mon log hijackthis pour worm.win32netsky, je crois...
Dernière réponse : dans Sécurité
bonjour, je patouille....
voilà mon log hijackthis...pour de l'aide
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:46:56, on 18/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\SysMonitor.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe
C:\Program Files\USB Disk Win98 Driver\Res.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\christine\Application Data\Simply Super Software\Trojan Remover\kbw43.exe
C:\Documents and Settings\christine\Application Data\Simply Super Software\Trojan Remover\kbw43.exe
C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\Répertoire temporaire 1 pour HiJackThis.zip\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ycomp/defaults/sp/*http://fr.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*http://fr.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: SXG Advisor - {DC4BF2E8-EA1E-4826-A0DA-E02ED1C0156A} - C:\WINDOWS\dmdqdrxodn.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - (no file)
O3 - Toolbar: emotrlq - {42F4C015-019A-4344-93B2-E0F3FD708ED7} - C:\WINDOWS\emotrlq.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [ntiMUI] c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\WINDOWS\system32\SysMonitor.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe 1
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Device Detector] "C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe" -autorun
O4 - HKLM\..\Run: [USB Storage Toolbox] C:\Program Files\USB Disk Win98 Driver\Res.EXE
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [TrojanScanner] C:\Program Files\Trojan Remover\Trjscan.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [updateMgr] c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Acer Empowering Technology.lnk = ?
O4 - Global Startup: Acer WLAN 11g USB Dongle.lnk = C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall....
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by126w.bay126.mail.live.com/mail/resources/MsnPU...
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.ca...
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab569...
O17 - HKLM\System\CCS\Services\Tcpip\..\{9899DC21-CCBC-423F-A4D2-64B5084FF2E2}: NameServer = 192.168.3.1
O21 - SSODL: bdmnopx - {29BF673B-C6C3-475C-8D2D-FE21EF9FF928} - C:\WINDOWS\bdmnopx.dll
O21 - SSODL: admggxp - {E78851FC-0C42-4D1D-9906-01807253F0D1} - C:\WINDOWS\admggxp.dll
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
--
End of file - 13356 bytes
Autres pages sur : log hijackthis worm win32netsky
Lassé par la pub ? Créez un compte
Bonjour,
[#ff0000]Désactive tes protections résidentes (antivirus, Spybot...) ![/#f]
Télécharge Combofix ([#ff0000]sUBs[/#f]) sur ton Bureau.
Double clique sur combofix.exe afin de le lancer.
Tape sur la touche 1 (Yes) pour démarrer le scan.
Lorsque le scan sera complété, un rapport apparaîtra. Poste ce rapport dans ta prochaine réponse.
[#ff0000]Désactive tes protections résidentes (antivirus, Spybot...) ![/#f]
omboFix 08-02-18.1 - christine 2008-02-18 19:21:15.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1496 [GMT 1:00]
Endroit: C:\Documents and Settings\christine\Local Settings\Temporary Internet Files\Content.IE5\X9928HQ2\ComboFix[1].exe
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\am‚lie\Bureau\Error Cleaner.url
C:\Documents and Settings\am‚lie\Bureau\Privacy Protector.url
C:\WINDOWS\dat.txt
C:\WINDOWS\search_res.txt
.
((((((((((((((((((((((((((((( Fichiers créés 2008-01-18 to 2008-02-18 ))))))))))))))))))))))))))))))))))))
.
2008-02-18 17:11 . 2008-02-18 17:11 <REP> d-------- C:\Documents and Settings\christine\Application Data\Symantec
2008-02-18 13:01 . 2008-02-18 13:01 <REP> d-------- C:\Program Files\CCleaner
2008-02-17 15:40 . 2008-01-10 15:57 2,421,312 --a------ C:\Documents and Settings\mathieu\Application Data.exe
2008-02-17 15:18 . 2008-02-18 19:04 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-17 15:16 . 2008-02-18 18:30 <REP> d-------- C:\Program Files\Trojan Remover
2008-02-17 15:16 . 2008-02-17 15:16 <REP> d-------- C:\Documents and Settings\christine\Application Data\Simply Super Software
2008-02-17 15:16 . 2008-02-17 15:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
2008-02-17 15:16 . 2006-05-25 14:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2008-02-17 15:16 . 2003-02-02 19:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2008-02-17 15:16 . 2005-08-26 00:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2008-02-17 15:16 . 2002-03-06 00:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-02-17 15:16 . 2006-06-19 12:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
2008-02-15 18:54 . 2008-02-16 20:08 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-15 18:54 . 2008-02-15 18:54 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-13 22:04 . 2008-02-13 17:52 258,048 --a------ C:\WINDOWS\dmdqdrxodn.dll
2008-02-13 22:04 . 2008-02-13 17:52 217,088 --a------ C:\WINDOWS\bdmnopx.dll
2008-02-13 22:04 . 2008-02-13 17:52 196,608 --a------ C:\WINDOWS\admggxp.dll
2008-02-13 22:04 . 2008-02-13 17:52 172,032 --a------ C:\WINDOWS\emotrlq.dll
2008-02-13 22:04 . 2008-02-13 17:52 81,920 --a------ C:\WINDOWS\fsxloqf.exe
2008-02-13 22:03 . 2008-02-13 22:04 <REP> d-------- C:\Program Files\MediaAccumulativeCodec
2008-02-13 21:09 . 2008-02-13 21:09 39,963 --a------ C:\WINDOWS\system32\diperto.ini
2008-01-23 09:52 . 2008-01-23 09:52 <REP> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-18 15:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-02-17 14:39 --------- d-----w C:\Documents and Settings\mathieu\Application Data\AdobeUM
2008-02-17 14:26 --------- d-----w C:\Program Files\USB Disk Win98 Driver
2008-02-16 13:59 --------- d-----w C:\Program Files\Norton AntiVirus
2008-02-16 13:58 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-02-16 13:58 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-02-16 13:58 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-02-16 13:58 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-02-16 13:58 --------- d-----w C:\Program Files\Symantec
2008-02-16 13:58 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-02-16 13:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-09 08:59 --------- d-----w C:\Program Files\MinitelADSL
2008-01-10 17:00 --------- d-----w C:\Program Files\LG Electronics
2008-01-10 16:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-10 16:56 --------- d-----w C:\Program Files\LG PC Suite
2007-12-20 19:07 --------- d-----w C:\Program Files\Dofus
2007-12-20 11:52 --------- d-----w C:\Program Files\Hoogendoorn
2007-12-18 09:51 179,584 ----a-w C:\WINDOWS\system32\drivers\mrxdav.sys
2007-12-07 02:08 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:41 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-03-10 15:47 251 ----a-w C:\Program Files\wt3d.ini
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DC4BF2E8-EA1E-4826-A0DA-E02ED1C0156A}]
2008-02-13 17:52 258048 --a------ C:\WINDOWS\dmdqdrxodn.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{5CBE3B7C-1E47-477E-A7DD-396DB0476E29}
{EF99BD32-C1FB-11D2-892F-0090271D4F88}
{2318C2B1-4965-11D4-9B18-009027A5CD4F}
{4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33}
{42F4C015-019A-4344-93B2-E0F3FD708ED7}
[HKEY_CLASSES_ROOT\clsid\{42f4c015-019a-4344-93b2-e0f3fd708ed7}]
[HKEY_CLASSES_ROOT\emotrlq.1]
[HKEY_CLASSES_ROOT\TypeLib\{18355603-0151-4093-8E73-E8FE98C513F3}]
[HKEY_CLASSES_ROOT\emotrlq]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 21:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-07 12:14 68856]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [ ]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2007-01-23 08:06 204843]
"updateMgr"="c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 15:45 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 14:01 67584]
"LaunchApp"="Alaunch" []
"RTHDCPL"="RTHDCPL.EXE" [2006-06-01 01:48 16208384 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 03:04 2879488 C:\WINDOWS\SkyTel.exe]
"ntiMUI"="c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2005-05-11 16:15 45056]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-10 21:00 208952]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-10 21:00 44032]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 21:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 21:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 21:00 455168]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-27 23:47 7573504]
"nwiz"="nwiz.exe" [2006-04-27 23:47 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-04-27 23:47 86016]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"Acer Empowering Technology Monitor"="C:\WINDOWS\system32\SysMonitor.exe" [2006-04-18 19:54 49152]
"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2006-03-17 15:00 345088]
"eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\eRAgent.exe" [2006-06-01 14:40 413696]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-10 21:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2007-01-18 00:21 115816]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2007-01-18 00:24 771704]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-08-04 12:45 155648]
"Device Detector"="C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe" [2005-06-27 09:21 221184]
"USB Storage Toolbox"="C:\Program Files\USB Disk Win98 Driver\Res.EXE" [2005-09-14 20:44 65536]
"Symantec PIF AlertEng"="C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 10:22 517768]
"TrojanScanner"="C:\Program Files\Trojan Remover\Trjscan.exe" [2008-02-18 18:29 862288]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 21:00 15360]
C:\Documents and Settings\elisa\Menu D‚marrer\Programmes\D‚marrage\
SM.lnk - C:\Program Files\SM\skymessnet.exe [2007-03-28 14:43:42 581632]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Acer Empowering Technology.lnk - C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe [2007-01-02 15:14:00 45056]
Acer WLAN 11g USB Dongle.lnk - C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe [2005-11-16 19:25:14 745472]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26 29696]
Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-11-27 11:00:14 126136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"bdmnopx"= {29BF673B-C6C3-475C-8D2D-FE21EF9FF928} - C:\WINDOWS\bdmnopx.dll [2008-02-13 17:52 217088]
"admggxp"= {E78851FC-0C42-4D1D-9906-01807253F0D1} - C:\WINDOWS\admggxp.dll [2008-02-13 17:52 196608]
R0 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys [2004-12-17 03:14]
R2 Planificateur LiveUpdate automatique;Planificateur LiveUpdate automatique;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2007-09-26 10:56]
R3 int15.sys;int15.sys;C:\Acer\Empowering Technology\eRecovery\int15.sys [2005-01-13 14:46]
R3 psdfilter;psdfilter;C:\WINDOWS\system32\Drivers\psdfilter.sys [2006-04-07 20:17]
R3 psdvdisk;psdvdisk;C:\WINDOWS\system32\Drivers\psdvdisk.sys [2006-03-08 17:10]
S3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2005-10-28 10:38]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{124f6789-a4b0-11db-9516-0030da3f28ef}]
\Shell\AutoRun\command - wscript.exe VirusRemoval.vbs
\Shell\open\Command - wscript.exe VirusRemoval.vbs
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-02-11 20:07:24 C:\WINDOWS\Tasks\Norton AntiVirus Online - Analyse système complète - christine.job"
- C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-18 19:24:39
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-02-18 19:25:04
ComboFix-quarantined-files.txt 2008-02-18 18:25:02
ComboFix2.txt 2008-02-18 18:12:31
.
2008-02-14 09:19:39 --- E O F ---
j'ai galéré pour copier ça merci pour l'aide, mais ça marche toujours pas.....a+....répondez svp
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1496 [GMT 1:00]
Endroit: C:\Documents and Settings\christine\Local Settings\Temporary Internet Files\Content.IE5\X9928HQ2\ComboFix[1].exe
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\am‚lie\Bureau\Error Cleaner.url
C:\Documents and Settings\am‚lie\Bureau\Privacy Protector.url
C:\WINDOWS\dat.txt
C:\WINDOWS\search_res.txt
.
((((((((((((((((((((((((((((( Fichiers créés 2008-01-18 to 2008-02-18 ))))))))))))))))))))))))))))))))))))
.
2008-02-18 17:11 . 2008-02-18 17:11 <REP> d-------- C:\Documents and Settings\christine\Application Data\Symantec
2008-02-18 13:01 . 2008-02-18 13:01 <REP> d-------- C:\Program Files\CCleaner
2008-02-17 15:40 . 2008-01-10 15:57 2,421,312 --a------ C:\Documents and Settings\mathieu\Application Data.exe
2008-02-17 15:18 . 2008-02-18 19:04 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-17 15:16 . 2008-02-18 18:30 <REP> d-------- C:\Program Files\Trojan Remover
2008-02-17 15:16 . 2008-02-17 15:16 <REP> d-------- C:\Documents and Settings\christine\Application Data\Simply Super Software
2008-02-17 15:16 . 2008-02-17 15:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
2008-02-17 15:16 . 2006-05-25 14:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2008-02-17 15:16 . 2003-02-02 19:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2008-02-17 15:16 . 2005-08-26 00:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2008-02-17 15:16 . 2002-03-06 00:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-02-17 15:16 . 2006-06-19 12:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
2008-02-15 18:54 . 2008-02-16 20:08 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-15 18:54 . 2008-02-15 18:54 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-13 22:04 . 2008-02-13 17:52 258,048 --a------ C:\WINDOWS\dmdqdrxodn.dll
2008-02-13 22:04 . 2008-02-13 17:52 217,088 --a------ C:\WINDOWS\bdmnopx.dll
2008-02-13 22:04 . 2008-02-13 17:52 196,608 --a------ C:\WINDOWS\admggxp.dll
2008-02-13 22:04 . 2008-02-13 17:52 172,032 --a------ C:\WINDOWS\emotrlq.dll
2008-02-13 22:04 . 2008-02-13 17:52 81,920 --a------ C:\WINDOWS\fsxloqf.exe
2008-02-13 22:03 . 2008-02-13 22:04 <REP> d-------- C:\Program Files\MediaAccumulativeCodec
2008-02-13 21:09 . 2008-02-13 21:09 39,963 --a------ C:\WINDOWS\system32\diperto.ini
2008-01-23 09:52 . 2008-01-23 09:52 <REP> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-18 15:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-02-17 14:39 --------- d-----w C:\Documents and Settings\mathieu\Application Data\AdobeUM
2008-02-17 14:26 --------- d-----w C:\Program Files\USB Disk Win98 Driver
2008-02-16 13:59 --------- d-----w C:\Program Files\Norton AntiVirus
2008-02-16 13:58 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-02-16 13:58 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-02-16 13:58 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-02-16 13:58 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-02-16 13:58 --------- d-----w C:\Program Files\Symantec
2008-02-16 13:58 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-02-16 13:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-09 08:59 --------- d-----w C:\Program Files\MinitelADSL
2008-01-10 17:00 --------- d-----w C:\Program Files\LG Electronics
2008-01-10 16:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-10 16:56 --------- d-----w C:\Program Files\LG PC Suite
2007-12-20 19:07 --------- d-----w C:\Program Files\Dofus
2007-12-20 11:52 --------- d-----w C:\Program Files\Hoogendoorn
2007-12-18 09:51 179,584 ----a-w C:\WINDOWS\system32\drivers\mrxdav.sys
2007-12-07 02:08 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:41 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-03-10 15:47 251 ----a-w C:\Program Files\wt3d.ini
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DC4BF2E8-EA1E-4826-A0DA-E02ED1C0156A}]
2008-02-13 17:52 258048 --a------ C:\WINDOWS\dmdqdrxodn.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{5CBE3B7C-1E47-477E-A7DD-396DB0476E29}
{EF99BD32-C1FB-11D2-892F-0090271D4F88}
{2318C2B1-4965-11D4-9B18-009027A5CD4F}
{4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33}
{42F4C015-019A-4344-93B2-E0F3FD708ED7}
[HKEY_CLASSES_ROOT\clsid\{42f4c015-019a-4344-93b2-e0f3fd708ed7}]
[HKEY_CLASSES_ROOT\emotrlq.1]
[HKEY_CLASSES_ROOT\TypeLib\{18355603-0151-4093-8E73-E8FE98C513F3}]
[HKEY_CLASSES_ROOT\emotrlq]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 21:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-07 12:14 68856]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [ ]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2007-01-23 08:06 204843]
"updateMgr"="c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 15:45 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 14:01 67584]
"LaunchApp"="Alaunch" []
"RTHDCPL"="RTHDCPL.EXE" [2006-06-01 01:48 16208384 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 03:04 2879488 C:\WINDOWS\SkyTel.exe]
"ntiMUI"="c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2005-05-11 16:15 45056]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-10 21:00 208952]
"IMEKRMIG6.1"="C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-10 21:00 44032]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 21:00 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 21:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 21:00 455168]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-27 23:47 7573504]
"nwiz"="nwiz.exe" [2006-04-27 23:47 1519616 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-04-27 23:47 86016]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"Acer Empowering Technology Monitor"="C:\WINDOWS\system32\SysMonitor.exe" [2006-04-18 19:54 49152]
"eDataSecurity Loader"="C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2006-03-17 15:00 345088]
"eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\eRAgent.exe" [2006-06-01 14:40 413696]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-10 21:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2007-01-18 00:21 115816]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2007-01-18 00:24 771704]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-08-04 12:45 155648]
"Device Detector"="C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe" [2005-06-27 09:21 221184]
"USB Storage Toolbox"="C:\Program Files\USB Disk Win98 Driver\Res.EXE" [2005-09-14 20:44 65536]
"Symantec PIF AlertEng"="C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 10:22 517768]
"TrojanScanner"="C:\Program Files\Trojan Remover\Trjscan.exe" [2008-02-18 18:29 862288]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 21:00 15360]
C:\Documents and Settings\elisa\Menu D‚marrer\Programmes\D‚marrage\
SM.lnk - C:\Program Files\SM\skymessnet.exe [2007-03-28 14:43:42 581632]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Acer Empowering Technology.lnk - C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe [2007-01-02 15:14:00 45056]
Acer WLAN 11g USB Dongle.lnk - C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe [2005-11-16 19:25:14 745472]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26 29696]
Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-11-27 11:00:14 126136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"bdmnopx"= {29BF673B-C6C3-475C-8D2D-FE21EF9FF928} - C:\WINDOWS\bdmnopx.dll [2008-02-13 17:52 217088]
"admggxp"= {E78851FC-0C42-4D1D-9906-01807253F0D1} - C:\WINDOWS\admggxp.dll [2008-02-13 17:52 196608]
R0 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys [2004-12-17 03:14]
R2 Planificateur LiveUpdate automatique;Planificateur LiveUpdate automatique;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2007-09-26 10:56]
R3 int15.sys;int15.sys;C:\Acer\Empowering Technology\eRecovery\int15.sys [2005-01-13 14:46]
R3 psdfilter;psdfilter;C:\WINDOWS\system32\Drivers\psdfilter.sys [2006-04-07 20:17]
R3 psdvdisk;psdvdisk;C:\WINDOWS\system32\Drivers\psdvdisk.sys [2006-03-08 17:10]
S3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2005-10-28 10:38]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{124f6789-a4b0-11db-9516-0030da3f28ef}]
\Shell\AutoRun\command - wscript.exe VirusRemoval.vbs
\Shell\open\Command - wscript.exe VirusRemoval.vbs
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-02-11 20:07:24 C:\WINDOWS\Tasks\Norton AntiVirus Online - Analyse système complète - christine.job"
- C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-18 19:24:39
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-02-18 19:25:04
ComboFix-quarantined-files.txt 2008-02-18 18:25:02
ComboFix2.txt 2008-02-18 18:12:31
.
2008-02-14 09:19:39 --- E O F ---
j'ai galéré pour copier ça merci pour l'aide, mais ça marche toujours pas.....a+....répondez svp
Télécharge le fichier suivant :
http://dcangeldark.googlepages.com/KillD.zip
Dézippe le sur ton bureau. Lance Kill.cmd puis poste le rapport.
http://dcangeldark.googlepages.com/KillD.zip
Dézippe le sur ton bureau. Lance Kill.cmd puis poste le rapport.
:\WINDOWS\admggxp.dll - Erreur de Suppression !
----------
C:\WINDOWS\bdmnopx.dll - Erreur de Suppression !
----------
C:\WINDOWS\dmdqdrxodn.dll - Erreur de Suppression !
----------
C:\WINDOWS\emotrlq.dll - Erreur de Suppression !
----------
C:\WINDOWS\fsxloqf.exe - Supprime !
----------
C:\Program Files\MediaAccumulativeCodec - Erreur de Suppression !
----------
j'ai pas tout compris mais j'espère que vous pouvez m'aider parceque ça va toujours pas!!!!!!!!!!!!!!!!!
----------
C:\WINDOWS\bdmnopx.dll - Erreur de Suppression !
----------
C:\WINDOWS\dmdqdrxodn.dll - Erreur de Suppression !
----------
C:\WINDOWS\emotrlq.dll - Erreur de Suppression !
----------
C:\WINDOWS\fsxloqf.exe - Supprime !
----------
C:\Program Files\MediaAccumulativeCodec - Erreur de Suppression !
----------
j'ai pas tout compris mais j'espère que vous pouvez m'aider parceque ça va toujours pas!!!!!!!!!!!!!!!!!
:\WINDOWS\admggxp.dll - Erreur de Suppression !
----------
C:\WINDOWS\bdmnopx.dll - Erreur de Suppression !
----------
C:\WINDOWS\dmdqdrxodn.dll - Erreur de Suppression !
----------
C:\WINDOWS\emotrlq.dll - Erreur de Suppression !
----------
C:\WINDOWS\fsxloqf.exe - Supprime !
----------
C:\Program Files\MediaAccumulativeCodec - Erreur de Suppression !
----------
C:\WINDOWS\admggxp.dll - Erreur de Suppression !
----------
C:\WINDOWS\bdmnopx.dll - Erreur de Suppression !
----------
C:\WINDOWS\dmdqdrxodn.dll - Erreur de Suppression !
----------
C:\WINDOWS\emotrlq.dll - Supprime !
----------
C:\Program Files\MediaAccumulativeCodec - Erreur de Suppression !
----------
c'est pareil???!!
----------
C:\WINDOWS\bdmnopx.dll - Erreur de Suppression !
----------
C:\WINDOWS\dmdqdrxodn.dll - Erreur de Suppression !
----------
C:\WINDOWS\emotrlq.dll - Erreur de Suppression !
----------
C:\WINDOWS\fsxloqf.exe - Supprime !
----------
C:\Program Files\MediaAccumulativeCodec - Erreur de Suppression !
----------
C:\WINDOWS\admggxp.dll - Erreur de Suppression !
----------
C:\WINDOWS\bdmnopx.dll - Erreur de Suppression !
----------
C:\WINDOWS\dmdqdrxodn.dll - Erreur de Suppression !
----------
C:\WINDOWS\emotrlq.dll - Supprime !
----------
C:\Program Files\MediaAccumulativeCodec - Erreur de Suppression !
----------
c'est pareil???!!
ahhhh sorrryyy, je suis pas douée:
ComboFix 08-02-20.2 - christine 2008-02-20 19:25:53.3 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1572 [GMT 1:00]Endroit: C:\Documents and Settings\christine\Local Settings\Temporary Internet Files\Content.IE5\X9928HQ2\ComboFix[1].exe
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\am‚lie\Bureau\Error Cleaner.url
C:\Documents and Settings\am‚lie\Bureau\Privacy Protector.url
C:\Documents and Settings\amélie\Bureau\Spyware&Malware Protection.url
C:\Documents and Settings\amélie\Favoris\Error Cleaner.url
C:\Documents and Settings\amélie\Favoris\Privacy Protector.url
C:\Documents and Settings\amélie\Favoris\Spyware&Malware Protection.url
C:\Documents and Settings\christine\Bureau\Error Cleaner.url
C:\Documents and Settings\christine\Bureau\Privacy Protector.url
C:\Documents and Settings\christine\Bureau\Spyware&Malware Protection.url
C:\Documents and Settings\christine\Favoris\Error Cleaner.url
C:\Documents and Settings\christine\Favoris\Privacy Protector.url
C:\Documents and Settings\christine\Favoris\Spyware&Malware Protection.url
C:\Documents and Settings\mathieu\Bureau\Error Cleaner.url
C:\Documents and Settings\mathieu\Bureau\Privacy Protector.url
C:\Documents and Settings\mathieu\Bureau\Spyware&Malware Protection.url
C:\Documents and Settings\mathieu\Favoris\Error Cleaner.url
C:\Documents and Settings\mathieu\Favoris\Privacy Protector.url
C:\Documents and Settings\mathieu\Favoris\Spyware&Malware Protection.url
C:\Documents and Settings\serge\Favoris\Error Cleaner.url
C:\Documents and Settings\serge\Favoris\Privacy Protector.url
C:\Documents and Settings\serge\Favoris\Spyware&Malware Protection.url
C:\WINDOWS\dat.txt
C:\WINDOWS\rs.txt
C:\WINDOWS\search_res.txt
----- BITS: Possible sites infectés -----
hxxp://onsafepro.com
hxxp://softworldnetwork.com
.
((((((((((((((((((((((((((((( Fichiers créés 2008-01-20 to 2008-02-20 ))))))))))))))))))))))))))))))))))))
.
2008-02-18 17:11 . 2008-02-18 17:11 <REP> d-------- C:\Documents and Settings\christine\Application Data\Symantec
2008-02-18 13:01 . 2008-02-18 13:01 <REP> d-------- C:\Program Files\CCleaner
2008-02-17 15:40 . 2008-01-10 15:57 2,421,312 --a------ C:\Documents and Settings\mathieu\Application Data.exe
2008-02-17 15:18 . 2008-02-18 19:04 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-17 15:16 . 2008-02-18 18:30 <REP> d-------- C:\Program Files\Trojan Remover
2008-02-17 15:16 . 2008-02-17 15:16 <REP> d-------- C:\Documents and Settings\christine\Application Data\Simply Super Software
2008-02-17 15:16 . 2008-02-17 15:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
2008-02-17 15:16 . 2006-05-25 14:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2008-02-17 15:16 . 2003-02-02 19:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2008-02-17 15:16 . 2005-08-26 00:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2008-02-17 15:16 . 2002-03-06 00:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-02-17 15:16 . 2006-06-19 12:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
2008-02-13 22:04 . 2008-02-13 17:52 258,048 --------- C:\WINDOWS\dmdqdrxodn.dll
2008-02-13 22:04 . 2008-02-13 17:52 217,088 --------- C:\WINDOWS\bdmnopx.dll
2008-02-13 22:04 . 2008-02-13 17:52 196,608 --------- C:\WINDOWS\admggxp.dll
2008-02-13 22:03 . 2008-02-13 22:04 <REP> d-------- C:\Program Files\MediaAccumulativeCodec
2008-02-13 21:09 . 2008-02-13 21:09 39,963 --a------ C:\WINDOWS\system32\diperto.ini
2008-01-23 09:52 . 2008-01-23 09:52 <REP> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-19 17:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-02-17 14:39 --------- d-----w C:\Documents and Settings\mathieu\Application Data\AdobeUM
2008-02-17 14:26 --------- d-----w C:\Program Files\USB Disk Win98 Driver
2008-02-16 13:59 --------- d-----w C:\Program Files\Norton AntiVirus
2008-02-16 13:58 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-02-16 13:58 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-02-16 13:58 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-02-16 13:58 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-02-16 13:58 --------- d-----w C:\Program Files\Symantec
2008-02-16 13:58 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-02-16 13:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-09 08:59 --------- d-----w C:\Program Files\MinitelADSL
2008-01-10 17:00 --------- d-----w C:\Program Files\LG Electronics
2008-01-10 16:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-10 16:56 --------- d-----w C:\Program Files\LG PC Suite
2007-12-20 19:07 --------- d-----w C:\Program Files\Dofus
2007-12-20 11:52 --------- d-----w C:\Program Files\Hoogendoorn
2007-12-07 02:08 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:41 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-03-10 15:47 251 ----a-w C:\Program Files\wt3d.ini
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DC4BF2E8-EA1E-4826-A0DA-E02ED1C0156A}]
2008-02-13 17:52 258048 --------- C:\WINDOWS\dmdqdrxodn.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 21:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-07 12:14 68856]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [ ]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2007-01-23 08:06 204843]
"updateMgr"="c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 15:45 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-27 23:47 7573504]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2007-01-18 00:21 115816]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 21:00 15360]
C:\Documents and Settings\elisa\Menu D‚marrer\Programmes\D‚marrage\
SM.lnk - C:\Program Files\SM\skymessnet.exe [2007-03-28 14:43:42 581632]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Acer Empowering Technology.lnk - C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe [2007-01-02 15:14:00 45056]
Acer WLAN 11g USB Dongle.lnk - C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe [2005-11-16 19:25:14 745472]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26 29696]
Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-11-27 11:00:14 126136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"bdmnopx"= {ED961B3E-3DC0-452A-AA8B-61731F5C848A} - C:\WINDOWS\bdmnopx.dll [2008-02-13 17:52 217088]
"admggxp"= {F97F2DC4-5D55-4E5B-9A42-82FAD914A692} - C:\WINDOWS\admggxp.dll [2008-02-13 17:52 196608]
R0 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys [2004-12-17 03:14]
R2 Planificateur LiveUpdate automatique;Planificateur LiveUpdate automatique;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2007-09-26 10:56]
S3 int15.sys;int15.sys;C:\Acer\Empowering Technology\eRecovery\int15.sys [2005-01-13 14:46]
S3 psdfilter;psdfilter;C:\WINDOWS\system32\Drivers\psdfilter.sys [2006-04-07 20:17]
S3 psdvdisk;psdvdisk;C:\WINDOWS\system32\Drivers\psdvdisk.sys [2006-03-08 17:10]
S3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2005-10-28 10:38]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{124f6789-a4b0-11db-9516-0030da3f28ef}]
\Shell\AutoRun\command - wscript.exe VirusRemoval.vbs
\Shell\open\Command - wscript.exe VirusRemoval.vbs
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-02-11 20:07:24 C:\WINDOWS\Tasks\Norton AntiVirus Online - Analyse système complète - christine.job"
- C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-20 19:29:05
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-02-20 19:29:28
ComboFix-quarantined-files.txt 2008-02-20 18:29:26
ComboFix2.txt 2008-02-18 18:25:05
ComboFix3.txt 2008-02-18 18:12:31
.
2008-02-14 09:19:39 --- E O F ---
ComboFix 08-02-20.2 - christine 2008-02-20 19:25:53.3 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1572 [GMT 1:00]Endroit: C:\Documents and Settings\christine\Local Settings\Temporary Internet Files\Content.IE5\X9928HQ2\ComboFix[1].exe
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\am‚lie\Bureau\Error Cleaner.url
C:\Documents and Settings\am‚lie\Bureau\Privacy Protector.url
C:\Documents and Settings\amélie\Bureau\Spyware&Malware Protection.url
C:\Documents and Settings\amélie\Favoris\Error Cleaner.url
C:\Documents and Settings\amélie\Favoris\Privacy Protector.url
C:\Documents and Settings\amélie\Favoris\Spyware&Malware Protection.url
C:\Documents and Settings\christine\Bureau\Error Cleaner.url
C:\Documents and Settings\christine\Bureau\Privacy Protector.url
C:\Documents and Settings\christine\Bureau\Spyware&Malware Protection.url
C:\Documents and Settings\christine\Favoris\Error Cleaner.url
C:\Documents and Settings\christine\Favoris\Privacy Protector.url
C:\Documents and Settings\christine\Favoris\Spyware&Malware Protection.url
C:\Documents and Settings\mathieu\Bureau\Error Cleaner.url
C:\Documents and Settings\mathieu\Bureau\Privacy Protector.url
C:\Documents and Settings\mathieu\Bureau\Spyware&Malware Protection.url
C:\Documents and Settings\mathieu\Favoris\Error Cleaner.url
C:\Documents and Settings\mathieu\Favoris\Privacy Protector.url
C:\Documents and Settings\mathieu\Favoris\Spyware&Malware Protection.url
C:\Documents and Settings\serge\Favoris\Error Cleaner.url
C:\Documents and Settings\serge\Favoris\Privacy Protector.url
C:\Documents and Settings\serge\Favoris\Spyware&Malware Protection.url
C:\WINDOWS\dat.txt
C:\WINDOWS\rs.txt
C:\WINDOWS\search_res.txt
----- BITS: Possible sites infectés -----
hxxp://onsafepro.com
hxxp://softworldnetwork.com
.
((((((((((((((((((((((((((((( Fichiers créés 2008-01-20 to 2008-02-20 ))))))))))))))))))))))))))))))))))))
.
2008-02-18 17:11 . 2008-02-18 17:11 <REP> d-------- C:\Documents and Settings\christine\Application Data\Symantec
2008-02-18 13:01 . 2008-02-18 13:01 <REP> d-------- C:\Program Files\CCleaner
2008-02-17 15:40 . 2008-01-10 15:57 2,421,312 --a------ C:\Documents and Settings\mathieu\Application Data.exe
2008-02-17 15:18 . 2008-02-18 19:04 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-17 15:16 . 2008-02-18 18:30 <REP> d-------- C:\Program Files\Trojan Remover
2008-02-17 15:16 . 2008-02-17 15:16 <REP> d-------- C:\Documents and Settings\christine\Application Data\Simply Super Software
2008-02-17 15:16 . 2008-02-17 15:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
2008-02-17 15:16 . 2006-05-25 14:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2008-02-17 15:16 . 2003-02-02 19:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2008-02-17 15:16 . 2005-08-26 00:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2008-02-17 15:16 . 2002-03-06 00:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-02-17 15:16 . 2006-06-19 12:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
2008-02-13 22:04 . 2008-02-13 17:52 258,048 --------- C:\WINDOWS\dmdqdrxodn.dll
2008-02-13 22:04 . 2008-02-13 17:52 217,088 --------- C:\WINDOWS\bdmnopx.dll
2008-02-13 22:04 . 2008-02-13 17:52 196,608 --------- C:\WINDOWS\admggxp.dll
2008-02-13 22:03 . 2008-02-13 22:04 <REP> d-------- C:\Program Files\MediaAccumulativeCodec
2008-02-13 21:09 . 2008-02-13 21:09 39,963 --a------ C:\WINDOWS\system32\diperto.ini
2008-01-23 09:52 . 2008-01-23 09:52 <REP> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-19 17:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-02-17 14:39 --------- d-----w C:\Documents and Settings\mathieu\Application Data\AdobeUM
2008-02-17 14:26 --------- d-----w C:\Program Files\USB Disk Win98 Driver
2008-02-16 13:59 --------- d-----w C:\Program Files\Norton AntiVirus
2008-02-16 13:58 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-02-16 13:58 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-02-16 13:58 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-02-16 13:58 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-02-16 13:58 --------- d-----w C:\Program Files\Symantec
2008-02-16 13:58 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-02-16 13:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-09 08:59 --------- d-----w C:\Program Files\MinitelADSL
2008-01-10 17:00 --------- d-----w C:\Program Files\LG Electronics
2008-01-10 16:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-10 16:56 --------- d-----w C:\Program Files\LG PC Suite
2007-12-20 19:07 --------- d-----w C:\Program Files\Dofus
2007-12-20 11:52 --------- d-----w C:\Program Files\Hoogendoorn
2007-12-07 02:08 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:41 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-03-10 15:47 251 ----a-w C:\Program Files\wt3d.ini
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DC4BF2E8-EA1E-4826-A0DA-E02ED1C0156A}]
2008-02-13 17:52 258048 --------- C:\WINDOWS\dmdqdrxodn.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 21:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-07 12:14 68856]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [ ]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2007-01-23 08:06 204843]
"updateMgr"="c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 15:45 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-27 23:47 7573504]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2007-01-18 00:21 115816]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 21:00 15360]
C:\Documents and Settings\elisa\Menu D‚marrer\Programmes\D‚marrage\
SM.lnk - C:\Program Files\SM\skymessnet.exe [2007-03-28 14:43:42 581632]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Acer Empowering Technology.lnk - C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe [2007-01-02 15:14:00 45056]
Acer WLAN 11g USB Dongle.lnk - C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe [2005-11-16 19:25:14 745472]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26 29696]
Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-11-27 11:00:14 126136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"bdmnopx"= {ED961B3E-3DC0-452A-AA8B-61731F5C848A} - C:\WINDOWS\bdmnopx.dll [2008-02-13 17:52 217088]
"admggxp"= {F97F2DC4-5D55-4E5B-9A42-82FAD914A692} - C:\WINDOWS\admggxp.dll [2008-02-13 17:52 196608]
R0 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys [2004-12-17 03:14]
R2 Planificateur LiveUpdate automatique;Planificateur LiveUpdate automatique;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2007-09-26 10:56]
S3 int15.sys;int15.sys;C:\Acer\Empowering Technology\eRecovery\int15.sys [2005-01-13 14:46]
S3 psdfilter;psdfilter;C:\WINDOWS\system32\Drivers\psdfilter.sys [2006-04-07 20:17]
S3 psdvdisk;psdvdisk;C:\WINDOWS\system32\Drivers\psdvdisk.sys [2006-03-08 17:10]
S3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2005-10-28 10:38]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{124f6789-a4b0-11db-9516-0030da3f28ef}]
\Shell\AutoRun\command - wscript.exe VirusRemoval.vbs
\Shell\open\Command - wscript.exe VirusRemoval.vbs
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-02-11 20:07:24 C:\WINDOWS\Tasks\Norton AntiVirus Online - Analyse système complète - christine.job"
- C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-20 19:29:05
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-02-20 19:29:28
ComboFix-quarantined-files.txt 2008-02-20 18:29:26
ComboFix2.txt 2008-02-18 18:25:05
ComboFix3.txt 2008-02-18 18:12:31
.
2008-02-14 09:19:39 --- E O F ---
Re,
[#ff0000]Désactive tes protections résidentes (antivirus...) ![/#f]
Copie (Ctrl+C) le texte se situant dans le cadre ci-dessous :
Ouvre le Bloc-Notes puis colle (Ctrl+V) le texte précedemment copié.
Sauvegarde ce fichier sous le nom de CFScript.txt.
Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :
![]()
Cela va relancer Combofix, tape sur 1 puis valide. Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.
[#ff0000]NOTE : S'il n'y a pas de rédémarrage, poste quand même les rapports demandés.[/#f]
[#ff0000]Désactive tes protections résidentes (antivirus...) ![/#f]
Copie (Ctrl+C) le texte se situant dans le cadre ci-dessous :
File::
C:\WINDOWS\dmdqdrxodn.dll
C:\WINDOWS\bdmnopx.dll
C:\WINDOWS\admggxp.dll
Folder::
C:\Program Files\MediaAccumulativeCodec
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DC4BF2E8-EA1E-4826-A0DA-E02ED1C0156A}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"bdmnopx"=-
"admggxp"=-
C:\WINDOWS\dmdqdrxodn.dll
C:\WINDOWS\bdmnopx.dll
C:\WINDOWS\admggxp.dll
Folder::
C:\Program Files\MediaAccumulativeCodec
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DC4BF2E8-EA1E-4826-A0DA-E02ED1C0156A}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"bdmnopx"=-
"admggxp"=-
Ouvre le Bloc-Notes puis colle (Ctrl+V) le texte précedemment copié.
Sauvegarde ce fichier sous le nom de CFScript.txt.
Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :

Cela va relancer Combofix, tape sur 1 puis valide. Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.
[#ff0000]NOTE : S'il n'y a pas de rédémarrage, poste quand même les rapports demandés.[/#f]
ComboFix 08-02-18.1 - christine 2008-02-22 13:51:00.4 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1435 [GMT 1:00]
Endroit: C:\Documents and Settings\christine\Mes documents\ComboFix.exe
Command switches used :: C:\Documents and Settings\christine\Mes documents\CFScript.txt
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\am‚lie\Bureau\Error Cleaner.url
C:\Documents and Settings\am‚lie\Bureau\Privacy Protector.url
C:\Documents and Settings\amélie\Bureau\Spyware&Malware Protection.url
C:\Documents and Settings\amélie\Favoris\Error Cleaner.url
C:\Documents and Settings\amélie\Favoris\Privacy Protector.url
C:\Documents and Settings\amélie\Favoris\Spyware&Malware Protection.url
C:\Documents and Settings\christine\Bureau\Error Cleaner.url
C:\Documents and Settings\christine\Bureau\Privacy Protector.url
C:\Documents and Settings\christine\Bureau\Spyware&Malware Protection.url
C:\Documents and Settings\christine\Favoris\Error Cleaner.url
C:\Documents and Settings\christine\Favoris\Privacy Protector.url
C:\Documents and Settings\christine\Favoris\Spyware&Malware Protection.url
C:\Documents and Settings\mathieu\Bureau\Error Cleaner.url
C:\Documents and Settings\mathieu\Bureau\Privacy Protector.url
C:\Documents and Settings\mathieu\Bureau\Spyware&Malware Protection.url
C:\Documents and Settings\mathieu\Favoris\Error Cleaner.url
C:\Documents and Settings\mathieu\Favoris\Privacy Protector.url
C:\Documents and Settings\mathieu\Favoris\Spyware&Malware Protection.url
C:\Program Files\MediaAccumulativeCodec
C:\Program Files\MediaAccumulativeCodec\install.ico
C:\Program Files\MediaAccumulativeCodec\MediaAccumulativeCodec.ocx
C:\Program Files\MediaAccumulativeCodec\Uninstall.exe
C:\WINDOWS\dat.txt
C:\WINDOWS\rs.txt
C:\WINDOWS\search_res.txt
----- BITS: Possible sites infectés -----
hxxp://softworldnetwork.com
hxxp://onsafepro.com
.
((((((((((((((((((((((((((((( Fichiers créés 2008-01-22 to 2008-02-22 ))))))))))))))))))))))))))))))))))))
.
2008-02-22 10:31 . 2008-02-22 10:31 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-22 10:31 . 2008-02-22 10:31 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-18 17:11 . 2008-02-18 17:11 <REP> d-------- C:\Documents and Settings\christine\Application Data\Symantec
2008-02-18 13:01 . 2008-02-18 13:01 <REP> d-------- C:\Program Files\CCleaner
2008-02-17 15:40 . 2008-01-10 15:57 2,421,312 --a------ C:\Documents and Settings\mathieu\Application Data.exe
2008-02-17 15:18 . 2008-02-18 19:04 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-17 15:16 . 2008-02-18 18:30 <REP> d-------- C:\Program Files\Trojan Remover
2008-02-17 15:16 . 2008-02-17 15:16 <REP> d-------- C:\Documents and Settings\christine\Application Data\Simply Super Software
2008-02-17 15:16 . 2008-02-17 15:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
2008-02-17 15:16 . 2006-05-25 14:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2008-02-17 15:16 . 2003-02-02 19:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2008-02-17 15:16 . 2005-08-26 00:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2008-02-17 15:16 . 2002-03-06 00:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-02-17 15:16 . 2006-06-19 12:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
2008-02-13 22:04 . 2008-02-13 17:52 258,048 --------- C:\WINDOWS\dmdqdrxodn.dll
2008-02-13 22:04 . 2008-02-13 17:52 217,088 --------- C:\WINDOWS\bdmnopx.dll
2008-02-13 22:04 . 2008-02-13 17:52 196,608 --------- C:\WINDOWS\admggxp.dll
2008-02-13 21:09 . 2008-02-13 21:09 39,963 --a------ C:\WINDOWS\system32\diperto.ini
2008-01-23 09:52 . 2008-01-23 09:52 <REP> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-22 07:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-02-17 14:39 --------- d-----w C:\Documents and Settings\mathieu\Application Data\AdobeUM
2008-02-17 14:26 --------- d-----w C:\Program Files\USB Disk Win98 Driver
2008-02-16 13:59 --------- d-----w C:\Program Files\Norton AntiVirus
2008-02-16 13:58 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-02-16 13:58 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-02-16 13:58 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-02-16 13:58 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-02-16 13:58 --------- d-----w C:\Program Files\Symantec
2008-02-16 13:58 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-02-16 13:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-09 08:59 --------- d-----w C:\Program Files\MinitelADSL
2008-01-10 17:00 --------- d-----w C:\Program Files\LG Electronics
2008-01-10 16:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-10 16:56 --------- d-----w C:\Program Files\LG PC Suite
2007-12-07 02:08 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:41 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-03-10 15:47 251 ----a-w C:\Program Files\wt3d.ini
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 21:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-07 12:14 68856]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [ ]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2007-01-23 08:06 204843]
"updateMgr"="c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 15:45 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-27 23:47 7573504]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2007-01-18 00:21 115816]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-08-04 12:45 155648]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 21:00 15360]
C:\Documents and Settings\elisa\Menu D‚marrer\Programmes\D‚marrage\
SM.lnk - C:\Program Files\SM\skymessnet.exe [2007-03-28 14:43:42 581632]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Acer Empowering Technology.lnk - C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe [2007-01-02 15:14:00 45056]
Acer WLAN 11g USB Dongle.lnk - C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe [2005-11-16 19:25:14 745472]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26 29696]
Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-11-27 11:00:14 126136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"admggxp"= {F97F2DC4-5D55-4E5B-9A42-82FAD914A692} - C:\WINDOWS\admggxp.dll [2008-02-13 17:52 196608]
R0 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys [2004-12-17 03:14]
R2 Planificateur LiveUpdate automatique;Planificateur LiveUpdate automatique;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2007-09-26 10:56]
S3 int15.sys;int15.sys;C:\Acer\Empowering Technology\eRecovery\int15.sys [2005-01-13 14:46]
S3 psdfilter;psdfilter;C:\WINDOWS\system32\Drivers\psdfilter.sys [2006-04-07 20:17]
S3 psdvdisk;psdvdisk;C:\WINDOWS\system32\Drivers\psdvdisk.sys [2006-03-08 17:10]
S3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2005-10-28 10:38]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{124f6789-a4b0-11db-9516-0030da3f28ef}]
\Shell\AutoRun\command - wscript.exe VirusRemoval.vbs
\Shell\open\Command - wscript.exe VirusRemoval.vbs
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-02-11 20:07:24 C:\WINDOWS\Tasks\Norton AntiVirus Online - Analyse système complète - christine.job"
- C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-22 13:53:30
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-02-22 13:53:56
ComboFix-quarantined-files.txt 2008-02-22 12:53:53
ComboFix2.txt 2008-02-20 18:29:29
ComboFix3.txt 2008-02-18 18:25:05
ComboFix4.txt 2008-02-18 18:12:31
.
2008-02-14 09:19:39 --- E O F ---
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1435 [GMT 1:00]
Endroit: C:\Documents and Settings\christine\Mes documents\ComboFix.exe
Command switches used :: C:\Documents and Settings\christine\Mes documents\CFScript.txt
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\am‚lie\Bureau\Error Cleaner.url
C:\Documents and Settings\am‚lie\Bureau\Privacy Protector.url
C:\Documents and Settings\amélie\Bureau\Spyware&Malware Protection.url
C:\Documents and Settings\amélie\Favoris\Error Cleaner.url
C:\Documents and Settings\amélie\Favoris\Privacy Protector.url
C:\Documents and Settings\amélie\Favoris\Spyware&Malware Protection.url
C:\Documents and Settings\christine\Bureau\Error Cleaner.url
C:\Documents and Settings\christine\Bureau\Privacy Protector.url
C:\Documents and Settings\christine\Bureau\Spyware&Malware Protection.url
C:\Documents and Settings\christine\Favoris\Error Cleaner.url
C:\Documents and Settings\christine\Favoris\Privacy Protector.url
C:\Documents and Settings\christine\Favoris\Spyware&Malware Protection.url
C:\Documents and Settings\mathieu\Bureau\Error Cleaner.url
C:\Documents and Settings\mathieu\Bureau\Privacy Protector.url
C:\Documents and Settings\mathieu\Bureau\Spyware&Malware Protection.url
C:\Documents and Settings\mathieu\Favoris\Error Cleaner.url
C:\Documents and Settings\mathieu\Favoris\Privacy Protector.url
C:\Documents and Settings\mathieu\Favoris\Spyware&Malware Protection.url
C:\Program Files\MediaAccumulativeCodec
C:\Program Files\MediaAccumulativeCodec\install.ico
C:\Program Files\MediaAccumulativeCodec\MediaAccumulativeCodec.ocx
C:\Program Files\MediaAccumulativeCodec\Uninstall.exe
C:\WINDOWS\dat.txt
C:\WINDOWS\rs.txt
C:\WINDOWS\search_res.txt
----- BITS: Possible sites infectés -----
hxxp://softworldnetwork.com
hxxp://onsafepro.com
.
((((((((((((((((((((((((((((( Fichiers créés 2008-01-22 to 2008-02-22 ))))))))))))))))))))))))))))))))))))
.
2008-02-22 10:31 . 2008-02-22 10:31 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-22 10:31 . 2008-02-22 10:31 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-18 17:11 . 2008-02-18 17:11 <REP> d-------- C:\Documents and Settings\christine\Application Data\Symantec
2008-02-18 13:01 . 2008-02-18 13:01 <REP> d-------- C:\Program Files\CCleaner
2008-02-17 15:40 . 2008-01-10 15:57 2,421,312 --a------ C:\Documents and Settings\mathieu\Application Data.exe
2008-02-17 15:18 . 2008-02-18 19:04 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-17 15:16 . 2008-02-18 18:30 <REP> d-------- C:\Program Files\Trojan Remover
2008-02-17 15:16 . 2008-02-17 15:16 <REP> d-------- C:\Documents and Settings\christine\Application Data\Simply Super Software
2008-02-17 15:16 . 2008-02-17 15:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
2008-02-17 15:16 . 2006-05-25 14:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2008-02-17 15:16 . 2003-02-02 19:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2008-02-17 15:16 . 2005-08-26 00:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2008-02-17 15:16 . 2002-03-06 00:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-02-17 15:16 . 2006-06-19 12:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
2008-02-13 22:04 . 2008-02-13 17:52 258,048 --------- C:\WINDOWS\dmdqdrxodn.dll
2008-02-13 22:04 . 2008-02-13 17:52 217,088 --------- C:\WINDOWS\bdmnopx.dll
2008-02-13 22:04 . 2008-02-13 17:52 196,608 --------- C:\WINDOWS\admggxp.dll
2008-02-13 21:09 . 2008-02-13 21:09 39,963 --a------ C:\WINDOWS\system32\diperto.ini
2008-01-23 09:52 . 2008-01-23 09:52 <REP> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-22 07:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-02-17 14:39 --------- d-----w C:\Documents and Settings\mathieu\Application Data\AdobeUM
2008-02-17 14:26 --------- d-----w C:\Program Files\USB Disk Win98 Driver
2008-02-16 13:59 --------- d-----w C:\Program Files\Norton AntiVirus
2008-02-16 13:58 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-02-16 13:58 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-02-16 13:58 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-02-16 13:58 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-02-16 13:58 --------- d-----w C:\Program Files\Symantec
2008-02-16 13:58 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-02-16 13:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-09 08:59 --------- d-----w C:\Program Files\MinitelADSL
2008-01-10 17:00 --------- d-----w C:\Program Files\LG Electronics
2008-01-10 16:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-10 16:56 --------- d-----w C:\Program Files\LG PC Suite
2007-12-07 02:08 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:41 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-03-10 15:47 251 ----a-w C:\Program Files\wt3d.ini
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 21:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-07 12:14 68856]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [ ]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2007-01-23 08:06 204843]
"updateMgr"="c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 15:45 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-27 23:47 7573504]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2007-01-18 00:21 115816]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-08-04 12:45 155648]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 21:00 15360]
C:\Documents and Settings\elisa\Menu D‚marrer\Programmes\D‚marrage\
SM.lnk - C:\Program Files\SM\skymessnet.exe [2007-03-28 14:43:42 581632]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Acer Empowering Technology.lnk - C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe [2007-01-02 15:14:00 45056]
Acer WLAN 11g USB Dongle.lnk - C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe [2005-11-16 19:25:14 745472]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26 29696]
Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-11-27 11:00:14 126136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"admggxp"= {F97F2DC4-5D55-4E5B-9A42-82FAD914A692} - C:\WINDOWS\admggxp.dll [2008-02-13 17:52 196608]
R0 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys [2004-12-17 03:14]
R2 Planificateur LiveUpdate automatique;Planificateur LiveUpdate automatique;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2007-09-26 10:56]
S3 int15.sys;int15.sys;C:\Acer\Empowering Technology\eRecovery\int15.sys [2005-01-13 14:46]
S3 psdfilter;psdfilter;C:\WINDOWS\system32\Drivers\psdfilter.sys [2006-04-07 20:17]
S3 psdvdisk;psdvdisk;C:\WINDOWS\system32\Drivers\psdvdisk.sys [2006-03-08 17:10]
S3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2005-10-28 10:38]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{124f6789-a4b0-11db-9516-0030da3f28ef}]
\Shell\AutoRun\command - wscript.exe VirusRemoval.vbs
\Shell\open\Command - wscript.exe VirusRemoval.vbs
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-02-11 20:07:24 C:\WINDOWS\Tasks\Norton AntiVirus Online - Analyse système complète - christine.job"
- C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-22 13:53:30
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-02-22 13:53:56
ComboFix-quarantined-files.txt 2008-02-22 12:53:53
ComboFix2.txt 2008-02-20 18:29:29
ComboFix3.txt 2008-02-18 18:25:05
ComboFix4.txt 2008-02-18 18:12:31
.
2008-02-14 09:19:39 --- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:28:32, on 22/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\PROGRA~1\INCRED~1\bin\IncMail.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\Répertoire temporaire 1 pour HiJackThis.zip\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*http://fr.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: SXG Advisor - {DC4BF2E8-EA1E-4826-A0DA-E02ED1C0156A} - C:\WINDOWS\dmdqdrxodn.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [updateMgr] c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Acer Empowering Technology.lnk = ?
O4 - Global Startup: Acer WLAN 11g USB Dongle.lnk = C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall....
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by126w.bay126.mail.live.com/mail/resources/MsnPU...
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.ca...
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab569...
O17 - HKLM\System\CCS\Services\Tcpip\..\{9899DC21-CCBC-423F-A4D2-64B5084FF2E2}: NameServer = 192.168.3.1
O21 - SSODL: admggxp - {F97F2DC4-5D55-4E5B-9A42-82FAD914A692} - C:\WINDOWS\admggxp.dll
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
--
End of file - 10027 bytes
Scan saved at 14:28:32, on 22/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\PROGRA~1\INCRED~1\bin\IncMail.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\Répertoire temporaire 1 pour HiJackThis.zip\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*http://fr.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: SXG Advisor - {DC4BF2E8-EA1E-4826-A0DA-E02ED1C0156A} - C:\WINDOWS\dmdqdrxodn.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [updateMgr] c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Acer Empowering Technology.lnk = ?
O4 - Global Startup: Acer WLAN 11g USB Dongle.lnk = C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall....
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by126w.bay126.mail.live.com/mail/resources/MsnPU...
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.ca...
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab569...
O17 - HKLM\System\CCS\Services\Tcpip\..\{9899DC21-CCBC-423F-A4D2-64B5084FF2E2}: NameServer = 192.168.3.1
O21 - SSODL: admggxp - {F97F2DC4-5D55-4E5B-9A42-82FAD914A692} - C:\WINDOWS\admggxp.dll
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
--
End of file - 10027 bytes
j'ai encore ce genre de truc qui s'affiche en cours de route :
Centre de sécurité de PC
Aide à protéger votre ordinateur
Ressources
Comment réparer
Erreurs du registre Windows
Comment assurer
La perte des données physiques
Menaces au systèmes sévères détectées sur votre ordinateur!
Les menaces au système suivantes ont été trouvées sur votre PC. Elles peuvent causer les pertes de données ou les pannes du système:
DESCRIPTION DU PROBLEME NIVEAU DE RISQUE
Clés du registre des données perdues haut
Les fichiers endommagés des Documents et paramètres moyen
Pour réparer les erreurs trouvées, veuillez cliquer ici pour télécharger le logiciel supplémentaire....
Centre de sécurité de PC. Aide à protéger votre ordinateur. Comment éviter les erreurs du système?
Centre de sécurité de PC
Aide à protéger votre ordinateur
Ressources
Comment réparer
Erreurs du registre Windows
Comment assurer
La perte des données physiques
Menaces au systèmes sévères détectées sur votre ordinateur!
Les menaces au système suivantes ont été trouvées sur votre PC. Elles peuvent causer les pertes de données ou les pannes du système:
DESCRIPTION DU PROBLEME NIVEAU DE RISQUE
Clés du registre des données perdues haut
Les fichiers endommagés des Documents et paramètres moyen
Pour réparer les erreurs trouvées, veuillez cliquer ici pour télécharger le logiciel supplémentaire....
Centre de sécurité de PC. Aide à protéger votre ordinateur. Comment éviter les erreurs du système?
omboFix 08-02-18.1 - christine 2008-02-23 14:20:06.6 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1571 [GMT 1:00]
Endroit: C:\Documents and Settings\christine\Mes documents\ComboFix.exe
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\am‚lie\Bureau\Error Cleaner.url
C:\Documents and Settings\am‚lie\Bureau\Privacy Protector.url
C:\WINDOWS\dat.txt
C:\WINDOWS\search_res.txt
----- BITS: Possible sites infectés -----
hxxp://softworldnetwork.com
.
((((((((((((((((((((((((((((( Fichiers créés 2008-01-23 to 2008-02-23 ))))))))))))))))))))))))))))))))))))
.
2008-02-23 10:16 . 2008-02-23 10:16 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-02-22 10:31 . 2008-02-23 09:27 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-22 10:31 . 2008-02-22 10:31 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-18 17:11 . 2008-02-18 17:11 <REP> d-------- C:\Documents and Settings\christine\Application Data\Symantec
2008-02-18 13:01 . 2008-02-18 13:01 <REP> d-------- C:\Program Files\CCleaner
2008-02-17 15:40 . 2008-01-10 15:57 2,421,312 --a------ C:\Documents and Settings\mathieu\Application Data.exe
2008-02-17 15:18 . 2008-02-18 19:04 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-17 15:16 . 2008-02-18 18:30 <REP> d-------- C:\Program Files\Trojan Remover
2008-02-17 15:16 . 2008-02-17 15:16 <REP> d-------- C:\Documents and Settings\christine\Application Data\Simply Super Software
2008-02-17 15:16 . 2008-02-17 15:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
2008-02-17 15:16 . 2006-05-25 14:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2008-02-17 15:16 . 2003-02-02 19:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2008-02-17 15:16 . 2005-08-26 00:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2008-02-17 15:16 . 2002-03-06 00:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-02-17 15:16 . 2006-06-19 12:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
2008-02-13 22:04 . 2008-02-13 17:52 258,048 --------- C:\WINDOWS\dmdqdrxodn.dll
2008-02-13 22:04 . 2008-02-13 17:52 217,088 --------- C:\WINDOWS\bdmnopx.dll
2008-02-13 22:04 . 2008-02-13 17:52 196,608 --------- C:\WINDOWS\admggxp.dll
2008-02-13 21:09 . 2008-02-13 21:09 39,963 --a------ C:\WINDOWS\system32\diperto.ini
2008-01-23 09:52 . 2008-01-23 09:52 <REP> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-23 11:07 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-02-23 09:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-02-23 09:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-17 14:39 --------- d-----w C:\Documents and Settings\mathieu\Application Data\AdobeUM
2008-02-17 14:26 --------- d-----w C:\Program Files\USB Disk Win98 Driver
2008-02-16 13:59 --------- d-----w C:\Program Files\Norton AntiVirus
2008-02-16 13:58 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-02-16 13:58 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-02-16 13:58 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-02-16 13:58 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-02-16 13:58 --------- d-----w C:\Program Files\Symantec
2008-02-16 13:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-09 08:59 --------- d-----w C:\Program Files\MinitelADSL
2008-01-10 17:00 --------- d-----w C:\Program Files\LG Electronics
2008-01-10 16:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-10 16:56 --------- d-----w C:\Program Files\LG PC Suite
2007-12-07 02:08 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:41 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-03-10 15:47 251 ----a-w C:\Program Files\wt3d.ini
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DC4BF2E8-EA1E-4826-A0DA-E02ED1C0156A}]
2008-02-13 17:52 258048 --------- C:\WINDOWS\dmdqdrxodn.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 21:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-07 12:14 68856]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [ ]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2007-01-23 08:06 204843]
"updateMgr"="c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 15:45 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-27 23:47 7573504]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2007-01-18 00:21 115816]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-08-04 12:45 155648]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 21:00 15360]
C:\Documents and Settings\elisa\Menu D‚marrer\Programmes\D‚marrage\
SM.lnk - C:\Program Files\SM\skymessnet.exe [2007-03-28 14:43:42 581632]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Acer Empowering Technology.lnk - C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe [2007-01-02 15:14:00 45056]
Acer WLAN 11g USB Dongle.lnk - C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe [2005-11-16 19:25:14 745472]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26 29696]
Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-11-27 11:00:14 126136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"admggxp"= {F97F2DC4-5D55-4E5B-9A42-82FAD914A692} - C:\WINDOWS\admggxp.dll [2008-02-13 17:52 196608]
R0 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys [2004-12-17 03:14]
R2 Planificateur LiveUpdate automatique;Planificateur LiveUpdate automatique;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2007-09-26 10:56]
S3 int15.sys;int15.sys;C:\Acer\Empowering Technology\eRecovery\int15.sys [2005-01-13 14:46]
S3 psdfilter;psdfilter;C:\WINDOWS\system32\Drivers\psdfilter.sys [2006-04-07 20:17]
S3 psdvdisk;psdvdisk;C:\WINDOWS\system32\Drivers\psdvdisk.sys [2006-03-08 17:10]
S3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2005-10-28 10:38]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{124f6789-a4b0-11db-9516-0030da3f28ef}]
\Shell\AutoRun\command - wscript.exe VirusRemoval.vbs
\Shell\open\Command - wscript.exe VirusRemoval.vbs
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-02-11 20:07:24 C:\WINDOWS\Tasks\Norton AntiVirus Online - Analyse système complète - christine.job"
- C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-23 14:21:34
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-02-23 14:22:00
ComboFix-quarantined-files.txt 2008-02-23 13:21:58
ComboFix2.txt 2008-02-23 13:09:44
ComboFix3.txt 2008-02-22 12:53:56
ComboFix4.txt 2008-02-20 18:29:29
ComboFix5.txt 2008-02-18 18:25:05
.
2008-02-14 09:19:39 --- E O F ---
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1571 [GMT 1:00]
Endroit: C:\Documents and Settings\christine\Mes documents\ComboFix.exe
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\am‚lie\Bureau\Error Cleaner.url
C:\Documents and Settings\am‚lie\Bureau\Privacy Protector.url
C:\WINDOWS\dat.txt
C:\WINDOWS\search_res.txt
----- BITS: Possible sites infectés -----
hxxp://softworldnetwork.com
.
((((((((((((((((((((((((((((( Fichiers créés 2008-01-23 to 2008-02-23 ))))))))))))))))))))))))))))))))))))
.
2008-02-23 10:16 . 2008-02-23 10:16 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-02-22 10:31 . 2008-02-23 09:27 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-22 10:31 . 2008-02-22 10:31 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-18 17:11 . 2008-02-18 17:11 <REP> d-------- C:\Documents and Settings\christine\Application Data\Symantec
2008-02-18 13:01 . 2008-02-18 13:01 <REP> d-------- C:\Program Files\CCleaner
2008-02-17 15:40 . 2008-01-10 15:57 2,421,312 --a------ C:\Documents and Settings\mathieu\Application Data.exe
2008-02-17 15:18 . 2008-02-18 19:04 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-17 15:16 . 2008-02-18 18:30 <REP> d-------- C:\Program Files\Trojan Remover
2008-02-17 15:16 . 2008-02-17 15:16 <REP> d-------- C:\Documents and Settings\christine\Application Data\Simply Super Software
2008-02-17 15:16 . 2008-02-17 15:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
2008-02-17 15:16 . 2006-05-25 14:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2008-02-17 15:16 . 2003-02-02 19:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2008-02-17 15:16 . 2005-08-26 00:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2008-02-17 15:16 . 2002-03-06 00:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-02-17 15:16 . 2006-06-19 12:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
2008-02-13 22:04 . 2008-02-13 17:52 258,048 --------- C:\WINDOWS\dmdqdrxodn.dll
2008-02-13 22:04 . 2008-02-13 17:52 217,088 --------- C:\WINDOWS\bdmnopx.dll
2008-02-13 22:04 . 2008-02-13 17:52 196,608 --------- C:\WINDOWS\admggxp.dll
2008-02-13 21:09 . 2008-02-13 21:09 39,963 --a------ C:\WINDOWS\system32\diperto.ini
2008-01-23 09:52 . 2008-01-23 09:52 <REP> d-------- C:\Documents and Settings\All Users\Application Data\nView_Profiles
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-23 11:07 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-02-23 09:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-02-23 09:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-17 14:39 --------- d-----w C:\Documents and Settings\mathieu\Application Data\AdobeUM
2008-02-17 14:26 --------- d-----w C:\Program Files\USB Disk Win98 Driver
2008-02-16 13:59 --------- d-----w C:\Program Files\Norton AntiVirus
2008-02-16 13:58 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-02-16 13:58 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-02-16 13:58 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-02-16 13:58 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-02-16 13:58 --------- d-----w C:\Program Files\Symantec
2008-02-16 13:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-02-09 08:59 --------- d-----w C:\Program Files\MinitelADSL
2008-01-10 17:00 --------- d-----w C:\Program Files\LG Electronics
2008-01-10 16:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-10 16:56 --------- d-----w C:\Program Files\LG PC Suite
2007-12-07 02:08 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:41 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-03-10 15:47 251 ----a-w C:\Program Files\wt3d.ini
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DC4BF2E8-EA1E-4826-A0DA-E02ED1C0156A}]
2008-02-13 17:52 258048 --------- C:\WINDOWS\dmdqdrxodn.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 21:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-07 12:14 68856]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [ ]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2007-01-23 08:06 204843]
"updateMgr"="c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 15:45 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-27 23:47 7573504]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2007-01-18 00:21 115816]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-08-04 12:45 155648]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 21:00 15360]
C:\Documents and Settings\elisa\Menu D‚marrer\Programmes\D‚marrage\
SM.lnk - C:\Program Files\SM\skymessnet.exe [2007-03-28 14:43:42 581632]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Acer Empowering Technology.lnk - C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe [2007-01-02 15:14:00 45056]
Acer WLAN 11g USB Dongle.lnk - C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe [2005-11-16 19:25:14 745472]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26 29696]
Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-11-27 11:00:14 126136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"admggxp"= {F97F2DC4-5D55-4E5B-9A42-82FAD914A692} - C:\WINDOWS\admggxp.dll [2008-02-13 17:52 196608]
R0 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys [2004-12-17 03:14]
R2 Planificateur LiveUpdate automatique;Planificateur LiveUpdate automatique;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2007-09-26 10:56]
S3 int15.sys;int15.sys;C:\Acer\Empowering Technology\eRecovery\int15.sys [2005-01-13 14:46]
S3 psdfilter;psdfilter;C:\WINDOWS\system32\Drivers\psdfilter.sys [2006-04-07 20:17]
S3 psdvdisk;psdvdisk;C:\WINDOWS\system32\Drivers\psdvdisk.sys [2006-03-08 17:10]
S3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2005-10-28 10:38]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{124f6789-a4b0-11db-9516-0030da3f28ef}]
\Shell\AutoRun\command - wscript.exe VirusRemoval.vbs
\Shell\open\Command - wscript.exe VirusRemoval.vbs
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-02-11 20:07:24 C:\WINDOWS\Tasks\Norton AntiVirus Online - Analyse système complète - christine.job"
- C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-23 14:21:34
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-02-23 14:22:00
ComboFix-quarantined-files.txt 2008-02-23 13:21:58
ComboFix2.txt 2008-02-23 13:09:44
ComboFix3.txt 2008-02-22 12:53:56
ComboFix4.txt 2008-02-20 18:29:29
ComboFix5.txt 2008-02-18 18:25:05
.
2008-02-14 09:19:39 --- E O F ---
Re,
[#ff0000]Désactive tes protections résidentes (antivirus...) ![/#f]
Copie (Ctrl+C) le texte se situant dans le cadre ci-dessous :
Ouvre le Bloc-Notes puis colle (Ctrl+V) le texte précedemment copié.
Sauvegarde ce fichier sous le nom de CFScript.txt.
Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :
![]()
Cela va relancer Combofix, tape sur 1 puis valide. Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.
[#ff0000]NOTE : S'il n'y a pas de rédémarrage, poste quand même les rapports demandés.[/#f]
[#ff0000]Désactive tes protections résidentes (antivirus...) ![/#f]
Copie (Ctrl+C) le texte se situant dans le cadre ci-dessous :
File::
C:\WINDOWS\dmdqdrxodn.dll
C:\WINDOWS\bdmnopx.dll
C:\WINDOWS\admggxp.dll
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DC4BF2E8-EA1E-4826-A0DA-E02ED1C0156A}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"admggxp"=-
C:\WINDOWS\dmdqdrxodn.dll
C:\WINDOWS\bdmnopx.dll
C:\WINDOWS\admggxp.dll
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DC4BF2E8-EA1E-4826-A0DA-E02ED1C0156A}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"admggxp"=-
Ouvre le Bloc-Notes puis colle (Ctrl+V) le texte précedemment copié.
Sauvegarde ce fichier sous le nom de CFScript.txt.
Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :

Cela va relancer Combofix, tape sur 1 puis valide. Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.
[#ff0000]NOTE : S'il n'y a pas de rédémarrage, poste quand même les rapports demandés.[/#f]
ComboFix 08-02-18.1 - christine 2008-02-25 10:32:20.7 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1552 [GMT 1:00]Endroit: C:\Documents and Settings\christine\Mes documents\ComboFix.exe
Command switches used :: C:\Documents and Settings\christine\Mes documents\CFScript.txt
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
FILE ::
C:\WINDOWS\admggxp.dll
C:\WINDOWS\bdmnopx.dll
C:\WINDOWS\dmdqdrxodn.dll
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\am‚lie\Bureau\Error Cleaner.url
C:\Documents and Settings\am‚lie\Bureau\Privacy Protector.url
C:\WINDOWS\admggxp.dll
C:\WINDOWS\bdmnopx.dll
C:\WINDOWS\dat.txt
C:\WINDOWS\dmdqdrxodn.dll
C:\WINDOWS\rs.txt
C:\WINDOWS\search_res.txt
----- BITS: Possible sites infectés -----
hxxp://softworldnetwork.com
hxxp://onsafepro.com
.
((((((((((((((((((((((((((((( Fichiers créés 2008-01-25 to 2008-02-25 ))))))))))))))))))))))))))))))))))))
.
2008-02-23 10:16 . 2008-02-23 10:16 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-02-22 10:31 . 2008-02-23 14:33 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-22 10:31 . 2008-02-22 10:31 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-18 17:11 . 2008-02-18 17:11 <REP> d-------- C:\Documents and Settings\christine\Application Data\Symantec
2008-02-18 13:01 . 2008-02-18 13:01 <REP> d-------- C:\Program Files\CCleaner
2008-02-17 15:40 . 2008-01-10 15:57 2,421,312 --a------ C:\Documents and Settings\mathieu\Application Data.exe
2008-02-17 15:18 . 2008-02-18 19:04 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-17 15:16 . 2008-02-18 18:30 <REP> d-------- C:\Program Files\Trojan Remover
2008-02-17 15:16 . 2008-02-17 15:16 <REP> d-------- C:\Documents and Settings\christine\Application Data\Simply Super Software
2008-02-17 15:16 . 2008-02-17 15:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
2008-02-17 15:16 . 2006-05-25 14:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2008-02-17 15:16 . 2003-02-02 19:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2008-02-17 15:16 . 2005-08-26 00:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2008-02-17 15:16 . 2002-03-06 00:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-02-17 15:16 . 2006-06-19 12:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
2008-02-13 21:09 . 2008-02-13 21:09 39,963 --a------ C:\WINDOWS\system32\diperto.ini
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-24 20:06 --------- d-----w C:\Program Files\MinitelADSL
2008-02-24 19:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-02-23 11:07 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-02-23 09:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-17 14:39 --------- d-----w C:\Documents and Settings\mathieu\Application Data\AdobeUM
2008-02-17 14:26 --------- d-----w C:\Program Files\USB Disk Win98 Driver
2008-02-16 13:59 --------- d-----w C:\Program Files\Norton AntiVirus
2008-02-16 13:58 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-02-16 13:58 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-02-16 13:58 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-02-16 13:58 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-02-16 13:58 --------- d-----w C:\Program Files\Symantec
2008-02-16 13:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-23 08:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-01-10 17:00 --------- d-----w C:\Program Files\LG Electronics
2008-01-10 16:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-10 16:56 --------- d-----w C:\Program Files\LG PC Suite
2007-12-07 02:08 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:41 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-03-10 15:47 251 ----a-w C:\Program Files\wt3d.ini
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 21:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-07 12:14 68856]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [ ]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2007-01-23 08:06 204843]
"updateMgr"="c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 15:45 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-27 23:47 7573504]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2007-01-18 00:21 115816]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-08-04 12:45 155648]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 21:00 15360]
C:\Documents and Settings\elisa\Menu D‚marrer\Programmes\D‚marrage\
SM.lnk - C:\Program Files\SM\skymessnet.exe [2007-03-28 14:43:42 581632]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Acer Empowering Technology.lnk - C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe [2007-01-02 15:14:00 45056]
Acer WLAN 11g USB Dongle.lnk - C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe [2005-11-16 19:25:14 745472]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26 29696]
Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-11-27 11:00:14 126136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
R0 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys [2004-12-17 03:14]
R2 Planificateur LiveUpdate automatique;Planificateur LiveUpdate automatique;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2007-09-26 10:56]
S3 int15.sys;int15.sys;C:\Acer\Empowering Technology\eRecovery\int15.sys [2005-01-13 14:46]
S3 psdfilter;psdfilter;C:\WINDOWS\system32\Drivers\psdfilter.sys [2006-04-07 20:17]
S3 psdvdisk;psdvdisk;C:\WINDOWS\system32\Drivers\psdvdisk.sys [2006-03-08 17:10]
S3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2005-10-28 10:38]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{124f6789-a4b0-11db-9516-0030da3f28ef}]
\Shell\AutoRun\command - wscript.exe VirusRemoval.vbs
\Shell\open\Command - wscript.exe VirusRemoval.vbs
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-02-11 20:07:24 C:\WINDOWS\Tasks\Norton AntiVirus Online - Analyse système complète - christine.job"
- C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-25 10:35:16
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-02-25 10:35:40
ComboFix-quarantined-files.txt 2008-02-25 09:35:38
ComboFix2.txt 2008-02-23 13:22:00
ComboFix3.txt 2008-02-23 13:09:44
ComboFix4.txt 2008-02-22 12:53:56
ComboFix5.txt 2008-02-20 18:29:29
.
2008-02-14 09:19:39 --- E O F ---
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1552 [GMT 1:00]Endroit: C:\Documents and Settings\christine\Mes documents\ComboFix.exe
Command switches used :: C:\Documents and Settings\christine\Mes documents\CFScript.txt
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
FILE ::
C:\WINDOWS\admggxp.dll
C:\WINDOWS\bdmnopx.dll
C:\WINDOWS\dmdqdrxodn.dll
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\am‚lie\Bureau\Error Cleaner.url
C:\Documents and Settings\am‚lie\Bureau\Privacy Protector.url
C:\WINDOWS\admggxp.dll
C:\WINDOWS\bdmnopx.dll
C:\WINDOWS\dat.txt
C:\WINDOWS\dmdqdrxodn.dll
C:\WINDOWS\rs.txt
C:\WINDOWS\search_res.txt
----- BITS: Possible sites infectés -----
hxxp://softworldnetwork.com
hxxp://onsafepro.com
.
((((((((((((((((((((((((((((( Fichiers créés 2008-01-25 to 2008-02-25 ))))))))))))))))))))))))))))))))))))
.
2008-02-23 10:16 . 2008-02-23 10:16 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-02-22 10:31 . 2008-02-23 14:33 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-22 10:31 . 2008-02-22 10:31 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-18 17:11 . 2008-02-18 17:11 <REP> d-------- C:\Documents and Settings\christine\Application Data\Symantec
2008-02-18 13:01 . 2008-02-18 13:01 <REP> d-------- C:\Program Files\CCleaner
2008-02-17 15:40 . 2008-01-10 15:57 2,421,312 --a------ C:\Documents and Settings\mathieu\Application Data.exe
2008-02-17 15:18 . 2008-02-18 19:04 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-17 15:16 . 2008-02-18 18:30 <REP> d-------- C:\Program Files\Trojan Remover
2008-02-17 15:16 . 2008-02-17 15:16 <REP> d-------- C:\Documents and Settings\christine\Application Data\Simply Super Software
2008-02-17 15:16 . 2008-02-17 15:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Simply Super Software
2008-02-17 15:16 . 2006-05-25 14:52 162,304 --a------ C:\WINDOWS\system32\ztvunrar36.dll
2008-02-17 15:16 . 2003-02-02 19:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2008-02-17 15:16 . 2005-08-26 00:50 77,312 --a------ C:\WINDOWS\system32\ztvunace26.dll
2008-02-17 15:16 . 2002-03-06 00:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-02-17 15:16 . 2006-06-19 12:01 69,632 --a------ C:\WINDOWS\system32\ztvcabinet.dll
2008-02-13 21:09 . 2008-02-13 21:09 39,963 --a------ C:\WINDOWS\system32\diperto.ini
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-24 20:06 --------- d-----w C:\Program Files\MinitelADSL
2008-02-24 19:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-02-23 11:07 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-02-23 09:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-17 14:39 --------- d-----w C:\Documents and Settings\mathieu\Application Data\AdobeUM
2008-02-17 14:26 --------- d-----w C:\Program Files\USB Disk Win98 Driver
2008-02-16 13:59 --------- d-----w C:\Program Files\Norton AntiVirus
2008-02-16 13:58 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-02-16 13:58 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-02-16 13:58 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-02-16 13:58 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-02-16 13:58 --------- d-----w C:\Program Files\Symantec
2008-02-16 13:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-01-23 08:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2008-01-10 17:00 --------- d-----w C:\Program Files\LG Electronics
2008-01-10 16:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-10 16:56 --------- d-----w C:\Program Files\LG PC Suite
2007-12-07 02:08 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-04 18:41 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-03-10 15:47 251 ----a-w C:\Program Files\wt3d.ini
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 21:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-07 12:14 68856]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [ ]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2007-01-23 08:06 204843]
"updateMgr"="c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 15:45 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-27 23:47 7573504]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2007-01-18 00:21 115816]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-08-04 12:45 155648]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 21:00 15360]
C:\Documents and Settings\elisa\Menu D‚marrer\Programmes\D‚marrage\
SM.lnk - C:\Program Files\SM\skymessnet.exe [2007-03-28 14:43:42 581632]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Acer Empowering Technology.lnk - C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe [2007-01-02 15:14:00 45056]
Acer WLAN 11g USB Dongle.lnk - C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe [2005-11-16 19:25:14 745472]
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26 29696]
Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-11-27 11:00:14 126136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
R0 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys [2004-12-17 03:14]
R2 Planificateur LiveUpdate automatique;Planificateur LiveUpdate automatique;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" [2007-09-26 10:56]
S3 int15.sys;int15.sys;C:\Acer\Empowering Technology\eRecovery\int15.sys [2005-01-13 14:46]
S3 psdfilter;psdfilter;C:\WINDOWS\system32\Drivers\psdfilter.sys [2006-04-07 20:17]
S3 psdvdisk;psdvdisk;C:\WINDOWS\system32\Drivers\psdvdisk.sys [2006-03-08 17:10]
S3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS);C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys [2005-10-28 10:38]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{124f6789-a4b0-11db-9516-0030da3f28ef}]
\Shell\AutoRun\command - wscript.exe VirusRemoval.vbs
\Shell\open\Command - wscript.exe VirusRemoval.vbs
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-02-11 20:07:24 C:\WINDOWS\Tasks\Norton AntiVirus Online - Analyse système complète - christine.job"
- C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-25 10:35:16
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-02-25 10:35:40
ComboFix-quarantined-files.txt 2008-02-25 09:35:38
ComboFix2.txt 2008-02-23 13:22:00
ComboFix3.txt 2008-02-23 13:09:44
ComboFix4.txt 2008-02-22 12:53:56
ComboFix5.txt 2008-02-20 18:29:29
.
2008-02-14 09:19:39 --- E O F ---
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:46:43, on 25/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32Info.exe
C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\Répertoire temporaire 1 pour HiJackThis.zip\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*http://fr.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [updateMgr] c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Acer Empowering Technology.lnk = ?
O4 - Global Startup: Acer WLAN 11g USB Dongle.lnk = C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall....
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by126w.bay126.mail.live.com/mail/resources/MsnPU...
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.ca...
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab569...
O17 - HKLM\System\CCS\Services\Tcpip\..\{9899DC21-CCBC-423F-A4D2-64B5084FF2E2}: NameServer = 192.168.3.1
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
--
End of file - 9627 bytes
Scan saved at 10:46:43, on 25/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32Info.exe
C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\Répertoire temporaire 1 pour HiJackThis.zip\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*http://fr.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [updateMgr] c:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Acer Empowering Technology.lnk = ?
O4 - Global Startup: Acer WLAN 11g USB Dongle.lnk = C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall....
O16 - DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} (France Telecom MDM ActiveX Control) - http://minitelweb.minitel.com/imin_data/ocx/MDM.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by126w.bay126.mail.live.com/mail/resources/MsnPU...
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.ca...
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPACl...
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab569...
O17 - HKLM\System\CCS\Services\Tcpip\..\{9899DC21-CCBC-423F-A4D2-64B5084FF2E2}: NameServer = 192.168.3.1
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
--
End of file - 9627 bytes
Lassé par la pub ? Créez un compte
- Contenus similaires :
Tags :
- ForumAcer empowering technology download
- ForumDownload acer empowering technology
- ForumAcer empowering technology xp
- ForumAcer empowering technology vista
- ForumAcer empowering technology télécharger
- ForumLogiciel acer empowering technology
- ForumEmpowering technology acer
- ForumProbleme acer empowering technology
- ForumTelecharger empowering technology pour acer
- ForumHijackthis windows genuine
- Voir plus
Toujours présent ?