| 6 bobo, le 19 jun 2009 à 22:47:00Voici le résultat de l'execution que dois je faire maintenant :
, il a trouvé qqe chose , a redémarré l'ordinateur et a terminé mais il reste qd même une fenetre de commande ouverte. :
------------------------------------
ComboFix 09-06-18.02 - Anne 19/06/2009 22:27.1 - NTFSx86
Lancé depuis: c:\users\Anne\Desktop\comb-fix.exe
AV: AntiVirus Firewall 7.03 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: AntiVirus Firewall 7.03 *disabled* {D4747503-0346-49EB-9262-997542F79BF4}
SP: AntiVirus Firewall 7.03 *disabled* (Updated) {0651C4B0-1D7E-4682-B965-2E9523C483A5}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
* Un antivirus résident est actif
.
Les fichiers ci-dessous ont été désactivés pendant l'exécution:
c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-1563594193-1437022621-3730783803-500
c:\$recycle.bin\S-1-5-21-327805618-3868785434-1756423215-500
c:\$recycle.bin\S-1-5-21-1563594193-1437022621-3730783803-500\desktop.ini
c:\$recycle.bin\S-1-5-21-327805618-3868785434-1756423215-500\desktop.ini
c:\windows\system32\drivers\MSIVXnoespeqxriyvdbxrxrtxoxotcvkvmnqw.sys
c:\windows\system32\MSIVXcount
c:\windows\system32\MSIVXhiibecwqmqmdbkvspinhxbmpgnutewdr.dll
c:\windows\system32\MSIVXtcofpepknqvlcskmtpbvlmidppdtmryc.dll
c:\windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_MSIVXserv.sys
((((((((((((((((((((((((((((( Fichiers créés du 2009-05-19 au 2009-06-19 ))))))))))))))))))))))))))))))))))))
.
2009-06-19 20:06 . 2009-06-19 19:57 3028246 ----a-w- c:\program files\ComboFix.exe
2009-06-19 19:02 . 2008-12-11 06:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-06-19 19:02 . 2009-04-03 09:18 130936 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-06-19 19:02 . 2008-12-18 10:16 73840 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-06-19 19:01 . 2009-06-19 19:02 -------- d-----w- c:\program files\Common Files\PC Tools
2009-06-19 19:01 . 2008-12-10 09:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2009-06-19 19:01 . 2009-06-19 19:16 -------- d-----w- c:\program files\Spyware Doctor
2009-06-19 19:01 . 2009-06-19 19:01 -------- d-----w- c:\users\Anne\AppData\Roaming\PC Tools
2009-06-19 19:01 . 2009-06-19 19:01 -------- d-----w- c:\programdata\PC Tools
2009-06-19 18:59 . 2009-06-19 18:59 -------- d-----w- c:\programdata\Google Updater
2009-06-14 20:27 . 2009-06-14 20:39 -------- d-----r- c:\users\Anne\mpt
2009-06-14 14:35 . 2009-06-14 14:35 -------- d-----w- C:\Click to Disc
2009-06-14 08:20 . 2009-06-14 08:20 0 ----a-w- c:\windows\nsreg.dat
2009-06-14 08:20 . 2009-06-14 08:20 -------- d-----w- c:\users\Anne\AppData\Local\Mozilla
2009-06-14 01:02 . 2008-06-20 01:14 97800 ----a-w- c:\windows\system32\infocardapi.dll
2009-06-14 01:02 . 2008-06-20 01:14 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-06-14 01:02 . 2008-06-20 01:14 622080 ----a-w- c:\windows\system32\icardagt.exe
2009-06-14 01:02 . 2008-06-20 01:14 11264 ----a-w- c:\windows\system32\icardres.dll
2009-06-14 01:02 . 2008-06-20 01:14 43544 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2009-06-14 01:01 . 2008-06-20 01:14 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2009-06-14 01:01 . 2008-06-20 01:14 326160 ----a-w- c:\windows\system32\PresentationHost.exe
2009-06-13 19:49 . 2009-06-13 19:49 -------- d-----w- c:\users\Anne\AppData\Roaming\Yahoo!
2009-06-13 19:49 . 2009-06-13 19:49 -------- d-----w- c:\programdata\Yahoo! Companion
2009-06-13 19:49 . 2009-06-13 19:49 -------- d-----w- c:\program files\Yahoo!
2009-06-13 13:10 . 2009-06-13 18:22 -------- d-----w- C:\Fraps
2009-06-13 06:48 . 2009-04-30 12:37 428544 ----a-w- c:\windows\system32\EncDec.dll
2009-06-13 06:48 . 2009-04-30 12:37 293376 ----a-w- c:\windows\system32\psisdecd.dll
2009-06-11 20:02 . 2009-04-21 11:55 2033152 ----a-w- c:\windows\system32\win32k.sys
2009-06-11 20:02 . 2009-04-23 12:42 636928 ----a-w- c:\windows\system32\localspl.dll
2009-06-11 20:01 . 2009-04-23 12:43 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-06-05 16:27 . 2009-06-05 16:27 -------- d-----w- c:\program files\Sega
2009-06-03 12:22 . 2009-06-03 12:22 -------- d-----w- c:\users\Anne\AppData\Roaming\Sega
2009-05-31 21:08 . 2009-05-31 21:08 -------- d-----w- c:\program files\DVD Decrypter
2009-05-31 20:45 . 2009-05-31 20:45 -------- d-----w- c:\program files\CCleaner
2009-05-31 14:20 . 2009-06-07 08:35 90112 ----a-w- c:\users\Anne\AppData\Roaming\Engelmann Media\Clips & Vidéos sur iPod et iPhone\HDX4VideoSites.dll
2009-05-31 14:20 . 2009-05-31 14:20 -------- d-----w- c:\users\Anne\AppData\Roaming\Engelmann Media
2009-05-31 14:15 . 2009-05-31 14:15 -------- d-----w- c:\programdata\Engelmann Media
2009-05-31 14:13 . 2009-05-31 14:13 53248 ----a-r- c:\users\Anne\AppData\Roaming\Microsoft\Installer\{C06EFB22-B5DB-46C5-9215-BCB5C19C0858}\NewShortcut1_C06EFB22B5DB46C59215BCB5C19C0858.exe
2009-05-31 14:13 . 2009-05-31 14:14 -------- d-----w- c:\program files\Micro Application
2009-05-31 14:13 . 2009-05-31 14:13 10134 ----a-r- c:\users\Anne\AppData\Roaming\Microsoft\Installer\{C06EFB22-B5DB-46C5-9215-BCB5C19C0858}\ARPPRODUCTICON.exe
2009-05-31 14:13 . 2009-05-31 14:13 -------- d-----w- c:\programdata\Micro Application
2009-05-25 18:57 . 2009-05-25 18:57 -------- d-----w- c:\users\remi
2009-05-24 20:08 . 2009-03-19 14:32 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-05-24 20:08 . 2008-04-17 10:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-05-24 20:07 . 2009-05-24 20:07 -------- d-----w- c:\program files\iPod
2009-05-24 20:07 . 2009-05-24 20:08 -------- d-----w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-24 20:07 . 2009-05-24 20:08 -------- d-----w- c:\program files\iTunes
2009-05-24 20:02 . 2009-05-24 20:02 75048 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-19 20:28 . 2008-01-21 08:40 730742 ----a-w- c:\windows\system32\perfh00C.dat
2009-06-19 20:28 . 2008-01-21 08:40 149382 ----a-w- c:\windows\system32\perfc00C.dat
2009-06-19 20:27 . 2008-12-14 13:22 2032 ----a-w- c:\users\Anne\AppData\Local\d3d9caps.dat
2009-06-19 18:59 . 2008-07-09 11:29 -------- d-----w- c:\program files\Google
2009-06-14 21:02 . 2008-12-17 09:32 -------- d-----w- c:\programdata\Roxio
2009-06-14 14:35 . 2008-07-09 13:48 -------- d-----w- c:\programdata\Sony Corporation
2009-06-14 07:28 . 2009-02-18 08:49 -------- d-----w- c:\users\Anne\AppData\Roaming\codeblocks
2009-06-07 08:35 . 2009-05-31 14:20 90112 ----a-w- c:\users\Anne\AppData\Roaming\Engelmann Media\Clips & Vidéos sur iPod et iPhone\HDX4VideoSites.dll
2009-06-03 11:37 . 2002-08-13 12:27 439296 ----a-w- c:\programdata\Microsoft\Windows\Start Menu\Programs\Riven\RivenGSDPatch.exe
2009-06-03 11:37 . 1996-08-26 02:12 345600 ----a-w- c:\programdata\Microsoft\Windows\Start Menu\Programs\Riven\QTIM32.DLL
2009-06-03 11:36 . 1996-08-26 02:12 32768 ----a-w- c:\programdata\Microsoft\Windows\Start Menu\Programs\Riven\CMGR32.DLL
2009-06-03 11:19 . 2009-04-26 16:06 -------- d-----w- c:\program files\Riven
2009-05-24 20:07 . 2009-02-21 13:44 -------- d-----w- c:\program files\Common Files\Apple
2009-05-15 13:51 . 2009-05-15 13:51 -------- d-----w- c:\users\Anne\AppData\Roaming\PCF-VLC
2009-05-15 13:49 . 2009-05-15 13:49 -------- d-----w- c:\users\Anne\AppData\Roaming\Participatory Culture Foundation
2009-05-15 13:48 . 2009-05-15 13:48 -------- d-----w- c:\program files\Participatory Culture Foundation
2009-05-14 05:14 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-12 17:03 . 2009-05-12 16:50 -------- d-----w- c:\program files\Schizm II
2009-05-12 15:07 . 2009-05-12 13:25 -------- d-----w- c:\users\Anne\AppData\Roaming\U3
2009-05-06 15:58 . 2009-05-06 15:50 -------- d--h--w- c:\program files\Zero G Registry
2009-05-06 15:50 . 2009-05-06 15:50 -------- d-----w- c:\program files\Ubi Soft
2009-05-05 19:11 . 2009-03-04 11:43 -------- d-----w- c:\program files\Bodom-Child - RaBBi
2009-05-03 16:51 . 2009-05-03 13:41 -------- d-----w- c:\users\Anne\AppData\Roaming\gtk-2.0
2009-05-03 12:45 . 2009-05-03 12:45 -------- d-----w- c:\program files\GIMP-2.0
2009-04-28 18:43 . 2009-04-28 18:43 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-04-26 17:08 . 2009-04-26 17:09 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-04-26 17:08 . 2008-07-09 13:48 -------- d-----w- c:\program files\Java
2009-04-26 16:09 . 2009-04-26 16:09 -------- d-----w- c:\program files\Red Orb Entertainment
2009-04-26 11:33 . 2009-03-20 16:06 -------- d-----w- c:\program files\Ubisoft
2009-04-10 18:13 . 2009-04-10 18:13 3328 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp AAC Encoder.dat
2009-04-10 18:13 . 2009-04-10 18:07 485240 ----a-w- c:\windows\system32\SpoonUninstall.exe
2009-04-10 18:07 . 2009-04-10 18:07 14373 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp Music Converter.dat
2009-03-26 13:23 . 2009-03-26 13:23 36864 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-03-26 13:23 . 2009-03-26 13:23 1900544 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-03-21 21:10 . 2009-03-21 21:10 684872 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NSUFloatingUI"="c:\program files\Sony\Network Utility\LANUtil.exe" [2008-06-27 262144]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-07-10 397312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-10 835584]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2008-04-03 317280]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-26 148888]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-08-10 29744]
"MarketingTools"="c:\program files\Sony\Marketing Tools\MarketingTools.exe" [2008-08-10 24576]
"OPTENET_GUI"="c:\progra~1\CONTRO~1\bin\optgui.exe" [2006-12-20 404536]
"ORAHSSSessionManager"="c:\program files\OrangeHSS\SessionManager\SessionManager.exe" [2007-12-12 107248]
"F-Secure Manager"="c:\program files\Orange\AntivirusFirewall\Common\FSM32.EXE" [2008-04-23 182936]
"F-Secure TNB"="c:\program files\Orange\AntivirusFirewall\FSGUI\TNBUtil.exe" [2008-04-23 744032]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2008-01-21 215552]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2008-12-08 1173384]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-07-03 6295552]
c:\users\Anne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Lanceur.lnk - c:\program files\Micro Application\LauncherMA.exe [2009-1-5 485376]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2008-07-07 10:28 98304 ----a-w- c:\windows\System32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{8318BE8D-E39F-4613-92FD-09D6B16C4684}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{98DFB218-2FAE-4AE8-91EA-DF9D9C5A59B7}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{603E3CD3-5730-495C-B59D-379D4956173C}"= UDP:c:\program files\Lecteur CANALPLAY\CanalPlayer.exe:Lecteur CANALPLAY
"{2276DF1F-6C78-433E-8843-469E02DF407E}"= TCP:c:\program files\Lecteur CANALPLAY\CanalPlayer.exe:Lecteur CANALPLAY
"{8BA79379-6D89-4B23-A37F-46AE3646C0E7}"= UDP:c:\program files\Sony Ericsson\Sony Ericsson Media Manager\MediaManager.exe:Sony Ericsson Media Manager 1.1
"{E811D0AF-6484-41B1-AEBC-ACDEFF2122AD}"= TCP:c:\program files\Sony Ericsson\Sony Ericsson Media Manager\MediaManager.exe:Sony Ericsson Media Manager 1.1
"{E9FDD574-1D4E-469B-9FDD-F56972B0D658}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{065D9E5C-0575-4086-9A21-B01E350CE662}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{1E131611-4038-4D12-9608-BF83D2063F5D}"= UDP:c:\program files\Ubisoft\Demo\Tom Clancy's H.A.W.X\HAWX.exe:Tom Clancy's H.A.W.X
"{F199D64E-FD61-408F-BCED-F4F8F3D3CBF3}"= TCP:c:\program files\Ubisoft\Demo\Tom Clancy's H.A.W.X\HAWX.exe:Tom Clancy's H.A.W.X
"{5F3CB768-D373-47A5-B264-24AE60CFF5BD}"= UDP:c:\program files\Ubisoft\Demo\Tom Clancy's H.A.W.X\HAWX_dx10.exe:Tom Clancy's H.A.W.X
"{036040A4-775B-4FD2-B1F3-96A06ABF610B}"= TCP:c:\program files\Ubisoft\Demo\Tom Clancy's H.A.W.X\HAWX_dx10.exe:Tom Clancy's H.A.W.X
"{BDA2F482-1028-4BB4-9523-D73D07AEDE22}"= UDP:990:LocalSubnet:LocalSubnet|IF={2C9FC096-437C-47D7-8AB1-2F303EDB3DBA}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:@%systemroot%\WindowsMobile\wmdSync.exe,-4001
"{CA259A62-7D85-47F2-84FF-CDFA386561D9}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{6AF9216C-B360-4634-AB4A-42DFBF462903}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\OrangeHSS\\Connectivity\\ConnectivityManager.exe"= c:\program files\OrangeHSS\Connectivity\ConnectivityManager.exe:*:enabled:CSS
R0 PCTCore;PCTools KDS;c:\windows\System32\drivers\PCTCore.sys [19/06/2009 21:02 130936]
R1 F-Secure HIPS;F-Secure HIPS;c:\program files\Orange\AntivirusFirewall\HIPS\fshs.sys [26/12/2008 13:10 41184]
R1 FSES;F-Secure Email Scanning Driver;c:\windows\System32\drivers\fses.sys [26/12/2008 13:10 34752]
R1 FSFW;F-Secure Firewall Driver;c:\windows\System32\drivers\fsdfw.sys [26/12/2008 13:10 60064]
R1 fsvista;F-Secure Vista Support Driver;c:\program files\Orange\AntivirusFirewall\Anti-Virus\minifilter\fsvista.sys [26/12/2008 13:09 12896]
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [14/04/2006 10:07 28933976]
R2 NSUService;NSUService;c:\program files\Sony\Network Utility\NSUService.exe [10/08/2008 10:36 299008]
R2 OPTENET_FILTER;Orange Contrôle Parental;c:\program files\Controle Parental\bin\optproxy.exe [17/12/2008 22:46 624376]
R2 regi;regi;c:\windows\System32\drivers\regi.sys [17/04/2007 20:09 11032]
R2 RtkAudioService;Realtek Audio Service;c:\windows\RTKAUDIOSERVICE.EXE [09/07/2008 13:38 104992]
R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [19/06/2009 21:01 348752]
R2 VAIO Power Management;VAIO Power Management;c:\program files\Sony\VAIO Power Management\SPMService.exe [09/07/2008 15:49 411488]
R2 VCFw;VAIO Content Folder Watcher;c:\program files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [20/06/2008 08:56 415744]
R2 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [10/08/2008 10:29 337184]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\Orange\AntivirusFirewall\Anti-Virus\minifilter\fsgk.sys [26/12/2008 13:09 62048]
R3 NETw5v32;Pilote de carte Intel(R) Wireless WiFi Link pour Windows Vista 32 bits ;c:\windows\System32\drivers\NETw5v32.sys [28/04/2008 06:29 3658752]
R3 SFEP;Sony Firmware Extension Parser;c:\windows\System32\drivers\SFEP.sys [09/07/2008 22:35 9344]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\System32\drivers\ggflt.sys [27/01/2009 19:15 10976]
S3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [10/08/2008 10:17 29744]
S3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:\windows\System32\drivers\PCAMp50.sys [17/12/2008 22:47 28224]
S3 s916bus;Sony Ericsson Device 916 driver (WDM);c:\windows\System32\drivers\s916bus.sys [02/11/2007 11:47 83496]
S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter;c:\windows\System32\drivers\s916mdfl.sys [06/01/2009 18:02 15016]
S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver;c:\windows\System32\drivers\s916mdm.sys [06/01/2009 18:02 109992]
S3 s916mgmt;Sony Ericsson Device 916 USB WMC Device Management Drivers (WDM);c:\windows\System32\drivers\s916mgmt.sys [06/01/2009 18:02 103976]
S3 s916obex;Sony Ericsson Device 916 USB WMC OBEX Interface;c:\windows\System32\drivers\s916obex.sys [06/01/2009 18:02 100008]
S3 Service CANALPLAY;Service CANALPLAY;c:\program files\Lecteur CANALPLAY\CanalPlayService.exe [10/08/2008 10:00 436096]
S3 SOHCImp;VAIO Media plus Content Importer;c:\program files\Sony\VAIO Media plus\SOHCImp.exe [10/08/2008 10:33 103712]
S3 SOHDms;VAIO Media plus Digital Media Server;c:\program files\Sony\VAIO Media plus\SOHDms.exe [10/08/2008 10:33 353568]
S3 SOHDs;VAIO Media plus Device Searcher;c:\program files\Sony\VAIO Media plus\SOHDs.exe [10/08/2008 10:33 62752]
S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe [10/08/2008 10:29 83232]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\Orange\AntivirusFirewall\Anti-Virus\win2k\fsfilter.sys [26/12/2008 13:09 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\Orange\AntivirusFirewall\Anti-Virus\win2k\fsrec.sys [26/12/2008 13:09 25184]
--- Autres Services/Pilotes en mémoire ---
*NewlyCreated* - MCHINJDRV
*NewlyCreated* - PCTCORE
*Deregistered* - mchInjDrv
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Contenu du dossier 'Tâches planifiées'
2009-06-19 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-08-10 18:59]
2009-06-19 c:\windows\Tasks\Scheduled scanning task.job
- c:\progra~1\Orange\ANTIVI~1\ANTI-V~1\fsav.exe [2008-12-26 16:11]
2009-06-19 c:\windows\Tasks\User_Feed_Synchronization-{103B65BD-4798-4CA0-9487-EB211B637804}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.orange.fr/
uInternet Settings,ProxyOverride = *.local
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\program files\Orange\AntivirusFirewall\FSPS\program\FSLSP.DLL
LSP: c:\program files\Controle Parental\bin\lsp.dll
Trusted Zone: canalplay.com
Trusted Zone: canalplusactive.com
Trusted Zone: canalplay.com
Trusted Zone: canalplusactive.com
FF - ProfilePath - c:\users\Anne\AppData\Roaming\Mozilla\Firefox\Profiles\ra6hykdv.default\
FF - prefs.js: browser.startup.homepage - www.orange.fr
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-19 22:36
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-1889839323-4235589502-2712449985-1003\Software\SecuROM\License information*]
"datasecu"=hex:7f,fd,fe,e6,2c,35,58,1f,49,c8,fe,6d,02,5f,2d,da,c5,c7,6c,21,2c,
08,b4,18,76,a8,b0,38,fb,86,ee,42,0e,15,56,96,f5,79,47,0b,57,ea,d7,f8,42,85,\
"rkeysecu"=hex:3e,80,9e,c4,40,b4,90,83,87,8e,33,49,64,ac,f8,d9
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\[u]0/u000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:0000003d
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\[u]0/u001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(920)
c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll
- - - - - - - > 'lsass.exe'(760)
c:\program files\Controle Parental\bin\lsp.dll
c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll
- - - - - - - > 'csrss.exe'(640)
c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll
- - - - - - - > 'csrss.exe'(708)
c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll
.
Heure de fin: 2009-06-19 22:39
ComboFix-quarantined-files.txt 2009-06-19 20:39
Avant-CF: 134 478 409 728 octets libres
Après-CF: 134 446 272 512 octets libres
286 --- E O F --- 2009-06-14 01:26 Répondre à bobo | Re
Télécharge Malwarebytes anti malware ici
http://www.malwarebytes.org/mbam.php
* Installe le (choisis bien "français" ; ne modifie pas les paramètres d'installe ) et mets le à jour .
(NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : http://www.malekal.com/download/comctl32.ocx
* Potasse le tuto pour te familiariser avec le prg :
http://forum.pcastuces.com/sujet.asp?f=31&s=3
(cela dis, il est très simple d’utilisation).
relance malwarebytes en suivant scrupuleusement ces consignes :
! Déconnecte toi et ferme toutes applications en cours !
* Lance Malwarebyte's .
Fais un examen dit "Complet" .
--> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
--> à la fin tu cliques sur "résultat" .
--> Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .
Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !
Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)
On a tous été un jour débutant dans quelque chose.
Mais le savoir est la récompense de l'assiduité. Répondre à Guillaume5188 | 8 bobo, le 20 jun 2009 à 13:31:27Bonjour j'ai fait ce que tu avais indiqué.
le résultat est ci dessous .
------------------------------------:
Malwarebytes' Anti-Malware 1.38
Version de la base de données: 2297
Windows 6.0.6001 Service Pack 1
20/06/2009 01:28:21
mbam-log-2009-06-20 (01-28-21).txt
Type de recherche: Examen complet (C:\|)
Eléments examinés: 273365
Temps écoulé: 2 hour(s), 5 minute(s), 31 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 2
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
c:\Qoobox\quarantine\C\Windows\System32\MSIVXhiibecwqmqmdbkvspinhxbmpgnutewdr.dll.vir (Spyware.Agent) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\Windows\System32\MSIVXtcofpepknqvlcskmtpbvlmidppdtmryc.dll.vir (Spyware.Agent) -> Quarantined and deleted successfully. Répondre à bobo | Bonjour
Relance combo-fix en mode normal stp merci.
@+
On a tous été un jour débutant dans quelque chose.
Mais le savoir est la récompense de l'assiduité. Répondre à Guillaume5188 | 10 bobo, le 20 jun 2009 à 14:20:52Voilà c'est fait.
le résultat :
icrosoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.33.1036.18.3068.1962 [GMT 2:00]
Lancé depuis: c:\users\Anne\Desktop\Combo-fix.exe
AV: AntiVirus Firewall 7.03 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: AntiVirus Firewall 7.03 *enabled* {D4747503-0346-49EB-9262-997542F79BF4}
SP: AntiVirus Firewall 7.03 *disabled* (Updated) {0651C4B0-1D7E-4682-B965-2E9523C483A5}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-05-20 au 2009-06-20 ))))))))))))))))))))))))))))))))))))
.
2009-06-19 21:21 . 2009-06-19 21:21 -------- d-----w- c:\users\Anne\AppData\Roaming\Malwarebytes
2009-06-19 21:21 . 2009-06-17 09:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-19 21:21 . 2009-06-19 21:21 -------- d-----w- c:\programdata\Malwarebytes
2009-06-19 21:21 . 2009-06-19 21:21 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-19 21:21 . 2009-06-17 09:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-19 20:13 . 2009-06-19 20:47 -------- d-s---w- C:\comb-fix
2009-06-19 20:06 . 2009-06-19 19:57 3028246 ----a-w- c:\program files\ComboFix.exe
2009-06-19 19:02 . 2008-12-11 06:38 159600 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2009-06-19 19:02 . 2009-04-03 09:18 130936 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-06-19 19:02 . 2008-12-18 10:16 73840 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2009-06-19 19:01 . 2009-06-19 19:02 -------- d-----w- c:\program files\Common Files\PC Tools
2009-06-19 19:01 . 2008-12-10 09:36 64392 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2009-06-19 19:01 . 2009-06-19 19:16 -------- d-----w- c:\program files\Spyware Doctor
2009-06-19 19:01 . 2009-06-19 19:01 -------- d-----w- c:\users\Anne\AppData\Roaming\PC Tools
2009-06-19 19:01 . 2009-06-19 19:01 -------- d-----w- c:\programdata\PC Tools
2009-06-19 18:59 . 2009-06-19 18:59 -------- d-----w- c:\programdata\Google Updater
2009-06-14 20:27 . 2009-06-14 20:39 -------- d-----r- c:\users\Anne\mpt
2009-06-14 14:35 . 2009-06-14 14:35 -------- d-----w- C:\Click to Disc
2009-06-14 08:20 . 2009-06-14 08:20 0 ----a-w- c:\windows\nsreg.dat
2009-06-14 08:20 . 2009-06-14 08:20 -------- d-----w- c:\users\Anne\AppData\Local\Mozilla
2009-06-14 01:02 . 2008-06-20 01:14 97800 ----a-w- c:\windows\system32\infocardapi.dll
2009-06-14 01:02 . 2008-06-20 01:14 105016 ----a-w- c:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2009-06-14 01:02 . 2008-06-20 01:14 622080 ----a-w- c:\windows\system32\icardagt.exe
2009-06-14 01:02 . 2008-06-20 01:14 11264 ----a-w- c:\windows\system32\icardres.dll
2009-06-14 01:02 . 2008-06-20 01:14 43544 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2009-06-14 01:01 . 2008-06-20 01:14 781344 ----a-w- c:\windows\system32\PresentationNative_v0300.dll
2009-06-14 01:01 . 2008-06-20 01:14 326160 ----a-w- c:\windows\system32\PresentationHost.exe
2009-06-13 19:49 . 2009-06-13 19:49 -------- d-----w- c:\users\Anne\AppData\Roaming\Yahoo!
2009-06-13 19:49 . 2009-06-13 19:49 -------- d-----w- c:\programdata\Yahoo! Companion
2009-06-13 19:49 . 2009-06-13 19:49 -------- d-----w- c:\program files\Yahoo!
2009-06-13 13:10 . 2009-06-13 18:22 -------- d-----w- C:\Fraps
2009-06-13 06:48 . 2009-04-30 12:37 428544 ----a-w- c:\windows\system32\EncDec.dll
2009-06-13 06:48 . 2009-04-30 12:37 293376 ----a-w- c:\windows\system32\psisdecd.dll
2009-06-11 20:02 . 2009-04-21 11:55 2033152 ----a-w- c:\windows\system32\win32k.sys
2009-06-11 20:02 . 2009-04-23 12:42 636928 ----a-w- c:\windows\system32\localspl.dll
2009-06-11 20:01 . 2009-04-23 12:43 784896 ----a-w- c:\windows\system32\rpcrt4.dll
2009-06-05 16:27 . 2009-06-05 16:27 -------- d-----w- c:\program files\Sega
2009-06-03 12:22 . 2009-06-03 12:22 -------- d-----w- c:\users\Anne\AppData\Roaming\Sega
2009-05-31 21:08 . 2009-05-31 21:08 -------- d-----w- c:\program files\DVD Decrypter
2009-05-31 20:45 . 2009-05-31 20:45 -------- d-----w- c:\program files\CCleaner
2009-05-31 14:20 . 2009-06-07 08:35 90112 ----a-w- c:\users\Anne\AppData\Roaming\Engelmann Media\Clips & Vidéos sur iPod et iPhone\HDX4VideoSites.dll
2009-05-31 14:20 . 2009-05-31 14:20 -------- d-----w- c:\users\Anne\AppData\Roaming\Engelmann Media
2009-05-31 14:15 . 2009-05-31 14:15 -------- d-----w- c:\programdata\Engelmann Media
2009-05-31 14:13 . 2009-05-31 14:13 53248 ----a-r- c:\users\Anne\AppData\Roaming\Microsoft\Installer\{C06EFB22-B5DB-46C5-9215-BCB5C19C0858}\NewShortcut1_C06EFB22B5DB46C59215BCB5C19C0858.exe
2009-05-31 14:13 . 2009-05-31 14:14 -------- d-----w- c:\program files\Micro Application
2009-05-31 14:13 . 2009-05-31 14:13 10134 ----a-r- c:\users\Anne\AppData\Roaming\Microsoft\Installer\{C06EFB22-B5DB-46C5-9215-BCB5C19C0858}\ARPPRODUCTICON.exe
2009-05-31 14:13 . 2009-05-31 14:13 -------- d-----w- c:\programdata\Micro Application
2009-05-25 18:57 . 2009-05-25 18:57 -------- d-----w- c:\users\remi
2009-05-24 20:08 . 2009-03-19 14:32 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-05-24 20:08 . 2008-04-17 10:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-05-24 20:07 . 2009-05-24 20:07 -------- d-----w- c:\program files\iPod
2009-05-24 20:07 . 2009-05-24 20:08 -------- d-----w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-24 20:07 . 2009-05-24 20:08 -------- d-----w- c:\program files\iTunes
2009-05-24 20:02 . 2009-05-24 20:02 75048 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-20 12:07 . 2008-01-21 08:40 730742 ----a-w- c:\windows\system32\perfh00C.dat
2009-06-20 12:07 . 2008-01-21 08:40 149382 ----a-w- c:\windows\system32\perfc00C.dat
2009-06-19 21:16 . 2008-08-10 08:11 -------- d-----w- c:\program files\Google BAE
2009-06-19 20:27 . 2008-12-14 13:22 2032 ----a-w- c:\users\Anne\AppData\Local\d3d9caps.dat
2009-06-19 18:59 . 2008-07-09 11:29 -------- d-----w- c:\program files\Google
2009-06-14 21:02 . 2008-12-17 09:32 -------- d-----w- c:\programdata\Roxio
2009-06-14 14:35 . 2008-07-09 13:48 -------- d-----w- c:\programdata\Sony Corporation
2009-06-14 07:28 . 2009-02-18 08:49 -------- d-----w- c:\users\Anne\AppData\Roaming\codeblocks
2009-06-07 08:35 . 2009-05-31 14:20 90112 ----a-w- c:\users\Anne\AppData\Roaming\Engelmann Media\Clips & Vidéos sur iPod et iPhone\HDX4VideoSites.dll
2009-06-03 11:37 . 2002-08-13 12:27 439296 ----a-w- c:\programdata\Microsoft\Windows\Start Menu\Programs\Riven\RivenGSDPatch.exe
2009-06-03 11:37 . 1996-08-26 02:12 345600 ----a-w- c:\programdata\Microsoft\Windows\Start Menu\Programs\Riven\QTIM32.DLL
2009-06-03 11:36 . 1996-08-26 02:12 32768 ----a-w- c:\programdata\Microsoft\Windows\Start Menu\Programs\Riven\CMGR32.DLL
2009-06-03 11:19 . 2009-04-26 16:06 -------- d-----w- c:\program files\Riven
2009-05-24 20:07 . 2009-02-21 13:44 -------- d-----w- c:\program files\Common Files\Apple
2009-05-15 13:51 . 2009-05-15 13:51 -------- d-----w- c:\users\Anne\AppData\Roaming\PCF-VLC
2009-05-15 13:49 . 2009-05-15 13:49 -------- d-----w- c:\users\Anne\AppData\Roaming\Participatory Culture Foundation
2009-05-15 13:48 . 2009-05-15 13:48 -------- d-----w- c:\program files\Participatory Culture Foundation
2009-05-14 05:14 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-05-12 17:03 . 2009-05-12 16:50 -------- d-----w- c:\program files\Schizm II
2009-05-12 15:07 . 2009-05-12 13:25 -------- d-----w- c:\users\Anne\AppData\Roaming\U3
2009-05-06 15:58 . 2009-05-06 15:50 -------- d--h--w- c:\program files\Zero G Registry
2009-05-06 15:50 . 2009-05-06 15:50 -------- d-----w- c:\program files\Ubi Soft
2009-05-05 19:11 . 2009-03-04 11:43 -------- d-----w- c:\program files\Bodom-Child - RaBBi
2009-05-03 16:51 . 2009-05-03 13:41 -------- d-----w- c:\users\Anne\AppData\Roaming\gtk-2.0
2009-05-03 12:45 . 2009-05-03 12:45 -------- d-----w- c:\program files\GIMP-2.0
2009-04-28 18:43 . 2009-04-28 18:43 98304 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-04-26 17:08 . 2009-04-26 17:09 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-04-26 17:08 . 2008-07-09 13:48 -------- d-----w- c:\program files\Java
2009-04-26 16:09 . 2009-04-26 16:09 -------- d-----w- c:\program files\Red Orb Entertainment
2009-04-26 11:33 . 2009-03-20 16:06 -------- d-----w- c:\program files\Ubisoft
2009-04-10 18:13 . 2009-04-10 18:13 3328 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp AAC Encoder.dat
2009-04-10 18:13 . 2009-04-10 18:07 485240 ----a-w- c:\windows\system32\SpoonUninstall.exe
2009-04-10 18:07 . 2009-04-10 18:07 14373 ----a-w- c:\windows\system32\SpoonUninstall-dBpoweramp Music Converter.dat
2009-03-26 13:23 . 2009-03-26 13:23 36864 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-03-26 13:23 . 2009-03-26 13:23 1900544 ----a-w- c:\windows\system32\usbaaplrc.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NSUFloatingUI"="c:\program files\Sony\Network Utility\LANUtil.exe" [2008-06-27 262144]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-07-10 397312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-10 835584]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2008-04-03 317280]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-26 148888]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-08-10 29744]
"MarketingTools"="c:\program files\Sony\Marketing Tools\MarketingTools.exe" [2008-08-10 24576]
"OPTENET_GUI"="c:\progra~1\CONTRO~1\bin\optgui.exe" [2006-12-20 404536]
"ORAHSSSessionManager"="c:\program files\OrangeHSS\SessionManager\SessionManager.exe" [2007-12-12 107248]
"F-Secure Manager"="c:\program files\Orange\AntivirusFirewall\Common\FSM32.EXE" [2008-04-23 182936]
"F-Secure TNB"="c:\program files\Orange\AntivirusFirewall\FSGUI\TNBUtil.exe" [2008-04-23 744032]
"Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2008-01-21 215552]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-07-03 6295552]
c:\users\Anne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Lanceur.lnk - c:\program files\Micro Application\LauncherMA.exe [2009-1-5 485376]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2008-07-07 10:28 98304 ----a-w- c:\windows\System32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{8318BE8D-E39F-4613-92FD-09D6B16C4684}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{98DFB218-2FAE-4AE8-91EA-DF9D9C5A59B7}"= c:\program files\Skype\Phone\Skype.exe:Skype
"{603E3CD3-5730-495C-B59D-379D4956173C}"= UDP:c:\program files\Lecteur CANALPLAY\CanalPlayer.exe:Lecteur CANALPLAY
"{2276DF1F-6C78-433E-8843-469E02DF407E}"= TCP:c:\program files\Lecteur CANALPLAY\CanalPlayer.exe:Lecteur CANALPLAY
"{8BA79379-6D89-4B23-A37F-46AE3646C0E7}"= UDP:c:\program files\Sony Ericsson\Sony Ericsson Media Manager\MediaManager.exe:Sony Ericsson Media Manager 1.1
"{E811D0AF-6484-41B1-AEBC-ACDEFF2122AD}"= TCP:c:\program files\Sony Ericsson\Sony Ericsson Media Manager\MediaManager.exe:Sony Ericsson Media Manager 1.1
"{E9FDD574-1D4E-469B-9FDD-F56972B0D658}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{065D9E5C-0575-4086-9A21-B01E350CE662}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{1E131611-4038-4D12-9608-BF83D2063F5D}"= UDP:c:\program files\Ubisoft\Demo\Tom Clancy's H.A.W.X\HAWX.exe:Tom Clancy's H.A.W.X
"{F199D64E-FD61-408F-BCED-F4F8F3D3CBF3}"= TCP:c:\program files\Ubisoft\Demo\Tom Clancy's H.A.W.X\HAWX.exe:Tom Clancy's H.A.W.X
"{5F3CB768-D373-47A5-B264-24AE60CFF5BD}"= UDP:c:\program files\Ubisoft\Demo\Tom Clancy's H.A.W.X\HAWX_dx10.exe:Tom Clancy's H.A.W.X
"{036040A4-775B-4FD2-B1F3-96A06ABF610B}"= TCP:c:\program files\Ubisoft\Demo\Tom Clancy's H.A.W.X\HAWX_dx10.exe:Tom Clancy's H.A.W.X
"{BDA2F482-1028-4BB4-9523-D73D07AEDE22}"= UDP:990:LocalSubnet:LocalSubnet|IF={2C9FC096-437C-47D7-8AB1-2F303EDB3DBA}|%SystemRoot%\system32\svchost.exe|Svc=rapimgr:@%systemroot%\WindowsMobile\wmdSync.exe,-4001
"{CA259A62-7D85-47F2-84FF-CDFA386561D9}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{6AF9216C-B360-4634-AB4A-42DFBF462903}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Program Files\\OrangeHSS\\Connectivity\\ConnectivityManager.exe"= c:\program files\OrangeHSS\Connectivity\ConnectivityManager.exe:*:enabled:CSS
R0 PCTCore;PCTools KDS;c:\windows\System32\drivers\PCTCore.sys [19/06/2009 21:02 130936]
R1 F-Secure HIPS;F-Secure HIPS;c:\program files\Orange\AntivirusFirewall\HIPS\fshs.sys [26/12/2008 13:10 41184]
R1 FSES;F-Secure Email Scanning Driver;c:\windows\System32\drivers\fses.sys [26/12/2008 13:10 34752]
R1 FSFW;F-Secure Firewall Driver;c:\windows\System32\drivers\fsdfw.sys [26/12/2008 13:10 60064]
R1 fsvista;F-Secure Vista Support Driver;c:\program files\Orange\AntivirusFirewall\Anti-Virus\minifilter\fsvista.sys [26/12/2008 13:09 12896]
R2 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [14/04/2006 10:07 28933976]
R2 NSUService;NSUService;c:\program files\Sony\Network Utility\NSUService.exe [10/08/2008 10:36 299008]
R2 OPTENET_FILTER;Orange Contrôle Parental;c:\program files\Controle Parental\bin\optproxy.exe [17/12/2008 22:46 624376]
R2 regi;regi;c:\windows\System32\drivers\regi.sys [17/04/2007 20:09 11032]
R2 RtkAudioService;Realtek Audio Service;c:\windows\RTKAUDIOSERVICE.EXE [09/07/2008 13:38 104992]
R2 VAIO Power Management;VAIO Power Management;c:\program files\Sony\VAIO Power Management\SPMService.exe [09/07/2008 15:49 411488]
R2 VCFw;VAIO Content Folder Watcher;c:\program files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [20/06/2008 08:56 415744]
R2 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [10/08/2008 10:29 337184]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\Orange\AntivirusFirewall\Anti-Virus\minifilter\fsgk.sys [26/12/2008 13:09 62048]
R3 NETw5v32;Pilote de carte Intel(R) Wireless WiFi Link pour Windows Vista 32 bits ;c:\windows\System32\drivers\NETw5v32.sys [28/04/2008 06:29 3658752]
R3 SFEP;Sony Firmware Extension Parser;c:\windows\System32\drivers\SFEP.sys [09/07/2008 22:35 9344]
S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\System32\drivers\ggflt.sys [27/01/2009 19:15 10976]
S3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [10/08/2008 10:17 29744]
S3 PCAMp50;PCAMp50 NDIS Protocol Driver;c:\windows\System32\drivers\PCAMp50.sys [17/12/2008 22:47 28224]
S3 s916bus;Sony Ericsson Device 916 driver (WDM);c:\windows\System32\drivers\s916bus.sys [02/11/2007 11:47 83496]
S3 s916mdfl;Sony Ericsson Device 916 USB WMC Modem Filter;c:\windows\System32\drivers\s916mdfl.sys [06/01/2009 18:02 15016]
S3 s916mdm;Sony Ericsson Device 916 USB WMC Modem Driver;c:\windows\System32\drivers\s916mdm.sys [06/01/2009 18:02 109992]
S3 s916mgmt;Sony Ericsson Device 916 USB WMC Device Management Drivers (WDM);c:\windows\System32\drivers\s916mgmt.sys [06/01/2009 18:02 103976]
S3 s916obex;Sony Ericsson Device 916 USB WMC OBEX Interface;c:\windows\System32\drivers\s916obex.sys [06/01/2009 18:02 100008]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [19/06/2009 21:01 348752]
S3 Service CANALPLAY;Service CANALPLAY;c:\program files\Lecteur CANALPLAY\CanalPlayService.exe [10/08/2008 10:00 436096]
S3 SOHCImp;VAIO Media plus Content Importer;c:\program files\Sony\VAIO Media plus\SOHCImp.exe [10/08/2008 10:33 103712]
S3 SOHDms;VAIO Media plus Digital Media Server;c:\program files\Sony\VAIO Media plus\SOHDms.exe [10/08/2008 10:33 353568]
S3 SOHDs;VAIO Media plus Device Searcher;c:\program files\Sony\VAIO Media plus\SOHDs.exe [10/08/2008 10:33 62752]
S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;c:\program files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe [10/08/2008 10:29 83232]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\Orange\AntivirusFirewall\Anti-Virus\win2k\fsfilter.sys [26/12/2008 13:09 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\Orange\AntivirusFirewall\Anti-Virus\win2k\fsrec.sys [26/12/2008 13:09 25184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
.
Contenu du dossier 'Tâches planifiées'
2009-06-20 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-08-10 18:59]
2009-06-20 c:\windows\Tasks\Scheduled scanning task.job
- c:\progra~1\Orange\ANTIVI~1\ANTI-V~1\fsav.exe [2008-12-26 16:11]
2009-06-20 c:\windows\Tasks\User_Feed_Synchronization-{103B65BD-4798-4CA0-9487-EB211B637804}.job
- c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.orange.fr/
uInternet Settings,ProxyOverride = *.local
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
LSP: c:\program files\Orange\AntivirusFirewall\FSPS\program\FSLSP.DLL
LSP: c:\program files\Controle Parental\bin\lsp.dll
Trusted Zone: canalplay.com
Trusted Zone: canalplusactive.com
Trusted Zone: canalplay.com
Trusted Zone: canalplusactive.com
FF - ProfilePath - c:\users\Anne\AppData\Roaming\Mozilla\Firefox\Profiles\ra6hykdv.default\
FF - prefs.js: browser.startup.homepage - www.orange.fr
FF - plugin: c:\program files\Google\Google Updater\2.4.1601.7122\npCIDetect13.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-20 14:13
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-1889839323-4235589502-2712449985-1003\Software\SecuROM\License information*]
"datasecu"=hex:7f,fd,fe,e6,2c,35,58,1f,49,c8,fe,6d,02,5f,2d,da,c5,c7,6c,21,2c,
08,b4,18,76,a8,b0,38,fb,86,ee,42,0e,15,56,96,f5,79,47,0b,57,ea,d7,f8,42,85,\
"rkeysecu"=hex:3e,80,9e,c4,40,b4,90,83,87,8e,33,49,64,ac,f8,d9
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\[u]0/u000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:0000003d
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\[u]0/u001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(848)
c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll
- - - - - - - > 'lsass.exe'(760)
c:\program files\Controle Parental\bin\lsp.dll
c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll
- - - - - - - > 'csrss.exe'(640)
c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll
- - - - - - - > 'csrss.exe'(712)
c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll
.
Heure de fin: 2009-06-20 14:14
ComboFix-quarantined-files.txt 2009-06-20 12:14
ComboFix2.txt 2009-06-19 20:39
Avant-CF: 131 332 997 120 octets libres
Après-CF: 128 158 613 504 octets libres
272 --- E O F --- 2009-06-20 11:25 Répondre à bobo | Re
1)Pour vérifier de plus prés ton PC fait ceci stp merci:
1- Télécharge et installe le logiciel HijackThis :
ici http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis
ou ici http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
ou ici http://www.clubic.com/lancer-le-telechargement-51452-0-hijackthis.html
-->Clique sur le setup pour lancer l'installation : laisse toi guider et ne modifie pas les paramètres d'installation .
A la fin de l’installation, le programme se lance automatiquement : ferme le en cliquant sur la croix rouge.
Au final, tu dois avoir un raccourci sur ton bureau et aussi un cheminement comme :
"C:\ program files\Trend Micro\HijackThis\HijackThis.exe " .
(Ne lance pas ce prg pour l'instant et fais la suite ... )
2- Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.
-> http://images.malwareremoval.com/random/RSIT.exe
! Déconnecte toi et ferme toutes tes applications en cours !
Double-clique sur " RSIT.exe " pour le lancer.
-> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .
* Devant l'option "List files/folders created ..." , tu choisis : 2 months
* clique ensuite sur " Continue " pour lancer l'analyse ...
-> laisse faire le scan et ne touche pas au PC ...
Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-notes).
Poste le contenu de " log.txt " (c'est celui qui apparaît à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...
Important : poste un rapport, puis l'autre dans la réponse suivante ...
Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum ...
( Et si "log.txt" seul, ne passe pas non plus , fais le en 2 fois ... merci ... )
( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
2)Lance un scan complet avec ton antivirus.Merci.
@+
On a tous été un jour débutant dans quelque chose.
Mais le savoir est la récompense de l'assiduité. Répondre à Guillaume5188 |
|
|
|
|
|