Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Messages recommandés

Posté(e)

Bonjour à tous,

 

depuis qq semaines (une ou deux) je trouve que mon PC redémarre sans raison beaucoup trop souvent. IL y a aussi certaines phase où il est très lents...

 

J'ai donc suivi la pré-procédure de désinfection avec Antivir (qui a trouvé 6 virus/troyen) et voici le rapport hijackthis à la suite de tout cela.

 

Merci d'avance pour votre aide et votre temps,

 

Cordialement

Vdelab

****************

 

Logfile of HijackThis v1.99.1

Scan saved at 07:40:16, on 01/07/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe

C:\Program Files\Avast4\aswUpdSv.exe

C:\Program Files\Avast4\ashServ.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Avast4\ashMaiSv.exe

C:\Program Files\Avast4\ashWebSv.exe

C:\WINDOWS\Explorer.EXE

C:\PROGRA~1\Avast4\ashDisp.exe

C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe

C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe

C:\Program Files\Acronis\TrueImage\TimounterMonitor.exe

C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe

C:\Program Files\QuickTime\qttask.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Utilitaires_PC\PrintScreen\PrintScreen.exe

C:\WINDOWS\system32\devldr32.exe

C:\Program Files\Vista_Menu\VistaStartMenu.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\Desktop Sidebar\dsidebar.exe

C:\Program Files\Microsoft ActiveSync\wcescomm.exe

C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe

C:\Program Files\DAEMON Tools Lite\daemon.exe

C:\PROGRA~1\MICROS~3\rapimgr.exe

C:\Program Files\Adobe\Acrobat writer\Distillr\acrotray.exe

C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

C:\Program Files\GigaTribe\gigatribe.exe

C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe

C:\Program Files\MSN Messenger\msnmsgr.exe

E:\Utilitaires\cleanup_securite\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =

 

http://www.avast.com/fre/faq-red-circle.html

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =

 

*.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program

 

Files\Adobe\Acrobat writer\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} -

 

C:\Program Files\Desktop Sidebar\sbhelp.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program

 

Files\Utilitaire_securite\Spybot\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program

 

Files\Java\jre1.6.0_06\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} -

 

C:\Program Files\Adobe\Acrobat writer\Acrobat\AcroIEFavClient.dll

O3 - Toolbar: Spb Wallet - {2913D3DD-9363-4C21-B205-C19A584A0674} - C:\Program Files\Spb

 

Wallet\SpbWalletToolbar.dll

O3 - Toolbar: Copernic Desktop Search 2 - {968631B6-4729-440D-9BF4-251F5593EC9A} -

 

C:\Program Files\Copernic Desktop Search 2\DesktopSearchBand201013011.dll

O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program

 

Files\Adobe\Acrobat writer\Acrobat\AcroIEFavClient.dll

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program

 

Files\Acronis\TrueImage\TrueImageMonitor.exe

O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program

 

Files\Acronis\TrueImage\TimounterMonitor.exe

O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Fichiers

 

communs\Acronis\Schedule2\schedhlp.exe"

O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software

 

Update\HPWuSchd2.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\CloneCD\ElbyCheck.exe" /L ElbyCDFL

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE

 

C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program

 

Files\Java\jre1.6.0_06\bin\jusched.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [iM Sniffer] "C:\Program Files\IM Sniffer\IMSniffer.exe" -start

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [Gadwin PrintScreen] C:\Program

 

Files\Utilitaires_PC\PrintScreen\PrintScreen.exe /nosplash

O4 - HKCU\..\Run: [VistaStartMenu] "C:\Program Files\Vista_Menu\VistaStartMenu.exe"

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [sIDEBAR] "C:\Program Files\Desktop Sidebar\dsidebar.exe"

O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft

 

ActiveSync\wcescomm.exe"

O4 - HKCU\..\Run: [Copernic Desktop Search 2] "C:\Program Files\Copernic Desktop Search

 

2\DesktopSearchService.exe" /tray

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe"

 

-autorun

O4 - Startup: GigaTribe.lnk = C:\Program Files\GigaTribe\gigatribe.exe

O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader

 

8.0\Reader\AdobeCollabSync.exe

O4 - Global Startup: Assistant d'Acrobat.lnk = C:\Program Files\Adobe\Acrobat

 

writer\Distillr\acrotray.exe

O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program

 

Files\HP\Digital Imaging\bin\hpqthb08.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital

 

Imaging\bin\hpqtra08.exe

O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Reader

 

8.0\Reader\reader_sl.exe

O8 - Extra context menu item: E&xporter vers Microsoft Excel -

 

res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

 

Files\Java\jre1.6.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}

 

- C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll

O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80}

 

- C:\Program Files\Desktop Sidebar\sbhelp.dll

O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar -

 

{09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll

O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} -

 

C:\PROGRA~1\MICROS~3\INetRepl.dll

O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} -

 

C:\PROGRA~1\MICROS~3\INetRepl.dll

O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... -

 

{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -

 

C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

 

C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)

O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

 

C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)

O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

 

http://update.microsoft.com/windowsupdate/...eb_site.cab?117

 

5965340296

O16 - DPF: {D5D30A68-E230-49D9-B4D5-BF7532692945} (CDiscountObj Class) -

 

https://clients.cdiscount.com/ediag/activex/CDiscount.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{5CB08976-916D-4D87-B0D2-18F0D6B83E87}:

 

NameServer = 192.168.1.1

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} -

 

C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program

 

Files\Fichiers communs\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} -

 

C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} -

 

C:\PROGRA~1\FICHIE~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O20 - Winlogon Notify: senscfg32 - C:\WINDOWS\SYSTEM32\senscfg32.dll

O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\

O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program

 

Files\Fichiers communs\Acronis\Schedule2\schedul2.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program

 

Files\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program

 

Files\Avast4\ashMaiSv.exe" /service (file missing)

O23 - Service: avast! Web Scanner - Unknown owner - C:\Program

 

Files\Avast4\ashWebSv.exe" /service (file missing)

O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) -

 

Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program

 

Files\Canon\CAL\CALMAIN.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program

 

Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation -

 

C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -

 

C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: VTingWinIe - Unknown owner - C:\WINDOWS\system32\drivers\svchost.exe

 

(file missing)

************************

Posté(e)

Bonsoir,

 

suite à la remarque de thorgal, voici un nouveau log Hijackthis, avec la version plus récente...

 

 

Merci à tous...

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 20:23:27, on 01/07/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe

C:\Program Files\Avast4\aswUpdSv.exe

C:\Program Files\Avast4\ashServ.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Avast4\ashMaiSv.exe

C:\Program Files\Avast4\ashWebSv.exe

C:\WINDOWS\Explorer.EXE

C:\PROGRA~1\Avast4\ashDisp.exe

C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe

C:\Program Files\Acronis\TrueImage\TimounterMonitor.exe

C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe

C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe

C:\Program Files\QuickTime\qttask.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Utilitaires_PC\PrintScreen\PrintScreen.exe

C:\WINDOWS\system32\devldr32.exe

C:\Program Files\Vista_Menu\VistaStartMenu.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\Desktop Sidebar\dsidebar.exe

C:\Program Files\Microsoft ActiveSync\wcescomm.exe

C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe

C:\Program Files\DAEMON Tools Lite\daemon.exe

C:\PROGRA~1\MICROS~3\rapimgr.exe

C:\Program Files\Adobe\Acrobat writer\Distillr\acrotray.exe

C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Program Files\GigaTribe\gigatribe.exe

C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe

C:\Program Files\MSN Messenger\msnmsgr.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =

 

http://www.avast.com/fre/faq-red-circle.html

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =

 

*.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program

 

Files\Adobe\Acrobat writer\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Idea2 SidebarBrowserMonitor Class - {45AD732C-2CE2-4666-B366-B2214AD57A49} -

 

C:\Program Files\Desktop Sidebar\sbhelp.dll

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program

 

Files\Utilitaire_securite\Spybot\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program

 

Files\Java\jre1.6.0_06\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} -

 

C:\Program Files\Adobe\Acrobat writer\Acrobat\AcroIEFavClient.dll

O3 - Toolbar: Spb Wallet - {2913D3DD-9363-4C21-B205-C19A584A0674} - C:\Program Files\Spb

 

Wallet\SpbWalletToolbar.dll

O3 - Toolbar: Copernic Desktop Search 2 - {968631B6-4729-440D-9BF4-251F5593EC9A} -

 

C:\Program Files\Copernic Desktop Search 2\DesktopSearchBand201013011.dll

O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program

 

Files\Adobe\Acrobat writer\Acrobat\AcroIEFavClient.dll

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program

 

Files\Acronis\TrueImage\TrueImageMonitor.exe

O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program

 

Files\Acronis\TrueImage\TimounterMonitor.exe

O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Fichiers

 

communs\Acronis\Schedule2\schedhlp.exe"

O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software

 

Update\HPWuSchd2.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\CloneCD\ElbyCheck.exe" /L ElbyCDFL

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE

 

C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program

 

Files\Java\jre1.6.0_06\bin\jusched.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [iM Sniffer] "C:\Program Files\IM Sniffer\IMSniffer.exe" -start

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [Gadwin PrintScreen] C:\Program

 

Files\Utilitaires_PC\PrintScreen\PrintScreen.exe /nosplash

O4 - HKCU\..\Run: [VistaStartMenu] "C:\Program Files\Vista_Menu\VistaStartMenu.exe"

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [sIDEBAR] "C:\Program Files\Desktop Sidebar\dsidebar.exe"

O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft

 

ActiveSync\wcescomm.exe"

O4 - HKCU\..\Run: [Copernic Desktop Search 2] "C:\Program Files\Copernic Desktop Search

 

2\DesktopSearchService.exe" /tray

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe"

 

-autorun

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE

 

LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE

 

RÉSEAU')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default

 

user')

O4 - Startup: GigaTribe.lnk = C:\Program Files\GigaTribe\gigatribe.exe

O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader

 

8.0\Reader\AdobeCollabSync.exe

O4 - Global Startup: Assistant d'Acrobat.lnk = C:\Program Files\Adobe\Acrobat

 

writer\Distillr\acrotray.exe

O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program

 

Files\HP\Digital Imaging\bin\hpqthb08.exe

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital

 

Imaging\bin\hpqtra08.exe

O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Reader

 

8.0\Reader\reader_sl.exe

O8 - Extra context menu item: E&xporter vers Microsoft Excel -

 

res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

 

Files\Java\jre1.6.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}

 

- C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll

O9 - Extra button: Subscribe in Desktop Sidebar - {09FE188B-6E85-479e-9411-51FB2220DF80}

 

- C:\Program Files\Desktop Sidebar\sbhelp.dll

O9 - Extra 'Tools' menuitem: Subscribe in Desktop Sidebar -

 

{09FE188B-6E85-479e-9411-51FB2220DF80} - C:\Program Files\Desktop Sidebar\sbhelp.dll

O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} -

 

C:\PROGRA~1\MICROS~3\INetRepl.dll

O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} -

 

C:\PROGRA~1\MICROS~3\INetRepl.dll

O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... -

 

{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -

 

C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

 

C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)

O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

 

C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

 

http://update.microsoft.com/windowsupdate/...eb_site.cab?117

 

5965340296

O16 - DPF: {D5D30A68-E230-49D9-B4D5-BF7532692945} (CDiscountObj Class) -

 

https://clients.cdiscount.com/ediag/activex/CDiscount.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{5CB08976-916D-4D87-B0D2-18F0D6B83E87}:

 

NameServer = 192.168.1.1

O20 - Winlogon Notify: senscfg32 - C:\WINDOWS\SYSTEM32\senscfg32.dll

O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program

 

Files\Fichiers communs\Acronis\Schedule2\schedul2.exe

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program

 

Files\Avast4\aswUpdSv.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program

 

Files\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program

 

Files\Avast4\ashWebSv.exe

O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) -

 

Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program

 

Files\Canon\CAL\CALMAIN.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program

 

Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation -

 

C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation -

 

C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

O23 - Service: VTingWinIe - Unknown owner - C:\WINDOWS\system32\drivers\svchost.exe

 

(file missing)

 

--

End of file - 9710 bytes

Posté(e)

  • Télécharge SmitFraudFix de S!Ri sur le bureau :
    http://siri.urz.free.fr/Fix/SmitfraudFix.exe
  • Note: si tu as une version de SmitfraudFix, ne l'utilise pas, élimine là et télécharge la dernière version.
  • Double-clique sur smitfraudfix.exe
  • Choisis l'option 1 pour créer un rapport des fichiers responsables de l'infection.
  • Poste le rapport sur le forum dans ta prochaine réponse. (si tu ne le trouves pas, il est dans "C:\rapport.txt")

 

 

Si process.exe est détecté par ton antivirus ou un autre logiciel, n'en tiens pas compte (choisis d'ignorer) et ne bloque pas le fichier, il sert à terminer des processus, d'où l'alerte émise par ces antivirus qui y voient un danger potentiel. (doc).

Posté(e)

Bonsoir,

 

voici le rapport Smitfraudfix:

 

je ne connaissais pas cet outils... quel différences avec Hijack?

 

Abientot,

 

********************************

 

SmitFraudFix v2.328

 

Rapport fait à 19:32:07,31, 02/07/2008

Executé à partir de C:\Program Files\Mozilla Firefox\SmitfraudFix

OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT

Le type du système de fichiers est NTFS

Fix executé en mode normal

 

»»»»»»»»»»»»»»»»»»»»»»»» Process

 

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe

C:\Program Files\Avast4\aswUpdSv.exe

C:\Program Files\Avast4\ashServ.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Avast4\ashMaiSv.exe

C:\Program Files\Avast4\ashWebSv.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\Explorer.EXE

C:\PROGRA~1\Avast4\ashDisp.exe

C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe

C:\Program Files\Acronis\TrueImage\TimounterMonitor.exe

C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe

C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe

C:\Program Files\QuickTime\qttask.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Utilitaires_PC\PrintScreen\PrintScreen.exe

C:\Program Files\Vista_Menu\VistaStartMenu.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\Desktop Sidebar\dsidebar.exe

C:\Program Files\Microsoft ActiveSync\wcescomm.exe

C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe

C:\Program Files\DAEMON Tools Lite\daemon.exe

C:\Program Files\Adobe\Acrobat writer\Distillr\acrotray.exe

C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Program Files\GigaTribe\gigatribe.exe

C:\PROGRA~1\MICROS~3\rapimgr.exe

C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe

C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Mozilla Firefox\SmitfraudFix\Policies.exe

C:\WINDOWS\system32\cmd.exe

 

»»»»»»»»»»»»»»»»»»»»»»»» hosts

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Vincent

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Vincent\Application Data

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Vincent\Favoris

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Bureau

 

 

»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]

"Source"="About:Home"

"SubscribedURL"="About:Home"

"FriendlyName"="Ma page d'accueil"

 

 

»»»»»»»»»»»»»»»»»»»»»»»» IEDFix

!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

 

IEDFix

Credits: Malware Analysis & Diagnostic

Code: S!Ri

 

 

 

»»»»»»»»»»»»»»»»»»»»»»»» VACFix

!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

 

VACFix

Credits: Malware Analysis & Diagnostic

Code: S!Ri

 

 

»»»»»»»»»»»»»»»»»»»»»»»» 404Fix

!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

 

404Fix

Credits: Malware Analysis & Diagnostic

Code: S!Ri

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler

!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

 

SrchSTS.exe by S!Ri

Search SharedTaskScheduler's .dll

 

 

»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs

!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]

"AppInit_DLLs"=""

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Winlogon

!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

"Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"

"System"=""

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Rustock

 

 

 

»»»»»»»»»»»»»»»»»»»»»»»» DNS

 

Description: Carte Ethernet Realtek PCI RTL8029(AS) - Miniport d'ordonnancement de

 

paquets

DNS Server Search Order: 192.168.1.1

 

HKLM\SYSTEM\CCS\Services\Tcpip\..\{5CB08976-916D-4D87-B0D2-18F0D6B83E87}:

 

NameServer=192.168.1.1

HKLM\SYSTEM\CS1\Services\Tcpip\..\{5CB08976-916D-4D87-B0D2-18F0D6B83E87}:

 

NameServer=192.168.1.1

HKLM\SYSTEM\CS3\Services\Tcpip\..\{5CB08976-916D-4D87-B0D2-18F0D6B83E87}:

 

NameServer=192.168.1.1

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

 

 

»»»»»»»»»»»»»»»»»»»»»»»» Fin

Posté(e)

HijackThis est avant tout un outil de diagnostic, smitFraudFix traite certaines infections.

Attention avec le suivant, à bien respecter la procédure (outil puissant et dangereux si on ne fait pas gaffe).

 

Télécharge combofix.exe de sUBs et sauvegarde le sur ton bureau (et pas ailleurs).

  • Assure toi que tous les programmes sont fermés avant de commencer.
  • Double-clique combofix.exe afin de l'exécuter.
  • Clique sur "Oui" au message de Limitation de Garantie qui s'affiche.
  • Il est possible que ton parefeu te demande si tu acceptes ou non l'accès de nircmd.cfexe à la zone sûre: accepte.
  • Ne ferme pas la fenêtre qui vient de s'ouvrir, tu te retrouverais avec un bureau vide.
  • Lorsque l'analyse sera terminée, un rapport apparaîtra.
  • Copie-colle ce rapport dans ta prochaine réponse.
    Le rapport se trouve dans : C:\Combofix.txt (si jamais).
  • Pour plus d'information et un tuto illustré, voici le seul tuto officiel et autorisé : http://www.bleepingcomputer.com/combofix/f...iliser-combofix

Posté(e)

Re-bonsoir, et merci de ton aide.

 

VOici le rapport combofix :

**************

 

 

ComboFix 08-07-01.5 - Vincent 2008-07-02 23:28:22.1 - NTFSx86

Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.358 [GMT 2:00]

Endroit: C:\Documents and Settings\Vincent\Bureau\ComboFix.exe

* Création d'un nouveau point de restauration

.

 

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))

.

 

.

((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

-------\Legacy_NPF

 

 

((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-02 to 2008-07-02 ))))))))))))))))))))))))))))))))))))

.

 

2008-07-02 19:32 . 2008-07-02 19:32 2,142 --a------ C:\WINDOWS\system32\tmp.reg

2008-06-30 21:07 . 2008-07-01 07:12 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira

2008-06-23 23:23 . 2008-06-24 19:43 <REP> d-------- C:\WINDOWS\SxsCaPendDel

2008-06-22 15:42 . 2008-06-22 15:42 <REP> d-------- C:\Documents and Settings\Vincent\Application Data\Apple Computer

2008-06-22 15:02 . 2008-06-22 15:02 54,156 --ah----- C:\WINDOWS\QTFont.qfn

2008-06-22 15:02 . 2008-06-22 15:02 1,409 --a------ C:\WINDOWS\QTFont.for

2008-06-22 14:28 . 2008-06-22 14:28 <REP> d-------- C:\Program Files\GigaTribe

2008-06-22 14:28 . 2008-06-29 12:37 <REP> d-------- C:\Documents and Settings\Vincent\Application Data\GigaTribe

2008-06-07 15:59 . 2008-06-07 15:59 <REP> d-------- C:\Documents and Settings\LocalService\Menu D‚marrer

2008-06-07 14:22 . 2008-06-07 14:25 <REP> d-------- C:\Program Files\parental-filter

2008-06-07 14:22 . 2006-09-02 19:10 757,760 --a------ C:\WINDOWS\system32\UniBasic100_EDA1811C.ocx

2008-06-07 14:22 . 2004-03-09 00:00 224,016 --a------ C:\WINDOWS\system32\TABCTL32.OCX

2008-06-07 14:22 . 2006-09-02 19:05 163,840 --a------ C:\WINDOWS\system32\UniTextBoxEx100_EDA1811C.ocx

2008-06-07 14:02 . 2008-06-07 14:02 <REP> d--hs---- C:\found.000

2008-06-07 09:53 . 2008-06-07 09:53 <REP> d-------- C:\Documents and Settings\Enfant\Contacts

 

.

(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))

.

2008-07-02 21:31 --------- d-----w C:\Documents and Settings\Vincent\Application Data\Desktop Sidebar

2008-07-02 17:16 --------- d-----w C:\Documents and Settings\Vincent\Application Data\Vista Start Menu

2008-07-01 21:22 --------- d-----w C:\Documents and Settings\Vincent\Application Data\Azureus

2008-07-01 18:49 --------- d-----w C:\Program Files\Azureus

2008-06-24 20:04 --------- d-----w C:\Program Files\Microsoft ActiveSync

2008-06-24 20:03 --------- d-----w C:\Program Files\Utilitaires_PC

2008-06-23 21:23 --------- d--h--w C:\Program Files\InstallShield Installation Information

2008-06-18 21:13 --------- d-----w C:\Program Files\Worms4

2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys

2008-06-07 07:31 --------- d-----w C:\Program Files\Steam

2008-06-01 14:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy

2008-06-01 10:05 --------- d-----w C:\Program Files\Java

2008-05-30 21:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet

2008-05-27 19:13 --------- d-----w C:\Program Files\MagicISO

2008-05-26 08:56 --------- d-----w C:\Program Files\Avast4

2008-05-25 19:12 691,545 ----a-w C:\WINDOWS\unins000.exe

2008-05-25 13:27 --------- d-----w C:\Program Files\DAEMON Tools Lite

2008-05-18 19:17 717,296 ----a-w C:\WINDOWS\system32\drivers\sptd.sys

2008-05-18 19:16 --------- d-----w C:\Documents and Settings\Vincent\Application Data\DAEMON Tools

2008-05-18 17:58 --------- d-----w C:\Program Files\Spb Software House

2008-05-17 18:42 --------- d-----w C:\Program Files\Spb Wallet

2008-05-14 22:30 --------- d-----w C:\Documents and Settings\Vincent\Application Data\AdobeUM

2008-05-14 22:26 --------- d-----w C:\Program Files\Fichiers communs\Adobe

2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys

.

 

((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

REGEDIT4

*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{2913D3DD-9363-4C21-B205-C19A584A0674}"= "C:\Program Files\Spb Wallet\SpbWalletToolbar.dll" [2007-07-03 15:53 114688]

 

[HKEY_CLASSES_ROOT\clsid\{2913d3dd-9363-4c21-b205-c19a584a0674}]

[HKEY_CLASSES_ROOT\SpbWalletToolbar.WalletToolbar.1]

[HKEY_CLASSES_ROOT\TypeLib\{48210861-28ED-416C-A316-5906D5FC6698}]

[HKEY_CLASSES_ROOT\SpbWalletToolbar.WalletToolbar]

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 17:09 15360]

"Gadwin PrintScreen"="C:\Program Files\Utilitaires_PC\PrintScreen\PrintScreen.exe" [2007-04-20 16:40 507904]

"VistaStartMenu"="C:\Program Files\Vista_Menu\VistaStartMenu.exe" [2007-10-29 18:47 1682944]

"SIDEBAR"="C:\Program Files\Desktop Sidebar\dsidebar.exe" [2006-07-09 22:58 1777664]

"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 15:07 1289000]

"Copernic Desktop Search 2"="C:\Program Files\Copernic Desktop Search 2\DesktopSearchService.exe" [2007-08-01 20:26 1514016]

"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-04-01 11:39 486856]

"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe" [2006-07-06 13:52 1126497]

"AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImage\TimounterMonitor.exe" [2006-07-06 13:55 1868040]

"Acronis Scheduler2 Service"="C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe" [2006-07-05 20:40 126976]

"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 15:49 49152]

"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]

"CloneCDElbyCDFL"="C:\Program Files\CloneCD\ElbyCheck.exe" [2001-12-06 14:09 45056]

"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22 7700480]

"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-10-22 12:22 86016]

"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]

"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-07 19:33 282624]

"nwiz"="nwiz.exe" [2006-10-22 12:22 1622016 C:\WINDOWS\system32\nwiz.exe]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-19 17:09 15360]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\senscfg32]

2004-01-05 09:47 8704 C:\WINDOWS\system32\senscfg32.dll

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"aux"= ctwdm32.dll

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Authentication Packages REG_MULTI_SZ msv1_0 relog_ap

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"C:\\WINDOWS\\system32\\sessmgr.exe"=

"C:\\Program Files\\Steam\\SteamApps\\vdelab\\counter-strike source\\hl2.exe"=

"C:\\Program Files\\Graphisoft\\ArchiCAD 10\\ArchiCAD.exe"=

"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=

"C:\\Program Files\\MSN Messenger\\livecall.exe"=

"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager

"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager

"C:\\Program Files\\Microsoft Money 2005\\MNYCoreFiles\\msmoney.exe"=

"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=

"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application

"C:\\Program Files\\Azureus\\Azureus.exe"=

"C:\\Program Files\\Steam\\SteamApps\\vdelab\\team fortress 2\\hl2.exe"=

"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=

"C:\\Program Files\\Worms4\\WORMS 4 MAYHEM.EXE"=

"C:\\Program Files\\GigaTribe\\gigatribe.exe"=

"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=

"C:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=

"C:\\Program Files\\Acronis\\TrueImage\\TrueImage.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"7654:TCP"= 7654:TCP:Emule port

"7664:UDP"= 7664:UDP:emule UDP

"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

"3671:TCP"= 3671:TCP:messenger

"8621:TCP"= 8621:TCP:messenger

"7643:TCP"= 7643:TCP:messenger

"7667:TCP"= 7667:TCP:messenger

"8723:TCP"= 8723:TCP:messenger

"6776:TCP"= 6776:TCP:messenger

"1816:TCP"= 1816:TCP:messenger

"5851:TCP"= 5851:TCP:messenger

"2854:TCP"= 2854:TCP:messenger

"5575:TCP"= 5575:TCP:messenger

"8561:TCP"= 8561:TCP:messenger

"4513:TCP"= 4513:TCP:messenger

"3163:TCP"= 3163:TCP:messenger

"4753:TCP"= 4753:TCP:messenger

"8584:TCP"= 8584:TCP:messenger

"3684:TCP"= 3684:TCP:messenger

 

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]

R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]

S0 AlfaFF;Alfa File System Mini-Filter;C:\WINDOWS\system32\Drivers\AlfaFF.sys []

S0 d344prt;d344prt;C:\WINDOWS\system32\Drivers\d344prt.sys []

S2 VTingWinIe;VTingWinIe;C:\WINDOWS\system32\drivers\svchost.exe []

 

.

- - - - ORPHANS REMOVED - - - -

 

HKLM-Run-IM Sniffer - C:\Program Files\IM Sniffer\IMSniffer.exe

Notify-WgaLogon - (no file)

 

 

**************************************************************************

 

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-07-02 23:34:27

Windows 5.1.2600 Service Pack 2 NTFS

 

Balayage processus cach‚s ...

 

Balayage cach‚ autostart entries ...

 

Balayage des fichiers cach‚s ...

 

Scan termin‚ avec succŠs

Les fichiers cach‚s: 0

 

**************************************************************************

.

------------------------ Other Running Processes ------------------------

.

C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe

C:\Program Files\Avast4\aswUpdSv.exe

C:\Program Files\Avast4\ashServ.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\Program Files\Avast4\ashMaiSv.exe

C:\Program Files\Avast4\ashWebSv.exe

C:\WINDOWS\system32\rundll32.exe

C:\WINDOWS\system32\rundll32.exe

C:\WINDOWS\system32\devldr32.exe

C:\Program Files\Adobe\Acrobat writer\Distillr\acrotray.exe

C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

C:\Program Files\GigaTribe\gigatribe.exe

C:\PROGRA~1\MICROS~3\rapimgr.exe

C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe

C:\Program Files\MSN Messenger\msnmsgr.exe

.

**************************************************************************

.

Temps d'accomplissement: 2008-07-02 23:40:57 - machine was rebooted

ComboFix-quarantined-files.txt 2008-07-02 21:40:40

 

Pre-Run: 19,977,994,240 octets libres

Post-Run: 20,334,972,928 octets libres

 

180 --- E O F --- 2008-06-24 20:05:08

Posté(e)

Rends toi sur ce lien : Virus Total

  • Clique sur le bouton Parcourir...
  • Parcours tes dossiers jusque à ce fichier, si tu le trouves :

  • C:\Program Files\Messenger\msmsgs.exe

  • Clique sur Envoyer le fichier, et si VirusTotal dit que le fichier a déjà été analysé, clique sur le bouton Reanalyse le fichier maintenant.
  • Laisse le site travailler tant que "Situation actuelle : en cours d'analyse" est affiché.
  • Il est possible que le fichier soit mis en file d'attente en raison d'un grand nombre de demandes d'analyses. Dans ce cas, il te faudra patienter sans réactualiser la page.
  • Lorsque l'analyse est terminée ("Situation actuelle: terminé"), clique sur Formaté (en haut à gauche)
  • Une nouvelle fenêtre de ton navigateur va apparaître
  • Clique alors sur cette image : txtvt.jpg
  • Fais un clic droit sur la page, et choisis Sélectionner tout, puis copier
  • Enfin colle le résultat dans ta prochaine réponse.
    NB : Peu importe le résultat, il est important de me communiquer le résultat de toute l'analyse.

Il est possible que tes outils de sécurité réagissent à l'envoi du fichier, auquel cas il faudra leur faire ignorer les alertes.

 

 

Ensuite, refais la même chose pour ce fichier stp :

 

C:\WINDOWS\SYSTEM32\senscfg32.dll

 

Je te préparerai un script pour shooter 2-3 choses après ça.

Posté(e)

Bonjour,

 

voici le rapport d'analyse de msmsgs.exe

****

 

Fichier msmsgs.exe reçu le 2008.07.03 07:33:58 (CET)

Antivirus Version Dernière mise à jour Résultat

AhnLab-V3 2008.7.2.0 2008.07.02 -

AntiVir 7.8.0.64 2008.07.02 -

Authentium 5.1.0.4 2008.07.02 -

Avast 4.8.1195.0 2008.07.02 -

AVG 7.5.0.516 2008.07.02 -

BitDefender 7.2 2008.07.03 -

CAT-QuickHeal 9.50 2008.07.02 -

ClamAV 0.93.1 2008.07.03 -

DrWeb 4.44.0.09170 2008.07.02 -

eSafe 7.0.17.0 2008.07.02 -

eTrust-Vet 31.6.5922 2008.07.02 -

Ewido 4.0 2008.07.02 -

F-Prot 4.4.4.56 2008.07.02 -

F-Secure 7.60.13501.0 2008.07.01 -

Fortinet 3.14.0.0 2008.07.03 -

GData 2.0.7306.1023 2008.07.03 -

Ikarus T3.1.1.26.0 2008.07.03 -

Kaspersky 7.0.0.125 2008.07.03 -

McAfee 5330 2008.07.02 -

Microsoft 1.3704 2008.07.03 -

NOD32v2 3236 2008.07.03 -

Norman 5.80.02 2008.07.02 -

Panda 9.0.0.4 2008.07.02 -

Prevx1 V2 2008.07.03 -

Rising 20.51.30.00 2008.07.03 -

Sophos 4.30.0 2008.07.03 -

Sunbelt 3.1.1509.1 2008.07.03 -

Symantec 10 2008.07.03 -

TheHacker 6.2.96.367 2008.07.03 -

TrendMicro 8.700.0.1004 2008.07.03 -

VBA32 3.12.6.8 2008.07.02 -

VirusBuster 4.5.11.0 2008.07.02 -

Webwasher-Gateway 6.6.2 2008.07.02 -

Information additionnelle

File size: 1694208 bytes

MD5...: 74e6e96c6f0e2eca4edbb7f7a468f259

SHA1..: 1b4729d1bd15e4d48422ecb5730959390c0be1c7

SHA256: 58d083fe62a47860de7e4d87ec74f1e900c1b1824a3e8c2b94ce07936af0d0d1

SHA512: 1fce520104f0a1f65db3be0e342f2e2d762da6da2250945d9102a3fc8a0368c4<br>3413b7185065212bceddb8337ef637d4d02197274845d700a0c8afbc3260f8f4

PEiD..: -

PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x105ed21<br>timedatestamp.....: 0x416d56bc (Wed Oct 13 16:24:28 2004)<br>machinetype.......: 0x14c (I386)<br><br>( 3 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x10fbe6 0x10fc00 6.53 a2343f3d5b70293a37b342ddbd9cb5f8<br>.data 0x111000 0x40c8 0x1800 3.88 725045f0fc6510e86034ba5c7df46e12<br>.rsrc 0x116000 0x8c120 0x8c200 6.49 aed27941d66b8f0cf79ff84ebac40cb8<br><br>( 20 imports ) <br>> msvcrt.dll: abort, _wtoi, _ftol, wcsncpy, __CxxFrameHandler, vswprintf, sprintf, _CxxThrowException, tolower, realloc, memset, fread, strncpy, _vscwprintf, _setjmp3, longjmp, _mbsstr, time, fprintf, _iob, strtod, _CIpow, _wcsnicmp, _wcsicmp, wcscmp, wcsspn, wcscspn, _strlwr, strtok, __1type_info@@UAE@XZ, _controlfp, _onexit, __dllonexit, __set_app_type, __p__fmode, __p__commode, _adjust_fdiv, __setusermatherr, _initterm, __getmainargs, _acmdln, exit, _cexit, _XcptFilter, _exit, _c_exit, memmove, wcslen, _wcslwr, wcsrchr, malloc, _purecall, __2@YAPAXI@Z, __3@YAXPAX@Z, free, _terminate@@YAXXZ, _except_handler3<br>> ADVAPI32.dll: OpenThreadToken, ImpersonateSelf, RegDeleteKeyA, RegCreateKeyExA, RegOpenKeyExA, CryptAcquireContextW, CryptCreateHash, CryptHashData, CryptGetHashParam, CryptDestroyHash, CryptReleaseContext, RegisterEventSourceW, ReportEventW, DeregisterEventSource, RegDeleteKeyW, RegEnumKeyW, RegQueryInfoKeyW, RegDeleteValueA, RegDeleteValueW, RegQueryValueExA, RegQueryValueExW, RegSetValueExA, RegSetValueExW, RegCreateKeyExW, RegFlushKey, OpenProcessToken, RegCloseKey, RegOpenKeyExW, AllocateAndInitializeSid, InitializeSecurityDescriptor, GetLengthSid, InitializeAcl, AddAccessAllowedAce, SetSecurityDescriptorDacl, FreeSid, RevertToSelf, AccessCheck, IsValidSecurityDescriptor, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, RegEnumKeyA<br>> KERNEL32.dll: GetProcessHeap, HeapSize, HeapReAlloc, HeapFree, HeapAlloc, HeapDestroy, GetVersionExA, GetStartupInfoA, GetModuleHandleA, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, QueryPerformanceCounter, IsValidLocale, LoadLibraryA, GetCurrentProcessId, GetUserDefaultLCID, lstrcpynA, GetCurrentDirectoryW, GetWindowsDirectoryW, SetCurrentDirectoryW, GetDateFormatW, GetTimeFormatW, GetSystemTimeAsFileTime, GetLocalTime, SystemTimeToFileTime, ExpandEnvironmentStringsW, FindFirstFileW, GetTempPathW, GetTempFileNameW, GetModuleFileNameW, FindResourceExW, FindResourceW, LoadResource, LockResource, SizeofResource, FormatMessageW, GetSystemDefaultUILanguage, GlobalMemoryStatus, CreateDirectoryW, GlobalFree, GetFileAttributesW, MulDiv, CreateEventA, SetUnhandledExceptionFilter, GetCommandLineW, GetModuleHandleW, WideCharToMultiByte, VirtualAlloc, VirtualFree, GetTempFileNameA, GetWindowsDirectoryA, FileTimeToSystemTime, ExpandEnvironmentStringsA, SearchPathA, GetTempPathA, GetFileAttributesA, CopyFileA, CreateFileA, DeleteFileA, CompareFileTime, CompareStringA, GetLocaleInfoW, FormatMessageA, GetSystemTime, IsBadStringPtrA, IsBadStringPtrW, IsBadWritePtr, ResumeThread, TerminateThread, WaitForMultipleObjects, GetSystemDefaultLCID, lstrcpyW, SetLastError, FlushInstructionCache, lstrcmpiA, lstrcmpA, SetFilePointer, MoveFileExW, SetErrorMode, CreateFileMappingA, CreateMutexA, DuplicateHandle, CreateProcessW, ReleaseMutex, GlobalLock, GlobalUnlock, VirtualQuery, GetSystemInfo, GetVersion, VirtualProtect, FindClose, MoveFileW, LocalAlloc, IsDBCSLeadByteEx, GlobalAlloc, SetThreadLocale, CreateFileMappingW, OpenFileMappingW, MapViewOfFile, UnmapViewOfFile, LocalFree, OpenEventW, SetEvent, ResetEvent, DeleteFileW, CompareStringW, WriteFile, ReadFile, lstrcpynW, lstrcmpW, lstrlenW, lstrcmpiW, CreateFileW, GetLastError, GetFileSize, MultiByteToWideChar, LoadLibraryW, GetProcAddress, FreeLibrary, GetTickCount, lstrlenA, LeaveCriticalSection, EnterCriticalSection, GetCurrentThreadId, Sleep, CreateEventW, CreateThread, InterlockedDecrement, InterlockedIncrement, WaitForSingleObject, CloseHandle, DeleteCriticalSection, InitializeCriticalSection, GetCurrentThread, FindResourceA, InterlockedExchange, GetACP, GetLocaleInfoA, GetThreadLocale, RaiseException, GetVersionExW<br>> GDI32.dll: CreatePalette, Ellipse, GetClipRgn, CreateRectRgn, SelectClipRgn, CreateDCW, LPtoDP, SaveDC, SetWindowOrgEx, SetViewportOrgEx, GetSystemPaletteEntries, GetPaletteEntries, BitBlt, CreateCompatibleBitmap, LineTo, MoveToEx, CreatePen, SetDIBits, GetDIBits, EnumFontFamiliesExW, CreateFontIndirectW, DPtoLP, SetBkMode, GetTextExtentPoint32W, FillRgn, CreatePolygonRgn, GetTextMetricsW, Polygon, CreateBitmap, IntersectClipRect, GetClipBox, SetTextAlign, GetTextAlign, ExcludeClipRect, Rectangle, GetMapMode, SetMapMode, GetViewportExtEx, GetWindowExtEx, CreateRectRgnIndirect, RestoreDC, GetStockObject, GetLayout, SetLayout, StretchBlt, GetDIBColorTable, SetTextColor, SetBkColor, CreateHalftonePalette, SelectPalette, RealizePalette, CreateSolidBrush, DeleteObject, GetDeviceCaps, CreateDIBSection, GetObjectW, SetDIBColorTable, SelectObject, DeleteDC, CreateCompatibleDC<br>> USER32.dll: CreateWindowExW, CharUpperA, GetClassInfoExA, RegisterClassExA, CreateWindowExA, LoadMenuW, GetDlgItemInt, SetDlgItemInt, CheckRadioButton, LoadIconW, CheckDlgButton, LoadBitmapW, CreateDialogParamW, GetWindowLongA, SetWindowLongA, IsDlgButtonChecked, CloseWindow, GetDlgCtrlID, DrawEdge, GetLastActivePopup, GetAsyncKeyState, GetScrollInfo, CreateAcceleratorTableW, CharNextW, GetClassNameW, DestroyAcceleratorTable, InvalidateRgn, SetCapture, GetWindowTextW, SetWindowTextW, SetDlgItemTextW, ScreenToClient, LoadStringA, ModifyMenuW, SetCursorPos, MessageBoxW, IsDialogMessageW, MessageBeep, SetWindowPos, SetRectEmpty, CreatePopupMenu, BeginDeferWindowPos, EndDeferWindowPos, LoadBitmapA, RegisterClassW, RegisterWindowMessageW, GetDoubleClickTime, SetMenuDefaultItem, MoveWindow, GetForegroundWindow, TrackPopupMenuEx, DestroyIcon, LoadImageA, TrackPopupMenu, GetSysColor, DrawTextW, GetSystemMetrics, SetParent, LoadIconA, LoadMenuA, SetMenu, SetWindowPlacement, UpdateWindow, AdjustWindowRect, LoadCursorA, SetCursor, RedrawWindow, DialogBoxParamW, GetDlgItemTextW, GetDlgItem, EndDialog, EnableWindow, SendMessageW, GetKeyState, GetFocus, GetNextDlgTabItem, CheckMenuItem, GetMenuItemID, GetMenuItemCount, EnableMenuItem, RemoveMenu, InsertMenuItemW, CheckMenuRadioItem, DeleteMenu, SetMenuItemInfoW, GetCursorPos, GetMenu, GetSubMenu, IsMenu, GetMenuItemInfoW, DestroyMenu, GetParent, FindWindowExW, GetWindowRect, DrawAnimatedRects, IsZoomed, IsWindow, ShowWindow, IsWindowVisible, GetWindowPlacement, SetPropA, GetPropA, CallWindowProcW, RemovePropA, SetForegroundWindow, InvalidateRect, GetSysColorBrush, FillRect, GetClientRect, GetDC, ReleaseDC, SetFocus, OpenInputDesktop, GetUserObjectInformationW, CloseDesktop, FindWindowW, CharPrevW, PostQuitMessage, GetClassInfoExW, RegisterClassExW, ReleaseCapture, DestroyWindow, DefWindowProcW, LoadStringW, GetWindowLongW, SetWindowLongW, KillTimer, SetTimer, PostMessageW, PostThreadMessageW, GetMessageW, TranslateMessage, DispatchMessageW, UnregisterClassW, IsClipboardFormatAvailable, GetDialogBaseUnits, DrawMenuBar, IsIconic, FlashWindow, GetMenuState, wsprintfW, IsChild, EqualRect, IsWindowEnabled, EnumChildWindows, MessageBoxIndirectW, EndPaint, BeginPaint, SystemParametersInfoW, SendDlgItemMessageW, PeekMessageW, LoadCursorW, GetWindowDC, LoadImageW, DrawFocusRect, InflateRect, OffsetRect, DeferWindowPos, GetUpdateRect, GetWindow, PtInRect, GetWindowTextLengthW, GetDesktopWindow, UnhookWindowsHookEx, GetLastInputInfo, CallNextHookEx, SetWindowsHookExW, MapWindowPoints, ClientToScreen, SetRect, AdjustWindowRectEx, MsgWaitForMultipleObjects, GetMessageTime, IntersectRect, WindowFromDC, ValidateRect, UnionRect, SetWindowRgn<br>> WSOCK32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -<br>> ole32.dll: StgOpenStorageOnILockBytes, IIDFromString, CoInitialize, CoUninitialize, StringFromCLSID, CoGetClassObject, OleLockRunning, OleFlushClipboard, OleRegGetMiscStatus, CreateOleAdviseHolder, OleRegGetUserType, OleRegEnumVerbs, OleSaveToStream, WriteClassStm, OleLoadFromStream, CreateILockBytesOnHGlobal, StgCreateDocfileOnILockBytes, OleCreateStaticFromData, OleRun, DoDragDrop, CoTaskMemAlloc, CoCreateGuid, CoTaskMemFree, StringFromGUID2, CreateStreamOnHGlobal, CLSIDFromString, CLSIDFromProgID, RegisterDragDrop, RevokeDragDrop, CoCreateInstance, CoRegisterClassObject, CoRevokeClassObject, OleUninitialize, OleInitialize, GetHGlobalFromILockBytes<br>> OLEAUT32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -<br>> COMCTL32.dll: CreateToolbarEx, ImageList_Add, ImageList_DrawEx, ImageList_GetIcon, ImageList_Destroy, ImageList_Draw, ImageList_EndDrag, ImageList_BeginDrag, ImageList_DragEnter, ImageList_DragMove, ImageList_DragLeave, CreateStatusWindowW, PropertySheetW, -, -, ImageList_Remove, ImageList_AddMasked, ImageList_Create<br>> comdlg32.dll: GetOpenFileNameW, GetSaveFileNameW, ChooseFontW<br>> SHELL32.dll: ShellExecuteW, DragQueryFileW, SHGetFolderPathW, Shell_NotifyIconW, Shell_NotifyIconA, SHAppBarMessage, DragFinish, DragAcceptFiles, SHGetPathFromIDListW, SHBrowseForFolderW, SHGetMalloc, ShellExecuteExW<br>> VERSION.dll: GetFileVersionInfoSizeW, GetFileVersionInfoW, GetFileVersionInfoA, GetFileVersionInfoSizeA, VerQueryValueA, VerQueryValueW<br>> WINMM.dll: PlaySoundW, waveInGetNumDevs, waveOutGetNumDevs<br>> SHLWAPI.dll: StrCmpIW, SHGetValueW, StrCmpNW, StrChrW, StrStrW, StrToIntExW, StrStrIW, StrCatBuffW, StrPBrkW, wnsprintfW, StrTrimW, StrRChrW, wnsprintfA, StrChrA, StrStrA, StrStrIA, StrCmpNA, -, StrTrimA, StrCatBuffA, StrRChrA, StrCpyNW, SHGetInverseCMAP, StrCmpNIW<br>> gdiplus.dll: GdipFree, GdipDeleteGraphics, GdipDisposeImage, GdipGetImageWidth, GdipGetImageHeight, GdipGetImagePixelFormat, GdipGetImagePaletteSize, GdipGetImagePalette, GdipCreateBitmapFromFile, GdipCreateBitmapFromFileICM, GdipCreateBitmapFromScan0, GdipBitmapLockBits, GdipBitmapUnlockBits, GdiplusStartup, GdipDrawImageI, GdipGetImageGraphicsContext, GdipAlloc, GdipCloneImage, GdipCreateBitmapFromStreamICM, GdipCreateBitmapFromStream, GdiplusShutdown<br>> MSIMG32.dll: AlphaBlend, TransparentBlt<br>> NETAPI32.dll: NetApiBufferFree, NetGetJoinInformation<br>> WININET.dll: InternetReadFile, InternetOpenUrlW, InternetSetStatusCallbackW, InternetOpenW, HttpQueryInfoW, InternetCloseHandle, InternetCrackUrlW, ResumeSuspendedDownload, HttpSendRequestW, GetUrlCacheEntryInfoW, InternetOpenA, InternetConnectW, InternetSetOptionW, HttpOpenRequestW, InternetSetOptionA, InternetCanonicalizeUrlW<br>> cryptdll.dll: MD5Init, MD5Final, MD5Update<br>> iphlpapi.dll: GetAdaptersInfo<br><br>( 0 exports ) <br>

 

Antivirus Version Dernière mise à jour Résultat

AhnLab-V3 2008.7.2.0 2008.07.02 -

AntiVir 7.8.0.64 2008.07.02 -

Authentium 5.1.0.4 2008.07.02 -

Avast 4.8.1195.0 2008.07.02 -

AVG 7.5.0.516 2008.07.02 -

BitDefender 7.2 2008.07.03 -

CAT-QuickHeal 9.50 2008.07.02 -

ClamAV 0.93.1 2008.07.03 -

DrWeb 4.44.0.09170 2008.07.02 -

eSafe 7.0.17.0 2008.07.02 -

eTrust-Vet 31.6.5922 2008.07.02 -

Ewido 4.0 2008.07.02 -

F-Prot 4.4.4.56 2008.07.02 -

F-Secure 7.60.13501.0 2008.07.01 -

Fortinet 3.14.0.0 2008.07.03 -

GData 2.0.7306.1023 2008.07.03 -

Ikarus T3.1.1.26.0 2008.07.03 -

Kaspersky 7.0.0.125 2008.07.03 -

McAfee 5330 2008.07.02 -

Microsoft 1.3704 2008.07.03 -

NOD32v2 3236 2008.07.03 -

Norman 5.80.02 2008.07.02 -

Panda 9.0.0.4 2008.07.02 -

Prevx1 V2 2008.07.03 -

Rising 20.51.30.00 2008.07.03 -

Sophos 4.30.0 2008.07.03 -

Sunbelt 3.1.1509.1 2008.07.03 -

Symantec 10 2008.07.03 -

TheHacker 6.2.96.367 2008.07.03 -

TrendMicro 8.700.0.1004 2008.07.03 -

VBA32 3.12.6.8 2008.07.02 -

VirusBuster 4.5.11.0 2008.07.02 -

Webwasher-Gateway 6.6.2 2008.07.02 -

 

Information additionnelle

File size: 1694208 bytes

MD5...: 74e6e96c6f0e2eca4edbb7f7a468f259

SHA1..: 1b4729d1bd15e4d48422ecb5730959390c0be1c7

SHA256: 58d083fe62a47860de7e4d87ec74f1e900c1b1824a3e8c2b94ce07936af0d0d1

SHA512: 1fce520104f0a1f65db3be0e342f2e2d762da6da2250945d9102a3fc8a0368c4<br>3413b7185065212bceddb8337ef637d4d02197274845d700a0c8afbc3260f8f4

PEiD..: -

PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x105ed21<br>timedatestamp.....: 0x416d56bc (Wed Oct 13 16:24:28 2004)<br>machinetype.......: 0x14c (I386)<br><br>( 3 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>.text 0x1000 0x10fbe6 0x10fc00 6.53 a2343f3d5b70293a37b342ddbd9cb5f8<br>.data 0x111000 0x40c8 0x1800 3.88 725045f0fc6510e86034ba5c7df46e12<br>.rsrc 0x116000 0x8c120 0x8c200 6.49 aed27941d66b8f0cf79ff84ebac40cb8<br><br>( 20 imports ) <br>> msvcrt.dll: abort, _wtoi, _ftol, wcsncpy, __CxxFrameHandler, vswprintf, sprintf, _CxxThrowException, tolower, realloc, memset, fread, strncpy, _vscwprintf, _setjmp3, longjmp, _mbsstr, time, fprintf, _iob, strtod, _CIpow, _wcsnicmp, _wcsicmp, wcscmp, wcsspn, wcscspn, _strlwr, strtok, __1type_info@@UAE@XZ, _controlfp, _onexit, __dllonexit, __set_app_type, __p__fmode, __p__commode, _adjust_fdiv, __setusermatherr, _initterm, __getmainargs, _acmdln, exit, _cexit, _XcptFilter, _exit, _c_exit, memmove, wcslen, _wcslwr, wcsrchr, malloc, _purecall, __2@YAPAXI@Z, __3@YAXPAX@Z, free, _terminate@@YAXXZ, _except_handler3<br>> ADVAPI32.dll: OpenThreadToken, ImpersonateSelf, RegDeleteKeyA, RegCreateKeyExA, RegOpenKeyExA, CryptAcquireContextW, CryptCreateHash, CryptHashData, CryptGetHashParam, CryptDestroyHash, CryptReleaseContext, RegisterEventSourceW, ReportEventW, DeregisterEventSource, RegDeleteKeyW, RegEnumKeyW, RegQueryInfoKeyW, RegDeleteValueA, RegDeleteValueW, RegQueryValueExA, RegQueryValueExW, RegSetValueExA, RegSetValueExW, RegCreateKeyExW, RegFlushKey, OpenProcessToken, RegCloseKey, RegOpenKeyExW, AllocateAndInitializeSid, InitializeSecurityDescriptor, GetLengthSid, InitializeAcl, AddAccessAllowedAce, SetSecurityDescriptorDacl, FreeSid, RevertToSelf, AccessCheck, IsValidSecurityDescriptor, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, RegEnumKeyA<br>> KERNEL32.dll: GetProcessHeap, HeapSize, HeapReAlloc, HeapFree, HeapAlloc, HeapDestroy, GetVersionExA, GetStartupInfoA, GetModuleHandleA, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, QueryPerformanceCounter, IsValidLocale, LoadLibraryA, GetCurrentProcessId, GetUserDefaultLCID, lstrcpynA, GetCurrentDirectoryW, GetWindowsDirectoryW, SetCurrentDirectoryW, GetDateFormatW, GetTimeFormatW, GetSystemTimeAsFileTime, GetLocalTime, SystemTimeToFileTime, ExpandEnvironmentStringsW, FindFirstFileW, GetTempPathW, GetTempFileNameW, GetModuleFileNameW, FindResourceExW, FindResourceW, LoadResource, LockResource, SizeofResource, FormatMessageW, GetSystemDefaultUILanguage, GlobalMemoryStatus, CreateDirectoryW, GlobalFree, GetFileAttributesW, MulDiv, CreateEventA, SetUnhandledExceptionFilter, GetCommandLineW, GetModuleHandleW, WideCharToMultiByte, VirtualAlloc, VirtualFree, GetTempFileNameA, GetWindowsDirectoryA, FileTimeToSystemTime, ExpandEnvironmentStringsA, SearchPathA, GetTempPathA, GetFileAttributesA, CopyFileA, CreateFileA, DeleteFileA, CompareFileTime, CompareStringA, GetLocaleInfoW, FormatMessageA, GetSystemTime, IsBadStringPtrA, IsBadStringPtrW, IsBadWritePtr, ResumeThread, TerminateThread, WaitForMultipleObjects, GetSystemDefaultLCID, lstrcpyW, SetLastError, FlushInstructionCache, lstrcmpiA, lstrcmpA, SetFilePointer, MoveFileExW, SetErrorMode, CreateFileMappingA, CreateMutexA, DuplicateHandle, CreateProcessW, ReleaseMutex, GlobalLock, GlobalUnlock, VirtualQuery, GetSystemInfo, GetVersion, VirtualProtect, FindClose, MoveFileW, LocalAlloc, IsDBCSLeadByteEx, GlobalAlloc, SetThreadLocale, CreateFileMappingW, OpenFileMappingW, MapViewOfFile, UnmapViewOfFile, LocalFree, OpenEventW, SetEvent, ResetEvent, DeleteFileW, CompareStringW, WriteFile, ReadFile, lstrcpynW, lstrcmpW, lstrlenW, lstrcmpiW, CreateFileW, GetLastError, GetFileSize, MultiByteToWideChar, LoadLibraryW, GetProcAddress, FreeLibrary, GetTickCount, lstrlenA, LeaveCriticalSection, EnterCriticalSection, GetCurrentThreadId, Sleep, CreateEventW, CreateThread, InterlockedDecrement, InterlockedIncrement, WaitForSingleObject, CloseHandle, DeleteCriticalSection, InitializeCriticalSection, GetCurrentThread, FindResourceA, InterlockedExchange, GetACP, GetLocaleInfoA, GetThreadLocale, RaiseException, GetVersionExW<br>> GDI32.dll: CreatePalette, Ellipse, GetClipRgn, CreateRectRgn, SelectClipRgn, CreateDCW, LPtoDP, SaveDC, SetWindowOrgEx, SetViewportOrgEx, GetSystemPaletteEntries, GetPaletteEntries, BitBlt, CreateCompatibleBitmap, LineTo, MoveToEx, CreatePen, SetDIBits, GetDIBits, EnumFontFamiliesExW, CreateFontIndirectW, DPtoLP, SetBkMode, GetTextExtentPoint32W, FillRgn, CreatePolygonRgn, GetTextMetricsW, Polygon, CreateBitmap, IntersectClipRect, GetClipBox, SetTextAlign, GetTextAlign, ExcludeClipRect, Rectangle, GetMapMode, SetMapMode, GetViewportExtEx, GetWindowExtEx, CreateRectRgnIndirect, RestoreDC, GetStockObject, GetLayout, SetLayout, StretchBlt, GetDIBColorTable, SetTextColor, SetBkColor, CreateHalftonePalette, SelectPalette, RealizePalette, CreateSolidBrush, DeleteObject, GetDeviceCaps, CreateDIBSection, GetObjectW, SetDIBColorTable, SelectObject, DeleteDC, CreateCompatibleDC<br>> USER32.dll: CreateWindowExW, CharUpperA, GetClassInfoExA, RegisterClassExA, CreateWindowExA, LoadMenuW, GetDlgItemInt, SetDlgItemInt, CheckRadioButton, LoadIconW, CheckDlgButton, LoadBitmapW, CreateDialogParamW, GetWindowLongA, SetWindowLongA, IsDlgButtonChecked, CloseWindow, GetDlgCtrlID, DrawEdge, GetLastActivePopup, GetAsyncKeyState, GetScrollInfo, CreateAcceleratorTableW, CharNextW, GetClassNameW, DestroyAcceleratorTable, InvalidateRgn, SetCapture, GetWindowTextW, SetWindowTextW, SetDlgItemTextW, ScreenToClient, LoadStringA, ModifyMenuW, SetCursorPos, MessageBoxW, IsDialogMessageW, MessageBeep, SetWindowPos, SetRectEmpty, CreatePopupMenu, BeginDeferWindowPos, EndDeferWindowPos, LoadBitmapA, RegisterClassW, RegisterWindowMessageW, GetDoubleClickTime, SetMenuDefaultItem, MoveWindow, GetForegroundWindow, TrackPopupMenuEx, DestroyIcon, LoadImageA, TrackPopupMenu, GetSysColor, DrawTextW, GetSystemMetrics, SetParent, LoadIconA, LoadMenuA, SetMenu, SetWindowPlacement, UpdateWindow, AdjustWindowRect, LoadCursorA, SetCursor, RedrawWindow, DialogBoxParamW, GetDlgItemTextW, GetDlgItem, EndDialog, EnableWindow, SendMessageW, GetKeyState, GetFocus, GetNextDlgTabItem, CheckMenuItem, GetMenuItemID, GetMenuItemCount, EnableMenuItem, RemoveMenu, InsertMenuItemW, CheckMenuRadioItem, DeleteMenu, SetMenuItemInfoW, GetCursorPos, GetMenu, GetSubMenu, IsMenu, GetMenuItemInfoW, DestroyMenu, GetParent, FindWindowExW, GetWindowRect, DrawAnimatedRects, IsZoomed, IsWindow, ShowWindow, IsWindowVisible, GetWindowPlacement, SetPropA, GetPropA, CallWindowProcW, RemovePropA, SetForegroundWindow, InvalidateRect, GetSysColorBrush, FillRect, GetClientRect, GetDC, ReleaseDC, SetFocus, OpenInputDesktop, GetUserObjectInformationW, CloseDesktop, FindWindowW, CharPrevW, PostQuitMessage, GetClassInfoExW, RegisterClassExW, ReleaseCapture, DestroyWindow, DefWindowProcW, LoadStringW, GetWindowLongW, SetWindowLongW, KillTimer, SetTimer, PostMessageW, PostThreadMessageW, GetMessageW, TranslateMessage, DispatchMessageW, UnregisterClassW, IsClipboardFormatAvailable, GetDialogBaseUnits, DrawMenuBar, IsIconic, FlashWindow, GetMenuState, wsprintfW, IsChild, EqualRect, IsWindowEnabled, EnumChildWindows, MessageBoxIndirectW, EndPaint, BeginPaint, SystemParametersInfoW, SendDlgItemMessageW, PeekMessageW, LoadCursorW, GetWindowDC, LoadImageW, DrawFocusRect, InflateRect, OffsetRect, DeferWindowPos, GetUpdateRect, GetWindow, PtInRect, GetWindowTextLengthW, GetDesktopWindow, UnhookWindowsHookEx, GetLastInputInfo, CallNextHookEx, SetWindowsHookExW, MapWindowPoints, ClientToScreen, SetRect, AdjustWindowRectEx, MsgWaitForMultipleObjects, GetMessageTime, IntersectRect, WindowFromDC, ValidateRect, UnionRect, SetWindowRgn<br>> WSOCK32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -<br>> ole32.dll: StgOpenStorageOnILockBytes, IIDFromString, CoInitialize, CoUninitialize, StringFromCLSID, CoGetClassObject, OleLockRunning, OleFlushClipboard, OleRegGetMiscStatus, CreateOleAdviseHolder, OleRegGetUserType, OleRegEnumVerbs, OleSaveToStream, WriteClassStm, OleLoadFromStream, CreateILockBytesOnHGlobal, StgCreateDocfileOnILockBytes, OleCreateStaticFromData, OleRun, DoDragDrop, CoTaskMemAlloc, CoCreateGuid, CoTaskMemFree, StringFromGUID2, CreateStreamOnHGlobal, CLSIDFromString, CLSIDFromProgID, RegisterDragDrop, RevokeDragDrop, CoCreateInstance, CoRegisterClassObject, CoRevokeClassObject, OleUninitialize, OleInitialize, GetHGlobalFromILockBytes<br>> OLEAUT32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -<br>> COMCTL32.dll: CreateToolbarEx, ImageList_Add, ImageList_DrawEx, ImageList_GetIcon, ImageList_Destroy, ImageList_Draw, ImageList_EndDrag, ImageList_BeginDrag, ImageList_DragEnter, ImageList_DragMove, ImageList_DragLeave, CreateStatusWindowW, PropertySheetW, -, -, ImageList_Remove, ImageList_AddMasked, ImageList_Create<br>> comdlg32.dll: GetOpenFileNameW, GetSaveFileNameW, ChooseFontW<br>> SHELL32.dll: ShellExecuteW, DragQueryFileW, SHGetFolderPathW, Shell_NotifyIconW, Shell_NotifyIconA, SHAppBarMessage, DragFinish, DragAcceptFiles, SHGetPathFromIDListW, SHBrowseForFolderW, SHGetMalloc, ShellExecuteExW<br>> VERSION.dll: GetFileVersionInfoSizeW, GetFileVersionInfoW, GetFileVersionInfoA, GetFileVersionInfoSizeA, VerQueryValueA, VerQueryValueW<br>> WINMM.dll: PlaySoundW, waveInGetNumDevs, waveOutGetNumDevs<br>> SHLWAPI.dll: StrCmpIW, SHGetValueW, StrCmpNW, StrChrW, StrStrW, StrToIntExW, StrStrIW, StrCatBuffW, StrPBrkW, wnsprintfW, StrTrimW, StrRChrW, wnsprintfA, StrChrA, StrStrA, StrStrIA, StrCmpNA, -, StrTrimA, StrCatBuffA, StrRChrA, StrCpyNW, SHGetInverseCMAP, StrCmpNIW<br>> gdiplus.dll: GdipFree, GdipDeleteGraphics, GdipDisposeImage, GdipGetImageWidth, GdipGetImageHeight, GdipGetImagePixelFormat, GdipGetImagePaletteSize, GdipGetImagePalette, GdipCreateBitmapFromFile, GdipCreateBitmapFromFileICM, GdipCreateBitmapFromScan0, GdipBitmapLockBits, GdipBitmapUnlockBits, GdiplusStartup, GdipDrawImageI, GdipGetImageGraphicsContext, GdipAlloc, GdipCloneImage, GdipCreateBitmapFromStreamICM, GdipCreateBitmapFromStream, GdiplusShutdown<br>> MSIMG32.dll: AlphaBlend, TransparentBlt<br>> NETAPI32.dll: NetApiBufferFree, NetGetJoinInformation<br>> WININET.dll: InternetReadFile, InternetOpenUrlW, InternetSetStatusCallbackW, InternetOpenW, HttpQueryInfoW, InternetCloseHandle, InternetCrackUrlW, ResumeSuspendedDownload, HttpSendRequestW, GetUrlCacheEntryInfoW, InternetOpenA, InternetConnectW, InternetSetOptionW, HttpOpenRequestW, InternetSetOptionA, InternetCanonicalizeUrlW<br>> cryptdll.dll: MD5Init, MD5Final, MD5Update<br>> iphlpapi.dll: GetAdaptersInfo<br><br>( 0 exports ) <br>

*****

Posté(e)

Rebonjour,

 

et voici ceux de senscfg32.dll

 

merci encore, et a bientot,

vdelab

 

 

*****

 

Fichier senscfg32.dll reçu le 2008.07.03 07:35:29 (CET)

Antivirus Version Dernière mise à jour Résultat

AhnLab-V3 2008.7.2.0 2008.07.02 -

AntiVir 7.8.0.64 2008.07.02 TR/Hijacker.Gen

Authentium 5.1.0.4 2008.07.02 -

Avast 4.8.1195.0 2008.07.02 -

AVG 7.5.0.516 2008.07.02 Downloader.Small.60.AO

BitDefender 7.2 2008.07.03 -

CAT-QuickHeal 9.50 2008.07.02 -

ClamAV 0.93.1 2008.07.03 -

DrWeb 4.44.0.09170 2008.07.02 -

eSafe 7.0.17.0 2008.07.02 Suspicious File

eTrust-Vet 31.6.5922 2008.07.02 -

Ewido 4.0 2008.07.02 -

F-Prot 4.4.4.56 2008.07.02 W32/Agent.AK.gen!Eldorado

F-Secure 7.60.13501.0 2008.07.01 Trojan.Win32.Agent.dwg

Fortinet 3.14.0.0 2008.07.03 -

GData 2.0.7306.1023 2008.07.03 Trojan.Win32.Agent.dwg

Ikarus T3.1.1.26.0 2008.07.03 Virus.Trojan.Win32.Agent.dwg

Kaspersky 7.0.0.125 2008.07.03 Trojan.Win32.Agent.dwg

McAfee 5330 2008.07.02 -

Microsoft 1.3704 2008.07.03 VirTool:Win32/Obfuscator.L

NOD32v2 3236 2008.07.03 -

Norman 5.80.02 2008.07.02 -

Panda 9.0.0.4 2008.07.02 -

Prevx1 V2 2008.07.03 -

Rising 20.51.30.00 2008.07.03 Trojan.Win32.Undef.ete

Sophos 4.30.0 2008.07.03 Sus/Behav-1021

Sunbelt 3.1.1509.1 2008.07.03 -

Symantec 10 2008.07.03 -

TheHacker 6.2.96.367 2008.07.03 -

TrendMicro 8.700.0.1004 2008.07.03 -

VBA32 3.12.6.8 2008.07.02 -

VirusBuster 4.5.11.0 2008.07.02 -

Webwasher-Gateway 6.6.2 2008.07.02 Trojan.Hijacker.Gen

Information additionnelle

File size: 8704 bytes

MD5...: 2d39159048ea8fff354b1af2c769f591

SHA1..: b202b64dd1698e213702015ea9172810c56e97be

SHA256: fa59865aa4bf0d4b8569c0e90d26f18ada6a44e490a22b7922c9779df9936924

SHA512: 52d64839e44edd832c63c3fe444b6429210d9024015440aae225763ab9abe752<br>e2313523b207c8cd8445a99340d0fc323f5ddaf71e64cd02e081eb8ed3aec627

PEiD..: -

PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x10009540<br>timedatestamp.....: 0x4730c963 (Tue Nov 06 20:06:59 2007)<br>machinetype.......: 0x14c (I386)<br><br>( 3 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>UPX0 0x1000 0x7000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e<br>UPX1 0x8000 0x2000 0x1800 7.75 402b4ffb896ad5839f3de50be4f04299<br>.rsrc 0xa000 0x1000 0x600 2.77 4c6b2d2551a9a15574bd762bf4e46141<br><br>( 1 imports ) <br>> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree<br><br>( 1 exports ) <br>ekab<br>

packers (F-Prot): UPX

 

Antivirus Version Dernière mise à jour Résultat

AhnLab-V3 2008.7.2.0 2008.07.02 -

AntiVir 7.8.0.64 2008.07.02 TR/Hijacker.Gen

Authentium 5.1.0.4 2008.07.02 -

Avast 4.8.1195.0 2008.07.02 -

AVG 7.5.0.516 2008.07.02 Downloader.Small.60.AO

BitDefender 7.2 2008.07.03 -

CAT-QuickHeal 9.50 2008.07.02 -

ClamAV 0.93.1 2008.07.03 -

DrWeb 4.44.0.09170 2008.07.02 -

eSafe 7.0.17.0 2008.07.02 Suspicious File

eTrust-Vet 31.6.5922 2008.07.02 -

Ewido 4.0 2008.07.02 -

F-Prot 4.4.4.56 2008.07.02 W32/Agent.AK.gen!Eldorado

F-Secure 7.60.13501.0 2008.07.01 Trojan.Win32.Agent.dwg

Fortinet 3.14.0.0 2008.07.03 -

GData 2.0.7306.1023 2008.07.03 Trojan.Win32.Agent.dwg

Ikarus T3.1.1.26.0 2008.07.03 Virus.Trojan.Win32.Agent.dwg

Kaspersky 7.0.0.125 2008.07.03 Trojan.Win32.Agent.dwg

McAfee 5330 2008.07.02 -

Microsoft 1.3704 2008.07.03 VirTool:Win32/Obfuscator.L

NOD32v2 3236 2008.07.03 -

Norman 5.80.02 2008.07.02 -

Panda 9.0.0.4 2008.07.02 -

Prevx1 V2 2008.07.03 -

Rising 20.51.30.00 2008.07.03 Trojan.Win32.Undef.ete

Sophos 4.30.0 2008.07.03 Sus/Behav-1021

Sunbelt 3.1.1509.1 2008.07.03 -

Symantec 10 2008.07.03 -

TheHacker 6.2.96.367 2008.07.03 -

TrendMicro 8.700.0.1004 2008.07.03 -

VBA32 3.12.6.8 2008.07.02 -

VirusBuster 4.5.11.0 2008.07.02 -

Webwasher-Gateway 6.6.2 2008.07.02 Trojan.Hijacker.Gen

 

Information additionnelle

File size: 8704 bytes

MD5...: 2d39159048ea8fff354b1af2c769f591

SHA1..: b202b64dd1698e213702015ea9172810c56e97be

SHA256: fa59865aa4bf0d4b8569c0e90d26f18ada6a44e490a22b7922c9779df9936924

SHA512: 52d64839e44edd832c63c3fe444b6429210d9024015440aae225763ab9abe752<br>e2313523b207c8cd8445a99340d0fc323f5ddaf71e64cd02e081eb8ed3aec627

PEiD..: -

PEInfo: PE Structure information<br><br>( base data )<br>entrypointaddress.: 0x10009540<br>timedatestamp.....: 0x4730c963 (Tue Nov 06 20:06:59 2007)<br>machinetype.......: 0x14c (I386)<br><br>( 3 sections )<br>name viradd virsiz rawdsiz ntrpy md5<br>UPX0 0x1000 0x7000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e<br>UPX1 0x8000 0x2000 0x1800 7.75 402b4ffb896ad5839f3de50be4f04299<br>.rsrc 0xa000 0x1000 0x600 2.77 4c6b2d2551a9a15574bd762bf4e46141<br><br>( 1 imports ) <br>> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree<br><br>( 1 exports ) <br>ekab<br>

packers (F-Prot): UPX

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Invité
Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
×
×
  • Créer...