Bonjour,
Je voulais aller sur internet pour télécharger Combofix...
Voici les nouveaux rapports
Merci d'avance pour l'aide
Xavoli
================================================
ComboFix 08-09-05.03 - Xavier 2008-09-07 22:35:47.1 - NTFSx86
Microsoft Windows XP Edition familiale 5.1.2600.2.1252.1.1036.18.235 [GMT 2:00]
Endroit: C:Documents and SettingsXavierBureauComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:Documents and SettingsXavierFavorisError Cleaner.url
C:Documents and SettingsXavierFavorisPrivacy Protector.url
C:Documents and SettingsXavierFavorisSpyware&Malware Protection.url
C:Program FilesPCHealthCenter
0.exe
C:Program FilesPCHealthCenter
0.gif
C:Program FilesPCHealthCenter1.exe
C:Program FilesPCHealthCenter1.gif
C:Program FilesPCHealthCenter1.ico
C:Program FilesPCHealthCenter2.exe
C:Program FilesPCHealthCenter2.gif
C:Program FilesPCHealthCenter2.ico
C:Program FilesPCHealthCenter3.gif
C:Program FilesPCHealthCenter4.exe
C:Program FilesPCHealthCenter7.exe
C:Program FilesPCHealthCentersc.html
C:Program FilesVideo Add-on
C:WINDOWScookies.ini
C:WINDOWSeeka.exe
C:WINDOWSgksraemq.dll
C:WINDOWSprivacy_danger
C:WINDOWSprivacy_dangerimagescapt.gif
C:WINDOWSprivacy_dangerimagesdanger.jpg
C:WINDOWSprivacy_dangerimagesdown.gif
C:WINDOWSprivacy_dangerimagesspacer.gif
C:WINDOWSprivacy_dangerindex.htm
C:WINDOWSsystem32cbbinz.dll
C:WINDOWSsystem32fvfcmo.dll
C:WINDOWSsystem32gnwnfpnx.ini
C:WINDOWSsystem32hdmdxjls.dll
C:WINDOWSsystem32hgGxWpNf.dll
C:WINDOWSsystem32jofwryqc.dll
C:WINDOWSsystem32kxtprh.dll
C:WINDOWSsystem32mcrh.tmp
C:WINDOWSsystem32mpVEeMoq.ini
C:WINDOWSsystem32mpVEeMoq.ini2
C:WINDOWSsystem32ouptfgdg.dll
C:WINDOWSsystem32qoMeEVpm.dll
C:WINDOWSsystem32
lcfxxmw.dll
C:WINDOWSsystem32
qRHwTKa.dll
C:WINDOWSsystem32wmxxfclr.ini
C:WINDOWSsystem32xtjyghdc.ini
C:WINDOWSwinhelp.ini
C:WINDOWSxrdwbfgn.dll
.
((((((((((((((((((((((((((((( Fichiers cr,,s 2008-08-07 to 2008-09-07 ))))))))))))))))))))))))))))))))))))
.
2008-09-07 16:58 . 2008-09-07 16:58 <REP> d-------- C:Program FilesSophos
2008-09-07 11:46 . 2008-09-07 11:46 <REP> d-------- C:Program FilesAvira
2008-09-07 11:46 . 2008-09-07 11:46 <REP> d-------- C:Documents and SettingsAll UsersApplication DataAvira
2008-09-06 15:30 . 2005-03-07 20:12 <REP> d--h----- C:Documents and SettingsAdministrateurVoisinage r,seau
2008-09-06 15:30 . 2005-03-07 20:12 <REP> d--h----- C:Documents and SettingsAdministrateurVoisinage d'impression
2008-09-06 15:30 . 2005-03-07 19:17 <REP> d--h----- C:Documents and SettingsAdministrateurModSles
2008-09-06 15:30 . 2005-03-23 15:26 <REP> dr------- C:Documents and SettingsAdministrateurMes documents
2008-09-06 15:30 . 2005-03-08 15:10 <REP> dr------- C:Documents and SettingsAdministrateurMenu D,marrer
2008-09-06 15:30 . 2005-03-23 15:26 <REP> dr------- C:Documents and SettingsAdministrateurFavoris
2008-09-06 15:30 . 2005-03-08 15:22 <REP> d-------- C:Documents and SettingsAdministrateurBureau
2008-09-06 15:30 . 2005-03-08 15:05 <REP> d-------- C:Documents and SettingsAdministrateurApplication DataSymantec
2008-09-06 15:30 . 2005-03-08 14:59 <REP> d-------- C:Documents and SettingsAdministrateurApplication DataSony Corporation
2008-09-06 15:30 . 2008-09-06 15:30 <REP> d-------- C:Documents and SettingsAdministrateur
2008-09-06 13:51 . 2008-09-06 13:58 <REP> d-------- C:Program FilesFichiers communsPC Tools
2008-09-06 13:51 . 2008-09-07 15:59 <REP> d-a------ C:Documents and SettingsAll UsersApplication DataTEMP
2008-09-06 13:51 . 2008-07-28 11:29 160,792 --a------ C:WINDOWSsystem32driverspctfw2.sys
2008-09-06 13:51 . 2008-08-25 11:36 81,288 --a------ C:WINDOWSsystem32driversiksyssec.sys
2008-09-06 13:51 . 2008-08-25 11:36 66,952 --a------ C:WINDOWSsystem32driversiksysflt.sys
2008-09-06 13:51 . 2008-08-25 11:36 40,840 --a------ C:WINDOWSsystem32driversikfilesec.sys
2008-09-06 13:51 . 2008-06-02 15:19 29,576 --a------ C:WINDOWSsystem32driverskcom.sys
2008-09-06 13:50 . 2008-09-07 14:58 <REP> d-------- C:Program FilesSpyware Doctor
2008-09-06 13:50 . 2008-09-06 13:50 <REP> d-------- C:Documents and SettingsXavierApplication DataPC Tools
2008-09-06 13:50 . 2008-09-06 13:50 <REP> d-------- C:Documents and SettingsAll UsersApplication DataPC Tools
2008-09-06 13:20 . 2008-09-06 13:20 <REP> d-------- C:Documents and SettingsAll UsersApplication DataGrisoft
2008-09-05 17:17 . 2008-09-05 17:07 3,262 --a------ C:WINDOWSsystem322.ico
2008-09-05 17:13 . 2008-09-07 22:49 <REP> d-------- C:Program FilesPCHealthCenter
2008-09-05 17:13 . 2008-09-05 15:42 86,016 --a------ C:WINDOWSsxmaokgf.exe
2008-09-05 17:13 . 2008-09-05 17:07 3,262 --a------ C:WINDOWSsystem321.ico
2008-08-25 14:24 . 2008-08-25 14:27 <REP> d-------- C:Program FilesWindows Live
2008-08-25 14:24 . 2008-08-25 14:25 <REP> d--hsc--- C:Program FilesFichiers communsWindowsLiveInstaller
2008-08-25 14:24 . 2008-08-25 14:24 <REP> d-------- C:Documents and SettingsAll UsersApplication DataWLInstaller
2008-08-22 17:18 . 2008-08-22 17:46 <REP> d-------- C:WINDOWSsystem32CatRoot_bak
2008-08-21 21:18 . 2008-09-06 11:33 54,156 --ah----- C:WINDOWSQTFont.qfn
2008-08-21 21:18 . 2008-08-21 21:18 1,409 --a------ C:WINDOWSQTFont.for
2008-08-14 17:50 . 2008-05-01 16:31 331,776 -----c--- C:WINDOWSsystem32dllcachemsadce.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-07 14:07 5,648 ----a-w C:WINDOWSsystem32 mp.reg
2008-07-18 20:10 94,920 ----a-w C:WINDOWSsystem32cdm.dll
2008-07-18 20:10 53,448 ----a-w C:WINDOWSsystem32wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:WINDOWSsystem32wups2.dll
2008-07-18 20:10 36,552 ----a-w C:WINDOWSsystem32wups.dll
2008-07-18 20:09 563,912 ----a-w C:WINDOWSsystem32wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:WINDOWSsystem32wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:WINDOWSsystem32wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:WINDOWSsystem32wuaueng.dll
2008-07-18 20:07 270,880 ----a-w C:WINDOWSsystem32mucltui.dll
2008-07-18 20:07 210,976 ----a-w C:WINDOWSsystem32muweb.dll
2008-07-07 20:31 253,952 ----a-w C:WINDOWSsystem32es.dll
2008-06-27 22:08 4,616 ----a-w C:Documents and SettingsXavierApplication Datawklnhst.dat
2008-06-24 16:23 74,240 ----a-w C:WINDOWSsystem32mscms.dll
2008-06-23 16:28 826,368 ----a-w C:WINDOWSsystem32wininet.dll
2008-06-20 17:41 247,808 ----a-w C:WINDOWSsystem32mswsock.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ,l,ments vides & les ,l,ments initiaux l,gitimes ne sont pas list,s
REGEDIT4
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"CTFMON.EXE"="C:WINDOWSsystem32ctfmon.exe" [2004-08-05 15360]
"swg"="C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe" [2007-08-17 68856]
"H/PC Connection Agent"="C:Program FilesMicrosoft ActiveSyncwcescomm.exe" [2006-06-21 1211176]
"MsnMsgr"="C:Program FilesWindows LiveMessengerMsnMsgr.Exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"Apoint"="C:Program FilesApointApoint.exe" [2003-11-07 114688]
"NvCplDaemon"="C:WINDOWSsystem32NvCpl.dll" [2005-02-17 5406720]
"IgfxTray"="C:WINDOWSsystem32igfxtray.exe" [2005-02-22 155648]
"HotKeysCmds"="C:WINDOWSsystem32hkcmd.exe" [2005-02-22 126976]
"SonyPowerCfg"="C:Program FilesSonyVAIO Power ManagementSPMgr.exe" [2005-01-14 184320]
"ISBMgr.exe"="C:Program FilesSonyISB UtilityISBMgr.exe" [2004-02-20 32768]
"HP Software Update"="C:Program FilesHPHP Software UpdateHPWuSchd2.exe" [2004-09-13 49152]
"SunJavaUpdateSched"="C:Program FilesJavajre1.6.0_05injusched.exe" [2008-02-22 144784]
"SsAAD.exe"="C:PROGRA~1SonySONICS~1SsAAD.exe" [2005-01-24 81920]
"VMConsole.exe"="C:Program FilesSonyVAIO Media Integrated ServerPlatformVMConsole.exe" [2005-01-14 315392]
"Net-It Launcher"="C:WINDOWSsystem32NILaunch.exe" [1998-02-05 24576]
"VAIO Update 3"="C:Program FilesSonyVAIO Update 3VAIOUpdt.exe" [2007-01-25 546936]
"QuickTime Task"="C:Program FilesQuickTimeqttask.exe" [2007-02-16 282624]
"Symantec PIF AlertEng"="C:Program FilesFichiers communsSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PIFSvc.exe" [2007-03-12 517768]
"EverioService"="C:Program FilesCyberLinkPCM4EverioEverioService.exe" [2006-11-22 151552]
"Adobe Reader Speed Launcher"="C:Program FilesAdobeReader 8.0ReaderReader_sl.exe" [2008-01-11 39792]
"!AVG Anti-Spyware"="C:Program FilesGrisoftAVG Anti-Spyware 7.5avgas.exe" [2008-09-06 6731312]
"avgnt"="C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe" [2008-06-12 266497]
"RTHDCPL"="RTHDCPL.EXE" [2005-02-21 C:WINDOWSRTHDCPL.EXE]
"Mouse Suite 98 Daemon"="ICO.EXE" [2002-03-14 C:WINDOWSsystem32ico.exe]
"atwtusb"="atwtusb.exe" [2005-09-21 C:WINDOWSsystem32ATWTUSB.EXE]
[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
"CTFMON.EXE"="C:WINDOWSsystem32CTFMON.EXE" [2004-08-05 15360]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionwinlogon
otifyVESWinlogon]
2005-01-18 13:48 73728 C:WINDOWSsystem32VESWinlogon.dll
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversiondrivers32]
"VIDC.dvsd"= C:PROGRA~1FICHIE~1SONYSH~1VideoLibsonydv.dll
[HKLM~startupfolderC:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Active la souris sans fil.lnk]
path=C:Documents and SettingsAll UsersMenu DémarrerProgrammesDémarrageActive la souris sans fil.lnk
backup=C:WINDOWSpssActive la souris sans fil.lnkCommon Startup
[HKLM~startupfolderC:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Active NumPad sans fil.lnk]
path=C:Documents and SettingsAll UsersMenu DémarrerProgrammesDémarrageActive NumPad sans fil.lnk
backup=C:WINDOWSpssActive NumPad sans fil.lnkCommon Startup
[HKLM~startupfolderC:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Démarrage rapide du logiciel HP Image Zone.lnk]
path=C:Documents and SettingsAll UsersMenu DémarrerProgrammesDémarrageDémarrage rapide du logiciel HP Image Zone.lnk
backup=C:WINDOWSpssDémarrage rapide du logiciel HP Image Zone.lnkCommon Startup
[HKLM~startupfolderC:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
path=C:Documents and SettingsAll UsersMenu DémarrerProgrammesDémarrageHP Digital Imaging Monitor.lnk
backup=C:WINDOWSpssHP Digital Imaging Monitor.lnkCommon Startup
[HKLM~startupfolderC:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Service Manager.lnk]
path=C:Documents and SettingsAll UsersMenu DémarrerProgrammesDémarrageService Manager.lnk
backup=C:WINDOWSpssService Manager.lnkCommon Startup
[HKLM~startupfolderC:^Documents and Settings^Xavier^Menu Démarrer^Programmes^Démarrage^VAIO Launcher.lnk]
path=C:Documents and SettingsXavierMenu DémarrerProgrammesDémarrageVAIO Launcher.lnk
backup=C:WINDOWSpssVAIO Launcher.lnkStartup
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregiTunesHelper]
--a--c--- 2007-03-14 19:05 257088 C:Program FilesiTunesiTunesHelper.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregswg]
--a------ 2007-08-17 21:06 68856 C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoringSymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
"%windir%\system32\sessmgr.exe"=
"C:\Program Files\Sony\VAIO Media 4.0\Vc.exe"=
"C:\Program Files\Messenger\msmsgs.exe"=
"%windir%\Network Diagnostic\xpnetdiag.exe"=
"C:\Program Files\iTunes\iTunes.exe"=
"C:Program FilesMicrosoft ActiveSync
apimgr.exe"= C:Program FilesMicrosoft ActiveSync
apimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:Program FilesMicrosoft ActiveSyncwcescomm.exe"= C:Program FilesMicrosoft ActiveSyncwcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:Program FilesMicrosoft ActiveSyncWCESMgr.exe"= C:Program FilesMicrosoft ActiveSyncWCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\Program Files\CyberLink\PCM4Everio\PCM4Everio.exe"=
"C:\Program Files\CyberLink\PCM4Everio\EverioService.exe"=
"D:\eMule\emule.exe"=
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"=
"C:\Program Files\Windows Live\Messenger\livecall.exe"=
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileGloballyOpenPortsList]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R1 aswSP;avast! Self Protection;C:WINDOWSsystem32driversaswSP.sys [2008-07-19 78416]
R1 MUsbFltr;WayTechMUSBFilterDriver;C:WINDOWSsystem32driversMUsbFltr.sys [2004-12-15 8704]
R1 pctfw2;pctfw2;C:WINDOWSsystem32driverspctfw2.sys [2008-07-28 160792]
R2 AdobeActiveFileMonitor;Adobe Active File Monitor;C:Program FilesAdobePhotoshop Elements 3.0PhotoshopElementsFileAgent.exe [2004-10-12 98304]
R2 aswFsBlk;aswFsBlk;C:WINDOWSsystem32DRIVERSaswFsBlk.sys [2008-07-19 20560]
R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;C:Program FilesMicrosoft SQL ServerMSSQL$VAIO_VEDBBinnsqlservr.exe [2002-12-17 7520337]
R2 PhotoshopElementsDeviceConnect;Photoshop Elements Device Connect;C:Program FilesAdobePhotoshop Elements 3.0PhotoshopElementsDeviceConnect.exe [2004-10-12 118784]
S1 aiptektp;HyperPen;C:WINDOWSsystem32DRIVERSaiptektp.sys [2004-07-07 22272]
S3 Image Converter video recording monitor for VAIO Entertainment;Image Converter video recording monitor for VAIO Entertainment;C:Program FilesSonyImage Converter 2IcVzMon.exe [2005-02-24 32768]
S3 MEMSWEEP2;MEMSWEEP2;C:WINDOWSsystem3242.tmp [ ]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;C:Program FilesMicrosoft SQL ServerMSSQL$VAIO_VEDBBinnsqlagent.EXE [2002-12-17 311872]
S3 usbscan;Pilote de scanneur USB;C:WINDOWSsystem32DRIVERSusbscan.sys [2004-08-03 15104]
S3 USBSTOR;Pilote de stockage de masse USB;C:WINDOWSsystem32DRIVERSUSBSTOR.SYS [2004-08-04 26496]
.
- - - - ORPHANS REMOVED - - - -
BHO-{D8DF2673-5D48-49BF-95E6-3D2049F194D0} - C:WINDOWSsystem32qoMeEVpm.dll
BHO-{E07D22E1-CE3A-487F-B754-8044DBEDB049} - C:WINDOWSsystem32
qRHwTKa.dll
ShellExecuteHooks-{E07D22E1-CE3A-487F-B754-8044DBEDB049} - C:WINDOWSsystem32
qRHwTKa.dll
.
------- Supplementary Scan -------
.
O8 -: E&xporter vers Microsoft Excel - C:PROGRA~1MICROS~4OFFICE11EXCEL.EXE/3000
O8 -: Transfert par Image Converter 2 - C:Program FilesSonyImage Converter 2menu.htm
O15 -: Trusted Zone: *.sony-europe.com
O15 -: Trusted Zone: *.sonystyle-europe.com
O15 -: Trusted Zone: *.vaio-link.com
O16 -: Microsoft XML Parser for Java -
file://C:WINDOWSJavaclassesxmldso.cab
C:WINDOWSDownloaded Program FilesMicrosoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-07 22:52:11
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach,s ...
Balayage cach, autostart entries ...
Balayage des fichiers cach,s ...
Scan termin, avec succSs
Les fichiers cach,s: 0
**************************************************************************
[HKEY_LOCAL_MACHINESystemControlSet001ServicesMEMSWEEP2]
"ImagePath"="??C:WINDOWSsystem3242.tmp"
.
------------------------ Other Running Processes ------------------------
.
C:Program FilesIntelWirelessBinEvtEng.exe
C:Program FilesIntelWirelessBinS24EvMon.exe
C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe
C:Program FilesAlwil SoftwareAvast4ashServ.exe
C:Program FilesAviraAntiVir PersonalEdition Classicsched.exe
C:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe
C:Program FilesGrisoftAVG Anti-Spyware 7.5guard.exe
C:Program FilesSymantecLiveUpdateAluSchedulerSvc.exe
C:WINDOWSsystem32HPZipm12.exe
C:Program FilesIntelWirelessBinRegSrvc.exe
C:Program FilesCyberLinkShared FilesRichVideo.exe
C:Program FilesSpyware DoctorpctsAuxs.exe
C:Program FilesSonyVAIO Event ServiceVESMgr.exe
C:Program FilesApointApntEx.exe
C:Program FilesFichiers communsSony SharedVAIO Entertainment PlatformVCSWVCSW.exe
C:Program FilesFichiers communsSony SharedVAIO Entertainment PlatformVzCdbVzCdbSvc.exe
C:WINDOWSsystem32igfxext.exe
C:Program FilesFichiers communsSony SharedVAIO Entertainment PlatformVzCdbVzFw.exe
C:PROGRA~1MI3AA1~1
apimgr.exe
C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe
C:WINDOWSsystem32wscntfy.exe
C:Program FilesAlwil SoftwareAvast4ashWebSv.exe
C:Program FilesFichiers communsSony SharedAVLibSSScsiSV.exe
C:Program FilesFichiers communsSony SharedVAIO EntertainmentVzRsVzRs.exe
C:Program FilesAviraAntiVir PersonalEdition Classicavwsc.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-09-07 23:03:06 - machine was rebooted [Xavier]
ComboFix-quarantined-files.txt 2008-09-07 21:02:50
Pre-Run: 4,511,371,264 octets libres
Post-Run: 4,953,473,024 octets libres
265 --- E O F --- 2008-09-04 20:01:56
============================================================
SmitFraudFix v2.346
Rapport fait à 8:02:23,56, 08/09/2008
Executé à partir de C:Documents and SettingsXavierBureauSmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode sans echec
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Arret des processus
»»»»»»»»»»»»»»»»»»»»»»»» hosts
127.0.0.1 localhost
»»»»»»»»»»»»»»»»»»»»»»»» VACFix
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix
S!Ri's WS2Fix: LSP not Found.
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés
C:WINDOWSsystem321.ico supprimé
C:WINDOWSsystem322.ico supprimé
C:Program FilesPCHealthCenter supprimé
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
AntiXPVSTFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» RK
»»»»»»»»»»»»»»»»»»»»»»»» DNS
»»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre
Nettoyage terminé.
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin
==========================================================
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:46:55, on 08/09/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:Program FilesIntelWirelessBinEvtEng.exe
C:Program FilesIntelWirelessBinS24EvMon.exe
C:WINDOWSsystem32spoolsv.exe
C:Program FilesAviraAntiVir PersonalEdition Classicsched.exe
C:Program FilesAdobePhotoshop Elements 3.0PhotoshopElementsFileAgent.exe
C:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe
C:Program FilesGrisoftAVG Anti-Spyware 7.5guard.exe
C:Program FilesFichiers communsSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PIFSvc.exe
C:Program FilesMicrosoft SQL ServerMSSQL$VAIO_VEDBBinnsqlservr.exe
C:WINDOWSExplorer.EXE
C:Program FilesAdobePhotoshop Elements 3.0PhotoshopElementsDeviceConnect.exe
C:Program FilesSymantecLiveUpdateALUSchedulerSvc.exe
C:WINDOWSsystem32HPZipm12.exe
C:Program FilesIntelWirelessBinRegSrvc.exe
C:Program FilesCyberLinkShared FilesRichVideo.exe
C:Program FilesSpyware DoctorpctsAuxs.exe
C:WINDOWSsystem32svchost.exe
C:Program FilesSonyVAIO Event ServiceVESMgr.exe
C:Program FilesSonyVAIO Media Integrated ServerVMISrv.exe
C:Program FilesApointApoint.exe
C:WINDOWSRTHDCPL.EXE
C:WINDOWSsystem32ICO.EXE
C:WINDOWSsystem32hkcmd.exe
C:Program FilesSonyVAIO Power ManagementSPMgr.exe
C:Program FilesSonyISB UtilityISBMgr.exe
C:Program FilesHPHP Software UpdateHPWuSchd2.exe
C:Program FilesJavajre1.6.0_05injusched.exe
C:PROGRA~1SonySONICS~1SsAAD.exe
C:Program FilesSonyVAIO Media Integrated ServerPlatformVMConsole.exe
C:WINDOWSsystem32NILaunch.exe
C:WINDOWSsystem32atwtusb.exe
C:Program FilesFichiers communsSony SharedVAIO Entertainment PlatformVCSWVCSW.exe
C:Program FilesSonyVAIO Update 3VAIOUpdt.exe
C:Program FilesApointApntex.exe
C:Program FilesQuickTimeqttask.exe
C:Program FilesFichiers communsSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PIFSvc.exe
C:Program FilesCyberLinkPCM4EverioEverioService.exe
C:Program FilesAdobeReader 8.0ReaderReader_sl.exe
C:Program FilesGrisoftAVG Anti-Spyware 7.5avgas.exe
C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe
C:WINDOWSsystem32ctfmon.exe
C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
C:Program FilesFichiers communsSony SharedVAIO Entertainment PlatformVzCdbVzCdbSvc.exe
C:Program FilesMicrosoft ActiveSyncwcescomm.exe
C:Program FilesSonyVAIO Media Integrated ServerPlatformSV_Httpd.exe
C:Program FilesWindows LiveMessengerMsnMsgr.Exe
C:Program FilesFichiers communsSony SharedVAIO Entertainment PlatformVzCdbVzFw.exe
C:Program FilesSonyVAIO Media Integrated ServerPlatformUPnPFramework.exe
C:PROGRA~1MI3AA1~1
apimgr.exe
C:Program FilesFichiers communsSony SharedVAIO EntertainmentVzRsVzRs.exe
C:Program FilesFichiers communsSony SharedAVLibSSScsiSV.exe
C:WINDOWSsystem32wuauclt.exe
C:WINDOWSsystem32wscntfy.exe
C:WINDOWSsystem32wuauclt.exe
C:Documents and SettingsXavierBureauSniffle.exe
C:WINDOWSsystem32msiexec.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Liens
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:Program FilesJavajre1.6.0_05inssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:Program FilesFichiers communsMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:program filesgooglegoogletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:Program FilesGoogleGoogleToolbarNotifier2.0.301.7164swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:program filesgooglegoogletoolbar2.dll
O4 - HKLM..Run: [Apoint] C:Program FilesApointApoint.exe
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM..Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM..Run: [IgfxTray] C:WINDOWSsystem32igfxtray.exe
O4 - HKLM..Run: [HotKeysCmds] C:WINDOWSsystem32hkcmd.exe
O4 - HKLM..Run: [SonyPowerCfg] C:Program FilesSonyVAIO Power ManagementSPMgr.exe
O4 - HKLM..Run: [ISBMgr.exe] C:Program FilesSonyISB UtilityISBMgr.exe
O4 - HKLM..Run: [HP Software Update] "C:Program FilesHPHP Software UpdateHPWuSchd2.exe"
O4 - HKLM..Run: [SunJavaUpdateSched] "C:Program FilesJavajre1.6.0_05injusched.exe"
O4 - HKLM..Run: [SsAAD.exe] C:PROGRA~1SonySONICS~1SsAAD.exe
O4 - HKLM..Run: [VMConsole.exe] C:Program FilesSonyVAIO Media Integrated ServerPlatformVMConsole.exe /windowmin
O4 - HKLM..Run: [Net-It Launcher] C:WINDOWSsystem32NILaunch.exe
O4 - HKLM..Run: [atwtusb] atwtusb.exe beta
O4 - HKLM..Run: [VAIO Update 3] "C:Program FilesSonyVAIO Update 3VAIOUpdt.exe" /Stationary
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [Symantec PIF AlertEng] "C:Program FilesFichiers communsSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PIFSvc.exe" /a /m "C:Program FilesFichiers communsSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}AlertEng.dll"
O4 - HKLM..Run: [EverioService] "C:Program FilesCyberLinkPCM4EverioEverioService.exe"
O4 - HKLM..Run: [Adobe Reader Speed Launcher] "C:Program FilesAdobeReader 8.0ReaderReader_sl.exe"
O4 - HKLM..Run: [!AVG Anti-Spyware] "C:Program FilesGrisoftAVG Anti-Spyware 7.5avgas.exe" /minimized
O4 - HKLM..Run: [avgnt] "C:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe" /min
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [swg] C:Program FilesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe
O4 - HKCU..Run: [H/PC Connection Agent] "C:Program FilesMicrosoft ActiveSyncwcescomm.exe"
O4 - HKCU..Run: [MsnMsgr] "C:Program FilesWindows LiveMessengerMsnMsgr.Exe" /background
O4 - HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'SERVICE RESEAU')
O4 - HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'SYSTEM')
O4 - HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'Default user')
O4 - .DEFAULT User Startup: VAIO Launcher.lnk = C:Program FilesSonyVAIO LauncherLauncher.exe (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel -
res://C:PROGRA~1MICROS~4OFFICE11EXCEL.EXE/3000
O8 - Extra context menu item: Transfert par Image Converter 2 - C:Program FilesSonyImage Converter 2menu.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_05inssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:Program FilesJavajre1.6.0_05inssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:PROGRA~1MI3AA1~1INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:PROGRA~1MI3AA1~1INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:PROGRA~1MI3AA1~1INetRepl.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/fr/
O15 - Trusted Zone: *.sony-europe.com
O15 - Trusted Zone: *.sonystyle-europe.com
O15 - Trusted Zone: *.vaio-link.com
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) -
http://a1540.g.akamai.net/7/1540/52/200 ... plugin.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/microso ... 3508891296
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/s ... wflash.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:Program FilesFichiers communsAdobe Systems SharedServiceAdobelmsvc.exe
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:Program FilesAdobePhotoshop Elements 3.0PhotoshopElementsFileAgent.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:Program FilesAviraAntiVir PersonalEdition Classicsched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:Program FilesGrisoftAVG Anti-Spyware 7.5guard.exe
O23 - Service: EvtEng - Intel Corporation - C:Program FilesIntelWirelessBinEvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:Program FilesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:Program FilesSonyImage Converter 2IcVzMon.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:Program FilesiPodiniPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:PROGRA~1SymantecLIVEUP~1LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:Program FilesFichiers communsSymantec SharedPIF{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}PIFSvc.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:Program FilesFichiers communsSony SharedAVLibMSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32
vsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:Program FilesFichiers communsSony SharedAVLibPACSPTISVR.exe
O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:Program FilesAdobePhotoshop Elements 3.0PhotoshopElementsDeviceConnect.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:Program FilesSymantecLiveUpdateALUSchedulerSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:WINDOWSsystem32HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:Program FilesIntelWirelessBinRegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:Program FilesCyberLinkShared FilesRichVideo.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:Program FilesIntelWirelessBinS24EvMon.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:Program FilesSpyware DoctorpctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:Program FilesSpyware DoctorpctsSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:Program FilesFichiers communsSony SharedAVLibSPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:Program FilesFichiers communsSony SharedAVLibSSScsiSV.exe
O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:Program FilesFichiers communsSony SharedVAIO EntertainmentVzRsVzRs.exe
O23 - Service: VAIO Entertainment Task Scheduler - Sony Corporation - C:Program FilesSonyVAIO EntertainmentVzTaskScheduler.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:Program FilesFichiers communsSony SharedVAIO Entertainment PlatformVzCsVzHardwareResourceManagerVzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:Program FilesSonyVAIO Event ServiceVESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:Program FilesSonyVAIO Media Integrated ServerVMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:Program FilesSonyVAIO Media Integrated ServerPlatformSV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:Program FilesSonyVAIO Media Integrated ServerPlatformUPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:Program FilesSonyVAIO Media Integrated ServerPlatformVmGateway.exe
O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:Program FilesSonyVAIO Cooperated InitialisationVCI_SVC.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:Program FilesFichiers communsSony SharedVAIO Entertainment PlatformVCSWVCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:Program FilesFichiers communsSony SharedVAIO Entertainment PlatformVzCdbVzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:Program FilesFichiers communsSony SharedVAIO Entertainment PlatformVzCdbVzFw.exe
--
End of file - 13582 bytes
=======================================================