Aller au contenu

Reukin

Membres
  • Compteur de contenus

    29
  • Inscription

  • Dernière visite

À propos de Reukin

  • Date de naissance 22/08/1991

Profile Information

  • Sexe
    Male
  • Localisation
    Saint Denis Réunion

Autres informations

  • Mes langues
    français, anglais, allemand

Reukin's Achievements

Member

Member (4/12)

0

Réputation sur la communauté

  1. Ho merci beaucoup! ça fonctionne de nouveau! je te remercie de m'avoir suivie depuis le début, d'être attentif, et d'avoir su résoudre mes problèmes! Infiniement merci
  2. Bonjour! Oui je suis l'administrateur de l'ordinateur, et j'ai aussi essayé plusieurs fois de changer les paramètres et de les remettre ensuite en Installation automatique, mais rien n'y fait...Et je crois que cela empêche le téléchargement des mis à jour de windows. Pourtant avant celà se faisait normalement et automatiquement (comme l'option l'indique)..mais là...
  3. Bon alors quand je clique sur activer on me dit : "Désolé. Le centre de sécurité n'a pas pu modifier vos paramètres de mises à jour automatiques. Pour tenter de modifier ces paramètres vous-même, sélectionnez Système dans le Panneau de configuration. Dans l'onglet Mises à jour automatiques, sélectionner Installation automatique (recommandé), puis cliquez sur OK." Le problème c'est qu'elle est déjà cochée la case d'installation automatique! donc je ne comprends pas cette alerte...
  4. Voila le rapport de du combofix! ComboFix 08-07-22.4 - Propriétaire 2008-07-23 20:15:05.3 - NTFSx86 Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.251 [GMT 4:00] Endroit: C:\Documents and Settings\Propriétaire\Bureau\ComboFix.exe Command switches used :: C:\Documents and Settings\Propriétaire\Bureau\CFScript.txt * Création d'un nouveau point de restauration AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !! . ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-23 to 2008-07-23 )))))))))))))))))))))))))))))))))))) . 2008-07-23 19:17 . 2008-07-23 19:18 <REP> d-------- C:\Program Files\MSN Messenger 2008-07-12 16:21 . 2008-07-12 16:21 <REP> d-------- C:\SDfix 2008-07-10 16:44 . 2008-07-10 21:42 <REP> d-------- C:\Program Files\FreeCommander 2008-07-10 15:47 . 2008-07-12 17:40 <REP> d-------- C:\Program Files\Navilog1 2008-07-10 11:09 . 2007-09-02 18:13 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage r‚seau 2008-07-10 11:09 . 2007-09-02 18:13 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression 2008-07-10 11:09 . 2007-09-02 17:23 <REP> d--h----- C:\Documents and Settings\Administrateur\ModŠles 2008-07-10 11:09 . 2007-09-02 18:13 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents 2008-07-10 11:09 . 2007-09-02 18:13 <REP> dr------- C:\Documents and Settings\Administrateur\Menu D‚marrer 2008-07-10 11:09 . 2007-09-02 18:13 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris 2008-07-10 11:09 . 2007-09-02 18:13 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau 2008-07-10 11:09 . 2008-07-10 11:09 <REP> d-------- C:\Documents and Settings\Administrateur 2008-07-09 22:11 . 2003-04-24 16:00 15,597 --a------ C:\WINDOWS\system32\accserv.mib 2008-07-09 12:50 . 2008-07-09 12:50 263 --a------ C:\ftetris.cfg 2008-07-09 11:02 . 2008-07-09 11:02 <REP> d-------- C:\Documents and Settings\All Users\Application Data\POP3Profiles 2008-07-09 10:53 . 2008-07-09 10:53 <REP> d-------- C:\Program Files\Ubisoft 2008-07-09 09:37 . 2008-07-09 09:37 <REP> d-------- C:\Program Files\Lionhead Studios 2008-07-08 13:23 . 2008-07-23 19:11 54,156 --ah----- C:\WINDOWS\QTFont.qfn 2008-07-08 13:23 . 2008-07-08 13:23 1,409 --a------ C:\WINDOWS\QTFont.for 2008-07-06 18:13 . 2008-07-06 18:15 <REP> d-------- C:\Output 2008-07-06 18:12 . 2008-07-06 18:12 34 --ah----- C:\WINDOWS\system32\VideoConverter_sysquict.dat 2008-07-06 18:11 . 2008-07-14 21:21 <REP> d-------- C:\Program Files\Aglare Mp4 to AVI Converter 2008-07-05 12:10 . 2008-07-05 12:10 <REP> d-------- C:\Program Files\iTunes 2008-07-05 12:10 . 2008-07-05 12:10 <REP> d-------- C:\Program Files\iPod 2008-07-04 16:51 . 2008-07-04 16:51 <REP> d-------- C:\Program Files\LimeWire 2008-06-30 19:52 . 2008-06-30 19:52 <REP> d-------- C:\Program Files\LucasArts 2008-06-30 19:24 . 2008-06-30 19:51 <REP> d-------- C:\Program Files\Oni 2008-06-30 13:35 . 2008-06-30 13:35 <REP> d-------- C:\Program Files\Big City Adventure SF 2008-06-30 13:35 . 2008-06-30 13:35 <REP> d-------- C:\Documents and Settings\All Users\Application Data\JollyBear 2008-06-28 16:49 . 2001-08-23 17:04 12,288 --a------ C:\WINDOWS\system32\drivers\mouhid.sys 2008-06-28 16:49 . 2001-08-23 17:04 12,288 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys 2008-06-27 16:01 . 2008-06-27 16:01 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Games 2008-06-27 12:43 . 2008-06-27 12:51 <REP> d-------- C:\Program Files\RegCleaner 2008-06-25 08:57 . 2008-06-25 08:57 <REP> d-------- C:\Program Files\CAPCOM . (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M )))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-23 16:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller 2008-07-21 11:25 --------- d-----w C:\Program Files\EA GAMES 2008-07-21 06:56 --------- d-----w C:\Program Files\ICQToolbar 2008-07-20 15:56 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP 2008-07-18 13:39 --------- d-----w C:\Program Files\Starcraft 2008-07-16 13:43 --------- d-----w C:\Program Files\GraphCalc 2008-07-14 17:23 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-07-14 17:07 --------- d-----w C:\Program Files\Electronic Arts 2008-07-14 17:01 --------- d-----w C:\Program Files\KompoZer 2008-07-14 17:00 --------- d-----w C:\Program Files\Web Media Player 2008-07-07 15:20 --------- d-----w C:\Program Files\Webteh 2008-07-05 08:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer 2008-07-03 16:22 --------- d-----w C:\Program Files\Azureus 2008-06-30 09:25 --------- d-----w C:\Program Files\Microsoft Games 2008-06-22 14:54 --------- d-----w C:\Program Files\Rumble Box 2008-06-22 14:54 --------- d-----w C:\Program Files\Free Audio Pack 2008-06-22 14:52 --------- d-----w C:\Program Files\Micro Application 2008-06-21 10:53 --------- d-----w C:\Program Files\Eurobarre 2008-06-21 10:51 --------- d-----w C:\Program Files\DebugMode 2008-06-21 08:31 --------- d-----w C:\Program Files\RomStation 2008-06-19 04:56 --------- d-----w C:\Program Files\Fichiers communs\xing shared 2008-06-19 04:56 --------- d-----w C:\Program Files\Fichiers communs\Real 2008-06-19 04:55 --------- d-----w C:\Program Files\Real 2008-06-19 04:40 --------- d-----w C:\Program Files\Xi 2008-06-19 04:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Zabersoft 2008-06-14 14:48 --------- d-----w C:\Program Files\Neoact 2008-06-14 14:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\pixelStorm 2008-06-14 12:21 --------- d-----w C:\Program Files\TuneUp Utilities 2007 2008-06-14 12:19 --------- d-----w C:\Program Files\pocketstation 2008-06-14 12:18 --------- d-----w C:\Program Files\Klondike WAP Browser 2008-06-12 16:39 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys 2008-06-12 15:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESTsoft 2008-06-11 15:46 --------- d-----w C:\Program Files\Warcraft III.2 2008-06-11 11:12 --------- d-----w C:\Program Files\Bullfrog 2008-06-08 18:54 --------- d-----w C:\Program Files\TuneUp Utilities 2008 2008-06-08 18:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\TuneUp Software 2008-06-08 18:38 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard 2008-06-08 17:45 --------- d-----w C:\Program Files\Google 2008-06-08 17:41 --------- d-----w C:\Program Files\MagicISO 2008-06-03 09:16 --------- d-----w C:\Program Files\CursorXP 2008-05-31 19:01 --------- d-----w C:\Program Files\WinISO 2008-05-31 03:07 18,048 ----a-w C:\WINDOWS\system32\drivers\lirsgt.sys 2008-05-31 03:07 165,376 ----a-w C:\WINDOWS\system32\drivers\atksgt.sys 2008-05-31 03:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\SpieleEntwicklungsKombinat 2008-05-31 02:53 --------- d-----w C:\Program Files\Sunflowers 2008-05-30 12:47 --------- d-----w C:\Program Files\DAP Premium 2008-05-29 13:37 --------- d-----w C:\Program Files\Conduit 2008-05-29 13:33 --------- d-----w C:\Program Files\Zylom Games 2008-05-29 13:33 --------- d-----w C:\Program Files\Yahoo! 2008-05-29 02:57 --------- d-----w C:\Program Files\eChanblard 2008-05-26 12:16 --------- d-----w C:\Program Files\Apple Software Update 2008-05-26 12:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple 2008-05-03 09:06 2,829 ----a-w C:\WINDOWS\War3Unin.pif 2008-05-03 09:06 126,976 ----a-w C:\WINDOWS\War3Unin.exe 1998-08-24 08:09 10,000 ----a-w C:\WINDOWS\inf\unregpn.exe 2006-05-06 16:42 7,260,160 ----a-w C:\Program Files\mozilla firefox\plugins\libvlc.dll . ((((((((((((((((((((((((((((( snapshot@2008-07-14_20.46.38.68 ))))))))))))))))))))))))))))))))))))))))) . + 2008-07-23 15:18:20 29,926 ----a-r C:\WINDOWS\Installer\{1B778141-BB7A-4F1A-A02D-5A2BC640585E}\MsblIco.Exe - 2007-10-18 07:31:46 51,224 ----a-w C:\WINDOWS\system32\sirenacm.dll + 2006-06-16 10:34:44 48,936 ----a-w C:\WINDOWS\system32\sirenacm.dll + 2008-07-23 16:20:36 16,384 ----atw C:\WINDOWS\temp\Perflib_Perfdata_614.dat + 2006-03-23 07:14:36 479,232 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_0de56c07\msvcm80.dll + 2006-03-23 07:14:36 548,864 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_0de56c07\msvcp80.dll + 2006-03-23 07:14:36 626,688 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_0de56c07\msvcr80.dll . ((((((((((((((((((((((((((((((((( Point de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "STYLEXP"="C:\Program Files\TGTSoft\StyleXP\StyleXP.exe" [2006-05-24 22:31 1372160] "CursorXP"="C:\Program Files\CursorXP\CursorXP.exe" [2001-12-13 20:00 100864] "TuneUp MemOptimizer"="C:\Program Files\TuneUp Utilities 2008\MemOptimizer.exe" [2008-04-16 09:59 154368] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2007-06-29 00:43 8466432] "NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2007-06-29 00:43 81920] "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-25 18:57 262401] "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-06-19 08:55 185896] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 15:27 385024] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-14 19:05 257088] "AdslTaskBar"="stmctrl.dll" [2005-02-11 11:38 167936 C:\WINDOWS\system32\stmctrl.dll] "RTHDCPL"="RTHDCPL.EXE" [2006-04-17 11:34 16143872 C:\WINDOWS\RTHDCPL.exe] "nwiz"="nwiz.exe" [2007-06-29 00:43 1626112 C:\WINDOWS\system32\nwiz.exe] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.MFZ0"= MyFlashZip0.ax [HKLM\~\startupfolder\C:^Documents and Settings^Propriétaire^Menu Démarrer^Programmes^Démarrage^pkemu.lnk] path=C:\Documents and Settings\Propriétaire\Menu Démarrer\Programmes\Démarrage\pkemu.lnk backup=C:\WINDOWS\pss\pkemu.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck] C:\WINDOWS\system32\dumprep 0 -k [X] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadAccelerator] --a------ 2008-05-29 19:16 4568576 C:\Program Files\DAP Premium\DAP.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite] --a------ 2006-07-11 14:15 3144800 C:\Program Files\ICQLite\ICQLite.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 2008-01-10 15:27 385024 C:\Program Files\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "VideoAcceleratorService"=2 (0x2) "StarWindServiceAE"=2 (0x2) "NVSvc"=2 (0x2) "WLSetupSvc"=3 (0x3) "usnjsvc"=3 (0x3) "ose"=3 (0x3) "odserv"=3 (0x3) "idsvc"=3 (0x3) "IDriverT"=3 (0x3) "AVG Anti-Spyware Guard"=2 (0x2) "NMIndexingService"=3 (0x3) "Nero BackItUp Scheduler 3"=2 (0x2) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe" "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "NeroFilterCheck"=C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime "DownloadAccelerator"="C:\Program Files\DAP Premium\DAP.EXE" /STARTUP "NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "C:\\Program Files\\Azureus\\Azureus.exe"= "C:\\Program Files\\ATOMIX~1.4_C\\virtualdj.exe"= "C:\\Program Files\\Messenger\\msmsgs.exe"= "C:\\Program Files\\ICQLite\\ICQLite.exe"= "C:\\Program Files\\DAP Premium\\DAP.exe"= "C:\\Program Files\\Fichiers communs\\Nero\\Nero Web\\SetupX.exe"= "C:\\Program Files\\Warcraft III.2\\Warcraft III.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "C:\\Program Files\\MSN Messenger\\msncall.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "4264:UDP"= 4264:UDP:Windows Media Format SDK (webMedia0.64.1.exe) "4265:UDP"= 4265:UDP:Windows Media Format SDK (webMedia0.64.1.exe) "4266:UDP"= 4266:UDP:Windows Media Format SDK (webMedia0.64.1.exe) R2 UxTuneUp;TuneUp Extension de thème;C:\WINDOWS\System32\svchost.exe [2004-08-19 16:10] R3 Stmatm;ATM/ADSL miniport;C:\WINDOWS\system32\DRIVERS\stmatm.sys [2005-07-07 14:07] R3 TaurusUsb;ADSL Modem USB Service;C:\WINDOWS\system32\DRIVERS\torususb.sys [2005-07-07 14:11] S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-06-08 22:54] S3 V0090VID;Creative WebCam Vista Plus;C:\WINDOWS\system32\DRIVERS\V0090Vid.sys [2005-04-14 03:00] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26df01d2-3641-11dd-998f-a3e5bfaf1c67}] \Shell\Auto\command - F:\Start.exe \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53652759-6212-11dc-986e-e0bd70b41eb9}] \Shell\AutoRun\command - E:\Setup.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53652762-6212-11dc-986e-e0bd70b41eb9}] \Shell\AutoRun\command - F:\autorun.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53652763-6212-11dc-986e-e0bd70b41eb9}] \Shell\AutoRun\command - G:\autorun.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8d4571c9-627d-11dc-9872-e6555e8c0399}] \Shell\Auto\command - F:\Start.exe \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cef46339-6420-11dc-987a-b9efb98f5844}] \Shell\Auto\command - H:\Start.exe \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe . Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es' "2008-07-23 16:20:12 C:\WINDOWS\Tasks\1-Click Maintenance.job" - C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe "2008-07-23 03:02:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe "2008-07-18 13:15:00 C:\WINDOWS\Tasks\Maintenance en 1 clic.job" - C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe . - - - - ORPHANS REMOVED - - - - HKCU-Run-msnmsgr - C:\Program Files\Windows Live\Messenger\msnmsgr.exe HKU-Default-Run-CTFMON.EXE - C:\WINDOWS\System32\CTFMON.EXE MSConfigStartUp-MsnMsgr - C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-23 20:20:44 Windows 5.1.2600 Service Pack 2 NTFS Balayage processus cach‚s ... Balayage cach‚ autostart entries ... Balayage des fichiers cach‚s ... C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Microsoft\Windows\GameExplorer\{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}\PlayTasks\1\Les Sims™ 2 : [email protected] 1091 bytes hidden from API Scan termin‚ avec succŠs Les fichiers cach‚s: 1 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe C:\WINDOWS\system32\snmp.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\iPod\bin\iPodService.exe . ************************************************************************** . Temps d'accomplissement: 2008-07-23 20:25:51 - machine was rebooted ComboFix-quarantined-files.txt 2008-07-23 16:25:44 ComboFix2.txt 2008-07-23 15:57:49 ComboFix3.txt 2008-07-14 16:48:14 Pre-Run: 29,967,470,592 octets libres Post-Run: 29,951,950,848 octets libres 248 --- E O F --- 2008-05-16 12:26:03
  5. Alors voilà les rapports demandé : ComboFix 08-07-22.4 - Propriétaire 2008-07-23 19:45:43.2 - NTFSx86 Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.226 [GMT 4:00] Endroit: C:\Documents and Settings\Propriétaire\Bureau\ComboFix.exe Command switches used :: C:\Documents and Settings\Propriétaire\Bureau\CFScript.txt * Création d'un nouveau point de restauration AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !! FILE :: C:\WINDOWS\iun6002.exe . (((((((((((((((((((((((((((((((((((( Autres suppressions )))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\All Users\Application Data\BOONTY C:\Documents and Settings\All Users\Application Data\BOONTY\Licenses\B3D3B000.dat C:\WINDOWS\iun6002.exe . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_BOONTY_GAMES -------\Service_Boonty Games ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-23 to 2008-07-23 )))))))))))))))))))))))))))))))))))) . 2008-07-23 19:17 . 2008-07-23 19:18 <REP> d-------- C:\Program Files\MSN Messenger 2008-07-12 16:21 . 2008-07-12 16:21 <REP> d-------- C:\SDfix 2008-07-10 16:44 . 2008-07-10 21:42 <REP> d-------- C:\Program Files\FreeCommander 2008-07-10 15:47 . 2008-07-12 17:40 <REP> d-------- C:\Program Files\Navilog1 2008-07-10 11:09 . 2007-09-02 18:13 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage r‚seau 2008-07-10 11:09 . 2007-09-02 18:13 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression 2008-07-10 11:09 . 2007-09-02 17:23 <REP> d--h----- C:\Documents and Settings\Administrateur\ModŠles 2008-07-10 11:09 . 2007-09-02 18:13 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents 2008-07-10 11:09 . 2007-09-02 18:13 <REP> dr------- C:\Documents and Settings\Administrateur\Menu D‚marrer 2008-07-10 11:09 . 2007-09-02 18:13 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris 2008-07-10 11:09 . 2007-09-02 18:13 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau 2008-07-10 11:09 . 2008-07-10 11:09 <REP> d-------- C:\Documents and Settings\Administrateur 2008-07-09 22:11 . 2003-04-24 16:00 15,597 --a------ C:\WINDOWS\system32\accserv.mib 2008-07-09 12:50 . 2008-07-09 12:50 263 --a------ C:\ftetris.cfg 2008-07-09 11:02 . 2008-07-09 11:02 <REP> d-------- C:\Documents and Settings\All Users\Application Data\POP3Profiles 2008-07-09 10:53 . 2008-07-09 10:53 <REP> d-------- C:\Program Files\Ubisoft 2008-07-09 09:37 . 2008-07-09 09:37 <REP> d-------- C:\Program Files\Lionhead Studios 2008-07-08 13:23 . 2008-07-23 19:11 54,156 --ah----- C:\WINDOWS\QTFont.qfn 2008-07-08 13:23 . 2008-07-08 13:23 1,409 --a------ C:\WINDOWS\QTFont.for 2008-07-06 18:13 . 2008-07-06 18:15 <REP> d-------- C:\Output 2008-07-06 18:12 . 2008-07-06 18:12 34 --ah----- C:\WINDOWS\system32\VideoConverter_sysquict.dat 2008-07-06 18:11 . 2008-07-14 21:21 <REP> d-------- C:\Program Files\Aglare Mp4 to AVI Converter 2008-07-05 12:10 . 2008-07-05 12:10 <REP> d-------- C:\Program Files\iTunes 2008-07-05 12:10 . 2008-07-05 12:10 <REP> d-------- C:\Program Files\iPod 2008-07-04 16:51 . 2008-07-04 16:51 <REP> d-------- C:\Program Files\LimeWire 2008-06-30 19:52 . 2008-06-30 19:52 <REP> d-------- C:\Program Files\LucasArts 2008-06-30 19:24 . 2008-06-30 19:51 <REP> d-------- C:\Program Files\Oni 2008-06-30 13:35 . 2008-06-30 13:35 <REP> d-------- C:\Program Files\Big City Adventure SF 2008-06-30 13:35 . 2008-06-30 13:35 <REP> d-------- C:\Documents and Settings\All Users\Application Data\JollyBear 2008-06-28 16:49 . 2001-08-23 17:04 12,288 --a------ C:\WINDOWS\system32\drivers\mouhid.sys 2008-06-28 16:49 . 2001-08-23 17:04 12,288 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys 2008-06-27 16:01 . 2008-06-27 16:01 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Games 2008-06-27 12:43 . 2008-06-27 12:51 <REP> d-------- C:\Program Files\RegCleaner 2008-06-25 08:57 . 2008-06-25 08:57 <REP> d-------- C:\Program Files\CAPCOM . (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M )))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-23 15:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller 2008-07-21 11:25 --------- d-----w C:\Program Files\EA GAMES 2008-07-21 06:56 --------- d-----w C:\Program Files\ICQToolbar 2008-07-20 15:56 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP 2008-07-18 13:39 --------- d-----w C:\Program Files\Starcraft 2008-07-16 13:43 --------- d-----w C:\Program Files\GraphCalc 2008-07-14 17:23 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-07-14 17:07 --------- d-----w C:\Program Files\Electronic Arts 2008-07-14 17:01 --------- d-----w C:\Program Files\KompoZer 2008-07-14 17:00 --------- d-----w C:\Program Files\Web Media Player 2008-07-07 15:20 --------- d-----w C:\Program Files\Webteh 2008-07-05 08:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer 2008-07-03 16:22 --------- d-----w C:\Program Files\Azureus 2008-06-30 09:25 --------- d-----w C:\Program Files\Microsoft Games 2008-06-22 14:54 --------- d-----w C:\Program Files\Rumble Box 2008-06-22 14:54 --------- d-----w C:\Program Files\Free Audio Pack 2008-06-22 14:52 --------- d-----w C:\Program Files\Micro Application 2008-06-21 10:53 --------- d-----w C:\Program Files\Eurobarre 2008-06-21 10:51 --------- d-----w C:\Program Files\DebugMode 2008-06-21 08:31 --------- d-----w C:\Program Files\RomStation 2008-06-19 04:56 --------- d-----w C:\Program Files\Fichiers communs\xing shared 2008-06-19 04:56 --------- d-----w C:\Program Files\Fichiers communs\Real 2008-06-19 04:55 --------- d-----w C:\Program Files\Real 2008-06-19 04:40 --------- d-----w C:\Program Files\Xi 2008-06-19 04:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Zabersoft 2008-06-14 14:48 --------- d-----w C:\Program Files\Neoact 2008-06-14 14:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\pixelStorm 2008-06-14 12:21 --------- d-----w C:\Program Files\TuneUp Utilities 2007 2008-06-14 12:19 --------- d-----w C:\Program Files\pocketstation 2008-06-14 12:18 --------- d-----w C:\Program Files\Klondike WAP Browser 2008-06-12 16:39 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys 2008-06-12 15:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESTsoft 2008-06-11 15:46 --------- d-----w C:\Program Files\Warcraft III.2 2008-06-11 11:12 --------- d-----w C:\Program Files\Bullfrog 2008-06-08 18:54 --------- d-----w C:\Program Files\TuneUp Utilities 2008 2008-06-08 18:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\TuneUp Software 2008-06-08 18:38 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard 2008-06-08 17:45 --------- d-----w C:\Program Files\Google 2008-06-08 17:41 --------- d-----w C:\Program Files\MagicISO 2008-06-03 09:16 --------- d-----w C:\Program Files\CursorXP 2008-05-31 19:01 --------- d-----w C:\Program Files\WinISO 2008-05-31 03:07 18,048 ----a-w C:\WINDOWS\system32\drivers\lirsgt.sys 2008-05-31 03:07 165,376 ----a-w C:\WINDOWS\system32\drivers\atksgt.sys 2008-05-31 03:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\SpieleEntwicklungsKombinat 2008-05-31 02:53 --------- d-----w C:\Program Files\Sunflowers 2008-05-30 12:47 --------- d-----w C:\Program Files\DAP Premium 2008-05-29 13:37 --------- d-----w C:\Program Files\Conduit 2008-05-29 13:33 --------- d-----w C:\Program Files\Zylom Games 2008-05-29 13:33 --------- d-----w C:\Program Files\Yahoo! 2008-05-29 02:57 --------- d-----w C:\Program Files\eChanblard 2008-05-26 12:16 --------- d-----w C:\Program Files\Apple Software Update 2008-05-26 12:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple 2008-05-03 09:06 2,829 ----a-w C:\WINDOWS\War3Unin.pif 2008-05-03 09:06 126,976 ----a-w C:\WINDOWS\War3Unin.exe 1998-08-24 08:09 10,000 ----a-w C:\WINDOWS\inf\unregpn.exe 2006-05-06 16:42 7,260,160 ----a-w C:\Program Files\mozilla firefox\plugins\libvlc.dll . <pre> ----a-w 6,731,312 2008-01-09 10:03:32 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe </pre> ((((((((((((((((((((((((((((( snapshot@2008-07-14_20.46.38.68 ))))))))))))))))))))))))))))))))))))))))) . + 2008-07-23 15:18:20 29,926 ----a-r C:\WINDOWS\Installer\{1B778141-BB7A-4F1A-A02D-5A2BC640585E}\MsblIco.Exe - 2007-10-18 07:31:46 51,224 ----a-w C:\WINDOWS\system32\sirenacm.dll + 2006-06-16 10:34:44 48,936 ----a-w C:\WINDOWS\system32\sirenacm.dll + 2008-07-23 15:52:27 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_634.dat + 2006-03-23 07:14:36 479,232 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_0de56c07\msvcm80.dll + 2006-03-23 07:14:36 548,864 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_0de56c07\msvcp80.dll + 2006-03-23 07:14:36 626,688 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.91_x-ww_0de56c07\msvcr80.dll . ((((((((((((((((((((((((((((((((( Point de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "STYLEXP"="C:\Program Files\TGTSoft\StyleXP\StyleXP.exe" [2006-05-24 22:31 1372160] "CursorXP"="C:\Program Files\CursorXP\CursorXP.exe" [2001-12-13 20:00 100864] "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [N/A] "TuneUp MemOptimizer"="C:\Program Files\TuneUp Utilities 2008\MemOptimizer.exe" [2008-04-16 09:59 154368] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2007-06-29 00:43 8466432] "NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2007-06-29 00:43 81920] "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-25 18:57 262401] "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-06-19 08:55 185896] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 15:27 385024] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-14 19:05 257088] "AdslTaskBar"="stmctrl.dll" [2005-02-11 11:38 167936 C:\WINDOWS\system32\stmctrl.dll] "RTHDCPL"="RTHDCPL.EXE" [2006-04-17 11:34 16143872 C:\WINDOWS\RTHDCPL.exe] "nwiz"="nwiz.exe" [2007-06-29 00:43 1626112 C:\WINDOWS\system32\nwiz.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [N/A] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.MFZ0"= MyFlashZip0.ax [HKLM\~\startupfolder\C:^Documents and Settings^Propriétaire^Menu Démarrer^Programmes^Démarrage^pkemu.lnk] path=C:\Documents and Settings\Propriétaire\Menu Démarrer\Programmes\Démarrage\pkemu.lnk backup=C:\WINDOWS\pss\pkemu.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck] C:\WINDOWS\system32\dumprep 0 -k [X] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadAccelerator] --a------ 2008-05-29 19:16 4568576 C:\Program Files\DAP Premium\DAP.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite] --a------ 2006-07-11 14:15 3144800 C:\Program Files\ICQLite\ICQLite.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr] C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [N/A] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 2008-01-10 15:27 385024 C:\Program Files\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "VideoAcceleratorService"=2 (0x2) "StarWindServiceAE"=2 (0x2) "NVSvc"=2 (0x2) "WLSetupSvc"=3 (0x3) "usnjsvc"=3 (0x3) "ose"=3 (0x3) "odserv"=3 (0x3) "idsvc"=3 (0x3) "IDriverT"=3 (0x3) "AVG Anti-Spyware Guard"=2 (0x2) "NMIndexingService"=3 (0x3) "Nero BackItUp Scheduler 3"=2 (0x2) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe" "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "NeroFilterCheck"=C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime "DownloadAccelerator"="C:\Program Files\DAP Premium\DAP.EXE" /STARTUP "NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "C:\\Program Files\\Azureus\\Azureus.exe"= "C:\\Program Files\\ATOMIX~1.4_C\\virtualdj.exe"= "C:\\Program Files\\Messenger\\msmsgs.exe"= "C:\\Program Files\\ICQLite\\ICQLite.exe"= "C:\\Program Files\\DAP Premium\\DAP.exe"= "C:\\Program Files\\Fichiers communs\\Nero\\Nero Web\\SetupX.exe"= "C:\\Program Files\\Warcraft III.2\\Warcraft III.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "C:\\Program Files\\MSN Messenger\\msncall.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "4264:UDP"= 4264:UDP:Windows Media Format SDK (webMedia0.64.1.exe) "4265:UDP"= 4265:UDP:Windows Media Format SDK (webMedia0.64.1.exe) "4266:UDP"= 4266:UDP:Windows Media Format SDK (webMedia0.64.1.exe) R2 UxTuneUp;TuneUp Extension de thème;C:\WINDOWS\System32\svchost.exe [2004-08-19 16:10] R3 Stmatm;ATM/ADSL miniport;C:\WINDOWS\system32\DRIVERS\stmatm.sys [2005-07-07 14:07] R3 TaurusUsb;ADSL Modem USB Service;C:\WINDOWS\system32\DRIVERS\torususb.sys [2005-07-07 14:11] S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-06-08 22:54] S3 V0090VID;Creative WebCam Vista Plus;C:\WINDOWS\system32\DRIVERS\V0090Vid.sys [2005-04-14 03:00] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26df01d2-3641-11dd-998f-a3e5bfaf1c67}] \Shell\Auto\command - F:\Start.exe \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53652759-6212-11dc-986e-e0bd70b41eb9}] \Shell\AutoRun\command - E:\Setup.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53652762-6212-11dc-986e-e0bd70b41eb9}] \Shell\AutoRun\command - F:\autorun.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53652763-6212-11dc-986e-e0bd70b41eb9}] \Shell\AutoRun\command - G:\autorun.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8d4571c9-627d-11dc-9872-e6555e8c0399}] \Shell\Auto\command - F:\Start.exe \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cef46339-6420-11dc-987a-b9efb98f5844}] \Shell\Auto\command - H:\Start.exe \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe . Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es' "2008-07-23 15:52:00 C:\WINDOWS\Tasks\1-Click Maintenance.job" - C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe "2008-07-23 03:02:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe "2008-07-18 13:15:00 C:\WINDOWS\Tasks\Maintenance en 1 clic.job" - C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-23 19:52:28 Windows 5.1.2600 Service Pack 2 NTFS Balayage processus cach‚s ... Balayage cach‚ autostart entries ... Balayage des fichiers cach‚s ... C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Microsoft\Windows\GameExplorer\{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}\PlayTasks\1\Les Sims™ 2 : [email protected] 1091 bytes hidden from API Scan termin‚ avec succŠs Les fichiers cach‚s: 1 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe C:\WINDOWS\system32\snmp.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\iPod\bin\iPodService.exe . ************************************************************************** . Temps d'accomplissement: 2008-07-23 19:57:48 - machine was rebooted ComboFix-quarantined-files.txt 2008-07-23 15:57:42 ComboFix2.txt 2008-07-14 16:48:14 Pre-Run: 29,784,686,592 octets libres Post-Run: 29,983,461,376 octets libres 263 --- E O F --- 2008-05-16 12:26:03 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 19:59:42, on 23/07/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\CursorXP\CursorXP.exe C:\Program Files\TuneUp Utilities 2008\MemOptimizer.exe C:\WINDOWS\explorer.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKCU\..\Run: [sTYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe -s O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2008\MemOptimizer.exe" autostart O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP Premium\Privacy Package\dapcleanerie.htm O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP Premium\dapextie.htm O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP Premium\dapextie2.htm O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Propriétaire\Menu Démarrer\Programmes\IMVU\Run IMVU.lnk (file missing) O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe (file missing) O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe -- End of file - 6996 bytes N.B.(quelques questions que je me pose) : ·Alors que j'ai activer mes mis à jour automatique, j'ai toujours une alerte windows qui me dis que ces mis à jours automatiques ne sont pas activé...c'est pas normal ça non? ·Et on dit la console de récupération n'est pas installé sur ce systeme au début du rapport combofix, c'est autre chose que la restauration système de windows ça?puisque la mienne est activée....
  6. salut! (désolé pour la semaine d'absence) Ben j'ai essayer d'enlever la plupart des jeux par la "configuration des programmes par défaut"...et oui j'aimerais bien virer ce truc là! s'il te plaît!
  7. Ben le bureau est réapparu, l'explorateur fonctionne normalement...le processus fonctionne bien!voilà le rapport demandé : ComboFix 08-07-13.14 - Propriétaire 2008-07-14 20:26:02.1 - NTFSx86 Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.255 [GMT 4:00] Endroit: C:\Documents and Settings\Propriétaire\Mes documents\My Completed Downloads\ComboFix.exe * Création d'un nouveau point de restauration AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !! . (((((((((((((((((((((((((((((((((((( Autres suppressions )))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\system32\adptrmyhelp.dll C:\WINDOWS\system32\drivers\npf.sys C:\WINDOWS\system32\geBsppol.dll C:\WINDOWS\system32\loppsBeg.ini C:\WINDOWS\system32\loppsBeg.ini2 C:\WINDOWS\system32\mcrh.tmp C:\WINDOWS\system32\packet.dll C:\WINDOWS\system32\rtstv.ini C:\WINDOWS\system32\rtstv.ini2 C:\WINDOWS\system32\svdhost.exe C:\WINDOWS\system32\urqOfggh.dll C:\WINDOWS\system32\vybeg.ini C:\WINDOWS\system32\vybeg.ini2 C:\WINDOWS\system32\wpcap.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_DOMAINSERVICE -------\Legacy_NPF -------\Service_NPF ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-14 to 2008-07-14 )))))))))))))))))))))))))))))))))))) . 2008-07-12 16:21 . 2008-07-12 16:21 <REP> d-------- C:\SDfix 2008-07-10 16:44 . 2008-07-10 21:42 <REP> d-------- C:\Program Files\FreeCommander 2008-07-10 15:47 . 2008-07-12 17:40 <REP> d-------- C:\Program Files\Navilog1 2008-07-10 11:09 . 2007-09-02 18:13 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage r‚seau 2008-07-10 11:09 . 2007-09-02 18:13 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression 2008-07-10 11:09 . 2007-09-02 17:23 <REP> d--h----- C:\Documents and Settings\Administrateur\ModŠles 2008-07-10 11:09 . 2007-09-02 18:13 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents 2008-07-10 11:09 . 2007-09-02 18:13 <REP> dr------- C:\Documents and Settings\Administrateur\Menu D‚marrer 2008-07-10 11:09 . 2007-09-02 18:13 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris 2008-07-10 11:09 . 2007-09-02 18:13 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau 2008-07-10 11:09 . 2008-07-10 11:09 <REP> d-------- C:\Documents and Settings\Administrateur 2008-07-09 22:11 . 2003-04-24 16:00 15,597 --a------ C:\WINDOWS\system32\accserv.mib 2008-07-09 12:50 . 2008-07-09 12:50 263 --a------ C:\ftetris.cfg 2008-07-09 11:02 . 2008-07-09 11:02 <REP> d-------- C:\Documents and Settings\All Users\Application Data\POP3Profiles 2008-07-09 10:53 . 2008-07-09 10:53 <REP> d-------- C:\Program Files\Ubisoft 2008-07-09 09:37 . 2008-07-09 09:37 <REP> d-------- C:\Program Files\Lionhead Studios 2008-07-08 13:23 . 2008-07-08 13:23 54,156 --ah----- C:\WINDOWS\QTFont.qfn 2008-07-08 13:23 . 2008-07-08 13:23 1,409 --a------ C:\WINDOWS\QTFont.for 2008-07-06 18:13 . 2008-07-06 18:15 <REP> d-------- C:\Output 2008-07-06 18:12 . 2008-07-06 18:12 34 --ah----- C:\WINDOWS\system32\VideoConverter_sysquict.dat 2008-07-06 18:11 . 2008-07-06 18:12 <REP> d-------- C:\Program Files\Aglare Mp4 to AVI Converter 2008-07-05 12:10 . 2008-07-05 12:10 <REP> d-------- C:\Program Files\iTunes 2008-07-05 12:10 . 2008-07-05 12:10 <REP> d-------- C:\Program Files\iPod 2008-07-04 16:51 . 2008-07-04 16:51 <REP> d-------- C:\Program Files\LimeWire 2008-06-30 19:52 . 2008-06-30 19:52 <REP> d-------- C:\Program Files\LucasArts 2008-06-30 19:24 . 2008-06-30 19:51 <REP> d-------- C:\Program Files\Oni 2008-06-30 13:35 . 2008-06-30 13:35 <REP> d-------- C:\Program Files\Big City Adventure SF 2008-06-30 13:35 . 2008-06-30 13:35 <REP> d-------- C:\Documents and Settings\All Users\Application Data\JollyBear 2008-06-28 16:49 . 2001-08-23 17:04 12,288 --a------ C:\WINDOWS\system32\drivers\mouhid.sys 2008-06-28 16:49 . 2001-08-23 17:04 12,288 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys 2008-06-27 16:01 . 2008-06-27 16:01 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Games 2008-06-27 12:43 . 2008-06-27 12:51 <REP> d-------- C:\Program Files\RegCleaner 2008-06-25 08:57 . 2008-06-25 08:57 <REP> d-------- C:\Program Files\CAPCOM 2008-06-22 18:37 . 2008-06-22 18:37 <REP> d-------- C:\Program Files\Globe Software 2008-06-21 12:28 . 2008-06-21 12:28 604 --a------ C:\Sonic The Hedgehog 3.srm 2008-06-19 08:56 . 2008-06-19 08:56 <REP> d-------- C:\Program Files\Fichiers communs\xing shared 2008-06-19 08:55 . 2008-06-19 08:55 <REP> d-------- C:\Program Files\Real 2008-06-19 08:55 . 2008-06-19 08:56 <REP> d-------- C:\Program Files\Fichiers communs\Real 2008-06-19 08:40 . 2008-06-19 08:40 <REP> d-------- C:\Program Files\Xi 2008-06-19 08:34 . 2008-06-19 08:34 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Zabersoft 2008-06-14 18:48 . 2008-06-14 18:48 <REP> d-------- C:\Program Files\Neoact 2008-06-14 18:48 . 2006-08-17 02:46 139,264 --a------ C:\WINDOWS\NeoUninstall.exe 2008-06-14 18:48 . 2008-06-14 18:49 26 --a------ C:\WINDOWS\neosetup.INI 2008-06-14 18:37 . 2008-06-21 22:25 <REP> d-------- C:\Games 2008-06-14 18:25 . 2008-06-14 18:25 <REP> d-------- C:\Documents and Settings\All Users\Application Data\pixelStorm 2008-06-14 10:41 . 2008-06-22 18:54 <REP> d-------- C:\Program Files\Rumble Box . (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M )))))))))))))))))))))))))))))))))))))))))))))))) . 2008-07-14 15:45 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP 2008-07-09 18:10 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-07-09 18:04 --------- d-----w C:\Program Files\EA GAMES 2008-07-07 15:20 --------- d-----w C:\Program Files\Webteh 2008-07-05 08:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer 2008-07-04 05:53 --------- d-----w C:\Program Files\Electronic Arts 2008-07-03 16:22 --------- d-----w C:\Program Files\Azureus 2008-07-02 17:39 --------- d-----w C:\Program Files\ICQToolbar 2008-06-30 09:25 --------- d-----w C:\Program Files\Microsoft Games 2008-06-22 14:54 --------- d-----w C:\Program Files\Free Audio Pack 2008-06-22 14:52 --------- d-----w C:\Program Files\Micro Application 2008-06-21 10:53 --------- d-----w C:\Program Files\Eurobarre 2008-06-21 10:51 --------- d-----w C:\Program Files\DebugMode 2008-06-21 08:31 --------- d-----w C:\Program Files\RomStation 2008-06-14 12:21 --------- d-----w C:\Program Files\TuneUp Utilities 2007 2008-06-14 12:19 --------- d-----w C:\Program Files\pocketstation 2008-06-14 12:18 --------- d-----w C:\Program Files\Klondike WAP Browser 2008-06-12 16:39 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys 2008-06-12 15:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\ESTsoft 2008-06-11 17:01 --------- d-----w C:\Program Files\Starcraft 2008-06-11 15:46 --------- d-----w C:\Program Files\Warcraft III.2 2008-06-11 11:12 --------- d-----w C:\Program Files\Bullfrog 2008-06-08 18:54 --------- d-----w C:\Program Files\TuneUp Utilities 2008 2008-06-08 18:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\TuneUp Software 2008-06-08 18:38 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard 2008-06-08 17:45 --------- d-----w C:\Program Files\Google 2008-06-08 17:41 --------- d-----w C:\Program Files\MagicISO 2008-06-03 09:16 --------- d-----w C:\Program Files\CursorXP 2008-05-31 19:01 --------- d-----w C:\Program Files\WinISO 2008-05-31 03:07 18,048 ----a-w C:\WINDOWS\system32\drivers\lirsgt.sys 2008-05-31 03:07 165,376 ----a-w C:\WINDOWS\system32\drivers\atksgt.sys 2008-05-31 03:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\SpieleEntwicklungsKombinat 2008-05-31 02:53 --------- d-----w C:\Program Files\Sunflowers 2008-05-30 12:47 --------- d-----w C:\Program Files\DAP Premium 2008-05-29 13:37 --------- d-----w C:\Program Files\Conduit 2008-05-29 13:33 --------- d-----w C:\Program Files\Zylom Games 2008-05-29 13:33 --------- d-----w C:\Program Files\Yahoo! 2008-05-29 02:57 --------- d-----w C:\Program Files\eChanblard 2008-05-26 12:16 --------- d-----w C:\Program Files\Apple Software Update 2008-05-26 12:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple 2008-05-19 14:31 --------- d-----w C:\Program Files\Satsuki Decoder Pack 2008-05-15 23:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help 2008-05-14 17:51 --------- d-----w C:\Program Files\GraphCalc 2008-05-14 11:10 --------- d-----w C:\Program Files\FLVPlayer4Free 2008-05-14 08:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\BOONTY 2008-05-09 14:34 720,896 ----a-w C:\WINDOWS\iun6002.exe 2008-05-03 09:06 2,829 ----a-w C:\WINDOWS\War3Unin.pif 2008-05-03 09:06 126,976 ----a-w C:\WINDOWS\War3Unin.exe 2008-04-15 01:57 69,632 ----a-w C:\WINDOWS\ScUnin.exe 1998-08-24 08:09 10,000 ----a-w C:\WINDOWS\inf\unregpn.exe 2006-05-06 16:42 7,260,160 ----a-w C:\Program Files\mozilla firefox\plugins\libvlc.dll . <pre> ----a-w 6,731,312 2008-01-09 10:03:32 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas .exe </pre> ((((((((((((((((((((((((((((((((( Point de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "STYLEXP"="C:\Program Files\TGTSoft\StyleXP\StyleXP.exe" [2006-05-24 22:31 1372160] "CursorXP"="C:\Program Files\CursorXP\CursorXP.exe" [2001-12-13 20:00 100864] "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184] "TuneUp MemOptimizer"="C:\Program Files\TuneUp Utilities 2008\MemOptimizer.exe" [2008-04-16 09:59 154368] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2007-06-29 00:43 8466432] "NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2007-06-29 00:43 81920] "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-25 18:57 262401] "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-06-19 08:55 185896] "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 15:27 385024] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-14 19:05 257088] "AdslTaskBar"="stmctrl.dll" [2005-02-11 11:38 167936 C:\WINDOWS\system32\stmctrl.dll] "RTHDCPL"="RTHDCPL.EXE" [2006-04-17 11:34 16143872 C:\WINDOWS\RTHDCPL.exe] "nwiz"="nwiz.exe" [2007-06-29 00:43 1626112 C:\WINDOWS\system32\nwiz.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [N/A] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "VIDC.MFZ0"= MyFlashZip0.ax [HKLM\~\startupfolder\C:^Documents and Settings^Propriétaire^Menu Démarrer^Programmes^Démarrage^pkemu.lnk] path=C:\Documents and Settings\Propriétaire\Menu Démarrer\Programmes\Démarrage\pkemu.lnk backup=C:\WINDOWS\pss\pkemu.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck] C:\WINDOWS\system32\dumprep 0 -k [X] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadAccelerator] --a------ 2008-05-29 19:16 4568576 C:\Program Files\DAP Premium\DAP.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite] --a------ 2006-07-11 14:15 3144800 C:\Program Files\ICQLite\ICQLite.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr] --a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] --a------ 2008-01-10 15:27 385024 C:\Program Files\QuickTime\QTTask.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "VideoAcceleratorService"=2 (0x2) "StarWindServiceAE"=2 (0x2) "NVSvc"=2 (0x2) "WLSetupSvc"=3 (0x3) "usnjsvc"=3 (0x3) "ose"=3 (0x3) "odserv"=3 (0x3) "idsvc"=3 (0x3) "IDriverT"=3 (0x3) "AVG Anti-Spyware Guard"=2 (0x2) "NMIndexingService"=3 (0x3) "Nero BackItUp Scheduler 3"=2 (0x2) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe" "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "NeroFilterCheck"=C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime "DownloadAccelerator"="C:\Program Files\DAP Premium\DAP.EXE" /STARTUP "NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "C:\\Program Files\\Azureus\\Azureus.exe"= "C:\\Program Files\\ATOMIX~1.4_C\\virtualdj.exe"= "C:\\Program Files\\DAZ\\Bryce 5.5\\Bryce55.exe"= "C:\\Program Files\\Messenger\\msmsgs.exe"= "C:\\Program Files\\ICQLite\\ICQLite.exe"= "C:\\Program Files\\Fichiers communs\\PocketSoft\\RTPatch\\AutoRTP\\artpschd.exe"= "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"= "C:\\Program Files\\DAP Premium\\DAP.exe"= "C:\\Program Files\\Fichiers communs\\Nero\\Nero Web\\SetupX.exe"= "C:\\Program Files\\Warcraft III.2\\Warcraft III.exe"= "C:\\Program Files\\EA GAMES\\American McGee's Alice\\Alice.exe"= "C:\\Program Files\\iTunes\\iTunes.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "4264:UDP"= 4264:UDP:Windows Media Format SDK (webMedia0.64.1.exe) "4265:UDP"= 4265:UDP:Windows Media Format SDK (webMedia0.64.1.exe) "4266:UDP"= 4266:UDP:Windows Media Format SDK (webMedia0.64.1.exe) R2 UxTuneUp;TuneUp Extension de thème;C:\WINDOWS\System32\svchost.exe [2004-08-19 16:10] R3 Stmatm;ATM/ADSL miniport;C:\WINDOWS\system32\DRIVERS\stmatm.sys [2005-07-07 14:07] R3 TaurusUsb;ADSL Modem USB Service;C:\WINDOWS\system32\DRIVERS\torususb.sys [2005-07-07 14:11] S3 Boonty Games;Boonty Games;C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe [] S3 EverestDriver;Lavalys EVEREST Kernel Driver;C:\Program Files\Lavalys\EVEREST Corporate + Ultimate Edition\kerneld.wnt [2007-12-14 02:09] S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-06-08 22:54] S3 V0090VID;Creative WebCam Vista Plus;C:\WINDOWS\system32\DRIVERS\V0090Vid.sys [2005-04-14 03:00] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs UxTuneUp [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{26df01d2-3641-11dd-998f-a3e5bfaf1c67}] \Shell\Auto\command - F:\Start.exe \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53652759-6212-11dc-986e-e0bd70b41eb9}] \Shell\AutoRun\command - E:\Setup.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53652762-6212-11dc-986e-e0bd70b41eb9}] \Shell\AutoRun\command - F:\autorun.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{53652763-6212-11dc-986e-e0bd70b41eb9}] \Shell\AutoRun\command - G:\autorun.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8d4571c9-627d-11dc-9872-e6555e8c0399}] \Shell\Auto\command - F:\Start.exe \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cef46339-6420-11dc-987a-b9efb98f5844}] \Shell\Auto\command - H:\Start.exe \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe . Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es' "2008-07-14 16:39:26 C:\WINDOWS\Tasks\1-Click Maintenance.job" - C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe "2008-07-09 03:02:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe "2008-07-11 13:15:00 C:\WINDOWS\Tasks\Maintenance en 1 clic.job" - C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-14 20:39:54 Windows 5.1.2600 Service Pack 2 NTFS Balayage processus cach‚s ... Balayage cach‚ autostart entries ... Balayage des fichiers cach‚s ... C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Microsoft\Windows\GameExplorer\{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}\PlayTasks\1\Les Sims™ 2 : [email protected] 1091 bytes hidden from API ************************************************************************** [HKEY_LOCAL_MACHINE\System\ControlSet003\Services\EverestDriver] "ImagePath"="\??\C:\Program Files\Lavalys\EVEREST Corporate + Ultimate Edition\kerneld.wnt" . ------------------------ Other Running Processes ------------------------ . C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe C:\WINDOWS\system32\snmp.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\iPod\bin\iPodService.exe . ************************************************************************** . Temps d'accomplissement: 2008-07-14 20:48:13 - machine was rebooted ComboFix-quarantined-files.txt 2008-07-14 16:47:04 Pre-Run: 15,378,259,968 octets libres Post-Run: 15,288,221,696 octets libres 274 --- E O F --- 2008-05-16 12:26:03 PS: ma restauration elle est normalement activé, mais lors de cette infection on dirait qu'il m'était impossible de l'utilisé et de la réactivé...je le remet en marche dès maintenant...
  8. Alors, j'utilise en ce moment freecommander pour une alternative à l'explorateur windows...qui est dans le même état qu'avant (même en relançant le processus via le gestionnaire de tache), voilà le rapport demandé: Rebooting Checking Files : No Trojan Files Found Removing Temp Files ADS Check : Final Check : catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-07-14 18:47:39 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... IPC error: 2 Le fichier spécifié est introuvable. scanning hidden services & system hive ... [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04] "p0"="C:\Program Files\Alcohol Soft\Alcohol 120\" "h0"=dword:00000000 "ujdew"=hex:11,af,f8,1f,ad,4b,10,62,a9,53,3f,ba,7f,c5,da,7a,87,fb,1b,fc,a4,.. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04] "p0"="C:\Program Files\Alcohol Soft\Alcohol 120\" "h0"=dword:00000000 "ujdew"=hex:11,af,f8,1f,ad,4b,10,62,a9,53,3f,ba,7f,c5,da,7a,87,fb,1b,fc,a4,.. [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg] "s1"=dword:2df9c43f "s2"=dword:110480d0 "h0"=dword:00000001 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04] "p0"="C:\Program Files\Alcohol Soft\Alcohol 120\" "h0"=dword:00000000 "ujdew"=hex:11,af,f8,1f,ad,4b,10,62,a9,53,3f,ba,7f,c5,da,7a,87,fb,1b,fc,a4,.. scanning hidden registry entries ... scanning hidden files ... C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Microsoft\Windows\GameExplorer\{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}\PlayTasks\1\Les Sims™ 2 : [email protected] 1091 bytes hidden from API scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 1 Remaining Services : Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook" "C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus" "C:\\Program Files\\ATOMIX~1.4_C\\virtualdj.exe"="C:\\Program Files\\ATOMIX~1.4_C\\virtualdj.exe:*:Enabled:VirtualDJ" "C:\\Program Files\\DAZ\\Bryce 5.5\\Bryce55.exe"="C:\\Program Files\\DAZ\\Bryce 5.5\\Bryce55.exe:*:Enabled:Bryce5.5" "C:\\DOCUME~1\\PROPRI~1\\LOCALS~1\\Temp\\spoolsv.exe"="C:\\DOCUME~1\\PROPRI~1\\LOCALS~1\\Temp\\spoolsv.exe:*:Enabled:Microsoft Office" "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger" "C:\\DOCUME~1\\PROPRI~1\\LOCALS~1\\Temp\\jdwsgvmr.exe"="C:\\DOCUME~1\\PROPRI~1\\LOCALS~1\\T" "C:\\WINDOWS\\system32\\ihaxjrah.exe"="C:\\WINDOWS\\system32\\iha" "C:\\WINDOWS\\system32\\rbtdfspb.exe"="C:\\WINDOWS\\system32\\rbt" "C:\\WINDOWS\\system32\\cebdgxsv.exe"="C:\\WINDOWS\\system32\\ceb" "C:\\WINDOWS\\system32\\mdsksghr.exe"="C:\\WINDOWS\\system32\\mds" "C:\\WINDOWS\\system32\\efutunxn.exe"="C:\\WINDOWS\\system32\\efu" "C:\\WINDOWS\\system32\\cdmoctlc.exe"="C:\\WINDOWS\\system32\\cdm" "C:\\Documents and Settings\\Propri‚taire\\Bureau\\Yvan\\l illusion\\Illusion.exe"="C:\\Documents and Settings\\Propri‚taire\\Bureau\\Yvan\\l illusion\\Illusion.exe:*:Enabled:mIRC" "C:\\WINDOWS\\system32\\kdxsbdxg.exe"="C:\\WINDOWS\\system32\\kdx" "C:\\Program Files\\ICQLite\\ICQLite.exe"="C:\\Program Files\\ICQLite\\ICQLite.exe:*:Enabled:ICQ Lite" "C:\\WINDOWS\\system32\\cgawrxdi.exe"="C:\\WINDOWS\\system32\\cga" "C:\\WINDOWS\\system32\\ewshihmx.exe"="C:\\WINDOWS\\system32\\ews" "C:\\WINDOWS\\system32\\xfdctkli.exe"="C:\\WINDOWS\\system32\\xfd" "C:\\WINDOWS\\system32\\yccoqjmm.exe"="C:\\WINDOWS\\system32\\ycc" "C:\\Program Files\\Fichiers communs\\PocketSoft\\RTPatch\\AutoRTP\\artpschd.exe"="C:\\Program Files\\Fichiers communs\\PocketSoft\\RTPatch\\AutoRTP\\artpschd.exe:*:Enabled:artpschd" "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger" "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)" "C:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.0\\cnc3game.dat"="C:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.0\\cnc3game.dat:*:Enabled:Command & Conquer 3 Les guerres du TiberiumT" "C:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.9\\cnc3game.dat"="C:\\Program Files\\Electronic Arts\\Command & Conquer 3\\RetailExe\\1.9\\cnc3game.dat:*:Enabled:Command & Conquer 3 Les guerres du TiberiumT" "C:\\Program Files\\DAP Premium\\DAP.exe"="C:\\Program Files\\DAP Premium\\DAP.exe:*:Enabled:Download Accelerator Plus (DAP)" "C:\\Program Files\\Fichiers communs\\Nero\\Nero Web\\SetupX.exe"="C:\\Program Files\\Fichiers communs\\Nero\\Nero Web\\SetupX.exe:*:Enabled:Nero ControlCenter" "C:\\Program Files\\Warcraft III.2\\Warcraft III.exe"="C:\\Program Files\\Warcraft III.2\\Warcraft III.exe:*:Enabled:Warcraft III" "C:\\Program Files\\Universe At War Earth Assault\\UAWEA.exe"="C:\\Program Files\\Universe At War Earth Assault\\UAWEA.exe:*:Enabled:Universe at War: Earth Assault Application" "C:\\Sierra\\Empire Earth\\Empire Earth.exe"="C:\\Sierra\\Empire Earth\\Empire Earth.exe:*:Enabled:Empire Earth" "C:\\Program Files\\EA GAMES\\American McGee's Alice\\Alice.exe"="C:\\Program Files\\EA GAMES\\American McGee's Alice\\Alice.exe:*:Enabled:American McGee's Alice" "C:\\Program Files\\Sunflowers\\ParaWorld\\bin\\PWServer.exe"="C:\\Program Files\\Sunflowers\\ParaWorld\\bin\\PWServer.exe:*:Enabled:ParaWorld Server" "C:\\Program Files\\Fox\\Aliens vs. Predator 2\\lithtech.exe"="C:\\Program Files\\Fox\\Aliens vs. Predator 2\\lithtech.exe:*:Enabled:Client" "C:\\Program Files\\Iron Man\\IronMan.exe"="C:\\Program Files\\Iron Man\\IronMan.exe:*:Enabled:A2M Game Engine" "C:\\Program Files\\Counter-Strike\\hl2.exe"="C:\\Program Files\\Counter-Strike\\hl2.exe:*:Enabled:hl2" "C:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe"="C:\\Program Files\\Microsoft Games\\Zoo Tycoon 2\\zt.exe:*:Enabled:Zoo Tycoon 2 Executable" "C:\\Documents and Settings\\Propri‚taire\\Mes documents\\Azureus Downloads\\PC_MechWarrior4_Mercenaries.-.direct.play.request.-ToeD\\MW4M\\MW4Mercs.exe"="C:\\Documents and Settings\\Propri‚taire\\Mes documents\\Azureus Downloads\\PC_MechWarrior4_Mercenaries.-.direct.play.request.-ToeD\\MW4M\\MW4Mercs.exe:*:Enabled:MechWarrior IV" "C:\\Program Files\\LucasArts\\Star Wars Jedi Knight Jedi Academy\\GameData\\jamp.exe"="C:\\Program Files\\LucasArts\\Star Wars Jedi Knight Jedi Academy\\GameData\\jamp.exe:*:Enabled:Jedi Academy MultiPlayer" "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger" "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)" Remaining Files : Files with Hidden Attributes : Wed 13 Oct 2004 1,694,208 ..SH. --- "C:\Program Files\Messenger\msmsgs.exe" Thu 19 Aug 2004 60,416 A.SH. --- "C:\Program Files\Outlook Express\msimn.exe" Wed 13 Jun 2007 946,176 ..SHR --- "C:\WINDOWS\system32\svdhost.exe" Mon 12 Nov 2007 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak" Wed 26 Sep 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp" Thu 13 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\0a67b6c406b1d7e0f5c1e6f6d44a3f6e\BIT7A.tmp" Tue 11 Sep 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\126216e1ea5a965d65b4b02390ca8357\BIT1.tmp" Thu 13 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\18b19374451d28a8fbaf1939cf31ff45\BIT7D.tmp" Thu 6 Sep 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\1e10da77e5e1c72d2afe101dc568fb06\BIT4.tmp" Thu 13 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\22fb973e059470cc1b5d76c4ae605351\BIT81.tmp" Wed 7 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\24af2a69c06a4de03e35dc89d706475f\BIT3.tmp" Thu 13 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\26924cbc8132a10b438ce6e2b49d4652\BIT79.tmp" Thu 13 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\2769b111678c52099a3b3123b12f2325\BIT7E.tmp" Thu 13 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\30285791903730fbf957a83562db4ff4\BIT7B.tmp" Wed 17 Oct 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\388e66e644283db0233c4a98f2fd08a0\BIT3.tmp" Fri 7 Sep 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\39966a42f96cc9ad6ccb51af2492b18b\BIT5.tmp" Mon 7 Apr 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\4844df1d57a292079101da42a26d7d72\BIT3.tmp" Fri 7 Sep 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\563853df011d8b0ddaf0b39deb74f6b7\BIT4.tmp" Tue 11 Sep 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\773244b80a35d887f4682727f34cdcce\BIT2.tmp" Fri 18 Apr 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\78670cbd6a90baaa408a8a72f52fdce2\BIT2.tmp" Tue 11 Sep 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\98e4ab2cb14986b0be91146bef7a2943\BIT4.tmp" Thu 13 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\9e870549834e2bceb796e44a1e3ac6f5\BIT80.tmp" Mon 7 Apr 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\bc066f3f60df1b38218903dd0d40ce98\BIT4.tmp" Thu 13 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\cb8921d0c7830b2f33c00fa4c8a10d17\BIT7C.tmp" Tue 11 Sep 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d197838ea2d2bcacd578dd8187e9778a\BIT7.tmp" Thu 13 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d77b9b5b8fed23dd91f50d167cce60d3\BIT7F.tmp" Wed 12 Sep 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\e2ee6701f2679c24dd339050a068b193\BIT45.tmp" Tue 11 Sep 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\ef6fc5596a288b3d8c382c11203f44d4\BIT6.tmp" Fri 7 Sep 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\fa7f963668fe10ab54e5d66e86408298\BIT3.tmp" Fri 4 Jul 2008 1,332 ...HR --- "C:\Documents and Settings\Propri‚taire\Application Data\SecuROM\UserData\securom_v7_01.bak" Tue 18 Sep 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\1c2306aaf515d79b143e70a059dcb005\download\BIT17.tmp" Finished! PS : le SDFIX a bloqué après quelques minutes de recherche mon pc en mode sans échec, j'ai refait une autre fois, et ça a fait meme chose, j'ai redémarrer normalement, et il a continuer le truc, et voilà le rapport donné....
  9. A oui mince désolé!! j'ai pas fait attention à la date!!! Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 13:38:21, on 14/07/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\FreeCommander\FreeCommander.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [Windows Sound] svdhost.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [LSA Shellu] C:\Documents and Settings\Propriétaire\lsass.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\RunServices: [Windows Sound] svdhost.exe O4 - HKCU\..\Run: [sTYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe -s O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2008\MemOptimizer.exe" autostart O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP Premium\Privacy Package\dapcleanerie.htm O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP Premium\dapextie.htm O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP Premium\dapextie2.htm O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Propriétaire\Menu Démarrer\Programmes\IMVU\Run IMVU.lnk (file missing) O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{4229D580-7E9B-44D8-9B00-9894079C64A8}: NameServer = 217.175.160.168 217.175.160.12 O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Boonty Games - Unknown owner - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe (file missing) O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe (file missing) O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe -- End of file - 6195 bytes
  10. Désolé pour le retard!explorer.exe ne marche toujours pas(c'est comme la dernière fois)!voila les rapports demandé!(sauf SDFIX) Clean Navipromo version 3.6.0 commencé le 12/07/2008 à 16:10:27,17 Outil exécuté depuis C:\Program Files\navilog1 Session actuelle : "Propriétaire" Mise à jour le 27.06.2008 à 23h00 par IL-MAFIOSO Microsoft Windows XP [version 5.1.2600] Internet Explorer : 6.0.2900.2180 Système de fichiers : NTFS Mode suppression automatique avec prise en charge résultats Catchme et GNS Nettoyage exécuté au redémarrage de l'ordinateur *** fsbl1.txt non trouvé *** (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche) *** Suppression avec sauvegardes résultats GenericNaviSearch *** * Suppression dans "C:\WINDOWS\System32" * * Suppression dans "C:\Documents and Settings\Propriétaire\locals~1\applic~1" * Autres Suppressions : wceemiy.exe trouvé ! Copie wceemiy.exe réalisée avec succès ! wceemiy.exe supprimé ! wceemiy.dat trouvé ! Copie wceemiy.dat réalisée avec succès ! wceemiy.dat supprimé ! wceemiy_nav.dat trouvé ! Copie wceemiy_nav.dat réalisée avec succès ! wceemiy_nav.dat supprimé ! wceemiy_navps.dat trouvé ! Copie wceemiy_navps.dat réalisée avec succès ! wceemiy_navps.dat supprimé ! C:\WINDOWS\prefetch\wceemiy*.pf trouvé ! Copie C:\WINDOWS\prefetch\wceemiy*.pf réalisée avec succès ! C:\WINDOWS\prefetch\wceemiy*.pf supprimé ! * Suppression dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" * *** Suppression dossiers dans "C:\WINDOWS" *** *** Suppression dossiers dans "C:\Program Files" *** *** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" *** *** Suppression dossiers dans "c:\docume~1\alluse~1\menudm~1\progra~1" *** *** Suppression dossiers dans "C:\Documents and Settings\Propriétaire\applic~1" *** *** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" *** *** Suppression dossiers dans "C:\Documents and Settings\Propriétaire\locals~1\applic~1" *** *** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *** *** Suppression dossiers dans "C:\Documents and Settings\Propriétaire\menudm~1\progra~1" *** *** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\menudm~1\progra~1" *** *** Suppression fichiers *** C:\WINDOWS\system32\nvs2.inf supprimé ! *** Suppression fichiers temporaires *** Nettoyage contenu C:\WINDOWS\Temp effectué ! Nettoyage contenu C:\Documents and Settings\Propri‚taire\locals~1\Temp effectué ! *** Traitement Recherche complémentaire *** (Recherche fichiers spécifiques) 1)Suppression avec sauvegardes nouveaux fichiers Instant Access : 2)Recherche, création sauvegardes et suppression Heuristique : * Dans "C:\WINDOWS\system32" * * Dans "C:\Documents and Settings\Propriétaire\locals~1\applic~1" * joupmogne.dat trouvé ! Copie joupmogne.dat réalisée avec succès ! joupmogne.dat supprimé ! joupmogne_nav.dat trouvé ! Copie joupmogne_nav.dat réalisée avec succès ! joupmogne_nav.dat supprimé ! joupmogne_navps.dat trouvé ! Copie joupmogne_navps.dat réalisée avec succès ! joupmogne_navps.dat supprimé ! * Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" * *** Sauvegarde du Registre vers dossier Safebackup *** sauvegarde du Registre réalisée avec succès ! *** Nettoyage Registre *** Nettoyage Registre Ok *** Certificats *** Certificat Egroup supprimé ! Certificat Electronic-Group supprimé ! Certificat OOO-Favorit supprimé ! Certificat Sunny-Day-Design-Ltdt absent ! *** Nettoyage terminé le 12/07/2008 à 16:15:47,53 *** Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:35:48, on 10/07/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\WINDOWS\system32\svdhost.exe C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\CursorXP\CursorXP.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Mozilla Firefox\firefox.exe c:\program files\avira\antivir personaledition classic\avcenter.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\WINDOWS\explorer.exe C:\WINDOWS\System32\imapi.exe C:\WINDOWS\system32\control.exe C:\WINDOWS\system32\rundll32.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [Windows Sound] svdhost.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [LSA Shellu] C:\Documents and Settings\Propriétaire\lsass.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\RunServices: [Windows Sound] svdhost.exe O4 - HKCU\..\Run: [sTYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe -s O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2008\MemOptimizer.exe" autostart O4 - HKCU\..\Run: [wceemiy] c:\documents and settings\propriétaire\local settings\application data\wceemiy.exe wceemiy O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP Premium\Privacy Package\dapcleanerie.htm O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP Premium\dapextie.htm O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP Premium\dapextie2.htm O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Propriétaire\Menu Démarrer\Programmes\IMVU\Run IMVU.lnk (file missing) O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{4229D580-7E9B-44D8-9B00-9894079C64A8}: NameServer = 217.175.160.168 217.175.160.12 O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Boonty Games - Unknown owner - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe (file missing) O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe (file missing) O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe -- End of file - 6769 bytes
  11. Voici le rapport demandé! Search Navipromo version 3.6.0 commencé le 10/07/2008 à 15:49:50,23 !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!! !!! Postez ce rapport sur le forum pour le faire analyser !!! !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!! Outil exécuté depuis C:\Program Files\navilog1 Session actuelle : "Propriétaire" Mise à jour le 27.06.2008 à 23h00 par IL-MAFIOSO Microsoft Windows XP [version 5.1.2600] Internet Explorer : 6.0.2900.2180 Système de fichiers : NTFS Recherche executé en mode normal *** Recherche Programmes installés *** *** Recherche dossiers dans "C:\WINDOWS" *** *** Recherche dossiers dans "C:\Program Files" *** *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" *** *** Recherche dossiers dans "c:\docume~1\alluse~1\menudm~1\progra~1" *** *** Recherche dossiers dans "C:\Documents and Settings\Propriétaire\applic~1" *** *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" *** *** Recherche dossiers dans "C:\Documents and Settings\Propriétaire\locals~1\applic~1" *** *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *** *** Recherche dossiers dans "C:\Documents and Settings\Propriétaire\menudm~1\progra~1" *** *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\menudm~1\progra~1" *** *** Recherche avec Catchme-rootkit/stealth malware detector par gmer *** pour + d'infos : http://www.gmer.net Aucun Fichier trouvé *** Recherche avec GenericNaviSearch *** !!! Tous ces résultats peuvent révéler des fichiers légitimes !!! !!! A vérifier impérativement avant toute suppression manuelle !!! * Recherche dans "C:\WINDOWS\system32" * * Recherche dans "C:\Documents and Settings\Propriétaire\locals~1\applic~1" * Fichiers suspects : wceemiy.exe trouvé ! wceemiy.dat trouvé ! wceemiy_nav.dat trouvé ! wceemiy_navps.dat trouvé ! * Recherche dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" * *** Recherche fichiers *** C:\WINDOWS\system32\nvs2.inf trouvé ! *** Recherche clés spécifiques dans le Registre *** *** Module de Recherche complémentaire *** (Recherche fichiers spécifiques) 1)Recherche nouveaux fichiers Instant Access : 2)Recherche Heuristique : * Dans "C:\WINDOWS\system32" : * Dans "C:\Documents and Settings\Propriétaire\locals~1\applic~1" : joupmogne.dat trouvé ! joupmogne_nav.dat trouvé ! joupmogne_navps.dat trouvé ! wceemiy.dat trouvé ! wceemiy_nav.dat trouvé ! wceemiy_navps.dat trouvé ! * Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" : 3)Recherche Certificats : Certificat Egroup trouvé ! Certificat Electronic-Group trouvé ! Certificat OOO-Favorit trouvé ! Certificat Sunny-Day-Design-Ltd absent ! 4)Recherche fichiers connus : C:\WINDOWS\system32\loppsBeg.ini2 trouvé ! infection Vundo possible non traitée par cet outil ! C:\WINDOWS\system32\rtstv.ini2 trouvé ! infection Vundo possible non traitée par cet outil ! C:\WINDOWS\system32\vybeg.ini2 trouvé ! infection Vundo possible non traitée par cet outil ! *** Analyse terminée le 10/07/2008 à 15:57:54,42 *** PS: je vois l'infection par Vundo, dois-je utilisé VundoFix?
  12. Bonjour! Alors depuis hier après midi, sans avoir fait quoi que ce soit d'inhabituel (sauf laisser mon petit cousin de 6 ans sur l'ordi, internet allumer, sans que je sois là durant quelques heures) j'ai un petit problème avec l'explorateur windows... Alors le soir j'arrive tout fonctionne, je joue un jeu et là le jeu se plante, je redémarre le PC et puis le processus explorer.exe démarre, s'arrête, démarre, s'arrête, puis s'arrête... totalement. J'ai essayé de relancer le processus de part le gestionnaire de tâche mais, le processus se lance puis s'arrête après quelques seconde (c'est grâce à ces quelques seconde que j'ai pu me connecter et lancer certaine recherche à ce sujet, mais en vain.) En effet, je précise que le processus s'arrête sans message d'erreur, et en mode sans échec le processus s'arrête aussi. Ce qui me pose un sérieux problème ; j'ai pu lancer une analyse avec mon antivir la nuit dernière, ce qui m'étonne c'est qu'il y a eu 1 seule détection, qui fut mis en quarantaine... (cette démarche d'analyse n'a pas pu etre fait en mode sans échec, le temps que le processus explorer.exe reste en fonction n'est que d'une fraction seconde)... Alors j'ai réussi tout juste a click sur le raccourci d'hijackthis..je vous envoie le rapport de mon antivir et d'hijackthis... PS: On m'a déjà averti pour l'illégalité, et les problèmes que peut engendré les crack de jeu...et puis je ne pense pas que ce soit l'un d'eux puisque la dernière installation n'a pas encore provoqué de problème visible et si encombrant que celui-là... PS.Bis : Hier j'ai téléchargé un petit jeu de tetris free mon petit cousin, bon j'ai désinstaller...enfin voilà un autre info qui pourrait être utile... Avira AntiVir Personal Report file date: mercredi 9 juillet 2008 22:53 Scanning for 1399497 virus strains and unwanted programs. Licensed to: Avira AntiVir PersonalEdition Classic Serial number: 0000149996-ADJIE-0001 Platform: Windows XP Windows version: (Service Pack 2) [5.1.2600] Boot mode: Normally booted Username: SYSTEM Computer name: HIGHTECH Version information: BUILD.DAT : 8.1.0.308 16478 Bytes 28/05/2008 17:03:00 AVSCAN.EXE : 8.1.2.12 311553 Bytes 25/04/2008 14:58:00 AVSCAN.DLL : 8.1.1.0 53505 Bytes 25/04/2008 14:58:00 LUKE.DLL : 8.1.2.9 151809 Bytes 25/04/2008 14:58:01 LUKERES.DLL : 8.1.2.1 12033 Bytes 25/04/2008 14:58:01 ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 13:44:41 ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 14:56:06 ANTIVIR2.VDF : 7.0.5.51 273408 Bytes 04/07/2008 14:56:27 ANTIVIR3.VDF : 7.0.5.81 281600 Bytes 09/07/2008 14:49:44 Engineversion : 8.1.0.64 AEVDF.DLL : 8.1.0.5 102772 Bytes 25/04/2008 14:58:02 AESCRIPT.DLL : 8.1.0.46 283002 Bytes 04/07/2008 14:56:56 AESCN.DLL : 8.1.0.22 119157 Bytes 21/06/2008 14:48:45 AERDL.DLL : 8.1.0.20 418165 Bytes 25/04/2008 14:58:02 AEPACK.DLL : 8.1.1.6 364918 Bytes 21/06/2008 14:48:42 AEOFFICE.DLL : 8.1.0.20 192891 Bytes 21/06/2008 14:48:36 AEHEUR.DLL : 8.1.0.35 1298806 Bytes 04/07/2008 14:56:52 AEHELP.DLL : 8.1.0.15 115063 Bytes 30/05/2008 14:49:37 AEGEN.DLL : 8.1.0.29 307573 Bytes 21/06/2008 14:48:18 AEEMU.DLL : 8.1.0.6 430451 Bytes 08/05/2008 14:39:25 AECORE.DLL : 8.1.0.32 168311 Bytes 04/07/2008 14:56:33 AVWINLL.DLL : 1.0.0.7 14593 Bytes 25/04/2008 14:58:00 AVPREF.DLL : 8.0.0.1 25857 Bytes 25/04/2008 14:58:00 AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 10:16:24 AVREG.DLL : 8.0.0.0 30977 Bytes 25/04/2008 14:58:00 AVARKT.DLL : 1.0.0.23 307457 Bytes 25/04/2008 14:57:59 AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 25/04/2008 14:57:59 SQLITE3.DLL : 3.3.17.1 339968 Bytes 25/04/2008 14:58:01 SMTPLIB.DLL : 1.2.0.19 28929 Bytes 25/04/2008 14:58:01 NETNT.DLL : 8.0.0.1 7937 Bytes 25/04/2008 14:58:01 RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 25/04/2008 14:57:53 RCTEXT.DLL : 8.0.32.0 86273 Bytes 25/04/2008 14:57:53 Configuration settings for the scan: Jobname..........................: Complete system scan Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp Logging..........................: low Primary action...................: interactive Secondary action.................: ignore Scan master boot sector..........: on Scan boot sector.................: on Boot sectors.....................: C:, Scan memory......................: on Process scan.....................: on Scan registry....................: on Search for rootkits..............: off Scan all files...................: Intelligent file selection Scan archives....................: on Recursion depth..................: 20 Smart extensions.................: on Macro heuristic..................: on File heuristic...................: medium Start of the scan: mercredi 9 juillet 2008 22:53 The scan of running processes will be started Scan process 'explorer.exe' - '1' Module(s) have been scanned Scan process 'avscan.exe' - '1' Module(s) have been scanned Scan process 'avcenter.exe' - '1' Module(s) have been scanned Scan process 'Azureus.exe' - '1' Module(s) have been scanned Scan process 'DAP.exe' - '1' Module(s) have been scanned Scan process 'wscntfy.exe' - '1' Module(s) have been scanned Scan process 'alg.exe' - '1' Module(s) have been scanned Scan process 'iPodService.exe' - '1' Module(s) have been scanned Scan process 'wceemiy.exe' - '1' Module(s) have been scanned Scan process 'MemOptimizer.exe' - '1' Module(s) have been scanned Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned Scan process 'CursorXP.exe' - '1' Module(s) have been scanned Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'snmp.exe' - '1' Module(s) have been scanned Scan process 'sched.exe' - '1' Module(s) have been scanned Scan process 'realsched.exe' - '1' Module(s) have been scanned Scan process 'svdhost.exe' - '1' Module(s) have been scanned Scan process 'avgnt.exe' - '1' Module(s) have been scanned Scan process 'rundll32.exe' - '1' Module(s) have been scanned Scan process 'RTHDCPL.exe' - '1' Module(s) have been scanned Scan process 'rundll32.exe' - '1' Module(s) have been scanned Scan process 'avguard.exe' - '1' Module(s) have been scanned Scan process 'spoolsv.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'lsass.exe' - '1' Module(s) have been scanned Scan process 'services.exe' - '1' Module(s) have been scanned Scan process 'winlogon.exe' - '1' Module(s) have been scanned Scan process 'csrss.exe' - '1' Module(s) have been scanned Scan process 'smss.exe' - '1' Module(s) have been scanned 34 processes with 34 modules were scanned Starting master boot sector scan: Master boot sector HD0 [iNFO] No virus was found! Start scanning boot sectors: Boot sector 'C:\' [iNFO] No virus was found! Starting to scan the registry. The registry was scanned ( '27' files ). Starting the file scan: Begin scan in 'C:\' <DivX> C:\pagefile.sys [WARNING] The file could not be opened! C:\Documents and Settings\Propriétaire\Mes documents\Azureus Downloads\TuneUp\TuneUp Utilities 2008 v7.0.8002\keygen.exe [DETECTION] Is the Trojan horse TR/PSW.LdPinch.uij [NOTE] The file was moved to '48ee840b.qua'! C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP104\A0046135.exe [DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/Agent.VB.P Backdoor server programs [NOTE] The file was moved to '48a58fc1.qua'! C:\WINDOWS\system32\drivers\sptd.sys [WARNING] The file could not be opened! End of the scan: jeudi 10 juillet 2008 08:42 Used time: 9:48:46 min The scan has been done completely. 11228 Scanning directories 484552 Files were scanned 2 viruses and/or unwanted programs were found 0 Files were classified as suspicious: 0 files were deleted 0 files were repaired 2 files were moved to quarantine 0 files were renamed 2 Files cannot be scanned 484550 Files not concerned 4634 Archives were scanned 2 Warnings 2 Notes Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:35:48, on 10/07/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\WINDOWS\system32\svdhost.exe C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\System32\snmp.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\CursorXP\CursorXP.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Mozilla Firefox\firefox.exe c:\program files\avira\antivir personaledition classic\avcenter.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\WINDOWS\explorer.exe C:\WINDOWS\System32\imapi.exe C:\WINDOWS\system32\control.exe C:\WINDOWS\system32\rundll32.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll O4 - HKLM\..\Run: [AdslTaskBar] rundll32.exe stmctrl.dll,TaskBar O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [Windows Sound] svdhost.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [LSA Shellu] C:\Documents and Settings\Propriétaire\lsass.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\RunServices: [Windows Sound] svdhost.exe O4 - HKCU\..\Run: [sTYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide O4 - HKCU\..\Run: [CursorXP] C:\Program Files\CursorXP\CursorXP.exe -s O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [TuneUp MemOptimizer] "C:\Program Files\TuneUp Utilities 2008\MemOptimizer.exe" autostart O4 - HKCU\..\Run: [wceemiy] c:\documents and settings\propriétaire\local settings\application data\wceemiy.exe wceemiy O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: &Clean Traces - C:\Program Files\DAP Premium\Privacy Package\dapcleanerie.htm O8 - Extra context menu item: &Download with &DAP - C:\Program Files\DAP Premium\dapextie.htm O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML O8 - Extra context menu item: Download &all with DAP - C:\Program Files\DAP Premium\dapextie2.htm O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Propriétaire\Menu Démarrer\Programmes\IMVU\Run IMVU.lnk (file missing) O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{4229D580-7E9B-44D8-9B00-9894079C64A8}: NameServer = 217.175.160.168 217.175.160.12 O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Boonty Games - Unknown owner - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe (file missing) O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe (file missing) O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe -- End of file - 6769 bytes
  13. oki...c'est pas une escuse mais ce dossier je l'ai pas téléchargé! mais je l'ai utilisé, et l'ai mis sur mon disque dur ( ce qui fait de moi le principale fautif, surtout avec tout les autres fichiers)...je l'ai supprimer maintenant..merci beaucoup beaucoup à toi!J'ai regaré les forums cités, c'est vrai qu'on change de regard par rapport à tout ça après, mais bon...j'ai aussi pris le FiXSFlog..c'est pas pour lancer une polémique, mais le peer to peer c'est à nos risque et péril non?il y a quelques années j'étais beaucoup moins vigilants, je prends autant de risques mais maintenant beaucoup plus mesuré...je te remercie encore une fois puisque j'ai pu apprendre certains choses grâce à ces forums (mais j'ai pas changé d'avis lol)...merci merci encore!
  14. Bonjour! Voici le rapport d'ANTIVIR! Avira AntiVir Personal Report file date: samedi 31 mai 2008 23:49 Scanning for 1302528 virus strains and unwanted programs. Licensed to: Avira AntiVir PersonalEdition Classic Serial number: 0000149996-ADJIE-0001 Platform: Windows XP Windows version: (Service Pack 2) [5.1.2600] Boot mode: Normally booted Username: SYSTEM Computer name: HIGHTECH Version information: BUILD.DAT : 8.1.0.308 16478 Bytes 28/05/2008 17:03:00 AVSCAN.EXE : 8.1.2.12 311553 Bytes 25/04/2008 14:58:00 AVSCAN.DLL : 8.1.1.0 53505 Bytes 25/04/2008 14:58:00 LUKE.DLL : 8.1.2.9 151809 Bytes 25/04/2008 14:58:01 LUKERES.DLL : 8.1.2.1 12033 Bytes 25/04/2008 14:58:01 ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 13:44:41 ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 14:07:54 ANTIVIR2.VDF : 7.0.4.53 1848832 Bytes 17/05/2008 14:46:15 ANTIVIR3.VDF : 7.0.4.118 376832 Bytes 30/05/2008 14:47:39 Engineversion : 8.1.0.51 AEVDF.DLL : 8.1.0.5 102772 Bytes 25/04/2008 14:58:02 AESCRIPT.DLL : 8.1.0.37 270715 Bytes 30/05/2008 14:50:22 AESCN.DLL : 8.1.0.20 119157 Bytes 30/05/2008 14:49:47 AERDL.DLL : 8.1.0.20 418165 Bytes 25/04/2008 14:58:02 AEPACK.DLL : 8.1.1.5 364918 Bytes 18/05/2008 14:48:53 AEOFFICE.DLL : 8.1.0.18 192890 Bytes 25/04/2008 14:58:02 AEHEUR.DLL : 8.1.0.29 1253750 Bytes 18/05/2008 14:48:31 AEHELP.DLL : 8.1.0.15 115063 Bytes 30/05/2008 14:49:37 AEGEN.DLL : 8.1.0.25 307573 Bytes 31/05/2008 14:47:18 AEEMU.DLL : 8.1.0.6 430451 Bytes 08/05/2008 14:39:25 AECORE.DLL : 8.1.0.30 168311 Bytes 30/05/2008 14:47:58 AVWINLL.DLL : 1.0.0.7 14593 Bytes 25/04/2008 14:58:00 AVPREF.DLL : 8.0.0.1 25857 Bytes 25/04/2008 14:58:00 AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 10:16:24 AVREG.DLL : 8.0.0.0 30977 Bytes 25/04/2008 14:58:00 AVARKT.DLL : 1.0.0.23 307457 Bytes 25/04/2008 14:57:59 AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 25/04/2008 14:57:59 SQLITE3.DLL : 3.3.17.1 339968 Bytes 25/04/2008 14:58:01 SMTPLIB.DLL : 1.2.0.19 28929 Bytes 25/04/2008 14:58:01 NETNT.DLL : 8.0.0.1 7937 Bytes 25/04/2008 14:58:01 RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 25/04/2008 14:57:53 RCTEXT.DLL : 8.0.32.0 86273 Bytes 25/04/2008 14:57:53 Configuration settings for the scan: Jobname..........................: Complete system scan Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp Logging..........................: low Primary action...................: interactive Secondary action.................: ignore Scan master boot sector..........: on Scan boot sector.................: on Boot sectors.....................: C:, Scan memory......................: on Process scan.....................: on Scan registry....................: on Search for rootkits..............: off Scan all files...................: Intelligent file selection Scan archives....................: on Recursion depth..................: 20 Smart extensions.................: on Macro heuristic..................: on File heuristic...................: medium Start of the scan: samedi 31 mai 2008 23:49 The scan of running processes will be started Scan process 'avscan.exe' - '1' Module(s) have been scanned Scan process 'avcenter.exe' - '1' Module(s) have been scanned Scan process 'SuperCopier2.exe' - '1' Module(s) have been scanned Scan process 'avgnt.exe' - '1' Module(s) have been scanned Scan process 'avguard.exe' - '1' Module(s) have been scanned Scan process 'alg.exe' - '1' Module(s) have been scanned Scan process 'qsujozu.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'sched.exe' - '1' Module(s) have been scanned Scan process 'rundll32.exe' - '1' Module(s) have been scanned Scan process 'RTHDCPL.exe' - '1' Module(s) have been scanned Scan process 'rundll32.exe' - '1' Module(s) have been scanned Scan process 'explorer.exe' - '1' Module(s) have been scanned Scan process 'spoolsv.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'StyleXPService.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'lsass.exe' - '1' Module(s) have been scanned Scan process 'services.exe' - '1' Module(s) have been scanned Scan process 'winlogon.exe' - '1' Module(s) have been scanned Scan process 'csrss.exe' - '1' Module(s) have been scanned Scan process 'smss.exe' - '1' Module(s) have been scanned 25 processes with 25 modules were scanned Starting master boot sector scan: Master boot sector HD0 [iNFO] No virus was found! Start scanning boot sectors: Boot sector 'C:\' [iNFO] No virus was found! Starting to scan the registry. The registry was scanned ( '22' files ). Starting the file scan: Begin scan in 'C:\' <DivX> C:\pagefile.sys [WARNING] The file could not be opened! C:\DiscD\jeux\Office 2007 Pro. FR {final v12 + serial - Windows 2003, XP & Vista}.rar [WARNING] An exception has been identified! [WARNING] In the module 'aecore.dll' an exception occured. Calling the function AVEPROC_TestFile in file: \\?\C:\DiscD\jeux\Office 2007 Pro. FR {final v12 + serial - Windows 2003, XP & Vista}.rar Error description:ACCESS_VIOLATION EAX = 0A483EE8 EBX = 02970AA8 ECX = 0A483EC4 EDX = 00000331 ESI = 09F99C50 EDI = 02970aa4 EIP = 0134C733 EBP = 0A39007C ESP = 01BFF05C Flg = 00010283 CS = 00000023 SS = 0000001B C:\Documents and Settings\Propriétaire\.bitrock\.bitrock.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] The file was deleted! C:\Documents and Settings\Propriétaire\Application Data\Application Data.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] The file was deleted! C:\Documents and Settings\Propriétaire\Application Data\Banque Française Commerciale Océan Indien - Mozilla Firefox.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] The file was deleted! C:\Documents and Settings\Propriétaire\Application Data\BFCOI Online - Mozilla Firefox.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48851567.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Documents and Settings\Propriétaire\Application Data\lsass.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48a31594.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Documents and Settings\Propriétaire\Application Data\smss.VIR [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48b5158e.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Documents and Settings\Propriétaire\Application Data\svchost.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48a51598.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Documents and Settings\Propriétaire\avidemux\avidemux.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48ab15de.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Documents and Settings\Propriétaire\Bureau\Yvan\nuke\hydrotruc\hydrotruc.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48a617a8.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Documents and Settings\Propriétaire\Bureau\Yvan\nuke\TPE nucléaire Word\TPE nucléaire Word.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48871784.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Documents and Settings\Propriétaire\Contacts\Contacts.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48b01833.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Documents and Settings\Propriétaire\Cookies\Cookies.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48b1183c.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Documents and Settings\Propriétaire\dwhelper\dwhelper.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48aa1848.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Documents and Settings\Propriétaire\Favoris\Favoris.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48b81832.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Documents and Settings\Propriétaire\Local Settings\Local Settings.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48a51841.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Documents and Settings\Propriétaire\Local Settings\Temporary Internet Files\Content.IE5\K9W9O7Q9\style[1].css [DETECTION] Contains detection pattern of the Java script virus JS/Redirector.A [NOTE] A backup was created as '48bb190b.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Documents and Settings\Propriétaire\Menu Démarrer\Menu Démarrer.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48b0196d.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Documents and Settings\Propriétaire\Mes documents\Mes documents.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48b51970.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Documents and Settings\Propriétaire\Mes documents\My Completed Downloads\Age_of_Mythology_The_Titans_Expansion.txt.exe.dap [0] Archive type: RAR SFX (self extracting) --> keygen.exe [DETECTION] Is the Trojan horse TR/Vundo.Gen [NOTE] A backup was created as '48a71bcc.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Documents and Settings\Propriétaire\Modèles\Modèles.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48a61c84.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Documents and Settings\Propriétaire\Recent\Recent.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48a51c7f.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Documents and Settings\Propriétaire\SendTo\SendTo.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48b01c80.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Documents and Settings\Propriétaire\UserData\UserData.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48a71c8e.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Documents and Settings\Propriétaire\Voisinage d'impression\Voisinage d'impression.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48ab1c8b.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Documents and Settings\Propriétaire\Voisinage réseau\Voisinage réseau.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '49d752cc.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Documents and Settings\Propriétaire\WINDOWS\WINDOWS.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48901c66.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Program Files\Starcraft\Demonic Terrans.exe [DETECTION] Is the Trojan horse TR/Dropper.Gen [NOTE] A backup was created as '48af25b8.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Program Files\Starcraft\fastermod.exe [DETECTION] Is the Trojan horse TR/Dropper.Gen [NOTE] A backup was created as '48b525b5.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Program Files\Starcraft\Realistic.exe [DETECTION] Is the Trojan horse TR/Dropper.Gen [NOTE] A backup was created as '48a325ba.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Program Files\Starcraft\Realistic1.5.exe [DETECTION] Is the Trojan horse TR/Dropper.Gen [NOTE] A backup was created as '49d8631b.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Program Files\Starcraft\SC_Revolutions.exe [DETECTION] Is the Trojan horse TR/Dropper.Gen [NOTE] A backup was created as '48a12599.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Program Files\Starcraft\starcraft_add-on_broodwar_demonicterran.zip [NOTE] A backup was created as '48a325cb.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Program Files\Starcraft\starcraft_add-on_broodwar_terran_doom.zip [NOTE] A backup was created as '48a325cc.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Program Files\Starcraft\starcraft_add-on_broodwar_weponmod_V1-0.zip [NOTE] A backup was created as '48a325cd.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Program Files\Starcraft\Terran Doom.exe [DETECTION] Is the Trojan horse TR/Dropper.Gen [NOTE] A backup was created as '48b425bf.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\Program Files\Starcraft\WeponMod (Final) V1.0.exe [DETECTION] Is the Trojan horse TR/Dropper.Gen [NOTE] A backup was created as '48b225bf.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP38\A0015368.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48722980.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP38\A0015369.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '490e67c1.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP38\A0015370.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48722981.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP38\A0015371.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '490e67c2.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP38\A0015372.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48722983.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP38\A0015373.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48722982.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP38\A0015374.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '490e67c3.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP38\A0015375.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '490e67c4.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP38\A0015376.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48722985.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP38\A0015377.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48722984.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP38\A0015378.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '490e67c5.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP38\A0015379.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48722986.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP38\A0015380.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '490e67c6.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP38\A0015381.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48722987.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP38\A0015382.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '490e67c8.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP38\A0015383.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '490e67c7.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP38\A0015384.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48722988.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP38\A0015385.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48722989.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP38\A0015386.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '490e67ca.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP38\A0015389.exe [DETECTION] Is the Trojan horse TR/Dropper.Gen [NOTE] A backup was created as '4872298b.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP38\A0015390.exe [DETECTION] Is the Trojan horse TR/Dropper.Gen [NOTE] A backup was created as '490e67c9.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP38\A0015391.exe [DETECTION] Is the Trojan horse TR/Dropper.Gen [NOTE] A backup was created as '4872298a.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP38\A0015392.exe [DETECTION] Is the Trojan horse TR/Dropper.Gen [NOTE] A backup was created as '490e67cb.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP38\A0015393.exe [DETECTION] Is the Trojan horse TR/Dropper.Gen [NOTE] A backup was created as '490e67cc.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP38\A0015394.exe [DETECTION] Is the Trojan horse TR/Dropper.Gen [NOTE] A backup was created as '4872298d.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\System Volume Information\_restore{376D3382-5BEE-4430-B02D-7271D565B820}\RP38\A0015395.exe [DETECTION] Is the Trojan horse TR/Dropper.Gen [NOTE] A backup was created as '4872298c.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\VundoFix Backups\awtsp.dll.bad [DETECTION] Is the Trojan horse TR/Vundo.Gen [NOTE] A backup was created as '48b629d6.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\VundoFix Backups\eqmjnuve.dll.bad [DETECTION] Is the Trojan horse TR/Vundo.dvc.6 [NOTE] A backup was created as '48af29d0.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\VundoFix Backups\kejulkhf.dll.bad [DETECTION] Is the Trojan horse TR/Dldr.ConHook.Gen [NOTE] A backup was created as '48ac29c5.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\VundoFix Backups\mljgg.dll.bad [DETECTION] Is the Trojan horse TR/Vundo.Gen [NOTE] A backup was created as '48ac29cc.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\VundoFix Backups\mlljk.dll.bad [DETECTION] Is the Trojan horse TR/Vundo.Gen [NOTE] A backup was created as '48ae29cc.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\WINDOWS\inf\smss.exe [DETECTION] Contains detection pattern of the worm WORM/SdBot.378880.A [NOTE] A backup was created as '48b52b44.qua' ( QUARANTINE ) [NOTE] The file was deleted! C:\WINDOWS\system32\drivers\sptd.sys [WARNING] The file could not be opened! End of the scan: dimanche 1 juin 2008 08:59 Used time: 9:10:06 min The scan has been done completely. 12146 Scanning directories 555794 Files were scanned 68 viruses and/or unwanted programs were found 0 Files were classified as suspicious: 68 files were deleted 0 files were repaired 65 files were moved to quarantine 0 files were renamed 2 Files cannot be scanned 555726 Files not concerned 5915 Archives were scanned 3 Warnings 68 Notes
  15. Internet n'est pas une immense toile qui relie les gens du monde entier? alors pourquoi le fait que je sois à proximité de Madagascar géographiquement, me ferais avoir un risque plus important que quiconque ait internet ce trouvant autre part???Enfin je ne sais pas vraiment... Bref... Angélique, comme j'ai un disque dur 250Go non partitionné et relativement plein (j'avais des petits DD pour le système avant, mais je les ai perdu en cours de route, et comme j'avais déjà des donnés sur celui-là j'ai pas partitionné lorsque j'ai installé mon système d'exploitation, ce qui fait que l'analyse risque de prendre beaucoup de temps(la dernière fois ça ma pris 14h), je le mettrais durant le weekend et je posterai le rapport quand ça sera terminer d'accord? Merci beaucoup pour ton attention, et ton aide qui m'a été très utile, je te remercie encore, pour l'attention que tu continue de m'accorder!
×
×
  • Créer...