Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Impossible de lancer Avast/spybot/ [résolu]


Arnoras

Messages recommandés

Combofix.txt :

 

ComboFix 09-02-25.02 - Arnoras 2009-02-26 1:28:31.2 - NTFSx86

Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.2047.1492 [GMT 1:00]

Lancé depuis: c:\documents and settings\Arnoras\Bureau\ComboFix.exe

Commutateurs utilisés :: c:\documents and settings\Arnoras\Bureau\CFScript.txt

AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated)

* Un nouveau point de restauration a été créé

 

FILE ::

c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}

C:\InfoSat.txt

c:\windows\IFinst27.exe

c:\windows\Navigma.INI

.

 

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))

.

 

C:\InfoSat.txt

c:\windows\IFinst27.exe

c:\windows\Navigma.INI

 

.

((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.

 

-------\Service_aarzypiz

 

 

((((((((((((((((((((((((((((( Fichiers créés du 2009-01-26 au 2009-02-26 ))))))))))))))))))))))))))))))))))))

.

 

2009-02-26 01:12 . 2009-02-26 01:12 <REP> d-------- C:\rsit

2009-02-26 00:55 . 2009-02-26 00:55 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware

2009-02-26 00:55 . 2009-02-26 00:55 <REP> d-------- c:\documents and settings\Arnoras\Application Data\Malwarebytes

2009-02-26 00:55 . 2009-02-26 00:55 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes

2009-02-26 00:55 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys

2009-02-26 00:55 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys

2009-02-25 23:20 . 2009-02-25 23:20 <REP> d-------- c:\documents and settings\Administrateur\Application Data\vlc

2009-02-25 22:43 . 2009-02-25 22:43 <REP> d-------- c:\program files\Kaspersky Lab

2009-02-25 22:43 . 2009-02-26 01:32 <REP> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab

2009-02-25 22:43 . 2009-02-26 01:29 1,598,496 --ahs---- c:\windows\system32\drivers\fidbox.dat

2009-02-25 22:43 . 2009-02-26 01:29 172,064 --ahs---- c:\windows\system32\drivers\fidbox2.dat

2009-02-25 22:43 . 2009-02-25 22:48 101,287 --a------ c:\windows\system32\drivers\klin.dat

2009-02-25 22:43 . 2009-02-25 22:48 89,601 --a------ c:\windows\system32\drivers\klick.dat

2009-02-25 22:43 . 2009-02-26 01:29 15,664 --ahs---- c:\windows\system32\drivers\fidbox.idx

2009-02-25 22:43 . 2009-02-26 01:29 1,668 --ahs---- c:\windows\system32\drivers\fidbox2.idx

2009-02-25 22:38 . 2009-02-25 22:38 <REP> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files

2009-02-25 22:14 . 2009-02-25 22:14 <REP> d-------- C:\!KillBox

2009-02-25 20:09 . 2009-02-25 20:27 <REP> d-------- C:\combo-fix

2009-02-25 20:03 . 2009-02-25 20:03 <REP> d-------- c:\program files\Trend Micro

2009-02-25 19:59 . 2009-02-25 19:59 <REP> d-------- c:\windows\system32\Kaspersky Lab

2009-02-25 19:30 . 2009-02-25 22:42 <REP> d-------- C:\spywarebegone-fs

2009-02-25 19:30 . 2009-02-25 19:30 724,992 --a------ c:\windows\iun6002.exe

2009-02-25 19:02 . 2009-02-25 19:02 <REP> d-------- c:\documents and settings\Arnoras\Application Data\AVS4YOU

2009-02-25 19:02 . 2009-02-25 19:02 <REP> d-------- c:\documents and settings\All Users\Application Data\AVS4YOU

2009-02-25 19:01 . 2009-02-25 19:02 <REP> d-------- c:\program files\Fichiers communs\AVSMedia

2009-02-25 19:01 . 2009-02-25 19:02 <REP> d-------- c:\program files\AVS4YOU

2009-02-25 19:01 . 2007-10-25 11:20 974,848 --a------ c:\windows\system32\mfc70.dll

2009-02-25 19:01 . 2007-10-25 11:20 487,424 --a------ c:\windows\system32\msvcp70.dll

2009-02-25 17:53 . 2009-02-25 18:34 <REP> d-------- c:\documents and settings\Arnoras\Application Data\eBay

2009-02-25 17:53 . 2009-02-25 18:34 <REP> d-------- c:\documents and settings\All Users\Application Data\eBay

2009-02-25 14:29 . 2009-02-25 14:30 <REP> d-------- c:\program files\PhotoFiltre

2009-02-23 22:53 . 2009-02-23 22:53 <REP> d-------- c:\windows\Intelliremote

2009-02-23 22:53 . 2009-02-25 01:38 <REP> d-------- c:\documents and settings\Arnoras\Application Data\Intelliremote

2009-02-23 19:39 . 2009-02-25 18:24 168 --a------ c:\windows\usdthank.ini

2009-02-23 19:39 . 2009-02-23 19:39 31 --a------ c:\windows\idc.ini

2009-02-22 14:42 . 2006-09-12 12:46 227,328 -r-hs---- c:\windows\system32\ac3DX.ax

2009-02-22 14:42 . 2008-03-16 14:30 216,064 -r-hs---- c:\windows\system32\nbDX.dll

2009-02-22 14:42 . 2006-03-10 22:48 169,472 -r-hs---- c:\windows\system32\MatroskaDX.ax

2009-02-22 14:42 . 2006-05-03 11:06 163,328 -r-hs---- c:\windows\system32\flvDX.dll

2009-02-22 14:42 . 2005-11-25 21:46 161,792 -r-hs---- c:\windows\system32\RealMediaDX.ax

2009-02-22 14:42 . 2006-01-13 00:23 123,904 -r-hs---- c:\windows\system32\AVCDX.ax

2009-02-22 14:42 . 2003-11-21 00:00 54,784 -r-hs---- c:\windows\system32\RLAPEDec.ax

2009-02-22 14:42 . 2004-04-27 00:00 37,888 -r-hs---- c:\windows\system32\RLMPCDec.ax

2009-02-22 14:42 . 2007-02-21 12:47 31,232 -r-hs---- c:\windows\system32\msfDX.dll

2009-02-22 13:51 . 2004-11-28 21:09 679,936 --a------ c:\windows\system32\xvidcore.dll

2009-02-20 23:00 . 2009-02-25 18:34 <REP> d-------- c:\program files\eBay

2009-02-20 23:00 . 2009-02-25 12:15 <REP> d-------- c:\documents and settings\All Users\eBay

2009-02-20 22:42 . 2009-02-20 22:42 <REP> d-------- c:\program files\Fichiers communs\GeoVid

2009-02-20 22:42 . 2007-06-28 18:55 77,824 --a------ c:\windows\system32\xvid.ax

2009-02-20 22:42 . 2005-06-07 15:11 60,416 --a------ c:\windows\system32\dsetup.dll

2009-02-20 21:34 . 2004-02-22 10:11 719,872 --a------ c:\windows\system32\devil.dll

2009-02-20 21:34 . 2007-05-17 17:30 318,976 --a------ c:\windows\system32\avisynth.dll

2009-02-20 21:34 . 2004-01-25 00:00 70,656 --a------ c:\windows\system32\yv12vfw.dll

2009-02-20 21:34 . 2004-01-25 00:00 70,656 --a------ c:\windows\system32\i420vfw.dll

2009-02-20 21:32 . 2009-02-20 21:32 <REP> d-------- c:\program files\eRightSoft

2009-02-20 21:32 . 2005-02-13 00:00 186,880 -r-hs---- c:\windows\system32\RLOgg.ax

2009-02-20 21:32 . 2005-01-18 00:26 179,200 -r-hs---- c:\windows\system32\DiracSplitter.ax

2009-02-20 21:32 . 2006-08-16 15:53 175,104 -r-hs---- c:\windows\system32\CoreAAC.ax

2009-02-20 21:32 . 2005-02-06 00:00 92,672 -r-hs---- c:\windows\system32\RLVorbisDec.ax

2009-02-20 21:32 . 2005-02-22 17:55 81,920 -r-hs---- c:\windows\system32\aac_parser.ax

2009-02-20 21:32 . 2005-02-13 00:00 67,584 -r-hs---- c:\windows\system32\RLTheoraDec.ax

2009-02-20 21:32 . 2005-02-13 00:00 51,712 -r-hs---- c:\windows\system32\RLSpeexDec.ax

2009-02-20 19:45 . 2004-05-25 17:06 417,792 --a------ c:\windows\system32\ac3filter.ax

2009-02-20 19:45 . 2005-02-27 21:48 356,352 --a------ c:\windows\system32\RealMediaSplitter.ax

2009-02-20 19:45 . 2004-01-10 17:02 258,048 --a------ c:\windows\system32\GplMpgDec.ax

2009-02-19 12:54 . 2009-02-20 22:32 <REP> d-------- c:\documents and settings\Arnoras\Application Data\Apple Computer

2009-02-19 12:53 . 2009-02-19 12:53 <REP> d-------- c:\program files\iTunes

2009-02-19 12:53 . 2009-02-19 12:53 <REP> d-------- c:\program files\iPod

2009-02-19 12:53 . 2009-02-19 12:53 <REP> d-------- c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}

2009-02-19 12:53 . 2008-04-17 13:12 107,368 --a------ c:\windows\system32\GEARAspi.dll

2009-02-19 12:53 . 2008-04-17 13:12 15,464 --a------ c:\windows\system32\drivers\GEARAspiWDM.sys

2009-02-19 12:52 . 2009-02-19 12:53 <REP> d-------- c:\program files\QuickTime

2009-02-19 12:52 . 2009-02-19 12:53 <REP> d-------- c:\program files\Fichiers communs\Apple

2009-02-19 12:52 . 2009-02-19 12:52 <REP> d-------- c:\program files\Apple Software Update

2009-02-19 12:52 . 2009-02-19 12:53 <REP> d-------- c:\documents and settings\All Users\Application Data\Apple Computer

2009-02-19 12:52 . 2009-02-19 12:52 <REP> d-------- c:\documents and settings\All Users\Application Data\Apple

2009-02-19 12:52 . 2008-11-07 14:23 32,000 --a------ c:\windows\system32\drivers\usbaapl.sys

2009-02-19 12:26 . 2008-04-14 04:33 159,232 --a------ c:\windows\system32\ptpusd.dll

2009-02-19 12:26 . 2008-04-13 20:45 15,104 --a------ c:\windows\system32\drivers\usbscan.sys

2009-02-19 12:26 . 2008-04-13 20:45 15,104 --a--c--- c:\windows\system32\dllcache\usbscan.sys

2009-02-19 12:26 . 2001-08-23 17:47 5,632 --a------ c:\windows\system32\ptpusb.dll

2009-02-18 02:00 . 2009-02-18 02:05 <REP> d-------- c:\program files\ElcomSoft

2009-02-17 10:51 . 2009-02-20 10:45 <REP> d-------- c:\documents and settings\Arnoras\Application Data\U3

2009-02-16 13:47 . 2009-02-16 13:57 <REP> d-------- c:\documents and settings\Arnoras\Application Data\fretsonfire

2009-02-16 13:46 . 2009-02-17 01:29 <REP> d-------- c:\program files\Frets on Fire

2009-02-15 23:14 . 2009-02-15 23:14 <REP> dr-h----- c:\documents and settings\Arnoras\Application Data\SecuROM

2009-02-15 23:09 . 2009-02-15 23:09 <REP> d-------- c:\program files\Aspyr

2009-02-14 18:32 . 2009-02-14 18:32 <REP> d-------- c:\documents and settings\Arnoras\Application Data\GlarySoft

2009-02-14 16:44 . 2009-02-14 16:44 <REP> d-------- C:\TarguTrans

2009-02-14 16:41 . 2009-02-14 16:42 <REP> d-------- c:\windows\speech

2009-02-14 16:41 . 2009-02-14 16:41 <REP> d-------- c:\windows\Lhsp

2009-02-14 16:32 . 2009-02-14 16:56 <REP> d-------- c:\program files\Power Translator 12

2009-02-14 13:13 . 2009-02-14 13:13 <REP> d-------- C:\profiles

2009-02-14 10:53 . 2009-02-14 10:53 <REP> d-------- c:\program files\WinPcap

2009-02-14 10:52 . 2009-02-14 12:32 <REP> d-------- c:\program files\Net Tools

2009-02-11 15:04 . 2009-02-11 15:04 <REP> d-------- c:\program files\LucasArts

2009-02-06 18:52 . 2009-02-06 18:52 49,504 --a------ c:\windows\system32\sirenacm.dll

2009-02-05 22:55 . 2009-02-05 22:55 <REP> d-------- c:\program files\Glary Utilities

2009-02-05 22:55 . 2009-02-05 22:55 <REP> d-------- c:\program files\CCleaner

2009-02-05 22:52 . 2009-02-05 22:52 <REP> d-------- c:\program files\Auslogics

2009-02-05 22:45 . 2009-02-05 22:45 <REP> d-------- c:\program files\VS Revo Group

2009-02-05 13:37 . 2009-02-05 13:37 1,044,480 -ra------ c:\windows\system32\roboex32.dll

2009-02-05 13:37 . 2009-02-05 13:37 49,152 -ra------ c:\windows\system32\inetwh32.dll

2009-02-04 18:48 . 2009-02-04 18:48 <REP> dr------- c:\documents and settings\Arnoras\Application Data\Brother

2009-02-04 17:00 . 2008-04-13 20:45 20,608 --a------ c:\windows\system32\drivers\usbuhci.sys

2009-02-04 17:00 . 2008-04-13 20:45 20,608 --a--c--- c:\windows\system32\dllcache\usbuhci.sys

2009-02-01 22:38 . 2009-02-01 22:38 <REP> d-------- c:\documents and settings\All Users\Application Data\Electronic Arts

2009-02-01 14:58 . 2009-02-01 14:58 <REP> d-------- c:\program files\LoCoSoft

2009-02-01 14:52 . 2009-02-01 14:52 <REP> d-------- c:\documents and settings\Arnoras\Application Data\AlauxSoft

 

.

(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-02-25 21:48 33,808 ----a-w c:\windows\system32\drivers\klbg.sys

2009-02-25 19:54 --------- d-----w c:\program files\IE8

2009-02-25 18:17 --------- d-----w c:\documents and settings\Arnoras\Application Data\uTorrent

2009-02-25 18:11 --------- d-----w c:\program files\eMule

2009-02-25 17:34 --------- d--h--w c:\program files\InstallShield Installation Information

2009-02-25 00:45 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP

2009-02-25 00:44 --------- d-----w c:\program files\DAEMON Tools Toolbar

2009-02-21 20:00 --------- d-----w c:\program files\Steam

2009-02-20 18:19 --------- d-----w c:\program files\Windows Live Safety Center

2009-02-14 18:57 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help

2009-02-14 11:58 --------- d-----w c:\documents and settings\Arnoras\Application Data\LimeWire

2009-02-14 11:33 --------- d-----w c:\program files\AviSynth 2.5

2009-02-12 21:53 --------- d-----w c:\program files\Messenger Plus! Live

2009-02-11 21:27 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!

2009-02-08 23:02 --------- d-----w c:\program files\DeskSpace

2009-02-08 22:54 --------- d-----w c:\program files\Gpotato.eu

2009-01-15 18:47 --------- d-----w c:\program files\Common Files

2009-01-11 01:40 --------- d-----w c:\program files\Woonoz

2009-01-11 01:40 --------- d-----w c:\program files\Anniversaire

2009-01-09 19:20 --------- d-----w c:\documents and settings\Arnoras\Application Data\Mumble

2009-01-07 19:10 --------- d-----w c:\program files\Packard Bell

2009-01-07 18:48 --------- d-----w c:\program files\Fichiers communs\InstallShield

2008-12-29 17:50 --------- d-----w c:\program files\Conquete 2.0

2008-12-28 15:01 --------- d-----w c:\documents and settings\Arnoras\Application Data\SiteAdvisor

2008-12-26 20:19 --------- d-----w c:\program files\Team JPN

2008-11-16 21:15 29,138,232 ----a-w c:\program files\IE8.exe

2008-10-30 19:33 106 ----a-w c:\program files\path.ini

2008-10-08 14:37 0 ----a-w c:\program files\checkversion.txt

2008-07-17 16:36 7,710,016 ----a-w c:\program files\FLV PlayerRCATSetup.exe

2008-05-08 23:58 222 ----a-w c:\program files\pink.bmp

2008-04-10 23:15 4,162 ----a-w c:\program files\color1.bmp

2008-03-24 21:49 474 ----a-w c:\program files\color.bmp

2007-12-07 09:18 19,636 ----a-w c:\program files\th_07.jpg

2007-12-07 09:05 680 ----a-w c:\program files\bl_07.jpg

2007-12-05 13:15 23,446 ----a-w c:\program files\bk2.jpg

2007-12-05 01:06 10,528 ----a-w c:\program files\else.gif

2006-05-03 10:06 163,328 --sh--r c:\windows\system32\flvDX.dll

2007-02-21 11:47 31,232 --sh--r c:\windows\system32\msfDX.dll

2008-03-16 13:30 216,064 --sh--r c:\windows\system32\nbDX.dll

.

 

((((((((((((((((((((((((((((( SnapShot@2009-02-25_20.24.28.48 )))))))))))))))))))))))))))))))))))))))))

.

- 2009-02-20 01:08:49 62,304 ----a-r c:\windows\Installer\{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}\IconWlc.exe

+ 2009-02-25 21:10:31 62,304 ----a-r c:\windows\Installer\{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}\IconWlc.exe

+ 2008-07-21 16:34:36 121,872 ----a-w c:\windows\system32\drivers\kl1.sys

+ 2009-02-25 21:48:08 226,832 ----a-w c:\windows\system32\drivers\klif.sys

+ 2008-04-30 16:06:48 24,592 ----a-w c:\windows\system32\drivers\klim5.sys

+ 2008-11-11 18:58:54 25,601 ----a-w c:\windows\system32\drivers\klopp.dat

+ 2008-11-11 19:00:04 218,376 ----a-w c:\windows\system32\klogon.dll

+ 2009-02-26 00:31:37 16,384 ----atw c:\windows\temp\Perflib_Perfdata_38c.dat

.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]

"Google Update"="c:\documents and settings\Arnoras\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-02-14 133104]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-13 212992]

"Lachesis"="c:\program files\Razer\Lachesis\razerhid.exe" [2007-09-12 172032]

"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-10-08 221184]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]

"!AVG Anti-Spyware"="c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]

"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-02-25 206088]

"SoundMan"="SOUNDMAN.EXE" [2004-11-15 c:\windows\SOUNDMAN.EXE]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"VIDC.I420"= i420vfw.dll

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]

"LDM"=c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe

"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" boot

"Steam"="c:\program files\Steam\Steam.exe" -silent

"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background

"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" -autorun

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]

"LogitechVideoRepair"=c:\program files\Logitech\Video\ISStart.exe

"LogitechVideoTray"=c:\program files\Logitech\Video\LogiTray.exe

"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusDisableNotify"=dword:00000001

"UpdatesDisableNotify"=dword:00000001

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]

"DisableMonitoring"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"c:\\Program Files\\uTorrent\\uTorrent.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\LimeWire\\LimeWire.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"13040:TCP"= 13040:TCP:Utorrent

"13040:UDP"= 13040:UDP:Utorrent2

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]

"AllowInboundEchoRequest"= 1 (0x1)

 

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 33808]

R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-04-30 24592]

R3 LachesisFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [2008-07-05 12032]

S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-07-05 31592]

.

Contenu du dossier 'Tâches planifiées'

 

2009-02-19 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

 

2009-02-26 c:\windows\Tasks\GlaryInitialize.job

- c:\program files\Glary Utilities\initialize.exe [2009-01-10 17:02]

 

2009-02-25 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-506798661-420042220-3537155185-1007.job

- c:\documents and settings\Arnoras\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-14 13:16]

 

2009-01-02 c:\windows\Tasks\Maintenance en 1 clic.job

- c:\program files\TuneUp Utilities 2008\OneClick.exe []

.

- - - - ORPHELINS SUPPRIMES - - - -

 

HKCU-Run-Spyware Begone - c:\spywarebegone-fs\freescan.exe

 

 

.

------- Examen supplémentaire -------

.

uStart Page = hxxp://www.dufpy.com

IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

IE: Recherche sur eBay - c:\program files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html

FF - ProfilePath - c:\documents and settings\Arnoras\Application Data\Mozilla\Firefox\Profiles\w0wpsbtq.default\

FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1460988&SearchSource=3&q=

FF - prefs.js: browser.search.selectedEngine - Google

FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/

FF - component: c:\documents and settings\Arnoras\Application Data\Mozilla\Firefox\Profiles\w0wpsbtq.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}\platform\WINNT\components\EbayAccessService.dll

FF - component: c:\documents and settings\Arnoras\Application Data\Mozilla\Firefox\Profiles\w0wpsbtq.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}\platform\WINNT\components\EbayFormSubmitObserver.dll

FF - component: c:\documents and settings\Arnoras\Application Data\Mozilla\Firefox\Profiles\w0wpsbtq.default\extensions\{8241b8d6-6bac-4f48-b012-464cf0f636e9}\components\FFAlert.dll

FF - plugin: c:\documents and settings\Arnoras\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-02-26 01:32:10

Windows 5.1.2600 Service Pack 3 NTFS

 

Recherche de processus cachés ...

 

Recherche d'éléments en démarrage automatique cachés ...

 

Recherche de fichiers cachés ...

 

Scan terminé avec succès

Fichiers cachés: 0

 

**************************************************************************

.

------------------------ Autres processus actifs ------------------------

.

c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

c:\program files\Java\jre6\bin\jqs.exe

c:\windows\system32\nvsvc32.exe

c:\program files\Windows Media Player\wmpnetwk.exe

c:\program files\Razer\Lachesis\OSD.exe

c:\program files\Razer\Lachesis\razertra.exe

c:\program files\Razer\Lachesis\razerofa.exe

c:\program files\iPod\bin\iPodService.exe

c:\windows\system32\wscntfy.exe

.

**************************************************************************

.

Heure de fin: 2009-02-26 1:35:13 - La machine a redémarré

ComboFix-quarantined-files.txt 2009-02-26 00:35:10

ComboFix2.txt 2009-02-25 19:27:01

 

Avant-CF: 108 226 793 472 octets libres

Après-CF: 108,212,793,344 octets libres

 

Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4

303 --- E O F --- 2009-02-14 18:58:32

Lien vers le commentaire
Partager sur d’autres sites

Ok, va faire une 2eme passe, voici le script :

 

Killall::

Folder::
c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}

Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=-
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=-

 

Poste le rapport obtenu, et voici la suite. :P

 

Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.

  • Double-clique maintenant sur le fichier téléchargé.
  • Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
  • Choisis maintenant l'option (Recherche). Patiente jusqu'à la fin de la recherche.
  • Poste le rapport généré. (C:\TB.txt)

Lien vers le commentaire
Partager sur d’autres sites

Voici le rapport obtenu : Je m'attaque à la suite immédiatement :

 

ComboFix 09-02-25.02 - Arnoras 2009-02-26 11:05:48.3 - NTFSx86

Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.2047.1463 [GMT 1:00]

Lancé depuis: c:\documents and settings\Arnoras\Bureau\ComboFix.exe

Commutateurs utilisés :: c:\documents and settings\Arnoras\Bureau\CFScript.txt

AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated)

* Un nouveau point de restauration a été créé

.

 

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))

.

 

c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}

c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\DIFxAPI.dll

c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\DifXInstall32.exe

c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\GEARAspiWDM.inf

c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\gearaspiwdmx86.cat

c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\x86\GEARAspi.dll

c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}\x86\x86\GEARAspiWDM.sys

 

.

((((((((((((((((((((((((((((( Fichiers créés du 2009-01-26 au 2009-02-26 ))))))))))))))))))))))))))))))))))))

.

 

2009-02-26 09:17 . 2009-02-26 09:17 <REP> d-------- c:\program files\MediaJoin

2009-02-26 09:17 . 2009-02-26 09:17 <REP> d-------- c:\documents and settings\Arnoras\Application Data\Seven Zip

2009-02-26 09:17 . 2009-02-26 09:17 <REP> d-------- c:\documents and settings\All Users\Application Data\{27ED786F-D773-47F8-93EB-8A249414AD30}

2009-02-26 09:12 . 2009-02-26 09:12 <REP> d-------- c:\program files\MovieToolbox

2009-02-26 01:12 . 2009-02-26 01:12 <REP> d-------- C:\rsit

2009-02-26 00:55 . 2009-02-26 00:55 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware

2009-02-26 00:55 . 2009-02-26 00:55 <REP> d-------- c:\documents and settings\Arnoras\Application Data\Malwarebytes

2009-02-26 00:55 . 2009-02-26 00:55 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes

2009-02-26 00:55 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys

2009-02-26 00:55 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys

2009-02-25 23:20 . 2009-02-25 23:20 <REP> d-------- c:\documents and settings\Administrateur\Application Data\vlc

2009-02-25 22:43 . 2009-02-25 22:43 <REP> d-------- c:\program files\Kaspersky Lab

2009-02-25 22:43 . 2009-02-26 11:10 <REP> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab

2009-02-25 22:43 . 2009-02-26 11:07 1,598,496 --ahs---- c:\windows\system32\drivers\fidbox.dat

2009-02-25 22:43 . 2009-02-26 11:10 180,256 --ahs---- c:\windows\system32\drivers\fidbox2.dat

2009-02-25 22:43 . 2009-02-25 22:48 101,287 --a------ c:\windows\system32\drivers\klin.dat

2009-02-25 22:43 . 2009-02-25 22:48 89,601 --a------ c:\windows\system32\drivers\klick.dat

2009-02-25 22:43 . 2009-02-26 11:07 15,664 --ahs---- c:\windows\system32\drivers\fidbox.idx

2009-02-25 22:43 . 2009-02-26 11:07 1,668 --ahs---- c:\windows\system32\drivers\fidbox2.idx

2009-02-25 22:38 . 2009-02-25 22:38 <REP> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files

2009-02-25 22:14 . 2009-02-25 22:14 <REP> d-------- C:\!KillBox

2009-02-25 20:09 . 2009-02-25 20:27 <REP> d-------- C:\combo-fix

2009-02-25 20:03 . 2009-02-25 20:03 <REP> d-------- c:\program files\Trend Micro

2009-02-25 19:59 . 2009-02-25 19:59 <REP> d-------- c:\windows\system32\Kaspersky Lab

2009-02-25 19:30 . 2009-02-25 22:42 <REP> d-------- C:\spywarebegone-fs

2009-02-25 19:30 . 2009-02-25 19:30 724,992 --a------ c:\windows\iun6002.exe

2009-02-25 19:02 . 2009-02-25 19:02 <REP> d-------- c:\documents and settings\Arnoras\Application Data\AVS4YOU

2009-02-25 19:02 . 2009-02-25 19:02 <REP> d-------- c:\documents and settings\All Users\Application Data\AVS4YOU

2009-02-25 19:01 . 2009-02-26 10:18 <REP> d-------- c:\program files\Fichiers communs\AVSMedia

2009-02-25 19:01 . 2009-02-26 10:18 <REP> d-------- c:\program files\AVS4YOU

2009-02-25 19:01 . 2007-10-25 11:20 974,848 --a------ c:\windows\system32\mfc70.dll

2009-02-25 19:01 . 2007-10-25 11:20 487,424 --a------ c:\windows\system32\msvcp70.dll

2009-02-25 17:53 . 2009-02-25 18:34 <REP> d-------- c:\documents and settings\Arnoras\Application Data\eBay

2009-02-25 17:53 . 2009-02-25 18:34 <REP> d-------- c:\documents and settings\All Users\Application Data\eBay

2009-02-25 14:29 . 2009-02-25 14:30 <REP> d-------- c:\program files\PhotoFiltre

2009-02-23 22:53 . 2009-02-23 22:53 <REP> d-------- c:\windows\Intelliremote

2009-02-23 22:53 . 2009-02-25 01:38 <REP> d-------- c:\documents and settings\Arnoras\Application Data\Intelliremote

2009-02-23 19:39 . 2009-02-25 18:24 168 --a------ c:\windows\usdthank.ini

2009-02-23 19:39 . 2009-02-23 19:39 31 --a------ c:\windows\idc.ini

2009-02-22 14:42 . 2006-09-12 12:46 227,328 -r-hs---- c:\windows\system32\ac3DX.ax

2009-02-22 14:42 . 2008-03-16 14:30 216,064 -r-hs---- c:\windows\system32\nbDX.dll

2009-02-22 14:42 . 2006-03-10 22:48 169,472 -r-hs---- c:\windows\system32\MatroskaDX.ax

2009-02-22 14:42 . 2006-05-03 11:06 163,328 -r-hs---- c:\windows\system32\flvDX.dll

2009-02-22 14:42 . 2005-11-25 21:46 161,792 -r-hs---- c:\windows\system32\RealMediaDX.ax

2009-02-22 14:42 . 2006-01-13 00:23 123,904 -r-hs---- c:\windows\system32\AVCDX.ax

2009-02-22 14:42 . 2003-11-21 00:00 54,784 -r-hs---- c:\windows\system32\RLAPEDec.ax

2009-02-22 14:42 . 2004-04-27 00:00 37,888 -r-hs---- c:\windows\system32\RLMPCDec.ax

2009-02-22 14:42 . 2007-02-21 12:47 31,232 -r-hs---- c:\windows\system32\msfDX.dll

2009-02-22 13:51 . 2004-11-28 21:09 679,936 --a------ c:\windows\system32\xvidcore.dll

2009-02-20 23:00 . 2009-02-25 18:34 <REP> d-------- c:\program files\eBay

2009-02-20 23:00 . 2009-02-25 12:15 <REP> d-------- c:\documents and settings\All Users\eBay

2009-02-20 22:42 . 2009-02-20 22:42 <REP> d-------- c:\program files\Fichiers communs\GeoVid

2009-02-20 22:42 . 2007-06-28 18:55 77,824 --a------ c:\windows\system32\xvid.ax

2009-02-20 22:42 . 2005-06-07 15:11 60,416 --a------ c:\windows\system32\dsetup.dll

2009-02-20 21:34 . 2004-02-22 10:11 719,872 --a------ c:\windows\system32\devil.dll

2009-02-20 21:34 . 2007-05-17 17:30 318,976 --a------ c:\windows\system32\avisynth.dll

2009-02-20 21:34 . 2004-01-25 00:00 70,656 --a------ c:\windows\system32\yv12vfw.dll

2009-02-20 21:34 . 2004-01-25 00:00 70,656 --a------ c:\windows\system32\i420vfw.dll

2009-02-20 21:32 . 2009-02-20 21:32 <REP> d-------- c:\program files\eRightSoft

2009-02-20 21:32 . 2005-02-13 00:00 186,880 -r-hs---- c:\windows\system32\RLOgg.ax

2009-02-20 21:32 . 2005-01-18 00:26 179,200 -r-hs---- c:\windows\system32\DiracSplitter.ax

2009-02-20 21:32 . 2006-08-16 15:53 175,104 -r-hs---- c:\windows\system32\CoreAAC.ax

2009-02-20 21:32 . 2005-02-06 00:00 92,672 -r-hs---- c:\windows\system32\RLVorbisDec.ax

2009-02-20 21:32 . 2005-02-22 17:55 81,920 -r-hs---- c:\windows\system32\aac_parser.ax

2009-02-20 21:32 . 2005-02-13 00:00 67,584 -r-hs---- c:\windows\system32\RLTheoraDec.ax

2009-02-20 21:32 . 2005-02-13 00:00 51,712 -r-hs---- c:\windows\system32\RLSpeexDec.ax

2009-02-20 19:45 . 2004-05-25 17:06 417,792 --a------ c:\windows\system32\ac3filter.ax

2009-02-20 19:45 . 2005-02-27 21:48 356,352 --a------ c:\windows\system32\RealMediaSplitter.ax

2009-02-20 19:45 . 2004-01-10 17:02 258,048 --a------ c:\windows\system32\GplMpgDec.ax

2009-02-19 12:54 . 2009-02-20 22:32 <REP> d-------- c:\documents and settings\Arnoras\Application Data\Apple Computer

2009-02-19 12:53 . 2009-02-19 12:53 <REP> d-------- c:\program files\iTunes

2009-02-19 12:53 . 2009-02-19 12:53 <REP> d-------- c:\program files\iPod

2009-02-19 12:53 . 2008-04-17 13:12 107,368 --a------ c:\windows\system32\GEARAspi.dll

2009-02-19 12:53 . 2008-04-17 13:12 15,464 --a------ c:\windows\system32\drivers\GEARAspiWDM.sys

2009-02-19 12:52 . 2009-02-19 12:53 <REP> d-------- c:\program files\QuickTime

2009-02-19 12:52 . 2009-02-19 12:53 <REP> d-------- c:\program files\Fichiers communs\Apple

2009-02-19 12:52 . 2009-02-19 12:52 <REP> d-------- c:\program files\Apple Software Update

2009-02-19 12:52 . 2009-02-19 12:53 <REP> d-------- c:\documents and settings\All Users\Application Data\Apple Computer

2009-02-19 12:52 . 2009-02-19 12:52 <REP> d-------- c:\documents and settings\All Users\Application Data\Apple

2009-02-19 12:52 . 2008-11-07 14:23 32,000 --a------ c:\windows\system32\drivers\usbaapl.sys

2009-02-19 12:26 . 2008-04-14 04:33 159,232 --a------ c:\windows\system32\ptpusd.dll

2009-02-19 12:26 . 2008-04-13 20:45 15,104 --a------ c:\windows\system32\drivers\usbscan.sys

2009-02-19 12:26 . 2008-04-13 20:45 15,104 --a--c--- c:\windows\system32\dllcache\usbscan.sys

2009-02-19 12:26 . 2001-08-23 17:47 5,632 --a------ c:\windows\system32\ptpusb.dll

2009-02-18 02:00 . 2009-02-18 02:05 <REP> d-------- c:\program files\ElcomSoft

2009-02-17 10:51 . 2009-02-20 10:45 <REP> d-------- c:\documents and settings\Arnoras\Application Data\U3

2009-02-16 13:47 . 2009-02-16 13:57 <REP> d-------- c:\documents and settings\Arnoras\Application Data\fretsonfire

2009-02-16 13:46 . 2009-02-17 01:29 <REP> d-------- c:\program files\Frets on Fire

2009-02-15 23:14 . 2009-02-15 23:14 <REP> dr-h----- c:\documents and settings\Arnoras\Application Data\SecuROM

2009-02-15 23:09 . 2009-02-15 23:09 <REP> d-------- c:\program files\Aspyr

2009-02-14 18:32 . 2009-02-14 18:32 <REP> d-------- c:\documents and settings\Arnoras\Application Data\GlarySoft

2009-02-14 16:44 . 2009-02-14 16:44 <REP> d-------- C:\TarguTrans

2009-02-14 16:41 . 2009-02-14 16:42 <REP> d-------- c:\windows\speech

2009-02-14 16:41 . 2009-02-14 16:41 <REP> d-------- c:\windows\Lhsp

2009-02-14 16:32 . 2009-02-14 16:56 <REP> d-------- c:\program files\Power Translator 12

2009-02-14 13:13 . 2009-02-14 13:13 <REP> d-------- C:\profiles

2009-02-14 10:53 . 2009-02-14 10:53 <REP> d-------- c:\program files\WinPcap

2009-02-14 10:52 . 2009-02-14 12:32 <REP> d-------- c:\program files\Net Tools

2009-02-11 15:04 . 2009-02-11 15:04 <REP> d-------- c:\program files\LucasArts

2009-02-06 18:52 . 2009-02-06 18:52 49,504 --a------ c:\windows\system32\sirenacm.dll

2009-02-05 22:55 . 2009-02-05 22:55 <REP> d-------- c:\program files\Glary Utilities

2009-02-05 22:55 . 2009-02-05 22:55 <REP> d-------- c:\program files\CCleaner

2009-02-05 22:52 . 2009-02-05 22:52 <REP> d-------- c:\program files\Auslogics

2009-02-05 22:45 . 2009-02-05 22:45 <REP> d-------- c:\program files\VS Revo Group

2009-02-05 13:37 . 2009-02-05 13:37 1,044,480 -ra------ c:\windows\system32\roboex32.dll

2009-02-05 13:37 . 2009-02-05 13:37 49,152 -ra------ c:\windows\system32\inetwh32.dll

2009-02-04 18:48 . 2009-02-04 18:48 <REP> dr------- c:\documents and settings\Arnoras\Application Data\Brother

2009-02-04 17:00 . 2008-04-13 20:45 20,608 --a------ c:\windows\system32\drivers\usbuhci.sys

2009-02-04 17:00 . 2008-04-13 20:45 20,608 --a--c--- c:\windows\system32\dllcache\usbuhci.sys

2009-02-01 22:38 . 2009-02-01 22:38 <REP> d-------- c:\documents and settings\All Users\Application Data\Electronic Arts

2009-02-01 14:58 . 2009-02-01 14:58 <REP> d-------- c:\program files\LoCoSoft

2009-02-01 14:52 . 2009-02-01 14:52 <REP> d-------- c:\documents and settings\Arnoras\Application Data\AlauxSoft

 

.

(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-02-25 21:48 33,808 ----a-w c:\windows\system32\drivers\klbg.sys

2009-02-25 19:54 --------- d-----w c:\program files\IE8

2009-02-25 18:17 --------- d-----w c:\documents and settings\Arnoras\Application Data\uTorrent

2009-02-25 18:11 --------- d-----w c:\program files\eMule

2009-02-25 17:34 --------- d--h--w c:\program files\InstallShield Installation Information

2009-02-25 00:45 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP

2009-02-25 00:44 --------- d-----w c:\program files\DAEMON Tools Toolbar

2009-02-21 20:00 --------- d-----w c:\program files\Steam

2009-02-20 18:19 --------- d-----w c:\program files\Windows Live Safety Center

2009-02-14 18:57 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help

2009-02-14 11:58 --------- d-----w c:\documents and settings\Arnoras\Application Data\LimeWire

2009-02-14 11:33 --------- d-----w c:\program files\AviSynth 2.5

2009-02-12 21:53 --------- d-----w c:\program files\Messenger Plus! Live

2009-02-11 21:27 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!

2009-02-08 23:02 --------- d-----w c:\program files\DeskSpace

2009-02-08 22:54 --------- d-----w c:\program files\Gpotato.eu

2009-01-15 18:47 --------- d-----w c:\program files\Common Files

2009-01-11 01:40 --------- d-----w c:\program files\Woonoz

2009-01-11 01:40 --------- d-----w c:\program files\Anniversaire

2009-01-09 19:20 --------- d-----w c:\documents and settings\Arnoras\Application Data\Mumble

2009-01-07 19:10 --------- d-----w c:\program files\Packard Bell

2009-01-07 18:48 --------- d-----w c:\program files\Fichiers communs\InstallShield

2008-12-29 17:50 --------- d-----w c:\program files\Conquete 2.0

2008-12-28 15:01 --------- d-----w c:\documents and settings\Arnoras\Application Data\SiteAdvisor

2008-12-26 20:19 --------- d-----w c:\program files\Team JPN

2008-11-16 21:15 29,138,232 ----a-w c:\program files\IE8.exe

2008-10-30 19:33 106 ----a-w c:\program files\path.ini

2008-10-08 14:37 0 ----a-w c:\program files\checkversion.txt

2008-07-17 16:36 7,710,016 ----a-w c:\program files\FLV PlayerRCATSetup.exe

2008-05-08 23:58 222 ----a-w c:\program files\pink.bmp

2008-04-10 23:15 4,162 ----a-w c:\program files\color1.bmp

2008-03-24 21:49 474 ----a-w c:\program files\color.bmp

2007-12-07 09:18 19,636 ----a-w c:\program files\th_07.jpg

2007-12-07 09:05 680 ----a-w c:\program files\bl_07.jpg

2007-12-05 13:15 23,446 ----a-w c:\program files\bk2.jpg

2007-12-05 01:06 10,528 ----a-w c:\program files\else.gif

2006-05-03 10:06 163,328 --sh--r c:\windows\system32\flvDX.dll

2007-02-21 11:47 31,232 --sh--r c:\windows\system32\msfDX.dll

2008-03-16 13:30 216,064 --sh--r c:\windows\system32\nbDX.dll

.

 

((((((((((((((((((((((((((((( SnapShot@2009-02-25_20.24.28.48 )))))))))))))))))))))))))))))))))))))))))

.

- 2009-02-20 01:08:49 62,304 ----a-r c:\windows\Installer\{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}\IconWlc.exe

+ 2009-02-25 21:10:31 62,304 ----a-r c:\windows\Installer\{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}\IconWlc.exe

+ 2005-11-07 22:33:17 122,880 ----a-w c:\windows\system32\DirectEncode.dll

+ 2008-07-21 16:34:36 121,872 ----a-w c:\windows\system32\drivers\kl1.sys

+ 2009-02-25 21:48:08 226,832 ----a-w c:\windows\system32\drivers\klif.sys

+ 2008-04-30 16:06:48 24,592 ----a-w c:\windows\system32\drivers\klim5.sys

+ 2008-11-11 18:58:54 25,601 ----a-w c:\windows\system32\drivers\klopp.dat

+ 2005-11-07 22:32:46 3,088,384 ----a-w c:\windows\system32\erdmpg-4.dll

+ 2008-11-11 19:00:04 218,376 ----a-w c:\windows\system32\klogon.dll

+ 2003-08-07 19:01:50 237,568 ----a-w c:\windows\system32\lame_enc.dll

+ 2002-07-23 17:19:18 319,488 ----a-w c:\windows\system32\LTCML13n.dll

+ 2005-11-05 02:57:14 258,048 ----a-w c:\windows\system32\Manipulate.dll

- 2007-03-19 11:58:30 344,064 ----a-w c:\windows\system32\msvcr70.dll

+ 2002-01-05 20:37:26 344,064 ----a-w c:\windows\system32\msvcr70.dll

+ 2005-06-01 16:11:04 877,568 ----a-w c:\windows\system32\NCTAudioFile2.dll

+ 2005-06-01 16:15:42 966,144 ----a-w c:\windows\system32\NCTAudioInformation2.dll

+ 2005-05-26 16:00:34 403,968 ----a-w c:\windows\system32\NCTWMAFile2.dll

+ 2009-02-26 10:09:24 16,384 ----atw c:\windows\temp\Perflib_Perfdata_2fc.dat

.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

REGEDIT4

 

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]

"Google Update"="c:\documents and settings\Arnoras\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-02-14 133104]

 

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2002-09-13 212992]

"Lachesis"="c:\program files\Razer\Lachesis\razerhid.exe" [2007-09-12 172032]

"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2004-10-08 221184]

"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-16 13529088]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]

"!AVG Anti-Spyware"="c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]

"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2009-02-25 206088]

"SoundMan"="SOUNDMAN.EXE" [2004-11-15 c:\windows\SOUNDMAN.EXE]

 

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"VIDC.I420"= i420vfw.dll

 

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]

"LDM"=c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe

"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" boot

"Steam"="c:\program files\Steam\Steam.exe" -silent

"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background

"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" -autorun

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]

"LogitechVideoRepair"=c:\program files\Logitech\Video\ISStart.exe

"LogitechVideoTray"=c:\program files\Logitech\Video\LogiTray.exe

"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

 

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime

 

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"UpdatesDisableNotify"=dword:00000001

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"c:\\Program Files\\uTorrent\\uTorrent.exe"=

"%windir%\\Network Diagnostic\\xpnetdiag.exe"=

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\LimeWire\\LimeWire.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"13040:TCP"= 13040:TCP:Utorrent

"13040:UDP"= 13040:UDP:Utorrent2

 

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]

"AllowInboundEchoRequest"= 1 (0x1)

 

R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 33808]

R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-04-30 24592]

R3 LachesisFltr;Lachesis Mouse Driver;c:\windows\system32\drivers\Lachesis.sys [2008-07-05 12032]

S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-07-05 31592]

.

Contenu du dossier 'Tâches planifiées'

 

2009-02-26 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

 

2009-02-26 c:\windows\Tasks\GlaryInitialize.job

- c:\program files\Glary Utilities\initialize.exe [2009-01-10 17:02]

 

2009-02-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-506798661-420042220-3537155185-1007.job

- c:\documents and settings\Arnoras\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-14 13:16]

 

2009-01-02 c:\windows\Tasks\Maintenance en 1 clic.job

- c:\program files\TuneUp Utilities 2008\OneClick.exe []

.

.

------- Examen supplémentaire -------

.

uStart Page = hxxp://www.dufpy.com

IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

IE: Recherche sur eBay - c:\program files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html

FF - ProfilePath - c:\documents and settings\Arnoras\Application Data\Mozilla\Firefox\Profiles\w0wpsbtq.default\

FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1460988&SearchSource=3&q=

FF - prefs.js: browser.search.selectedEngine - Google

FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/

FF - component: c:\documents and settings\Arnoras\Application Data\Mozilla\Firefox\Profiles\w0wpsbtq.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}\platform\WINNT\components\EbayAccessService.dll

FF - component: c:\documents and settings\Arnoras\Application Data\Mozilla\Firefox\Profiles\w0wpsbtq.default\extensions\{62760FD6-B943-48C9-AB09-F99C6FE96088}\platform\WINNT\components\EbayFormSubmitObserver.dll

FF - component: c:\documents and settings\Arnoras\Application Data\Mozilla\Firefox\Profiles\w0wpsbtq.default\extensions\{8241b8d6-6bac-4f48-b012-464cf0f636e9}\components\FFAlert.dll

FF - plugin: c:\documents and settings\Arnoras\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll

.

 

**************************************************************************

 

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-02-26 11:10:00

Windows 5.1.2600 Service Pack 3 NTFS

 

Recherche de processus cachés ...

 

Recherche d'éléments en démarrage automatique cachés ...

 

Recherche de fichiers cachés ...

 

Scan terminé avec succès

Fichiers cachés: 0

 

**************************************************************************

.

------------------------ Autres processus actifs ------------------------

.

c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

c:\program files\Java\jre6\bin\jqs.exe

c:\windows\system32\nvsvc32.exe

c:\program files\Windows Media Player\wmpnetwk.exe

c:\program files\Razer\Lachesis\OSD.exe

c:\program files\Razer\Lachesis\razertra.exe

c:\program files\Razer\Lachesis\razerofa.exe

c:\program files\iPod\bin\iPodService.exe

c:\windows\system32\wscntfy.exe

.

**************************************************************************

.

Heure de fin: 2009-02-26 11:14:05 - La machine a redémarré

ComboFix-quarantined-files.txt 2009-02-26 10:14:03

ComboFix2.txt 2009-02-26 00:35:15

ComboFix3.txt 2009-02-25 19:27:01

 

Avant-CF: 108 263 587 840 octets libres

Après-CF: 108,244,336,640 octets libres

 

Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4

307 --- E O F --- 2009-02-14 18:58:32

Modifié par Arnoras
Lien vers le commentaire
Partager sur d’autres sites

et voici le TB.txt :

 

 

-----------\\ ToolBar S&D 1.2.8 XP/Vista

 

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3

X86-based PC ( Uniprocessor Free : AMD Athlon 64 Processor 3500+ )

BIOS : Phoenix - Award BIOS v6.00PG

USER : Arnoras ( Administrator )

BOOT : Normal boot

Antivirus : Kaspersky Anti-Virus 8.0.0.506 (Not Activated)

A:\ (USB)

C:\ (Local Disk) - NTFS - Total:185 Go (Free:100 Go)

D:\ (CD or DVD)

E:\ (USB)

F:\ (USB)

G:\ (USB)

H:\ (USB)

I:\ (Local Disk) - NTFS - Total:232 Go (Free:16 Go)

J:\ (CD or DVD)

K:\ (CD or DVD)

L:\ (CD or DVD)

M:\ (Local Disk) - NTFS - Total:189 Go (Free:92 Go)

 

"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )

Option : [1] ( 26/02/2009|11:16 )

 

-----------\\ Recherche de Fichiers / Dossiers ...

 

C:\Program Files\DAEMON Tools Toolbar

C:\Program Files\DAEMON Tools Toolbar\_DTLite.xml

C:\WINDOWS\iun6002.exe

 

-----------\\ Extensions

 

(Arnoras) - {1650a312-02bc-40ee-977e-83f158701739} => safe

(Arnoras) - {62760FD6-B943-48C9-AB09-F99C6FE96088} => ebaycompanion

(Arnoras) - {8241b8d6-6bac-4f48-b012-464cf0f636e9} => torrent411

(Arnoras) - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} => adblockplus

 

 

-----------\\ [..\Internet Explorer\Main]

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Start Page"="http://www.dufpy.com"

"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]

"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"

"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"'>http://go.microsoft.com/fwlink/?LinkId=54896"

"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"

"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home"

 

 

--------------------\\ Recherche d'autres infections

 

--------------------\\ ROOTKIT !!

 

Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA]

Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa]

 

--------------------\\ Cracks & Keygens ..

 

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Adobe Photoshop CS3 + Mises à jour + Keygen + Patch Fr.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Adobe Premiere Pro CS3 Multi-Language + Crack + Tutorials.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Adobe Premiere Pro CS3 Multi-language Incl Crack.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Avast Antivirus Pro v4.7.827 Fr Incl-Keygen.rar.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\avast! v4.8.1169 Pro+Keygen-HeartBug.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Crack.rar.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Everest Ultimate v4.50 + keygen[h33t][johncanadude].torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Everest.Ultimate.v4.50.inkl.Keygen.featured.by.BRD-Wolf.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\keygen.rar.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Spyware Doctor With Antivirus V6.0.0.386 + Genuine Serials + Crack.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Supreme Commander KeyGen v.1.0.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Supreme.Commander.CLONEDvD+Crack.MuLTi4-TXT.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\System Mechanic Pro v7.5.10.5 Multilanguage + Crack.1.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\System Mechanic Pro v7.5.10.5 Multilanguage + Crack.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Unreal Tournament III FR + Keygen by seeker.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Unreal Tournament III FR + Keygen.torrent

C:\DOCUME~1\Arnoras\Bureau\[PC Game]Star Wars - Episode I Racer Full Fr Crack By !llusion

C:\DOCUME~1\Arnoras\Bureau\[PC Game]Star Wars - Episode I Racer Full Fr Crack By !llusion\!llusion.txt

C:\DOCUME~1\Arnoras\Bureau\[PC Game]Star Wars - Episode I Racer Full Fr Crack By !llusion\Episode I Racer.ccd

C:\DOCUME~1\Arnoras\Bureau\[PC Game]Star Wars - Episode I Racer Full Fr Crack By !llusion\Episode I Racer.cue

C:\DOCUME~1\Arnoras\Bureau\[PC Game]Star Wars - Episode I Racer Full Fr Crack By !llusion\Episode I Racer.img

C:\DOCUME~1\Arnoras\Bureau\[PC Game]Star Wars - Episode I Racer Full Fr Crack By !llusion\Episode I Racer.sub

C:\DOCUME~1\Arnoras\Mes documents\Ma musique\Marilyn Manson - Discography 1993-2005 (1)\Bonus\Zarrbi\Berlin Crack.mp3

C:\DOCUME~1\Arnoras\Mes documents\Ma musique\Pixies Discography\Pixies - Discography 1988-2004\Pixies - Discography 1988-2004\02. Doolittle (1989)\09. Crackity Jones.mp3

C:\DOCUME~1\Arnoras\Mes documents\Ma musique\Pixies Discography\Pixies - Discography 1988-2004\Pixies - Discography 1988-2004\05. Death To The Pixies 1987-1991 (1997)\Cd 2\14. Crackity Jones.mp3

 

 

 

1 - "C:\ToolBar SD\TB_1.txt" - 26/02/2009|11:17 - Option : [1]

 

-----------\\ Fin du rapport a 11:17:13,37

Lien vers le commentaire
Partager sur d’autres sites

Bon, on a trouvé la source de l'infection, le kilo de cracks qui traîne. Un de ces cracks ou plusieurs est certainement infecté par Bagle, et c'est ce qui t'a pourri ta machine.

Débarrasse toi de ces saletés.

 

Vieux reste à éliminer, sans gravité particulière actuellement.

  • Ouvre le bloc notes. Copie-colle dedans le contenu de la boite code qui suit, sans ligne blanche vide au début, ça doit commencer par Windows Registry Editor Version 5.00 comme ci dessous :

Windows Registry Editor Version 5.00

[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa]

  • Sauvegarde cela sur le bureau en donnant comme nom lib.reg (pas d'extension texte donc).
  • Le fichier va être créé avec une icône de base de registre, double clique dessus et confirme pour l'ajouter au registre.

 

-----

 

Relance Toolbar-S&D. Choisis cette fois l'option "suppression" puis valide en appuyant sur "Entrée".

! Ne ferme pas la fenêtre lors de la suppression !

Un rapport sera généré, poste son contenu ici.

 

NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.

Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."

Tape explorer puis valide.

Lien vers le commentaire
Partager sur d’autres sites

voici le nouveau TB.txt :

 

-----------\\ ToolBar S&D 1.2.8 XP/Vista

 

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3

X86-based PC ( Uniprocessor Free : AMD Athlon 64 Processor 3500+ )

BIOS : Phoenix - Award BIOS v6.00PG

USER : Arnoras ( Administrator )

BOOT : Normal boot

Antivirus : Kaspersky Anti-Virus 8.0.0.506 (Not Activated)

A:\ (USB)

C:\ (Local Disk) - NTFS - Total:185 Go (Free:100 Go)

D:\ (CD or DVD)

E:\ (USB)

F:\ (USB)

G:\ (USB)

H:\ (USB)

I:\ (Local Disk) - NTFS - Total:232 Go (Free:16 Go)

J:\ (CD or DVD)

K:\ (CD or DVD)

L:\ (CD or DVD)

M:\ (Local Disk) - NTFS - Total:189 Go (Free:92 Go)

 

"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )

Option : [2] ( 26/02/2009|11:25 )

 

-----------\\ SUPPRESSION

 

Supprime! - C:\Program Files\DAEMON Tools Toolbar\_DTLite.xml

Supprime! - C:\WINDOWS\iun6002.exe

Supprime! - C:\Program Files\DAEMON Tools Toolbar

 

-----------\\ Recherche de Fichiers / Dossiers ...

 

 

-----------\\ Extensions

 

(Arnoras) - {1650a312-02bc-40ee-977e-83f158701739} => safe

(Arnoras) - {62760FD6-B943-48C9-AB09-F99C6FE96088} => ebaycompanion

(Arnoras) - {8241b8d6-6bac-4f48-b012-464cf0f636e9} => torrent411

(Arnoras) - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} => adblockplus

 

 

-----------\\ [..\Internet Explorer\Main]

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Start Page"="http://www.dufpy.com"

"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]

"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"

"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"'>http://go.microsoft.com/fwlink/?LinkId=54896"

"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"

"Start Page"="http://www.msn.com/"

 

 

--------------------\\ Recherche d'autres infections

 

--------------------\\ ROOTKIT !!

 

Rootkit Bagle ! .. [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA]

 

--------------------\\ Cracks & Keygens ..

 

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Adobe Photoshop CS3 + Mises à jour + Keygen + Patch Fr.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Adobe Premiere Pro CS3 Multi-Language + Crack + Tutorials.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Adobe Premiere Pro CS3 Multi-language Incl Crack.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Avast Antivirus Pro v4.7.827 Fr Incl-Keygen.rar.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\avast! v4.8.1169 Pro+Keygen-HeartBug.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Crack.rar.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Everest Ultimate v4.50 + keygen[h33t][johncanadude].torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Everest.Ultimate.v4.50.inkl.Keygen.featured.by.BRD-Wolf.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\keygen.rar.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Spyware Doctor With Antivirus V6.0.0.386 + Genuine Serials + Crack.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Supreme Commander KeyGen v.1.0.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Supreme.Commander.CLONEDvD+Crack.MuLTi4-TXT.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\System Mechanic Pro v7.5.10.5 Multilanguage + Crack.1.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\System Mechanic Pro v7.5.10.5 Multilanguage + Crack.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Unreal Tournament III FR + Keygen by seeker.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Unreal Tournament III FR + Keygen.torrent

C:\DOCUME~1\Arnoras\Bureau\[PC Game]Star Wars - Episode I Racer Full Fr Crack By !llusion

C:\DOCUME~1\Arnoras\Bureau\[PC Game]Star Wars - Episode I Racer Full Fr Crack By !llusion\!llusion.txt

C:\DOCUME~1\Arnoras\Bureau\[PC Game]Star Wars - Episode I Racer Full Fr Crack By !llusion\Episode I Racer.ccd

C:\DOCUME~1\Arnoras\Bureau\[PC Game]Star Wars - Episode I Racer Full Fr Crack By !llusion\Episode I Racer.cue

C:\DOCUME~1\Arnoras\Bureau\[PC Game]Star Wars - Episode I Racer Full Fr Crack By !llusion\Episode I Racer.img

C:\DOCUME~1\Arnoras\Bureau\[PC Game]Star Wars - Episode I Racer Full Fr Crack By !llusion\Episode I Racer.sub

C:\DOCUME~1\Arnoras\Mes documents\Ma musique\Marilyn Manson - Discography 1993-2005 (1)\Bonus\Zarrbi\Berlin Crack.mp3

C:\DOCUME~1\Arnoras\Mes documents\Ma musique\Pixies Discography\Pixies - Discography 1988-2004\Pixies - Discography 1988-2004\02. Doolittle (1989)\09. Crackity Jones.mp3

C:\DOCUME~1\Arnoras\Mes documents\Ma musique\Pixies Discography\Pixies - Discography 1988-2004\Pixies - Discography 1988-2004\05. Death To The Pixies 1987-1991 (1997)\Cd 2\14. Crackity Jones.mp3

 

 

 

1 - "C:\ToolBar SD\TB_1.txt" - 26/02/2009|11:17 - Option : [1]

2 - "C:\ToolBar SD\TB_2.txt" - 26/02/2009|11:25 - Option : [2]

 

-----------\\ Fin du rapport a 11:25:53,96

 

 

( les cracks sont toujours là ? normal ? :s )

Modifié par Arnoras
Lien vers le commentaire
Partager sur d’autres sites

Pardon ? J'ai pas compris ton dernier post ? Tu veux dire que ma machine est condamné ? ou j'ai mal compris ta phrase ? :P

 

HiJackThis.log :

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 11:32:06, on 26/02/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\Program Files\Razer\Lachesis\razerhid.exe

C:\WINDOWS\system32\LVCOMSX.EXE

C:\Program Files\Java\jre6\bin\jusched.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Razer\Lachesis\OSD.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\Windows Media Player\WMPNSCFG.exe

C:\Documents and Settings\Arnoras\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

C:\Program Files\Razer\Lachesis\razertra.exe

C:\Program Files\Razer\Lachesis\razerofa.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\explorer.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Documents and Settings\Arnoras\Bureau\HiJackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dufpy.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

R3 - Default URLSearchHook is missing

O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll

O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll (file missing)

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: (no name) - {1DBAB667-A486-421e-AFE4-CF07DD0088E5} - (no file)

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE

O4 - HKLM\..\Run: [Lachesis] C:\Program Files\Razer\Lachesis\razerhid.exe

O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Arnoras\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O8 - Extra context menu item: Recherche sur eBay - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html

O9 - Extra button: Statistiques de la protection du trafic Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo...toUploader5.cab

O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe

O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab56986.cab

O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownlo...iaSmartScan.cab

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab56907.cab

O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab56986.cab

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe

O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe

O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe

 

--

End of file - 7348 bytes

Lien vers le commentaire
Partager sur d’autres sites

Bagle s'attrape par des cracks piégés (c'est fini le temps bien pépère où on ne risquait rien). Ta machine est remplie de cracks.

Certains sont probablement piégés avec Bagle dedans. Garde ces cracks et tu finiras par réinfecter ta machine rapidement... :P

 

Relance HijackThis, clique sur "Do a system scan only" puis coche ceci et clique sur le bouton "Fix checked", en bas à gauche :

R3 - Default URLSearchHook is missing

O3 - Toolbar: (no name) - {1DBAB667-A486-421e-AFE4-CF07DD0088E5} - (no file)

 

Est-ce que ton antivirus et ton antispyware fonctionnent encore ? On peut mettre à jour, on peut scanner ? Teste stp, Bagle a la vilaine manie de les shooter.

Lien vers le commentaire
Partager sur d’autres sites

Bagle s'attrape par des cracks piégés (c'est fini le temps bien pépère où on ne risquait rien). Ta machine est remplie de cracks.

Certains sont probablement piégés avec Bagle dedans. Garde ces cracks et tu finiras par réinfecter ta machine rapidement... :P

 

En gros tu me conseills de supprimer manuellement tout ces fichiers ? :

 

--------------------\\ Cracks & Keygens ..

 

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Adobe Photoshop CS3 + Mises à jour + Keygen + Patch Fr.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Adobe Premiere Pro CS3 Multi-Language + Crack + Tutorials.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Adobe Premiere Pro CS3 Multi-language Incl Crack.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Avast Antivirus Pro v4.7.827 Fr Incl-Keygen.rar.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\avast! v4.8.1169 Pro+Keygen-HeartBug.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Crack.rar.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Everest Ultimate v4.50 + keygen[h33t][johncanadude].torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Everest.Ultimate.v4.50.inkl.Keygen.featured.by.BRD-Wolf.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\keygen.rar.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Spyware Doctor With Antivirus V6.0.0.386 + Genuine Serials + Crack.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Supreme Commander KeyGen v.1.0.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Supreme.Commander.CLONEDvD+Crack.MuLTi4-TXT.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\System Mechanic Pro v7.5.10.5 Multilanguage + Crack.1.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\System Mechanic Pro v7.5.10.5 Multilanguage + Crack.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Unreal Tournament III FR + Keygen by seeker.torrent

C:\DOCUME~1\Arnoras\Application Data\uTorrent\Unreal Tournament III FR + Keygen.torrent

C:\DOCUME~1\Arnoras\Bureau\[PC Game]Star Wars - Episode I Racer Full Fr Crack By !llusion

C:\DOCUME~1\Arnoras\Bureau\[PC Game]Star Wars - Episode I Racer Full Fr Crack By !llusion\!llusion.txt

C:\DOCUME~1\Arnoras\Bureau\[PC Game]Star Wars - Episode I Racer Full Fr Crack By !llusion\Episode I Racer.ccd

C:\DOCUME~1\Arnoras\Bureau\[PC Game]Star Wars - Episode I Racer Full Fr Crack By !llusion\Episode I Racer.cue

C:\DOCUME~1\Arnoras\Bureau\[PC Game]Star Wars - Episode I Racer Full Fr Crack By !llusion\Episode I Racer.img

C:\DOCUME~1\Arnoras\Bureau\[PC Game]Star Wars - Episode I Racer Full Fr Crack By !llusion\Episode I Racer.sub

C:\DOCUME~1\Arnoras\Mes documents\Ma musique\Marilyn Manson - Discography 1993-2005 (1)\Bonus\Zarrbi\Berlin Crack.mp3

C:\DOCUME~1\Arnoras\Mes documents\Ma musique\Pixies Discography\Pixies - Discography 1988-2004\Pixies - Discography 1988-2004\02. Doolittle (1989)\09. Crackity Jones.mp3

C:\DOCUME~1\Arnoras\Mes documents\Ma musique\Pixies Discography\Pixies - Discography 1988-2004\Pixies - Discography 1988-2004\05. Death To The Pixies 1987-1991 (1997)\Cd 2\14. Crackity Jones.mp3

 

Relance HijackThis, clique sur "Do a system scan only" puis coche ceci et clique sur le bouton "Fix checked", en bas à gauche :

 

 

Est-ce que ton antivirus et ton antispyware fonctionnent encore ? On peut mettre à jour, on peut scanner ? Teste stp, Bagle a la vilaine manie de les shooter.

 

 

j'ai reussi à lancer Spybot, et à faire la mise a jour de celui-ci. C'est déjà un début. Avast je l'ai viré, il m'a saoulé, je vais mettre antivir, qui fonctionnait déjà même avec le Virus. le problème est que je ne peux plus utilisé msn, l'exe a été supprimer lors d'une analyse combofix, et maintenant, l'exe n'existe plus, et quand j'essaye de le reinstaller, l'install de windows live me dit qu'il est déjà installer =/

Modifié par Arnoras
Lien vers le commentaire
Partager sur d’autres sites

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Invité
Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
×
×
  • Créer...