Resalut,
Voilà les rapports:
MSNFix 1.715
C:\Users\Bassel ASBATY\Downloads\MSNFix
Fix exécuté le 06/05/2008 - 19:19:27,63 By Bassel ASBATY
mode normal
************************ Recherche les fichiers présents
Aucun Fichier trouvé
************************ Recherche les dossiers présents
Aucun dossier trouvé
************************ Fichiers suspects
/!\ ces fichiers nécessitent un avis expérimenté avant toute intervention
[C:\Windows\system32\winload.exe] 85D2C8A361D5D24DC5B06FE2119C4954
[color=#FF0000][b]==>/b/color SVP merci d'envoyer le fichier [b] C:\Users\BASSEL~1\Desktop\Upload_Me.zip /b sur http://upload.changelog.fr
************************ HKLM\...\Winlogon\Userinit
Userinit = C:\Windows\system32\userinit.exe,
------------------------------------------------------------------------
Auteur : !aur3n7 Contact: http://changelog.fr
------------------------------------------------------------------------
--------------------------------------------- END ---------------------------------------------
Malwarebytes' Anti-Malware 1.12
Version de la base de données: 724
Type de recherche: Examen complet (C:\|D:\|E:\|G:\|)
Eléments examinés: 148758
Temps écoulé: 27 minute(s), 55 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 1
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\WINDOWS\System32\nvs2.inf (Adware.EGDAccess) -> No action taken.
ComboFix 08-05-01.3 - Bassel ASBATY 2008-05-06 20:52:47.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.349 [GMT 1:00]
Running from: C:\Users\Bassel ASBATY\Desktop\killbagle.exe
* Created a new restore point
.
((((((((((((((((((((((((( Files Created from 2008-04-06 to 2008-05-06 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-06 18:34 --------- d-----w C:\Users\Bassel ASBATY\AppData\Roaming\Malwarebytes
2008-05-06 18:33 --------- d-----w C:\ProgramData\Malwarebytes
2008-05-06 18:33 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-05-06 15:28 --------- d-----w C:\Program Files\Trend Micro
2008-05-06 14:23 --------- d-----w C:\ProgramData\Symantec
2008-05-06 14:23 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-06 13:35 --------- d-----w C:\Users\Bassel ASBATY\AppData\Roaming\Grisoft
2008-05-06 13:35 --------- d-----w C:\ProgramData\Grisoft
2008-05-05 20:33 --------- d-----w C:\Program Files\DC++
2008-05-05 19:46 27,048 ----a-w C:\Windows\system32\drivers\mbamcatchme.sys
2008-05-05 19:46 15,864 ----a-w C:\Windows\system32\drivers\mbam.sys
2008-05-01 02:15 --------- d-----w C:\Program Files\Windows Mail
2008-05-01 02:08 --------- d-----w C:\ProgramData\Microsoft Help
2008-04-27 17:11 --------- d-----w C:\Users\Bassel ASBATY\AppData\Roaming\Skype
2008-04-27 17:05 --------- d-----w C:\Users\Bassel ASBATY\AppData\Roaming\skypePM
2008-04-19 20:35 --------- d-----w C:\Program Files\Naevius YouTube Converter
2008-04-19 19:56 --------- d-----w C:\Program Files\Conjugaison
2008-04-15 17:19 --------- d-----w C:\Program Files\Java
2008-04-07 00:08 --------- d-----w C:\Users\Bassel ASBATY\AppData\Roaming\Media Player Classic
2008-04-06 16:14 --------- d-----w C:\Program Files\K-Lite Codec Pack
2008-04-01 17:54 --------- d-----w C:\Program Files\SopCast
2008-03-22 19:14 --------- d-----w C:\Program Files\Microsoft Works
2008-03-22 19:12 --------- d-----w C:\Program Files\Microsoft.NET
2008-03-21 14:54 --------- d-----w C:\ProgramData\Yahoo!
2008-03-21 14:52 --------- d-----w C:\Program Files\Yahoo!
2008-03-14 23:03 --------- d-----w C:\Users\Bassel ASBATY\AppData\Roaming\CyberLink
2008-03-11 14:04 --------- d-----w C:\Users\Bassel ASBATY\AppData\Roaming\InternetCalls
2008-03-11 13:33 --------- d-----w C:\Users\Bassel ASBATY\AppData\Roaming\HP
2008-03-11 13:33 --------- d-----w C:\ProgramData\HP
2008-03-11 13:05 --------- d-----w C:\Program Files\InternetCalls.com
2008-03-04 20:02 28,095 ----a-w C:\Users\Bassel ASBATY\AppData\Roaming\nvModes.dat
2008-03-04 11:33 7,680 ----a-w C:\Windows\System32\ff_vfw.dll
2008-03-03 22:33 174 --sha-w C:\Program Files\desktop.ini
2008-03-03 22:22 8,192 ----a-w C:\Windows\System32\riched32.dll
2008-03-03 22:22 77,824 ----a-w C:\Windows\System32\rascfg.dll
2008-03-03 22:22 52,736 ----a-w C:\Windows\System32\rasdiag.dll
2008-03-03 22:22 22,016 ----a-w C:\Windows\System32\rasser.dll
2008-03-03 22:20 704,000 ----a-w C:\Windows\System32\PhotoScreensaver.scr
2008-03-03 22:20 67,584 ----a-w C:\Windows\System32\wlanhlp.dll
2008-03-03 22:20 542,720 ----a-w C:\Windows\System32\sysmain.dll
2008-03-03 22:20 502,784 ----a-w C:\Windows\System32\wlansvc.dll
2008-03-03 22:20 47,104 ----a-w C:\Windows\System32\wlanapi.dll
2008-03-03 22:20 297,984 ----a-w C:\Windows\System32\wlansec.dll
2008-03-03 22:20 290,816 ----a-w C:\Windows\System32\wlanmsm.dll
2008-03-03 22:20 24,064 ----a-w C:\Windows\System32\wtsapi32.dll
2008-03-03 22:20 2,923,520 ----a-w C:\Windows\explorer.exe
2008-03-03 22:19 32 ----a-w C:\Users\All Users\ezsid.dat
2008-03-03 22:19 32 ----a-w C:\ProgramData\ezsid.dat
2008-03-03 22:19 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-03-03 22:18 49,664 ----a-w C:\Windows\System32\csrsrv.dll
2008-03-03 22:18 376,320 ----a-w C:\Windows\System32\winsrv.dll
2008-03-03 22:11 374,456 ----a-w C:\Windows\System32\mcupdate_GenuineIntel.dll
2008-03-03 22:10 414,208 ----a-w C:\Windows\System32\msscp.dll
2008-03-03 22:09 8,147,968 ----a-w C:\Windows\System32\wmploc.DLL
2008-03-03 22:09 7,680 ----a-w C:\Windows\System32\spwmp.dll
2008-03-03 22:09 4,096 ----a-w C:\Windows\System32\dxmasf.dll
2008-03-03 22:09 356,864 ----a-w C:\Windows\System32\MediaMetadataHandler.dll
2008-03-03 22:08 86,016 ----a-w C:\Windows\System32\icfupgd.dll
2008-03-03 22:08 61,952 ----a-w C:\Windows\System32\cmifw.dll
2008-03-03 22:08 396,800 ----a-w C:\Windows\System32\MPSSVC.dll
2008-03-03 22:08 392,192 ----a-w C:\Windows\System32\FirewallAPI.dll
2008-03-03 22:08 178,688 ----a-w C:\Windows\System32\iphlpsvc.dll
2008-03-03 22:08 16,896 ----a-w C:\Windows\System32\wfapigp.dll
2008-03-03 22:07 3,504,696 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-03-03 22:07 3,470,392 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-03-03 22:07 2,048 ----a-w C:\Windows\System32\msxml3r.dll
2008-03-03 22:07 1,191,936 ----a-w C:\Windows\System32\msxml3.dll
2008-03-03 22:06 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-03-03 22:06 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-03-03 22:06 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-03-03 22:06 1,327,104 ----a-w C:\Windows\System32\quartz.dll
2008-03-03 22:05 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
2008-03-03 22:05 57,856 ----a-w C:\Windows\System32\SLUINotify.dll
2008-03-03 22:05 566,784 ----a-w C:\Windows\System32\SLCommDlg.dll
2008-03-03 22:05 39,936 ----a-w C:\Windows\System32\slcinst.dll
2008-03-03 22:05 351,232 ----a-w C:\Windows\System32\SLUI.exe
2008-03-03 22:05 33,280 ----a-w C:\Windows\System32\slwmi.dll
2008-03-03 22:05 268,288 ----a-w C:\Windows\System32\mcbuilder.exe
2008-03-03 22:05 223,232 ----a-w C:\Windows\System32\WMASF.DLL
2008-03-03 22:05 223,232 ----a-w C:\Windows\System32\SLC.dll
2008-03-03 22:05 2,605,568 ----a-w C:\Windows\System32\SLsvc.exe
2008-03-03 22:05 2,048 ----a-w C:\Windows\System32\asferror.dll
2008-03-03 22:05 186,368 ----a-w C:\Windows\System32\SLLUA.exe
2008-03-03 22:04 2,048 ----a-w C:\Windows\System32\msxml6r.dll
2008-03-03 22:04 1,335,296 ----a-w C:\Windows\System32\msxml6.dll
2008-03-03 22:02 84,480 ----a-w C:\Windows\System32\INETRES.dll
2008-03-03 22:02 737,792 ----a-w C:\Windows\System32\inetcomm.dll
2008-03-03 22:02 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-03-03 22:02 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-03-03 22:02 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-03-03 22:02 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-03-03 22:02 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-03-03 22:02 11,776 ----a-w C:\Windows\System32\sbunattend.exe
2008-03-03 22:02 1,686,528 ----a-w C:\Windows\System32\gameux.dll
2008-03-03 22:01 788,992 ----a-w C:\Windows\System32\rpcrt4.dll
2008-03-03 22:00 5,120 ----a-w C:\Windows\System32\wmi.dll
2008-03-03 22:00 152,576 ----a-w C:\Windows\System32\imagehlp.dll
2008-03-03 21:59 633,856 ----a-w C:\Windows\System32\user32.dll
2008-03-03 21:59 2,048 ----a-w C:\Windows\System32\tzres.dll
2008-03-03 21:58 750,080 ----a-w C:\Windows\System32\qmgr.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-03-03 23:02 1232896]
"WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 13:34 2159104 C:\WINDOWS\System32\oobefldr.dll]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35 125440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-03-03 23:14 1006264]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2007-01-16 23:34 634880]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-13 04:36 827392]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-09 18:50 4390912 C:\WINDOWS\RtHDVCpl.exe]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-02-12 15:37 174872]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2007-04-24 02:11 176128]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-02-13 19:38 159744]
"HP Health Check Scheduler"="C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-03-12 19:54 50696]
"hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 21:18 472776]
"WAWifiMessage"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-11 00:12 317128]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 07:11 49152]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-05-15 01:38 8429568]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-05-15 01:38 81920]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 01:47 31016]
"XP System"="systemxp.exe" []
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="%WINDIR%\SMINST\launcher.exe" [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{29F1DAD3-C691-499B-8BB6-C00E4B398343}"= C:\Program Files\HP\QuickPlay\QP.exe:Quick Play
"{E4259D20-FC2F-4C88-99B8-4BE3652A4E9C}"= C:\Program Files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{B7C64229-C1AD-4130-A3EE-9873164E0853}"= UDP:C:\Program Files\Google\Google Talk\googletalk.exe:Google Talk
"{0AD71EBD-D568-44B3-A2B8-24DD77C3AF85}"= TCP:C:\Program Files\Google\Google Talk\googletalk.exe:Google Talk
"{24034951-042A-4E7C-91D2-79E79FBB803A}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{5BA16E6B-458D-4656-85C2-4C253E3FDB00}"= UDP:C:\Program Files\InternetCalls.com\InternetCalls\InternetCalls.exe:InternetCalls
"{ACE1D955-7AD1-44C4-ABBB-115D1D003860}"= TCP:C:\Program Files\InternetCalls.com\InternetCalls\InternetCalls.exe:InternetCalls
"{6FB8C681-F3A2-464F-A31A-6ACCB9B00517}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{9863C24F-A35C-4A24-BF6B-E8B4E166BF48}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{35A28114-B8C5-4471-9F3F-CCC97CA67812}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{C09A9A9E-57AF-4DAC-BE07-792B10634763}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{D1E91C91-63CF-42DE-857E-82255D1EB912}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{961FB17E-C6A8-4202-A4BC-8119FF9CCD20}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{B53266E7-0AA7-4827-9BBD-F0665F7A0CB1}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{95C8D958-C3CF-4E9A-AE17-66EB5898B35E}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{95D03F80-E0D9-4DD8-8104-B7CE84C326B9}"= UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype
"{907650D0-4372-41DD-9374-9A8792D92FE7}"= TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype
"TCP Query User{FC851399-FA46-4958-8DBC-93AB1ADC02DC}C:\\program files\\dc++\\dcplusplus.exe"= UDP:C:\program files\dc++\dcplusplus.exe:DC++
"UDP Query User{2C4070A8-2C76-4683-A493-CB798DEEF013}C:\\program files\\dc++\\dcplusplus.exe"= TCP:C:\program files\dc++\dcplusplus.exe:DC++
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"DoNotAllowExceptions"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-11-02 08:30]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
*Newly Created Service* - AVG_ANTI-SPYWARE_DRIVER
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-06 20:55:11
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 14
**************************************************************************
.
Completion time: 2008-05-06 20:56:41
ComboFix-quarantined-files.txt 2008-05-06 19:56:31
The system cannot find message text for message number 0x2379 in the message file for Application.
The system cannot find message text for message number 0x2379 in the message file for Application.
201 --- E O F --- 2008-05-01 02:08:45