A voir également:
- (trojan) Ravmon, AdobeR, et + si affinités ..
- Trojan remover - Télécharger - Antivirus & Antimalwares
- Trojan b901 ✓ - Forum Virus
- Csrss.exe trojan ✓ - Forum Virus
- [Virus] Trojan ou virus dans csrss.exe et spo - Forum Virus
- Problème csrss.exe, virus? ✓ - Forum Virus
2 réponses
PFFFFFFFFFFFFFFFFFFFFF !!!!
je suis toujours vérolé par AdobeR !!!!!
voila un rapport combofix:
ComboFix 07-08-09.3 - "Marc" 2007-08-11 15:05:42.3 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.524 [GMT 2:00]
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Autorun.inf
C:\WINDOWS\adober.exe
((((((((((((((((((((((((( Files Created from 2007-07-11 to 2007-08-11 )))))))))))))))))))))))))))))))
2007-08-11 14:46 <REP> d-------- C:\WINDOWS\system32\ActiveScan
2007-08-11 14:05 <REP> d-------- C:\WINDOWS\LastGood
2007-08-09 23:00 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2007-08-09 23:00 94,416 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-08-09 23:00 92,848 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-08-09 23:00 783,224 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-08-09 23:00 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-08-09 23:00 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-08-09 23:00 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-08-09 21:14 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-08-09 19:57 <REP> d-------- C:\DOCUME~1\Marc\.housecall6.6
2007-08-09 19:49 <REP> d-------- C:\Program Files\Nouveau dossier
2007-08-08 21:59 <REP> d-------- C:\Downloads
2007-08-08 21:59 <REP> d-------- C:\Bases
2007-08-08 21:33 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-08 21:08 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-08-08 21:08 4,536 --a------ C:\WINDOWS\system32\tmp.reg
2007-08-08 21:08 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-08-05 20:55 <REP> d-------- C:\WINDOWS\BDOSCAN8
2007-08-05 17:02 <REP> d-------- C:\WINDOWS\ERUNT
2007-08-05 16:40 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-08-05 15:58 26,112 --a------ C:\WINDOWS\system32\nircmd.exe
2007-08-05 15:37 <REP> d-------- C:\HiJackThis
2007-08-03 12:13 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
2007-08-02 20:59 <REP> d-------- C:\Program Files\Google
2007-07-27 21:21 <REP> d-------- C:\Program Files\servers
2007-07-27 21:21 <REP> d-------- C:\Program Files\friends
2007-07-27 21:21 <REP> d-------- C:\Program Files\appcache
2007-07-27 21:19 <REP> d-------- C:\Program Files\SteamLogs
2007-07-27 21:19 <REP> d-------- C:\Program Files\config
2007-07-27 21:18 69,624 --a------ C:\Program Files\Steam_api.dll
2007-07-27 21:18 338,936 --a------ C:\Program Files\vstdlib_s.dll
2007-07-27 21:18 3,261,688 --a------ C:\Program Files\Steam.dll
2007-07-27 21:18 251,384 --a------ C:\Program Files\WriteMiniDump.exe
2007-07-27 21:18 232,696 --a------ C:\Program Files\tier0_s.dll
2007-07-27 21:18 2,452,728 --a------ C:\Program Files\SteamUI.dll
2007-07-27 21:18 117,752 --a------ C:\Program Files\CSERHelper.dll
2007-07-27 21:18 1,318,648 --a------ C:\Program Files\steamclient.dll
2007-07-27 21:18 1,039,192 --a------ C:\Program Files\dbghelp.dll
2007-07-27 21:18 <REP> d-------- C:\Program Files\skins
2007-07-27 21:18 <REP> d-------- C:\Program Files\resource
2007-07-27 21:18 <REP> d-------- C:\Program Files\Graphics
2007-07-27 21:18 <REP> d-------- C:\Program Files\bin
2007-07-27 21:17 <REP> d-------- C:\Program Files\SteamApps
2007-07-27 21:17 <REP> d-------- C:\Program Files\Public
2007-07-27 21:16 81,768 --a------ C:\WINDOWS\system32\xinput1_3.dll
2007-07-27 21:16 62,744 --a------ C:\WINDOWS\system32\xinput1_2.dll
2007-07-27 21:16 443,752 --a------ C:\WINDOWS\system32\d3dx10_33.dll
2007-07-27 21:16 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll
2007-07-27 21:16 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
2007-07-27 21:16 261,480 --a------ C:\WINDOWS\system32\xactengine2_7.dll
2007-07-27 21:16 255,848 --a------ C:\WINDOWS\system32\xactengine2_6.dll
2007-07-27 21:16 251,672 --a------ C:\WINDOWS\system32\xactengine2_5.dll
2007-07-27 21:16 237,848 --a------ C:\WINDOWS\system32\xactengine2_4.dll
2007-07-27 21:16 236,824 --a------ C:\WINDOWS\system32\xactengine2_3.dll
2007-07-27 21:16 2,414,360 --a------ C:\WINDOWS\system32\d3dx9_31.dll
2007-07-27 21:16 15,128 --a------ C:\WINDOWS\system32\x3daudio1_1.dll
2007-07-27 21:16 1,123,696 --a------ C:\WINDOWS\system32\D3DCompiler_33.dll
2007-07-27 20:20 20,505 --a------ C:\WINDOWS\War3Unin.dat
2007-07-27 20:20 2,829 --a------ C:\WINDOWS\War3Unin.pif
2007-07-27 20:20 126,976 --a------ C:\WINDOWS\War3Unin.exe
2007-07-11 20:18 <REP> d-------- C:\DOCUME~1\Marc\APPLIC~1\Opera
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-11 14:08 64922 --a------ C:\WINDOWS\system32\perfc00C.dat
2007-08-11 14:08 447222 --a------ C:\WINDOWS\system32\perfh00C.dat
2007-08-11 14:06 333235 --a------ C:\Program Files\ClientRegistry.blob
2007-08-11 14:05 87416 --a------ C:\Program Files\AppUpdateStats.blob
2007-08-11 14:04 36493 --a------ C:\Program Files\Steam.log
2007-08-05 15:08 --------- d-------- C:\Program Files\Fichiers communs\Symantec Shared
2007-08-05 15:01 --------- d-------- C:\Program Files\Styler
2007-08-03 23:38 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-08-03 12:13 --------- d-------- C:\Program Files\Fichiers communs\InstallShield
2007-07-27 21:18 50747 --a------ C:\Program Files\SteamUI_336.mst
2007-07-27 21:18 14 --a------ C:\Program Files\Steam_36.mst
2007-07-27 21:18 1258744 --a------ C:\Program Files\Steam.exe
2007-07-13 12:36 --------- d-------- C:\Program Files\Winamp
2007-07-13 09:54 --------- d-------- C:\Program Files\Acer Inc
2007-07-04 18:43 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-06-24 23:26 --------- d-------- C:\DOCUME~1\Marc\APPLIC~1\Styler
2007-05-16 17:13 683520 --a------ C:\WINDOWS\system32\inetcomm.dll
2007-03-29 15:29 121 --a------ C:\Program Files\Support.url
2005-09-15 15:20 318 -ra------ C:\Program Files\steam.ico
2005-09-13 17:49 9653 --a------ C:\Program Files\steam_install_agreement.rtf
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 14:34]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-16 17:32]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2005-06-11 21:51]
"AGRSMMSG"="AGRSMMSG.exe" [2005-12-12 15:50 C:\WINDOWS\AGRSMMSG.exe]
"ntiMUI"="C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2005-05-11 18:15]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-10 06:00]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 06:00]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 06:00]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 06:00]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-01-19 10:43]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-01-19 10:43]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 18:56 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 20:04 C:\WINDOWS\SkyTel.exe]
"Alcmtr"="ALCMTR.EXE" [2005-05-03 20:43 C:\WINDOWS\Alcmtr.exe]
"eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\eRAgent.exe" [2006-06-01 15:40]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2006-06-23 11:39]
"LogitechCameraAssistant"="C:\Program Files\Acer\OrbiCam\CameraAssistant.exe" [2006-06-26 16:47]
"LogitechVideo[inspector]"="C:\Program Files\Acer\OrbiCam\InstallHelper.exe" [2006-06-26 16:55]
"LogitechCameraService(E)"="C:\WINDOWS\system32\ElkCtrl.exe" [2004-11-01 19:22]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-20 21:07]
"BtcMaestro"="C:\Program Files\HP Wireless Keyboard\KMaestro.exe" [2005-06-13 03:38]
"nwiz"="nwiz.exe" [2006-01-19 10:43 C:\WINDOWS\system32\nwiz.exe]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-07-28 00:03]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 13:55]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 06:00]
"Steam"="C:\Program Files\Steam.exe" [2007-07-27 21:18]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 01:04]
C:\Documents and Settings\Marc\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2006-12-29 15:42:08]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 05:44:06]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
R0 sfsync02;StarForce Protection Synchronization Driver (version 2.x);C:\WINDOWS\system32\drivers\sfsync02.sys
R0 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys
R1 WmiAcpi;Interface de gestion Microsoft Windows pour ACPI;C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
R2 EpmPsd;Acer EPM Power Scheme Driver;\??\C:\WINDOWS\system32\drivers\epm-psd.sys
R2 EpmShd;Acer EPM System Hardware Driver;\??\C:\WINDOWS\system32\drivers\epm-shd.sys
R3 int15.sys;int15.sys;\??\C:\Acer\Empowering Technology\eRecovery\int15.sys
R3 k750bus;Sony Ericsson 750 driver (WDM);C:\WINDOWS\system32\DRIVERS\k750bus.sys
R3 k750mdfl;Sony Ericsson 750 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k750mdfl.sys
R3 k750mdm;Sony Ericsson 750 USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\k750mdm.sys
R3 k750mgmt;Sony Ericsson 750 USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\k750mgmt.sys
R3 k750obex;Sony Ericsson 750 USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\k750obex.sys
R3 lv321av;Logitech USB PC Camera (VC0321);C:\WINDOWS\system32\DRIVERS\lv321av.sys
R3 NTIDrvr;Upper Class Filter Driver;C:\WINDOWS\system32\DRIVERS\NTIDrvr.sys
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver;C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
R3 sdbus;sdbus;C:\WINDOWS\system32\DRIVERS\sdbus.sys
R3 tifm21;tifm21;C:\WINDOWS\system32\drivers\tifm21.sys
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
R3 w39n51;Intel(R) PRO/Wireless 3945ABG Adapter Driver;C:\WINDOWS\system32\DRIVERS\w39n51.sys
S1 hidfltr;HID Filter Driver;C:\WINDOWS\system32\drivers\MWhid.sys
S2 Planificateur LiveUpdate automatique;Planificateur LiveUpdate automatique;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe"
S2 spupdsvc;Windows Service Pack Installer update service;C:\WINDOWS\system32\spupdsvc.exe
S3 LVPrcMon;Logitech LVPrcMon Driver;\??\C:\WINDOWS\system32\drivers\LVPrcMon.sys
S3 nm;Pilote du Moniteur réseau;C:\WINDOWS\system32\DRIVERS\NMnt.sys
S3 psdfilter;psdfilter;\??\C:\WINDOWS\system32\Drivers\psdfilter.sys
S3 psdvdisk;psdvdisk;\??\C:\WINDOWS\system32\Drivers\psdvdisk.sys
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
Auto\command- H:\AdobeR.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\I]
Auto\command- I:\AdobeR.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7a4d922c-2fa8-11dc-b94c-0018de724811}]
Auto\command- F:\AdobeR.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8838aea6-b550-11db-b8b1-0018de724811}]
Auto\command- I:\AdobeR.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8fc88afc-0cea-11dc-b90f-0018de724811}]
Auto\command- F:\AdobeR.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c949288c-eab1-11db-b8ef-0018de724811}]
Auto\command- AdobeR.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e524733f-d983-11db-b8db-0018de724811}]
Auto\command- I:\AdobeR.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e71aedec-047b-11dc-b908-0018de724811}]
AutoRun\command- F:\ie.exe
explore\Command- F:\ie.exe
open\Command- F:\ie.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-11 15:07:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-11 15:08:03
C:\ComboFix-quarantined-files.txt ... 2007-08-11 15:07
C:\ComboFix2.txt ... 2007-08-09 21:59
C:\ComboFix3.txt ... 2007-08-08 21:40
--- E O F ---
----------------------------------------
Help si l vous plait !!! je veux pas formater mon ordi!!!
,:o(
je suis toujours vérolé par AdobeR !!!!!
voila un rapport combofix:
ComboFix 07-08-09.3 - "Marc" 2007-08-11 15:05:42.3 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.524 [GMT 2:00]
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Autorun.inf
C:\WINDOWS\adober.exe
((((((((((((((((((((((((( Files Created from 2007-07-11 to 2007-08-11 )))))))))))))))))))))))))))))))
2007-08-11 14:46 <REP> d-------- C:\WINDOWS\system32\ActiveScan
2007-08-11 14:05 <REP> d-------- C:\WINDOWS\LastGood
2007-08-09 23:00 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2007-08-09 23:00 94,416 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-08-09 23:00 92,848 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-08-09 23:00 783,224 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-08-09 23:00 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-08-09 23:00 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-08-09 23:00 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-08-09 21:14 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-08-09 19:57 <REP> d-------- C:\DOCUME~1\Marc\.housecall6.6
2007-08-09 19:49 <REP> d-------- C:\Program Files\Nouveau dossier
2007-08-08 21:59 <REP> d-------- C:\Downloads
2007-08-08 21:59 <REP> d-------- C:\Bases
2007-08-08 21:33 51,200 --a------ C:\WINDOWS\nircmd.exe
2007-08-08 21:08 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-08-08 21:08 4,536 --a------ C:\WINDOWS\system32\tmp.reg
2007-08-08 21:08 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-08-05 20:55 <REP> d-------- C:\WINDOWS\BDOSCAN8
2007-08-05 17:02 <REP> d-------- C:\WINDOWS\ERUNT
2007-08-05 16:40 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-08-05 15:58 26,112 --a------ C:\WINDOWS\system32\nircmd.exe
2007-08-05 15:37 <REP> d-------- C:\HiJackThis
2007-08-03 12:13 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
2007-08-02 20:59 <REP> d-------- C:\Program Files\Google
2007-07-27 21:21 <REP> d-------- C:\Program Files\servers
2007-07-27 21:21 <REP> d-------- C:\Program Files\friends
2007-07-27 21:21 <REP> d-------- C:\Program Files\appcache
2007-07-27 21:19 <REP> d-------- C:\Program Files\SteamLogs
2007-07-27 21:19 <REP> d-------- C:\Program Files\config
2007-07-27 21:18 69,624 --a------ C:\Program Files\Steam_api.dll
2007-07-27 21:18 338,936 --a------ C:\Program Files\vstdlib_s.dll
2007-07-27 21:18 3,261,688 --a------ C:\Program Files\Steam.dll
2007-07-27 21:18 251,384 --a------ C:\Program Files\WriteMiniDump.exe
2007-07-27 21:18 232,696 --a------ C:\Program Files\tier0_s.dll
2007-07-27 21:18 2,452,728 --a------ C:\Program Files\SteamUI.dll
2007-07-27 21:18 117,752 --a------ C:\Program Files\CSERHelper.dll
2007-07-27 21:18 1,318,648 --a------ C:\Program Files\steamclient.dll
2007-07-27 21:18 1,039,192 --a------ C:\Program Files\dbghelp.dll
2007-07-27 21:18 <REP> d-------- C:\Program Files\skins
2007-07-27 21:18 <REP> d-------- C:\Program Files\resource
2007-07-27 21:18 <REP> d-------- C:\Program Files\Graphics
2007-07-27 21:18 <REP> d-------- C:\Program Files\bin
2007-07-27 21:17 <REP> d-------- C:\Program Files\SteamApps
2007-07-27 21:17 <REP> d-------- C:\Program Files\Public
2007-07-27 21:16 81,768 --a------ C:\WINDOWS\system32\xinput1_3.dll
2007-07-27 21:16 62,744 --a------ C:\WINDOWS\system32\xinput1_2.dll
2007-07-27 21:16 443,752 --a------ C:\WINDOWS\system32\d3dx10_33.dll
2007-07-27 21:16 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll
2007-07-27 21:16 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
2007-07-27 21:16 261,480 --a------ C:\WINDOWS\system32\xactengine2_7.dll
2007-07-27 21:16 255,848 --a------ C:\WINDOWS\system32\xactengine2_6.dll
2007-07-27 21:16 251,672 --a------ C:\WINDOWS\system32\xactengine2_5.dll
2007-07-27 21:16 237,848 --a------ C:\WINDOWS\system32\xactengine2_4.dll
2007-07-27 21:16 236,824 --a------ C:\WINDOWS\system32\xactengine2_3.dll
2007-07-27 21:16 2,414,360 --a------ C:\WINDOWS\system32\d3dx9_31.dll
2007-07-27 21:16 15,128 --a------ C:\WINDOWS\system32\x3daudio1_1.dll
2007-07-27 21:16 1,123,696 --a------ C:\WINDOWS\system32\D3DCompiler_33.dll
2007-07-27 20:20 20,505 --a------ C:\WINDOWS\War3Unin.dat
2007-07-27 20:20 2,829 --a------ C:\WINDOWS\War3Unin.pif
2007-07-27 20:20 126,976 --a------ C:\WINDOWS\War3Unin.exe
2007-07-11 20:18 <REP> d-------- C:\DOCUME~1\Marc\APPLIC~1\Opera
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-08-11 14:08 64922 --a------ C:\WINDOWS\system32\perfc00C.dat
2007-08-11 14:08 447222 --a------ C:\WINDOWS\system32\perfh00C.dat
2007-08-11 14:06 333235 --a------ C:\Program Files\ClientRegistry.blob
2007-08-11 14:05 87416 --a------ C:\Program Files\AppUpdateStats.blob
2007-08-11 14:04 36493 --a------ C:\Program Files\Steam.log
2007-08-05 15:08 --------- d-------- C:\Program Files\Fichiers communs\Symantec Shared
2007-08-05 15:01 --------- d-------- C:\Program Files\Styler
2007-08-03 23:38 --------- d--h----- C:\Program Files\InstallShield Installation Information
2007-08-03 12:13 --------- d-------- C:\Program Files\Fichiers communs\InstallShield
2007-07-27 21:18 50747 --a------ C:\Program Files\SteamUI_336.mst
2007-07-27 21:18 14 --a------ C:\Program Files\Steam_36.mst
2007-07-27 21:18 1258744 --a------ C:\Program Files\Steam.exe
2007-07-13 12:36 --------- d-------- C:\Program Files\Winamp
2007-07-13 09:54 --------- d-------- C:\Program Files\Acer Inc
2007-07-04 18:43 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-06-24 23:26 --------- d-------- C:\DOCUME~1\Marc\APPLIC~1\Styler
2007-05-16 17:13 683520 --a------ C:\WINDOWS\system32\inetcomm.dll
2007-03-29 15:29 121 --a------ C:\Program Files\Support.url
2005-09-15 15:20 318 -ra------ C:\Program Files\steam.ico
2005-09-13 17:49 9653 --a------ C:\Program Files\steam_install_agreement.rtf
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 14:34]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-12-16 17:32]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2005-06-11 21:51]
"AGRSMMSG"="AGRSMMSG.exe" [2005-12-12 15:50 C:\WINDOWS\AGRSMMSG.exe]
"ntiMUI"="C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2005-05-11 18:15]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-10 06:00]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 06:00]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 06:00]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-10 06:00]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-01-19 10:43]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-01-19 10:43]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 18:56 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 20:04 C:\WINDOWS\SkyTel.exe]
"Alcmtr"="ALCMTR.EXE" [2005-05-03 20:43 C:\WINDOWS\Alcmtr.exe]
"eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\eRAgent.exe" [2006-06-01 15:40]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2006-06-23 11:39]
"LogitechCameraAssistant"="C:\Program Files\Acer\OrbiCam\CameraAssistant.exe" [2006-06-26 16:47]
"LogitechVideo[inspector]"="C:\Program Files\Acer\OrbiCam\InstallHelper.exe" [2006-06-26 16:55]
"LogitechCameraService(E)"="C:\WINDOWS\system32\ElkCtrl.exe" [2004-11-01 19:22]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-20 21:07]
"BtcMaestro"="C:\Program Files\HP Wireless Keyboard\KMaestro.exe" [2005-06-13 03:38]
"nwiz"="nwiz.exe" [2006-01-19 10:43 C:\WINDOWS\system32\nwiz.exe]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-07-28 00:03]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 13:55]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 06:00]
"Steam"="C:\Program Files\Steam.exe" [2007-07-27 21:18]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 01:04]
C:\Documents and Settings\Marc\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2006-12-29 15:42:08]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 05:44:06]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
R0 sfsync02;StarForce Protection Synchronization Driver (version 2.x);C:\WINDOWS\system32\drivers\sfsync02.sys
R0 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys
R1 WmiAcpi;Interface de gestion Microsoft Windows pour ACPI;C:\WINDOWS\system32\DRIVERS\wmiacpi.sys
R2 EpmPsd;Acer EPM Power Scheme Driver;\??\C:\WINDOWS\system32\drivers\epm-psd.sys
R2 EpmShd;Acer EPM System Hardware Driver;\??\C:\WINDOWS\system32\drivers\epm-shd.sys
R3 int15.sys;int15.sys;\??\C:\Acer\Empowering Technology\eRecovery\int15.sys
R3 k750bus;Sony Ericsson 750 driver (WDM);C:\WINDOWS\system32\DRIVERS\k750bus.sys
R3 k750mdfl;Sony Ericsson 750 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\k750mdfl.sys
R3 k750mdm;Sony Ericsson 750 USB WMC Modem Drivers;C:\WINDOWS\system32\DRIVERS\k750mdm.sys
R3 k750mgmt;Sony Ericsson 750 USB WMC Device Management Drivers;C:\WINDOWS\system32\DRIVERS\k750mgmt.sys
R3 k750obex;Sony Ericsson 750 USB WMC OBEX Interface Drivers;C:\WINDOWS\system32\DRIVERS\k750obex.sys
R3 lv321av;Logitech USB PC Camera (VC0321);C:\WINDOWS\system32\DRIVERS\lv321av.sys
R3 NTIDrvr;Upper Class Filter Driver;C:\WINDOWS\system32\DRIVERS\NTIDrvr.sys
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver;C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys
R3 sdbus;sdbus;C:\WINDOWS\system32\DRIVERS\sdbus.sys
R3 tifm21;tifm21;C:\WINDOWS\system32\drivers\tifm21.sys
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
R3 w39n51;Intel(R) PRO/Wireless 3945ABG Adapter Driver;C:\WINDOWS\system32\DRIVERS\w39n51.sys
S1 hidfltr;HID Filter Driver;C:\WINDOWS\system32\drivers\MWhid.sys
S2 Planificateur LiveUpdate automatique;Planificateur LiveUpdate automatique;"C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe"
S2 spupdsvc;Windows Service Pack Installer update service;C:\WINDOWS\system32\spupdsvc.exe
S3 LVPrcMon;Logitech LVPrcMon Driver;\??\C:\WINDOWS\system32\drivers\LVPrcMon.sys
S3 nm;Pilote du Moniteur réseau;C:\WINDOWS\system32\DRIVERS\NMnt.sys
S3 psdfilter;psdfilter;\??\C:\WINDOWS\system32\Drivers\psdfilter.sys
S3 psdvdisk;psdvdisk;\??\C:\WINDOWS\system32\Drivers\psdvdisk.sys
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
Auto\command- H:\AdobeR.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\I]
Auto\command- I:\AdobeR.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7a4d922c-2fa8-11dc-b94c-0018de724811}]
Auto\command- F:\AdobeR.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8838aea6-b550-11db-b8b1-0018de724811}]
Auto\command- I:\AdobeR.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8fc88afc-0cea-11dc-b90f-0018de724811}]
Auto\command- F:\AdobeR.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c949288c-eab1-11db-b8ef-0018de724811}]
Auto\command- AdobeR.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e524733f-d983-11db-b8db-0018de724811}]
Auto\command- I:\AdobeR.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e71aedec-047b-11dc-b908-0018de724811}]
AutoRun\command- F:\ie.exe
explore\Command- F:\ie.exe
open\Command- F:\ie.exe
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-11 15:07:11
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-08-11 15:08:03
C:\ComboFix-quarantined-files.txt ... 2007-08-11 15:07
C:\ComboFix2.txt ... 2007-08-09 21:59
C:\ComboFix3.txt ... 2007-08-08 21:40
--- E O F ---
----------------------------------------
Help si l vous plait !!! je veux pas formater mon ordi!!!
,:o(