 0 (0x0)
"NoStartMenuPinnedList"= 0 (0x0)
"NoStartMenuMFUprogramsList"= 0 (0x0)
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{88485281-8b4b-4f8d-9ede-82e29a064277}"= C:\PROGRA~1\MarkAny\CONTEN~1\MACSMA~1.DLL [2004-11-23 16:51 192512]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="LogonUI.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NI.UWAS6V_0001_N91M2208"="c:\documents and settings\guillaume\application data\winantispyware2006freeinstall_fr[1].exe" -nag
"PCDrProfiler"=
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
"DriveCleaner Free"="C:\Program Files\DriveCleaner Free\UDC.exe" /min
"ehTray"=C:\WINDOWS\ehome\ehtray.exe
"Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
R1 oreans32;oreans32;C:\WINDOWS\system32\drivers\oreans32.sys [2007-09-13 16:55]
R2 RPCHED;Remote Procedure CallD (RPCE);C:\Program Files\Intel\Intell.exe [2002-01-09 17:19]
R3 fbxusb;Carte réseau virtuelle FreeBox USB;C:\WINDOWS\system32\DRIVERS\fbxusb32.sys [2004-10-20 14:23]
R3 usbstor;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-10 12:00]
S3 SPC500NC;SPC 500NC Laptop Camera;C:\WINDOWS\system32\DRIVERS\SPC610NC.SYS [2007-01-19 16:14]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\setup.exe
\Shell\directx\command - E:\DirectX\dxsetup.exe
\Shell\setup\command - E:\setup.exe
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2007-12-28 16:15:00 C:\WINDOWS\Tasks\Maintenance en 1 clic.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2008-01-17 16:00:00 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job"
- C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-17 17:25:32
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-17 17:29:23
ComboFix-quarantined-files.txt 2008-01-17 16:29:12
ComboFix2.txt 2008-01-16 18:34:42
.
2008-01-17 17:21:26 --- E O F ---
C'est bon?
Quand tu dis Exécute le... tu parle de quoi? ComboFix? -
Modérateurc'est parti !
Crée un nouveau document texte et nomme le CFScript.txt ( attention très important ! ) : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes en gras :
File ::
C:\WINDOWS\~GLC0000.TMP
C:\WINDOWS\system32\tmpC444F.FOT
C:\WINDOWS\system32\tmp9774F.FOT
C:\WINDOWS\system32\tmp5084F.FOT
C:\WINDOWS\IFinst26.exe
C:\upload_moi_DARLING.tar.gz
C:\WINDOWS\imsins.BAK
C:\WINDOWS\system32\drivers\oreans32.sys
Folder ::
C:\Program Files\DriveCleaner Free
Driver ::
oreans32
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0785D7B3-75D1-449C-8764-B7F34CACB9D1}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{183DAFA3-28F8-402D-9B71-70FB514D5BC2}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{23B28C7D-CFB4-4DC5-B5FF-BD9E9F41A04D}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30266CAA-B742-4380-9228-5E42C1C047E3}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6E3D2E1D-7B23-41c8-8A6C-13012A889F99}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{82A94863-7169-45E5-83A9-C9B6D1552051}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{874EE138-DC4F-41E0-AD02-C71A9ABEFFDC}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{881E8220-FF74-49B5-A14B-E3BDA5DC95FC}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8E6CEAAA-5821-4482-B893-5E01B46A62F5}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8F15DB30-0F2C-4DC0-8109-55F905F7F95F}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{980682F0-8794-4A1E-804C-77B45606DEC8}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9BFE63B9-F62C-487A-B890-DFD9FE6675AE}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A4D51FEC-F3AB-4207-88C8-BA4B2F669E56}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A74364D3-8A44-42EA-BC8A-C02131BBEAD4}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BB05CEDD-8A90-4994-B5A5-0FE52101411d}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BC890CB2-9C59-4E90-97F2-CB47D1B2B200}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C1F74180-ADD5-47A4-AA34-4BA4B2F3E73C}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EB417852-6BFC-46D6-83DA-BCF80BDAD918}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ED8FB9E5-6430-44BE-B970-AD34DD9DB3D6}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtsq]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awvtr]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awvtu]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebcb]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geeba]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geebc]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geebx]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geede]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkjh]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljkhhf]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmkjk]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqpn]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqromm]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtutt]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winemx32]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NI.UWAS6V_0001_N91M2208"="-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="-
ensuite fais glisser le fichier texte sur combo.exe comme sur l'animation : http://img.photobucket.com/albums/v666/sUBs/CFScript.gif
Dans la fenêtre qui suit, choisie l'option 1 puis valide
Patiente un peu, si le bureau disparait parfois durant le scan : c'est normal !
A la fin du scan, un rapport va s'afficher : poste le stp ( sinon il se situe dans ici : C:\ComboFix.txt )
puis, fais ceci stp :
Exécute le et clique sur "Open the misc tools section" -> "Open ADS Spy..." -> "Scan" -> "Save log..." -> Copie/colle ici le texte ouvert avec le bloc note.
@+
-
Contributeur sécuritébonne nuit ,a demain !
-
Je vais me coucher, je me lève tôt demain (4h :-( )... Je reviens vers 17h.
A+ -
Modérateurça s'appelle une erreur de frappe ! :))
je te prépare la manip !
oui, c'est vraiment pas triste !
@+
- 1
- 2
- 3