Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Messages recommandés

Posté(e)

Bonjour,

 

Depuis quelques jours, un virus "trojan horse generic.7" me pourrit la vie.

Novice en informatique, j'ai lu tout ce que je pouvais lire sur le net à propos de mon nouvel ami dans l'espoir de pouvoir le supprimer.

Rien n'y fait ... je m'adresse donc à celui d'entre vous qui pourra patiemment m'aider.

D'avance merci, Henri.

 

PS : je joins ci-dessus le dernier rapport HijackThis ... que je ne peux malheureusement pas convenablement interprété.

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 18:57:54, on 19/03/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe

C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe

C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\nvsvc32.exe

C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

C:\Program Files\Support.com\bin\tgcmd.exe

C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe

C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

C:\WINDOWS\system32\rundll32.exe

C:\Program Files\Analog Devices\SoundMAX\SMTray.exe

C:\Program Files\QuickTime\qttask.exe

C:\WINDOWS\system32\NotifyPhoneBook.exe

C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe

C:\Program Files\Belgacom\bin\sprtcmd.exe

C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe

C:\Program Files\Windows Live\Messenger\msnmsgr.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe

C:\WINDOWS\system32\HPZipm12.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.actu24.be/page/homepage/btw/1.aspx

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\DOCUME~1\SBASTI~1\LOCALS~1\Temp\services.exe

O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"

O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor

O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP

O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"

O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL

O4 - HKLM\..\Run: [smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"

O4 - HKLM\..\Run: [belgacom] "C:\Program Files\Belgacom\bin\sprtcmd.exe" /P Belgacom

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Casino-On-Net - {3015DB92-158E-4b77-9020-85C8E311FBB5} - C:\PROGRA~1\CASINO~1\casino.exe (file missing)

O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612...ex/qtplugin.cab

O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-BE/a-UNO1/GAME_UNO1.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1109587710531

O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111...all/xscan53.cab

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD39/JSCDL/jdk/6u...ows-i586-jc.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab55762.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab

O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab

O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{68BC809E-7649-4817-8FC2-3F2C674BE7EE}: NameServer = 195.238.2.21 195.238.2.22

O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

 

--

End of file - 11381 bytes

Posté(e)

'soir et bienvenu sur Zebulon :P

 

Desactive temporairement le TeaTimer de spybot , sinon il va géner dans la désinfection.

 

• relance HJT "do a system scan only" , coche|selectionne les lignes ci dessous et clic onglet FIXCHECKED:

 

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\DOCUME~1\SBASTI~1\LOCALS~1\Temp\services.exe

 

• Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.

http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

Double clique sur SDFix.exe et choisis Install pour l'extraire en c:\SDFix.

 

Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :

 

Redémarre en mode Sans Échec : au redémarrage, tapote immédiatement la touche F8 ; tu verras un écran avec choix de démarrages apparaître. Utilisant les flèches du clavier, choisis "Mode Sans Échec" et valide avec "Entrée". Choisis ton compte usuel, et non Administrateur.

 

 

 

* Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.cmd pour lancer le script.

* Appuie sur Y pour commencer le processus de nettoyage.

* Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.

* Appuie sur une touche pour redémarrer le PC.

* Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.(laisse le s'executer sans rien toucher!!)

* Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.

* Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.(ne touche à rien!!laisse le faire)

* Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.

* Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum avec un nouveau rapport HJT

Posté(e)

Bonsoir Angélique et merci pour la rapidité de ta réponse.

J'ai essayé de suivre à la lettre les instructions indiquées ... voici le dernier rapport hijackthis et le sdfix.

Remarque : en me connectant à internet, je viens de recevoir un nouveau message d'alerte "trojan horse generic.7 dans doc et settings/henri/fjgotp.exe"

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 19:52:04, on 19/03/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe

C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe

C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\nvsvc32.exe

C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

C:\Program Files\Support.com\bin\tgcmd.exe

C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe

C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

C:\WINDOWS\system32\rundll32.exe

C:\Program Files\Analog Devices\SoundMAX\SMTray.exe

C:\Program Files\QuickTime\qttask.exe

C:\WINDOWS\system32\NotifyPhoneBook.exe

C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe

C:\Program Files\Belgacom\bin\sprtcmd.exe

C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe

C:\Program Files\Windows Live\Messenger\msnmsgr.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.actu24.be/page/homepage/btw/1.aspx

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\DOCUME~1\SBASTI~1\LOCALS~1\Temp\services.exe

O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"

O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor

O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP

O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"

O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL

O4 - HKLM\..\Run: [smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"

O4 - HKLM\..\Run: [belgacom] "C:\Program Files\Belgacom\bin\sprtcmd.exe" /P Belgacom

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Casino-On-Net - {3015DB92-158E-4b77-9020-85C8E311FBB5} - C:\PROGRA~1\CASINO~1\casino.exe (file missing)

O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612...ex/qtplugin.cab

O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-BE/a-UNO1/GAME_UNO1.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1109587710531

O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111...all/xscan53.cab

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD39/JSCDL/jdk/6u...ows-i586-jc.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab55762.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab

O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab

O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab

O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

 

--

End of file - 11229 bytes

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 19:52:04, on 19/03/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe

C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe

C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\nvsvc32.exe

C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

C:\Program Files\Support.com\bin\tgcmd.exe

C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe

C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

C:\WINDOWS\system32\rundll32.exe

C:\Program Files\Analog Devices\SoundMAX\SMTray.exe

C:\Program Files\QuickTime\qttask.exe

C:\WINDOWS\system32\NotifyPhoneBook.exe

C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe

C:\Program Files\Belgacom\bin\sprtcmd.exe

C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe

C:\Program Files\Windows Live\Messenger\msnmsgr.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.actu24.be/page/homepage/btw/1.aspx

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\DOCUME~1\SBASTI~1\LOCALS~1\Temp\services.exe

O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"

O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor

O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP

O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"

O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL

O4 - HKLM\..\Run: [smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"

O4 - HKLM\..\Run: [belgacom] "C:\Program Files\Belgacom\bin\sprtcmd.exe" /P Belgacom

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Casino-On-Net - {3015DB92-158E-4b77-9020-85C8E311FBB5} - C:\PROGRA~1\CASINO~1\casino.exe (file missing)

O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612...ex/qtplugin.cab

O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-BE/a-UNO1/GAME_UNO1.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1109587710531

O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111...all/xscan53.cab

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD39/JSCDL/jdk/6u...ows-i586-jc.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab55762.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab

O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab

O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab

O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

 

--

End of file - 11229 bytes

Posté(e)

Je suis parfois distrait ... voici le rapport sdfix, le rapport hijackthis étant reprsi 2 fois dans le post précédent.

Henri.

 

 

 

SDFix: Version 1.158

 

Run by Henri on mer. 19/03/2008 at 19:33

 

Microsoft Windows XP [version 5.1.2600]

Running From: C:\SDFix

 

Checking Services :

 

 

Restoring Windows Registry Values

Restoring Windows Default Hosts File

 

Rebooting

 

 

Checking Files :

 

Trojan Files Found:

 

C:\Documents and Settings\Henri\nod32.txt - Deleted

 

 

 

 

 

Removing Temp Files

 

ADS Check :

 

 

 

Final Check :

 

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-03-19 19:42:04

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

C:\DOCUME~1\SBASTI~1\LOCALS~1\Temp\services.exe [348] 0x8228F7A8

 

scanning hidden services & system hive ...

 

scanning hidden registry entries ...

 

scanning hidden files ...

 

 

scan completed successfully

hidden processes: 1

hidden services: 0

hidden files: 0

 

 

Remaining Services :

 

 

 

Authorized Application Key Export:

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"C:\\Program Files\\support.com\\bin\\tgcmd.exe"="C:\\Program Files\\support.com\\bin\\tgcmd.exe:*:Enabled:Support.com Scheduler and Command Dispatcher"

"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"

"C:\\Program Files\\Ahead\\ODD Toolkit\\ODDUpdate.exe"="C:\\Program Files\\Ahead\\ODD Toolkit\\ODDUpdate.exe:*:Enabled:AsusUpdate"

"C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"="C:\\Program Files\\IncrediMail\\bin\\IMApp.exe:*:Enabled:IncrediMail"

"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"="C:\\Program Files\\IncrediMail\\bin\\IncMail.exe:*:Enabled:IncrediMail"

"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"="C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe:*:Enabled:IncrediMail"

"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe:*:Enabled:avginet.exe"

"C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"="C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe:*:Enabled:Age of Empires 3"

"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE:*:Enabled:Internet Explorer"

"C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3x.exe"="C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3x.exe:*:Enabled:Age of Empires III - The WarChiefs"

"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe:*:Enabled:avgamsvr.exe"

"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe:*:Enabled:avgcc.exe"

"C:\\DOCUME~1\\SBASTI~1\\LOCALS~1\\Temp\\iPrint.exe"="C:\\DOCUME~1\\SBASTI~1\\LOCALS~1\\Temp\\iPrint.exe:*:Enabled:iPrint Tray"

"C:\\Program Files\\Ankama Games\\Dofus\\Dofus.exe"="C:\\Program Files\\Ankama Games\\Dofus\\Dofus.exe:*:Enabled:Dofus Client"

"C:\\WINDOWS\\system32\\java.exe"="C:\\WINDOWS\\system32\\java.exe:*:Enabled:Java Platform SE binary"

"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

"C:\\DOCUME~1\\SBASTI~1\\LOCALS~1\\Temp\\services.exe"="C:\\DOCUME~1\\SBASTI~1\\LOCALS~1\\Temp\\services.exe:*:Enabled:Flash Media"

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

 

Remaining Files :

 

 

File Backups: - C:\SDFix\backups\backups.zip

 

Files with Hidden Attributes :

 

Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"

Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"

Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"

Thu 27 Dec 2007 52,224 ..SHR --- "C:\Program Files\ChessTrainer\ChessTrainer\Setup.exe"

Fri 18 Mar 2005 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\FOR20.tmp"

Fri 18 Mar 2005 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\FOR25.tmp"

Fri 18 Mar 2005 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\FOR27.tmp"

Fri 18 Mar 2005 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\FOR29.tmp"

Wed 19 Mar 2008 4,680 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R11.tmp"

Wed 19 Mar 2008 10,304 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R13.tmp"

Wed 19 Mar 2008 12,884 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R15.tmp"

Wed 19 Mar 2008 12,448 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R17.tmp"

Wed 19 Mar 2008 11,012 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R19.tmp"

Wed 19 Mar 2008 4,216 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R1B.tmp"

Wed 19 Mar 2008 5,564 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R1D.tmp"

Wed 19 Mar 2008 13,564 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R21.tmp"

Wed 19 Mar 2008 5,920 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R23.tmp"

Wed 19 Mar 2008 4,216 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R25.tmp"

Wed 19 Mar 2008 8,468 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R27.tmp"

Wed 19 Mar 2008 9,872 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R28.tmp"

Wed 19 Mar 2008 12,928 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R29.tmp"

Wed 19 Mar 2008 10,960 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R2A.tmp"

Wed 19 Mar 2008 13,908 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R2B.tmp"

Wed 19 Mar 2008 4,680 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R2C.tmp"

Wed 19 Mar 2008 4,680 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R2D.tmp"

Wed 19 Mar 2008 11,524 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R2E.tmp"

Wed 19 Mar 2008 9,056 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R2F.tmp"

Wed 19 Mar 2008 9,804 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R30.tmp"

Wed 19 Mar 2008 4,216 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R31.tmp"

Wed 19 Mar 2008 12,256 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R32.tmp"

Wed 19 Mar 2008 7,472 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R34.tmp"

Wed 19 Mar 2008 11,556 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R35.tmp"

Wed 19 Mar 2008 13,688 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R36.tmp"

Wed 19 Mar 2008 4,680 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R37.tmp"

Wed 19 Mar 2008 14,760 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R38.tmp"

Wed 19 Mar 2008 11,440 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R39.tmp"

Wed 19 Mar 2008 4,680 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R3A.tmp"

Wed 19 Mar 2008 4,216 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R3B.tmp"

Wed 19 Mar 2008 8,220 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R3C.tmp"

Wed 19 Mar 2008 4,216 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R3E.tmp"

Wed 19 Mar 2008 47,464 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R3F.tmp"

Wed 19 Mar 2008 11,344 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R41.tmp"

Wed 19 Mar 2008 9,952 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R42.tmp"

Wed 19 Mar 2008 13,068 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R43.tmp"

Wed 19 Mar 2008 15,212 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R45.tmp"

Wed 19 Mar 2008 17,720 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R46.tmp"

Wed 19 Mar 2008 4,680 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R47.tmp"

Wed 19 Mar 2008 17,720 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R48.tmp"

Wed 19 Mar 2008 10,644 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R49.tmp"

Wed 19 Mar 2008 4,216 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R4B.tmp"

Wed 19 Mar 2008 4,680 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R4F.tmp"

Wed 19 Mar 2008 8,288 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R51.tmp"

Wed 19 Mar 2008 13,092 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R52.tmp"

Wed 19 Mar 2008 14,064 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R53.tmp"

Wed 19 Mar 2008 10,844 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R54.tmp"

Wed 19 Mar 2008 15,048 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R55.tmp"

Wed 19 Mar 2008 8,632 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R56.tmp"

Wed 19 Mar 2008 11,196 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R57.tmp"

Wed 19 Mar 2008 5,120 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R59.tmp"

Wed 19 Mar 2008 4,216 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R5B.tmp"

Wed 19 Mar 2008 10,396 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R5D.tmp"

Wed 19 Mar 2008 13,940 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R5F.tmp"

Wed 19 Mar 2008 14,924 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R61.tmp"

Wed 19 Mar 2008 4,680 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R63.tmp"

Wed 19 Mar 2008 10,556 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R65.tmp"

Wed 19 Mar 2008 4,216 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R67.tmp"

Wed 19 Mar 2008 4,984 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R69.tmp"

Wed 19 Mar 2008 4,344 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R6B.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S12.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S14.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S16.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S18.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S1A.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S1C.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S1E.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S22.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S24.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S26.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S28.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S29.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S2A.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S2B.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S2C.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S2D.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S2E.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S2F.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S30.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S31.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S32.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S33.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S35.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S36.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S37.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S38.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S39.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S3A.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S3B.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S3C.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S3D.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S3F.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S40.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S42.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S43.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S44.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S46.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S47.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S48.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S49.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S4A.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S4C.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S50.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S52.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S53.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S54.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S55.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S56.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S57.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S58.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S5A.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S5C.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S5E.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S60.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S62.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S64.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S66.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S68.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S6A.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S6C.tmp"

Mon 3 Mar 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\ad213d081e2675ef87a62c73b8abf209\BIT3.tmp"

 

Finished!

 

 

 

 

 

 

 

Je suis parfois distrait ... voici le rapport sdfix, le rapport hijackthis étant reprsi 2 fois dans le post précédent.

Henri.

 

 

 

SDFix: Version 1.158

 

Run by Henri on mer. 19/03/2008 at 19:33

 

Microsoft Windows XP [version 5.1.2600]

Running From: C:\SDFix

 

Checking Services :

 

 

Restoring Windows Registry Values

Restoring Windows Default Hosts File

 

Rebooting

 

 

Checking Files :

 

Trojan Files Found:

 

C:\Documents and Settings\Henri\nod32.txt - Deleted

 

 

 

 

 

Removing Temp Files

 

ADS Check :

 

 

 

Final Check :

 

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-03-19 19:42:04

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

C:\DOCUME~1\SBASTI~1\LOCALS~1\Temp\services.exe [348] 0x8228F7A8

 

scanning hidden services & system hive ...

 

scanning hidden registry entries ...

 

scanning hidden files ...

 

 

scan completed successfully

hidden processes: 1

hidden services: 0

hidden files: 0

 

 

Remaining Services :

 

 

 

Authorized Application Key Export:

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"C:\\Program Files\\support.com\\bin\\tgcmd.exe"="C:\\Program Files\\support.com\\bin\\tgcmd.exe:*:Enabled:Support.com Scheduler and Command Dispatcher"

"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"

"C:\\Program Files\\Ahead\\ODD Toolkit\\ODDUpdate.exe"="C:\\Program Files\\Ahead\\ODD Toolkit\\ODDUpdate.exe:*:Enabled:AsusUpdate"

"C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"="C:\\Program Files\\IncrediMail\\bin\\IMApp.exe:*:Enabled:IncrediMail"

"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"="C:\\Program Files\\IncrediMail\\bin\\IncMail.exe:*:Enabled:IncrediMail"

"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"="C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe:*:Enabled:IncrediMail"

"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe:*:Enabled:avginet.exe"

"C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"="C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe:*:Enabled:Age of Empires 3"

"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE:*:Enabled:Internet Explorer"

"C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3x.exe"="C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3x.exe:*:Enabled:Age of Empires III - The WarChiefs"

"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe:*:Enabled:avgamsvr.exe"

"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"="C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe:*:Enabled:avgcc.exe"

"C:\\DOCUME~1\\SBASTI~1\\LOCALS~1\\Temp\\iPrint.exe"="C:\\DOCUME~1\\SBASTI~1\\LOCALS~1\\Temp\\iPrint.exe:*:Enabled:iPrint Tray"

"C:\\Program Files\\Ankama Games\\Dofus\\Dofus.exe"="C:\\Program Files\\Ankama Games\\Dofus\\Dofus.exe:*:Enabled:Dofus Client"

"C:\\WINDOWS\\system32\\java.exe"="C:\\WINDOWS\\system32\\java.exe:*:Enabled:Java Platform SE binary"

"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

"C:\\DOCUME~1\\SBASTI~1\\LOCALS~1\\Temp\\services.exe"="C:\\DOCUME~1\\SBASTI~1\\LOCALS~1\\Temp\\services.exe:*:Enabled:Flash Media"

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

 

Remaining Files :

 

 

File Backups: - C:\SDFix\backups\backups.zip

 

Files with Hidden Attributes :

 

Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"

Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"

Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"

Thu 27 Dec 2007 52,224 ..SHR --- "C:\Program Files\ChessTrainer\ChessTrainer\Setup.exe"

Fri 18 Mar 2005 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\FOR20.tmp"

Fri 18 Mar 2005 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\FOR25.tmp"

Fri 18 Mar 2005 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\FOR27.tmp"

Fri 18 Mar 2005 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\FOR29.tmp"

Wed 19 Mar 2008 4,680 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R11.tmp"

Wed 19 Mar 2008 10,304 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R13.tmp"

Wed 19 Mar 2008 12,884 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R15.tmp"

Wed 19 Mar 2008 12,448 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R17.tmp"

Wed 19 Mar 2008 11,012 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R19.tmp"

Wed 19 Mar 2008 4,216 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R1B.tmp"

Wed 19 Mar 2008 5,564 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R1D.tmp"

Wed 19 Mar 2008 13,564 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R21.tmp"

Wed 19 Mar 2008 5,920 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R23.tmp"

Wed 19 Mar 2008 4,216 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R25.tmp"

Wed 19 Mar 2008 8,468 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R27.tmp"

Wed 19 Mar 2008 9,872 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R28.tmp"

Wed 19 Mar 2008 12,928 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R29.tmp"

Wed 19 Mar 2008 10,960 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R2A.tmp"

Wed 19 Mar 2008 13,908 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R2B.tmp"

Wed 19 Mar 2008 4,680 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R2C.tmp"

Wed 19 Mar 2008 4,680 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R2D.tmp"

Wed 19 Mar 2008 11,524 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R2E.tmp"

Wed 19 Mar 2008 9,056 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R2F.tmp"

Wed 19 Mar 2008 9,804 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R30.tmp"

Wed 19 Mar 2008 4,216 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R31.tmp"

Wed 19 Mar 2008 12,256 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R32.tmp"

Wed 19 Mar 2008 7,472 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R34.tmp"

Wed 19 Mar 2008 11,556 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R35.tmp"

Wed 19 Mar 2008 13,688 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R36.tmp"

Wed 19 Mar 2008 4,680 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R37.tmp"

Wed 19 Mar 2008 14,760 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R38.tmp"

Wed 19 Mar 2008 11,440 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R39.tmp"

Wed 19 Mar 2008 4,680 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R3A.tmp"

Wed 19 Mar 2008 4,216 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R3B.tmp"

Wed 19 Mar 2008 8,220 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R3C.tmp"

Wed 19 Mar 2008 4,216 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R3E.tmp"

Wed 19 Mar 2008 47,464 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R3F.tmp"

Wed 19 Mar 2008 11,344 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R41.tmp"

Wed 19 Mar 2008 9,952 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R42.tmp"

Wed 19 Mar 2008 13,068 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R43.tmp"

Wed 19 Mar 2008 15,212 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R45.tmp"

Wed 19 Mar 2008 17,720 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R46.tmp"

Wed 19 Mar 2008 4,680 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R47.tmp"

Wed 19 Mar 2008 17,720 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R48.tmp"

Wed 19 Mar 2008 10,644 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R49.tmp"

Wed 19 Mar 2008 4,216 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R4B.tmp"

Wed 19 Mar 2008 4,680 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R4F.tmp"

Wed 19 Mar 2008 8,288 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R51.tmp"

Wed 19 Mar 2008 13,092 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R52.tmp"

Wed 19 Mar 2008 14,064 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R53.tmp"

Wed 19 Mar 2008 10,844 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R54.tmp"

Wed 19 Mar 2008 15,048 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R55.tmp"

Wed 19 Mar 2008 8,632 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R56.tmp"

Wed 19 Mar 2008 11,196 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R57.tmp"

Wed 19 Mar 2008 5,120 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R59.tmp"

Wed 19 Mar 2008 4,216 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R5B.tmp"

Wed 19 Mar 2008 10,396 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R5D.tmp"

Wed 19 Mar 2008 13,940 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R5F.tmp"

Wed 19 Mar 2008 14,924 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R61.tmp"

Wed 19 Mar 2008 4,680 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R63.tmp"

Wed 19 Mar 2008 10,556 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R65.tmp"

Wed 19 Mar 2008 4,216 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R67.tmp"

Wed 19 Mar 2008 4,984 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R69.tmp"

Wed 19 Mar 2008 4,344 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@R6B.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S12.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S14.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S16.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S18.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S1A.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S1C.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S1E.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S22.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S24.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S26.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S28.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S29.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S2A.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S2B.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S2C.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S2D.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S2E.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S2F.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S30.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S31.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S32.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S33.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S35.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S36.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S37.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S38.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S39.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S3A.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S3B.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S3C.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S3D.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S3F.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S40.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S42.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S43.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S44.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S46.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S47.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S48.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S49.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S4A.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S4C.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S50.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S52.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S53.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S54.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S55.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S56.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S57.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S58.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S5A.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S5C.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S5E.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S60.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S62.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S64.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S66.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S68.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S6A.tmp"

Wed 19 Mar 2008 1,409 ...H. --- "C:\Documents and Settings\Marie-C‚cile\Local Settings\Temp\Z@S6C.tmp"

Mon 3 Mar 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\ad213d081e2675ef87a62c73b8abf209\BIT3.tmp"

 

Finished!

Posté(e)

Le voici, merci pour l'analyse ...

Henri.

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 21:06:52, on 19/03/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16608)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe

C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe

C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE

C:\WINDOWS\system32\nvsvc32.exe

C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

C:\Program Files\Support.com\bin\tgcmd.exe

C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe

C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

C:\WINDOWS\system32\rundll32.exe

C:\Program Files\Analog Devices\SoundMAX\SMTray.exe

C:\Program Files\QuickTime\qttask.exe

C:\WINDOWS\system32\NotifyPhoneBook.exe

C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe

C:\Program Files\Belgacom\bin\sprtcmd.exe

C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe

C:\Program Files\Windows Live\Messenger\msnmsgr.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.actu24.be/page/homepage/btw/1.aspx

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\DOCUME~1\SBASTI~1\LOCALS~1\Temp\services.exe

O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"

O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor

O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP

O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"

O4 - HKLM\..\Run: [AME_CSA] rundll32 amecsa.cpl,RUN_DLL

O4 - HKLM\..\Run: [smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"

O4 - HKLM\..\Run: [belgacom] "C:\Program Files\Belgacom\bin\sprtcmd.exe" /P Belgacom

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: Casino-On-Net - {3015DB92-158E-4b77-9020-85C8E311FBB5} - C:\PROGRA~1\CASINO~1\casino.exe (file missing)

O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab

O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/200612...ex/qtplugin.cab

O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab

O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab

O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-BE/a-UNO1/GAME_UNO1.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co...b?1109587710531

O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2005111...all/xscan53.cab

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD39/JSCDL/jdk/6u...ows-i586-jc.cab

O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab

O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab55762.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab

O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab

O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{68BC809E-7649-4817-8FC2-3F2C674BE7EE}: NameServer = 195.238.2.21 195.238.2.22

O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe

O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

 

--

End of file - 11375 bytes

Posté(e)

• Télécharge combofix.exe (par sUBs) et sauvegarde le sur ton bureau.

 

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

 

*desactive temporairement ton antivirus avg

* Double-clique combofix.exe afin de l'exécuter et suis les instructions.

* Lorsque l'analyse sera complétée, un rapport apparaîtra que tu me posteras.

Posté(e)

Bonjour Angélique,

 

Voici le rapport d'analyse généré par combofix ... complètement illisible pour moi.

J'attends de tes nouvelles.

Merci, Henri.

 

ComboFix 08-03-18.1 - Henri 2008-03-20 11:33:13.2 - NTFSx86

Microsoft Windows XP Édition familiale 5.1.2600.2.1252.33.1036.18.214 [GMT 1:00]

Endroit: C:\Documents and Settings\Henri\Bureau\ComboFix.exe

 

AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!

.

 

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\Documents and Settings\admin\err.log

C:\Documents and Settings\All Users\Application Data\SystemDoctor Free

C:\Documents and Settings\All Users\Application Data\SystemDoctor Free\Data\Abbr

C:\Documents and Settings\All Users\Application Data\SystemDoctor Free\Data\ActivationCode

C:\Documents and Settings\All Users\Application Data\SystemDoctor Free\Data\HOURS

C:\Documents and Settings\All Users\Application Data\SystemDoctor Free\Data\ProductCode

C:\Documents and Settings\Bertrand.OEM\Application Data\SystemDoctor Free

C:\Documents and Settings\Bertrand.OEM\Application Data\SystemDoctor Free\Logs\update.log

C:\Documents and Settings\Bertrand.OEM\err.log

C:\Documents and Settings\Bertrand.OEM\ResErrors.log

C:\Documents and Settings\Henri\Application Data\SystemDoctor Free

C:\Documents and Settings\Henri\Application Data\SystemDoctor Free\Logs\update.log

C:\Documents and Settings\Henri\err.log

C:\Documents and Settings\Henri\ResErrors.log

C:\Documents and Settings\Marie-Cécile\Application Data\SystemDoctor Free

C:\Documents and Settings\Marie-Cécile\Application Data\SystemDoctor Free\Logs\update.log

C:\Documents and Settings\Marie-Cécile\err.log

C:\Documents and Settings\Marie-Cécile\ResErrors.log

C:\Documents and Settings\Sébastien\Application Data\SystemDoctor Free

C:\Documents and Settings\Sébastien\Application Data\SystemDoctor Free\Logs\update.log

C:\Documents and Settings\Sébastien\err.log

C:\Documents and Settings\Sébastien\ResErrors.log

C:\Program Files\Fichiers communs\SystemDoctor

C:\Program Files\Fichiers communs\SystemDoctor\err.log

 

.

((((((((((((((((((((((((((((( Fichiers créés 2008-02-20 to 2008-03-20 ))))))))))))))))))))))))))))))))))))

.

 

2008-03-19 19:54 . 2008-03-19 19:54 9,296 --a------ C:\Documents and Settings\Henri\fjgotp.exe

2008-03-19 19:26 . 2008-03-19 19:26 1,413,852 --a------ C:\SDFix.exe

2008-03-19 17:55 . 2008-03-19 17:55 <REP> d-------- C:\WINDOWS\ERUNT

2008-03-19 17:54 . 2005-02-28 11:42 <REP> d--h----- C:\Documents and Settings\Administrateur.OEM\Voisinage réseau

2008-03-19 17:54 . 2005-02-28 11:42 <REP> d--h----- C:\Documents and Settings\Administrateur.OEM\Voisinage d'impression

2008-03-19 17:54 . 2005-02-28 10:50 <REP> d--h----- C:\Documents and Settings\Administrateur.OEM\Modèles

2008-03-19 17:54 . 2005-02-28 11:42 <REP> d-------- C:\Documents and Settings\Administrateur.OEM\Mes documents

2008-03-19 17:54 . 2005-02-28 11:42 <REP> dr------- C:\Documents and Settings\Administrateur.OEM\Menu Démarrer

2008-03-19 17:54 . 2005-02-28 11:42 <REP> d-------- C:\Documents and Settings\Administrateur.OEM\Favoris

2008-03-19 17:54 . 2008-03-19 17:57 <REP> d-------- C:\Documents and Settings\Administrateur.OEM\Bureau

2008-03-19 17:46 . 2008-03-19 19:50 <REP> d-------- C:\SDFix

2008-03-17 23:46 . 2005-02-28 11:42 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau

2008-03-17 23:46 . 2005-02-28 11:42 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression

2008-03-17 23:46 . 2005-02-28 10:50 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles

2008-03-17 23:46 . 2005-02-28 11:42 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents

2008-03-17 23:46 . 2005-02-28 11:42 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer

2008-03-17 23:46 . 2005-02-28 11:42 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris

2008-03-17 23:46 . 2008-03-17 23:48 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau

2008-03-17 23:41 . 2008-03-17 23:41 <REP> d-------- C:\Documents and Settings\Sébastien\Application Data\Grisoft

2008-03-17 23:41 . 2008-03-17 23:41 <REP> d-------- C:\Documents and Settings\Marie-Cécile\Application Data\Grisoft

2008-03-17 23:41 . 2008-03-17 23:41 <REP> d-------- C:\Documents and Settings\Bertrand.OEM\Application Data\Grisoft

2008-03-14 18:21 . 2008-03-14 18:21 37,376 --a------ C:\WINDOWS\mrofinu1423.exe.MSNFix

2008-03-14 07:45 . 2008-03-14 07:45 <REP> d-------- C:\Documents and Settings\Henri\belgacom

2008-03-14 07:32 . 2008-03-14 07:32 37,376 --a------ C:\WINDOWS\mrofinu1423.MSNFix

2008-03-14 00:43 . 2008-03-14 00:47 591 --a------ C:\WINDOWS\wininit.ini

2008-03-14 00:02 . 2008-03-14 00:02 <REP> d-------- C:\Program Files\CCleaner

2008-03-13 23:54 . 2008-03-13 23:55 <REP> d-------- C:\Program Files\Spybot - Search & Destroy

2008-03-13 23:54 . 2008-03-14 00:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy

2008-03-13 23:35 . 2008-03-13 23:35 <REP> d-------- C:\WINDOWS\DED53B0BB67C4244AE6AD6FD3C28D1EF.TMP

2008-03-13 23:27 . 2008-03-13 23:27 <REP> d-------- C:\Program Files\Lavasoft

2008-03-13 23:27 . 2008-03-13 23:28 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft

2008-03-13 23:26 . 2008-03-13 23:26 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard

2008-03-13 22:22 . 2008-03-13 22:22 <REP> d-------- C:\Documents and Settings\Henri\Application Data\Grisoft

2008-03-13 22:22 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys

2008-03-13 22:17 . 2008-03-13 22:17 <REP> d-------- C:\Program Files\Trend Micro

2008-03-02 22:20 . 2008-03-02 22:20 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2

2008-03-02 14:03 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll

2008-03-02 14:03 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll

2008-03-02 14:03 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui

2008-03-01 22:36 . 2008-03-01 22:37 <REP> d-------- C:\Program Files\Windows Live

2008-03-01 22:36 . 2008-03-01 22:36 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller

2008-03-01 22:35 . 2008-03-01 22:35 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller

2008-02-21 21:32 . 2008-02-21 21:32 <REP> d-------- C:\Documents and Settings\Henri\Application Data\Leadertech

 

.

(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-03-17 22:12 --------- d-----w C:\Program Files\Java

2008-03-14 13:14 --------- d-----w C:\Program Files\GeoGebra

2008-03-13 21:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft

2008-03-09 13:15 --------- d-----w C:\Documents and Settings\Henri\Application Data\AVG7

2008-02-21 07:00 --------- d-----w C:\Documents and Settings\LocalService\Application Data\AVG7

2008-02-10 14:15 --------- d-----w C:\Program Files\SEGA

2008-02-10 14:14 --------- d--h--w C:\Program Files\InstallShield Installation Information

2008-02-08 20:33 --------- d-----w C:\Program Files\Fichiers communs\Adobe

2008-02-04 10:49 --------- d-----w C:\Documents and Settings\Sébastien\Application Data\Leadertech

.

 

((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]

"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-27 13:32 68856]

"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00 15360]

"Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]

"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-10-29 16:50 4620288]

"nwiz"="nwiz.exe" [2004-10-29 16:50 921600 C:\WINDOWS\system32\nwiz.exe]

"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2004-10-29 16:50 86016]

"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]

"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 13:38 49152]

"tgcmd"="C:\Program Files\Support.com\bin\tgcmd.exe" [2005-02-06 17:31 1757184]

"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2008-01-15 08:00 579072]

"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 15:18 241664]

"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]

"AME_CSA"="amecsa.cpl" [2002-10-30 03:26 757760 C:\WINDOWS\system32\AmeCSA.cpl]

"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 08:57 143360]

"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-17 20:31 282624]

"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" [2007-03-16 10:45 63712]

"Belgacom"="C:\Program Files\Belgacom\bin\sprtcmd.exe" [2006-06-22 09:34 192512]

"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]

"Flash Media"="C:\DOCUME~1\SBASTI~1\LOCALS~1\Temp\services.exe" [2008-03-03 18:08 64156]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 13:00 15360]

"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-11-06 08:03 219136]

"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]

 

C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\

D‚marrage rapide du logiciel HP Image Zone.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-28 23:06:36 53248]

HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 22:31:38 241664]

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"C:\\Program Files\\support.com\\bin\\tgcmd.exe"=

"C:\\Program Files\\Messenger\\msmsgs.exe"=

"C:\\Program Files\\Ahead\\ODD Toolkit\\ODDUpdate.exe"=

"C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=

"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=

"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=

"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"=

"C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=

"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=

"C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3x.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"=

"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"=

"C:\\Program Files\\Ankama Games\\Dofus\\Dofus.exe"=

"C:\\WINDOWS\\system32\\java.exe"=

"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

"C:\\DOCUME~1\\SBASTI~1\\LOCALS~1\\Temp\\services.exe"=

 

R3 AmeAtmPc;AmeAtmPc;C:\WINDOWS\system32\DRIVERS\AmeAtmPc.sys [2002-12-17 02:29]

S3 AtmElan;Réseau émulant ATM;C:\WINDOWS\system32\DRIVERS\atmlane.sys [2004-08-05 13:00]

S3 AtmLane;Émulation réseau ATM;C:\WINDOWS\system32\DRIVERS\atmlane.sys [2004-08-05 13:00]

 

.

**************************************************************************

 

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-03-20 11:35:55

Windows 5.1.2600 Service Pack 2 NTFS

 

Balayage processus cachés ...

 

? [780]

? [2196]

? [488]

? [1088]

? [184]

? [3304]

? [2716]

 

Balayage caché autostart entries ...

 

Balayage des fichiers cachés ...

 

Scan terminé avec succès

Les fichiers cachés: 0

 

**************************************************************************

.

Temps d'accomplissement: 2008-03-20 11:38:54

ComboFix-quarantined-files.txt 2008-03-20 10:38:52

.

2008-03-12 16:02:23 --- E O F ---

Posté(e)

Peut-être une remarque importante ...

Nous pensons que notre ordi est infecté depuis le 2 mars 2008 : un de mes gamins (Sébastien) a ouvert un message (du style "ta photo est sur le net") reçu sur msn.

A binetôt, Henri.

Posté(e)

On essaie comme ça:

 

• ouvre ton bloc note[executer--notepad] et copies/colles le contenu du cadre ci dessous:

 

File::
C:\DOCUME~1\SBASTI~1\LOCALS~1\Temp\services.exe
C:\Documents and Settings\Henri\fjgotp.exe
C:\SDFix.exe
C:\WINDOWS\mrofinu1423.exe.MSNFix
C:\WINDOWS\mrofinu1423.MSNFix

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Flash Media"=-
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\DOCUME~1\\SBASTI~1\\LOCALS~1\\Temp\\services.exe"=-

 

[*]Va en haut de la page et clique sur le menu"Fichier" , une liste apparait=>

[*]Choisis "Enregistrer sous" et choisis "Bureau"

[*]Dans le champs "Nom du fichier" en bas de page donne le nom suivant:CFScript en fichier .txt

[*]Clique sur le bouton "Enregistrer" à droite du champs "nom du fichier"

[*]Quitte le Bloc Notes.

[*]Fait un glisser/déposer de ce fichier CFScript.txt sur le fichier ComboFix.exe comme sur la capture

 

 

CFScript.gif

 

 

* suis les instructions

* Patiente le temps du scan.Le bureau va disparaitre à plusieurs reprises: c'est normal!

Ne touche à rien tant que le scan n'est pas terminé.

* Une fois le scan achevé, un rapport va s'afficher: poste son contenu avec un nouveau rapport HijackThis

* Si le fichier n'apparait pas, il se trouve ici > C:\ComboFix.txt

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Invité
Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
×
×
  • Créer...