Fenetres de pub......
Des fenetres de pub apparaissent incessemment. Hier j'ai réussi à éradiquer leprobleme en restaurant sur un point antérieur. Ce matin, les fenetres sont de retour et la lenteur aussi... Quand j'ai voulu restaurer comme hier, j'ai constaté que les points de restauration avaient disparu.....
J'ai parcouru le forum et réussi à identifier la présence du vilain ntos.exe... Avec SDFix en suivant les conseils trouvés sur le foum je pense l'avoir dégagé.... et pourtant les fenetres reviennent et la lenteur aussi.
A tout hasard je joins le rapport SDI ix :
[b]SDFix: Version 1.205 [/b]
Run by user on 13/07/2008 at 09:15
Microsoft Windows XP [version 5.1.2600]
Running From: C:\PROGRA~1\SDFix
[b]Checking Services [/b]:
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files [/b]:
Trojan Files Found:
C:\DOCUME~1\user\LOCALS~1\Temp\removalfile.bat - Deleted
C:\WINDOWS\system32\ntos.exe - Deleted
C:\Documents and Settings\Caroline\Application Data\wsnpoem\video.dll - Deleted
C:\WINDOWS\system32\wsnpoem\video.dll - Deleted
C:\Documents and Settings\Caroline\Application Data\wsnpoem\audio.dll - Deleted
C:\Documents and Settings\LocalService\Application Data\wsnpoem\audio.dll - Deleted
C:\Documents and Settings\NetworkService\Application Data\wsnpoem\audio.dll - Deleted
C:\WINDOWS\system32\wsnpoem\audio.dll - Deleted
Folder C:\WINDOWS\system32\wsnpoem - Removed
Removing Temp Files
[b]ADS Check [/b]:
[b]Final Check [/b]:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-13 09:25:31
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:36,67,8c,9f,43,9d,31,1c,79,f2,b1,5b,da,4d,9f,d6,fa,59,61,b0,1e,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,cc,49,68,7e,bc,c7,ef,6b,a4,df,0e,ea,d0,6c,eb,a8,c2,..
"khjeh"=hex:98,31,64,dd,32,04,be,95,09,7c,17,7f,c2,63,e7,67,2a,5b,36,d7,05,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:51,a3,d2,93,82,99,6a,55,29,5f,07,27,04,d3,72,09,1e,9e,22,00,82,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:36,67,8c,9f,43,9d,31,1c,79,f2,b1,5b,da,4d,9f,d6,fa,59,61,b0,1e,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,cc,49,68,7e,bc,c7,ef,6b,a4,df,0e,ea,d0,6c,eb,a8,c2,..
"khjeh"=hex:98,31,64,dd,32,04,be,95,09,7c,17,7f,c2,63,e7,67,2a,5b,36,d7,05,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:51,a3,d2,93,82,99,6a,55,29,5f,07,27,04,d3,72,09,1e,9e,22,00,82,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"khjeh"=hex:36,67,8c,9f,43,9d,31,1c,79,f2,b1,5b,da,4d,9f,d6,fa,59,61,b0,1e,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,cc,49,68,7e,bc,c7,ef,6b,a4,df,0e,ea,d0,6c,eb,a8,c2,..
"khjeh"=hex:98,31,64,dd,32,04,be,95,09,7c,17,7f,c2,63,e7,67,2a,5b,36,d7,05,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:51,a3,d2,93,82,99,6a,55,29,5f,07,27,04,d3,72,09,1e,9e,22,00,82,..
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
[b]Remaining Services [/b]:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\ma-config.com\\maconfservice.exe"="C:\\Program Files\\ma-config.com\\maconfservice.exe:LocalSubNet:Enabled:maconfservice"
"C:\\Program Files\\FlashGet\\flashget.exe"="C:\\Program Files\\FlashGet\\flashget.exe:*:Enabled:Flashget"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"="C:\\Program Files\\Winamp Remote\\bin\\Orb.exe:*:Enabled:Orb"
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"="C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe:*:Enabled:OrbTray"
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"="C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe:*:Enabled:Orb Stream Client"
"C:\\WINDOWS\\system32\\PnkBstrA.exe"="C:\\WINDOWS\\system32\\PnkBstrA.exe:*:Enabled:PnkBstrA"
"C:\\WINDOWS\\system32\\PnkBstrB.exe"="C:\\WINDOWS\\system32\\PnkBstrB.exe:*:Enabled:PnkBstrB"
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"="C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM)"
"C:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"="C:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe:*:Enabled:Football Manager 2008"
"C:\\Program Files\\THQ\\Frontlines-Fuel of War Demo\\Binaries\\FFOW-MPDemo.exe"="C:\\Program Files\\THQ\\Frontlines-Fuel of War Demo\\Binaries\\FFOW-MPDemo.exe:*:Enabled:Frontlines Game"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[b]Remaining Files [/b]:
File Backups: - C:\PROGRA~1\SDFix\backups\backups.zip
[b]Files with Hidden Attributes [/b]:
Thu 22 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\326d1a08fc685e3efad9e9a5b059ebfb\BIT12C.tmp"
Wed 4 Jun 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\585dc2612ebcefc90e7dee4c276ee95e\BIT2.tmp"
Thu 22 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\5b6da8fb69b176ee583a3734e2af76e6\BIT12F.tmp"
Sun 1 Jun 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\ab59ac72525ea90a47679441587835c9\BIT4.tmp"
[b]Finished![/b]
Je suis en train de scanner avec Kaspersky mais apres 30 minutes il n'a vu que 10 % du disque dur...
J'ajoute que mes deux diablotins de fils vont se faire gronder car je suis quasi certaine que le probleme vient du chargement de jeux "gratuits" qu'ils effectuent régulièrement.
Merci à tous de votre aide. Je suis désesépérée en fait...
Caro
Configuration: Windows XP Internet Explorer 7.0
32 réponses
Des fenêtres publicitaires apparaissent de manière répétée et le système ralentit, malgré la suppression apparente de ntos.exe; un rapport SDFix montre que plusieurs fichiers malveillants ont été supprimés mais le problème persiste. Des éléments de diagnostic tels que HijackThis ont été recommandés pour recueillir des logs et identifier les clés de démarrage et les modules douteux, sur XP, tandis que le rapport montre chemins et services impliqués. En parallèle, SDFix est utilisé et des rapports détaillent des suppressions réussies et des vérifications rootkit via GMER, indiquant qu’aucun élément caché n’a été trouvé. D'autres soulignent que l'analyse doit inclure les autorisations de pare-feu et les programmes lancés au démarrage, car certains éléments légitimes peuvent être configurés de manière dangereuse.
-
Voici le rapport Bit Defender :
BitDefender Online Scanner - Rapport virus en temps réel
Généré à: Mon, Jul 14, 2008 - 13:33:02
Info d'analyse
Fichiers scannés 249621
Infectés Fichiers 28
Virus Détectés
Adware.Brilliantdigital.3022.A 1
Application.Brilliantdigital.B 1
Trojan.Patched.BD 1
Trojan.Downloader.Swizzor.AG 1
Adware.Brilliantdigital.1100.A 1
Application.Topsearch.B 1
Application.Prockill.BD 1
Adware.Whenu.Savenow.AP 1
Application.Imesh.H 1
Adware.Navipromo.M 2
Adware.Altnet.B 1
Trojan.Vundo.EWZ 1
Application.Delfin.Media.Viewer.B 1
MemScan:Trojan.Agent.AISC 2
Application.Delfin.Media.Viewer.D 1
Adware.Brilliantdigital.C 1
Adware.Brilliantdigital.1007.A 1
Adware.Generic.15412 1
Trojan.Downloader.3346.A 1
Adware.BDE 1
Adware.Navipromo.NR 4
Adware.Altnet.K 1
Application.Cydoor.S 1
Il faut que je réeffecteue toutes les manipes faites hier ?????
Merci à vous
Caro75 -
Ecoute, il fait super beau sur Paris, alors profites en bien....
Moi je suis scotchée dans une pièce sans fenetre devant l'écran qui scan après scan m'annonce toujours plus de virus......
Quelle misère...
Et puis Bitdefender, plus il avance et moins il avance... il reste toujours une heure 30 de scan... après 40 minutes d'analyse....
ce qui est pas mal c'est que j'ai le nom des coupables qui s'affiche et que mes fils vont devoir s'expliquer car pour l'instant je vois leurs noms s'afficher dans les dossiers infectés ...
Caro75 -
L'analyse Kaspersky commence avec en bas à gauche l'inscription "erreur sur la page".... Est ce que c'est ça qui empêche de générer un rapport à la fin ? autant le savoir maintenant plutot que de me taper les 14 heures de procédure .....
Caro75-
oui,
tu as raison.
Alors faisons autrement :
> Scanne ton PC avec BitDefender en ligne http://www.bitdefender.fr/scan_fr/scan8/ie.html (uniquement sous Internet Explorer)
- Clique sur J'accepte puis accepte également l'ActiveX bloqué par la barre anti-popup du SP2 qui clignotera en haut et installe le.
- Commence par connecter tout ton matériel de stockage à ton PC (clés USB, DD amovible...) si possible. Allume les si necessaire.
- Ensuite, clique sur Cliquez ici pour scanner.
- Patiente jusqu'à la fin du scan qui peut durer assez longtemps...
- Poste le rapport une fois terminé.
Tuto : https://www.malekal.com/scan-antivirus-ligne-nod32/#mozTocId131054
Je t'ai dis que je viens sur Paris cet aprèm ? :-) -
@Utilisateur anonymeBon c'est parti avec Bitdefender....
Il lui reste 1heure 30 environ à faire....
D'ores et déjà il me dit avoir trouvé des vilaines choses dont une "insupprimable" TrojanPatched BD qui est dans Windows/system32/sens/dll.....
On est mal.....
Bouh bouh
Caro75 -
@Caro75Oui,
On est mal.
Je ne serais pas là quand il sera fini. Car je vais sur Paris (je sais pas si je t'ai dit...) pour 14H30 à St Lazare.
Mais je re dans la soirée. A moins qu'on se voit avant.
:-)
-
-
Re,
ok, alors pour les deux CD tu peux les virer des lecteurs ça ira plus vite.
(si tu souhaites les analyser tu pourras les faire plus tard. S'ils sont infectés => poubelle (a moins qu'ils soient réinscriptibles).
Non, pas besoin de désactiver ton antivirus. Au contraire, il faut que tu sois protéger notamment sur le web.
Aller bon courage Caro. -
Ahhhh, j'ai oublié un truc important .... Kaspersky disait 8 virus trouvés et 52 fuchiers infectés...
Caro75 -
C'est la cata....
APrès 14 heures de scan, mais j'ai deux disques durs et 300 000 fichiers à passer en revue (plus les cd-roms laissés dans les lecteurs qui y ont eu droit aussi) et les alertes de l'antivirus qui exige de cliquer sur deny it avant de poursuivre l'analyse (ce qui explique en partie la longueur du processus, et bien Kaspersky s'est fini par une "erreur sur la page" et l'impossibilité de générer un rapport.... Alors je recommence tout... Il faut ptet que je désactive l'antivirus pour effectuer un scan Kaspersky ????
Caro75 -
Bon, Kapersky a toujours pas fini le boulot.... 21% en 4 heures 15....
Sinon j'ai chargé Kério mais il faut redémarrer pour l'activer et je vais pas interrompre le scan pour ça....
Voila, la suite demain.. Je vais me cpucher.
Merci encore
Bonne nuit à tous.
Caro -
Mais si... je fais le test de Kapersky mais c'est long à charger ce truc....
En revanche mon micro refuse d'installer Zone Alarme...
Rapport de Kaperski suivra bientôt.
Merci
Caro -
Bon... ben je sais pas afficher "pbe résolu" pourtant j'avais vu ça tout à l'heure mais incapable de retrouver....
Désolée
caro-
Tu peux pas parce que tu n'es pas membre de CCM mais anonyme.
Tant pis pour toi puisque tu ne veux pas faire le scanne en ligne. Pourtant c'est important, comme de créer un point de restauration système et de mettre à jour ce qui n'est pas à jour et présente des failles de sécurité et de .... (choses que je t'aurais dites après...).
Bref,
Alors,
A+++
-
-
Merci infiniment à toi et à Geoffrey qui m'a aussi grandement aidée.
Je charge un parefeu, promis....
Et puis je passe le sujet en vert alors.
Merci pour le lien vers la vidéo.
Ca m'a bien fait rire.
Bisous à tous et bon courage à ceux qui sont en galère.
Caro -
Merci Diid mais dans l'intervalle, la déprime n'étant que passagère j'ai quand même généré un rapport Hijacjkthis....
Et qu'est ce qu'il dit le rapport ???
Je peux cliquer sur l'icone verte du fil réparé...?
Caro-
Ok,
Non : c'est propre.
En plus,
Afin d'éviter les trojans... :
> Installe un pare feu :
- Je te conseille Kerio : http://www.commentcamarche.net/telecharger/telecharger 206 kerio . Si problème, tuto : https://kerio.probb.fr/
- Si tu as des difficultés avec les configuration de Kerio, alors installe Zone Alarme : /telecharger/telecharger-157-zonealarm, en cas de problème : http://forum.telecharger.01net.com/forum/high-tech/PRODUITS/Questions-techniques/zonealarm-tutorial-sujet_169658_1.htm
- Installe le nouveau pare-feu, puis désactive le pare-feu windows.
Mais fais le scanne Kasper quand même stp et donne moi ton adresse car : https://www.youtube.com/watch?v=F-04OM2oUt4&gl=FR
:D
Désolé, aujourd'hui je suis complètement fou.
A+
-
-
J'ai refait Hijackthis...
Dites moi que tout est OK....
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:03:08, on 13/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\a-squared Anti-Malware\a2service.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\a-squared Anti-Malware\a2guard.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe" /d=60
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Tout télécharger avec FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD44/JSCDL/jdk/6u7/jinstall-6u7-windows-i586-jc.cab?e=1215935405533&h=25c8346752a28a7c54f91ae6a9b7b78b/&filename=jinstall-6u7-windows-i586-jc.cab
O23 - Service: a-squared Anti-Malware Service (a2AntiMalware) - Emsi Software GmbH - C:\Program Files\a-squared Anti-Malware\a2service.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
-
Un hijack T ????
Merci à toi DID mais j'ai tout enlevé avec Toolscreen....
Bouh, bouh, bouh...
Caro (déprimée après 12 heures à fixer l'écran qui lui reste imperturbable...)-
Rhôôôooo...
Faut pas déprimer :)
Alors, avant de finir :
> Fais un scan en ligne avec Kaspersky : https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
N.B. : Le scan ne marche que sous Internet Explorer.
- Commence par connecter tout ton matériel de stockage à ton PC (clés USB, DD amovible...) si possible. Allume les si necessaire.
- Sous Démonstration en ligne, on t'explique la marche à suivre, et pour lancer le scan il faut sélectionner < Exécuter l'analyse en ligne >.
- On va te demander de télécharger un contrôle active x, accepte .
- Dans le menu < Choisissez la cible de l'analyse >, sélectionne < Poste de travail >. Le scan va commencer.
- Poste le rapport qui sera généré stp.
S'il y a un problème, assure toi que les contrôles active x sont bien configurés dans les options internet comme décrit sur ce lien : http://www.inoculer.com/activex.php3
Rappel : le scan est à faire sous Internet Explorer
Tuto ici si problème : http://www.vista-xp.fr/forum/topic109.html
A+
Ludo. :D
-
-
ARRRGGGGHHHHH
Pourtant, Geoffrey il m'a filé un sacré coup de main...
Quelles "crasses" restent et comment les enlever sans tout briser ??
Merci à tous
Bisous
Caro-
Arff...
Je me suis trompé de topique.. J'ai plusieurs pages web d'ouvertes et je pensais que celle avec le rapport correspondait à ton topique.
Désolé.
Pour me faire pardonner : Caroline est un très joli prénom. Je crois que c'est mon préféré avec Isabelle. (J'ai peu dormi et je suis complètement fou aujourd'hui :DDD)))
Non, ça a l'air propre.
Peux tu poster un nouveau HiJackT quand même ?
BizZZzzz
-
-
Bon je pense avoir tout fini, avec quelques sueurs froides en prime mais ça a l'air bon....
Voici le rapport de Combofix :
ComboFix 08-07-12.4 - user 2008-07-13 17:05:39.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.1482 [GMT 2:00]
Endroit: C:\Documents and Settings\user\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\user\Bureau\WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\ddcYqnmk.dll
C:\WINDOWS\system32\eofiiyux.dll
C:\WINDOWS\system32\jgeivisu.dll
C:\WINDOWS\system32\lelbhgog.dll
C:\WINDOWS\system32\lrtjhytr.dll
C:\WINDOWS\system32\mcrh.tmp
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-13 to 2008-07-13 ))))))))))))))))))))))))))))))))))))
.
2008-07-13 15:47 . 2008-07-13 15:47 <REP> d-------- C:\Documents and Settings\LocalService\Mes documents
2008-07-13 14:28 . 2008-07-13 16:41 <REP> d-------- C:\Program Files\a-squared Anti-Malware
2008-07-13 14:28 . 2008-07-13 14:28 33,095,104 --a------ C:\Program Files\a2AntiMalwareSetup.exe
2008-07-13 14:18 . 2008-07-13 14:18 452,608 --a------ C:\Program Files\ToolsCleaner2.exe
2008-07-13 13:54 . 2008-07-13 13:54 <REP> d-------- C:\Program Files\Avira
2008-07-13 13:54 . 2008-07-13 13:54 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-07-13 11:07 . 2008-07-13 11:07 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-13 11:07 . 2008-07-13 11:07 <REP> d-------- C:\Documents and Settings\user\Application Data\Malwarebytes
2008-07-13 11:07 . 2008-07-13 11:07 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-13 11:07 . 2008-07-07 17:35 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-07-13 11:07 . 2008-07-07 17:35 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-13 10:54 . 2008-07-13 14:25 <REP> d-------- C:\Program Files\Trend Micro
2008-07-13 09:50 . 2008-07-13 09:50 <REP> d-------- C:\WINDOWS\Sun
2008-07-13 09:50 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-07-13 09:49 . 2008-07-13 09:50 <REP> d-------- C:\Program Files\Java
2008-07-13 09:49 . 2008-07-13 09:49 <REP> d-------- C:\Program Files\Fichiers communs\Java
2008-07-13 09:04 . 2008-07-13 09:05 <REP> d-------- C:\WINDOWS\ERUNT
2008-07-13 08:43 . 2008-07-13 09:28 <REP> d-------- C:\Program Files\SDFix
2008-07-13 08:19 . 2007-01-18 14:00 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys
2008-07-13 07:35 . 2008-07-13 07:35 <REP> d-------- C:\Program Files\CCleaner
2008-07-13 07:35 . 2008-07-13 07:35 2,919,360 --a------ C:\Program Files\ccsetup209.exe
2008-07-13 07:27 . 2008-07-13 07:27 0 --a------ C:\WINDOWS\nsreg.dat
2008-07-13 07:26 . 2008-07-13 07:26 7,599,856 --a------ C:\Program Files\Firefox Setup 3.0.exe
2008-07-13 03:03 . 2008-07-13 03:03 127 --a------ C:\WINDOWS\system32\MRT.INI
2008-07-12 22:05 . 2008-07-12 22:05 <REP> d-------- C:\Program Files\Apple Software Update
2008-07-12 22:05 . 2008-07-12 22:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-07-12 22:05 . 2008-07-12 22:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-07-12 22:03 . 2008-07-12 22:06 <REP> d-------- C:\Program Files\QuickTime
2008-07-12 18:58 . 2008-07-12 18:58 <REP> d-------- C:\WINDOWS\system32\AGEIA
2008-07-12 18:58 . 2008-07-12 18:58 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-07-12 18:58 . 2008-07-12 18:59 <REP> d-------- C:\Program Files\AGEIA Technologies
2008-07-12 18:54 . 2008-07-12 18:54 <REP> d-------- C:\Program Files\THQ
2008-07-12 08:38 . 2008-07-12 08:38 <REP> d-------- C:\Program Files\UnzipThemAll
2008-07-12 08:38 . 2008-07-12 08:38 <REP> d-------- C:\Program Files\DAEMON Tools Lite
2008-07-11 15:38 . 2008-07-11 15:38 <REP> d-------- C:\Program Files\Lavasoft
2008-07-11 15:38 . 2008-07-12 08:38 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-11 15:27 . 2008-07-11 15:27 0 --a------ C:\WINDOWS\system32\mbxacytu.tmp
2008-07-09 19:41 . 2008-07-09 19:41 <REP> d-------- C:\Documents and Settings\user\Application Data\Sports Interactive
2008-07-09 19:39 . 2008-07-09 19:40 <REP> d--h----- C:\Program Files\Zero G Registry
2008-07-09 19:39 . 2008-07-09 19:39 <REP> d-------- C:\Program Files\Sports Interactive
2008-07-09 19:39 . 2008-07-09 19:39 <REP> d--h----- C:\Documents and Settings\user\InstallAnywhere
2008-07-09 19:20 . 2008-06-20 12:45 360,320 --a------ C:\WINDOWS\system32\drivers\tcpip.sys
2008-07-09 19:20 . 2008-06-20 11:52 225,920 --a------ C:\WINDOWS\system32\drivers\tcpip6.sys
2008-07-09 19:20 . 2008-06-20 12:44 138,368 --a------ C:\WINDOWS\system32\drivers\afd.sys
2008-07-09 01:44 . 2008-07-09 01:45 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WinZip
2008-07-03 00:07 . 2008-07-03 00:07 <REP> d-------- C:\Documents and Settings\user\Application Data\DAEMON Tools
2008-07-03 00:07 . 2008-07-03 00:07 717,296 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-07-02 15:28 . 2008-07-02 15:28 <REP> d-------- C:\Program Files\AviSynth 2.5
2008-07-02 15:25 . 2004-01-08 11:38 208,896 --a------ C:\WINDOWS\system32\lame_enc.dll
2008-07-01 21:34 . 2008-07-01 21:34 <REP> d-------- C:\Program Files\Google
2008-07-01 21:34 . 2008-07-01 21:34 7,726,360 --a------ C:\Program Files\Google_Earth_CZXV.exe
2008-06-26 22:05 . 2008-07-10 15:07 <REP> d-------- C:\Documents and Settings\Caroline\Application Data\Winamp
2008-06-21 18:43 . 2008-06-21 18:43 22,328 --a------ C:\Documents and Settings\user\Application Data\PnkBstrK.sys
2008-06-21 18:42 . 2008-06-21 18:42 <REP> d-------- C:\WINDOWS\system32\LogFiles
2008-06-21 18:42 . 2008-06-27 17:43 107,832 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2008-06-21 18:42 . 2008-06-24 22:37 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2008-06-21 18:42 . 2008-06-21 18:42 319 --a------ C:\WINDOWS\game.ini
2008-06-21 18:33 . 2008-06-21 18:33 <REP> d-------- C:\Program Files\Activision
2008-06-21 18:31 . 2008-06-21 18:31 <REP> d--hs---- C:\WINDOWS\ftpcache
2008-06-21 11:44 . 2008-06-21 11:44 268 --ah----- C:\sqmdata02.sqm
2008-06-21 11:44 . 2008-06-21 11:44 244 --ah----- C:\sqmnoopt02.sqm
2008-06-21 11:26 . 2008-06-21 11:26 268 --ah----- C:\sqmdata01.sqm
2008-06-21 11:26 . 2008-06-21 11:26 244 --ah----- C:\sqmnoopt01.sqm
2008-06-21 11:25 . 2008-06-21 11:25 <REP> d-------- C:\Documents and Settings\quentin\Application Data\Teleca
2008-06-21 11:23 . 2008-06-21 11:23 268 --ah----- C:\sqmdata00.sqm
2008-06-21 11:23 . 2008-06-21 11:23 244 --ah----- C:\sqmnoopt00.sqm
2008-06-21 11:21 . 2008-06-21 11:21 2,422 --a------ C:\WINDOWS\system32\wpa.bak
2008-06-17 23:34 . 2008-06-17 23:34 1,489,855 --a------ C:\Program Files\UnzipThemAll.exe
2008-06-16 11:00 . 2008-06-16 11:00 <REP> d-------- C:\Documents and Settings\quentin\Application Data\Sony Ericsson
2008-06-16 10:59 . 2008-05-20 20:04 <REP> d--h----- C:\Documents and Settings\quentin\Voisinage r‚seau
2008-06-16 10:59 . 2008-05-20 20:04 <REP> d--h----- C:\Documents and Settings\quentin\Voisinage d'impression
2008-06-16 10:59 . 2008-05-20 18:20 <REP> d--h----- C:\Documents and Settings\quentin\ModŠles
2008-06-16 10:59 . 2008-07-11 14:36 <REP> dr------- C:\Documents and Settings\quentin\Mes documents
2008-06-16 10:59 . 2008-05-20 20:04 <REP> dr------- C:\Documents and Settings\quentin\Menu D‚marrer
2008-06-16 10:59 . 2008-06-16 11:00 <REP> dr------- C:\Documents and Settings\quentin\Favoris
2008-06-16 10:59 . 2008-05-20 20:04 <REP> d-------- C:\Documents and Settings\quentin\Bureau
2008-06-16 10:59 . 2008-07-13 07:05 <REP> d-------- C:\Documents and Settings\quentin
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-12 16:53 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-12 06:38 --------- d-----w C:\Program Files\Azureus
2008-07-12 06:38 --------- d-----w C:\Documents and Settings\user\Application Data\Azureus
2008-06-29 13:35 --------- d-----w C:\Documents and Settings\Caroline\Application Data\Teleca
2008-06-27 15:43 138,408 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-12 11:44 --------- d-----w C:\Documents and Settings\user\Application Data\Teleca
2008-06-02 17:11 --------- d-----w C:\Documents and Settings\Caroline\Application Data\Sony Ericsson
2008-06-02 08:18 --------- d-----w C:\Program Files\Disc2Phone
2008-06-02 08:06 --------- d-----w C:\Program Files\Sony Setup
2008-06-02 08:06 --------- d-----w C:\Documents and Settings\user\Application Data\Sony Setup
2008-06-02 08:02 --------- d-----w C:\Documents and Settings\user\Application Data\Sony Ericsson
2008-06-02 08:00 --------- d-----w C:\Program Files\Sony Ericsson
2008-06-02 08:00 --------- d-----w C:\Program Files\Fichiers communs\Teleca Shared
2008-06-02 08:00 --------- d-----w C:\Program Files\Fichiers communs\Sony Ericsson Shared
2008-06-02 08:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Teleca
2008-06-02 08:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sony Ericsson
2008-06-02 07:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Azureus
2008-06-01 23:24 --------- d-----w C:\Program Files\DivX
2008-06-01 15:48 2,864 ----a-w C:\WINDOWS\system32\winsock.dll
2008-06-01 08:15 --------- d-----w C:\Program Files\Alwil Software
2008-06-01 08:13 --------- d-----w C:\Program Files\FlashGet
2008-05-30 18:16 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-05-30 18:02 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-05-30 18:01 --------- d-----w C:\Program Files\Microsoft.NET
2008-05-26 10:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\OrbNetworks
2008-05-25 11:07 --------- d-----w C:\Documents and Settings\user\Application Data\Media Player Classic
2008-05-25 10:12 --------- d-----w C:\Documents and Settings\user\Application Data\Winamp
2008-05-25 09:56 --------- d-----w C:\Program Files\Fichiers communs\NSV
2008-05-25 09:43 --------- d-----w C:\Program Files\Winamp
2008-05-25 09:42 --------- d-----w C:\Program Files\Winamp Remote
2008-05-25 06:00 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-05-24 07:03 --------- d-----w C:\Program Files\MSXML 4.0
2008-05-23 16:33 --------- d-----w C:\Program Files\Windows Live
2008-05-23 16:32 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-05-23 16:21 46,592 ----a-w C:\e4bc1k.exe
2008-05-22 18:33 --------- d-----w C:\Program Files\HP
2008-05-22 18:33 --------- d-----w C:\Program Files\Fichiers communs\Hewlett-Packard
2008-05-22 18:31 43,488 ----a-w C:\WINDOWS\system32\drivers\AFS2K.SYS
2008-05-22 18:31 --------- d-----w C:\Program Files\Fichiers communs\HP
2008-05-22 16:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-05-21 19:44 --------- d-----w C:\Documents and Settings\user\Application Data\SecondLife
2008-05-21 18:11 --------- d-----w C:\Program Files\Motive
2008-05-21 18:11 --------- d-----w C:\Program Files\Club-Internet
2008-05-21 16:14 --------- d-----w C:\Program Files\Fichiers communs\Motive
2008-05-21 16:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Motive
2008-05-21 16:13 --------- d-----w C:\Program Files\Common Files
2008-05-21 16:07 155,995 ----a-w C:\WINDOWS\java\Packages\CNTR71JB.ZIP
2008-05-21 12:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\ma-config.com
2008-05-21 12:45 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-05-21 12:45 --------- d-----w C:\Program Files\Realtek
2008-05-21 12:45 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-05-21 12:19 --------- d-----w C:\Program Files\Marvell
2008-05-21 11:36 --------- d-----w C:\Program Files\Intel
2008-05-21 11:23 --------- d-----w C:\Program Files\ma-config.com
2008-05-20 16:24 --------- d-----w C:\Program Files\microsoft frontpage
2008-05-20 16:23 --------- d-----w C:\Program Files\Services en ligne
2008-05-13 01:51 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-05-13 01:51 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-30 15:27 442,368 ----a-w C:\WINDOWS\system32\NVUNINST.EXE
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 14:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-03 05:46 13529088]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-03 05:46 86016]
"Motive SmartBridge"="C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe" [2006-04-21 15:41 438359]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-06-25 11:24 49152]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-06-26 18:50 212992]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-04-01 20:49 36352]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2006-11-24 01:06 487424]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-07-12 22:03 413696]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
"a-squared"="C:\Program Files\a-squared Anti-Malware\a2guard.exe" [2008-07-13 14:37 2132112]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 14:31 16857600 C:\WINDOWS\RTHDCPL.exe]
"nwiz"="nwiz.exe" [2008-05-03 05:46 1630208 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 14:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"VIDC.YV12"= yv12vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\FlashGet\\flashget.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"C:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"=
"C:\\Program Files\\THQ\\Frontlines-Fuel of War Demo\\Binaries\\FFOW-MPDemo.exe"=
S3 maconfservice;Ma-Config Service;C:\Program Files\ma-config.com\maconfservice.exe [2008-05-19 10:01]
S3 se44bus;Sony Ericsson Device 068 driver (WDM);C:\WINDOWS\system32\DRIVERS\se44bus.sys [2006-11-30 14:58]
S3 se44mdfl;Sony Ericsson Device 068 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\se44mdfl.sys [2006-11-30 14:58]
S3 se44mdm;Sony Ericsson Device 068 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\se44mdm.sys [2006-11-30 14:58]
S3 se44mgmt;Sony Ericsson Device 068 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\se44mgmt.sys [2006-11-30 14:58]
S3 se44nd5;Sony Ericsson Device 068 USB Ethernet Emulation SEMC44 (NDIS);C:\WINDOWS\system32\DRIVERS\se44nd5.sys [2006-11-30 14:58]
S3 se44obex;Sony Ericsson Device 068 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\se44obex.sys [2006-11-30 14:58]
S3 se44unic;Sony Ericsson Device 068 USB Ethernet Emulation SEMC44 (WDM);C:\WINDOWS\system32\DRIVERS\se44unic.sys [2006-11-30 14:58]
S3 VNUWL5B;VIA Networking Technologies USB Wireless LAN Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\VNUWL5B.SYS [2006-09-19 14:34]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\setup\rsrc\Autorun.exe
\Shell\dinstall\command - E:\Directx\dxsetup.exe
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-07-12 20:05:17 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-22 18:38:06 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1211481323.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe0/#Hewlett-Packard#hp psc 1300 series#1211481323
"2008-07-12 10:43:06 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1213267215.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe0/#Hewlett-Packard#hp psc 1300 series#1213267215
"2008-07-13 11:22:07 C:\WINDOWS\Tasks\WebReg 20080713132206.job"
- C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exeX/TaskName 20080713132206 /N
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-DXDllRegExe - dxdllreg.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-13 17:09:35
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\a-squared Anti-Malware\a2service.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-07-13 17:14:31 - machine was rebooted [user]
ComboFix-quarantined-files.txt 2008-07-13 15:13:28
Pre-Run: 299,141,906,432 octets libres
Post-Run: 299,317,370,880 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
267 --- E O F --- 2008-07-13 01:03:28
C'est rassurant ???
Caro-
Re,
Il reste des crasses.
Geoffrey tu n'as pas répondu à mes questions ici : http://www.commentcamarche.net/forum/affich 7385048 fenetres de pub#17
?
-
-
Bon ca y est, j'ai tout effectué, enfin je pense. J'étais pas rassurée pendant la phase finale mais je crois être au terme de la quête d'un ordi clean ..... voici le rapport de Cmbfix... c'est un peu indigeste....
ComboFix 08-07-12.4 - user 2008-07-13 17:05:39.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.1482 [GMT 2:00]
Endroit: C:\Documents and Settings\user\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\user\Bureau\WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\ddcYqnmk.dll
C:\WINDOWS\system32\eofiiyux.dll
C:\WINDOWS\system32\jgeivisu.dll
C:\WINDOWS\system32\lelbhgog.dll
C:\WINDOWS\system32\lrtjhytr.dll
C:\WINDOWS\system32\mcrh.tmp
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-13 to 2008-07-13 ))))))))))))))))))))))))))))))))))))
.
2008-07-13 15:47 . 2008-07-13 15:47 <REP> d-------- C:\Documents and Settings\LocalService\Mes documents
2008-07-13 14:28 . 2008-07-13 16:41 <REP> d-------- C:\Program Files\a-squared Anti-Malware
2008-07-13 14:28 . 2008-07-13 14:28 33,095,104 --a------ C:\Program Files\a2AntiMalwareSetup.exe
2008-07-13 14:18 . 2008-07-13 14:18 452,608 --a------ C:\Program Files\ToolsCleaner2.exe
2008-07-13 13:54 . 2008-07-13 13:54 <REP> d-------- C:\Program Files\Avira
2008-07-13 13:54 . 2008-07-13 13:54 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-07-13 11:07 . 2008-07-13 11:07 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-13 11:07 . 2008-07-13 11:07 <REP> d-------- C:\Documents and Settings\user\Application Data\Malwarebytes
2008-07-13 11:07 . 2008-07-13 11:07 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-13 11:07 . 2008-07-07 17:35 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-07-13 11:07 . 2008-07-07 17:35 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-13 10:54 . 2008-07-13 14:25 <REP> d-------- C:\Program Files\Trend Micro
2008-07-13 09:50 . 2008-07-13 09:50 <REP> d-------- C:\WINDOWS\Sun
2008-07-13 09:50 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-07-13 09:49 . 2008-07-13 09:50 <REP> d-------- C:\Program Files\Java
2008-07-13 09:49 . 2008-07-13 09:49 <REP> d-------- C:\Program Files\Fichiers communs\Java
2008-07-13 09:04 . 2008-07-13 09:05 <REP> d-------- C:\WINDOWS\ERUNT
2008-07-13 08:43 . 2008-07-13 09:28 <REP> d-------- C:\Program Files\SDFix
2008-07-13 08:19 . 2007-01-18 14:00 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys
2008-07-13 07:35 . 2008-07-13 07:35 <REP> d-------- C:\Program Files\CCleaner
2008-07-13 07:35 . 2008-07-13 07:35 2,919,360 --a------ C:\Program Files\ccsetup209.exe
2008-07-13 07:27 . 2008-07-13 07:27 0 --a------ C:\WINDOWS\nsreg.dat
2008-07-13 07:26 . 2008-07-13 07:26 7,599,856 --a------ C:\Program Files\Firefox Setup 3.0.exe
2008-07-13 03:03 . 2008-07-13 03:03 127 --a------ C:\WINDOWS\system32\MRT.INI
2008-07-12 22:05 . 2008-07-12 22:05 <REP> d-------- C:\Program Files\Apple Software Update
2008-07-12 22:05 . 2008-07-12 22:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-07-12 22:05 . 2008-07-12 22:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-07-12 22:03 . 2008-07-12 22:06 <REP> d-------- C:\Program Files\QuickTime
2008-07-12 18:58 . 2008-07-12 18:58 <REP> d-------- C:\WINDOWS\system32\AGEIA
2008-07-12 18:58 . 2008-07-12 18:58 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-07-12 18:58 . 2008-07-12 18:59 <REP> d-------- C:\Program Files\AGEIA Technologies
2008-07-12 18:54 . 2008-07-12 18:54 <REP> d-------- C:\Program Files\THQ
2008-07-12 08:38 . 2008-07-12 08:38 <REP> d-------- C:\Program Files\UnzipThemAll
2008-07-12 08:38 . 2008-07-12 08:38 <REP> d-------- C:\Program Files\DAEMON Tools Lite
2008-07-11 15:38 . 2008-07-11 15:38 <REP> d-------- C:\Program Files\Lavasoft
2008-07-11 15:38 . 2008-07-12 08:38 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-11 15:27 . 2008-07-11 15:27 0 --a------ C:\WINDOWS\system32\mbxacytu.tmp
2008-07-09 19:41 . 2008-07-09 19:41 <REP> d-------- C:\Documents and Settings\user\Application Data\Sports Interactive
2008-07-09 19:39 . 2008-07-09 19:40 <REP> d--h----- C:\Program Files\Zero G Registry
2008-07-09 19:39 . 2008-07-09 19:39 <REP> d-------- C:\Program Files\Sports Interactive
2008-07-09 19:39 . 2008-07-09 19:39 <REP> d--h----- C:\Documents and Settings\user\InstallAnywhere
2008-07-09 19:20 . 2008-06-20 12:45 360,320 --a------ C:\WINDOWS\system32\drivers\tcpip.sys
2008-07-09 19:20 . 2008-06-20 11:52 225,920 --a------ C:\WINDOWS\system32\drivers\tcpip6.sys
2008-07-09 19:20 . 2008-06-20 12:44 138,368 --a------ C:\WINDOWS\system32\drivers\afd.sys
2008-07-09 01:44 . 2008-07-09 01:45 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WinZip
2008-07-03 00:07 . 2008-07-03 00:07 <REP> d-------- C:\Documents and Settings\user\Application Data\DAEMON Tools
2008-07-03 00:07 . 2008-07-03 00:07 717,296 --a------ C:\WINDOWS\system32\drivers\sptd.sys
2008-07-02 15:28 . 2008-07-02 15:28 <REP> d-------- C:\Program Files\AviSynth 2.5
2008-07-02 15:25 . 2004-01-08 11:38 208,896 --a------ C:\WINDOWS\system32\lame_enc.dll
2008-07-01 21:34 . 2008-07-01 21:34 <REP> d-------- C:\Program Files\Google
2008-07-01 21:34 . 2008-07-01 21:34 7,726,360 --a------ C:\Program Files\Google_Earth_CZXV.exe
2008-06-26 22:05 . 2008-07-10 15:07 <REP> d-------- C:\Documents and Settings\Caroline\Application Data\Winamp
2008-06-21 18:43 . 2008-06-21 18:43 22,328 --a------ C:\Documents and Settings\user\Application Data\PnkBstrK.sys
2008-06-21 18:42 . 2008-06-21 18:42 <REP> d-------- C:\WINDOWS\system32\LogFiles
2008-06-21 18:42 . 2008-06-27 17:43 107,832 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2008-06-21 18:42 . 2008-06-24 22:37 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2008-06-21 18:42 . 2008-06-21 18:42 319 --a------ C:\WINDOWS\game.ini
2008-06-21 18:33 . 2008-06-21 18:33 <REP> d-------- C:\Program Files\Activision
2008-06-21 18:31 . 2008-06-21 18:31 <REP> d--hs---- C:\WINDOWS\ftpcache
2008-06-21 11:44 . 2008-06-21 11:44 268 --ah----- C:\sqmdata02.sqm
2008-06-21 11:44 . 2008-06-21 11:44 244 --ah----- C:\sqmnoopt02.sqm
2008-06-21 11:26 . 2008-06-21 11:26 268 --ah----- C:\sqmdata01.sqm
2008-06-21 11:26 . 2008-06-21 11:26 244 --ah----- C:\sqmnoopt01.sqm
2008-06-21 11:25 . 2008-06-21 11:25 <REP> d-------- C:\Documents and Settings\quentin\Application Data\Teleca
2008-06-21 11:23 . 2008-06-21 11:23 268 --ah----- C:\sqmdata00.sqm
2008-06-21 11:23 . 2008-06-21 11:23 244 --ah----- C:\sqmnoopt00.sqm
2008-06-21 11:21 . 2008-06-21 11:21 2,422 --a------ C:\WINDOWS\system32\wpa.bak
2008-06-17 23:34 . 2008-06-17 23:34 1,489,855 --a------ C:\Program Files\UnzipThemAll.exe
2008-06-16 11:00 . 2008-06-16 11:00 <REP> d-------- C:\Documents and Settings\quentin\Application Data\Sony Ericsson
2008-06-16 10:59 . 2008-05-20 20:04 <REP> d--h----- C:\Documents and Settings\quentin\Voisinage r‚seau
2008-06-16 10:59 . 2008-05-20 20:04 <REP> d--h----- C:\Documents and Settings\quentin\Voisinage d'impression
2008-06-16 10:59 . 2008-05-20 18:20 <REP> d--h----- C:\Documents and Settings\quentin\ModŠles
2008-06-16 10:59 . 2008-07-11 14:36 <REP> dr------- C:\Documents and Settings\quentin\Mes documents
2008-06-16 10:59 . 2008-05-20 20:04 <REP> dr------- C:\Documents and Settings\quentin\Menu D‚marrer
2008-06-16 10:59 . 2008-06-16 11:00 <REP> dr------- C:\Documents and Settings\quentin\Favoris
2008-06-16 10:59 . 2008-05-20 20:04 <REP> d-------- C:\Documents and Settings\quentin\Bureau
2008-06-16 10:59 . 2008-07-13 07:05 <REP> d-------- C:\Documents and Settings\quentin
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-12 16:53 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-12 06:38 --------- d-----w C:\Program Files\Azureus
2008-07-12 06:38 --------- d-----w C:\Documents and Settings\user\Application Data\Azureus
2008-06-29 13:35 --------- d-----w C:\Documents and Settings\Caroline\Application Data\Teleca
2008-06-27 15:43 138,408 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-12 11:44 --------- d-----w C:\Documents and Settings\user\Application Data\Teleca
2008-06-02 17:11 --------- d-----w C:\Documents and Settings\Caroline\Application Data\Sony Ericsson
2008-06-02 08:18 --------- d-----w C:\Program Files\Disc2Phone
2008-06-02 08:06 --------- d-----w C:\Program Files\Sony Setup
2008-06-02 08:06 --------- d-----w C:\Documents and Settings\user\Application Data\Sony Setup
2008-06-02 08:02 --------- d-----w C:\Documents and Settings\user\Application Data\Sony Ericsson
2008-06-02 08:00 --------- d-----w C:\Program Files\Sony Ericsson
2008-06-02 08:00 --------- d-----w C:\Program Files\Fichiers communs\Teleca Shared
2008-06-02 08:00 --------- d-----w C:\Program Files\Fichiers communs\Sony Ericsson Shared
2008-06-02 08:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Teleca
2008-06-02 08:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sony Ericsson
2008-06-02 07:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Azureus
2008-06-01 23:24 --------- d-----w C:\Program Files\DivX
2008-06-01 15:48 2,864 ----a-w C:\WINDOWS\system32\winsock.dll
2008-06-01 08:15 --------- d-----w C:\Program Files\Alwil Software
2008-06-01 08:13 --------- d-----w C:\Program Files\FlashGet
2008-05-30 18:16 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-05-30 18:02 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-05-30 18:01 --------- d-----w C:\Program Files\Microsoft.NET
2008-05-26 10:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\OrbNetworks
2008-05-25 11:07 --------- d-----w C:\Documents and Settings\user\Application Data\Media Player Classic
2008-05-25 10:12 --------- d-----w C:\Documents and Settings\user\Application Data\Winamp
2008-05-25 09:56 --------- d-----w C:\Program Files\Fichiers communs\NSV
2008-05-25 09:43 --------- d-----w C:\Program Files\Winamp
2008-05-25 09:42 --------- d-----w C:\Program Files\Winamp Remote
2008-05-25 06:00 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-05-24 07:03 --------- d-----w C:\Program Files\MSXML 4.0
2008-05-23 16:33 --------- d-----w C:\Program Files\Windows Live
2008-05-23 16:32 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-05-23 16:21 46,592 ----a-w C:\e4bc1k.exe
2008-05-22 18:33 --------- d-----w C:\Program Files\HP
2008-05-22 18:33 --------- d-----w C:\Program Files\Fichiers communs\Hewlett-Packard
2008-05-22 18:31 43,488 ----a-w C:\WINDOWS\system32\drivers\AFS2K.SYS
2008-05-22 18:31 --------- d-----w C:\Program Files\Fichiers communs\HP
2008-05-22 16:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-05-21 19:44 --------- d-----w C:\Documents and Settings\user\Application Data\SecondLife
2008-05-21 18:11 --------- d-----w C:\Program Files\Motive
2008-05-21 18:11 --------- d-----w C:\Program Files\Club-Internet
2008-05-21 16:14 --------- d-----w C:\Program Files\Fichiers communs\Motive
2008-05-21 16:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Motive
2008-05-21 16:13 --------- d-----w C:\Program Files\Common Files
2008-05-21 16:07 155,995 ----a-w C:\WINDOWS\java\Packages\CNTR71JB.ZIP
2008-05-21 12:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\ma-config.com
2008-05-21 12:45 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-05-21 12:45 --------- d-----w C:\Program Files\Realtek
2008-05-21 12:45 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-05-21 12:19 --------- d-----w C:\Program Files\Marvell
2008-05-21 11:36 --------- d-----w C:\Program Files\Intel
2008-05-21 11:23 --------- d-----w C:\Program Files\ma-config.com
2008-05-20 16:24 --------- d-----w C:\Program Files\microsoft frontpage
2008-05-20 16:23 --------- d-----w C:\Program Files\Services en ligne
2008-05-13 01:51 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-05-13 01:51 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-30 15:27 442,368 ----a-w C:\WINDOWS\system32\NVUNINST.EXE
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 14:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-05-03 05:46 13529088]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2008-05-03 05:46 86016]
"Motive SmartBridge"="C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe" [2006-04-21 15:41 438359]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-06-25 11:24 49152]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-06-26 18:50 212992]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-04-01 20:49 36352]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2006-11-24 01:06 487424]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-07-12 22:03 413696]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
"a-squared"="C:\Program Files\a-squared Anti-Malware\a2guard.exe" [2008-07-13 14:37 2132112]
"RTHDCPL"="RTHDCPL.EXE" [2008-02-13 14:31 16857600 C:\WINDOWS\RTHDCPL.exe]
"nwiz"="nwiz.exe" [2008-05-03 05:46 1630208 C:\WINDOWS\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 14:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"VIDC.YV12"= yv12vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\FlashGet\\flashget.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"C:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"=
"C:\\Program Files\\THQ\\Frontlines-Fuel of War Demo\\Binaries\\FFOW-MPDemo.exe"=
S3 maconfservice;Ma-Config Service;C:\Program Files\ma-config.com\maconfservice.exe [2008-05-19 10:01]
S3 se44bus;Sony Ericsson Device 068 driver (WDM);C:\WINDOWS\system32\DRIVERS\se44bus.sys [2006-11-30 14:58]
S3 se44mdfl;Sony Ericsson Device 068 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\se44mdfl.sys [2006-11-30 14:58]
S3 se44mdm;Sony Ericsson Device 068 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\se44mdm.sys [2006-11-30 14:58]
S3 se44mgmt;Sony Ericsson Device 068 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\se44mgmt.sys [2006-11-30 14:58]
S3 se44nd5;Sony Ericsson Device 068 USB Ethernet Emulation SEMC44 (NDIS);C:\WINDOWS\system32\DRIVERS\se44nd5.sys [2006-11-30 14:58]
S3 se44obex;Sony Ericsson Device 068 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\se44obex.sys [2006-11-30 14:58]
S3 se44unic;Sony Ericsson Device 068 USB Ethernet Emulation SEMC44 (WDM);C:\WINDOWS\system32\DRIVERS\se44unic.sys [2006-11-30 14:58]
S3 VNUWL5B;VIA Networking Technologies USB Wireless LAN Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\VNUWL5B.SYS [2006-09-19 14:34]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\setup\rsrc\Autorun.exe
\Shell\dinstall\command - E:\Directx\dxsetup.exe
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-07-12 20:05:17 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-22 18:38:06 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1211481323.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe0/#Hewlett-Packard#hp psc 1300 series#1211481323
"2008-07-12 10:43:06 C:\WINDOWS\Tasks\HP DArC Task #Hewlett-Packard#hp psc 1300 series#1213267215.job"
- C:\Program Files\HP\hpcoretech\comp\hpdarc.exe0/#Hewlett-Packard#hp psc 1300 series#1213267215
"2008-07-13 11:22:07 C:\WINDOWS\Tasks\WebReg 20080713132206.job"
- C:\Program Files\HP\Digital Imaging\bin\hpqwrg.exeX/TaskName 20080713132206 /N
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-DXDllRegExe - dxdllreg.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-13 17:09:35
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\a-squared Anti-Malware\a2service.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-07-13 17:14:31 - machine was rebooted [user]
ComboFix-quarantined-files.txt 2008-07-13 15:13:28
Pre-Run: 299,141,906,432 octets libres
Post-Run: 299,317,370,880 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
267 --- E O F --- 2008-07-13 01:03:28
Est ce que c'est réparé ?
Merci encore en tout cas car les pubs ne s'affichent plus pour l'instant....
Caro -
Contributeur sécuritéNe fais pas toolscleaner maintenant, si tu l as fais c est pas grave...fais ceci :
télécharge combofix (par sUBs) ici :
https://forospyware.com
et enregistre le sur le Bureau.
déconnecte toi d'internet et ferme toutes tes applications.
désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)
double-clique sur combofix.exe et suis les instructions
à la fin, il va produire un rapport C:\ComboFix.txt
réactive ton parefeu, ton antivirus, la garde de ton antispyware
copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.
Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.
Tu as un tutoriel complet ici :
https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix -
Je fais tout ça mais je suis reparti pour un scan des 300 000 fichiers alors évidemment c'est un peu long....
En revanche l'antivirus tout neuf ;-))) continue à me dire que le méchant vundo cherche à se réimplanter...
Des nouvelles neuves dès la fin du scan.....
Caro -
Contributeur sécuritépas besoin de rapport hijackthis ..
fais ceci :
Pour supprimer toutes les traces des logiciels qui ont servi à traiter les infections spécifiques :
Télécharge toolscleaner sur ton Bureau : http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
* Double-clique sur ToolsCleaner2.bat et laisse le travailler
* Clique sur Recherche et laisse le scan se terminer.
* Clique sur Suppression pour finaliser.
* Tu peux, si tu le souhaites, te servir des Options facultatives.
* Clique sur Quitter, pour que le rapport puisse se créer.
* Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)...colle le dans ta réponse
Désactive et réactive la Restauration du système :
1 Dans la barre des tâches de Windows, clique sur Démarrer.
2 Clique avec le bouton droit de la souris sur Poste de travail puis clique sur Propriétés.
3 Dans l'onglet Restauration du système, coche "Désactiver la Restauration du système"
4 Clique sur Appliquer.
5 Ensuite décoche "Désactiver la restauration du systeme"
6 clique sur appliquer puis ok
ensuite :
télécharge a-squared free 3.5 à cette adresse : https://www.emsisoft.com/fr/
fais la mise à jour et analyses. -
Ca a l'air résolu et, effectivement, l'antivirus me prévient sans cesse que des Trojans veulent s'installer sur Widows/System 32/....
Tu veux un dernier rapport pour vérifier que c'est clean ?
Dois je faire un point de restauration maintenant ?
Merci
Caro
- 1
- 2