| Re,
essaie a nouveau combofix stp car les fichiers (infections) sont toujours present
-> Double clique combofix.exe.
-> Tape sur la touche 1 (Yes) pour démarrer le scan.
-> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
NOTE : Le rapport se trouve également ici : C:\Combofix.txt
Avant d'utiliser ComboFix :
-> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.
-> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.
Une fois fait, sur ton bureau double-clic sur Combofix.exe.
- Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.
/!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.
- En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.
- Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)
-> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.
-> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.
-> Tutoriel http://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
@+
Le meilleur moyen de faire tourner la tête à une femme, c'est de lui dire qu'elle a un joli profil Répondre à g!rly | 25 sandraemma, le 8 avr 2008 à 23:36:28Voici le rapport de combofix :
ComboFix 08-04-08.4 - sandra sandrine 2008-04-08 23:26:53.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.313 [GMT 2:00]
Endroit: C:\Users\sandra sandrine\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2008-03-08 to 2008-04-08 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier créé dans cet espace de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-08 16:46 --------- d-----w C:\ProgramData\wvuhmtgr
2008-04-08 09:35 640 ----a-w C:\Users\sandra sandrine\AppData\Roaming\wklnhst.dat
2008-04-07 19:45 --------- d-----w C:\Users\sandra sandrine\AppData\Roaming\Uniblue
2008-04-07 18:43 --------- d-----w C:\Program Files\Navilog1
2008-04-07 17:01 --------- d-----w C:\Program Files\Abbyy FineReader 6.0 Sprint
2008-04-07 16:48 --------- d-----w C:\Program Files\Google
2008-04-07 16:46 --------- d---a-w C:\ProgramData\TEMP
2008-04-07 16:33 --------- d-----w C:\Users\sandra sandrine\AppData\Roaming\Talkback
2008-04-07 15:22 --------- d-----w C:\Program Files\ItsLabel
2008-04-07 15:16 --------- d-----w C:\Program Files\lx_cats
2008-04-07 15:05 --------- d-----w C:\Users\sandra sandrine\AppData\Roaming\EoRezo
2008-04-07 15:05 --------- d-----w C:\Program Files\EoRezo
2008-04-06 18:05 --------- d-----w C:\Program Files\NeroInstall.bak
2008-04-06 17:50 --------- d-----w C:\Program Files\Common Files\Nero
2008-04-06 17:46 --------- d-----w C:\ProgramData\Nero
2008-04-06 16:41 --------- d-----w C:\Program Files\PC-Cleaner
2008-04-03 23:45 --------- d-----w C:\ProgramData\fssg
2008-04-03 22:56 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-31 21:13 --------- d-----w C:\Program Files\Torrent Search
2008-03-30 22:13 --------- d-----w C:\ProgramData\Media Center Programs
2008-03-30 20:51 --------- d-----w C:\Program Files\PC-Antispyware
2008-03-29 20:59 --------- d-----w C:\Program Files\DivX
2008-03-29 17:46 --------- d-----w C:\Users\sandra sandrine\AppData\Roaming\PC-Cleaner
2008-03-25 17:33 --------- d-----w C:\Users\sandra sandrine\AppData\Roaming\Samsung
2008-03-25 17:06 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-13 11:52 --------- d-----w C:\Program Files\Windows Mail
2008-03-13 11:46 --------- d-----w C:\ProgramData\Microsoft Help
2008-03-07 18:29 --------- d-----w C:\Users\sandra sandrine\AppData\Roaming\Apple Computer
2008-03-07 18:28 --------- d-----w C:\ProgramData\Apple Computer
2008-03-07 18:28 --------- d-----w C:\Program Files\iTunes
2008-03-07 18:28 --------- d-----w C:\Program Files\iPod
2008-03-07 18:27 --------- d-----w C:\Program Files\QuickTime
2008-03-07 18:21 --------- d-----w C:\Program Files\Common Files\Apple
2008-03-05 00:07 --------- d-----w C:\Program Files\VSO
2008-03-05 00:06 47,360 ----a-w C:\Users\sandra sandrine\AppData\Roaming\pcouffin.sys
2008-03-05 00:06 --------- d-----w C:\Users\sandra sandrine\AppData\Roaming\Vso
2008-03-04 23:59 --------- d-----w C:\Users\sandra sandrine\AppData\Roaming\DivX
2008-03-04 23:46 --------- d-----w C:\Program Files\Common Files\PX Storage Engine
2008-03-04 23:38 --------- d-----w C:\ProgramData\NtiDvdCopy
2008-02-28 16:08 --------- d-----w C:\ProgramData\LightScribe
2008-02-28 15:59 --------- d-----w C:\Users\sandra sandrine\AppData\Roaming\Nero
2008-02-28 15:54 --------- d-----w C:\Program Files\Nero
2008-02-28 15:43 --------- d-----w C:\Program Files\Ahead
2008-02-28 15:41 --------- d-----w C:\Users\sandra sandrine\AppData\Roaming\ItsLabel
2008-02-28 15:38 972,072 ----a-w C:\Windows\UNNeroMediaHome.exe
2008-02-28 14:44 --------- d-----w C:\ProgramData\Yahoo! Companion
2008-02-28 14:38 --------- d-----w C:\Program Files\Yahoo!
2008-02-28 14:01 --------- d-----w C:\ProgramData\Ahead
2008-02-28 14:01 --------- d-----w C:\Program Files\Common Files\Ahead
2008-02-28 08:59 --------- d-----w C:\Program Files\Windows Live
2008-02-26 14:14 972,072 ----a-w C:\Windows\UNRecode.exe
2008-02-21 02:03 156,992 ----a-w C:\Windows\System32\DivXCodecVersionChecker.exe
2008-02-18 14:04 95,600 ----a-w C:\Windows\System32\NeroCo.dll
2008-02-18 10:16 30,464 ----a-w C:\Windows\system32\drivers\usbaapl.sys
2008-02-13 12:58 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-02-13 12:58 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
2008-02-13 12:54 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
2008-02-13 12:54 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
2008-02-13 12:54 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-02-13 12:54 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-02-13 12:54 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-02-13 12:54 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-02-13 12:54 216,632 ----a-w C:\Windows\system32\drivers\netio.sys
2008-02-13 12:54 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
2008-02-13 12:54 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-02-13 12:54 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
2008-02-13 12:54 15,928 ----a-w C:\Windows\system32\drivers\pciide.sys
2008-02-13 12:54 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys
2008-02-13 12:53 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-13 12:53 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-13 12:53 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-02-13 12:53 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-13 12:53 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-13 12:53 1,686,528 ----a-w C:\Windows\System32\gameux.dll
2008-02-13 12:51 824,832 ----a-w C:\Windows\System32\wininet.dll
2008-02-13 12:51 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-13 12:51 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-13 12:51 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-02-11 16:36 --------- d-----w C:\Program Files\LibreSystem
2008-02-11 16:11 --------- d-----w C:\Users\sandra sandrine\AppData\Roaming\libresystem
2008-02-11 16:05 --------- d-----w C:\Program Files\Common Files\LibreSystem
2008-02-01 10:17 587,264 ----a-w C:\Windows\WLXPGSS.SCR
2008-01-10 08:13 11,776 ----a-w C:\Windows\System32\sbunattend.exe
2008-01-10 05:50 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2007-11-08 08:03 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((( snapshot@2008-04-08_23.13.59,72 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-04-08 16:49:37 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2008-04-08 21:17:18 67,584 --s-a-w C:\Windows\bootstat.dat
- 2008-04-08 21:04:52 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\UsrClass.dat
+ 2008-04-08 21:23:31 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\UsrClass.dat
- 2008-04-08 19:22:57 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
+ 2008-04-08 21:20:00 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
+ 2008-04-08 21:20:00 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2008-04-08 21:09:51 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\UsrClass.dat
+ 2008-04-08 21:23:33 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\UsrClass.dat
- 2008-04-08 16:51:59 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2008-04-08 21:19:54 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2008-04-08 21:19:54 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-04-08 20:25:30 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-04-08 21:22:48 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-04-08 20:25:30 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-04-08 21:22:48 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-04-08 20:25:30 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-04-08 21:22:48 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-04-08 19:23:39 103,726 ----a-w C:\Windows\System32\perfc009.dat
+ 2008-04-08 21:22:56 103,726 ----a-w C:\Windows\System32\perfc009.dat
- 2008-04-08 19:23:39 117,366 ----a-w C:\Windows\System32\perfc00C.dat
+ 2008-04-08 21:22:57 117,366 ----a-w C:\Windows\System32\perfc00C.dat
- 2008-04-08 19:23:39 609,944 ----a-w C:\Windows\System32\perfh009.dat
+ 2008-04-08 21:22:56 609,944 ----a-w C:\Windows\System32\perfh009.dat
- 2008-04-08 19:23:39 690,594 ----a-w C:\Windows\System32\perfh00C.dat
+ 2008-04-08 21:22:57 690,594 ----a-w C:\Windows\System32\perfh00C.dat
- 2008-04-08 16:52:01 11,454 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-781064967-1303576918-4005160290-1000_UserData.bin
+ 2008-04-08 21:19:36 11,454 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-781064967-1303576918-4005160290-1000_UserData.bin
- 2008-04-08 16:52:01 60,132 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-04-08 21:19:35 60,140 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{10F0C2A9-8E38-43e3-204D-45524C494E20}]
2008-03-29 23:42 176128 --------- C:\Program Files\PC-Antispyware\IeExtension.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-10 10:13 1232896]
"Acer Tour Reminder"="" []
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 14:35 125440]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ]
"Shareaza"="C:\Program Files\Shareaza\Shareaza.exe" [2008-01-01 18:49 4739072]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" [2008-02-28 17:07 132392]
"Uniblue RegistryBooster 2"="c:\users\sandra sandrine\desktop\registrybooster 2\StartRegistryBooster.exe" [ ]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2007-05-06 21:28:40 528384]
PCM Media Sharing.lnk - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe [2007-05-06 21:33:11 200812]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"Windows Live Toolbar"= {E1456757-0848-1684-8541-00B59958803B} - c:\program files\windows live toolbar\winrwfye2.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.mkdmp3enc"= C:\PROGRA~1\ACERAR~1\ACERVI~1\Kernel\Burner\MKDMP3Enc.ACM
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
c:\Program Files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IS CfgWiz]
c:\Program Files\Common Files\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\cltUIStb.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\osCheck]
c:\Program Files\Norton Internet Security\osCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-02-01 00:13 385024 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{3949DEB9-8DD8-42E4-A506-7B9F4A231291}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{A033DC2D-F311-40C6-91FC-22337523B865}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{F726BF72-BF4E-4B4F-B9FE-4CDF4E903131}"= C:\Program Files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live
"{51674872-C1F2-4F6E-9B9C-A757F38BE2C6}"= C:\Program Files\Acer Arcade Live\SlideShow DVD\Component\CLSLDVD.exe:SlideShow DVD workprocess
"{00717E99-5B5E-4D82-B899-5B920CE145A9}"= C:\Program Files\Acer Arcade Live\Acer DV Magician\Component\ARAWP.exe:DV Magician ARA workprocess
"{F90A806B-AED4-4244-AC78-EA10F3E4F0E6}"= C:\Program Files\Acer Arcade Live\Acer DV Magician\Component\DVAX2Process.exe:DV Magician AVAX workprocess
"{2EACCE03-44AD-4451-AFA5-833B35CC35B9}"= C:\Program Files\Acer Arcade Live\Acer DVDivine\DVDivine.exe:DVDivine
"{39E7738E-3D11-43B9-835D-D16D2F3B2B0D}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia\HomeMedia.exe:HomeMedia
"{59B339AA-E6E9-43D5-A0ED-DAC81D658E12}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\HomeMedia Connect.exe:HomeMedia Connect
"{B70C9DFF-8065-445C-8092-F386899335A3}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.EXE:HomeMedia Connect Service
"{9F52794C-B028-4208-88E2-1D78370B9A3B}"= C:\Program Files\Acer Arcade Live\Acer VideoMagician\VideoMagician.exe:VideoMagician
"{88AFEB6C-72F5-40D6-8D72-2319F5BCD35D}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{B806CE8E-B21A-495A-82E0-58D170550BFF}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{CBAA3875-8D77-428F-966D-7497308AF300}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"TCP Query User{27E9550E-7994-4E04-AB65-219D1EBED821}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{C23C3D15-DBDF-4217-BB4B-EABFBC744A51}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"{C787582F-07F3-4723-99FC-617864138FE2}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{12BF26CF-00C2-4B84-A05A-02D40C04764B}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{DDEC5FDA-FD5A-4794-B3BC-ADF65653903E}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\ImApp.exe:IncrediMail
"{99804F25-CD48-462E-90AE-DB4AF05A1314}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\ImApp.exe:IncrediMail
"{1B2F9B22-7A25-4D81-B7C3-06F364D65FF6}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\IncMail.exe:IncrediMail
"{C4062E9C-B4EA-4081-8570-BEE7A8B1EBEA}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\IncMail.exe:IncrediMail
"TCP Query User{D8619921-47E1-4CD0-BFB8-BA33A4211AE9}C:\\program files\\shareaza\\shareaza.exe"= UDP:C:\program files\shareaza\shareaza.exe:Shareaza Ultimate File Sharing
"UDP Query User{6336D062-5D3F-4095-965E-748B69114E9D}C:\\program files\\shareaza\\shareaza.exe"= TCP:C:\program files\shareaza\shareaza.exe:Shareaza Ultimate File Sharing
"{0EE64B0A-54BB-4935-932F-6D9E2CD2D6D7}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{CC3AADA1-01D0-459B-945F-2FD62748649D}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Acer\\Empowering Technology\\eDataSecurity\\eDSfsu.exe"= C:\Acer\Empowering Technology\eDataSecurity\eDSfsu.exe:*:Enabled:eDSfsu
"C:\\Acer\\Empowering Technology\\eDataSecurity\\encryption.exe"= C:\Acer\Empowering Technology\eDataSecurity\encryption.exe:*:Enabled:encryption
"C:\\Acer\\Empowering Technology\\eDataSecurity\\decryption.exe"= C:\Acer\Empowering Technology\eDataSecurity\decryption.exe:*:Enabled:decryption
R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys [2006-10-30 05:22]
R0 PSDFilter;PSDFilter;C:\Windows\system32\DRIVERS\psdfilter.sys [2007-02-07 00:04]
R0 PSDNServ;PSDNSERVER;C:\Windows\system32\drivers\PSDNServ.sys [2007-02-07 00:04]
R0 psdvdisk;psdvdisk;C:\Windows\system32\drivers\psdvdisk.sys [2007-02-07 00:04]
R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;"C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe" [2007-04-04 18:54]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2007-12-04 16:52]
R2 eDataSecurity Service;eDSService.exe;"C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe" [2007-02-07 00:04]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-03-14 16:04]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-03-23 04:12]
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2007-11-16 11:01:58 C:\Windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-08 23:30:15
Windows 6.0.6000 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-04-08 23:31:15
ComboFix-quarantined-files.txt 2008-04-08 21:30:47
ComboFix2.txt 2008-04-08 21:14:28
Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
.
2008-04-07 09:53:43 --- E O F ---
alors bien sur, j'ai eu un soucis, je sais j'ai la poisse, j'ai donc lancer combofix, ça ma donner un rapport et impossible de le retrouver pourtant j'aai ete dans le dossier comme vous m'avais dit, j'ai fait une recherche manuelle et rien pas de rapport donc j'ai refait l'analyse...
voila et encore Répondre à sandraemma |
| 26 sandraemma, le 8 avr 2008 à 23:40:29Oups, rapport de la premiere analyse retrouver :
ComboFix 08-04-08.4 - sandra sandrine 2008-04-08 23:10:25.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.281 [GMT 2:00]
Endroit: C:\Users\sandra sandrine\Desktop\ComboFix.exe
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Users\sandra sandrine\AppData\Roaming\inst.exe
C:\Users\sandra sandrine\Desktopblackbird.jpg
C:\Users\sandra sandrine\DesktopEditorFKWP1.5.exe
C:\Users\sandra sandrine\DesktopEditorFKWP2.0.exe
C:\Users\sandra sandrine\Desktopfilemanagerclient.exe
C:\Users\sandra sandrine\Desktopfkwp1.5.exe
C:\Users\sandra sandrine\Desktopfkwp2.0.exe
C:\Users\sandra sandrine\Desktopfwebd.exe
C:\Users\sandra sandrine\DesktopFWebdEditor.exe
C:\Users\sandra sandrine\DesktopTrojan.Win32.BlackBird.exe
C:\Users\sandra sandrine\Desktopvirii
C:\Windows\a.bat
C:\Windows\bdn.com
C:\Windows\fkdnrwsv.dll
C:\Windows\iTunesMusic.exe
C:\Windows\mssecu.exe
C:\Windows\system32akttzn.exe
C:\Windows\system32anticipator.dll
C:\Windows\system32awtoolb.dll
C:\Windows\system32bdn.com
C:\Windows\system32bsva-egihsg52.exe
C:\Windows\system32dpcproxy.exe
C:\Windows\system32emesx.dll
C:\Windows\system32h@tkeysh@@k.dll
C:\Windows\system32hoproxy.dll
C:\Windows\system32hxiwlgpm.dat
C:\Windows\system32hxiwlgpm.exe
C:\Windows\system32medup012.dll
C:\Windows\system32medup020.dll
C:\Windows\system32msgp.exe
C:\Windows\system32msnbho.dll
C:\Windows\system32mssecu.exe
C:\Windows\system32msvchost.exe
C:\Windows\system32mtr2.exe
C:\Windows\system32mwin32.exe
C:\Windows\system32netode.exe
C:\Windows\system32newsd32.exe
C:\Windows\system32ps1.exe
C:\Windows\system32psof1.exe
C:\Windows\system32psoft1.exe
C:\Windows\system32regc64.dll
C:\Windows\system32regm64.dll
C:\Windows\system32Rundl1.exe
C:\Windows\system32smp
C:\Windows\system32smp\msrc.exe
C:\Windows\system32sncntr.exe
C:\Windows\system32ssurf022.dll
C:\Windows\system32ssvchost.com
C:\Windows\system32ssvchost.exe
C:\Windows\system32sysreq.exe
C:\Windows\system32taack.dat
C:\Windows\system32taack.exe
C:\Windows\system32temp#01.exe
C:\Windows\system32thun.dll
C:\Windows\system32thun32.dll
C:\Windows\system32VBIEWER.OCX
C:\Windows\system32vbsys2.dll
C:\Windows\system32vcatchpi.dll
C:\Windows\system32winlogonpc.exe
C:\Windows\system32winsystem.exe
C:\Windows\system32WINWGPX.EXE
C:\Windows\Web\def.htm
.
((((((((((((((((((((((((((((( Fichiers créés 2008-03-08 to 2008-04-08 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier créé dans cet espace de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-08 16:46 --------- d-----w C:\ProgramData\wvuhmtgr
2008-04-08 09:35 640 ----a-w C:\Users\sandra sandrine\AppData\Roaming\wklnhst.dat
2008-04-07 19:45 --------- d-----w C:\Users\sandra sandrine\AppData\Roaming\Uniblue
2008-04-07 18:43 --------- d-----w C:\Program Files\Navilog1
2008-04-07 17:01 --------- d-----w C:\Program Files\Abbyy FineReader 6.0 Sprint
2008-04-07 16:48 --------- d-----w C:\Program Files\Google
2008-04-07 16:46 --------- d---a-w C:\ProgramData\TEMP
2008-04-07 16:33 --------- d-----w C:\Users\sandra sandrine\AppData\Roaming\Talkback
2008-04-07 15:22 --------- d-----w C:\Program Files\ItsLabel
2008-04-07 15:16 --------- d-----w C:\Program Files\lx_cats
2008-04-07 15:05 --------- d-----w C:\Users\sandra sandrine\AppData\Roaming\EoRezo
2008-04-07 15:05 --------- d-----w C:\Program Files\EoRezo
2008-04-06 18:05 --------- d-----w C:\Program Files\NeroInstall.bak
2008-04-06 17:50 --------- d-----w C:\Program Files\Common Files\Nero
2008-04-06 17:46 --------- d-----w C:\ProgramData\Nero
2008-04-06 16:41 --------- d-----w C:\Program Files\PC-Cleaner
2008-04-03 23:45 --------- d-----w C:\ProgramData\fssg
2008-04-03 22:56 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-31 21:13 --------- d-----w C:\Program Files\Torrent Search
2008-03-30 22:13 --------- d-----w C:\ProgramData\Media Center Programs
2008-03-30 20:51 --------- d-----w C:\Program Files\PC-Antispyware
2008-03-29 20:59 --------- d-----w C:\Program Files\DivX
2008-03-29 17:46 --------- d-----w C:\Users\sandra sandrine\AppData\Roaming\PC-Cleaner
2008-03-25 17:33 --------- d-----w C:\Users\sandra sandrine\AppData\Roaming\Samsung
2008-03-25 17:06 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-13 11:52 --------- d-----w C:\Program Files\Windows Mail
2008-03-13 11:46 --------- d-----w C:\ProgramData\Microsoft Help
2008-03-07 18:29 --------- d-----w C:\Users\sandra sandrine\AppData\Roaming\Apple Computer
2008-03-07 18:28 --------- d-----w C:\ProgramData\Apple Computer
2008-03-07 18:28 --------- d-----w C:\Program Files\iTunes
2008-03-07 18:28 --------- d-----w C:\Program Files\iPod
2008-03-07 18:27 --------- d-----w C:\Program Files\QuickTime
2008-03-07 18:21 --------- d-----w C:\Program Files\Common Files\Apple
2008-03-05 00:07 --------- d-----w C:\Program Files\VSO
2008-03-05 00:06 47,360 ----a-w C:\Users\sandra sandrine\AppData\Roaming\pcouffin.sys
2008-03-05 00:06 --------- d-----w C:\Users\sandra sandrine\AppData\Roaming\Vso
2008-03-04 23:59 --------- d-----w C:\Users\sandra sandrine\AppData\Roaming\DivX
2008-03-04 23:46 --------- d-----w C:\Program Files\Common Files\PX Storage Engine
2008-03-04 23:38 --------- d-----w C:\ProgramData\NtiDvdCopy
2008-02-28 16:08 --------- d-----w C:\ProgramData\LightScribe
2008-02-28 15:59 --------- d-----w C:\Users\sandra sandrine\AppData\Roaming\Nero
2008-02-28 15:54 --------- d-----w C:\Program Files\Nero
2008-02-28 15:43 --------- d-----w C:\Program Files\Ahead
2008-02-28 15:41 --------- d-----w C:\Users\sandra sandrine\AppData\Roaming\ItsLabel
2008-02-28 15:38 972,072 ----a-w C:\Windows\UNNeroMediaHome.exe
2008-02-28 14:44 --------- d-----w C:\ProgramData\Yahoo! Companion
2008-02-28 14:38 --------- d-----w C:\Program Files\Yahoo!
2008-02-28 14:01 --------- d-----w C:\ProgramData\Ahead
2008-02-28 14:01 --------- d-----w C:\Program Files\Common Files\Ahead
2008-02-28 08:59 --------- d-----w C:\Program Files\Windows Live
2008-02-26 14:14 972,072 ----a-w C:\Windows\UNRecode.exe
2008-02-21 02:03 156,992 ----a-w C:\Windows\System32\DivXCodecVersionChecker.exe
2008-02-18 14:04 95,600 ----a-w C:\Windows\System32\NeroCo.dll
2008-02-18 10:16 30,464 ----a-w C:\Windows\system32\drivers\usbaapl.sys
2008-02-13 12:58 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-02-13 12:58 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
2008-02-13 12:54 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
2008-02-13 12:54 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
2008-02-13 12:54 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-02-13 12:54 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-02-13 12:54 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-02-13 12:54 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-02-13 12:54 216,632 ----a-w C:\Windows\system32\drivers\netio.sys
2008-02-13 12:54 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
2008-02-13 12:54 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-02-13 12:54 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
2008-02-13 12:54 15,928 ----a-w C:\Windows\system32\drivers\pciide.sys
2008-02-13 12:54 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys
2008-02-13 12:53 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-13 12:53 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-13 12:53 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-02-13 12:53 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-13 12:53 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-13 12:53 1,686,528 ----a-w C:\Windows\System32\gameux.dll
2008-02-13 12:51 824,832 ----a-w C:\Windows\System32\wininet.dll
2008-02-13 12:51 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-13 12:51 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-13 12:51 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-02-11 16:36 --------- d-----w C:\Program Files\LibreSystem
2008-02-11 16:11 --------- d-----w C:\Users\sandra sandrine\AppData\Roaming\libresystem
2008-02-11 16:05 --------- d-----w C:\Program Files\Common Files\LibreSystem
2008-02-01 10:17 587,264 ----a-w C:\Windows\WLXPGSS.SCR
2008-01-10 08:13 11,776 ----a-w C:\Windows\System32\sbunattend.exe
2008-01-10 05:50 1,244,672 ----a-w C:\Windows\System32\mcmde.dll
2007-11-08 08:03 174 --sha-w C:\Program Files\desktop.ini
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{10F0C2A9-8E38-43e3-204D-45524C494E20}]
2008-03-29 23:42 176128 --------- C:\Program Files\PC-Antispyware\IeExtension.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-10 10:13 1232896]
"Acer Tour Reminder"="" []
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 14:35 125440]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [ ]
"Shareaza"="C:\Program Files\Shareaza\Shareaza.exe" [2008-01-01 18:49 4739072]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe" [2008-02-28 17:07 132392]
"Uniblue RegistryBooster 2"="c:\users\sandra sandrine\desktop\registrybooster 2\StartRegistryBooster.exe" [ ]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2007-05-06 21:28:40 528384]
PCM Media Sharing.lnk - C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe [2007-05-06 21:33:11 200812]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"Windows Live Toolbar"= {E1456757-0848-1684-8541-00B59958803B} - c:\program files\windows live toolbar\winrwfye2.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.mkdmp3enc"= C:\PROGRA~1\ACERAR~1\ACERVI~1\Kernel\Burner\MKDMP3Enc.ACM
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
c:\Program Files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IS CfgWiz]
c:\Program Files\Common Files\Symantec Shared\OPC\{31011D49-D90C-4da0-878B-78D28AD507AF}\cltUIStb.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\osCheck]
c:\Program Files\Norton Internet Security\osCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-02-01 00:13 385024 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{3949DEB9-8DD8-42E4-A506-7B9F4A231291}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{A033DC2D-F311-40C6-91FC-22337523B865}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{F726BF72-BF4E-4B4F-B9FE-4CDF4E903131}"= C:\Program Files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live
"{51674872-C1F2-4F6E-9B9C-A757F38BE2C6}"= C:\Program Files\Acer Arcade Live\SlideShow DVD\Component\CLSLDVD.exe:SlideShow DVD workprocess
"{00717E99-5B5E-4D82-B899-5B920CE145A9}"= C:\Program Files\Acer Arcade Live\Acer DV Magician\Component\ARAWP.exe:DV Magician ARA workprocess
"{F90A806B-AED4-4244-AC78-EA10F3E4F0E6}"= C:\Program Files\Acer Arcade Live\Acer DV Magician\Component\DVAX2Process.exe:DV Magician AVAX workprocess
"{2EACCE03-44AD-4451-AFA5-833B35CC35B9}"= C:\Program Files\Acer Arcade Live\Acer DVDivine\DVDivine.exe:DVDivine
"{39E7738E-3D11-43B9-835D-D16D2F3B2B0D}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia\HomeMedia.exe:HomeMedia
"{59B339AA-E6E9-43D5-A0ED-DAC81D658E12}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\HomeMedia Connect.exe:HomeMedia Connect
"{B70C9DFF-8065-445C-8092-F386899335A3}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.EXE:HomeMedia Connect Service
"{9F52794C-B028-4208-88E2-1D78370B9A3B}"= C:\Program Files\Acer Arcade Live\Acer VideoMagician\VideoMagician.exe:VideoMagician
"{88AFEB6C-72F5-40D6-8D72-2319F5BCD35D}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{B806CE8E-B21A-495A-82E0-58D170550BFF}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{CBAA3875-8D77-428F-966D-7497308AF300}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"TCP Query User{27E9550E-7994-4E04-AB65-219D1EBED821}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{C23C3D15-DBDF-4217-BB4B-EABFBC744A51}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"{C787582F-07F3-4723-99FC-617864138FE2}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{12BF26CF-00C2-4B84-A05A-02D40C04764B}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\ImpCnt.exe:IncrediMail
"{DDEC5FDA-FD5A-4794-B3BC-ADF65653903E}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\ImApp.exe:IncrediMail
"{99804F25-CD48-462E-90AE-DB4AF05A1314}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\ImApp.exe:IncrediMail
"{1B2F9B22-7A25-4D81-B7C3-06F364D65FF6}"= Disabled:UDP:C:\Program Files\IncrediMail\bin\IncMail.exe:IncrediMail
"{C4062E9C-B4EA-4081-8570-BEE7A8B1EBEA}"= Disabled:TCP:C:\Program Files\IncrediMail\bin\IncMail.exe:IncrediMail
"TCP Query User{D8619921-47E1-4CD0-BFB8-BA33A4211AE9}C:\\program files\\shareaza\\shareaza.exe"= UDP:C:\program files\shareaza\shareaza.exe:Shareaza Ultimate File Sharing
"UDP Query User{6336D062-5D3F-4095-965E-748B69114E9D}C:\\program files\\shareaza\\shareaza.exe"= TCP:C:\program files\shareaza\shareaza.exe:Shareaza Ultimate File Sharing
"{0EE64B0A-54BB-4935-932F-6D9E2CD2D6D7}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{CC3AADA1-01D0-459B-945F-2FD62748649D}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Acer\\Empowering Technology\\eDataSecurity\\eDSfsu.exe"= C:\Acer\Empowering Technology\eDataSecurity\eDSfsu.exe:*:Enabled:eDSfsu
"C:\\Acer\\Empowering Technology\\eDataSecurity\\encryption.exe"= C:\Acer\Empowering Technology\eDataSecurity\encryption.exe:*:Enabled:encryption
"C:\\Acer\\Empowering Technology\\eDataSecurity\\decryption.exe"= C:\Acer\Empowering Technology\eDataSecurity\decryption.exe:*:Enabled:decryption
R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys [2006-10-30 05:22]
R0 PSDFilter;PSDFilter;C:\Windows\system32\DRIVERS\psdfilter.sys [2007-02-07 00:04]
R0 PSDNServ;PSDNSERVER;C:\Windows\system32\drivers\PSDNServ.sys [2007-02-07 00:04]
R0 psdvdisk;psdvdisk;C:\Windows\system32\drivers\psdvdisk.sys [2007-02-07 00:04]
R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;"C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe" [2007-04-04 18:54]
R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2007-12-04 16:52]
R2 eDataSecurity Service;eDSService.exe;"C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe" [2007-02-07 00:04]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-03-14 16:04]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-03-23 04:12]
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2007-11-16 11:01:58 C:\Windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-08 23:13:38
Windows 6.0.6000 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-04-08 23:14:27
ComboFix-quarantined-files.txt 2008-04-08 21:14:10
Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
.
2008-04-07 09:53:43 --- E O F ---
vraiment désolé il n'etait pas dans le bon dossier il s'etait perdu Répondre à sandraemma |
|