Pubs et awtqrqq & awvvw.dll [Résolu] - Sécurité - Virus
TomsGuide.com : 700 000 inscrits répondent à toutes vos questions high-tech et informatique.
Pour obtenir de l'aide, inscrivez-vous gratuitement !
 




Mot :   Pseudo :  
 
Bas de page
Auteur
 Sujet : Pubs et awtqrqq & awvvw.dll [Résolu]
 
Profil : IDNaute
Plus d'informations

Bonjour à tous. Cela fait un bon moment que mon ordinateur est, je pense, infecté.
J'explique mon probleme:
En naviguant sur internet avec mozilla firefox, j'ai beaucoup de pop up qui s'ouvrent pour m'afficher des pubs (immobilier, la redoute, centre de sécurité windows ... ect ).
Aussi, mon antivirus (Nod32) me prévient souvent de deux infections, mais il n'arrive jamais à les supprimer :

Code :
  1. c:\windows\system32\awtqrqq.dll - probablement une variante de  Win32/Genetik  cheval de Troie
  2. c:\windows\system32\awvvw.dll - Win32/Adware.Virtumonde application


J'ai aussi remarqué que le mode sans échec de mon PC ne fonctionne plus; apres avoir ouvert ma session, il affiche le bureau quelques secondes, les icones et la bare des taches disparaissent, il ne reste que l'écran noir avec écrit " Mode sans échec" dans chaque coin.

J'espere que vous pourrez m'aider.
Merci d'avance pour votre aide :).


Message édité par loys@IDN le 06-12-2007 Ã  20:39:42
Liens sponsorisés


Inscrivez-vous ou connectez-vous pour masquer ceci.

Profil : Helper
Plus d'informations

Salut,

Télécharge Hijackthis (de Trend Micro)
Poste un rapport en suivant ce tuto.


---------------
Prière de signaler si vous vous faites déjà aider sur un autre forum ou dans un autre topic.

Sécurité/Prévention
Profil : IDNaute
Plus d'informations

Salut, merci beaucoup pour ton aide :)

Voila mon rapport HijackThis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:51:26, on 01/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Kerio\Personal Firewall\persfw.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\ESET\nod32kui.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://recherche.neuf.fr/ie/default.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://recherche.neuf.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66006
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_ [...] TbId=66006
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://recherche.neuf.fr/ie/default.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_ [...] TbId=66006
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=1036
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: NOD32 Control Center.lnk = C:\Program Files\ESET\nod32kui.exe
O4 - Global Startup: Acer WLAN 11g USB Dongle.lnk = C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BlueSoleil.lnk = ?
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Microsoft Office.lnk.disabled
O4 - Global Startup: NOD32 Control Center.lnk = C:\Program Files\ESET\nod32kui.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Loïc\Menu Démarrer\Programmes\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawfl [...] awflow.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/bina [...] b56986.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-F [...] E_UNO1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activ [...] asinst.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b56907.cab
O22 - SharedTaskScheduler: z - {9794859F-875B-40F3-842F-3DBEE5680101} - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\psevwdff.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Kerio Personal Firewall (PersFw) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall\persfw.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe (file missing)

--
End of file - 9396 bytes

Profil : Helper
Plus d'informations

Re,

Infection Vundo :

Fais ces manips dans l’ordre :

1/ Télécharge VundoFix.exe :

Double-clique VundoFix.exe .
Clique sur Scan for Vundo.
Lorsque le scan est complété, clique sur le bouton Remove Vundo.
Ensuite clique sur YES
Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers.
Tu auras un message comme quoi l’ordinateur va s’éteindre, fais ok

Poste le rapport qui se trouve dans C:\vundofix.txt

2/ Télécharge Combofix (par sUBs) sur ton Bureau. (Tuto)
Double clique combofix.exe.
Tape sur la touche 1 (Yes) pour démarrer le scan.
Lorsque le scan sera complété, un rapport apparaîtra. Poste ce rapport dans ta prochaine réponse.

Le rapport se trouve ici : C:\Combofix.txt

3/ Poste un nouveau rapport HiJackThis (en ayant renommé HiJackthis.exe en scanner.exe)


---------------
Prière de signaler si vous vous faites déjà aider sur un autre forum ou dans un autre topic.

Sécurité/Prévention
Profil : IDNaute
Plus d'informations

Re,
Voici les trois rapports que tu m'as demandé :

Rapport VundoFix:

Code :
  1. Checking Java version...
  2. Java version is 1.5.0.6
  3. Scan started at 19:34:31 13/03/2007
  4. Listing files found while scanning....
  5. No infected files were found.
  6. Beginning removal...
  7. VundoFix V6.1.4
  8. Checking Java version...
  9. Java version is 1.5.0.6
  10. Scan started at 19:51:30 13/03/2007
  11. Listing files found while scanning....
  12. No infected files were found.
  13. Beginning removal...
  14. VundoFix V6.3.16
  15. Checking Java version...
  16. Java version is 1.5.0.6
  17. Old versions of java are exploitable and should be removed.
  18. Scan started at 16:56:05 14/03/2007
  19. Listing files found while scanning....
  20. VundoFix V6.3.16
  21. Checking Java version...
  22. Java version is 1.5.0.6
  23. Old versions of java are exploitable and should be removed.
  24. Scan started at 21:03:41 14/03/2007
  25. Listing files found while scanning....
  26. C:\WINDOWS\system32\efcdbbc.dll
  27. C:\WINDOWS\system32\efhkj.bak1
  28. C:\WINDOWS\system32\efhkj.bak2
  29. C:\WINDOWS\system32\efhkj.ini
  30. C:\WINDOWS\system32\efhkj.ini2
  31. C:\WINDOWS\system32\efhkj.tmp
  32. C:\WINDOWS\system32\jkhfe.dll
  33. C:\WINDOWS\system32\pmnmjhe.dll
  34. C:\WINDOWS\system32\rqrollk.dll
  35. C:\WINDOWS\system32\rqromnn.dll
  36. C:\WINDOWS\system32\ssqomlk.dll
  37. C:\WINDOWS\system32\wvurroo.dll
  38. Beginning removal...
  39. Attempting to delete C:\WINDOWS\system32\efcdbbc.dll
  40. C:\WINDOWS\system32\efcdbbc.dll Has been deleted!
  41. Attempting to delete C:\WINDOWS\system32\efhkj.bak1
  42. C:\WINDOWS\system32\efhkj.bak1 Has been deleted!
  43. Attempting to delete C:\WINDOWS\system32\efhkj.bak2
  44. C:\WINDOWS\system32\efhkj.bak2 Has been deleted!
  45. Attempting to delete C:\WINDOWS\system32\efhkj.ini
  46. C:\WINDOWS\system32\efhkj.ini Has been deleted!
  47. Attempting to delete C:\WINDOWS\system32\efhkj.ini2
  48. C:\WINDOWS\system32\efhkj.ini2 Has been deleted!
  49. Attempting to delete C:\WINDOWS\system32\efhkj.tmp
  50. C:\WINDOWS\system32\efhkj.tmp Has been deleted!
  51. Attempting to delete C:\WINDOWS\system32\jkhfe.dll
  52. C:\WINDOWS\system32\jkhfe.dll Has been deleted!
  53. Attempting to delete C:\WINDOWS\system32\pmnmjhe.dll
  54. C:\WINDOWS\system32\pmnmjhe.dll Has been deleted!
  55. Attempting to delete C:\WINDOWS\system32\rqrollk.dll
  56. C:\WINDOWS\system32\rqrollk.dll Has been deleted!
  57. Attempting to delete C:\WINDOWS\system32\rqromnn.dll
  58. C:\WINDOWS\system32\rqromnn.dll Has been deleted!
  59. Attempting to delete C:\WINDOWS\system32\ssqomlk.dll
  60. C:\WINDOWS\system32\ssqomlk.dll Has been deleted!
  61. Attempting to delete C:\WINDOWS\system32\wvurroo.dll
  62. C:\WINDOWS\system32\wvurroo.dll Could not be deleted.
  63. Performing Repairs to the registry.
  64. Done!
  65. Beginning removal...
  66. Attempting to delete C:\WINDOWS\system32\wvurroo.dll
  67. C:\WINDOWS\system32\wvurroo.dll Has been deleted!
  68. Performing Repairs to the registry.
  69. Done!
  70. VundoFix V6.6.2
  71. Checking Java version...
  72. Java version is 1.5.0.6
  73. Old versions of java are exploitable and should be removed.
  74. Java version is 1.5.0.11
  75. Scan started at 00:12:18 02/12/2007
  76. Listing files found while scanning....
  77. C:\WINDOWS\system32\awtqrqq.dll
  78. C:\windows\system32\awvtq.dll
  79. C:\WINDOWS\system32\awvvw.dll
  80. C:\windows\system32\cbxxyyx.dll
  81. C:\windows\system32\ddcya.dll
  82. C:\windows\system32\ddcyx.dll
  83. C:\windows\system32\dfdjhxjf.dll
  84. C:\WINDOWS\system32\dgybneee.dll
  85. C:\windows\system32\efrxlvnj.exe
  86. C:\windows\system32\jkkji.dll
  87. C:\windows\system32\kjkmp.bak1
  88. C:\windows\system32\kjkmp.bak2
  89. C:\windows\system32\kjkmp.ini
  90. C:\WINDOWS\system32\lmllm.bak1
  91. C:\WINDOWS\system32\lmllm.bak2
  92. C:\WINDOWS\system32\lmllm.ini
  93. C:\WINDOWS\system32\lmllm.ini2
  94. C:\WINDOWS\system32\lmllm.tmp
  95. C:\windows\system32\mljgg.dll
  96. C:\WINDOWS\system32\mllml.dll
  97. C:\WINDOWS\system32\ogqtwyjq.dll
  98. C:\windows\system32\pfgqumod.exe
  99. C:\windows\system32\pmkjk.dll
  100. C:\windows\system32\qvttdjpp.dll
  101. C:\windows\system32\vtsqq.dll
  102. C:\windows\system32\vtstu.dll
  103. C:\WINDOWS\system32\wvvwa.bak1
  104. C:\windows\system32\wvvwa.bak2
  105. C:\WINDOWS\system32\wvvwa.ini
  106. C:\WINDOWS\system32\wvvwa.ini2
  107. C:\WINDOWS\system32\wvvwa.tmp
  108. C:\WINDOWS\system32\ysetuvon.dll
  109. Beginning removal...
  110. Attempting to delete C:\WINDOWS\system32\awtqrqq.dll
  111. C:\WINDOWS\system32\awtqrqq.dll Could not be deleted.
  112. Attempting to delete C:\windows\system32\awvtq.dll
  113. C:\windows\system32\awvtq.dll Has been deleted!
  114. Attempting to delete C:\WINDOWS\system32\awvvw.dll
  115. C:\WINDOWS\system32\awvvw.dll Has been deleted!
  116. Attempting to delete C:\windows\system32\cbxxyyx.dll
  117. C:\windows\system32\cbxxyyx.dll Has been deleted!
  118. Attempting to delete C:\windows\system32\ddcya.dll
  119. C:\windows\system32\ddcya.dll Has been deleted!
  120. Attempting to delete C:\windows\system32\ddcyx.dll
  121. C:\windows\system32\ddcyx.dll Has been deleted!
  122. Attempting to delete C:\windows\system32\dfdjhxjf.dll
  123. C:\windows\system32\dfdjhxjf.dll Has been deleted!
  124. Attempting to delete C:\windows\system32\efrxlvnj.exe
  125. C:\windows\system32\efrxlvnj.exe Has been deleted!
  126. Attempting to delete C:\windows\system32\jkkji.dll
  127. C:\windows\system32\jkkji.dll Has been deleted!
  128. Attempting to delete C:\windows\system32\kjkmp.bak1
  129. C:\windows\system32\kjkmp.bak1 Has been deleted!
  130. Attempting to delete C:\windows\system32\kjkmp.bak2
  131. C:\windows\system32\kjkmp.bak2 Has been deleted!
  132. Attempting to delete C:\windows\system32\kjkmp.ini
  133. C:\windows\system32\kjkmp.ini Has been deleted!
  134. Attempting to delete C:\WINDOWS\system32\lmllm.bak1
  135. C:\WINDOWS\system32\lmllm.bak1 Has been deleted!
  136. Attempting to delete C:\WINDOWS\system32\lmllm.bak2
  137. C:\WINDOWS\system32\lmllm.bak2 Has been deleted!
  138. Attempting to delete C:\WINDOWS\system32\lmllm.ini
  139. C:\WINDOWS\system32\lmllm.ini Has been deleted!
  140. Attempting to delete C:\WINDOWS\system32\lmllm.ini2
  141. C:\WINDOWS\system32\lmllm.ini2 Has been deleted!
  142. Attempting to delete C:\WINDOWS\system32\lmllm.tmp
  143. C:\WINDOWS\system32\lmllm.tmp Has been deleted!
  144. Attempting to delete C:\windows\system32\mljgg.dll
  145. C:\windows\system32\mljgg.dll Has been deleted!
  146. Attempting to delete C:\windows\system32\pfgqumod.exe
  147. C:\windows\system32\pfgqumod.exe Has been deleted!
  148. Attempting to delete C:\windows\system32\pmkjk.dll
  149. C:\windows\system32\pmkjk.dll Has been deleted!
  150. Attempting to delete C:\windows\system32\qvttdjpp.dll
  151. C:\windows\system32\qvttdjpp.dll Has been deleted!
  152. Attempting to delete C:\windows\system32\vtsqq.dll
  153. C:\windows\system32\vtsqq.dll Has been deleted!
  154. Attempting to delete C:\windows\system32\vtstu.dll
  155. C:\windows\system32\vtstu.dll Has been deleted!
  156. Attempting to delete C:\WINDOWS\system32\wvvwa.bak1
  157. C:\WINDOWS\system32\wvvwa.bak1 Has been deleted!
  158. Attempting to delete C:\windows\system32\wvvwa.bak2
  159. C:\windows\system32\wvvwa.bak2 Has been deleted!
  160. Attempting to delete C:\WINDOWS\system32\wvvwa.ini
  161. C:\WINDOWS\system32\wvvwa.ini Has been deleted!
  162. Attempting to delete C:\WINDOWS\system32\wvvwa.ini2
  163. C:\WINDOWS\system32\wvvwa.ini2 Has been deleted!
  164. Attempting to delete C:\WINDOWS\system32\wvvwa.tmp
  165. C:\WINDOWS\system32\wvvwa.tmp Has been deleted!
  166. Performing Repairs to the registry.
  167. Done!
  168. Beginning removal...
  169. Attempting to delete C:\WINDOWS\system32\awtqrqq.dll
  170. C:\WINDOWS\system32\awtqrqq.dll Has been deleted!
  171. Performing Repairs to the registry.
  172. Done!



Rapport Combofix:

Code :
  1. ComboFix 07-12-02.4 - Loïc 2007-12-02  0:29:28.1 - NTFSx86
  2. Microsoft Windows XP Professionnel  5.1.2600.2.1252.1.1036.18.328 [GMT 1:00]
  3. Running from: C:\Documents and Settings\Loïc\Bureau\ComboFix.exe
  4. * Created a new restore point
  5. .
  6. ((((((((((((((((((((((((((((((((((((  Autres suppressions  ))))))))))))))))))))))))))))))))))))))))))))))))
  7. .
  8. C:\Documents and Settings\Eric & Valérie\Application Data\macromedia\Flash Player\#SharedObjects\AQ62P34R\www.broadcaster.com
  9. C:\Documents and Settings\Eric & Valérie\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com
  10. C:\Documents and Settings\Eric & Valérie\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.broadcaster.com\settings.sol
  11. C:\WINDOWS\system32\nvs2.inf
  12. c:\WINDOWS\system32\rfxxlimbn.dat
  13. c:\windows\system32\rfxxlimbn.exe
  14. c:\WINDOWS\system32\rfxxlimbn_nav.dat
  15. C:\WINDOWS\system32\rfxxlimbn_navps.dat
  16. C:\WINDOWS\system32\unsvchosts.exe
  17. C:\WINDOWS\system32\unsvchosts.lzma
  18. .
  19. (((((((((((((((((((((((((((((((((((((((  Drivers/Services  )))))))))))))))))))))))))))))))))))))))))))))))))
  20. .
  21. -------\LEGACY_DOMAINSERVICE
  22. -------\DomainService
  23. -------\NPF
  24. (((((((((((((((((((((((((((((  Fichiers cr‚‚s 2007-11-01 to 2007-12-01  ))))))))))))))))))))))))))))))))))))
  25. .
  26. 2007-12-01 18:50 . 2007-12-01 18:50    <REP>    d--------    C:\Program Files\Trend Micro
  27. 2007-11-28 15:42 . 2007-11-28 15:59    <REP>    d--------    C:\Program Files\The All-Seeing Eye
  28. 2007-11-27 18:45 . 2007-11-27 18:46    <REP>    d--------    C:\Program Files\Windows Live
  29. 2007-11-25 14:49 . 2007-11-25 14:49    <REP>    d--------    C:\Program Files\Microsoft CAPICOM 2.1.0.2
  30. 2007-11-25 06:52 . 2007-07-30 19:19    271,224    --a------    C:\WINDOWS\system32\mucltui.dll
  31. 2007-11-25 06:52 . 2007-07-30 19:19    207,736    --a------    C:\WINDOWS\system32\muweb.dll
  32. 2007-11-25 06:52 . 2007-07-30 19:18    30,072    --a------    C:\WINDOWS\system32\mucltui.dll.mui
  33. 2007-11-24 20:26 . 2007-11-24 20:29    <REP>    d--hsc---    C:\Program Files\Fichiers communs\WindowsLiveInstaller
  34. 2007-11-24 20:26 . 2007-11-27 19:02    <REP>    d--------    C:\Documents and Settings\All Users\Application Data\WLInstaller
  35. 2007-11-22 08:24 . 2007-11-22 08:24    <REP>    d--------    C:\Documents and Settings\All Users\Application Data\nView_Profiles
  36. 2007-11-20 00:09 . 2007-11-20 00:09    <REP>    d--------    C:\Program Files\mnProjects
  37. 2007-11-18 16:52 . 2007-11-28 14:44    107,832    --a------    C:\WINDOWS\system32\PnkBstrB.exe
  38. 2007-11-18 16:52 . 2007-11-18 16:52    66,872    --a------    C:\WINDOWS\system32\PnkBstrA.exe
  39. 2007-11-18 16:52 . 2007-11-28 14:44    22,328    --a------    C:\WINDOWS\system32\drivers\PnkBstrK.sys
  40. 2007-11-18 16:00 . 2007-11-25 08:52    <REP>    d--------    C:\Program Files\Wolfenstein - Enemy Territory
  41. 2007-11-17 11:35 . 2007-11-18 18:41    <REP>    d--------    C:\Program Files\NCSoft
  42. 2007-11-17 11:35 . 2007-03-12 16:42    3,495,784    --a------    C:\WINDOWS\system32\d3dx9_33.dll
  43. 2007-11-14 07:08 . 2007-11-14 07:08    118    --a------    C:\WINDOWS\system32\MRT.INI
  44. 2007-11-10 21:05 . 2007-11-21 15:06    54,156    --ah-----    C:\WINDOWS\QTFont.qfn
  45. 2007-11-10 21:05 . 2007-11-10 21:05    1,409    --a------    C:\WINDOWS\QTFont.for
  46. 2007-11-05 18:09 . 2007-11-05 18:45    <REP>    d--------    C:\Program Files\Perfect World
  47. 2007-11-05 18:07 . 2007-11-05 17:38    258,352    --a------    C:\WINDOWS\system32\unicows.dll
  48. 2007-11-01 15:21 . 2007-09-28 17:07    129,784    ---------    C:\WINDOWS\system32\pxafs.dll
  49. 2007-11-01 15:21 . 2007-09-28 17:07    9,464    ---------    C:\WINDOWS\system32\drivers\cdralw2k.sys
  50. 2007-11-01 15:21 . 2007-09-28 17:07    9,336    ---------    C:\WINDOWS\system32\drivers\cdr4_xp.sys
  51. 2007-11-01 09:33 . 2007-11-19 08:20    <REP>    d--------    C:\Program Files\Crawler
  52. 2007-11-01 09:33 . 2007-11-18 18:44    <REP>    d--------    C:\Program Files\Beneton Movie GIF
  53. .
  54. ((((((((((((((((((((((((((((((((((  Compte-rendu de Find3M  ))))))))))))))))))))))))))))))))))))))))))))))))
  55. .
  56. 2007-12-01 21:31    ---------    d-----w    C:\Program Files\eMule
  57. 2007-11-24 18:39    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\Google Updater
  58. 2007-11-18 17:44    ---------    d-----w    C:\Program Files\vanBasco's Karaoke Player
  59. 2007-11-18 17:44    ---------    d-----w    C:\Program Files\TrackMania Nations ESWC
  60. 2007-11-18 17:44    ---------    d-----w    C:\Program Files\StuffPlug3
  61. 2007-11-18 17:44    ---------    d-----w    C:\Program Files\LimeWire
  62. 2007-11-18 17:44    ---------    d-----w    C:\Program Files\Heroes Ragnarok
  63. 2007-11-18 17:44    ---------    d-----w    C:\Program Files\FrenchOtto
  64. 2007-11-18 17:44    ---------    d-----w    C:\Program Files\FaxTools
  65. 2007-11-18 17:44    ---------    d-----w    C:\Program Files\DivX
  66. 2007-11-18 17:41    ---------    d--h--w    C:\Program Files\InstallShield Installation Information
  67. 2007-11-18 17:39    ---------    d-----w    C:\Program Files\Jasc Software Inc
  68. 2007-10-23 10:29    ---------    d-----w    C:\Program Files\Net Pro Anti-Popup
  69. 2007-10-22 17:10    ---------    d-----w    C:\Documents and Settings\All Users\Application Data\WhiteCap (Holiday Edition)
  70. 2007-10-22 17:08    ---------    d-----w    C:\Program Files\Microsoft
  71. 2007-10-21 15:20    ---------    d-----w    C:\Program Files\Red Kawa
  72. 2006-12-09 22:54    251    ----a-w    C:\Program Files\wt3d.ini
  73. 2007-07-26 08:13    6,486    --sh--w    C:\WINDOWS\system32\bbeeg.bak1
  74. 2007-04-29 11:49    538,529    --sh--w    C:\WINDOWS\system32\egjlm.bak1
  75. 2007-07-12 06:38    505,697    --sh--w    C:\WINDOWS\system32\egjlm.bak2
  76. 2007-07-18 17:14    557,212    --sh--w    C:\WINDOWS\system32\egjlm.ini2
  77. 2007-07-19 08:06    6,545    --sh--w    C:\WINDOWS\system32\fgjlm.bak1
  78. 2007-07-25 14:32    6,526    --sh--w    C:\WINDOWS\system32\fgjlm.bak2
  79. 2007-07-27 09:45    6,655    --sh--w    C:\WINDOWS\system32\fgjlm.ini2
  80. 2007-07-31 08:36    6,486    --sh--w    C:\WINDOWS\system32\fhhkj.bak1
  81. 2007-07-14 17:30    6,362    --sh--w    C:\WINDOWS\system32\gjkkj.bak1
  82. 2007-07-19 13:32    6,362    --sh--w    C:\WINDOWS\system32\gjllm.bak1
  83. 2007-07-12 17:45    6,362    --sh--w    C:\WINDOWS\system32\hjjlm.bak1
  84. 2007-07-20 11:14    6,362    --sh--w    C:\WINDOWS\system32\hjkmp.bak1
  85. 2007-07-20 05:56    6,362    --sh--w    C:\WINDOWS\system32\ijllm.bak1
  86. 2007-07-13 16:02    6,362    --sh--w    C:\WINDOWS\system32\ilnmp.bak1
  87. 2007-07-15 17:38    6,710    --sh--w    C:\WINDOWS\system32\ilnmp.bak2
  88. 2007-07-11 07:48    6,497    --sh--w    C:\WINDOWS\system32\jjllm.bak1
  89. 2007-07-13 09:59    6,402    --sh--w    C:\WINDOWS\system32\jjllm.bak2
  90. 2007-07-30 17:16    6,486    --sh--w    C:\WINDOWS\system32\kjkkj.bak1
  91. 2007-07-13 11:53    6,362    --sh--w    C:\WINDOWS\system32\klkkj.bak1
  92. 2007-07-25 18:35    6,526    --sh--w    C:\WINDOWS\system32\mpqss.bak1
  93. 2007-07-12 18:19    6,482    --sh--w    C:\WINDOWS\system32\nqtss.bak1
  94. 2007-07-30 18:49    6,486    --sh--w    C:\WINDOWS\system32\orutv.bak1
  95. 2007-07-13 08:52    6,362    --sh--w    C:\WINDOWS\system32\pqtss.bak1
  96. 2007-07-16 07:46    6,362    --sh--w    C:\WINDOWS\system32\rqtss.bak1
  97. 2007-07-17 22:08    6,362    --sh--w    C:\WINDOWS\system32\rtutv.bak1
  98. 2007-07-20 08:06    6,362    --sh--w    C:\WINDOWS\system32\srqss.bak1
  99. 2007-07-10 10:30    6,547    --sh--w    C:\WINDOWS\system32\ststv.bak1
  100. 2007-07-31 08:25    6,486    --sh--w    C:\WINDOWS\system32\uttss.bak1
  101. 2007-07-18 07:50    6,568    --sh--w    C:\WINDOWS\system32\wybeg.bak1
  102. 2007-07-23 20:48    6,486    --sh--w    C:\WINDOWS\system32\wybeg.bak2
  103. 2007-07-18 20:58    6,406    --sh--w    C:\WINDOWS\system32\wycdd.bak1
  104. 2007-07-22 08:59    6,526    --sh--w    C:\WINDOWS\system32\wycdd.bak2
  105. 2007-07-28 11:15    6,486    --sh--w    C:\WINDOWS\system32\yccdd.bak1
  106. 2007-07-26 20:50    6,486    --sh--w    C:\WINDOWS\system32\yybeg.bak1
  107. .
  108. (((((((((((((((((((((((((((((((((  Point de chargement Reg  )))))))))))))))))))))))))))))))))))))))))))))))))
  109. .
  110. .
  111. *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
  112. [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0BE01085-B26D-4F83-8B23-E269C00895F4}]
  113.             C:\WINDOWS\system32\uayeaflv.dll
  114. [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{11C3004B-1C61-4A14-B43D-870FA5DE49E3}]
  115.             C:\WINDOWS\system32\mllml.dll
  116. [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8B637DAB-09C1-4509-9C41-B7DEFE0EF726}]
  117.             C:\WINDOWS\system32\wvurroo.dll
  118. [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9794859F-875B-40F3-842F-3DBEE5680101}]
  119. [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{99EB758D-F83E-411B-B831-B1BE84EF9ECF}]
  120.             C:\WINDOWS\system32\mllml.dll
  121. [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B2DAA879-74EB-43A9-8867-033A6DBA2367}]
  122.             C:\WINDOWS\system32\uayeaflv.dll
  123. [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DFE8772C-312C-49EC-9A7B-A9E4BB789A6F}]
  124.             C:\WINDOWS\system32\awvvw.dll
  125. [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E108FE29-5684-44FB-896A-443374608B8B}]
  126.             C:\WINDOWS\system32\awvvw.dll
  127. [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EBB99DBB-9896-4EB0-BC56-844412E8B29d}]
  128.             C:\WINDOWS\system32\uayeaflv.dll
  129. [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
  130. "MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-11-06 15:03]
  131. "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 21:00]
  132. "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2007-05-16 08:27]
  133. [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
  134. "NvCplDaemon"="RUNDLL32.exe" [2004-08-10 21:00 C:\WINDOWS\system32\rundll32.exe]
  135. "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-12-05 20:46]
  136. "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 15:57]
  137. "NeroFilterCheck"="C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2007-03-01 14:57]
  138. "UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" []
  139. [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
  140. "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 21:00]
  141. [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
  142. "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
  143. "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
  144. [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
  145. "{8B637DAB-09C1-4509-9C41-B7DEFE0EF726}"= C:\WINDOWS\system32\wvurroo.dll [ ]
  146. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddccy]
  147. C:\WINDOWS\system32\ddccy.dll
  148. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcyw]
  149. C:\WINDOWS\system32\ddcyw.dll
  150. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebyw]
  151. C:\WINDOWS\system32\gebyw.dll
  152. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebyy]
  153. C:\WINDOWS\system32\gebyy.dll
  154. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geebb]
  155. C:\WINDOWS\system32\geebb.dll
  156. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkhhf]
  157. C:\WINDOWS\system32\jkhhf.dll
  158. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkjg]
  159. C:\WINDOWS\system32\jkkjg.dll
  160. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkjk]
  161. C:\WINDOWS\system32\jkkjk.dll
  162. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkklk]
  163. C:\WINDOWS\system32\jkklk.dll
  164. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljge]
  165. C:\WINDOWS\system32\mljge.dll
  166. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljgf]
  167. C:\WINDOWS\system32\mljgf.dll
  168. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljjh]
  169. C:\WINDOWS\system32\mljjh.dll
  170. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mlljg]
  171. C:\WINDOWS\system32\mlljg.dll
  172. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mllji]
  173. C:\WINDOWS\system32\mllji.dll
  174. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mlljj]
  175. C:\WINDOWS\system32\mlljj.dll
  176. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mllml]
  177. C:\WINDOWS\system32\mllml.dll
  178. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmkhh]
  179. C:\WINDOWS\system32\pmkhh.dll
  180. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmkjh]
  181. C:\WINDOWS\system32\pmkjh.dll
  182. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnli]
  183. C:\WINDOWS\system32\pmnli.dll
  184. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqpm]
  185. C:\WINDOWS\system32\ssqpm.dll
  186. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqrs]
  187. C:\WINDOWS\system32\ssqrs.dll
  188. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sstqn]
  189. C:\WINDOWS\system32\sstqn.dll
  190. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sstqp]
  191. C:\WINDOWS\system32\sstqp.dll
  192. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sstqr]
  193. C:\WINDOWS\system32\sstqr.dll
  194. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssttu]
  195. C:\WINDOWS\system32\ssttu.dll
  196. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtsts]
  197. C:\WINDOWS\system32\vtsts.dll
  198. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vturo]
  199. C:\WINDOWS\system32\vturo.dll
  200. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtutr]
  201. C:\WINDOWS\system32\vtutr.dll
  202. [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winzbd32]
  203. winzbd32.dll
  204. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\j4241531]
  205.             rundll32 C:\WINDOWS\system32\j4241531.dll sook
  206. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
  207.             RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
  208. [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\setup]
  209.             rundll32.exe C:\WINDOWS\system32\vlobmjpy.dll,realset
  210. [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
  211. "NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
  212. "GPLv3"=rundll32.exe "C:\WINDOWS\system32\xocfstys.dll",realset
  213. "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
  214. "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe"  -osboot
  215. R1 fwdrv;Kerio Personal Firewall Driver;C:\WINDOWS\system32\Drivers\fwdrv.sys
  216. S2 Ca533av;Icatch(IV) Video Camera Device;C:\WINDOWS\system32\Drivers\Ca533av.sys
  217. S3 int15.sys;int15.sys;\??\C:\Acer\Empowering Technology\eRecovery\int15.sys
  218. S3 psdfilter;psdfilter;\??\C:\WINDOWS\system32\Drivers\psdfilter.sys
  219. S3 psdvdisk;psdvdisk;\??\C:\WINDOWS\system32\Drivers\psdvdisk.sys
  220. S3 USBCamera;Icatch(IV) Still Camera Device;C:\WINDOWS\system32\Drivers\Bulk533.sys
  221. S3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys
  222. .
  223. Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
  224. "2007-11-07 09:03:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
  225. - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
  226. .
  227. **************************************************************************
  228. catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
  229. Rootkit scan 2007-12-02 00:34:34
  230. Windows 5.1.2600 Service Pack 2 NTFS
  231. scanning hidden processes ...
  232. scanning hidden autostart entries ...
  233. scanning hidden files ...
  234. scan completed successfully
  235. hidden files: 0
  236. **************************************************************************
  237. .
  238. Completion time: 2007-12-02  0:35:02 - machine was rebooted
  239. .
  240.     --- E O F ---



Rapport HijackThis:

Code :
  1. Logfile of Trend Micro HijackThis v2.0.2
  2. Scan saved at 00:38:03, on 02/12/2007
  3. Platform: Windows XP SP2 (WinNT 5.01.2600)
  4. MSIE: Internet Explorer v7.00 (7.00.6000.16544)
  5. Boot mode: Normal
  6. Running processes:
  7. C:\WINDOWS\System32\smss.exe
  8. C:\WINDOWS\system32\winlogon.exe
  9. C:\WINDOWS\system32\services.exe
  10. C:\WINDOWS\system32\lsass.exe
  11. C:\WINDOWS\system32\svchost.exe
  12. C:\WINDOWS\System32\svchost.exe
  13. C:\WINDOWS\system32\LEXBCES.EXE
  14. C:\WINDOWS\system32\spoolsv.exe
  15. C:\WINDOWS\system32\LEXPPS.EXE
  16. C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
  17. C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
  18. C:\WINDOWS\eHome\ehRecvr.exe
  19. C:\WINDOWS\eHome\ehSched.exe
  20. c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
  21. C:\Program Files\Eset\nod32krn.exe
  22. C:\WINDOWS\system32\nvsvc32.exe
  23. C:\Program Files\Kerio\Personal Firewall\persfw.exe
  24. C:\WINDOWS\system32\PnkBstrA.exe
  25. C:\WINDOWS\system32\svchost.exe
  26. C:\WINDOWS\system32\dllhost.exe
  27. C:\WINDOWS\Explorer.EXE
  28. C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
  29. C:\Program Files\QuickTime\qttask.exe
  30. C:\WINDOWS\system32\ctfmon.exe
  31. C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
  32. C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
  33. C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
  34. C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
  35. C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
  36. C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
  37. C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
  38. C:\Program Files\Google\Google Updater\GoogleUpdater.exe
  39. C:\Program Files\ESET\nod32kui.exe
  40. C:\WINDOWS\System32\svchost.exe
  41. C:\WINDOWS\system32\wuauclt.exe
  42. C:\Program Files\Mozilla Firefox\firefox.exe
  43. C:\Program Files\Trend Micro\HijackThis\scanner.exe
  44. R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
  45. R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
  46. R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://recherche.neuf.fr/
  47. R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66006
  48. R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=66006
  49. R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
  50. R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
  51. R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=1036
  52. R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
  53. R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
  54. O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
  55. O2 - BHO: (no name) - {0BE01085-B26D-4F83-8B23-E269C00895F4} - C:\WINDOWS\system32\uayeaflv.dll (file missing)
  56. O2 - BHO: (no name) - {11C3004B-1C61-4A14-B43D-870FA5DE49E3} - C:\WINDOWS\system32\mllml.dll (file missing)
  57. O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.2.7.dll
  58. O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\eoRezo\EoAdv\EoRezobho.dll (file missing)
  59. O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
  60. O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
  61. O2 - BHO: (no name) - {8B637DAB-09C1-4509-9C41-B7DEFE0EF726} - C:\WINDOWS\system32\wvurroo.dll (file missing)
  62. O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
  63. O2 - BHO: (no name) - {9794859F-875B-40F3-842F-3DBEE5680101} - (no file)
  64. O2 - BHO: (no name) - {99EB758D-F83E-411B-B831-B1BE84EF9ECF} - C:\WINDOWS\system32\mllml.dll (file missing)
  65. O2 - BHO: (no name) - {B2DAA879-74EB-43A9-8867-033A6DBA2367} - C:\WINDOWS\system32\uayeaflv.dll (file missing)
  66. O2 - BHO: (no name) - {DFE8772C-312C-49EC-9A7B-A9E4BB789A6F} - C:\WINDOWS\system32\awvvw.dll (file missing)
  67. O2 - BHO: (no name) - {E108FE29-5684-44FB-896A-443374608B8B} - C:\WINDOWS\system32\awvvw.dll (file missing)
  68. O2 - BHO: (no name) - {EBB99DBB-9896-4EB0-BC56-844412E8B29d} - C:\WINDOWS\system32\uayeaflv.dll (file missing)
  69. O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
  70. O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe"  -osboot
  71. O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
  72. O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
  73. O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
  74. O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
  75. O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
  76. O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
  77. O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
  78. O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
  79. O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
  80. O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
  81. O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
  82. O4 - Startup: NOD32 Control Center.lnk = C:\Program Files\ESET\nod32kui.exe
  83. O4 - Global Startup: Acer WLAN 11g USB Dongle.lnk = C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
  84. O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
  85. O4 - Global Startup: BlueSoleil.lnk = ?
  86. O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
  87. O4 - Global Startup: Microsoft Office.lnk.disabled
  88. O4 - Global Startup: NOD32 Control Center.lnk = C:\Program Files\ESET\nod32kui.exe
  89. O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
  90. O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
  91. O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
  92. O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
  93. O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
  94. O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
  95. O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Loïc\Menu Démarrer\Programmes\IMVU\Run IMVU.lnk (file missing)
  96. O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
  97. O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
  98. O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
  99. O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
  100. O16 - DPF: {029FDBA6-3547-11D7-AA4C-0050BF051A00} (Rawflow ICD Client) - http://s.tf1.fr/mmdia/static/rawflow/clients/5.3.1.0/Rawflow.cab
  101. O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
  102. O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
  103. O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
  104. O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
  105. O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
  106. O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
  107. O20 - Winlogon Notify: ddccy - C:\WINDOWS\system32\ddccy.dll (file missing)
  108. O20 - Winlogon Notify: ddcyw - C:\WINDOWS\system32\ddcyw.dll (file missing)
  109. O20 - Winlogon Notify: gebyw - C:\WINDOWS\system32\gebyw.dll (file missing)
  110. O20 - Winlogon Notify: gebyy - C:\WINDOWS\system32\gebyy.dll (file missing)
  111. O20 - Winlogon Notify: geebb - C:\WINDOWS\system32\geebb.dll (file missing)
  112. O20 - Winlogon Notify: jkhhf - C:\WINDOWS\system32\jkhhf.dll (file missing)
  113. O20 - Winlogon Notify: jkkjg - C:\WINDOWS\system32\jkkjg.dll (file missing)
  114. O20 - Winlogon Notify: jkkjk - C:\WINDOWS\system32\jkkjk.dll (file missing)
  115. O20 - Winlogon Notify: jkklk - C:\WINDOWS\system32\jkklk.dll (file missing)
  116. O20 - Winlogon Notify: mljge - C:\WINDOWS\system32\mljge.dll (file missing)
  117. O20 - Winlogon Notify: mljgf - C:\WINDOWS\system32\mljgf.dll (file missing)
  118. O20 - Winlogon Notify: mljjh - C:\WINDOWS\system32\mljjh.dll (file missing)
  119. O20 - Winlogon Notify: mlljg - C:\WINDOWS\system32\mlljg.dll (file missing)
  120. O20 - Winlogon Notify: mllji - C:\WINDOWS\system32\mllji.dll (file missing)
  121. O20 - Winlogon Notify: mlljj - C:\WINDOWS\system32\mlljj.dll (file missing)
  122. O20 - Winlogon Notify: mllml - C:\WINDOWS\system32\mllml.dll (file missing)
  123. O20 - Winlogon Notify: pmkhh - C:\WINDOWS\system32\pmkhh.dll (file missing)
  124. O20 - Winlogon Notify: pmkjh - C:\WINDOWS\system32\pmkjh.dll (file missing)
  125. O20 - Winlogon Notify: pmnli - C:\WINDOWS\system32\pmnli.dll (file missing)
  126. O20 - Winlogon Notify: ssqpm - C:\WINDOWS\system32\ssqpm.dll (file missing)
  127. O20 - Winlogon Notify: ssqrs - C:\WINDOWS\system32\ssqrs.dll (file missing)
  128. O20 - Winlogon Notify: sstqn -