Pb malware bloque MAJ
Résolumon ordinateur a contracter un spyware , et maintenant quand je clique sur un lien, je suis amener sur un autre site , je ne suis maintenant plus capable de mettre avast a jour , j'ai le message Imposible de se connecter au serveur et sa me fait la même chose quand j'essaie d'instaler "Spypot "
je pe envoyer un rapport hijackthis peut etre? je ss un peu bcp en galere !
Configuration: Windows XP Internet Explorer 6.0
37 réponses
Une infection par spyware empêche les mises à jour d' Avast et redirige les clics de liens vers d'autres sites, sur un système Windows XP avec Internet Explorer 6. Des mesures recommandées incluent la mise à jour d'Internet Explorer et un scan en ligne via Kaspersky, puis l'utilisation de ToolsCleaner2 et CCleaner pour nettoyer le système et le registre. D'autres préconisations portent sur la désactivation puis réactivation de la restauration système, la création d'un point de restauration et le recours à Antivir avec MBAM, privilégiant Firefox et Noscript. En complément, il est suggéré de vérifier ou modifier le fichier hosts et d'envisager des extensions de sécurité comme NoScript pour Mozilla Firefox pour augmenter la vigilance lors de la navigation.
-
ModérateurSalut,
Ne te fais pas aider par plusieurs forums à la fois, risque de plantage :
http://www.infos-du-net.com/forum/284161-11-discussion#t352676 -
ModérateurBonne soirée ;)
-
mon pc a l'air de mieu fonctioner
je te remerci pour ton aide et tes conseils
je tire mon chapo ^^ ! -
ok je l'ai effacé je vais passer maintenant a la restauration du systeme
-
ModérateurIl est dans C:\Downloads\
-
je peux rechercher combofix et effacer tous les fichiers
mais je sais pas si sa suffira a le suprimer -
ModérateurComboFix, tu peux le supprimer toi-même ?
-
je n'arivé pas a trouver le rapport TCleaner
jai relancé loperation et voici le 2eme rapport . je ne trouve pas le 1er
apparement il a tout supprimer sauf combofix :
[ Rapport ToolsCleaner version 2.2.7 (par A.Rothstein & dj QUIOU) ]
-->- Recherche:
C:\Downloads\ComboFix.exe: trouvé !
---------------------------------
-->- Suppression:
C:\Downloads\ComboFix.exe: ERREUR DE SUPPRESSION !! -
Modérateur1/
---> Désinstalle HijackThis.
---> Télécharge ToolsCleaner2 sur ton Bureau.
* Double-clique sur ToolsCleaner2.exe pour le lancer.
* Clique sur Recherche et laisse le scan agir.
* Clique sur Suppression pour finaliser.
* Tu peux, si tu le souhaites, te servir des Options Facultatives.
* Clique sur Quitter pour obtenir le rapport.
* Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
2/
---> Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :
* Lance-le. Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
* Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
* Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs (Sauvegarde la base de registre).
3/
---> Il est nécessaire de désactiver puis réactiver la restauration système pour la purger :
http://www.infos-du-net.com/forum/272480-11-desactiver-activer-restauration-systeme
---> Je te conseille de créer un point de restauration que tu pourras utiliser plus tard si tu as un problème :
https://www.vulgarisation-informatique.com/creer-point-restauration.php
4/
Je te conseille Antivir à la place d'Avast :
http://www.commentcamarche.net/telecharger/telecharger 55 antivir
Conserve MBAM. Il te servira à scanner les fichiers douteux en complément de l'antivirus et scanne le disque dur régulièrement.
Comme navigateur, utilise plutôt Mozilla Firefox qu'Internet Explorer. Tu peux utiliser l'extension Noscript pour plus de sécurité.
Vérifie que les mises à jour automatiques sont bien activées (Menu Démarrer, clique droit sur Poste de travail, Onglet Mises à jour automatiques).
Tu peux aussi modifier le fichier Hosts pour améliorer la sécurité de ton PC :
http://www.commentcamarche.net/faq/sujet 5993 modifier son fichier hosts
https://blog.sosordi.net/category/articles
Par rapport au P2P :
http://www.libellules.ch/...
Voici un dossier complet (A lire avec Adobe Reader ou Foxit Reader) :
https://www.malekal.com/fichiers/projetantimalwares/prevention-protection.pdf
Sois plus vigilant sur Internet ;) -
jai ouvert le mode sans echec sans connexion , le pc a redemaré suite a loperation et voici le rapport :
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat moved successfully.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat moved successfully.
========== COMMANDS ==========
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 12172008_193321 -
ModérateurFais la manip' en mode sans échec.
---> Pour redémarrer en mode sans échec :
- Redémarre ton PC.
- Au démarrage, tapote sur F8 (F5 sur certains PC) juste après l'affichage du BIOS et juste avant le chargement de Windows.
- Dans le menu d'options avancées, choisis Mode sans échec.
- Choisis ta session. -
voici le rapport apres redemarage du pc :
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
File move failed. C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat scheduled to be moved on reboot.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\VINCE\LOCALS~1\Temp\~DF6F85.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_534.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_6fc.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 12172008_191622
Files moved on Reboot...
File move failed. C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat scheduled to be moved on reboot.
File move failed. C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat scheduled to be moved on reboot.
C:\DOCUME~1\VINCE\LOCALS~1\Temp\~DF6F85.tmp moved successfully.
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File C:\WINDOWS\temp\Perflib_Perfdata_534.dat not found!
File C:\WINDOWS\temp\Perflib_Perfdata_6fc.dat not found! -
Modérateur---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.
---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :
http://oldtimer.geekstogo.com/OTMoveIt3.exe
---> Double-clique sur OTMoveIt3.exe afin de le lancer.
---> Copie (Ctrl+C) le texte suivant ci-dessous :
:processes
explorer.exe
:files
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
:commands
[purity]
[emptytemp]
[start explorer]
[reboot]
---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.
Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.
---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log -
voici le rapport de kapersky qui a trouvé 6 fichiers avec des virus et 12 qui sont infectés :
Wednesday, December 17, 2008 7:06:16 PM
Système d'exploitation : Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version : 5.0.84.2
Dernière mise à jour de la base antivirus Kaspersky : 17/12/2008
Enregistrements dans la base antivirus Kaspersky : 1468877
Paramètres d'analyse
Analyser avec la base antivirus suivante étendue
Analyser les archives vrai
Analyser les bases de messagerie vrai
Cible de l'analyse Poste de travail
A:\
C:\
D:\
Statistiques de l'analyse
Total d'objets analysés 31777
Nombre de virus trouvés 6
Nombre d'objets infectés 12 / 0
Nombre d'objets suspects 0
Durée de l'analyse 01:21:37
Nom de l'objet infecté Nom du virus Dernière action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat L'objet est verrouillé ignoré
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Cookies\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\NTUSER.DAT L'objet est verrouillé ignoré
C:\Documents and Settings\LocalService\ntuser.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService\NTUSER.DAT L'objet est verrouillé ignoré
C:\Documents and Settings\NetworkService\ntuser.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\VINCE\Cookies\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\VINCE\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
C:\Documents and Settings\VINCE\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
C:\Documents and Settings\VINCE\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\VINCE\Local Settings\Historique\History.IE5\MSHist012008121720081218\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\VINCE\Local Settings\temp\~DF62B9.tmp L'objet est verrouillé ignoré
C:\Documents and Settings\VINCE\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
C:\Documents and Settings\VINCE\NTUSER.DAT L'objet est verrouillé ignoré
C:\Documents and Settings\VINCE\ntuser.dat.LOG L'objet est verrouillé ignoré
C:\Downloads\Grand.Theft.Auto.IV-Darkc0der\GTA IV DVD 1.iso.bc! L'objet est verrouillé ignoré
C:\Downloads\Grand.Theft.Auto.IV-Darkc0der\GTA IV DVD 2.iso.bc! L'objet est verrouillé ignoré
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat L'objet est verrouillé ignoré
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db L'objet est verrouillé ignoré
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws L'objet est verrouillé ignoré
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log L'objet est verrouillé ignoré
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log L'objet est verrouillé ignoré
C:\Program Files\Alwil Software\Avast4\DATA\log\selfdef.log L'objet est verrouillé ignoré
C:\Program Files\Alwil Software\Avast4\DATA\report\Protection résidente.txt L'objet est verrouillé ignoré
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\TDSSserv.sys.vir Infecté : Rootkit.Win32.Agent.eeq ignoré
C:\Qoobox\Quarantine\C\WINDOWS\system32\tdssadw.dll.vir Infecté : Rootkit.Win32.Clbd.ky ignoré
C:\Qoobox\Quarantine\C\WINDOWS\system32\TDSSl.dll.vir Infecté : Backdoor.Win32.TDSS.zj ignoré
C:\Qoobox\Quarantine\C\WINDOWS\system32\tdsslog.dll.vir Infecté : Backdoor.Win32.Agent.rfv ignoré
C:\Qoobox\Quarantine\C\WINDOWS\system32\tdssmain.dll.vir Infecté : Backdoor.Win32.Agent.tcb ignoré
C:\Qoobox\Quarantine\C\WINDOWS\system32\tdssserf.dll.vir Infecté : Trojan-Downloader.Win32.FraudLoad.vbxt ignoré
C:\System Volume Information\MountPointManagerRemoteDatabase L'objet est verrouillé ignoré
C:\System Volume Information\_restore{5B348BB1-EE94-4667-856D-CD2D19796466}\RP0\A0000001.sys Infecté : Rootkit.Win32.Agent.eeq ignoré
C:\System Volume Information\_restore{5B348BB1-EE94-4667-856D-CD2D19796466}\RP0\A0000040.dll Infecté : Rootkit.Win32.Clbd.ky ignoré
C:\System Volume Information\_restore{5B348BB1-EE94-4667-856D-CD2D19796466}\RP0\A0000042.dll Infecté : Backdoor.Win32.TDSS.zj ignoré
C:\System Volume Information\_restore{5B348BB1-EE94-4667-856D-CD2D19796466}\RP0\A0000043.dll Infecté : Backdoor.Win32.Agent.rfv ignoré
C:\System Volume Information\_restore{5B348BB1-EE94-4667-856D-CD2D19796466}\RP0\A0000044.dll Infecté : Backdoor.Win32.Agent.tcb ignoré
C:\System Volume Information\_restore{5B348BB1-EE94-4667-856D-CD2D19796466}\RP0\A0000045.dll Infecté : Trojan-Downloader.Win32.FraudLoad.vbxt ignoré
C:\System Volume Information\_restore{5B348BB1-EE94-4667-856D-CD2D19796466}\RP8\change.log L'objet est verrouillé ignoré
C:\WINDOWS\Debug\PASSWD.LOG L'objet est verrouillé ignoré
C:\WINDOWS\SchedLgU.Txt L'objet est verrouillé ignoré
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log L'objet est verrouillé ignoré
C:\WINDOWS\system32\CatRoot2\edb.log L'objet est verrouillé ignoré
C:\WINDOWS\system32\CatRoot2\tmp.edb L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\Antivirus.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\AppEvent.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\default L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\default.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\Internet.evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SAM L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SAM.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SecEvent.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SECURITY L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SECURITY.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\software L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\software.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\SysEvent.Evt L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\system L'objet est verrouillé ignoré
C:\WINDOWS\system32\config\system.LOG L'objet est verrouillé ignoré
C:\WINDOWS\system32\h323log.txt L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA L'objet est verrouillé ignoré
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP L'objet est verrouillé ignoré
C:\WINDOWS\temp\Perflib_Perfdata_534.dat L'objet est verrouillé ignoré
C:\WINDOWS\temp\Perflib_Perfdata_6fc.dat L'objet est verrouillé ignoré
C:\WINDOWS\temp\_avast4_\Webshlock.txt L'objet est verrouillé ignoré
C:\WINDOWS\WindowsUpdate.log L'objet est verrouillé ignoré
Analyse terminée. -
Modérateur---> Mets à jour Internet Explorer :
http://www.microsoft.com/downloads/details.aspx?FamilyId=9AE91EBE-3385-447C-8A30-081805B2F90B&displaylang=fr
- Fais un scan en ligne ici https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr (Avec Internet Explorer).
- En bas à droite, clique sur Démarrer Online-scanner.
- Dans la nouvelle fenêtre qui s'affiche, clique sur J'accepte.
- Accepte les Contrôles ActiveX.
- Choisis Poste de travail pour le scan.
- Celui-ci terminé, sauvegarde (Choisis fichier texte) et poste le rapport.
- Pour t'aider à utiliser le scan en ligne :
https://www.malekal.com/scan-antivirus-ligne-nod32/#mozTocId291566
NOTE : Si tu reçois le message La licence de Kaspersky On-line Scanner est périmée, va dans Ajout/Suppression de programmes puis désinstalle On-Line Scanner, reconnecte-toi sur le site de Kaspersky pour retenter le scan en ligne. -
je ne sais pas si mon pc est encore infécté, il rame moins qu'avant et les pages web s'affiche normalement
mais peut etre reste t'il des choses a faire ? -
voici le log :
Logfile of random's system information tool 1.04 (written by random/random)
Run by VINCE at 2008-12-16 20:13:12
Microsoft Windows XP Professionnel Service Pack 2
System drive C: has 136 GB (70%) free of 194 GB
Total RAM: 1023 MB (62% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:13:18, on 16/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Hercules\WiFi Station\WifiStation.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\BitComet\BitComet.exe
C:\WINDOWS\System32\svchost.exe
C:\Downloads\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\VINCE.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: WiFi Station.lnk = ?
O8 - Extra context menu item: &T&élécharger &avec BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &T&élécharger tout avec BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &T&élécharger toute vidéo avec BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - https://www.systemrequirementslab.com/cyri
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - https://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
-
Modérateur---> Supprime le dossier RSIT situé dans C:\
---> Refais un scan RSIT et poste les rapports. -
Modérateur---> Désinstalle Java 6 Update 7.
---> Mets à jour Java :
https://www.java.com/fr/download/manual.jsp
---> Mets à jour Adobe Reader :
https://get2.adobe.com/reader/otherversions/
---> Télécharge Malwarebytes' Anti-Malware (MBAM) sur ton Bureau.
---> Double-clique sur le fichier téléchargé pour lancer le processus d'installation.
---> Dans l'onglet Mise à jour, clique sur le bouton Recherche de mise à jour : si le pare-feu demande l'autorisation à MBAM de se connecter à Internet, accepte.
---> Une fois la mise à jour terminée, rends-toi dans l'onglet Recherche.
---> Sélectionne Exécuter un examen rapide.
---> Clique sur Rechercher. L'analyse démarre.
A la fin de l'analyse, un message s'affiche :
L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
---> Clique sur OK pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
---> Ferme tes navigateurs.
Si des malwares ont été détectés, clique sur Afficher les résultats.
---> Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre infectés et en mettre une copie dans la quarantaine.
---> MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport dans ta prochaine réponse.-
MBAM n'a rien trouvé
voici son rapport:
Malwarebytes' Anti-Malware 1.31
Version de la base de données: 1507
Windows 5.1.2600 Service Pack 2
16/12/2008 19:58:46
mbam-log-2008-12-16 (19-58-46).txt
Type de recherche: Examen rapide
Eléments examinés: 43447
Temps écoulé: 3 minute(s), 1 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
(Aucun élément nuisible détecté)
-
-
Modérateur/!\ Seul victa peut suivre cette procédure /!\
1/
---> Clique sur Démarrer, Exécuter, tape notepad clique sur OK.
---> Copie le texte ci-dessous par sélection puis Ctrl+C :
KillAll::
File::
C:\WINDOWS\system32\Agent.OMZ.Fix.exe
C:\WINDOWS\system32\gnbihsre.dll
---> Colle la sélection dans le bloc-notes
---> Enregistre ce fichier sur le bureau (Impératif)
---> Nom du fichier : CFScript
---> Type du fichier : tous les fichiers
---> Clique sur Enregistrer
---> Quitte le bloc-notes
2/
---> Fait un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe comme sur la capture :
http://www.searchengines.pl/phpbb203/pliki/picasso/virus/programs/combofix/combofix_cfscript.gif
[*] Une fenêtre bleue va apparaître : au message qui apparaît, tu acceptes.
[*] Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises : c'est normal !
Ne touche à rien tant que le scan n'est pas terminé.
[*] Une fois le scan achevé, un rapport va s'afficher : poste-le
[*] Si le fichier ne s'ouvre pas, il se trouve ici C:\ComboFix\Combofix.txt-
voici le rapport de combofix :
ComboFix 08-12-15.01 - VINCE 2008-12-16 18:19:38.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1023.637 [GMT 1:00]
Lancé depuis: c:\downloads\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\VINCE\Bureau\CFScript.txt
* Un nouveau point de restauration a été créé
[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]
FILE ::
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\gnbihsre.dll
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\gnbihsre.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-16 au 2008-12-16 ))))))))))))))))))))))))))))))))))))
.
2008-12-16 09:36 . 2008-12-16 09:36 <REP> d-------- C:\rsit
2008-12-15 15:34 . 2008-08-14 14:44 2,182,400 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-12-15 15:34 . 2008-08-14 14:44 2,138,112 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-12-15 15:34 . 2008-08-14 14:44 2,059,776 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-12-15 15:34 . 2008-08-14 14:44 2,017,792 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-12-15 15:34 . 2008-09-04 17:45 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-12-15 15:34 . 2008-10-24 12:10 453,632 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-12-15 15:34 . 2008-10-15 17:59 332,800 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-12-15 15:34 . 2008-10-03 11:17 247,326 -----c--- c:\windows\system32\dllcache\strmdll.dll
2008-12-15 15:15 . 2008-12-15 15:15 <REP> d-------- c:\program files\Trend Micro
2008-12-15 14:36 . 2008-12-15 16:32 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-14 20:27 . 2008-12-14 20:27 <REP> d-------- c:\documents and settings\All Users\Application Data\NVIDIA
2008-12-06 19:40 . 2008-12-06 19:40 <REP> d-------- c:\program files\OpenAL
2008-12-06 19:40 . 2008-12-06 19:50 413,696 --a------ c:\windows\system32\wrap_oal.dll
2008-12-06 19:40 . 2008-12-06 19:50 110,592 --a------ c:\windows\system32\OpenAL32.dll
2008-12-05 18:45 . 2008-12-16 17:23 <REP> d-------- c:\program files\PowerArchiver
2008-11-30 11:23 . 2008-11-30 11:23 573,473 --a------ c:\windows\system32\WBOCX.OCX
2008-11-30 11:23 . 2008-11-30 11:23 56,496 --a------ c:\windows\system32\WBHELP2.DLL
2008-11-29 00:33 . 2008-12-16 18:18 69 --a------ c:\windows\NeroDigital.ini
2008-11-29 00:31 . 2008-11-29 00:32 <REP> d-------- c:\program files\Fichiers communs\Ahead
2008-11-29 00:31 . 2008-11-29 00:31 <REP> d-------- c:\program files\Ahead
2008-11-29 00:31 . 2004-07-26 17:16 1,568,768 --------- c:\windows\system32\ImagX7.dll
2008-11-29 00:31 . 2004-07-26 17:16 476,320 --------- c:\windows\system32\ImagXpr7.dll
2008-11-29 00:31 . 2004-07-26 17:16 471,040 --------- c:\windows\system32\ImagXRA7.dll
2008-11-29 00:31 . 2004-07-26 17:16 262,144 --------- c:\windows\system32\ImagXR7.dll
2008-11-29 00:31 . 2001-07-09 11:50 155,648 --a------ c:\windows\system32\NeroCheck.exe
2008-11-29 00:31 . 2000-06-26 11:45 106,496 --a------ c:\windows\system32\TwnLib20.dll
2008-11-19 19:33 . 2008-11-19 19:33 <REP> d-------- c:\documents and settings\VINCE\Application Data\Capcom
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-16 12:53 --------- d-----w c:\program files\eMule
2008-12-06 18:52 --------- d-----w c:\documents and settings\All Users\Application Data\TrackMania
2008-12-06 18:44 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-26 12:47 --------- d-----w c:\program files\BitComet
2008-11-17 22:38 --------- d-----w c:\program files\Fichiers communs\InstallShield
2008-10-31 13:40 --------- d-----w c:\program files\TmNationsForever
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-09-17 18:19 74,752 ----a-w c:\windows\ST6UNST.EXE
2008-09-17 18:19 290,816 ------w c:\windows\Setup1.exe
.
((((((((((((((((((((((((((((( snapshot@2008-12-15_22.59.24.96 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-10-24 11:10:42 453,632 ------w c:\windows\Driver Cache\i386\mrxsmb.sys
+ 2008-08-14 13:44:35 2,138,112 ------w c:\windows\Driver Cache\i386\ntkrnlmp.exe
+ 2008-08-14 13:44:39 2,059,776 ------w c:\windows\Driver Cache\i386\ntkrnlpa.exe
+ 2008-08-14 13:44:33 2,017,792 ------w c:\windows\Driver Cache\i386\ntkrpamp.exe
+ 2008-08-14 13:44:37 2,182,400 ------w c:\windows\Driver Cache\i386\ntoskrnl.exe
- 2008-06-23 15:39:58 1,024,000 ----a-w c:\windows\system32\browseui.dll
+ 2008-10-16 10:38:30 1,024,000 ----a-w c:\windows\system32\browseui.dll
- 2008-06-23 15:39:58 152,064 ----a-w c:\windows\system32\cdfview.dll
+ 2008-10-16 10:38:27 152,064 ----a-w c:\windows\system32\cdfview.dll
- 2008-06-23 15:39:59 1,056,768 ----a-w c:\windows\system32\danim.dll
+ 2008-10-16 10:38:27 1,056,768 ----a-w c:\windows\system32\danim.dll
- 2008-06-20 10:44:38 138,368 -c--a-w c:\windows\system32\dllcache\afd.sys
+ 2008-08-14 09:51:43 138,368 -c--a-w c:\windows\system32\dllcache\afd.sys
- 2008-06-23 15:39:58 1,024,000 -c--a-w c:\windows\system32\dllcache\browseui.dll
+ 2008-10-16 10:38:30 1,024,000 -c--a-w c:\windows\system32\dllcache\browseui.dll
- 2008-06-23 15:39:58 152,064 -c--a-w c:\windows\system32\dllcache\cdfview.dll
+ 2008-10-16 10:38:27 152,064 -c--a-w c:\windows\system32\dllcache\cdfview.dll
- 2008-06-23 15:39:59 1,056,768 -c--a-w c:\windows\system32\dllcache\danim.dll
+ 2008-10-16 10:38:27 1,056,768 -c--a-w c:\windows\system32\dllcache\danim.dll
- 2008-06-23 15:40:00 357,888 -c--a-w c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-10-16 10:38:27 357,888 -c--a-w c:\windows\system32\dllcache\dxtmsft.dll
- 2008-06-23 15:40:00 205,312 -c--a-w c:\windows\system32\dllcache\dxtrans.dll
+ 2008-10-16 10:38:28 205,312 -c--a-w c:\windows\system32\dllcache\dxtrans.dll
- 2008-06-23 15:40:00 55,808 -c--a-w c:\windows\system32\dllcache\extmgr.dll
+ 2008-10-16 10:38:28 55,808 -c--a-w c:\windows\system32\dllcache\extmgr.dll
+ 2008-10-23 13:00:15 283,648 -c----w c:\windows\system32\dllcache\gdi32.dll
- 2008-06-23 09:49:29 18,432 -c--a-w c:\windows\system32\dllcache\iedw.exe
+ 2008-10-15 09:45:01 18,432 -c--a-w c:\windows\system32\dllcache\iedw.exe
- 2008-06-23 15:40:00 251,392 -c--a-w c:\windows\system32\dllcache\iepeers.dll
+ 2008-10-16 10:38:28 251,392 -c--a-w c:\windows\system32\dllcache\iepeers.dll
- 2008-06-23 15:40:00 96,768 -c--a-w c:\windows\system32\dllcache\inseng.dll
+ 2008-10-16 10:38:28 96,768 -c--a-w c:\windows\system32\dllcache\inseng.dll
- 2008-06-23 15:40:00 16,384 -c--a-w c:\windows\system32\dllcache\jsproxy.dll
+ 2008-10-16 10:38:29 16,384 -c--a-w c:\windows\system32\dllcache\jsproxy.dll
+ 2008-06-10 00:31:06 103,936 -c----w c:\windows\system32\dllcache\logagent.exe
- 2008-06-23 15:40:02 3,080,704 -c--a-w c:\windows\system32\dllcache\mshtml.dll
+ 2008-10-16 10:38:30 3,080,704 -c--a-w c:\windows\system32\dllcache\mshtml.dll
- 2008-06-23 15:40:03 449,024 -c--a-w c:\windows\system32\dllcache\mshtmled.dll
+ 2008-10-16 10:38:29 449,024 -c--a-w c:\windows\system32\dllcache\mshtmled.dll
- 2008-06-23 15:40:03 146,432 -c--a-w c:\windows\system32\dllcache\msrating.dll
+ 2008-10-16 10:38:28 146,432 -c--a-w c:\windows\system32\dllcache\msrating.dll
- 2008-06-23 15:40:04 532,480 -c--a-w c:\windows\system32\dllcache\mstime.dll
+ 2008-10-16 10:38:28 532,480 -c--a-w c:\windows\system32\dllcache\mstime.dll
- 2008-06-23 15:40:04 39,424 -c--a-w c:\windows\system32\dllcache\pngfilt.dll
+ 2008-10-16 10:38:28 39,424 -c--a-w c:\windows\system32\dllcache\pngfilt.dll
- 2008-06-23 15:40:05 1,495,040 -c--a-w c:\windows\system32\dllcache\shdocvw.dll
+ 2008-10-16 10:38:29 1,495,040 -c--a-w c:\windows\system32\dllcache\shdocvw.dll
- 2008-06-23 15:40:06 474,624 -c--a-w c:\windows\system32\dllcache\shlwapi.dll
+ 2008-10-16 10:38:29 474,624 -c--a-w c:\windows\system32\dllcache\shlwapi.dll
- 2004-08-03 21:14:46 336,256 -c--a-w c:\windows\system32\dllcache\srv.sys
+ 2008-08-28 10:04:17 333,056 -c--a-w c:\windows\system32\dllcache\srv.sys
- 2008-06-23 15:40:06 617,984 -c--a-w c:\windows\system32\dllcache\urlmon.dll
+ 2008-10-16 10:38:30 617,984 -c--a-w c:\windows\system32\dllcache\urlmon.dll
- 2004-08-03 22:45:58 1,836,032 -c--a-w c:\windows\system32\dllcache\win32k.sys
+ 2008-09-15 15:39:16 1,846,144 -c--a-w c:\windows\system32\dllcache\win32k.sys
- 2008-06-23 15:40:08 663,552 -c--a-w c:\windows\system32\dllcache\wininet.dll
+ 2008-10-16 10:38:29 663,552 -c--a-w c:\windows\system32\dllcache\wininet.dll
+ 2008-06-10 17:18:18 1,053,696 -c----w c:\windows\system32\dllcache\WMNetmgr.dll
+ 2008-11-07 17:32:20 2,109,440 -c----w c:\windows\system32\dllcache\WMVCore.dll
- 2008-06-20 10:44:38 138,368 ----a-w c:\windows\system32\drivers\afd.sys
+ 2008-08-14 09:51:43 138,368 ----a-w c:\windows\system32\drivers\afd.sys
- 2004-08-03 21:14:46 336,256 ----a-w c:\windows\system32\drivers\srv.sys
+ 2008-08-28 10:04:17 333,056 ----a-w c:\windows\system32\drivers\srv.sys
- 2008-06-23 15:40:00 357,888 ----a-w c:\windows\system32\dxtmsft.dll
+ 2008-10-16 10:38:27 357,888 ----a-w c:\windows\system32\dxtmsft.dll
- 2008-06-23 15:40:00 205,312 ----a-w c:\windows\system32\dxtrans.dll
+ 2008-10-16 10:38:28 205,312 ----a-w c:\windows\system32\dxtrans.dll
- 2008-06-23 15:40:00 55,808 ----a-w c:\windows\system32\extmgr.dll
+ 2008-10-16 10:38:28 55,808 ----a-w c:\windows\system32\extmgr.dll
- 2008-09-17 17:23:19 95,072 ----a-w c:\windows\system32\FNTCACHE.DAT
+ 2008-12-16 07:45:28 95,072 ----a-w c:\windows\system32\FNTCACHE.DAT
- 2004-08-19 14:09:28 278,016 ----a-w c:\windows\system32\gdi32.dll
+ 2008-10-23 13:00:15 283,648 ----a-w c:\windows\system32\gdi32.dll
- 2008-06-23 15:40:00 251,392 ----a-w c:\windows\system32\iepeers.dll
+ 2008-10-16 10:38:28 251,392 ----a-w c:\windows\system32\iepeers.dll
- 2008-06-23 15:40:00 96,768 ----a-w c:\windows\system32\inseng.dll
+ 2008-10-16 10:38:28 96,768 ----a-w c:\windows\system32\inseng.dll
- 2008-06-23 15:40:00 16,384 ----a-w c:\windows\system32\jsproxy.dll
+ 2008-10-16 10:38:29 16,384 ----a-w c:\windows\system32\jsproxy.dll
- 2004-08-19 14:09:56 103,936 ----a-w c:\windows\system32\logagent.exe
+ 2008-06-10 00:31:06 103,936 ----a-w c:\windows\system32\logagent.exe
- 2008-08-05 09:11:02 15,888,504 ----a-w c:\windows\system32\MRT.exe
+ 2008-12-09 14:24:38 17,593,280 ----a-w c:\windows\system32\MRT.exe
- 2008-06-23 15:40:02 3,080,704 ----a-w c:\windows\system32\mshtml.dll
+ 2008-10-16 10:38:30 3,080,704 ----a-w c:\windows\system32\mshtml.dll
- 2008-06-23 15:40:03 449,024 ----a-w c:\windows\system32\mshtmled.dll
+ 2008-10-16 10:38:29 449,024 ----a-w c:\windows\system32\mshtmled.dll
- 2008-06-23 15:40:03 146,432 ----a-w c:\windows\system32\msrating.dll
+ 2008-10-16 10:38:28 146,432 ----a-w c:\windows\system32\msrating.dll
- 2008-06-23 15:40:04 532,480 ----a-w c:\windows\system32\mstime.dll
+ 2008-10-16 10:38:28 532,480 ----a-w c:\windows\system32\mstime.dll
- 2004-08-19 14:09:36 1,236,480 ----a-w c:\windows\system32\msxml3.dll
+ 2008-09-04 16:45:11 1,106,944 ----a-w c:\windows\system32\msxml3.dll
- 2004-08-19 14:09:36 332,288 ----a-w c:\windows\system32\netapi32.dll
+ 2008-10-15 16:59:28 332,800 ----a-w c:\windows\system32\netapi32.dll
- 2004-08-03 23:05:42 2,058,880 ----a-w c:\windows\system32\ntkrnlpa.exe
+ 2008-08-14 13:44:39 2,059,776 ----a-w c:\windows\system32\ntkrnlpa.exe
- 2004-08-03 22:49:16 2,183,040 ----a-w c:\windows\system32\ntoskrnl.exe
+ 2008-08-14 13:44:37 2,182,400 ----a-w c:\windows\system32\ntoskrnl.exe
- 2008-06-23 15:40:04 39,424 ----a-w c:\windows\system32\pngfilt.dll
+ 2008-10-16 10:38:28 39,424 ----a-w c:\windows\system32\pngfilt.dll
- 2008-06-23 15:40:05 1,495,040 ----a-w c:\windows\system32\shdocvw.dll
+ 2008-10-16 10:38:29 1,495,040 ----a-w c:\windows\system32\shdocvw.dll
- 2008-06-23 15:40:06 474,624 ----a-w c:\windows\system32\shlwapi.dll
+ 2008-10-16 10:38:29 474,624 ----a-w c:\windows\system32\shlwapi.dll
- 2004-08-19 14:09:46 246,302 ----a-w c:\windows\system32\strmdll.dll
+ 2008-10-03 10:17:02 247,326 ----a-w c:\windows\system32\strmdll.dll
- 2008-07-14 11:09:18 62,976 ------w c:\windows\system32\tzchange.exe
+ 2008-10-22 09:47:07 62,976 ------w c:\windows\system32\tzchange.exe
- 2008-06-23 15:40:06 617,984 ----a-w c:\windows\system32\urlmon.dll
+ 2008-10-16 10:38:30 617,984 ----a-w c:\windows\system32\urlmon.dll
- 2004-08-03 22:45:58 1,836,032 ----a-w c:\windows\system32\win32k.sys
+ 2008-09-15 15:39:16 1,846,144 ----a-w c:\windows\system32\win32k.sys
- 2008-06-23 15:40:08 663,552 ----a-w c:\windows\system32\wininet.dll
+ 2008-10-16 10:38:29 663,552 ----a-w c:\windows\system32\wininet.dll
- 2004-08-19 14:09:50 1,050,624 ----a-w c:\windows\system32\wmnetmgr.dll
+ 2008-06-10 17:18:18 1,053,696 ----a-w c:\windows\system32\WMNetmgr.dll
- 2004-08-19 14:10:14 2,105,344 ----a-w c:\windows\system32\wmvcore.dll
+ 2008-11-07 17:32:20 2,109,440 ----a-w c:\windows\system32\WMVCore.dll
- 2008-07-03 09:42:35 370,176 ----a-w c:\windows\system32\xpsp3res.dll
+ 2008-10-15 19:05:28 370,176 ----a-w c:\windows\system32\xpsp3res.dll
+ 2008-04-15 17:56:59 1,724,416 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.3352_x-ww_81af8e88\GdiPlus.dll
.
-- Instantané actualisé --
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"eMuleAutoStart"="c:\program files\eMule\emule.exe" [2008-08-01 5480448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-05-11 6729728]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-05-11 86016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-08-26 413696]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-03 c:\windows\RTHDCPL.exe]
"nwiz"="nwiz.exe" [2005-05-11 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
WiFi Station.lnk - c:\program files\Hercules\WiFi Station\WifiStation.exe [2008-07-19 650240]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2 Demo\\BF2.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"24428:TCP"= 24428:TCP:BitComet 24428 TCP
"24428:UDP"= 24428:UDP:BitComet 24428 UDP
"25135:TCP"= 25135:TCP:BitComet 25135 TCP
"25135:UDP"= 25135:UDP:BitComet 25135 UDP
"23071:TCP"= 23071:TCP:BitComet 23071 TCP
"23071:UDP"= 23071:UDP:BitComet 23071 UDP
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-08-25 78416]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-08-25 20560]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.ustart.org
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: &T&élécharger &avec BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &T&élécharger tout avec BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: &T&élécharger toute vidéo avec BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
c:\windows\Downloaded Program Files\sysreqlab3.dll - O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E}
hxxp://www.srtest.com/srl_bin/sysreqlab3.cab
c:\windows\Downloaded Program Files\SysReqLab3.osd
O16 -: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - hxxp://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection_3_0_2_0.cab
c:\windows\Downloaded Program Files\hardwaredetection.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-16 18:21:56
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\windows\system32\WgaTray.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2008-12-16 18:23:51 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-12-16 17:23:08
ComboFix2.txt 2008-12-15 21:59:59
Avant-CF: 142 797 623 296 octets libres
Après-CF: 142,836,568,064 octets libres
265 --- E O F --- 2008-12-15 22:23:49
-
- 1
- 2