Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Messages recommandés

Posté(e)

Pour Vista, je ne dispose pas d'assez de droits pour placer l'élément sur le Bureau...or je suis le seul Admin de l'ordinateur (et aussi le seul utilisateur).

 

Bref là je dois partir, je reviens vers 20 heures.

 

Merci déjà pour toute l'aide.

Posté(e)
File move failed. C:\Windows\ehome\ehtray.exe scheduled to be moved on reboot.

 

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 07022008_184754

 

Files moved on Reboot...

File move failed. C:\Windows\ehome\ehtray.exe scheduled to be moved on reboot.

 

J'ai essayé en mode sans échec, même résultat....

Posté(e)

Génial, la sale bête. :P

Bon, au moins, c'est un cas intéressant !

 

Il y a une nouvelle version de ComboFix depuis quelque minutes. J'aimerais la tester et avoir un nouveau rapport avec.

Il faudra écraser ton ancien combofix.exe et le remplacer par le nouveau. Toujours sur le bureau et pas ailleurs. :P

 

Avant tout ça, désative l'UAC -contrôle des comptes utilisateurs (surtout, bien penser à le réactiver après la désinfection), même si combofix s'en fiche, en fait :

 

* Démarrer > Panneau de Configuration

* Double clique sur l'icône Comptes d'utilisateurs

* Clique ensuite sur Désactiver et valide.

 

 

Télécharge combofix.exe de sUBs et sauvegarde le sur ton bureau (et pas ailleurs).

  • Assure toi que tous les programmes sont fermés avant de commencer.
  • Double-clique combofix.exe afin de l'exécuter.
  • Clique sur "Oui" au message de Limitation de Garantie qui s'affiche.
  • Il est possible que ton parefeu te demande si tu acceptes ou non l'accès de nircmd.cfexe à la zone sûre: accepte.
  • Ne ferme pas la fenêtre qui vient de s'ouvrir, tu te retrouverais avec un bureau vide.
  • Lorsque l'analyse sera terminée, un rapport apparaîtra.
  • Copie-colle ce rapport dans ta prochaine réponse.
    Le rapport se trouve dans : C:\Combofix.txt (si jamais).
  • Pour plus d'information et un tuto illustré, voici le seul tuto officiel et autorisé : http://www.bleepingcomputer.com/combofix/f...iliser-combofix

 

Pense à la réactiver après (on le redésactivera ensuite pour tests).

Posté(e)
ComboFix 08-07-01.5 - Moissette 2008-07-02 21:19:26.3 - NTFSx86

Microsoft® Windows Vista Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2374 [GMT 2:00]

Endroit: C:\Users\Moissette\Desktop\ComboFix.exe

* Création d'un nouveau point de restauration

* Resident AV is active

 

.

 

((((((((((((((((((((((((((((( Fichiers créés 2008-06-02 to 2008-07-02 ))))))))))))))))))))))))))))))))))))

.

 

2008-07-02 16:47 . 2008-07-02 16:47 0 --a------ C:\Windows\System32\drivers\lvuvc.hs

2008-07-02 14:42 . 2008-07-02 14:42 <REP> d-------- C:\_OTMoveIt

2008-07-02 09:25 . 2008-07-02 09:25 <REP> d-------- C:\Program Files\Schmads Inc

2008-07-01 18:49 . 2008-07-01 18:49 <REP> d-------- C:\Deckard

2008-07-01 15:40 . 2008-07-01 15:40 <REP> d-------- C:\Users\Moissette\AppData\Roaming\Malwarebytes

2008-07-01 15:40 . 2008-07-01 15:40 <REP> d-------- C:\ProgramData\Malwarebytes

2008-07-01 15:40 . 2008-07-01 17:06 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware

2008-07-01 15:40 . 2008-06-28 14:16 34,296 --a------ C:\Windows\System32\drivers\mbamcatchme.sys

2008-07-01 15:40 . 2008-06-28 14:16 17,144 --a------ C:\Windows\System32\drivers\mbam.sys

2008-07-01 15:38 . 2008-07-01 15:38 <REP> d-------- C:\Users\Moissette\AppData\Roaming\Leadertech

2008-07-01 15:38 . 2008-07-01 15:38 127,034 -r------- C:\Windows\bwUnin-8.1.1.50-8876480SL.exe

2008-07-01 15:37 . 2008-02-06 04:21 4,658,456 --a------ C:\Windows\System32\drivers\lvuvc.sys

2008-07-01 15:37 . 2008-02-06 04:20 628,760 --a------ C:\Windows\System32\drivers\lvrs.sys

2008-07-01 15:37 . 2008-02-06 04:21 490,008 --a------ C:\Windows\System32\LVUI2.dll

2008-07-01 15:37 . 2008-02-06 04:21 465,432 --a------ C:\Windows\System32\LVUI2RC.dll

2008-07-01 15:37 . 2008-02-06 04:18 416,280 --a------ C:\Windows\System32\lvcodec2.dll

2008-07-01 15:37 . 2008-02-06 04:18 195,096 --a------ C:\Windows\System32\lvci11701196.dll

2008-07-01 15:37 . 2008-02-06 03:37 66,482 --a------ C:\Windows\System32\lvcoinst.ini

2008-07-01 15:37 . 2008-02-06 04:21 41,752 --a------ C:\Windows\System32\drivers\LVUSBSta.sys

2008-07-01 15:37 . 2008-02-06 03:40 25,056 --a------ C:\Windows\System32\Repository.reg

2008-07-01 15:35 . 2008-07-02 18:51 <REP> d-------- C:\ProgramData\Logishrd

2008-06-26 09:41 . 2008-07-02 21:23 81,984 --a------ C:\Windows\System32\bdod.bin

2008-06-26 09:29 . 2008-06-26 09:59 <REP> d-------- C:\Program Files\Common Files\Labtec

2008-06-26 09:28 . 2008-07-01 15:38 <REP> d-------- C:\Program Files\Common Files\LogiShrd

2008-06-26 09:26 . 2008-06-26 09:26 <REP> d-------- C:\Program Files\directx

2008-06-26 09:26 . 2008-06-26 09:46 <REP> d-------- C:\Program Files\Common Files\Real

2008-06-26 09:26 . 2008-06-26 09:26 <REP> d-------- C:\My Music

2008-06-26 09:25 . 2008-06-26 09:26 560 --a------ C:\Windows\_delis32.ini

2008-06-26 09:23 . 2008-06-26 09:50 <REP> d-------- C:\Program Files\Labtec

2008-06-26 08:51 . 2008-06-26 08:53 <REP> d-------- C:\Program Files\GUILD WARS5

2008-06-24 13:18 . 2008-06-25 09:31 <REP> d-------- C:\Program Files\GUILD WARS4

2008-06-22 16:46 . 2008-06-22 16:53 <REP> d-------- C:\Program Files\GUILD WARS2

2008-06-22 16:31 . 2008-06-23 01:14 <REP> d-------- C:\Program Files\GUILD WARS3

2008-06-19 13:13 . 2008-06-19 13:13 <REP> d-------- C:\ProgramData\pixelStorm

2008-06-15 00:10 . 2008-04-23 06:42 428,544 --a------ C:\Windows\System32\EncDec.dll

2008-06-15 00:10 . 2008-04-23 06:42 293,376 --a------ C:\Windows\System32\psisdecd.dll

2008-06-15 00:10 . 2008-04-23 06:41 218,624 --a------ C:\Windows\System32\psisrndr.ax

2008-06-15 00:10 . 2008-04-23 06:41 57,856 --a------ C:\Windows\System32\MSDvbNP.ax

2008-06-11 16:29 . 2008-06-16 11:18 <REP> d-------- C:\Program Files\MappingOut

2008-06-09 21:58 . 2008-06-09 22:20 <REP> d-------- C:\Users\Moissette\AppData\Roaming\MeuhMeuhTV

2008-06-09 21:57 . 2008-06-09 21:57 <REP> d-------- C:\Program Files\MeuhMeuhTV Alpha

2008-06-09 21:35 . 2008-06-09 21:35 <REP> d-------- C:\Program Files\K!TV

2008-06-09 21:13 . 2008-06-09 21:13 <REP> d-------- C:\Users\Moissette\Pinnacle

2008-06-09 21:02 . 2008-06-09 21:02 <REP> d-------- C:\Program Files\Devnz

2008-06-09 18:58 . 2008-06-09 18:58 <REP> d-------- C:\Program Files\DivX

2008-06-09 18:50 . 2008-06-09 21:22 <REP> d-------- C:\Program Files\Pinnacle

2008-06-09 18:49 . 2008-06-09 21:23 <REP> d-------- C:\ProgramData\Pinnacle

2008-06-04 18:19 . 2008-06-04 18:19 <REP> d-------- C:\Program Files\IrfanView

 

.

(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-07-02 16:49 --------- d-----w C:\Program Files\Steam

2008-07-01 13:38 --------- d--h--w C:\Program Files\InstallShield Installation Information

2008-07-01 13:38 --------- d-----w C:\Program Files\Logitech

2008-07-01 13:35 --------- d-----w C:\ProgramData\Logitech

2008-06-30 22:29 --------- d-----w C:\Users\Moissette\AppData\Roaming\teamspeak2

2008-06-30 21:59 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard

2008-06-26 07:29 --------- d-----w C:\Program Files\Common Files\Logitech

2008-06-24 10:05 86,792 ----a-w C:\Windows\system32\drivers\bdfndisf.sys

2008-06-22 14:17 1,634 ----a-w C:\Users\Moissette\AppData\Roaming\wklnhst.dat

2008-06-17 09:56 --------- d-----w C:\Program Files\Common Files\Steam

2008-06-12 01:07 --------- d-----w C:\Program Files\Windows Mail

2008-05-31 15:21 --------- d-----w C:\ProgramData\Media Center Programs

2008-05-31 15:21 --------- d-----w C:\Program Files\GUILD WARS

2008-05-30 16:17 --------- d-----w C:\Program Files\Warcraft III

2008-05-29 22:30 --------- d-----w C:\ProgramData\NVIDIA

2008-05-29 22:04 23,600 ----a-w C:\Windows\system32\drivers\TVICHW32.SYS

2008-05-28 21:29 --------- d-----w C:\Program Files\PC Inspector File Recovery

2008-05-28 21:22 0 ---ha-w C:\Windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf

2008-05-28 20:50 --------- d-----w C:\ProgramData\Roxio

2008-05-28 12:31 --------- d-----w C:\Program Files\Dollcevita

2008-05-25 15:17 0 ---ha-w C:\Windows\system32\drivers\Msft_User_AuxiliaryDisplayEnhancedDriver_01_00_00.Wdf

2008-05-25 15:17 --------- d-----w C:\Program Files\Microsoft Silverlight

2008-05-25 15:06 174 --sha-w C:\Program Files\desktop.ini

2008-05-25 15:00 --------- d-----w C:\Program Files\Windows Sidebar

2008-05-25 15:00 --------- d-----w C:\Program Files\Windows Photo Gallery

2008-05-25 15:00 --------- d-----w C:\Program Files\Windows Journal

2008-05-25 15:00 --------- d-----w C:\Program Files\Windows Defender

2008-05-25 15:00 --------- d-----w C:\Program Files\Windows Collaboration

2008-05-25 15:00 --------- d-----w C:\Program Files\Windows Calendar

2008-05-25 14:50 409,600 ----a-w C:\Windows\System32\wrap_oal.dll

2008-05-25 14:50 114,688 ----a-w C:\Windows\System32\OpenAL32.dll

2008-05-25 13:58 82,432 ----a-w C:\Windows\System32\axaltocm.dll

2008-05-25 13:58 101,888 ----a-w C:\Windows\System32\ifxcardm.dll

2008-05-24 13:46 --------- d-----w C:\Users\Moissette\AppData\Roaming\My Games

2008-05-24 13:38 --------- d-----w C:\Program Files\Firaxis Games

2008-05-12 12:12 --------- d-----w C:\ProgramData\Creative

2008-05-10 01:33 113,664 ----a-w C:\Windows\system32\drivers\rmcast.sys

2008-05-03 17:12 --------- d-----w C:\Program Files\Virtual DJ

2008-04-29 03:54 181,760 ----a-w C:\Windows\System32\fsquirt.exe

2008-04-26 08:08 1,314,816 ----a-w C:\Windows\System32\quartz.dll

2008-04-25 04:35 826,880 ----a-w C:\Windows\System32\wininet.dll

2008-04-14 14:37 2,829 ----a-w C:\Windows\War3Unin.pif

2008-04-14 14:37 139,264 ----a-w C:\Windows\War3Unin.exe

2008-04-13 16:11 988,216 ----a-w C:\Windows\System32\winload.exe

2008-04-13 16:11 927,288 ----a-w C:\Windows\System32\winresume.exe

2008-04-13 16:11 615,992 ----a-w C:\Windows\System32\ci.dll

2008-04-13 16:11 6,656 ----a-w C:\Windows\System32\kbd106n.dll

2008-04-13 16:11 46,592 ----a-w C:\Windows\System32\setbcdlocale.dll

2008-04-13 16:11 40,960 ----a-w C:\Windows\System32\srclient.dll

2008-04-13 16:11 378,368 ----a-w C:\Windows\System32\srcore.dll

2008-04-13 16:11 318,464 ----a-w C:\Windows\System32\rstrui.exe

2008-04-13 16:11 19,000 ----a-w C:\Windows\System32\kd1394.dll

2008-04-13 16:11 14,848 ----a-w C:\Windows\System32\srdelayed.exe

2008-04-13 16:10 295,936 ----a-w C:\Windows\System32\gdi32.dll

2008-04-13 16:10 2,032,128 ----a-w C:\Windows\System32\win32k.sys

2008-04-13 15:24 77,824 ----a-w C:\Windows\System32\xcomm.dll

.

 

((((((((((((((((((((((((((((( snapshot_2008-07-02_11.58.52.61 )))))))))))))))))))))))))))))))))))))))))

.

- 2008-07-02 09:54:33 67,584 --s-a-w C:\Windows\bootstat.dat

+ 2008-07-02 16:48:54 67,584 --s-a-w C:\Windows\bootstat.dat

- 2008-07-02 09:53:23 3,349 ----a-w C:\Windows\bthservsdp.dat

+ 2008-07-02 16:46:03 3,349 ----a-w C:\Windows\bthservsdp.dat

- 2008-07-02 09:54:33 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2008-07-02 16:48:54 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2008-07-02 16:48:54 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

- 2008-07-02 09:55:04 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT

+ 2008-07-02 16:50:19 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT

+ 2008-07-02 16:50:19 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1

- 2008-07-02 09:55:04 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT

+ 2008-07-02 16:50:14 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT

- 2008-07-02 09:54:41 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2008-07-02 16:49:02 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2008-07-02 09:54:41 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2008-07-02 16:49:02 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2008-07-02 09:54:41 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2008-07-02 16:49:02 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2008-07-02 08:34:17 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat

+ 2008-07-02 19:19:11 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat

+ 2008-07-02 19:19:11 262,144 ---ha-w C:\Windows\System32\config\systemprofile\ntuser.dat.LOG1

- 2008-05-25 15:03:21 321,296 ----a-w C:\Windows\System32\FNTCACHE.DAT

+ 2008-07-02 14:47:58 321,296 ----a-w C:\Windows\System32\FNTCACHE.DAT

- 2008-07-02 08:53:26 101,052 ----a-w C:\Windows\System32\perfc009.dat

+ 2008-07-02 16:54:07 101,052 ----a-w C:\Windows\System32\perfc009.dat

- 2008-07-02 08:53:26 123,350 ----a-w C:\Windows\System32\perfc00C.dat

+ 2008-07-02 16:54:07 123,350 ----a-w C:\Windows\System32\perfc00C.dat

- 2008-07-02 08:53:26 586,980 ----a-w C:\Windows\System32\perfh009.dat

+ 2008-07-02 16:54:07 586,980 ----a-w C:\Windows\System32\perfh009.dat

- 2008-07-02 08:53:26 669,340 ----a-w C:\Windows\System32\perfh00C.dat

+ 2008-07-02 16:54:07 669,340 ----a-w C:\Windows\System32\perfh00C.dat

- 2008-07-02 08:49:08 8,392 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2917644237-1699333532-349216916-1000_UserData.bin

+ 2008-07-02 16:50:51 8,856 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2917644237-1699333532-349216916-1000_UserData.bin

- 2008-07-02 08:49:08 70,930 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin

+ 2008-07-02 16:50:50 71,684 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin

- 2008-07-02 07:18:46 47,512 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin

+ 2008-07-02 16:50:47 49,090 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin

.

-- Snapshot reset to current date --

.

((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]

"Steam"="C:\Program Files\Steam\Steam.exe" [2008-04-13 18:35 1271032]

"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2008-02-13 20:21 202544]

"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-04-01 11:39 486856]

"Sidebar"="C:\Program Files\windows sidebar\sidebar.exe" [2008-01-19 09:33 1233920]

"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 09:33 202240]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SunJavaUpdateSched"="c:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2008-04-08 13:47 77824]

"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 16:44 178712]

"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-08 13:57 1838592]

"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-02-13 20:21 16384]

"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe" [2007-12-14 15:25 244208]

"BitDefender Antiphishing Helper"="C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe" [2008-04-13 17:25 61440]

"BDAgent"="C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" [2008-06-24 12:05 368640]

"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-30 00:14 155648]

"OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-03-21 13:19 69632]

"VolPanel"="C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2007-04-17 15:22 184320]

"UpdReg"="C:\Windows\UpdReg.EXE" [2000-05-11 01:00 90112]

"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

"Launch LCDMon"="C:\Program Files\Common Files\Logitech\LCD Manager\LCDMon.exe" [2007-04-26 16:54 774168]

"Launch LGDCore"="C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" [2007-04-26 17:22 1132056]

"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2008-02-13 20:21 202544]

"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-03-24 19:52 13531680]

"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2008-03-24 19:52 92704]

"QCDriverInstaller"="C:\PROGRA~1\COMMON~1\Logitech\QCDriver\Lqdsw.exe" [2001-11-13 15:57 638976]

"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-02-13 13:02 564496]

"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2008-02-13 13:06 2196240]

"Bluetooth HCI Monitor"="HCIMNTR.DLL" [2006-12-08 01:50 9728 C:\Windows\System32\HCIMNTR.DLL]

"PMX Daemon"="ICO.EXE" [2006-11-08 16:01 49152 C:\Windows\System32\ico.exe]

"CTXFIREG"="CTxfiReg.exe" [2008-02-21 13:09 46592 C:\Windows\System32\CTXFIREG.EXE]

"CTxfiHlp"="CTXFIHLP.EXE" [2008-02-21 13:12 23552 C:\Windows\System32\CTXFIHLP.EXE]

 

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\

BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-02-13 12:43:38 715568]

Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-07-01 15:38:22 66864]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]

"{EC9CCE91-C74D-4C17-A593-F6EDA7C2A307}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

"{7D31A71D-3868-454F-BF4F-1876C68E9D68}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour

"{4C2E529D-7117-4E73-88BF-DCC4845222FB}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour

"{04035B2E-773E-414D-BF6C-D93DDCC2570E}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes

"{15FC2B7C-1729-45ED-9D24-7E53C93438BB}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes

"{3880EFC7-C50D-4BF9-B474-817C41472B47}"= UDP:C:\Program Files\Sierra Entertainment\World in Conflict\wic.exe:World in Conflict

"{7D679070-BEDA-4025-90F6-06EAAE0EC54F}"= TCP:C:\Program Files\Sierra Entertainment\World in Conflict\wic.exe:World in Conflict

"{6E30EDCE-09BF-4C87-9493-EB66BF2C050F}"= UDP:C:\Program Files\Sierra Entertainment\World in Conflict\wic_online.exe:World in Conflict - En ligne uniquement

"{658ED5D2-F8B6-45E9-A04A-ED0B58F7CB48}"= TCP:C:\Program Files\Sierra Entertainment\World in Conflict\wic_online.exe:World in Conflict - En ligne uniquement

"{DA98CAFE-F691-4FD4-8824-14C639EF25FE}"= UDP:C:\Program Files\Sierra Entertainment\World in Conflict\wic_ds.exe:World in Conflict - Serveur dédié

"{299E16E3-C102-482B-B9BD-D8C9EF5AD413}"= TCP:C:\Program Files\Sierra Entertainment\World in Conflict\wic_ds.exe:World in Conflict - Serveur dédié

"{624CA91C-0F8E-481B-80D4-94182C2D0854}"= UDP:C:\Program Files\Unreal Tournament 3\Binaries\UT3.exe:Unreal Tournament 3

"{F133FCA3-2645-42D5-A601-7ECF31EA1BA4}"= TCP:C:\Program Files\Unreal Tournament 3\Binaries\UT3.exe:Unreal Tournament 3

"{298EFA7A-B5E2-4E6A-8CE0-E3468DB00AC8}"= UDP:C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe:Sid Meier's Civilization 4

"{BDEE606A-77DF-4B1B-A016-7AAF62517464}"= TCP:C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe:Sid Meier's Civilization 4

"{CB669BCD-7343-44A6-B89B-C1394411CB49}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger

"{6D54F236-7203-46FC-947F-CDA3D8612DD9}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger

"{DCCF7DF2-6EC5-4724-8F10-825324CED304}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger

"{46C0C609-F00F-4F1A-A66E-27C6BC9D7428}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger

"{5748BD2F-4CD8-461D-9EE3-4D67CAFFA41E}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger

"{8D5C7DE3-1E4F-45FA-A97B-525EF5A0ED74}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]

"EnableFirewall"= 0 (0x0)

 

R2 CTAudSvcService;Creative Audio Service;C:\Program Files\Creative\Shared Files\CTAudSvc.exe [2008-03-07 19:24]

R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2008-02-13 20:21]

R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\Windows\system32\DRIVERS\bdfndisf.sys [2008-06-24 12:05]

R3 btwaudio;Périphérique audio Bluetooth;C:\Windows\system32\drivers\btwaudio.sys [2007-04-02 06:42]

R3 btwavdt;Bluetooth AVDT Service;C:\Windows\system32\drivers\btwavdt.sys [2007-04-02 06:42]

R3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2007-04-02 06:42]

R3 ha20x2k;Creative 20X HAL Driver;C:\Windows\system32\drivers\ha20x2k.sys [2008-02-21 14:33]

R3 LVRS;Logitech RightSound Filter Driver;C:\Windows\system32\DRIVERS\lvrs.sys [2008-02-06 04:20]

R3 pmxmouse;PMXMOUSE;C:\Windows\system32\DRIVERS\pmxmouse.sys [2007-06-01 14:41]

R3 pmxusblf;PMXUSBLF;C:\Windows\system32\DRIVERS\pmxusblf.sys [2007-05-24 17:44]

S2 RoxLiveShare10;LiveShare P2P Server 10;"C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe" [2007-12-14 15:25]

S2 RoxWatch10;Roxio Hard Drive Watcher 10;"C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe" [2007-12-14 15:25]

S2 SessionLauncher;SessionLauncher;C:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe []

S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 09:36]

S3 RoxMediaDB10;RoxMediaDB10;"C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe" [2007-12-14 15:25]

S3 Steam Client Service;Steam Client Service;C:\Program Files\Common Files\Steam\SteamService.exe [2008-06-13 10:36]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

bthsvcs REG_MULTI_SZ BthServ

bdx REG_MULTI_SZ scan

 

*Newly Created Service* - CATCHME

.

Contenu du dossier 'Scheduled Tasks/Tâches planifiées'

"2008-06-30 10:24:58 C:\Windows\Tasks\Maintenance en 1 clic.job"

- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe

.

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-07-02 21:22:52

Windows 6.0.6001 Service Pack 1 NTFS

 

Balayage processus cachés ...

 

Balayage caché autostart entries ...

 

Balayage des fichiers cachés ...

 

 

**************************************************************************

.

Temps d'accomplissement: 2008-07-02 21:26:59

ComboFix-quarantined-files.txt 2008-07-02 19:25:37

ComboFix2.txt 2008-07-02 09:59:33

 

Pre-Run: 339,889,303,552 octets libres

Post-Run: 339,852,242,944 octets libres

 

270 --- E O F --- 2008-06-25 07:19:23

Posté(e)

Bon, là, ça marche avec cette version sans heurts apparemment.

Redésactive l'UAC, on passe un script.

 

  • Ouvre le bloc notes. Copie colle ceci dedans :

 

Killall::

 

File::

C:\Windows\System32\drivers\lvuvc.hs

C:\Windows\ehome\ehTray.exe

 

Folder::

C:\Program Files\ShoppingReport

 

Registry::

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ehTray.exe"=-

[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dcf34fba-055f-11dd-b043-806e6f6e6963}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShopperReports]

 

  • Sauvegarde cela comme fichier texte nommé CFScript, sur le bureau.
     
  • Fais un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe comme sur la capture

CFScript.gif

  • Une fenêtre bleue va apparaître: au message qui apparaît (Type 1 to continue, or 2 to abort) , tape 1 puis valide.
  • Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises: c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
  • Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
  • Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt

 

Ensuite ajoute un nouveau rapport HijackThis stp et réactive ton UAC.

Posté(e)
ComboFix 08-07-01.5 - Moissette 2008-07-02 21:40:41.4 - NTFSx86

Microsoft® Windows Vista Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2163 [GMT 2:00]

Endroit: C:\Users\Moissette\Desktop\ComboFix.exe

Command switches used :: C:\Users\Moissette\Desktop\CFScript.txt

* Création d'un nouveau point de restauration

* Resident AV is active

 

 

FILE ::

C:\Windows\ehome\ehTray.exe

C:\Windows\System32\drivers\lvuvc.hs

.

 

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\Windows\System32\drivers\lvuvc.hs

C:\Windows\ehome\ehTray.exe . . . . Echec de suppression

 

.

((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-02 to 2008-07-02 ))))))))))))))))))))))))))))))))))))

.

 

2008-07-02 21:39 . 2008-07-02 21:39 <REP> d-------- C:\327882R2FWJFW

2008-07-02 14:42 . 2008-07-02 14:42 <REP> d-------- C:\_OTMoveIt

2008-07-02 09:25 . 2008-07-02 09:25 <REP> d-------- C:\Program Files\Schmads Inc

2008-07-01 18:49 . 2008-07-01 18:49 <REP> d-------- C:\Deckard

2008-07-01 15:40 . 2008-07-01 15:40 <REP> d-------- C:\Users\Moissette\AppData\Roaming\Malwarebytes

2008-07-01 15:40 . 2008-07-01 15:40 <REP> d-------- C:\ProgramData\Malwarebytes

2008-07-01 15:40 . 2008-07-01 17:06 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware

2008-07-01 15:40 . 2008-06-28 14:16 34,296 --a------ C:\Windows\System32\drivers\mbamcatchme.sys

2008-07-01 15:40 . 2008-06-28 14:16 17,144 --a------ C:\Windows\System32\drivers\mbam.sys

2008-07-01 15:38 . 2008-07-01 15:38 <REP> d-------- C:\Users\Moissette\AppData\Roaming\Leadertech

2008-07-01 15:38 . 2008-07-01 15:38 127,034 -r------- C:\Windows\bwUnin-8.1.1.50-8876480SL.exe

2008-07-01 15:37 . 2008-02-06 04:21 4,658,456 --a------ C:\Windows\System32\drivers\lvuvc.sys

2008-07-01 15:37 . 2008-02-06 04:20 628,760 --a------ C:\Windows\System32\drivers\lvrs.sys

2008-07-01 15:37 . 2008-02-06 04:21 490,008 --a------ C:\Windows\System32\LVUI2.dll

2008-07-01 15:37 . 2008-02-06 04:21 465,432 --a------ C:\Windows\System32\LVUI2RC.dll

2008-07-01 15:37 . 2008-02-06 04:18 416,280 --a------ C:\Windows\System32\lvcodec2.dll

2008-07-01 15:37 . 2008-02-06 04:18 195,096 --a------ C:\Windows\System32\lvci11701196.dll

2008-07-01 15:37 . 2008-02-06 03:37 66,482 --a------ C:\Windows\System32\lvcoinst.ini

2008-07-01 15:37 . 2008-02-06 04:21 41,752 --a------ C:\Windows\System32\drivers\LVUSBSta.sys

2008-07-01 15:37 . 2008-02-06 03:40 25,056 --a------ C:\Windows\System32\Repository.reg

2008-07-01 15:35 . 2008-07-02 18:51 <REP> d-------- C:\ProgramData\Logishrd

2008-06-26 09:41 . 2008-07-02 21:47 81,984 --a------ C:\Windows\System32\bdod.bin

2008-06-26 09:29 . 2008-06-26 09:59 <REP> d-------- C:\Program Files\Common Files\Labtec

2008-06-26 09:28 . 2008-07-01 15:38 <REP> d-------- C:\Program Files\Common Files\LogiShrd

2008-06-26 09:26 . 2008-06-26 09:26 <REP> d-------- C:\Program Files\directx

2008-06-26 09:26 . 2008-06-26 09:46 <REP> d-------- C:\Program Files\Common Files\Real

2008-06-26 09:26 . 2008-06-26 09:26 <REP> d-------- C:\My Music

2008-06-26 09:25 . 2008-06-26 09:26 560 --a------ C:\Windows\_delis32.ini

2008-06-26 09:23 . 2008-06-26 09:50 <REP> d-------- C:\Program Files\Labtec

2008-06-26 08:51 . 2008-06-26 08:53 <REP> d-------- C:\Program Files\GUILD WARS5

2008-06-24 13:18 . 2008-06-25 09:31 <REP> d-------- C:\Program Files\GUILD WARS4

2008-06-22 16:46 . 2008-06-22 16:53 <REP> d-------- C:\Program Files\GUILD WARS2

2008-06-22 16:31 . 2008-06-23 01:14 <REP> d-------- C:\Program Files\GUILD WARS3

2008-06-19 13:13 . 2008-06-19 13:13 <REP> d-------- C:\ProgramData\pixelStorm

2008-06-15 00:10 . 2008-04-23 06:42 428,544 --a------ C:\Windows\System32\EncDec.dll

2008-06-15 00:10 . 2008-04-23 06:42 293,376 --a------ C:\Windows\System32\psisdecd.dll

2008-06-15 00:10 . 2008-04-23 06:41 218,624 --a------ C:\Windows\System32\psisrndr.ax

2008-06-15 00:10 . 2008-04-23 06:41 57,856 --a------ C:\Windows\System32\MSDvbNP.ax

2008-06-11 16:29 . 2008-06-16 11:18 <REP> d-------- C:\Program Files\MappingOut

2008-06-09 21:58 . 2008-06-09 22:20 <REP> d-------- C:\Users\Moissette\AppData\Roaming\MeuhMeuhTV

2008-06-09 21:57 . 2008-06-09 21:57 <REP> d-------- C:\Program Files\MeuhMeuhTV Alpha

2008-06-09 21:35 . 2008-06-09 21:35 <REP> d-------- C:\Program Files\K!TV

2008-06-09 21:13 . 2008-06-09 21:13 <REP> d-------- C:\Users\Moissette\Pinnacle

2008-06-09 21:02 . 2008-06-09 21:02 <REP> d-------- C:\Program Files\Devnz

2008-06-09 18:58 . 2008-06-09 18:58 <REP> d-------- C:\Program Files\DivX

2008-06-09 18:50 . 2008-06-09 21:22 <REP> d-------- C:\Program Files\Pinnacle

2008-06-09 18:49 . 2008-06-09 21:23 <REP> d-------- C:\ProgramData\Pinnacle

2008-06-04 18:19 . 2008-06-04 18:19 <REP> d-------- C:\Program Files\IrfanView

 

.

(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-07-02 19:47 --------- d-----w C:\Program Files\Steam

2008-07-01 13:38 --------- d--h--w C:\Program Files\InstallShield Installation Information

2008-07-01 13:38 --------- d-----w C:\Program Files\Logitech

2008-07-01 13:35 --------- d-----w C:\ProgramData\Logitech

2008-06-30 22:29 --------- d-----w C:\Users\Moissette\AppData\Roaming\teamspeak2

2008-06-30 21:59 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard

2008-06-26 07:29 --------- d-----w C:\Program Files\Common Files\Logitech

2008-06-24 10:05 86,792 ----a-w C:\Windows\system32\drivers\bdfndisf.sys

2008-06-22 14:17 1,634 ----a-w C:\Users\Moissette\AppData\Roaming\wklnhst.dat

2008-06-17 09:56 --------- d-----w C:\Program Files\Common Files\Steam

2008-06-12 01:07 --------- d-----w C:\Program Files\Windows Mail

2008-05-31 15:21 --------- d-----w C:\ProgramData\Media Center Programs

2008-05-31 15:21 --------- d-----w C:\Program Files\GUILD WARS

2008-05-30 16:17 --------- d-----w C:\Program Files\Warcraft III

2008-05-29 22:30 --------- d-----w C:\ProgramData\NVIDIA

2008-05-29 22:04 23,600 ----a-w C:\Windows\system32\drivers\TVICHW32.SYS

2008-05-28 21:29 --------- d-----w C:\Program Files\PC Inspector File Recovery

2008-05-28 21:22 0 ---ha-w C:\Windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf

2008-05-28 20:50 --------- d-----w C:\ProgramData\Roxio

2008-05-28 12:31 --------- d-----w C:\Program Files\Dollcevita

2008-05-25 15:17 0 ---ha-w C:\Windows\system32\drivers\Msft_User_AuxiliaryDisplayEnhancedDriver_01_00_00.Wdf

2008-05-25 15:17 --------- d-----w C:\Program Files\Microsoft Silverlight

2008-05-25 15:06 174 --sha-w C:\Program Files\desktop.ini

2008-05-25 15:00 --------- d-----w C:\Program Files\Windows Sidebar

2008-05-25 15:00 --------- d-----w C:\Program Files\Windows Photo Gallery

2008-05-25 15:00 --------- d-----w C:\Program Files\Windows Journal

2008-05-25 15:00 --------- d-----w C:\Program Files\Windows Defender

2008-05-25 15:00 --------- d-----w C:\Program Files\Windows Collaboration

2008-05-25 15:00 --------- d-----w C:\Program Files\Windows Calendar

2008-05-25 14:50 409,600 ----a-w C:\Windows\System32\wrap_oal.dll

2008-05-25 14:50 114,688 ----a-w C:\Windows\System32\OpenAL32.dll

2008-05-25 13:58 82,432 ----a-w C:\Windows\System32\axaltocm.dll

2008-05-25 13:58 101,888 ----a-w C:\Windows\System32\ifxcardm.dll

2008-05-24 13:46 --------- d-----w C:\Users\Moissette\AppData\Roaming\My Games

2008-05-24 13:38 --------- d-----w C:\Program Files\Firaxis Games

2008-05-12 12:12 --------- d-----w C:\ProgramData\Creative

2008-05-10 01:33 113,664 ----a-w C:\Windows\system32\drivers\rmcast.sys

2008-05-03 17:12 --------- d-----w C:\Program Files\Virtual DJ

2008-04-29 03:54 181,760 ----a-w C:\Windows\System32\fsquirt.exe

2008-04-26 08:08 1,314,816 ----a-w C:\Windows\System32\quartz.dll

2008-04-25 04:35 826,880 ----a-w C:\Windows\System32\wininet.dll

2008-04-14 14:37 2,829 ----a-w C:\Windows\War3Unin.pif

2008-04-14 14:37 139,264 ----a-w C:\Windows\War3Unin.exe

2008-04-13 16:11 988,216 ----a-w C:\Windows\System32\winload.exe

2008-04-13 16:11 927,288 ----a-w C:\Windows\System32\winresume.exe

2008-04-13 16:11 615,992 ----a-w C:\Windows\System32\ci.dll

2008-04-13 16:11 6,656 ----a-w C:\Windows\System32\kbd106n.dll

2008-04-13 16:11 46,592 ----a-w C:\Windows\System32\setbcdlocale.dll

2008-04-13 16:11 40,960 ----a-w C:\Windows\System32\srclient.dll

2008-04-13 16:11 378,368 ----a-w C:\Windows\System32\srcore.dll

2008-04-13 16:11 318,464 ----a-w C:\Windows\System32\rstrui.exe

2008-04-13 16:11 19,000 ----a-w C:\Windows\System32\kd1394.dll

2008-04-13 16:11 14,848 ----a-w C:\Windows\System32\srdelayed.exe

2008-04-13 16:10 295,936 ----a-w C:\Windows\System32\gdi32.dll

2008-04-13 16:10 2,032,128 ----a-w C:\Windows\System32\win32k.sys

2008-04-13 15:24 77,824 ----a-w C:\Windows\System32\xcomm.dll

.

 

((((((((((((((((((((((((((((( snapshot_2008-07-02_21.24.20.08 )))))))))))))))))))))))))))))))))))))))))

.

- 2008-07-02 16:48:54 67,584 --s-a-w C:\Windows\bootstat.dat

+ 2008-07-02 19:46:25 67,584 --s-a-w C:\Windows\bootstat.dat

- 2008-07-02 16:46:03 3,349 ----a-w C:\Windows\bthservsdp.dat

+ 2008-07-02 19:44:35 3,349 ----a-w C:\Windows\bthservsdp.dat

- 2008-07-02 16:50:19 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT

+ 2008-07-02 19:46:54 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT

+ 2008-07-02 19:46:54 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1

- 2008-07-02 16:50:14 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT

+ 2008-07-02 19:46:54 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT

+ 2008-07-02 19:46:54 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1

- 2008-07-02 16:49:02 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2008-07-02 19:46:33 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2008-07-02 16:49:02 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2008-07-02 19:46:33 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2008-07-02 16:49:02 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2008-07-02 19:46:33 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2008-07-02 16:54:07 101,052 ----a-w C:\Windows\System32\perfc009.dat

+ 2008-07-02 19:44:40 101,052 ----a-w C:\Windows\System32\perfc009.dat

- 2008-07-02 16:54:07 123,350 ----a-w C:\Windows\System32\perfc00C.dat

+ 2008-07-02 19:44:40 123,350 ----a-w C:\Windows\System32\perfc00C.dat

- 2008-07-02 16:54:07 586,980 ----a-w C:\Windows\System32\perfh009.dat

+ 2008-07-02 19:44:40 586,980 ----a-w C:\Windows\System32\perfh009.dat

- 2008-07-02 16:54:07 669,340 ----a-w C:\Windows\System32\perfh00C.dat

+ 2008-07-02 19:44:40 669,340 ----a-w C:\Windows\System32\perfh00C.dat

- 2008-07-02 16:50:51 8,856 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2917644237-1699333532-349216916-1000_UserData.bin

+ 2008-07-02 19:39:13 8,856 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2917644237-1699333532-349216916-1000_UserData.bin

- 2008-07-02 16:50:50 71,684 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin

+ 2008-07-02 19:39:12 71,770 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin

- 2008-07-02 16:50:47 49,090 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin

+ 2008-07-02 19:39:10 49,250 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin

.

-- Snapshot reset to current date --

.

((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]

"Steam"="C:\Program Files\Steam\Steam.exe" [2008-04-13 18:35 1271032]

"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2008-02-13 20:21 202544]

"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-04-01 11:39 486856]

"Sidebar"="C:\Program Files\windows sidebar\sidebar.exe" [2008-01-19 09:33 1233920]

"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 09:33 202240]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SunJavaUpdateSched"="c:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2008-04-08 13:47 77824]

"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 16:44 178712]

"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-08 13:57 1838592]

"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-02-13 20:21 16384]

"RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe" [2007-12-14 15:25 244208]

"BitDefender Antiphishing Helper"="C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe" [2008-04-13 17:25 61440]

"BDAgent"="C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" [2008-06-24 12:05 368640]

"SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-30 00:14 155648]

"OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" [2006-03-21 13:19 69632]

"VolPanel"="C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2007-04-17 15:22 184320]

"UpdReg"="C:\Windows\UpdReg.EXE" [2000-05-11 01:00 90112]

"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

"Launch LCDMon"="C:\Program Files\Common Files\Logitech\LCD Manager\LCDMon.exe" [2007-04-26 16:54 774168]

"Launch LGDCore"="C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" [2007-04-26 17:22 1132056]

"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2008-02-13 20:21 202544]

"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-03-24 19:52 13531680]

"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2008-03-24 19:52 92704]

"QCDriverInstaller"="C:\PROGRA~1\COMMON~1\Logitech\QCDriver\Lqdsw.exe" [2001-11-13 15:57 638976]

"LogitechCommunicationsManager"="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-02-13 13:02 564496]

"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2008-02-13 13:06 2196240]

"Bluetooth HCI Monitor"="HCIMNTR.DLL" [2006-12-08 01:50 9728 C:\Windows\System32\HCIMNTR.DLL]

"PMX Daemon"="ICO.EXE" [2006-11-08 16:01 49152 C:\Windows\System32\ico.exe]

"CTXFIREG"="CTxfiReg.exe" [2008-02-21 13:09 46592 C:\Windows\System32\CTXFIREG.EXE]

"CTxfiHlp"="CTXFIHLP.EXE" [2008-02-21 13:12 23552 C:\Windows\System32\CTXFIHLP.EXE]

 

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\

BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-02-13 12:43:38 715568]

Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-07-01 15:38:22 66864]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableUIADesktopToggle"= 0 (0x0)

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]

"{EC9CCE91-C74D-4C17-A593-F6EDA7C2A307}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

"{7D31A71D-3868-454F-BF4F-1876C68E9D68}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour

"{4C2E529D-7117-4E73-88BF-DCC4845222FB}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour

"{04035B2E-773E-414D-BF6C-D93DDCC2570E}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes

"{15FC2B7C-1729-45ED-9D24-7E53C93438BB}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes

"{3880EFC7-C50D-4BF9-B474-817C41472B47}"= UDP:C:\Program Files\Sierra Entertainment\World in Conflict\wic.exe:World in Conflict

"{7D679070-BEDA-4025-90F6-06EAAE0EC54F}"= TCP:C:\Program Files\Sierra Entertainment\World in Conflict\wic.exe:World in Conflict

"{6E30EDCE-09BF-4C87-9493-EB66BF2C050F}"= UDP:C:\Program Files\Sierra Entertainment\World in Conflict\wic_online.exe:World in Conflict - En ligne uniquement

"{658ED5D2-F8B6-45E9-A04A-ED0B58F7CB48}"= TCP:C:\Program Files\Sierra Entertainment\World in Conflict\wic_online.exe:World in Conflict - En ligne uniquement

"{DA98CAFE-F691-4FD4-8824-14C639EF25FE}"= UDP:C:\Program Files\Sierra Entertainment\World in Conflict\wic_ds.exe:World in Conflict - Serveur dédié

"{299E16E3-C102-482B-B9BD-D8C9EF5AD413}"= TCP:C:\Program Files\Sierra Entertainment\World in Conflict\wic_ds.exe:World in Conflict - Serveur dédié

"{624CA91C-0F8E-481B-80D4-94182C2D0854}"= UDP:C:\Program Files\Unreal Tournament 3\Binaries\UT3.exe:Unreal Tournament 3

"{F133FCA3-2645-42D5-A601-7ECF31EA1BA4}"= TCP:C:\Program Files\Unreal Tournament 3\Binaries\UT3.exe:Unreal Tournament 3

"{298EFA7A-B5E2-4E6A-8CE0-E3468DB00AC8}"= UDP:C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe:Sid Meier's Civilization 4

"{BDEE606A-77DF-4B1B-A016-7AAF62517464}"= TCP:C:\Program Files\Firaxis Games\Sid Meier's Civilization 4\Civilization4.exe:Sid Meier's Civilization 4

"{CB669BCD-7343-44A6-B89B-C1394411CB49}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger

"{6D54F236-7203-46FC-947F-CDA3D8612DD9}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger

"{DCCF7DF2-6EC5-4724-8F10-825324CED304}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger

"{46C0C609-F00F-4F1A-A66E-27C6BC9D7428}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger

"{5748BD2F-4CD8-461D-9EE3-4D67CAFFA41E}"= UDP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger

"{8D5C7DE3-1E4F-45FA-A97B-525EF5A0ED74}"= TCP:C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe:Logitech Desktop Messenger

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]

"EnableFirewall"= 0 (0x0)

 

R2 CTAudSvcService;Creative Audio Service;C:\Program Files\Creative\Shared Files\CTAudSvc.exe [2008-03-07 19:24]

R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe [2008-02-13 20:21]

R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\Windows\system32\DRIVERS\bdfndisf.sys [2008-06-24 12:05]

R3 btwaudio;Périphérique audio Bluetooth;C:\Windows\system32\drivers\btwaudio.sys [2007-04-02 06:42]

R3 btwavdt;Bluetooth AVDT Service;C:\Windows\system32\drivers\btwavdt.sys [2007-04-02 06:42]

R3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2007-04-02 06:42]

R3 ha20x2k;Creative 20X HAL Driver;C:\Windows\system32\drivers\ha20x2k.sys [2008-02-21 14:33]

R3 LVRS;Logitech RightSound Filter Driver;C:\Windows\system32\DRIVERS\lvrs.sys [2008-02-06 04:20]

R3 pmxmouse;PMXMOUSE;C:\Windows\system32\DRIVERS\pmxmouse.sys [2007-06-01 14:41]

R3 pmxusblf;PMXUSBLF;C:\Windows\system32\DRIVERS\pmxusblf.sys [2007-05-24 17:44]

S2 RoxLiveShare10;LiveShare P2P Server 10;"C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe" [2007-12-14 15:25]

S2 RoxWatch10;Roxio Hard Drive Watcher 10;"C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe" [2007-12-14 15:25]

S2 SessionLauncher;SessionLauncher;C:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe []

S3 R300;R300;C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 09:36]

S3 RoxMediaDB10;RoxMediaDB10;"C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe" [2007-12-14 15:25]

S3 Steam Client Service;Steam Client Service;C:\Program Files\Common Files\Steam\SteamService.exe [2008-06-13 10:36]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

bthsvcs REG_MULTI_SZ BthServ

bdx REG_MULTI_SZ scan

 

.

Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'

"2008-06-30 10:24:58 C:\Windows\Tasks\Maintenance en 1 clic.job"

- C:\Program Files\TuneUp Utilities 2008\OneClickStarter.exe

.

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-07-02 21:47:04

Windows 6.0.6001 Service Pack 1 NTFS

 

Balayage processus cach‚s ...

 

Balayage cach‚ autostart entries ...

 

Balayage des fichiers cach‚s ...

 

Scan termin‚ avec succŠs

Les fichiers cach‚s: 0

 

**************************************************************************

.

------------------------ Other Running Processes ------------------------

.

C:\Windows\System32\nvvsvc.exe

C:\Windows\System32\audiodg.exe

C:\Windows\System32\WUDFHost.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe

C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe

C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe

C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe

C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe

C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe

C:\Windows\System32\WUDFHost.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe

C:\Windows\System32\conime.exe

C:\Windows\System32\pmxmiced.exe

C:\Windows\System32\rundll32.exe

C:\Windows\System32\CTXFISPI.EXE

C:\Program Files\Windows Media Player\wmpnetwk.exe

C:\Program Files\Schmads Inc\G15_TeamSpeak\G15_TeamSpeak.exe

C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe

C:\Program Files\XPSMiniViewGadget\XPSMiniViewGadget.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe

C:\Program Files\Windows Live\Messenger\usnsvc.exe

C:\Windows\System32\wbem\WMIADAP.exe

C:\Windows\servicing\TrustedInstaller.exe

C:\Windows\System32\dllhost.exe

C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

.

**************************************************************************

.

Temps d'accomplissement: 2008-07-02 21:51:25 - machine was rebooted

ComboFix-quarantined-files.txt 2008-07-02 19:51:20

ComboFix2.txt 2008-07-02 19:27:02

ComboFix3.txt 2008-07-02 09:59:33

 

Pre-Run: 338,420,449,280 octets libres

Post-Run: 338,579,218,432 octets libres

 

308 --- E O F --- 2008-06-25 07:19:23

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 21:52:17, on 02/07/2008

Platform: Windows Vista SP1 (WinNT 6.00.1905)

MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Boot mode: Normal

 

Running processes:

C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe

C:\Windows\system32\Dwm.exe

C:\Windows\system32\taskeng.exe

C:\Program Files\Java\jre1.6.0\bin\jusched.exe

C:\Windows\System32\ico.exe

C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe

C:\Windows\System32\Pmxmiced.exe

C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe

C:\Program Files\ScanSoft\OmniPageSE4.0\OpWareSE4.exe

C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe

C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

C:\Program Files\Common Files\Logitech\LCD Manager\LCDMon.exe

C:\Windows\System32\CTXFIHLP.EXE

C:\Program Files\Dell Support Center\bin\sprtcmd.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe

C:\Program Files\Logitech\QuickCam\Quickcam.exe

C:\Program Files\Windows Live\Messenger\msnmsgr.exe

C:\Windows\SYSTEM32\CTXFISPI.EXE

C:\Program Files\DAEMON Tools Lite\daemon.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

C:\Program Files\Schmads Inc\G15_TeamSpeak\G15_TeamSpeak.exe

C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe

C:\Program Files\XPSMiniViewGadget\XPSMiniViewGadget.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe

C:\Windows\Explorer.exe

C:\Users\Moissette\Desktop\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ig/dell?hl=fr&cli...amp;ibd=6080408

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr/ig/dell?hl=fr&cli...amp;ibd=6080408

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll

O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll

O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll

O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll

O4 - HKLM\..\Run: [bluetooth HCI Monitor] RunDll32 HCIMNTR.DLL,RunCheckHCIMode

O4 - HKLM\..\Run: [sunJavaUpdateSched] "c:\Program Files\Java\jre1.6.0\bin\jusched.exe"

O4 - HKLM\..\Run: [PMX Daemon] ICO.EXE

O4 - HKLM\..\Run: [iAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"

O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup

O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"

O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe"

O4 - HKLM\..\Run: [bitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"

O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"

O4 - HKLM\..\Run: [sSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot

O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"

O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r

O4 - HKLM\..\Run: [updReg] C:\Windows\UpdReg.EXE

O4 - HKLM\..\Run: [CTXFIREG] CTxfiReg.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [Launch LCDMon] "C:\Program Files\Common Files\Logitech\LCD Manager\LCDMon.exe"

O4 - HKLM\..\Run: [Launch LGDCore] "C:\Program Files\Common Files\Logitech\G-series Software\LGDCore.exe" /SHOWHIDE

O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE

O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [QCDriverInstaller] C:\PROGRA~1\COMMON~1\Logitech\QCDriver\Lqdsw.exe /addrun /l 1036 /LaunchAtStart

O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"

O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [steam] "C:\Program Files\Steam\Steam.exe" -silent

O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun

O4 - HKCU\..\Run: [sidebar] C:\Program Files\windows sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - Global Startup: BTTray.lnk = ?

O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe

O8 - Extra context menu item: Easy-WebPrint Ajouter à la liste d'impressions - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html

O8 - Extra context menu item: Easy-WebPrint Impression rapide - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html

O8 - Extra context menu item: Easy-WebPrint Imprimer - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html

O8 - Extra context menu item: Easy-WebPrint Prévisualiser - res://C:\Program Files\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html

O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll

O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm

O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

O13 - Gopher Prefix:

O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.euro.dell.com/systemprofiler/SysPro.CAB

O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab

O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cab

O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://config.zebulon.fr/plugins/hardwaredetection.cab

O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab

O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab

O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL

O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe

O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files\Creative\Shared Files\CTAudSvc.exe

O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe

O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe

O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe

O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe

O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe

O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe

O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

O23 - Service: LiveShare P2P Server 10 (RoxLiveShare10) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe

O23 - Service: RoxMediaDB10 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe

O23 - Service: Roxio Hard Drive Watcher 10 (RoxWatch10) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe

O23 - Service: SessionLauncher - Unknown owner - C:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe (file missing)

O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe

O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe

O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe

O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Common Files\BitDefender\BitDefender Communicator\xcommsvr.exe

 

--

End of file - 11926 bytes

Posté(e)

Le fichier n'a pas dégagé (rare), mais n'est plus actif.

On tentera 2-3 trucs. Sais-tu utiliser un liveCD linux ?

N'oublie pas de réactiver l'UAC.

 

As-tu encore des symptômes infectieux ?

Posté(e)

Bon, on vois demain, de toute façon plus d'infections actives, la machine est ok.

Mais je veux en avoir le coeur net, il y a plusieurs fichiers sous ce nom et emplacement, celui-là est sans doute l'infecté, il ne réagit pas normalement, etc... intéressant quoi ! :P

S'il est infectieux, il faut le virer à coups de pompe, même si c'est un vieux reste. :P

 

@ "demain" (on est déjà demain)

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Invité
Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
×
×
  • Créer...