Virus de pop ups.

Fermé
mia928 - Modifié par mia928 le 19/04/2010 à 05:07
 gen-hackman - 20 mai 2010 à 04:32
Bonjour, j'ai été asser stupide pour télécharger un fichier pas très safe.. et maintenant je recois des pop ups sans arrêt.. je ne suis pas super bonne avec les ordinateurs.. et en ce moment je suis en train de scanner mon ordi avec Avast... mais de ce que j'ai lu.. ca sert à rien avec ce virus... quelqu'un s'aurait-il comment s'en débarasser?
J'utilise Mozilla Firefox...Windows XP...

69 réponses

dédétraqué Messages postés 4384 Date d'inscription vendredi 5 septembre 2008 Statut Contributeur sécurité Dernière intervention 4 février 2013 286
22 avril 2010 à 00:14
Salut mia928


Télécharge Gmer et enregistre-le sur ton bureau.
http://www2.gmer.net/download.php

- Déconnecte toi d'internet si possible et ferme tous les programmes, puis lance l'outil.
- Clique sur le bouton "Scan" sur la droite.

- Lorsque le scan est terminé, clic sur "Copy".
- Ouvre le bloc-note et clic sur le Menu Edition / Coller
- Le rapport doit alors apparaître.

- Enregistre le fichier sur ton bureau et copie/colle le contenu ici.


@++ :)
0
Salut dédétraqué
Désolé du delai pour répondre, j'étais pas à la maison pour la fin de semaine.
Alors voici le rapport:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-04-22 23:07:53
Windows 5.1.2600 Service Pack 3
Running: z0vjw5ke.exe; Driver: C:\DOCUME~1\Zamboni\LOCALS~1\Temp\fxrorkoc.sys


---- System - GMER 1.0.15 ----

SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwClose [0xAD383576]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateKey [0xAD383432]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDeleteValueKey [0xAD383910]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwDuplicateObject [0xAD38300A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenKey [0xAD38350C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenProcess [0xAD382F4A]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwOpenThread [0xAD382FAE]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwQueryValueKey [0xAD38362C]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwRestoreKey [0xAD3835EC]
SSDT \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwSetValueKey [0xAD38376C]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xAD43EF20]

---- Kernel code sections - GMER 1.0.15 ----

.rsrc C:\WINDOWS\system32\drivers\atapi.sys entry point in ".rsrc" section [0xF7325780]
.text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xF638A000, 0x19DA46, 0xE8000020]

---- User IAT/EAT - GMER 1.0.15 ----

IAT C:\WINDOWS\system32\services.exe[900] @ C:\WINDOWS\system32\services.exe [ADVAPI32.dll!CreateProcessAsUserW] 00380002
IAT C:\WINDOWS\system32\services.exe[900] @ C:\WINDOWS\system32\services.exe [KERNEL32.dll!CreateProcessW] 00380000

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs aswMon2.SYS (avast! File System Filter Driver for Windows XP/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Ip aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\Tcp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

Device \Driver\atapi \Device\Ide\IdePort0 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdePort1 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdePort2 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdePort3 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdePort4 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdePort5 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-16 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdeDeviceP5T0L0-b [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}

AttachedDevice \Driver\Tcpip \Device\Udp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice \Driver\Tcpip \Device\RawIp aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)

---- Registry - GMER 1.0.15 ----

Reg HKLM\SOFTWARE\Classes\CLSID\{089E6823-B8BE-478A-BD90-D4B8DDC332DE}\InprocServer32@ C:\PROGRA~1\MICROS~2\OFFICE11\IEAWSDC.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{089E6823-B8BE-478A-BD90-D4B8DDC332DE}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{089E6823-B8BE-478A-BD90-D4B8DDC332DE}\ProgID@ Office.awsdc.1
Reg HKLM\SOFTWARE\Classes\CLSID\{089E6823-B8BE-478A-BD90-D4B8DDC332DE}\TypeLib@ {012F24C1-35B0-11D0-BF2D-0000E8D0D146}
Reg HKLM\SOFTWARE\Classes\CLSID\{089E6823-B8BE-478A-BD90-D4B8DDC332DE}\Version@ 1.0
Reg HKLM\SOFTWARE\Classes\CLSID\{089E6823-B8BE-478A-BD90-D4B8DDC332DE}\VersionIndependentProgID@ Office.awsdc
Reg HKLM\SOFTWARE\Classes\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}\TreatAs@ {63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}
Reg HKLM\SOFTWARE\Classes\CLSID\{284F0BD5-81D1-7456-EF12-DF58AD1383B6}\InprocServer32@ C:\WINDOWS\system32\PortableDeviceTypes.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{284F0BD5-81D1-7456-EF12-DF58AD1383B6}\InprocServer32@ThreadingModel Both
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\LocalServer32@ C:\PROGRA~1\MICROS~2\OFFICE11\MSPUB.EXE /Automation
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\LocalServer32@LocalServer32 *]gAVn-}f(ZXfeAR6.jiPubPrimary>dic+V~SM09P_'_@$%)xK /Automation?
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\NotInsertable@
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\ProgID@ Publisher.Application.11
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\Programmable@
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\TypeLib@ {0002123C-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\VersionIndependentProgID@ Publisher.Application
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xC8 0x28 0x51 0xAF ...
Reg HKLM\SOFTWARE\Classes\CLSID\{5FA45BED-077A-9079-9181-7DC47626297F}\InprocServer32@ C:\Program Files\Fichiers communs\Microsoft Shared\Information Retrieval\ITIRCL52.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{5FA45BED-077A-9079-9181-7DC47626297F}\InprocServer32@InprocServer32 *]gAVn-}f(ZXfeAR6.jiTranslationHidden>BbxH8x=!g(3?!!!_GX=b?
Reg HKLM\SOFTWARE\Classes\CLSID\{5FA45BED-077A-9079-9181-7DC47626297F}\InprocServer32@ThreadingModel both
Reg HKLM\SOFTWARE\Classes\CLSID\{5FA45BED-077A-9079-9181-7DC47626297F}\ProgID@ ITIR.DefaultStemmer.5.2
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x71 0x3B 0x04 0x66 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0xFF 0x7C 0x85 0xE0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x86 0x8C 0x21 0x01 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xF5 0x1D 0x4D 0x73 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xB0 0x18 0xED 0xA7 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\DefaultIcon@ C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE,7
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\InprocServer32@ C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\Shell\Open
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\Shell\Open\Command
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\Shell\Open\Command@ "C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE"
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\shellex\PropertySheetHandlers
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\shellex\PropertySheetHandlers\{00020D75-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\shellex\PropertySheetHandlers\{00020D75-0000-0000-C000-000000000046}@
Reg HKLM\SOFTWARE\Classes\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3}\TreatAs@ {A9571378-68A1-443d-B082-284F960C6D17}
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\InprocServer32@ C:\Program Files\Google\Google Earth\plugin\plugin_ax.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\InprocServer32@ThreadingModel apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\MiscStatus@ 0
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\MiscStatus\1
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\MiscStatus\1@ 131473
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\ProgID@ KmlLayerRootCoClass.KmlLayerRootCoC.1.0
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\ToolboxBitmap32@ C:\Program Files\Google\Google Earth\plugin\plugin_ax.dll, 1
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\TypeLib@ {F9152AEC-3462-4632-8087-EEE3C3CDDA35}
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\Version@ 1.0
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\VersionIndependentProgID@ KmlLayerRootCoClass.KmlLayerRootCoC
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0x31 0x77 0xE1 0xBA ...
Reg HKLM\SOFTWARE\Classes\CLSID\{D9C47CD5-9B59-C3BF-FC64-7B1564692D75}\InProcServer32@ %SystemRoot%\system32\dsuiext.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{D9C47CD5-9B59-C3BF-FC64-7B1564692D75}\InProcServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{D9C47CD5-9B59-C3BF-FC64-7B1564692D75}\ShellEx\MayChangeDefaultMenu
Reg HKLM\SOFTWARE\Classes\CLSID\{D9C47CD5-9B59-C3BF-FC64-7B1564692D75}\ShellEx\MayChangeDefaultMenu@ 1
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x83 0x6C 0x56 0x8B ...
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0xF6 0x0F 0x4E 0x58 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0xB1 0xCD 0x45 0x5A ...
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0xE3 0x0E 0x66 0xD5 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0xFA 0xEA 0x66 0x7F ...
Reg HKLM\SOFTWARE\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid@ {00020420-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid32@ {00020420-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib@ {29D67D3C-509A-4544-903F-C8C1B8236554}
Reg HKLM\SOFTWARE\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib@Version 1.0
Reg HKLM\SOFTWARE\Classes\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ProxyStubClsid@ {00020424-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ProxyStubClsid32@ {00020424-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\TypeLib@ {E47CAEE0-DEEA-464A-9326-3F2801535A4D}
Reg HKLM\SOFTWARE\Classes\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\TypeLib@Version 1.0
Reg HKLM\SOFTWARE\Classes\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\ProxyStubClsid@ {00020424-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\ProxyStubClsid32@ {00020424-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\TypeLib@ {D518921A-4A03-425E-9873-B9A71756821E}
Reg HKLM\SOFTWARE\Classes\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\TypeLib@Version 1.0
Reg HKLM\SOFTWARE\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0@ HtmldocPlugin 1.0 Type Library
Reg HKLM\SOFTWARE\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\0
Reg HKLM\SOFTWARE\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\0\win32
Reg HKLM\SOFTWARE\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\0\win32@ C:\Program Files\MyWebSearch\bar\2.bin\F3REPROX.DLL
Reg HKLM\SOFTWARE\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\FLAGS
Reg HKLM\SOFTWARE\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\FLAGS@ 0
Reg HKLM\SOFTWARE\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\HELPDIR
Reg HKLM\SOFTWARE\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\HELPDIR@ C:\Program Files\MyWebSearch\bar\2.bin\

---- Files - GMER 1.0.15 ----

File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

---- EOF - GMER 1.0.15 ----

Merci!
0
dédétraqué Messages postés 4384 Date d'inscription vendredi 5 septembre 2008 Statut Contributeur sécurité Dernière intervention 4 février 2013 286
26 avril 2010 à 00:24
Salut mia928


On a un fichier système patché (modifié), on va tenter d'en trouver un sain sur le PC:

Télécharge SystemLook sur ton Bureau :
http://jpshortstuff.247fixes.com/SystemLook.exe

- Double-clique sur SystemLook.exe pour le lancer.

- Copie le contenu en gras ci-dessous et colle-le dans la zone texte de SystemLook :

:filefind
atapi.sys


- Clique sur le bouton Look pour démarrer l'examen.
- A la fin, le Bloc-notes s'ouvre avec le résultat de l'analyse. Copie-colle le rapport dans ta prochaine réponse.


@++ :)
0
Salut dédétraqué
Voici le rapport:

SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 16:41 on 26/04/2010 by Zamboni (Administrator - Elevation successful)

========== filefind ==========

Searching for "atapi.sys "
C:\WINDOWS\$NtServicePackUninstall$\atapi.sys -----c 95360 bytes [18:02 17/10/2008] [01:59 04/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51
C:\WINDOWS\ERDNT\cache\atapi.sys --a--- 96512 bytes [20:09 21/04/2010] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674
C:\WINDOWS\ServicePackFiles\i386\atapi.sys -----c 96512 bytes [18:40 13/04/2008] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674
C:\WINDOWS\system32\drivers\atapi.sys --a--- 96512 bytes [12:00 02/03/2006] [18:40 13/04/2008] 9F3A2F5AA6875C72BF062C712CFA2674
C:\WINDOWS\system32\drivers\system32\DRIVERS\atapi.sys --a--c 95360 bytes [06:15 03/07/2008] [12:00 02/03/2006] CDFE4411A69C224BD1D11B2DA92DAC51
C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys --a--c 95360 bytes [06:15 03/07/2008] [12:00 02/03/2006] CDFE4411A69C224BD1D11B2DA92DAC51
C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys --a--c 95360 bytes [06:15 03/07/2008] [01:59 04/08/2004] CDFE4411A69C224BD1D11B2DA92DAC51

-=End Of File=-

Merci!
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
dédétraqué Messages postés 4384 Date d'inscription vendredi 5 septembre 2008 Statut Contributeur sécurité Dernière intervention 4 février 2013 286
27 avril 2010 à 00:46
Salut mia928


Faire un scan de ce fichier atapi.sys ici :

https://www.virustotal.com/gui/


Clique sur Parcourir et copie/colle ceci :
C:\WINDOWS\ServicePackFiles\i386\atapi.sys
Après tu clique sur Envoyer le fichier et attendre le résultat de l'analyse.

Si il te dit que le fichier a déjà été analysé, sélectionne le bouton :
Reanalyse le fichier maintenant et attendre le résultat de l'analyse, poste le résultat au complet.

Poste le résultat au complet

Aide : http://bibou0007.com/scans-en-ligne-f75/tutorial-sur-virustotal-t190.htm


@++ :)
0
Salut dédétraqué

Voici le résultat:

Antivirus Version Dernière mise à jour Résultat
a-squared 4.5.0.50 2010.04.26 -
AhnLab-V3 5.0.0.2 2010.04.26 -
AntiVir 8.2.1.224 2010.04.26 -
Antiy-AVL 2.0.3.7 2010.04.26 -
Authentium 5.2.0.5 2010.04.26 -
Avast 4.8.1351.0 2010.04.26 -
Avast5 5.0.332.0 2010.04.26 -
AVG 9.0.0.787 2010.04.26 -
BitDefender 7.2 2010.04.27 -
CAT-QuickHeal 10.00 2010.04.26 -
ClamAV 0.96.0.3-git 2010.04.27 -
Comodo 4684 2010.04.26 -
DrWeb 5.0.2.03300 2010.04.27 -
eSafe 7.0.17.0 2010.04.26 Win32.Rootkit
eTrust-Vet 35.2.7452 2010.04.26 -
F-Prot 4.5.1.85 2010.04.26 -
F-Secure 9.0.15370.0 2010.04.26 -
Fortinet 4.0.14.0 2010.04.26 -
GData 21 2010.04.27 -
Ikarus T3.1.1.80.0 2010.04.26 -
Jiangmin 13.0.900 2010.04.26 -
Kaspersky 7.0.0.125 2010.04.26 -
McAfee 5.400.0.1158 2010.04.27 -
McAfee-GW-Edition 6.8.5 2010.04.26 -
Microsoft 1.5703 2010.04.27 -
NOD32 5063 2010.04.26 -
Norman 6.04.11 2010.04.26 -
nProtect 2010-04-26.01 2010.04.26 -
Panda 10.0.2.7 2010.04.26 -
PCTools 7.0.3.5 2010.04.26 -
Prevx 3.0 2010.04.27 -
Rising 22.45.00.04 2010.04.26 -
Sophos 4.53.0 2010.04.27 -
Sunbelt 6225 2010.04.26 -
Symantec 20091.2.0.41 2010.04.26 -
TheHacker 6.5.2.0.269 2010.04.26 -
TrendMicro 9.120.0.1004 2010.04.26 -
TrendMicro-HouseCall 9.120.0.1004 2010.04.27 -
VBA32 3.12.12.4 2010.04.26 -
ViRobot 2010.4.26.2294 2010.04.26 -
VirusBuster 5.0.27.0 2010.04.26 -
Information additionnelle
File size: 96512 bytes
MD5...: 9f3a2f5aa6875c72bf062c712cfa2674
SHA1..: a719156e8ad67456556a02c34e762944234e7a44
SHA256: b4df1d2c56a593c6b54de57395e3b51d288f547842893b32b0f59228a0cf70b9
ssdeep: 1536:MwXpkfV74F1D7yNEZIHRRJMohmus27G1j/XBoDQi7oaRMJfYHFktprll1Kb
DD0uu:MQ+N74vkEZIxMohjsimBoDTRMBwFktZu
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x159f7
timedatestamp.....: 0x4802539d (Sun Apr 13 18:40:29 2008)
machinetype.......: 0x14c (I386)

( 9 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x380 0x97ba 0x9800 6.45 0d7d81391f33c6450a81be1e3ac8c7b7
NONPAGE 0x9b80 0x18e8 0x1900 6.48 c74a833abd81cc5d037de168e055ad29
.rdata 0xb480 0xa64 0xa80 4.31 8523651899e28819a14bf9415af25708
.data 0xbf00 0xd94 0xe00 0.45 3575b51634ae7a56f55f1ee0a6213834
PAGESCAN 0xcd00 0x157f 0x1580 6.20 dc4c309c4db9576daa752fdd125fccf9
PAGE 0xe280 0x61da 0x6200 6.46 40b83d4d552384e58a03517a98eb4863
INIT 0x14480 0x22be 0x2300 6.47 906462abc478368424ea462d5868d2e3
.rsrc 0x16780 0x3e0 0x400 3.36 8fd2d82e745b289c28bc056d3a0d62ab
.reloc 0x16b80 0xd20 0xd80 6.39 ce2b0898cc0e40b618e5df9099f6be45

( 3 imports )
> ntoskrnl.exe: RtlInitUnicodeString, swprintf, KeSetEvent, IoCreateSymbolicLink, IoGetConfigurationInformation, IoDeleteSymbolicLink, MmFreeMappingAddress, IoFreeErrorLogEntry, IoDisconnectInterrupt, MmUnmapIoSpace, ObReferenceObjectByPointer, IofCompleteRequest, RtlCompareUnicodeString, IofCallDriver, MmAllocateMappingAddress, IoAllocateErrorLogEntry, IoConnectInterrupt, IoDetachDevice, KeWaitForSingleObject, KeInitializeEvent, KeCancelTimer, RtlAnsiStringToUnicodeString, RtlInitAnsiString, IoBuildDeviceIoControlRequest, IoQueueWorkItem, MmMapIoSpace, IoInvalidateDeviceRelations, IoReportDetectedDevice, IoReportResourceForDetection, RtlxAnsiStringToUnicodeSize, NlsMbCodePageTag, PoRequestPowerIrp, KeInsertByKeyDeviceQueue, PoRegisterDeviceForIdleDetection, sprintf, MmMapLockedPagesSpecifyCache, ObfDereferenceObject, IoGetAttachedDeviceReference, IoInvalidateDeviceState, ZwClose, ObReferenceObjectByHandle, ZwCreateDirectoryObject, IoBuildSynchronousFsdRequest, PoStartNextPowerIrp, IoCreateDevice, RtlCopyUnicodeString, IoAllocateDriverObjectExtension, RtlQueryRegistryValues, ZwOpenKey, RtlFreeUnicodeString, IoStartTimer, KeInitializeTimer, IoInitializeTimer, KeInitializeDpc, KeInitializeSpinLock, IoInitializeIrp, ZwCreateKey, RtlAppendUnicodeStringToString, RtlIntegerToUnicodeString, ZwSetValueKey, KeInsertQueueDpc, KefAcquireSpinLockAtDpcLevel, IoStartPacket, KefReleaseSpinLockFromDpcLevel, IoBuildAsynchronousFsdRequest, IoFreeMdl, MmUnlockPages, IoWriteErrorLogEntry, KeRemoveByKeyDeviceQueue, MmMapLockedPagesWithReservedMapping, MmUnmapReservedMapping, KeSynchronizeExecution, IoStartNextPacket, KeBugCheckEx, KeRemoveDeviceQueue, KeSetTimer, _allmul, MmProbeAndLockPages, _except_handler3, PoSetPowerState, IoOpenDeviceRegistryKey, RtlWriteRegistryValue, RtlDeleteRegistryValue, _aulldiv, strstr, _strupr, KeQuerySystemTime, IoWMIRegistrationControl, KeTickCount, IoAttachDeviceToDeviceStack, IoDeleteDevice, ExAllocatePoolWithTag, IoAllocateWorkItem, IoAllocateIrp, IoAllocateMdl, MmBuildMdlForNonPagedPool, MmLockPagableDataSection, IoGetDriverObjectExtension, MmUnlockPagableImageSection, ExFreePoolWithTag, IoFreeIrp, IoFreeWorkItem, InitSafeBootMode, RtlCompareMemory, PoCallDriver, memmove, MmHighestUserAddress
> HAL.dll: KfAcquireSpinLock, READ_PORT_UCHAR, KeGetCurrentIrql, KfRaiseIrql, KfLowerIrql, HalGetInterruptVector, HalTranslateBusAddress, KeStallExecutionProcessor, KfReleaseSpinLock, READ_PORT_BUFFER_USHORT, READ_PORT_USHORT, WRITE_PORT_BUFFER_USHORT, WRITE_PORT_UCHAR
> WMILIB.SYS: WmiSystemControl, WmiCompleteRequest

( 0 exports )
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: Win32 Executable Generic (68.0%)
Generic Win/DOS Executable (15.9%)
DOS Executable Generic (15.9%)
Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
packers (Kaspersky): PE_Patch
sigcheck:
publisher....: Microsoft Corporation
copyright....: (c) Microsoft Corporation. All rights reserved.
product......: Microsoft_ Windows_ Operating System
description..: IDE/ATAPI Port Driver
original name: atapi.sys
internal name: atapi.sys
file version.: 5.1.2600.5512 (xpsp.080413-2108)
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned


Merci!
0
dédétraqué Messages postés 4384 Date d'inscription vendredi 5 septembre 2008 Statut Contributeur sécurité Dernière intervention 4 février 2013 286
27 avril 2010 à 04:39
Salut mia928


- Clique sur le menu démarrer/Exécuter, tape notepad à l'invite de commande et OK.

- Copie/colle ce qui est en gras ci-dessous dans le Bloc-Notes :

KillAll::

Mbr::

FCopy::
C:\WINDOWS\ServicePackFiles\i386\atapi.sys | C:\WINDOWS\system32\drivers\atapi.sys

RegLockDel::
[HKEY_USERS\S-1-5-21-117609710-838170752-839522115-1007\Software\FunWebProducts\Settings\MSNMessenger]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}\TreatAs]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3}\TreatAs]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ProxyStubClsid]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\ProxyStubClsid]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0]
[HKEY_LOCAL_MACHINE\software\Fun Web Products\MSNMessenger]
[HKEY_LOCAL_MACHINE\software\Fun Web Products\ScreenSaver]
[HKEY_LOCAL_MACHINE\software\Fun Web Products\Settings]
[HKEY_LOCAL_MACHINE\software\FunWebProducts\Installer]
[HKEY_LOCAL_MACHINE\software\MyWebSearch\bar]
[HKEY_LOCAL_MACHINE\software\MyWebSearch\SearchAssistant]
[HKEY_LOCAL_MACHINE\software\MyWebSearch\SkinTools]


- Enregistre ce fichier sur le bureau (Impératif)

-Nom du fichier : CFScript.txt
-Type du fichier : tous les fichiers

- Clique sur Enregistrer et quitte le Bloc Notes

Important Désactive ton Antivirus et antispyware avant de faire le glisser/déposer

- Fait un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe sur le bureau, comme sur cette capture (l'icône est un lion) :

http://free0.hiboox.com/images/2409/9126d3b136f7db9ab6242ad715b44296.gif

* Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises: c'est normal!
Ne touche à rien tant que le scan n'est pas terminé.
* Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
* Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt


@++ :)
0
Salut dédétraqué

Voici le rapport:

ComboFix 10-04-26.02 - Zamboni 2010-04-27 0:21.2.2 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.2.1036.18.3071.2608 [GMT -3:00]
Lancé depuis: c:\documents and settings\Zamboni\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\Zamboni\Bureau\CFScript.txt
AV: avast! antivirus 4.8.1296 [VPS 090807-0] *On-access scanning disabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

.
--------------- FCopy ---------------

c:\windows\ServicePackFiles\i386\atapi.sys --> c:\windows\system32\drivers\atapi.sys
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-03-27 au 2010-04-27 ))))))))))))))))))))))))))))))))))))
.

2010-04-20 23:45 . 2010-04-20 23:45 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-04-20 23:44 . 2010-04-20 23:44 79488 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\jre1.6.0_20\gtapi.dll
2010-04-20 23:44 . 2010-04-20 23:44 152576 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\jre1.6.0_20\lzma.dll
2010-04-20 02:12 . 2010-04-20 02:12 -------- d-----w- c:\program files\ESET
2010-04-18 23:56 . 2010-04-20 23:27 -------- d-----w- c:\program files\trend micro
2010-04-16 21:16 . 2010-04-16 21:16 -------- d-----w- c:\program files\Ares
2010-04-13 10:26 . 2010-04-13 10:26 -------- d-----w- c:\program files\iPod
2010-04-13 10:26 . 2010-04-13 10:27 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-04-13 10:24 . 2010-04-13 10:24 -------- d-----w- c:\program files\QuickTime
2010-04-13 10:22 . 2010-04-13 10:22 -------- d-----w- c:\program files\Bonjour
2010-04-13 10:20 . 2010-04-13 10:20 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.1.0.79\SetupAdmin.exe
2010-04-10 22:30 . 2010-04-10 22:30 532 ----a-w- c:\windows\eReg.dat
2010-04-10 22:29 . 2010-04-10 22:29 -------- d-----w- c:\program files\Maxis

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-20 23:47 . 2008-07-03 19:45 -------- d-----w- c:\program files\CCleaner
2010-04-20 23:37 . 2008-07-03 19:46 -------- d-----w- c:\program files\Fichiers communs\Adobe
2010-04-18 23:14 . 2009-02-14 00:15 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-04-17 00:31 . 2008-08-14 20:43 -------- d-----w- c:\program files\Fichiers communs\DVDVIDEOSOFT
2010-04-16 21:26 . 2010-03-08 00:58 -------- d-----w- c:\documents and settings\Zamboni\Application Data\LimeWire
2010-04-16 21:07 . 2009-02-24 21:15 -------- d-----w- c:\program files\Google
2010-04-13 10:27 . 2008-12-28 12:06 -------- d-----w- c:\program files\iTunes
2010-04-13 10:26 . 2008-12-28 12:05 -------- d-----w- c:\program files\Fichiers communs\Apple
2010-03-23 02:46 . 2010-02-05 21:26 50354 ----a-w- c:\documents and settings\Zamboni\Application Data\Facebook\uninstall.exe
2010-03-23 02:46 . 2010-02-05 21:26 -------- d-----w- c:\documents and settings\Zamboni\Application Data\Facebook
2010-03-15 03:49 . 2010-03-15 03:49 -------- d-----w- c:\program files\Fichiers communs\Java
2010-03-15 03:49 . 2010-03-15 03:49 503808 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-10733cf8-n\msvcp71.dll
2010-03-15 03:49 . 2010-03-15 03:49 499712 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-10733cf8-n\jmc.dll
2010-03-15 03:49 . 2010-03-15 03:49 348160 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-10733cf8-n\msvcr71.dll
2010-03-15 03:49 . 2010-03-15 03:49 61440 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-28a3a294-n\decora-sse.dll
2010-03-15 03:49 . 2010-03-15 03:49 12800 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-28a3a294-n\decora-d3d.dll
2010-03-15 03:49 . 2009-02-16 10:37 -------- d-----w- c:\program files\Java
2010-03-15 03:48 . 2006-03-02 12:00 85608 ----a-w- c:\windows\system32\perfc00C.dat
2010-03-15 03:48 . 2006-03-02 12:00 513410 ----a-w- c:\windows\system32\perfh00C.dat
2010-03-14 16:48 . 2009-11-11 17:56 79488 ----a-w- c:\documents and settings\Zamboni\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-03-11 12:34 . 2006-03-02 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
2010-03-11 12:34 . 2009-10-27 15:14 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:34 . 2006-03-02 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2010-03-09 11:10 . 2006-03-02 12:00 430080 ----a-w- c:\windows\system32\vbscript.dll
2010-03-08 01:03 . 2010-03-08 01:03 -------- d-----w- c:\documents and settings\All Users\Application Data\SiComponents
2010-03-06 05:30 . 2010-03-06 05:30 5582848 ----a-w- c:\documents and settings\Zamboni\Application Data\Facebook\npfbplugin_1_0_3.dll
2010-03-03 20:36 . 2010-02-17 01:14 -------- d-----w- c:\documents and settings\Zamboni\Application Data\FrostWire
2010-02-24 13:11 . 2006-03-02 12:00 455680 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-17 01:32 . 2010-02-17 01:32 0 -c--a-w- c:\documents and settings\Zamboni\Application Data\FrostWire\.NetworkShare\Incomplete\T-4506256-LimeWireWin4.16.6.exe
2010-02-16 19:06 . 2006-03-02 12:00 2148352 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 19:06 . 2004-08-19 16:04 2026496 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 14:46 . 2010-02-12 14:46 91424 ----a-w- c:\windows\system32\dnssd.dll
2010-02-12 14:46 . 2010-02-12 14:46 107808 ----a-w- c:\windows\system32\dns-sd.exe
2010-02-12 04:34 . 2006-03-02 12:00 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:02 . 2006-03-02 12:00 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
2010-02-09 20:14 . 2008-08-30 20:17 58402 -c--a-w- c:\windows\War3Unin.dat
2010-02-08 01:42 . 2010-02-08 01:42 180224 ----a-w- c:\windows\system32\WinVd32.sys
2010-02-08 01:42 . 2010-02-08 01:42 7680 ----a-w- c:\windows\system32\WinFLsrv.exe
2010-02-01 22:04 . 2010-02-01 22:04 847040 ----a-w- c:\documents and settings\Zamboni\Application Data\Facebook\axfbootloader.dll
2010-02-01 22:04 . 2010-02-01 22:04 5578752 ----a-w- c:\documents and settings\Zamboni\Application Data\Facebook\npfbplugin_1_0_1.dll
2010-01-28 12:19 . 2010-01-24 18:58 21035 ----a-w- c:\windows\system32\drivers\AegisP.sys
2008-11-02 21:06 . 2008-11-02 21:06 89408 -c--a-w- c:\program files\setup spiral frog.exe
2008-09-30 01:36 . 2008-09-30 01:36 5408074 -c--a-w- c:\program files\Last.fm-1.5.2.38918.exe
2008-08-14 19:17 . 2008-08-14 19:17 611424 -c--a-w- c:\program files\setuppad.exe
2008-08-02 05:35 . 2008-08-02 05:35 1283912 -c--a-w- c:\program files\WoW-2.3.0.7561-enUS-downloader.exe
.

((((((((((((((((((((((((((((( SnapShot@2010-04-21_20.09.18 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-04-27 03:28 . 2010-04-27 03:28 16384 c:\windows\Temp\Perflib_Perfdata_770.dat
+ 2010-04-27 03:28 . 2010-04-27 03:28 16384 c:\windows\Temp\Perflib_Perfdata_690.dat
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\377081.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\32b118b.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\2f56995.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\2693f.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\22440a9.msp
+ 2005-08-22 05:29 . 2005-08-22 05:29 103434240 c:\windows\Installer\1f43884.msp
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Fichiers communs\LightScribe\LightScribeControlPanel.exe" [2007-08-23 455968]
"msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-01-15 1830128]
"WeatherEye"="c:\documents and settings\Zamboni\Local Settings\Application Data\TheWeatherNetwork\WeatherEye\WeatherEye.exe" [2009-10-27 718232]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VM30xSnap"="VM30xSnap.exe Vimicro USB PC Camera (ZC030x)" [X]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-08-14 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-08-14 114688]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-08-14 94208]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-06 54832]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"Window UDP Control Servic"="winlogon.exe" [2008-04-14 512000]
"SlipStream"="c:\program files\Netscape Accélérateur\slipcore.exe" [2006-04-06 237568]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-03-26 142120]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2010-04-02 40368]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2010-02-18 248040]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Menu D'marrer\Programmes\D'marrage\
Belkin Wireless G Desktop Card Client Utility.lnk - c:\program files\Belkin\F5D7000v7032\Belkinwcui.exe [2010-1-28 1560576]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HonorAutoRunSetting"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"HonorAutoRunSetting"= 0 (0x0)

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 15:05 356352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-04-02 18:05 40368 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
2005-05-03 18:43 69632 -c----r- c:\windows\Alcmtr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
2007-08-23 20:36 455968 ----a-w- c:\program files\Fichiers communs\LightScribe\LightScribeControlPanel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
2007-04-10 15:28 16126464 -c----r- c:\windows\RTHDCPL.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
2007-04-04 17:22 1822720 -c----r- c:\windows\SkyTel.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
2008-01-21 15:17 61440 -c--a-w- c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AresChatServer"=3 (0x3)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\All Users\\Documents\\Warcraft III\\Warcraft III.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Documents and Settings\\All Users\\Documents\\Warcraft III\\War3.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=

R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-07-04 111184]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-01-15 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-01-15 55024]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-07-04 20560]
R2 WinFLdrv;WinFLdrv;c:\windows\system32\WinFLdrv.sys [2010-02-07 17984]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;c:\windows\system32\drivers\atl01_xp.sys [2008-07-03 35840]
R3 Belkin700F;Belkin Wireless G Desktop Card Service v7;c:\windows\system32\drivers\BLKWGDv7.sys [2010-01-24 303616]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-01-15 7408]
R3 VM30xx86;Vimicro USB PC Camera (ZC030x);c:\windows\system32\drivers\vm30xx86.sys [2009-02-24 1294336]
S2 gupdate1c996c4f9b01916;Google Update Service (gupdate1c996c4f9b01916);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-24 133104]
S3 SjyPkt;SjyPkt;\??\c:\windows\System32\Drivers\SjyPkt.sys --> c:\windows\System32\Drivers\SjyPkt.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
2007-08-23 20:34 451872 ----a-w- c:\program files\Fichiers communs\LightScribe\LSRunOnce.exe
.
Contenu du dossier 'Tâches planifiées'

2010-04-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]

2010-04-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-24 21:15]

2010-04-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-02-24 21:15]

2010-04-27 c:\windows\Tasks\User_Feed_Synchronization-{1976200C-4A2E-4FAC-9D4C-74B0D23C66DA}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 21:36]
.
.
0
------- Examen supplémentaire -------
.
uStart Page = hxxp://facebook.com/
uInternet Settings,ProxyOverride = *.local
IE: Save YouTube Video - c:\program files\Fichiers communs\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP4.htm
IE: Save YouTube Video as MP3 - c:\program files\Fichiers communs\DVDVideoSoft\Dll\IEContextMenuY.dll/scriptY2MP3.htm
LSP: c:\progra~1\NETSCA~2\sliplsp.dll
DPF: {D40F5876-A494-4124-8161-82625BB28C06} - hxxp://download.playfirst.com/play/game/chocolatier2/Chocolatier2Web.1.0.0.10.cab
FF - ProfilePath - c:\documents and settings\Zamboni\Application Data\Mozilla\Firefox\Profiles\q7i78nx0.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.facebook.com/
FF - component: c:\documents and settings\Zamboni\Application Data\Mozilla\Firefox\Profiles\q7i78nx0.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\documents and settings\Zamboni\Application Data\Facebook\npfbplugin_1_0_1.dll
FF - plugin: c:\documents and settings\Zamboni\Application Data\Facebook\npfbplugin_1_0_3.dll
FF - plugin: c:\documents and settings\Zamboni\Application Data\Mozilla\Firefox\Profiles\q7i78nx0.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "https://www.mozilla.org/en-US/firefox/new/?redirect_source=firefox-com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-04-27 00:31
Windows 5.1.2600 Service Pack 3 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...


c:\windows\system32\sys_drv.dat 6024 bytes
c:\windows\system32\sys_drv_2.dat 5020 bytes
c:\windows\system32\WinFLdrv.sys 17984 bytes executable
c:\documents and settings\Zamboni\Application Data\systemfl.$dk 990 bytes

Scan terminé avec succès
Fichiers cachés: 4

**************************************************************************

Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys >>UNKNOWN [0x8AEA08C8]<<
kernel: MBR read successfully
detected MBR rootkit hooks:
\Driver\Disk -> CLASSPNP.SYS @ 0xf74cbf28
\Driver\ACPI -> ACPI.sys @ 0xf735dcb8
\Driver\atapi -> atapi.sys @ 0xf7318b3a
IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
\Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
NDIS: Belkin Wireless G Desktop Card #2 -> SendCompleteHandler -> NDIS.sys @ 0xf7221bb0
PacketIndicateHandler -> NDIS.sys @ 0xf7210a0d
SendHandler -> NDIS.sys @ 0xf7224b40
user & kernel MBR OK

**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------

[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\0\win32]
@DACL=(02 0000)
@="c:\\Program Files\\MyWebSearch\\bar\\2.bin\\F3REPROX.DLL"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø*€|ÿÿÿÿ*€|ù*9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h-€|ÿÿÿÿ¤*€|ù*9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€-€|ÿÿÿÿÀ*€|ù*9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------

- - - - - - - > 'winlogon.exe'(860)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
c:\windows\system32\Ati2evxx.dll

- - - - - - - > 'lsass.exe'(916)
c:\progra~1\NETSCA~2\sliplsp.dll
c:\windows\system32\sliprt.dll

- - - - - - - > 'explorer.exe'(204)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\drivers\CDAC11BA.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Fichiers communs\LightScribe\LSSrvc.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\windows\system32\pctspk.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Heure de fin: 2010-04-27 00:35:20 - La machine a redémarré
ComboFix-quarantined-files.txt 2010-04-27 03:35
ComboFix2.txt 2010-04-21 20:10

Avant-CF: 70 788 694 016 octets libres
Après-CF: 70 761 717 760 octets libres

- - End Of File - - 9C1DEC043E2A0D6316F5016E20E51036

Merci!
0
dédétraqué Messages postés 4384 Date d'inscription vendredi 5 septembre 2008 Statut Contributeur sécurité Dernière intervention 4 février 2013 286
28 avril 2010 à 23:38
Salut mia928


Télécharge MBR par (GMER) sur ton Bureau :

http://www2.gmer.net/mbr/mbr.exe

- Désactive tous les programmes de protection (antivirus, antispyware etc.)
https://forum.pcastuces.com/default.asp

- Double-clique sur mbr.exe > une fenêtre noire va s'ouvrir et se refermer.
- Poste le rapport mbr.log qui apparaît.


@++ :)
0
Salut dédétraqué..
Aucun rapport n'a apparu après que la fenêtre noire a disparu.. mais voici ce que la fenêtre noire avait d'inscrit:

http://tinypic.com/images/goodbye.jpg

Merci!
0
dédétraqué Messages postés 4384 Date d'inscription vendredi 5 septembre 2008 Statut Contributeur sécurité Dernière intervention 4 février 2013 286
29 avril 2010 à 02:27
Salut mia928


On va vérifier si rien de caché :

Faire un scan avec Nod32 en ligne (il faut utiliser Internet Explorer) ici :

https://www.eset.com/int/home/online-scanner/

(coche toutes les cases à chaque fois, sauf les deux dernières a la fin du scan, sinon le rapport est supprimer)
A la fin, colle le rapport : C:\Program Files\EsetOnlineScanner\log.txt


@++ :)
0
Salut dédétraqué

Voici le rapport:

ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=7.00.6000.17023 (vista_gdr.100222-0012)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=0a3b0c1e05dbe24cbf6e0778eb00c548
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2010-04-20 04:31:11
# local_time=2010-04-20 01:31:11 (-0400, Atlantique (heure d'été))
# country="Canada"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=769 16775129 100 98 0 207096428 21979802 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=108142
# found=12
# cleaned=12
# scan_time=8199
C:\UsbFix_Upload_Me_UTILISAT-3CF45A.zip multiple threats (deleted - quarantined) 00000000000000000000000000000000 C
C:\Ad-Remover\Quarantine\C\Program Files\Windows Live\Messenger\Riched20.dll.vir Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\Zamboni\Mes documents\Téléchargements\balligomingo.over.you.45026(2).exe Win32/TrojanDownloader.FakeAlert.AQI trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\Zamboni\Mes documents\Téléchargements\balligomingo.over.you.45026(3).exe Win32/TrojanDownloader.FakeAlert.AQI trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\Zamboni\Mes documents\Téléchargements\balligomingo.over.you.45026.exe Win32/TrojanDownloader.FakeAlert.AQI trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\Zamboni\Mes documents\Téléchargements\MallTycoonSetup-dm.exe Win32/Adware.Trymedia application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Documents and Settings\Zamboni\Mes documents\Téléchargements\Pet_Pals_Animal_Doctor_Setup-dm.exe Win32/Adware.Trymedia application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\System Volume Information\_restore{F61F9CA3-36E7-44DC-95CB-4D9E05BBB1AB}\RP937\A0106155.dll Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\UsbFix\Quarantine\C\DOCUME~1\Zamboni\LOCALS~1\Temp\Jxp.exe.UsbFix Win32/TrojanDownloader.FakeAlert.AQI trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\UsbFix\Quarantine\C\DOCUME~1\Zamboni\LOCALS~1\Temp\Jxq.exe.UsbFix a variant of Win32/Kryptik.DTU trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\WINDOWS\system32\spool\prtprocs\w32x86\00002262.tmp Win32/Olmarik.XO trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\_OTM\MovedFiles\04192010_221154\C_WINDOWS\Jrupya.exe Win32/TrojanDownloader.FakeAlert.AQI trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
esets_scanner_update returned -1 esets_gle=53251
# version=7
# iexplore.exe=7.00.6000.17023 (vista_gdr.100222-0012)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=0a3b0c1e05dbe24cbf6e0778eb00c548
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2010-04-20 06:51:25
# local_time=2010-04-20 03:51:25 (-0400, Atlantique (heure d'été))
# country="Canada"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=769 16775129 100 98 0 207104767 21152941 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=108405
# found=1
# cleaned=1
# scan_time=8273
C:\System Volume Information\_restore{F61F9CA3-36E7-44DC-95CB-4D9E05BBB1AB}\RP938\A0106303.exe Win32/TrojanDownloader.FakeAlert.AQI trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
# version=7
# iexplore.exe=7.00.6000.17023 (vista_gdr.100222-0012)
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=0a3b0c1e05dbe24cbf6e0778eb00c548
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2010-04-29 02:53:27
# local_time=2010-04-28 11:53:27 (-0400, Atlantique (heure d'été))
# country="Canada"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 610018 610018 0 0
# compatibility_mode=769 16775145 100 98 0 207869205 22752579 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=99737
# found=0
# cleaned=0
# scan_time=7157

Merci!
0
dédétraqué Messages postés 4384 Date d'inscription vendredi 5 septembre 2008 Statut Contributeur sécurité Dernière intervention 4 février 2013 286
1 mai 2010 à 18:28
Salut mia928


Désolé j'ai été absent deux jours sur le forum.

Le dernier rapport est propre, as-tu d'autre souci?


@++ :)
0
Salut dédétraqué

Ne t'inquiète pas pour tes absences. :)

Les pop ups n'apparaisent plus.. mais j'ai encore des redirections Google, malheureusement.

Merci!
0
dédétraqué Messages postés 4384 Date d'inscription vendredi 5 septembre 2008 Statut Contributeur sécurité Dernière intervention 4 février 2013 286
2 mai 2010 à 18:14
Salut mia928


As-tu des redirections avec IE et Firefox?


@++ :)
0
Salut dédétraqué

Oui, avec les deux navigateurs.

Merci!
0
dédétraqué Messages postés 4384 Date d'inscription vendredi 5 septembre 2008 Statut Contributeur sécurité Dernière intervention 4 février 2013 286
3 mai 2010 à 05:16
Salut mia928


Fais moi un nouveau scan avec Combofix et Gmer, poste les rapports.


@++ :)
0
Salut dédétraqué
Désolé de mon absence... :(

Mon beau-père à installer un nouveau anti-virus sur mon ordi et cela à suprimer ComboFix car le programme était malveillant.. Alors, ce ne serait pas prudent de l'installer à nouveau, non?

Entre temps, voici le rapport Gmer:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-10 15:55:55
Windows 5.1.2600 Service Pack 3
Running: z0vjw5ke.exe; Driver: C:\DOCUME~1\Zamboni\LOCALS~1\Temp\fxrorkoc.sys


---- System - GMER 1.0.15 ----

SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwOpenProcess [0xF6BF7670]
SSDT \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys (SASKUTIL.SYS/SUPERAdBlocker.com and SUPERAntiSpyware.com) ZwTerminateProcess [0xAD16AF20]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwTerminateThread [0xF6BF77C0]
SSDT \??\C:\Program Files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys (IDS Application Activity Monitor Loader Driver./AVG Technologies CZ, s.r.o. ) ZwWriteVirtualMemory [0xF6BF7860]

---- Kernel code sections - GMER 1.0.15 ----

.rsrc C:\WINDOWS\system32\drivers\atapi.sys entry point in ".rsrc" section [0xF7325780]
.text C:\WINDOWS\system32\DRIVERS\ati2mtag.sys section is writeable [0xF62F9000, 0x19DA46, 0xE8000020]

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs AVGIDSFilter.sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)

Device \Driver\atapi \Device\Ide\IdePort0 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdePort1 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdePort2 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdePort3 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdePort4 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdePort5 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdeDeviceP2T0L0-16 [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}
Device \Driver\atapi \Device\Ide\IdeDeviceP5T0L0-b [F7318B3A] atapi.sys[unknown section] {MOV EAX, [0xffdf0308]; JMP [EAX+0xac]}

AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat AVGIDSFilter.sys (IDS Application Activity Monitor Filter Driver./AVG Technologies CZ, s.r.o. )

---- Registry - GMER 1.0.15 ----

Reg HKLM\SOFTWARE\Classes\CLSID\{089E6823-B8BE-478A-BD90-D4B8DDC332DE}\InprocServer32@ C:\PROGRA~1\MICROS~2\OFFICE11\IEAWSDC.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{089E6823-B8BE-478A-BD90-D4B8DDC332DE}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{089E6823-B8BE-478A-BD90-D4B8DDC332DE}\ProgID@ Office.awsdc.1
Reg HKLM\SOFTWARE\Classes\CLSID\{089E6823-B8BE-478A-BD90-D4B8DDC332DE}\TypeLib@ {012F24C1-35B0-11D0-BF2D-0000E8D0D146}
Reg HKLM\SOFTWARE\Classes\CLSID\{089E6823-B8BE-478A-BD90-D4B8DDC332DE}\Version@ 1.0
Reg HKLM\SOFTWARE\Classes\CLSID\{089E6823-B8BE-478A-BD90-D4B8DDC332DE}\VersionIndependentProgID@ Office.awsdc
Reg HKLM\SOFTWARE\Classes\CLSID\{284F0BD5-81D1-7456-EF12-DF58AD1383B6}\InprocServer32@ C:\WINDOWS\system32\PortableDeviceTypes.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{284F0BD5-81D1-7456-EF12-DF58AD1383B6}\InprocServer32@ThreadingModel Both
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\LocalServer32@ C:\PROGRA~1\MICROS~2\OFFICE11\MSPUB.EXE /Automation
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\LocalServer32@LocalServer32 *]gAVn-}f(ZXfeAR6.jiPubPrimary>dic+V~SM09P_'_@$%)xK /Automation?
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\NotInsertable@
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\ProgID@ Publisher.Application.11
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\Programmable@
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\TypeLib@ {0002123C-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\CLSID\{35C4FFFE-BE6C-7BA5-2E99-205B388F02D7}\VersionIndependentProgID@ Publisher.Application
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32@cd042efbbd7f7af1647644e76e06692b 0xC8 0x28 0x51 0xAF ...
Reg HKLM\SOFTWARE\Classes\CLSID\{5FA45BED-077A-9079-9181-7DC47626297F}\InprocServer32@ C:\Program Files\Fichiers communs\Microsoft Shared\Information Retrieval\ITIRCL52.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{5FA45BED-077A-9079-9181-7DC47626297F}\InprocServer32@InprocServer32 *]gAVn-}f(ZXfeAR6.jiTranslationHidden>BbxH8x=!g(3?!!!_GX=b?
Reg HKLM\SOFTWARE\Classes\CLSID\{5FA45BED-077A-9079-9181-7DC47626297F}\InprocServer32@ThreadingModel both
Reg HKLM\SOFTWARE\Classes\CLSID\{5FA45BED-077A-9079-9181-7DC47626297F}\ProgID@ ITIR.DefaultStemmer.5.2
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32@bca643cdc5c2726b20d2ecedcc62c59b 0x71 0x3B 0x04 0x66 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32@2c81e34222e8052573023a60d06dd016 0xFF 0x7C 0x85 0xE0 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32@2582ae41fb52324423be06337561aa48 0x86 0x8C 0x21 0x01 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32@caaeda5fd7a9ed7697d9686d4b818472 0xF5 0x1D 0x4D 0x73 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ThreadingModel Apartment
0
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32@a4a1bcf2cc2b8bc3716b74b2b4522f5d 0xB0 0x18 0xED 0xA7 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\DefaultIcon@ C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE,7
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\InprocServer32@ C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\Shell\Open
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\Shell\Open\Command
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\Shell\Open\Command@ "C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE"
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\shellex\PropertySheetHandlers
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\shellex\PropertySheetHandlers\{00020D75-0000-0000-C000-000000000046}
Reg HKLM\SOFTWARE\Classes\CLSID\{961E2139-9A58-90A1-0365-C7FA3C64FE29}\shellex\PropertySheetHandlers\{00020D75-0000-0000-C000-000000000046}@
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\InprocServer32@ C:\Program Files\Google\Google Earth\plugin\plugin_ax.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\InprocServer32@ThreadingModel apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\MiscStatus@ 0
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\MiscStatus\1
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\MiscStatus\1@ 131473
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\ProgID@ KmlLayerRootCoClass.KmlLayerRootCoC.1.0
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\ToolboxBitmap32@ C:\Program Files\Google\Google Earth\plugin\plugin_ax.dll, 1
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\TypeLib@ {F9152AEC-3462-4632-8087-EEE3C3CDDA35}
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\Version@ 1.0
Reg HKLM\SOFTWARE\Classes\CLSID\{A4A89CDB-91EF-5D57-F4C6-A70AD0C9D045}\VersionIndependentProgID@ KmlLayerRootCoClass.KmlLayerRootCoC
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32@4d370831d2c43cd13623e232fed27b7b 0x31 0x77 0xE1 0xBA ...
Reg HKLM\SOFTWARE\Classes\CLSID\{D9C47CD5-9B59-C3BF-FC64-7B1564692D75}\InProcServer32@ %SystemRoot%\system32\dsuiext.dll
Reg HKLM\SOFTWARE\Classes\CLSID\{D9C47CD5-9B59-C3BF-FC64-7B1564692D75}\InProcServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{D9C47CD5-9B59-C3BF-FC64-7B1564692D75}\ShellEx\MayChangeDefaultMenu
Reg HKLM\SOFTWARE\Classes\CLSID\{D9C47CD5-9B59-C3BF-FC64-7B1564692D75}\ShellEx\MayChangeDefaultMenu@ 1
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32@1d68fe701cdea33e477eb204b76f993d 0x83 0x6C 0x56 0x8B ...
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32@1fac81b91d8e3c5aa4b0a51804d844a3 0xF6 0x0F 0x4E 0x58 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32@f5f62a6129303efb32fbe080bb27835b 0xB1 0xCD 0x45 0x5A ...
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32@fd4e2e1a3940b94dceb5a6a021f2e3c6 0xE3 0x0E 0x66 0xD5 ...
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ThreadingModel Apartment
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@ C:\WINDOWS\system32\OLE32.DLL
Reg HKLM\SOFTWARE\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32@8a8aec57dd6508a385616fbc86791ec2 0xFA 0xEA 0x66 0x7F ...
Reg HKLM\SOFTWARE\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0\0\win32@ C:\Program Files\MyWebSearch\bar\2.bin\F3REPROX.DLL

---- Files - GMER 1.0.15 ----

File C:\WINDOWS\system32\sys_drv.dat 6024 bytes
File C:\WINDOWS\system32\sys_drv_2.dat 5020 bytes
File C:\WINDOWS\system32\WinFLdrv.sys 17984 bytes executable <-- ROOTKIT !!!
File C:\Documents and Settings\Zamboni\Application Data\systemfl.$dk 990 bytes
File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

---- Services - GMER 1.0.15 ----

Service C:\WINDOWS\system32\WinFLdrv.sys [AUTO] WinFLdrv <-- ROOTKIT !!!

---- EOF - GMER 1.0.15 ----


Merci!
0