Fichier xpdx inexistant [Résolu]
Dernière réponse : dans Sécurité
Bonsoir,
apparemment j'ai pas posté où il fallait la première fois, alors je recommence.
J'ai un fichier xpdx détecté par Spybot, mais quand je veux le supprimer, le fichier est inexistant. De plus, mon PC semble être en activité quasi permanente, même si je n'y fais rien...
Que puis-je faire pour résoudre ces problèmes?
apparemment j'ai pas posté où il fallait la première fois, alors je recommence.
J'ai un fichier xpdx détecté par Spybot, mais quand je veux le supprimer, le fichier est inexistant. De plus, mon PC semble être en activité quasi permanente, même si je n'y fais rien...
Que puis-je faire pour résoudre ces problèmes?
Autres pages sur : fichier xpdx inexistant resolu
Lassé par la pub ? Créez un compte
Bonjour,
[#ff0000]Désactive tes protections résidentes (antivirus, Spybot-S&D, etc.) ![/#f]
Télécharge ComboFix ([#ff0000]sUBs[/#f]) sur ton Bureau.
Double clique sur ComboFix.exe (le .exe n'est pas forcément visible) afin de le lancer.
Lorsque la recherche sera terminée, un rapport apparaîtra. Poste ce rapport (C:\combofix.txt*) dans ta prochaine réponse.
AIDE : Un guide et un tutoriel sur l'utilisation de ComboFix
* le nom de la partition peut changer
[#ff0000]Désactive tes protections résidentes (antivirus, Spybot-S&D, etc.) ![/#f]
AIDE : Un guide et un tutoriel sur l'utilisation de ComboFix
* le nom de la partition peut changer
Bonjour,
voici le rapport demandé.
ComboFix 08-06-10.5 - MINOIA 2008-06-12 16:18:25.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.140 [GMT 2:00]
Endroit: C:\Documents and Settings\MINOIA\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\MINOIA\new.txt
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\eacaebdbf1_g.dll
C:\WINDOWS\system32\jfplokuqto.dat
C:\WINDOWS\system32\jfplokuqto_nav.dat
C:\WINDOWS\system32\jfplokuqto_navps.dat
C:\WINDOWS\system32\xpdx.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_RUNTIME
-------\Legacy_RUNTIME2
-------\Service_xpdx
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-05-12 to 2008-06-12 ))))))))))))))))))))))))))))))))))))
.
2008-06-11 08:45 . 2008-04-14 17:52 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 08:45 . 2008-04-14 17:52 272,768 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-09 22:02 . 2008-06-09 22:02 49,721,243 --a------ C:\upload_moi_MINOIA-6C2C42D4.tar.gz
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-12 14:09 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-06-12 14:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-04 06:00 --------- d-----w C:\Documents and Settings\LocalService\Application Data\AVG7
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-30 10:38 --------- d-----w C:\Program Files\Safari
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-16 14:25 --------- d-----w C:\Program Files\a-squared Free
2008-04-16 13:21 --------- d-----w C:\Program Files\iTunes
2008-04-16 13:21 --------- d-----w C:\Documents and Settings\MINOIA\Application Data\Apple Computer
2008-04-16 13:20 --------- d-----w C:\Program Files\iPod
2008-04-16 13:19 --------- d-----w C:\Program Files\QuickTime
2008-04-16 13:15 --------- d-----w C:\Program Files\Apple Software Update
2008-04-15 17:27 --------- d-----w C:\Program Files\Activision Value
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 194,144 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
2007-07-30 10:30 5,548 ----a-w C:\Documents and Settings\MINOIA\gatftn.exe
2007-07-30 10:23 5,548 ----a-w C:\Documents and Settings\MINOIA\psupqy.exe
2007-07-30 10:16 5,548 ----a-w C:\Documents and Settings\MINOIA\kshxla.exe
2007-07-30 10:10 5,547 ----a-w C:\Documents and Settings\MINOIA\vinytw.exe
2007-07-30 10:03 5,548 ----a-w C:\Documents and Settings\MINOIA\ocwhya.exe
2007-07-30 09:57 5,548 ----a-w C:\Documents and Settings\MINOIA\zorocr.exe
2007-07-30 09:50 5,548 ----a-w C:\Documents and Settings\MINOIA\aqmzoy.exe
2007-07-30 09:43 5,548 ----a-w C:\Documents and Settings\MINOIA\toflra.exe
2007-07-30 09:36 5,548 ----a-w C:\Documents and Settings\MINOIA\zdujir.exe
2007-07-30 09:34 5,548 ----a-w C:\Documents and Settings\MINOIA\gpimjh.exe
2007-07-30 09:03 5,548 ----a-w C:\Documents and Settings\MINOIA\rarhfp.exe
2007-07-30 08:58 5,548 ----a-w C:\Documents and Settings\MINOIA\hokxky.exe
2007-07-30 08:43 5,548 ----a-w C:\Documents and Settings\MINOIA\jndddo.exe
2007-07-30 08:36 5,548 ----a-w C:\Documents and Settings\MINOIA\mvnzfn.exe
2007-07-30 08:30 5,548 ----a-w C:\Documents and Settings\MINOIA\vmckrx.exe
2007-07-30 08:24 5,548 ----a-w C:\Documents and Settings\MINOIA\nsauny.exe
2007-07-30 08:16 5,548 ----a-w C:\Documents and Settings\MINOIA\swfuls.exe
2007-07-30 08:10 5,548 ----a-w C:\Documents and Settings\MINOIA\lgsmtw.exe
2007-07-30 08:03 5,548 ----a-w C:\Documents and Settings\MINOIA\ttlodh.exe
2007-07-30 08:02 5,548 ----a-w C:\Documents and Settings\MINOIA\cbliqd.exe
2007-07-30 07:56 5,548 ----a-w C:\Documents and Settings\MINOIA\xstwhj.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 14:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-21 21:07 68856]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2008-04-18 10:34 579584]
"Device Detector"="C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe" [2005-06-27 11:21 221184]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 14:00 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-25 10:45 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
--a------ 2005-06-14 03:48 69632 C:\WINDOWS\ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2006-03-02 14:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DWQueuedReporting]
--a------ 2005-04-25 13:45 36040 C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
--------- 2005-01-07 18:07 61952 C:\WINDOWS\system32\HdAShCut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-12-15 12:18 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-03-30 10:36 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jfplokuqto]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-03-28 23:37 413696 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
--a------ 2005-06-14 03:48 14477312 C:\WINDOWS\RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-07-12 04:00 132496 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R0 m5287;m5287;C:\WINDOWS\system32\drivers\m5287.sys [2005-09-23 20:53]
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-06-11 10:32:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-12 16:22:58
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\HPZipm12.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-06-12 16:26:49 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-12 14:26:45
Pre-Run: 10,491,973,632 octets libres
Post-Run: 10,580,844,544 octets libres
174 --- E O F --- 2008-06-11 20:29:18
voici le rapport demandé.
ComboFix 08-06-10.5 - MINOIA 2008-06-12 16:18:25.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.140 [GMT 2:00]
Endroit: C:\Documents and Settings\MINOIA\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\MINOIA\new.txt
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\eacaebdbf1_g.dll
C:\WINDOWS\system32\jfplokuqto.dat
C:\WINDOWS\system32\jfplokuqto_nav.dat
C:\WINDOWS\system32\jfplokuqto_navps.dat
C:\WINDOWS\system32\xpdx.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_RUNTIME
-------\Legacy_RUNTIME2
-------\Service_xpdx
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-05-12 to 2008-06-12 ))))))))))))))))))))))))))))))))))))
.
2008-06-11 08:45 . 2008-04-14 17:52 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 08:45 . 2008-04-14 17:52 272,768 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-09 22:02 . 2008-06-09 22:02 49,721,243 --a------ C:\upload_moi_MINOIA-6C2C42D4.tar.gz
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-12 14:09 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-06-12 14:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-04 06:00 --------- d-----w C:\Documents and Settings\LocalService\Application Data\AVG7
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-30 10:38 --------- d-----w C:\Program Files\Safari
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-16 14:25 --------- d-----w C:\Program Files\a-squared Free
2008-04-16 13:21 --------- d-----w C:\Program Files\iTunes
2008-04-16 13:21 --------- d-----w C:\Documents and Settings\MINOIA\Application Data\Apple Computer
2008-04-16 13:20 --------- d-----w C:\Program Files\iPod
2008-04-16 13:19 --------- d-----w C:\Program Files\QuickTime
2008-04-16 13:15 --------- d-----w C:\Program Files\Apple Software Update
2008-04-15 17:27 --------- d-----w C:\Program Files\Activision Value
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 194,144 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
2007-07-30 10:30 5,548 ----a-w C:\Documents and Settings\MINOIA\gatftn.exe
2007-07-30 10:23 5,548 ----a-w C:\Documents and Settings\MINOIA\psupqy.exe
2007-07-30 10:16 5,548 ----a-w C:\Documents and Settings\MINOIA\kshxla.exe
2007-07-30 10:10 5,547 ----a-w C:\Documents and Settings\MINOIA\vinytw.exe
2007-07-30 10:03 5,548 ----a-w C:\Documents and Settings\MINOIA\ocwhya.exe
2007-07-30 09:57 5,548 ----a-w C:\Documents and Settings\MINOIA\zorocr.exe
2007-07-30 09:50 5,548 ----a-w C:\Documents and Settings\MINOIA\aqmzoy.exe
2007-07-30 09:43 5,548 ----a-w C:\Documents and Settings\MINOIA\toflra.exe
2007-07-30 09:36 5,548 ----a-w C:\Documents and Settings\MINOIA\zdujir.exe
2007-07-30 09:34 5,548 ----a-w C:\Documents and Settings\MINOIA\gpimjh.exe
2007-07-30 09:03 5,548 ----a-w C:\Documents and Settings\MINOIA\rarhfp.exe
2007-07-30 08:58 5,548 ----a-w C:\Documents and Settings\MINOIA\hokxky.exe
2007-07-30 08:43 5,548 ----a-w C:\Documents and Settings\MINOIA\jndddo.exe
2007-07-30 08:36 5,548 ----a-w C:\Documents and Settings\MINOIA\mvnzfn.exe
2007-07-30 08:30 5,548 ----a-w C:\Documents and Settings\MINOIA\vmckrx.exe
2007-07-30 08:24 5,548 ----a-w C:\Documents and Settings\MINOIA\nsauny.exe
2007-07-30 08:16 5,548 ----a-w C:\Documents and Settings\MINOIA\swfuls.exe
2007-07-30 08:10 5,548 ----a-w C:\Documents and Settings\MINOIA\lgsmtw.exe
2007-07-30 08:03 5,548 ----a-w C:\Documents and Settings\MINOIA\ttlodh.exe
2007-07-30 08:02 5,548 ----a-w C:\Documents and Settings\MINOIA\cbliqd.exe
2007-07-30 07:56 5,548 ----a-w C:\Documents and Settings\MINOIA\xstwhj.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 14:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-21 21:07 68856]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2008-04-18 10:34 579584]
"Device Detector"="C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe" [2005-06-27 11:21 221184]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 14:00 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-25 10:45 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
--a------ 2005-06-14 03:48 69632 C:\WINDOWS\ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2006-03-02 14:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DWQueuedReporting]
--a------ 2005-04-25 13:45 36040 C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
--------- 2005-01-07 18:07 61952 C:\WINDOWS\system32\HdAShCut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-12-15 12:18 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-03-30 10:36 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jfplokuqto]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-03-28 23:37 413696 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
--a------ 2005-06-14 03:48 14477312 C:\WINDOWS\RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-07-12 04:00 132496 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R0 m5287;m5287;C:\WINDOWS\system32\drivers\m5287.sys [2005-09-23 20:53]
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-06-11 10:32:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-12 16:22:58
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\HPZipm12.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-06-12 16:26:49 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-12 14:26:45
Pre-Run: 10,491,973,632 octets libres
Post-Run: 10,580,844,544 octets libres
174 --- E O F --- 2008-06-11 20:29:18
Re,
Télécharge MalwareByte's Anti-Malware sur ton Bureau.
Installe-le en double-cliquant sur le fichier Download_mbam-setup.exe.
Une fois l'installation et la mise à jour effectuées, redémarre en mode sans échec.
AIDE : Redémarrer en mode sans échec
Exécute maintenant MalwareByte's Anti-Malware. Si cela n'est pas déjà fait, sélectionne "Exécuter un examen complet".
Afin de lancer la recherche, clic sur"Rechercher".
Une fois le scan terminé, une fenêtre s'ouvre, clic sur OK. Deux possibilités s'offrent à toi :
-- si le programme n'a rien trouvé, appuie sur OK. Un rapport va apparaître, ferme-le.
-- si des infections sont présentes, clic sur "Afficher les résultats" puis sur "Supprimer la sélection". Enregistre le rapport sur ton Bureau afin de le poster dans ta prochaine réponse.
[#ff0000]REMARQUE : Si MalwareByte's Anti-Malware a besoin de redémarrer pour terminer la suppression, accepte en cliquant sur Ok.[/#f]
AIDE : Tuto en images sur MBAM
Télécharge MalwareByte's Anti-Malware sur ton Bureau.
Installe-le en double-cliquant sur le fichier Download_mbam-setup.exe.
Une fois l'installation et la mise à jour effectuées, redémarre en mode sans échec.
AIDE : Redémarrer en mode sans échec
-- si le programme n'a rien trouvé, appuie sur OK. Un rapport va apparaître, ferme-le.
-- si des infections sont présentes, clic sur "Afficher les résultats" puis sur "Supprimer la sélection". Enregistre le rapport sur ton Bureau afin de le poster dans ta prochaine réponse.
[#ff0000]REMARQUE : Si MalwareByte's Anti-Malware a besoin de redémarrer pour terminer la suppression, accepte en cliquant sur Ok.[/#f]
AIDE : Tuto en images sur MBAM
Re,
j'ai fait un scan avec MalwareByte's Anti-Malware en mode sans échec, il n'a rien trouvé.
J'en ai refait un en mode normal, il a trouvé un élément que j'ai supprimé, voilà le rapport:
Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 92666
Temps écoulé: 12 minute(s), 1 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 1
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\WINDOWS\system32\dllcache\beep.sys (Fake.Beep.Sys) -> Delete on reboot.
j'ai fait un scan avec MalwareByte's Anti-Malware en mode sans échec, il n'a rien trouvé.
J'en ai refait un en mode normal, il a trouvé un élément que j'ai supprimé, voilà le rapport:
Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 92666
Temps écoulé: 12 minute(s), 1 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 1
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\WINDOWS\system32\dllcache\beep.sys (Fake.Beep.Sys) -> Delete on reboot.
Bonjour,
voilà le rapport Combofix
ComboFix 08-06-11.3 - MINOIA 2008-06-13 13:33:41.3 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.74 [GMT 2:00]
Endroit: C:\Documents and Settings\MINOIA\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
((((((((((((((((((((((((((((( Fichiers créés 2008-05-13 to 2008-06-13 ))))))))))))))))))))))))))))))))))))
.
2008-06-13 13:13 . 2007-03-09 13:02 <REP> d--h----- C:\Documents and Settings\Youlan\Voisinage réseau
2008-06-13 13:13 . 2007-03-09 13:02 <REP> d--h----- C:\Documents and Settings\Youlan\Voisinage d'impression
2008-06-13 13:13 . 2007-03-09 12:07 <REP> d--h----- C:\Documents and Settings\Youlan\Modèles
2008-06-13 13:13 . 2008-06-13 13:21 <REP> dr------- C:\Documents and Settings\Youlan\Mes documents
2008-06-13 13:13 . 2007-03-09 13:02 <REP> dr------- C:\Documents and Settings\Youlan\Menu Démarrer
2008-06-13 13:13 . 2008-06-13 13:13 <REP> dr------- C:\Documents and Settings\Youlan\Favoris
2008-06-13 13:13 . 2008-06-13 13:21 <REP> d-------- C:\Documents and Settings\Youlan\Bureau
2008-06-13 13:13 . 2008-06-13 13:13 <REP> d-------- C:\Documents and Settings\Youlan\Application Data\Grisoft
2008-06-13 13:13 . 2008-06-13 13:13 <REP> d-------- C:\Documents and Settings\Youlan\Application Data\AVG7
2008-06-13 13:13 . 2008-06-13 13:13 <REP> d-------- C:\Documents and Settings\Youlan
2008-06-13 13:13 . 2008-06-13 13:32 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-13 13:13 . 2008-06-13 13:13 1,409 --a------ C:\WINDOWS\QTFont.for
2008-06-12 18:49 . 2008-06-12 18:49 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Malwarebytes
2008-06-12 18:48 . 2007-03-09 13:02 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
2008-06-12 18:48 . 2007-03-09 13:02 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-06-12 18:48 . 2007-03-09 12:07 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
2008-06-12 18:48 . 2007-03-09 13:02 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents
2008-06-12 18:48 . 2007-03-09 13:02 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
2008-06-12 18:48 . 2007-03-09 13:02 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris
2008-06-12 18:48 . 2007-03-09 13:02 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2008-06-12 18:48 . 2008-06-12 18:48 <REP> d-------- C:\Documents and Settings\Administrateur
2008-06-12 18:31 . 2008-06-12 18:31 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-12 18:31 . 2008-06-12 18:31 <REP> d-------- C:\Documents and Settings\MINOIA\Application Data\Malwarebytes
2008-06-12 18:31 . 2008-06-12 18:31 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-12 18:31 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-12 18:31 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-11 08:45 . 2008-04-14 17:52 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 08:45 . 2008-04-14 17:52 272,768 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-09 22:02 . 2008-06-09 22:02 49,721,243 --a------ C:\upload_moi_MINOIA-6C2C42D4.tar.gz
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-12 14:09 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-06-12 14:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-04 06:00 --------- d-----w C:\Documents and Settings\LocalService\Application Data\AVG7
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-30 10:38 --------- d-----w C:\Program Files\Safari
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-16 14:25 --------- d-----w C:\Program Files\a-squared Free
2008-04-16 13:21 --------- d-----w C:\Program Files\iTunes
2008-04-16 13:21 --------- d-----w C:\Documents and Settings\MINOIA\Application Data\Apple Computer
2008-04-16 13:20 --------- d-----w C:\Program Files\iPod
2008-04-16 13:19 --------- d-----w C:\Program Files\QuickTime
2008-04-16 13:15 --------- d-----w C:\Program Files\Apple Software Update
2008-04-15 17:27 --------- d-----w C:\Program Files\Activision Value
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 194,144 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
2007-07-30 10:30 5,548 ----a-w C:\Documents and Settings\MINOIA\gatftn.exe
2007-07-30 10:23 5,548 ----a-w C:\Documents and Settings\MINOIA\psupqy.exe
2007-07-30 10:16 5,548 ----a-w C:\Documents and Settings\MINOIA\kshxla.exe
2007-07-30 10:10 5,547 ----a-w C:\Documents and Settings\MINOIA\vinytw.exe
2007-07-30 10:03 5,548 ----a-w C:\Documents and Settings\MINOIA\ocwhya.exe
2007-07-30 09:57 5,548 ----a-w C:\Documents and Settings\MINOIA\zorocr.exe
2007-07-30 09:50 5,548 ----a-w C:\Documents and Settings\MINOIA\aqmzoy.exe
2007-07-30 09:43 5,548 ----a-w C:\Documents and Settings\MINOIA\toflra.exe
2007-07-30 09:36 5,548 ----a-w C:\Documents and Settings\MINOIA\zdujir.exe
2007-07-30 09:34 5,548 ----a-w C:\Documents and Settings\MINOIA\gpimjh.exe
2007-07-30 09:03 5,548 ----a-w C:\Documents and Settings\MINOIA\rarhfp.exe
2007-07-30 08:58 5,548 ----a-w C:\Documents and Settings\MINOIA\hokxky.exe
2007-07-30 08:43 5,548 ----a-w C:\Documents and Settings\MINOIA\jndddo.exe
2007-07-30 08:36 5,548 ----a-w C:\Documents and Settings\MINOIA\mvnzfn.exe
2007-07-30 08:30 5,548 ----a-w C:\Documents and Settings\MINOIA\vmckrx.exe
2007-07-30 08:24 5,548 ----a-w C:\Documents and Settings\MINOIA\nsauny.exe
2007-07-30 08:16 5,548 ----a-w C:\Documents and Settings\MINOIA\swfuls.exe
2007-07-30 08:10 5,548 ----a-w C:\Documents and Settings\MINOIA\lgsmtw.exe
2007-07-30 08:03 5,548 ----a-w C:\Documents and Settings\MINOIA\ttlodh.exe
2007-07-30 08:02 5,548 ----a-w C:\Documents and Settings\MINOIA\cbliqd.exe
2007-07-30 07:56 5,548 ----a-w C:\Documents and Settings\MINOIA\xstwhj.exe
.
((((((((((((((((((((((((((((( snapshot@2008-06-12_16.26.34.82 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-12 14:22:06 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-13 07:20:54 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 14:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-21 21:07 68856]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2008-04-18 10:34 579584]
"Device Detector"="C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe" [2005-06-27 11:21 221184]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 14:00 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-25 10:45 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
--a------ 2005-06-14 03:48 69632 C:\WINDOWS\ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2006-03-02 14:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DWQueuedReporting]
--a------ 2005-04-25 13:45 36040 C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
--------- 2005-01-07 18:07 61952 C:\WINDOWS\system32\HdAShCut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-12-15 12:18 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-03-30 10:36 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jfplokuqto]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-03-28 23:37 413696 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
--a------ 2005-06-14 03:48 14477312 C:\WINDOWS\RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-07-12 04:00 132496 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R0 m5287;m5287;C:\WINDOWS\system32\drivers\m5287.sys [2005-09-23 20:53]
*Newly Created Service* - CATCHME
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-06-11 10:32:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-13 13:35:20
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-06-13 13:37:46
ComboFix-quarantined-files.txt 2008-06-13 11:37:41
ComboFix2.txt 2008-06-13 11:19:24
ComboFix3.txt 2008-06-12 14:26:51
Pre-Run: 10,587,611,136 octets libres
Post-Run: 10,583,699,456 octets libres
179 --- E O F --- 2008-06-11 20:29:18
voilà le rapport Combofix
ComboFix 08-06-11.3 - MINOIA 2008-06-13 13:33:41.3 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.74 [GMT 2:00]
Endroit: C:\Documents and Settings\MINOIA\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
((((((((((((((((((((((((((((( Fichiers créés 2008-05-13 to 2008-06-13 ))))))))))))))))))))))))))))))))))))
.
2008-06-13 13:13 . 2007-03-09 13:02 <REP> d--h----- C:\Documents and Settings\Youlan\Voisinage réseau
2008-06-13 13:13 . 2007-03-09 13:02 <REP> d--h----- C:\Documents and Settings\Youlan\Voisinage d'impression
2008-06-13 13:13 . 2007-03-09 12:07 <REP> d--h----- C:\Documents and Settings\Youlan\Modèles
2008-06-13 13:13 . 2008-06-13 13:21 <REP> dr------- C:\Documents and Settings\Youlan\Mes documents
2008-06-13 13:13 . 2007-03-09 13:02 <REP> dr------- C:\Documents and Settings\Youlan\Menu Démarrer
2008-06-13 13:13 . 2008-06-13 13:13 <REP> dr------- C:\Documents and Settings\Youlan\Favoris
2008-06-13 13:13 . 2008-06-13 13:21 <REP> d-------- C:\Documents and Settings\Youlan\Bureau
2008-06-13 13:13 . 2008-06-13 13:13 <REP> d-------- C:\Documents and Settings\Youlan\Application Data\Grisoft
2008-06-13 13:13 . 2008-06-13 13:13 <REP> d-------- C:\Documents and Settings\Youlan\Application Data\AVG7
2008-06-13 13:13 . 2008-06-13 13:13 <REP> d-------- C:\Documents and Settings\Youlan
2008-06-13 13:13 . 2008-06-13 13:32 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-13 13:13 . 2008-06-13 13:13 1,409 --a------ C:\WINDOWS\QTFont.for
2008-06-12 18:49 . 2008-06-12 18:49 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Malwarebytes
2008-06-12 18:48 . 2007-03-09 13:02 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
2008-06-12 18:48 . 2007-03-09 13:02 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-06-12 18:48 . 2007-03-09 12:07 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
2008-06-12 18:48 . 2007-03-09 13:02 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents
2008-06-12 18:48 . 2007-03-09 13:02 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
2008-06-12 18:48 . 2007-03-09 13:02 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris
2008-06-12 18:48 . 2007-03-09 13:02 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2008-06-12 18:48 . 2008-06-12 18:48 <REP> d-------- C:\Documents and Settings\Administrateur
2008-06-12 18:31 . 2008-06-12 18:31 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-12 18:31 . 2008-06-12 18:31 <REP> d-------- C:\Documents and Settings\MINOIA\Application Data\Malwarebytes
2008-06-12 18:31 . 2008-06-12 18:31 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-12 18:31 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-12 18:31 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-11 08:45 . 2008-04-14 17:52 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 08:45 . 2008-04-14 17:52 272,768 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-09 22:02 . 2008-06-09 22:02 49,721,243 --a------ C:\upload_moi_MINOIA-6C2C42D4.tar.gz
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-12 14:09 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-06-12 14:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-04 06:00 --------- d-----w C:\Documents and Settings\LocalService\Application Data\AVG7
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-30 10:38 --------- d-----w C:\Program Files\Safari
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-16 14:25 --------- d-----w C:\Program Files\a-squared Free
2008-04-16 13:21 --------- d-----w C:\Program Files\iTunes
2008-04-16 13:21 --------- d-----w C:\Documents and Settings\MINOIA\Application Data\Apple Computer
2008-04-16 13:20 --------- d-----w C:\Program Files\iPod
2008-04-16 13:19 --------- d-----w C:\Program Files\QuickTime
2008-04-16 13:15 --------- d-----w C:\Program Files\Apple Software Update
2008-04-15 17:27 --------- d-----w C:\Program Files\Activision Value
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 194,144 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
2007-07-30 10:30 5,548 ----a-w C:\Documents and Settings\MINOIA\gatftn.exe
2007-07-30 10:23 5,548 ----a-w C:\Documents and Settings\MINOIA\psupqy.exe
2007-07-30 10:16 5,548 ----a-w C:\Documents and Settings\MINOIA\kshxla.exe
2007-07-30 10:10 5,547 ----a-w C:\Documents and Settings\MINOIA\vinytw.exe
2007-07-30 10:03 5,548 ----a-w C:\Documents and Settings\MINOIA\ocwhya.exe
2007-07-30 09:57 5,548 ----a-w C:\Documents and Settings\MINOIA\zorocr.exe
2007-07-30 09:50 5,548 ----a-w C:\Documents and Settings\MINOIA\aqmzoy.exe
2007-07-30 09:43 5,548 ----a-w C:\Documents and Settings\MINOIA\toflra.exe
2007-07-30 09:36 5,548 ----a-w C:\Documents and Settings\MINOIA\zdujir.exe
2007-07-30 09:34 5,548 ----a-w C:\Documents and Settings\MINOIA\gpimjh.exe
2007-07-30 09:03 5,548 ----a-w C:\Documents and Settings\MINOIA\rarhfp.exe
2007-07-30 08:58 5,548 ----a-w C:\Documents and Settings\MINOIA\hokxky.exe
2007-07-30 08:43 5,548 ----a-w C:\Documents and Settings\MINOIA\jndddo.exe
2007-07-30 08:36 5,548 ----a-w C:\Documents and Settings\MINOIA\mvnzfn.exe
2007-07-30 08:30 5,548 ----a-w C:\Documents and Settings\MINOIA\vmckrx.exe
2007-07-30 08:24 5,548 ----a-w C:\Documents and Settings\MINOIA\nsauny.exe
2007-07-30 08:16 5,548 ----a-w C:\Documents and Settings\MINOIA\swfuls.exe
2007-07-30 08:10 5,548 ----a-w C:\Documents and Settings\MINOIA\lgsmtw.exe
2007-07-30 08:03 5,548 ----a-w C:\Documents and Settings\MINOIA\ttlodh.exe
2007-07-30 08:02 5,548 ----a-w C:\Documents and Settings\MINOIA\cbliqd.exe
2007-07-30 07:56 5,548 ----a-w C:\Documents and Settings\MINOIA\xstwhj.exe
.
((((((((((((((((((((((((((((( snapshot@2008-06-12_16.26.34.82 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-12 14:22:06 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-13 07:20:54 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 14:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-21 21:07 68856]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2008-04-18 10:34 579584]
"Device Detector"="C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe" [2005-06-27 11:21 221184]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 14:00 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-25 10:45 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
--a------ 2005-06-14 03:48 69632 C:\WINDOWS\ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2006-03-02 14:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DWQueuedReporting]
--a------ 2005-04-25 13:45 36040 C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
--------- 2005-01-07 18:07 61952 C:\WINDOWS\system32\HdAShCut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-12-15 12:18 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-03-30 10:36 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jfplokuqto]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-03-28 23:37 413696 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
--a------ 2005-06-14 03:48 14477312 C:\WINDOWS\RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-07-12 04:00 132496 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R0 m5287;m5287;C:\WINDOWS\system32\drivers\m5287.sys [2005-09-23 20:53]
*Newly Created Service* - CATCHME
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-06-11 10:32:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-13 13:35:20
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-06-13 13:37:46
ComboFix-quarantined-files.txt 2008-06-13 11:37:41
ComboFix2.txt 2008-06-13 11:19:24
ComboFix3.txt 2008-06-12 14:26:51
Pre-Run: 10,587,611,136 octets libres
Post-Run: 10,583,699,456 octets libres
179 --- E O F --- 2008-06-11 20:29:18
Re,
Copie (Ctrl+C) le texte se situant dans le cadre ci-dessous :
Ouvre le Bloc-Notes puis colle (Ctrl+V) le texte précedemment copié.
Sauvegarde ce fichier sous le nom de CFScript.txt.
Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :
![]()
Cela va relancer Combofix, tape sur 1 puis valide. Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.
[#ff0000]NOTE : S'il n'y a pas de rédémarrage, poste quand même les rapports demandés.[/#f]
Copie (Ctrl+C) le texte se situant dans le cadre ci-dessous :
File::
C:\Documents and Settings\MINOIA\gatftn.exe
C:\Documents and Settings\MINOIA\psupqy.exe
C:\Documents and Settings\MINOIA\kshxla.exe
C:\Documents and Settings\MINOIA\vinytw.exe
C:\Documents and Settings\MINOIA\ocwhya.exe
C:\Documents and Settings\MINOIA\zorocr.exe
C:\Documents and Settings\MINOIA\aqmzoy.exe
C:\Documents and Settings\MINOIA\toflra.exe
C:\Documents and Settings\MINOIA\zdujir.exe
C:\Documents and Settings\MINOIA\gpimjh.exe
C:\Documents and Settings\MINOIA\rarhfp.exe
C:\Documents and Settings\MINOIA\hokxky.exe
C:\Documents and Settings\MINOIA\jndddo.exe
C:\Documents and Settings\MINOIA\mvnzfn.exe
C:\Documents and Settings\MINOIA\vmckrx.exe
C:\Documents and Settings\MINOIA\nsauny.exe
C:\Documents and Settings\MINOIA\swfuls.exe
C:\Documents and Settings\MINOIA\lgsmtw.exe
C:\Documents and Settings\MINOIA\ttlodh.exe
C:\Documents and Settings\MINOIA\cbliqd.exe
C:\Documents and Settings\MINOIA\xstwhj.exe
C:\Documents and Settings\MINOIA\gatftn.exe
C:\Documents and Settings\MINOIA\psupqy.exe
C:\Documents and Settings\MINOIA\kshxla.exe
C:\Documents and Settings\MINOIA\vinytw.exe
C:\Documents and Settings\MINOIA\ocwhya.exe
C:\Documents and Settings\MINOIA\zorocr.exe
C:\Documents and Settings\MINOIA\aqmzoy.exe
C:\Documents and Settings\MINOIA\toflra.exe
C:\Documents and Settings\MINOIA\zdujir.exe
C:\Documents and Settings\MINOIA\gpimjh.exe
C:\Documents and Settings\MINOIA\rarhfp.exe
C:\Documents and Settings\MINOIA\hokxky.exe
C:\Documents and Settings\MINOIA\jndddo.exe
C:\Documents and Settings\MINOIA\mvnzfn.exe
C:\Documents and Settings\MINOIA\vmckrx.exe
C:\Documents and Settings\MINOIA\nsauny.exe
C:\Documents and Settings\MINOIA\swfuls.exe
C:\Documents and Settings\MINOIA\lgsmtw.exe
C:\Documents and Settings\MINOIA\ttlodh.exe
C:\Documents and Settings\MINOIA\cbliqd.exe
C:\Documents and Settings\MINOIA\xstwhj.exe
Ouvre le Bloc-Notes puis colle (Ctrl+V) le texte précedemment copié.
Sauvegarde ce fichier sous le nom de CFScript.txt.
Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :

Cela va relancer Combofix, tape sur 1 puis valide. Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.
[#ff0000]NOTE : S'il n'y a pas de rédémarrage, poste quand même les rapports demandés.[/#f]
Re,
ci-dessous le rapport Combofix:
ComboFix 08-06-11.3 - MINOIA 2008-06-13 18:15:45.4 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.138 [GMT 2:00]
Endroit: C:\Documents and Settings\MINOIA\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\MINOIA\Bureau\CFScript.txt
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
FILE ::
C:\Documents and Settings\MINOIA\aqmzoy.exe
C:\Documents and Settings\MINOIA\cbliqd.exe
C:\Documents and Settings\MINOIA\gatftn.exe
C:\Documents and Settings\MINOIA\gpimjh.exe
C:\Documents and Settings\MINOIA\hokxky.exe
C:\Documents and Settings\MINOIA\jndddo.exe
C:\Documents and Settings\MINOIA\kshxla.exe
C:\Documents and Settings\MINOIA\lgsmtw.exe
C:\Documents and Settings\MINOIA\mvnzfn.exe
C:\Documents and Settings\MINOIA\nsauny.exe
C:\Documents and Settings\MINOIA\ocwhya.exe
C:\Documents and Settings\MINOIA\psupqy.exe
C:\Documents and Settings\MINOIA\rarhfp.exe
C:\Documents and Settings\MINOIA\swfuls.exe
C:\Documents and Settings\MINOIA\toflra.exe
C:\Documents and Settings\MINOIA\ttlodh.exe
C:\Documents and Settings\MINOIA\vinytw.exe
C:\Documents and Settings\MINOIA\vmckrx.exe
C:\Documents and Settings\MINOIA\xstwhj.exe
C:\Documents and Settings\MINOIA\zdujir.exe
C:\Documents and Settings\MINOIA\zorocr.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\MINOIA\aqmzoy.exe
C:\Documents and Settings\MINOIA\cbliqd.exe
C:\Documents and Settings\MINOIA\gatftn.exe
C:\Documents and Settings\MINOIA\gpimjh.exe
C:\Documents and Settings\MINOIA\hokxky.exe
C:\Documents and Settings\MINOIA\jndddo.exe
C:\Documents and Settings\MINOIA\kshxla.exe
C:\Documents and Settings\MINOIA\lgsmtw.exe
C:\Documents and Settings\MINOIA\mvnzfn.exe
C:\Documents and Settings\MINOIA\nsauny.exe
C:\Documents and Settings\MINOIA\ocwhya.exe
C:\Documents and Settings\MINOIA\psupqy.exe
C:\Documents and Settings\MINOIA\rarhfp.exe
C:\Documents and Settings\MINOIA\swfuls.exe
C:\Documents and Settings\MINOIA\toflra.exe
C:\Documents and Settings\MINOIA\ttlodh.exe
C:\Documents and Settings\MINOIA\vinytw.exe
C:\Documents and Settings\MINOIA\vmckrx.exe
C:\Documents and Settings\MINOIA\xstwhj.exe
C:\Documents and Settings\MINOIA\zdujir.exe
C:\Documents and Settings\MINOIA\zorocr.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2008-05-13 to 2008-06-13 ))))))))))))))))))))))))))))))))))))
.
2008-06-13 13:13 . 2007-03-09 13:02 <REP> d--h----- C:\Documents and Settings\Youlan\Voisinage réseau
2008-06-13 13:13 . 2007-03-09 13:02 <REP> d--h----- C:\Documents and Settings\Youlan\Voisinage d'impression
2008-06-13 13:13 . 2007-03-09 12:07 <REP> d--h----- C:\Documents and Settings\Youlan\Modèles
2008-06-13 13:13 . 2008-06-13 13:21 <REP> dr------- C:\Documents and Settings\Youlan\Mes documents
2008-06-13 13:13 . 2007-03-09 13:02 <REP> dr------- C:\Documents and Settings\Youlan\Menu Démarrer
2008-06-13 13:13 . 2008-06-13 13:13 <REP> dr------- C:\Documents and Settings\Youlan\Favoris
2008-06-13 13:13 . 2008-06-13 13:21 <REP> d-------- C:\Documents and Settings\Youlan\Bureau
2008-06-13 13:13 . 2008-06-13 13:13 <REP> d-------- C:\Documents and Settings\Youlan\Application Data\Grisoft
2008-06-13 13:13 . 2008-06-13 13:13 <REP> d-------- C:\Documents and Settings\Youlan\Application Data\AVG7
2008-06-13 13:13 . 2008-06-13 13:13 <REP> d-------- C:\Documents and Settings\Youlan
2008-06-13 13:13 . 2008-06-13 13:32 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-13 13:13 . 2008-06-13 13:13 1,409 --a------ C:\WINDOWS\QTFont.for
2008-06-12 18:49 . 2008-06-12 18:49 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Malwarebytes
2008-06-12 18:48 . 2007-03-09 13:02 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
2008-06-12 18:48 . 2007-03-09 13:02 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-06-12 18:48 . 2007-03-09 12:07 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
2008-06-12 18:48 . 2007-03-09 13:02 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents
2008-06-12 18:48 . 2007-03-09 13:02 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
2008-06-12 18:48 . 2007-03-09 13:02 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris
2008-06-12 18:48 . 2007-03-09 13:02 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2008-06-12 18:48 . 2008-06-12 18:48 <REP> d-------- C:\Documents and Settings\Administrateur
2008-06-12 18:31 . 2008-06-12 18:31 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-12 18:31 . 2008-06-12 18:31 <REP> d-------- C:\Documents and Settings\MINOIA\Application Data\Malwarebytes
2008-06-12 18:31 . 2008-06-12 18:31 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-12 18:31 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-12 18:31 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-11 08:45 . 2008-04-14 17:52 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 08:45 . 2008-04-14 17:52 272,768 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-09 22:02 . 2008-06-09 22:02 49,721,243 --a------ C:\upload_moi_MINOIA-6C2C42D4.tar.gz
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-12 14:09 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-06-12 14:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-04 06:00 --------- d-----w C:\Documents and Settings\LocalService\Application Data\AVG7
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-30 10:38 --------- d-----w C:\Program Files\Safari
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-16 14:25 --------- d-----w C:\Program Files\a-squared Free
2008-04-16 13:21 --------- d-----w C:\Program Files\iTunes
2008-04-16 13:21 --------- d-----w C:\Documents and Settings\MINOIA\Application Data\Apple Computer
2008-04-16 13:20 --------- d-----w C:\Program Files\iPod
2008-04-16 13:19 --------- d-----w C:\Program Files\QuickTime
2008-04-16 13:15 --------- d-----w C:\Program Files\Apple Software Update
2008-04-15 17:27 --------- d-----w C:\Program Files\Activision Value
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 194,144 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
.
((((((((((((((((((((((((((((( snapshot@2008-06-12_16.26.34.82 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-12 14:22:06 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-13 07:20:54 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 14:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-21 21:07 68856]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2008-04-18 10:34 579584]
"Device Detector"="C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe" [2005-06-27 11:21 221184]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 14:00 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-25 10:45 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
--a------ 2005-06-14 03:48 69632 C:\WINDOWS\ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2006-03-02 14:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DWQueuedReporting]
--a------ 2005-04-25 13:45 36040 C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
--------- 2005-01-07 18:07 61952 C:\WINDOWS\system32\HdAShCut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-12-15 12:18 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-03-30 10:36 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jfplokuqto]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-03-28 23:37 413696 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
--a------ 2005-06-14 03:48 14477312 C:\WINDOWS\RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-07-12 04:00 132496 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R0 m5287;m5287;C:\WINDOWS\system32\drivers\m5287.sys [2005-09-23 20:53]
*Newly Created Service* - CATCHME
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-06-11 10:32:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-13 18:18:08
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-06-13 18:19:46
ComboFix-quarantined-files.txt 2008-06-13 16:19:17
ComboFix2.txt 2008-06-13 11:37:47
ComboFix3.txt 2008-06-13 11:19:24
ComboFix4.txt 2008-06-12 14:26:51
Pre-Run: 10,568,474,624 octets libres
Post-Run: 10,561,609,728 octets libres
206 --- E O F --- 2008-06-11 20:29:18
et le rapport HijackThis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:27:12, on 13/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Device Detector] "C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe" -autorun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld...
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/ActiveX/downloadcont...
O16 - DPF: {E6ACF817-0A85-4EBE-9F0A-096C6488CFEA} (NTR ActiveX 1.1.8) - http://eu.ntrsupport.com/inquiero/mod/setup/ntractivex1...
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 6338 bytes
Merci beaucoup de m'aider
, j'ai découvert ce forum il y a quelques jours, et je tire mon chapeau à tous les helper, vous faites vraiment du bon boulot
ci-dessous le rapport Combofix:
ComboFix 08-06-11.3 - MINOIA 2008-06-13 18:15:45.4 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.138 [GMT 2:00]
Endroit: C:\Documents and Settings\MINOIA\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\MINOIA\Bureau\CFScript.txt
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
FILE ::
C:\Documents and Settings\MINOIA\aqmzoy.exe
C:\Documents and Settings\MINOIA\cbliqd.exe
C:\Documents and Settings\MINOIA\gatftn.exe
C:\Documents and Settings\MINOIA\gpimjh.exe
C:\Documents and Settings\MINOIA\hokxky.exe
C:\Documents and Settings\MINOIA\jndddo.exe
C:\Documents and Settings\MINOIA\kshxla.exe
C:\Documents and Settings\MINOIA\lgsmtw.exe
C:\Documents and Settings\MINOIA\mvnzfn.exe
C:\Documents and Settings\MINOIA\nsauny.exe
C:\Documents and Settings\MINOIA\ocwhya.exe
C:\Documents and Settings\MINOIA\psupqy.exe
C:\Documents and Settings\MINOIA\rarhfp.exe
C:\Documents and Settings\MINOIA\swfuls.exe
C:\Documents and Settings\MINOIA\toflra.exe
C:\Documents and Settings\MINOIA\ttlodh.exe
C:\Documents and Settings\MINOIA\vinytw.exe
C:\Documents and Settings\MINOIA\vmckrx.exe
C:\Documents and Settings\MINOIA\xstwhj.exe
C:\Documents and Settings\MINOIA\zdujir.exe
C:\Documents and Settings\MINOIA\zorocr.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\MINOIA\aqmzoy.exe
C:\Documents and Settings\MINOIA\cbliqd.exe
C:\Documents and Settings\MINOIA\gatftn.exe
C:\Documents and Settings\MINOIA\gpimjh.exe
C:\Documents and Settings\MINOIA\hokxky.exe
C:\Documents and Settings\MINOIA\jndddo.exe
C:\Documents and Settings\MINOIA\kshxla.exe
C:\Documents and Settings\MINOIA\lgsmtw.exe
C:\Documents and Settings\MINOIA\mvnzfn.exe
C:\Documents and Settings\MINOIA\nsauny.exe
C:\Documents and Settings\MINOIA\ocwhya.exe
C:\Documents and Settings\MINOIA\psupqy.exe
C:\Documents and Settings\MINOIA\rarhfp.exe
C:\Documents and Settings\MINOIA\swfuls.exe
C:\Documents and Settings\MINOIA\toflra.exe
C:\Documents and Settings\MINOIA\ttlodh.exe
C:\Documents and Settings\MINOIA\vinytw.exe
C:\Documents and Settings\MINOIA\vmckrx.exe
C:\Documents and Settings\MINOIA\xstwhj.exe
C:\Documents and Settings\MINOIA\zdujir.exe
C:\Documents and Settings\MINOIA\zorocr.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2008-05-13 to 2008-06-13 ))))))))))))))))))))))))))))))))))))
.
2008-06-13 13:13 . 2007-03-09 13:02 <REP> d--h----- C:\Documents and Settings\Youlan\Voisinage réseau
2008-06-13 13:13 . 2007-03-09 13:02 <REP> d--h----- C:\Documents and Settings\Youlan\Voisinage d'impression
2008-06-13 13:13 . 2007-03-09 12:07 <REP> d--h----- C:\Documents and Settings\Youlan\Modèles
2008-06-13 13:13 . 2008-06-13 13:21 <REP> dr------- C:\Documents and Settings\Youlan\Mes documents
2008-06-13 13:13 . 2007-03-09 13:02 <REP> dr------- C:\Documents and Settings\Youlan\Menu Démarrer
2008-06-13 13:13 . 2008-06-13 13:13 <REP> dr------- C:\Documents and Settings\Youlan\Favoris
2008-06-13 13:13 . 2008-06-13 13:21 <REP> d-------- C:\Documents and Settings\Youlan\Bureau
2008-06-13 13:13 . 2008-06-13 13:13 <REP> d-------- C:\Documents and Settings\Youlan\Application Data\Grisoft
2008-06-13 13:13 . 2008-06-13 13:13 <REP> d-------- C:\Documents and Settings\Youlan\Application Data\AVG7
2008-06-13 13:13 . 2008-06-13 13:13 <REP> d-------- C:\Documents and Settings\Youlan
2008-06-13 13:13 . 2008-06-13 13:32 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-13 13:13 . 2008-06-13 13:13 1,409 --a------ C:\WINDOWS\QTFont.for
2008-06-12 18:49 . 2008-06-12 18:49 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Malwarebytes
2008-06-12 18:48 . 2007-03-09 13:02 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
2008-06-12 18:48 . 2007-03-09 13:02 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-06-12 18:48 . 2007-03-09 12:07 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
2008-06-12 18:48 . 2007-03-09 13:02 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents
2008-06-12 18:48 . 2007-03-09 13:02 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
2008-06-12 18:48 . 2007-03-09 13:02 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris
2008-06-12 18:48 . 2007-03-09 13:02 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2008-06-12 18:48 . 2008-06-12 18:48 <REP> d-------- C:\Documents and Settings\Administrateur
2008-06-12 18:31 . 2008-06-12 18:31 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-06-12 18:31 . 2008-06-12 18:31 <REP> d-------- C:\Documents and Settings\MINOIA\Application Data\Malwarebytes
2008-06-12 18:31 . 2008-06-12 18:31 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-12 18:31 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-12 18:31 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-11 08:45 . 2008-04-14 17:52 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 08:45 . 2008-04-14 17:52 272,768 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-09 22:02 . 2008-06-09 22:02 49,721,243 --a------ C:\upload_moi_MINOIA-6C2C42D4.tar.gz
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-12 14:09 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-06-12 14:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-06-04 06:00 --------- d-----w C:\Documents and Settings\LocalService\Application Data\AVG7
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2008-04-30 10:38 --------- d-----w C:\Program Files\Safari
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-16 14:25 --------- d-----w C:\Program Files\a-squared Free
2008-04-16 13:21 --------- d-----w C:\Program Files\iTunes
2008-04-16 13:21 --------- d-----w C:\Documents and Settings\MINOIA\Application Data\Apple Computer
2008-04-16 13:20 --------- d-----w C:\Program Files\iPod
2008-04-16 13:19 --------- d-----w C:\Program Files\QuickTime
2008-04-16 13:15 --------- d-----w C:\Program Files\Apple Software Update
2008-04-15 17:27 --------- d-----w C:\Program Files\Activision Value
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 194,144 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
.
((((((((((((((((((((((((((((( snapshot@2008-06-12_16.26.34.82 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-12 14:22:06 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-13 07:20:54 2,048 --s-a-w C:\WINDOWS\bootstat.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 14:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-21 21:07 68856]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" [2008-04-18 10:34 579584]
"Device Detector"="C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe" [2005-06-27 11:21 221184]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 14:00 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe" [2007-10-25 10:45 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.ACDV"= ACDV.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-01-11 23:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
--a------ 2005-06-14 03:48 69632 C:\WINDOWS\ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2006-03-02 14:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DWQueuedReporting]
--a------ 2005-04-25 13:45 36040 C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
--------- 2005-01-07 18:07 61952 C:\WINDOWS\system32\HdAShCut.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2005-12-15 12:18 49152 C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-03-30 10:36 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\jfplokuqto]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-03-28 23:37 413696 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
--a------ 2005-06-14 03:48 14477312 C:\WINDOWS\RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-07-12 04:00 132496 C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avginet.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgemc.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgamsvr.exe"=
"C:\\Program Files\\Grisoft\\AVG Free\\avgcc.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\WINDOWS\\system32\\mmc.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R0 m5287;m5287;C:\WINDOWS\system32\drivers\m5287.sys [2005-09-23 20:53]
*Newly Created Service* - CATCHME
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-06-11 10:32:06 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-13 18:18:08
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-06-13 18:19:46
ComboFix-quarantined-files.txt 2008-06-13 16:19:17
ComboFix2.txt 2008-06-13 11:37:47
ComboFix3.txt 2008-06-13 11:19:24
ComboFix4.txt 2008-06-12 14:26:51
Pre-Run: 10,568,474,624 octets libres
Post-Run: 10,561,609,728 octets libres
206 --- E O F --- 2008-06-11 20:29:18
et le rapport HijackThis:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:27:12, on 13/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Device Detector] "C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe" -autorun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld...
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/ActiveX/downloadcont...
O16 - DPF: {E6ACF817-0A85-4EBE-9F0A-096C6488CFEA} (NTR ActiveX 1.1.8) - http://eu.ntrsupport.com/inquiero/mod/setup/ntractivex1...
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
--
End of file - 6338 bytes
Merci beaucoup de m'aider
, j'ai découvert ce forum il y a quelques jours, et je tire mon chapeau à tous les helper, vous faites vraiment du bon boulot
Lassé par la pub ? Créez un compte
- Contenus similaires :
- ForumSupprimer un fichier endommagé ou illisible résolu
- ForumSupprimer un fichier inexistant
- ForumPhp creer un fichier inexistant sur serveur
- solutionsWindows 7 installation fichier source inexistant
- ForumSupprimer fichier inexistant
- ForumComment supprimer fichier 0 octet inexistant
- ForumCiel compta erreur fichier inexistant
- ForumErreur 2 fichier inexistant zip mac
- ForumXpdx
- ForumWin32 résolu
- Voir plus