|
|
|
|
Bonjour,
je suis désireux de faire un grand nettoyage de mon ordinateur. En effet depuis quelque semaine il commence a RAMER énormement et je ne vous parle pas de la vitesse d'affichage de certaines page internet. De plus lorsque je lance un MMORPG de la game Gpotato ou NCsoft il reboot ... C'est pourquoi je vous demande un petit coup de main voici le premier rapport HijackThis:
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 19:21:43, on 28/10/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\TortoiseSVN\bin\TSVNCache.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\windows\system\hpsysdrv.exe C:\WINDOWS\ALCXMNTR.EXE C:\HP\KBD\KBD.EXE C:\WINDOWS\system32\rundll32.exe C:\Program Files\HP\HP Software Update\HPwuSchd2.exe C:\PROGRA~1\AVG\AVG8\avgtray.exe C:\Program Files\Search Settings\SearchSettings.exe C:\Program Files\Unlocker\UnlockerAssistant.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe C:\Program Files\Messenger\msmsgs.exe C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Free Download Manager\fdm.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\libusbd-nt.exe C:\Program Files\Hamachi\hamachi.exe C:\Program Files\MagicDisc\MagicDisc.exe C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe C:\WINDOWS\system32\svchost.exe C:\PROGRA~1\AVG\AVG8\avgemc.exe C:\PROGRA~1\AVG\AVG8\avgrsx.exe C:\PROGRA~1\AVG\AVG8\avgnsx.exe C:\Program Files\AVG\AVG8\avgcsrvx.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Windows Live\Messenger\usnsvc.exe C:\Program Files\Java\jre6\bin\jucheck.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Downloads\Software\hijackthis-2.0.2.exe C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\hijackthis-2.0.2.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) R3 - URLSearchHook: (no name) - *{E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file) R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll O2 - BHO: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll O2 - BHO: SnapFlash Class - {A44CBB0B-C77D-4BF5-87CC-B4EE79AD1B7E} - C:\Program Files\Fichiers communs\Justdo\Jd2002.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb128\SearchSettings.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} - C:\Program Files\Dealio Toolbar\DealioToolbarIE.dll O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [EPSON Stylus DX7400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE /FU "C:\WINDOWS\TEMP\E_S11B.tmp" /EF "HKCU" O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe O8 - Extra context menu item: &Traduire à partir de l'anglais - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Recherche &Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Save Flash with Flash Catcher - res://C:\Program Files\Fichiers communs\Justdo\IECatcher.DLL/FlashCatcher.htm O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O9 - Extra button: Flash Catcher - {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - C:\Program Files\Fichiers communs\Justdo\IECatcher.DLL O9 - Extra 'Tools' menuitem: Flash Catcher - {90BAE0EF-F4BF-4FAC-B2EC-2C725C34AF12} - C:\Program Files\Fichiers communs\Justdo\IECatcher.DLL O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/... O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/... O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Buddy Central Service 2 (BuddyCentralService) - Unknown owner - O:\versus gb\gbserv\BuddyCenter\BuddyCenter2.exe O23 - Service: Buddy Service 2 (BuddyService) - Unknown owner - O:\versus gb\gbserv\BuddyServ\BuddyServ2.exe O23 - Service: GunBoundXPBroker[8372] - Unknown owner - O:\versus gb\gbserv\Central\GunBoundBroker3.exe O23 - Service: GunBoundXPServ[8360] - Unknown owner - O:\versus gb\gbserv\Server8360\GunBoundServ3.exe O23 - Service: GunBoundXPServ[8361] - Unknown owner - O:\versus gb\gbserv\Server8361\GunBoundServ3.exe O23 - Service: GunBoundXPServ[8362] - Unknown owner - O:\versus gb\gbserv\Server8362\GunBoundServ3.exe O23 - Service: GunBoundXPServ[8363] - Unknown owner - O:\versus gb\gbserv\Server8363\GunBoundServ3.exe O23 - Service: Service Google Update (gupdate1ca2dc65a610444) (gupdate1ca2dc65a610444) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: LibUsb-Win32 - Daemon, Version 0.1.10.1 (libusbd) - http://libusb-win32.sourceforge.net - C:\WINDOWS\system32\libusbd-nt.exe O23 - Service: MySQL - Unknown owner - C:\Program.exe (file missing) O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\system32\GameMon.des.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe -- End of file - 12971 bytes
Configuration: Windows XP Internet Explorer 7.0
Salut :
|
Bonjour,
|
Hello , y a du boulot :
|
Bonjour,
Kill'em by g3n-h@ckm@n 1.0.4.8
User : Compaq_Propriétaire () # KURO
Update on 29/10/2009 by g3n-h@ckm@n ::::: 18.30
Start at: 00:40:24 | 06/11/2009
Contact : g3n-h@ckm@n sur CCM
AMD Athlon(tm) 64 Processor 3400+
Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
Internet Explorer 8.0.6001.18702
Windows Firewall Status : Enabled
AV : AVG Anti-Virus Free 8.5 [ Enabled | Updated ]
C:\ -> Disque fixe local | 180,3 Go (3,51 Go free) [PRESARIO] | NTFS
E:\ -> Disque CD-ROM | 646,71 Mo (0 Mo free) [K2_UK_V_1_0_DSC_] | CDFS
F:\ -> Disque fixe local | 111,79 Go (25,48 Go free) | NTFS
G:\ -> Disque CD-ROM
L:\ -> Disque CD-ROM
M:\ -> Disque CD-ROM
O:\ -> Disque fixe local | 232,88 Go (110,6 Go free) [local] | NTFS
Z:\ -> Disque fixe local | 5,99 Go (2,34 Go free) [PRESARIO_RP] | FAT32
Fichiers analysés :
=================
¤¤¤¤¤¤¤¤¤¤ Fichiers et dossiers presents :
C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
"C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat"
"C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat"
"C:\Program Files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}"
"C:\Program Files\Mozilla Firefox\extensions\search@searchsettings.com"
"C:\Program Files\Mozilla Firefox\searchplugins\search.xml"
"C:\Program Files\Search Settings"
"C:\WINDOWS\aucfg.ini"
"C:\WINDOWS\IFinst27.exe"
"C:\WINDOWS\patch.exe"
C:\WINDOWS\System32\_000111_.tmp.dll
C:\WINDOWS\System32\SET103.tmp
C:\WINDOWS\System32\SET104.tmp
C:\WINDOWS\System32\SET106.tmp
C:\WINDOWS\System32\SET107.tmp
C:\WINDOWS\System32\SET108.tmp
C:\WINDOWS\System32\SET10B.tmp
C:\WINDOWS\System32\SET10C.tmp
C:\WINDOWS\System32\SET10D.tmp
C:\WINDOWS\System32\SET27D.tmp
C:\WINDOWS\System32\SET27F.tmp
C:\WINDOWS\System32\SET284.tmp
C:\WINDOWS\System32\SET28B.tmp
"C:\Documents and Settings\Compaq_Propri‚taire\Application Data\Dealio"
"C:\Documents and Settings\Compaq_Propri‚taire\Application Data\Search Settings"
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\AutoRun.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\DWPUpgradeInstaller.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\First15.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\hijackthis-2.0.2.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\jre-6u15-windows-i586-iftw.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\msxml6-KB927977-enu-x86.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\sspatch.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\sspatch2.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\VP6Install.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\wlsetup-cvr.exe
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\tmp112.tmp
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\TMP3D.tmp
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\TMP57.tmp
C:\Documents and Settings\Compaq_Propri‚taire\LOCAL Settings\Temp\TMPE1.tmp
¤¤¤¤¤¤¤¤¤¤ Action sur les fichiers :
Quarantaine :
aucfg.ini.Kill'em
AutoRun.exe.Kill'em
Dealio.Kill'em
DWPUpgradeInstaller.exe.Kill'em
First15.exe.Kill'em
hijackthis-2.0.2.exe.Kill'em
IFinst27.exe.Kill'em
jre-6u15-windows-i586-iftw.exe.Kill'em
msxml6-KB927977-enu-x86.exe.Kill'em
PATCH.EXE.Kill'em
qmgr0.dat.Kill'em
qmgr1.dat.Kill'em
QTSBandwidthCache.Kill'em
Search Settings.Kill'em
search.xml.Kill'em
search@searchsettings.com.Kill'em
SET103.tmp.Kill'em
SET104.tmp.Kill'em
SET106.tmp.Kill'em
SET107.tmp.Kill'em
SET108.tmp.Kill'em
SET10B.tmp.Kill'em
SET10C.tmp.Kill'em
SET10D.tmp.Kill'em
SET27D.tmp.Kill'em
SET27F.tmp.Kill'em
SET284.tmp.Kill'em
SET28B.tmp.Kill'em
sspatch.exe.Kill'em
sspatch2.exe.Kill'em
tmp112.tmp.Kill'em
TMP3D.tmp.Kill'em
TMP57.tmp.Kill'em
TMPE1.tmp.Kill'em
VP6Install.exe.Kill'em
wlsetup-cvr.exe.Kill'em
_000111_.tmp.dll.Kill'em
{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}.Kill'em
¤¤¤¤¤¤¤¤¤¤ Verification :
===============
Path : C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;c:\Python22;C:\Program Files\QuickTime\QTSystem\;C:\Program Files\TortoiseSVN\bin
===============
¤¤¤¤¤¤¤¤¤¤ Fichiers et dossiers presents :
¤¤¤¤¤¤¤¤¤¤ Clés de registre Presentes :
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "msconfig"
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe
HKCR\SearchSettings.BHO
HKCR\SearchSettings.BHO.1
HKLM\Software\Classes\SearchSettings.BHO
HKLM\Software\Classes\SearchSettings.BHO.1
HKLM\Software\Classes\TypeLib\{CD082CCA-086F-4FD8-8FD7-247A0DBBD1CC}
HKLM\Software\Dealio
"HKLM\Software\Search Settings"
HKCR\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
HKLM\Software\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}
¤¤¤¤¤¤¤¤¤¤ C:\WINDOWS\Prefetch :
2009-07-29ARAGEXERE X-RAY_PAT-0DF82948.pf
Layout.ini
NTOSBOOT-B00DFAAD.pf
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
Ad report.log: . ======= RAPPORT D'AD-REMOVER 1.1.4.5_Z | UNIQUEMENT XP/VISTA/7 ======= . Mit à jour par C_XX le 17.10.2009 à 11:48 Contact: AdRemover.contact@gmail.com Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html . Lancé à: 1:00:27, 06/11/2009 | Mode Normal | Option: CLEAN Exécuté de: C:\Program Files\Ad-Remover\ Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600 Nom du PC: KURO | Utilisateur actuel: Compaq_Propri‚taire . ============== ÉLÉMENT(S) NEUTRALISÉ(S) ============== . HKCU\Software\Search Settings HKLM\Software\Classes\SearchSettings.BHO HKLM\Software\Classes\SearchSettings.BHO.1 HKLM\Software\Dealio HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D} HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{0B1AAC97-8563-41D9-AE47-58E6A222F0E1} HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{94C3BB3A-56A1-43DE-A242-8B41F46E97EF} HKLM\Software\Search Settings HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SearchSettings HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C} HKLM\Software\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D} HKLM\Software\Classes\TypeLib\{1FFEEBC8-D7CA-A5F1-1B02-8E46330FA5CA} HKLM\Software\Classes\TypeLib\{CD082CCA-086F-4FD8-8FD7-247A0DBBD1CC} . C:\DOCUME~1\COMPAQ~1\APPLIC~1\Dealio C:\DOCUME~1\COMPAQ~1\APPLIC~1\DesktopIcon C:\DOCUME~1\COMPAQ~1\APPLIC~1\Search Settings C:\Program Files\Dealio Toolbar C:\Program Files\Mozilla FireFox\regxpcom.exe C:\Windows\Installer\4404bf.msi C:\Windows\Installer\4404c8.msi C:\Documents and Settings\Compaq_Propri‚taire\Application Data\Microsoft\Internet Explorer\Quick Launch\Ebay.lnk C:\DOCUME~1\COMPAQ~1\MENUDM~1\Ebay.lnk C:\DOCUME~1\COMPAQ~1\Cookies\compaq_propri‚taire@partypoker[2].txt C:\DOCUME~1\COMPAQ~1\Cookies\compaq_propri‚taire@rotator.adjuggler[1].txt (!) -- Fichiers temporaires supprimés. . ============== Scan additionnel ============== . . * Mozilla FireFox Version 2.0.0.20 [fr] * . Nom du profil: gwlgfg7a.default (Compaq_Propri‚taire) . (Prefs.js) user_pref("browser.search.defaultenginename", "Yahoo! Search"); (Prefs.js) user_pref("browser.search.selectedEngine", "Yahoo! Search"); (Prefs.js) user_pref("browser.search.defaulturl", "hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q="); (Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.8.1.20"); . . * Internet Explorer Version 8.0.6001.18702 * . [HKEY_CURRENT_USER\..\Internet Explorer\Main] . Start Page: hxxp://fr.msn.com/ Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch Default_search_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch Default_page_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896 . [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main] . Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch Start Page: hxxp://fr.msn.com/ Search bar: hxxp://search.msn.com/spbasic.htm . [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS] . Tabs: res://ieframe.dll/tabswelcome.htm . ============== Suspect (Cracks, Serials ... ) ============== . C:\Documents and Settings\Compaq_Propri‚taire\Application Data\Azureus\torrents\Heroes[1].of.Might.and.Magic 5_PC.DVD_[.FR.ENG.ESP.IT.GER].+.CRACK.NoDVD.rar [mininova].torrent C:\Documents and Settings\Compaq_Propri‚taire\Bureau\Google earth\Crack.exe C:\Documents and Settings\Compaq_Propri‚taire\Bureau\win98\popsiclesthingys\win 98 y2k patches\y2k.exe C:\Documents and Settings\Compaq_Propri‚taire\Bureau\win98\popsiclesthingys\win 98 y2k patches\y2kw98_2.exe . =================================== . 4010 Octet(s) - C:\Ad-Report-CLEAN[1].log . 1302 Fichier(s) - C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp 17 Fichier(s) - C:\WINDOWS\Temp . 19 Fichier(s) - C:\Program Files\Ad-Remover\BACKUP 35 Fichier(s) - C:\Program Files\Ad-Remover\QUARANTINE . Fin à: 1:24:39 | 06/11/2009 - CLEAN[1] . ============== E.O.F ============== . Et enfin le usbfix: ############################## | UsbFix V6.048 | User : Compaq_Propriétaire (Administrateurs) # KURO Update on 04/11/2009 by Chiquitine29, C_XX & Chimay8 Start at: 01:28:56 | 06/11/2009 Website : http://pagesperso-orange.fr/NosTools/index.html Contact : FindyKill.Contact@gmail.com AMD Athlon(tm) 64 Processor 3400+ Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3 Internet Explorer 8.0.6001.18702 Windows Firewall Status : Disabled AV : AVG Anti-Virus Free 8.5 [ Enabled | Updated ] C:\ -> Disque fixe local # 180,3 Go (6,27 Go free) [PRESARIO] # NTFS E:\ -> Disque CD-ROM # 646,71 Mo (0 Mo free) [K2_UK_V_1_0_DSC_] # CDFS F:\ -> Disque fixe local # 111,79 Go (25,48 Go free) # NTFS G:\ -> Disque CD-ROM L:\ -> Disque CD-ROM M:\ -> Disque CD-ROM O:\ -> Disque fixe local # 232,88 Go (110,75 Go free) [local] # NTFS Z:\ -> Disque fixe local # 5,99 Go (2,34 Go free) [PRESARIO_RP] # FAT32 ############################## | Processus actifs | C:\WINDOWS\System32\smss.exe 756 C:\WINDOWS\system32\csrss.exe 832 C:\WINDOWS\system32\winlogon.exe 856 C:\WINDOWS\system32\services.exe 900 C:\WINDOWS\system32\lsass.exe 912 C:\WINDOWS\system32\svchost.exe 1080 C:\WINDOWS\system32\svchost.exe 1148 C:\WINDOWS\System32\svchost.exe 1396 C:\WINDOWS\system32\svchost.exe 1460 C:\WINDOWS\system32\svchost.exe 1712 C:\WINDOWS\system32\spoolsv.exe 144 C:\Program Files\TortoiseSVN\bin\TSVNCache.exe 332 C:\WINDOWS\system32\svchost.exe 652 C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 684 C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe 696 C:\Program Files\Bonjour\mDNSResponder.exe 716 C:\Program Files\Java\jre6\bin\jqs.exe 1108 C:\WINDOWS\system32\libusbd-nt.exe 1224 C:\windows\system\hpsysdrv.exe 1528 C:\WINDOWS\ALCXMNTR.EXE 1608 C:\HP\KBD\KBD.EXE 1616 C:\Program Files\HP\HP Software Update\HPwuSchd2.exe 1748 C:\PROGRA~1\AVG\AVG8\avgtray.exe 1840 C:\Program Files\MySQL\MySQL Server 4.1\bin\mysqld-nt.exe 1864 C:\WINDOWS\system32\nvsvc32.exe 1948 C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe 308 C:\Program Files\Unlocker\UnlockerAssistant.exe 340 C:\WINDOWS\system32\svchost.exe 576 C:\PROGRA~1\AVG\AVG8\avgrsx.exe 628 C:\Program Files\iTunes\iTunesHelper.exe 1336 C:\PROGRA~1\AVG\AVG8\avgemc.exe 288 C:\Program Files\Java\jre6\bin\jusched.exe 1476 C:\PROGRA~1\AVG\AVG8\avgnsx.exe 356 C:\WINDOWS\system32\ctfmon.exe 2884 C:\Program Files\Free Download Manager\fdm.exe 2972 C:\Program Files\MagicDisc\MagicDisc.exe 3072 C:\Program Files\AVG\AVG8\avgcsrvx.exe 3824 C:\Program Files\iPod\bin\iPodService.exe 3516 C:\WINDOWS\System32\alg.exe 3804 C:\WINDOWS\system32\wbem\wmiapsrv.exe 248 C:\WINDOWS\system32\wscntfy.exe 3320 C:\WINDOWS\explorer.exe 1276 C:\PROGRA~1\MOZILL~1\FIREFOX.EXE 2840 C:\WINDOWS\system32\wbem\wmiprvse.exe 1376 ################## | Fichiers # Dossiers infectieux | E:\autorun.inf Z:\autorun.inf ################## | Registre # Clés Run infectieuses | ################## | Registre # Mountpoints2 | HKCU\..\..\Explorer\MountPoints2\E Shell\AutoRun\command =E:\autorun.exe HKCU\..\..\Explorer\MountPoints2\Z Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480 HKCU\..\..\Explorer\MountPoints2\{2a9a0008-b705-11dd-b6af-0013d3fbeb9f} shell\explore\command =explorer.exe shell\open\Command =explorer.exe HKCU\..\..\Explorer\MountPoints2\{98a56187-80fd-11de-bdda-0013d3fbeb9f} Shell\AutoRun\command =H:\RavMon.exe Shell\explore\Command =H:\RavMon.exe -e Shell\open\Command =H:\RavMon.exe ################## | Suspect | http://www.virustotal.com | ################## | Cracks / Keygens / Serials | "C:\Documents and Settings\Compaq_Propri‚taire\Bureau\Google earth\Crack.exe" 02/09/2007 12:03 |Size 1516356 |Crc32 f4b6da64 |Md5 2302eace8e12fa460b14c2e6764ac952 "C:\Program Files\Java\jdk1.5.0_04\bin\serialver.exe" 03/06/2005 02:29 |Size 49277 |Crc32 2154eef5 |Md5 96ef5b153cebc9512bf6bfad78215df7 "C:\Program Files\Java\jdk1.5.0_06\bin\serialver.exe" 10/11/2005 11:37 |Size 49277 |Crc32 98b90c7a |Md5 bc9d147ee008f28a05088dff936eaa98 "E:\Crack\Cracktro.exe" 15/05/2006 17:30 |Size 109056 |Crc32 DENIED |Md5 DENIED "E:\Crack\swkotor2.exe" 15/05/2006 18:10 |Size 4578816 |Crc32 a03e210a |Md5 4a318b515e0e35ba7f289b7764ac1aad "F:\Adobe Dreamweaver CS3\Crack\Dreamweaver2.exe" 20/06/2008 16:02 |Size 16083128 |Crc32 90cdca4e |Md5 21a554b844d714644c05d6773c2fb598 "F:\Adobe Flash Pro CS3 2007\Adobe.Flash.CS3.Keymaker.Only-ZWT\Keygen.exe" 21/04/2007 03:51 |Size 53760 |Crc32 c684a5eb |Md5 e3c7d489013b51c671aa79c9068a2a00 "F:\Adobe Premiere Pro CS3 + Keygen Activator And New Keygen\ADBEPPROCS3_ALP.exe" 24/06/2008 18:17 |Size 37121024 |Crc32 48521d3e |Md5 f94256ce28c5d02dd67dc5c3a36a41cf "F:\Adobe Premiere Pro CS3 + New Keygen - Limited Keys (Grab Now)\ADBEPPROCS3_ALP.exe" 24/06/2008 16:55 |Size 37169152 |Crc32 be6a3d54 |Md5 b5bbeaf5ce81becb026bd7ca9c51046e "F:\Adobe.After.Effects.CS3[ENG][Crack]\Xp Gold\xp.gold.edition.by.slisher\msconfig-cleanup-setup.exe" 30/07/2005 13:09 |Size 709421 |Crc32 7365e0a0 |Md5 072491dc2caaa5570a41d0642646654c "F:\Adobe.After.Effects.CS3[ENG][Crack]\Xp Gold\xp.gold.edition.by.slisher\SETUP.EXE" 01/09/2004 07:00 |Size 1314816 |Crc32 1ab7c8fe |Md5 fc65835d2a9cd4e527f2b2674f9b9778 "F:\Adobe.After.Effects.CS3[ENG][Crack]\Xp Gold\xp.gold.edition.by.slisher\I386\spnpinst.exe" 01/09/2004 07:00 |Size 11776 |Crc32 06fd3df6 |Md5 70e9c484ebad7c9a91cb3d393dc19615 "F:\After Effects Final with Keygen\ADBEAFETCS3_ALP.exe" 26/01/2008 03:19 |Size 877719320 |Crc32 8b0bea73 |Md5 1eccb29c06ef760493c751230069df63 "F:\Macromedia DreamWeaver CS3 + Plugins and Crack\Crack\Dreamweaver.exe" 19/04/2007 10:54 |Size 16083128 |Crc32 90cdca4e |Md5 21a554b844d714644c05d6773c2fb598 "F:\Reason 4 + Keygen + Patch RPS\KEYGEN.EXE" 31/08/2007 15:33 |Size 164352 |Crc32 dae7a014 |Md5 ac271f7c2907076984144dda7db30c4a "O:\AVS Video Converter v4.3.1.371[++Final++CrAcK]\AVSVideoConverter4.exe" 05/01/2006 23:32 |Size 26708114 |Crc32 3486a9fe |Md5 dc08d793309996e8bc05ca015d9051bf "O:\AVS Video Converter v4.3.1.371[++Final++CrAcK]\Crack\AVSVideoConverter4.exe" 04/01/2006 23:21 |Size 7067136 |Crc32 5e09df9a |Md5 cee2260e4ed854224c5bacca4927f4d3 ################## | ! Fin du rapport # UsbFix V6.048 ! | Merci pour le coup de main ^^ |
Salut supprime tous ces cracks et keygens source d infection , puis :
|
Bonjour,
|