jeanmimigab a écrit:re,
Tu m'as poster le premier rapport que tu as fait hier, ce n'est pas celui là qu'il me faut, si il n'est pas présent ici
C:\combofix.txt c'est que le scan n'est pas arrivé à son terme.
Si tu ne le trouve pas fait cela...
> crée un nouveau document texte sur ton bureau
> pour cela clic droit sur le bureau > Nouveau > document texte > copie et colle le contenu de la citation ci-dessous à l'intérieur
KillAll::
File::
c:\windows\Fonts\82D34D77.EXE -k
Collect::
c:\windows\system32\aybeg.tmp
c:\windows\system32\ghhkj.tmp
c:\windows\system32\oqtss.tmp
C:\Program Files\NetRatingsNetSight\NetSight\NielsenOnline.exe
Folder::
C:\Program Files\NetRatingsNetSight
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NielsenOnline"=-
RegLock::
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•9~*]
FileLook::
c:\documents and settings\Jocelyne\Local Settings\Application Data\plupz.exe
Respect à la lettre la procédure d'enregistrement suivante,c'est très important> ensuite clic sur fichier > enregistrer sous...
> dans la fenêtre d'enregistrement choisie le
bureau comme destination > dans type choisie
tous les fichiers > et dans nom du fichier tape
CFScript.txt > ensuite clic sur enregistrer et ferme le document texte.
> fait un
glisser/déposer(clic-gauche enfoncer sur CFScript.txt et tu fait glisser) de ce fichier
CFScript.txt sur le fichier
KittyFix.exe comme sur cette capture.
> une fenêtre bleue va apparaître,suis les instructions
patiente le temps du scan. Le bureau va disparaître à plusieurs reprises,c'est normal!
> Ne touche à rien
tant que le scan n'est pas terminé > Vers la fin du scan, une fenêtre va
peut être apparaître et t'indiquer que combofix doit uploader des fichiers, si c'est le cas,cliques sur "ok" et patiente jusqu'à la fin du scan
> Une fois le scan achevé, un rapport va s'afficher,
ferme le...
Ensuite très important...Redémarre ton pc une nouvelle fois... et postes le rapport qui se trouve à cet emplacement
C:\ComboFix.txt @++
C'est encore moi je tiens le coup!!!!
ci dessous le rapport demandé j'espere que ce sera bon pour pouvoir avancer!
bonne soirée a++
ComboFix 09-12-19.03 - Jocelyne 20/12/2009 19:52:42.2.2 - x86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.1022.679 [GMT 1:00]
Lancé depuis: c:\documents and settings\Jocelyne\Bureau\KittyFix.exe
Commutateurs utilisés :: c:\documents and settings\Jocelyne\Bureau\CFScript.txt
AV: avast! antivirus 4.8.1368 [VPS 091220-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FILE ::
"c:\windows\Fonts\82D34D77.EXE -k"
file zipped: c:\program files\NetRatingsNetSight\NetSight\NielsenOnline.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\NetRatingsNetSight
c:\program files\NetRatingsNetSight\NetSight\download\authrsp.xml
c:\program files\NetRatingsNetSight\NetSight\download\communication.dll
c:\program files\NetRatingsNetSight\NetSight\download\core.cab
c:\program files\NetRatingsNetSight\NetSight\download\data1.cab
c:\program files\NetRatingsNetSight\NetSight\download\data2.cab
c:\program files\NetRatingsNetSight\NetSight\download\data3.cab
c:\program files\NetRatingsNetSight\NetSight\download\data4.cab
c:\program files\NetRatingsNetSight\NetSight\download\data5.cab
c:\program files\NetRatingsNetSight\NetSight\download\data6.cab
c:\program files\NetRatingsNetSight\NetSight\download\data7.cab
c:\program files\NetRatingsNetSight\NetSight\download\km_filter.sys
c:\program files\NetRatingsNetSight\NetSight\download\meter.dll
c:\program files\NetRatingsNetSight\NetSight\download\metercfg.xml
c:\program files\NetRatingsNetSight\NetSight\download\msvcp71.dll
c:\program files\NetRatingsNetSight\NetSight\download\msvcr71.dll
c:\program files\NetRatingsNetSight\NetSight\download\nielgfx.cat
c:\program files\NetRatingsNetSight\NetSight\download\nielgfx.inf
c:\program files\NetRatingsNetSight\NetSight\download\NielGfx.sys
c:\program files\NetRatingsNetSight\NetSight\download\nielprt.cat
c:\program files\NetRatingsNetSight\NetSight\download\nielprt.inf
c:\program files\NetRatingsNetSight\NetSight\download\nielprt.sys
c:\program files\NetRatingsNetSight\NetSight\download\nielprt2.inf
c:\program files\NetRatingsNetSight\NetSight\download\nielprt2.sys
c:\program files\NetRatingsNetSight\NetSight\download\NielsenTestCert.cer
c:\program files\NetRatingsNetSight\NetSight\download\nnrnstdi.sys
c:\program files\NetRatingsNetSight\NetSight\download\NNRNSTDI.VXD
c:\program files\NetRatingsNetSight\NetSight\download\npap.dll
c:\program files\NetRatingsNetSight\NetSight\download\npdav3.dll
c:\program files\NetRatingsNetSight\NetSight\download\npfilters.dll
c:\program files\NetRatingsNetSight\NetSight\download\npftp.dll
c:\program files\NetRatingsNetSight\NetSight\download\nphooks.dll
c:\program files\NetRatingsNetSight\NetSight\download\nphttp.dll
c:\program files\NetRatingsNetSight\NetSight\download\npiptool.exe
c:\program files\NetRatingsNetSight\NetSight\download\npitune.dll
c:\program files\NetRatingsNetSight\NetSight\download\npmms.dll
c:\program files\NetRatingsNetSight\NetSight\download\npnsobsvr.dll
c:\program files\NetRatingsNetSight\NetSight\download\npsession.dll
c:\program files\NetRatingsNetSight\NetSight\download\npshtool.exe
c:\program files\NetRatingsNetSight\NetSight\download\npsocket.dll
c:\program files\NetRatingsNetSight\NetSight\download\npsp1.dll
c:\program files\NetRatingsNetSight\NetSight\download\npsurvey.dll
c:\program files\NetRatingsNetSight\NetSight\download\nptdi.dll
c:\program files\NetRatingsNetSight\NetSight\download\nptrackers.dll
c:\program files\NetRatingsNetSight\NetSight\download\npwmi.dll
c:\program files\NetRatingsNetSight\NetSight\download\nscore.dll
c:\program files\NetRatingsNetSight\NetSight\download\nsgkff10.dll
c:\program files\NetRatingsNetSight\NetSight\download\nsgkff15.dll
c:\program files\NetRatingsNetSight\NetSight\download\nsgkff20.dll
c:\program files\NetRatingsNetSight\NetSight\download\nsgkff30.dll
c:\program files\NetRatingsNetSight\NetSight\download\nsgkff31.dll
c:\program files\NetRatingsNetSight\NetSight\download\nsitplg.dll
c:\program files\NetRatingsNetSight\NetSight\download\nsstmt.exe
c:\program files\NetRatingsNetSight\NetSight\download\pkginfo.xml
c:\program files\NetRatingsNetSight\NetSight\download\spsys.dll
c:\program files\NetRatingsNetSight\NetSight\download\WdfCoInstaller01007.dll
c:\program files\NetRatingsNetSight\NetSight\download\wmpplugin.dll
c:\program files\NetRatingsNetSight\NetSight\Helpdesk.htm
c:\program files\NetRatingsNetSight\NetSight\meter1\authrsp.xml
c:\program files\NetRatingsNetSight\NetSight\meter1\communication.dll
c:\program files\NetRatingsNetSight\NetSight\meter1\core.cab
c:\program files\NetRatingsNetSight\NetSight\meter1\data1.cab
c:\program files\NetRatingsNetSight\NetSight\meter1\data2.cab
c:\program files\NetRatingsNetSight\NetSight\meter1\data3.cab
c:\program files\NetRatingsNetSight\NetSight\meter1\data4.cab
c:\program files\NetRatingsNetSight\NetSight\meter1\data5.cab
c:\program files\NetRatingsNetSight\NetSight\meter1\data6.cab
c:\program files\NetRatingsNetSight\NetSight\meter1\km_filter.sys
c:\program files\NetRatingsNetSight\NetSight\meter1\meter.dll
c:\program files\NetRatingsNetSight\NetSight\meter1\metercfg.xml
c:\program files\NetRatingsNetSight\NetSight\meter1\msvcp71.dll
c:\program files\NetRatingsNetSight\NetSight\meter1\msvcr71.dll
c:\program files\NetRatingsNetSight\NetSight\meter1\nnrnstdi.sys
c:\program files\NetRatingsNetSight\NetSight\meter1\NNRNSTDI.VXD
c:\program files\NetRatingsNetSight\NetSight\meter1\npdav3.dll
c:\program files\NetRatingsNetSight\NetSight\meter1\npfilters.dll
c:\program files\NetRatingsNetSight\NetSight\meter1\npftp.dll
c:\program files\NetRatingsNetSight\NetSight\meter1\nphooks.dll
c:\program files\NetRatingsNetSight\NetSight\meter1\nphttp.dll
c:\program files\NetRatingsNetSight\NetSight\meter1\npiptool.exe
c:\program files\NetRatingsNetSight\NetSight\meter1\npitune.dll
c:\program files\NetRatingsNetSight\NetSight\meter1\npmms.dll
c:\program files\NetRatingsNetSight\NetSight\meter1\npnsobsvr.dll
c:\program files\NetRatingsNetSight\NetSight\meter1\nppopsmtp.dll
c:\program files\NetRatingsNetSight\NetSight\meter1\npsession.dll
c:\program files\NetRatingsNetSight\NetSight\meter1\npshtool.exe
c:\program files\NetRatingsNetSight\NetSight\meter1\npsocket.dll
c:\program files\NetRatingsNetSight\NetSight\meter1\npsp1.dll
c:\program files\NetRatingsNetSight\NetSight\meter1\npsurvey.dll
c:\program files\NetRatingsNetSight\NetSight\meter1\nptdi.dll
c:\program files\NetRatingsNetSight\NetSight\meter1\nptrackers.dll
c:\program files\NetRatingsNetSight\NetSight\meter1\npwmi.dll
c:\program files\NetRatingsNetSight\NetSight\meter1\nscore.dll
c:\program files\NetRatingsNetSight\NetSight\meter1\nsgkff10.dll
c:\program files\NetRatingsNetSight\NetSight\meter1\nsgkff15.dll
c:\program files\NetRatingsNetSight\NetSight\meter1\nsgkff20.dll
c:\program files\NetRatingsNetSight\NetSight\meter1\nsgkff30.dll
c:\program files\NetRatingsNetSight\NetSight\meter1\nsitplg.dll
c:\program files\NetRatingsNetSight\NetSight\meter1\nslog\err.log
c:\program files\NetRatingsNetSight\NetSight\meter1\nsstmt.exe
c:\program files\NetRatingsNetSight\NetSight\meter1\nsupload.ini
c:\program files\NetRatingsNetSight\NetSight\meter1\pkginfo.xml
c:\program files\NetRatingsNetSight\NetSight\meter1\spsys.dll
c:\program files\NetRatingsNetSight\NetSight\meter1\wmpplugin.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\authrsp.xml
c:\program files\NetRatingsNetSight\NetSight\meter2\communication.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\core.cab
c:\program files\NetRatingsNetSight\NetSight\meter2\data1.cab
c:\program files\NetRatingsNetSight\NetSight\meter2\data2.cab
c:\program files\NetRatingsNetSight\NetSight\meter2\data3.cab
c:\program files\NetRatingsNetSight\NetSight\meter2\data4.cab
c:\program files\NetRatingsNetSight\NetSight\meter2\data5.cab
c:\program files\NetRatingsNetSight\NetSight\meter2\data6.cab
c:\program files\NetRatingsNetSight\NetSight\meter2\data7.cab
c:\program files\NetRatingsNetSight\NetSight\meter2\km_filter.sys
c:\program files\NetRatingsNetSight\NetSight\meter2\meter.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\metercfg.xml
c:\program files\NetRatingsNetSight\NetSight\meter2\msvcp71.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\msvcr71.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\nielgfx.cat
c:\program files\NetRatingsNetSight\NetSight\meter2\nielgfx.inf
c:\program files\NetRatingsNetSight\NetSight\meter2\NielGfx.sys
c:\program files\NetRatingsNetSight\NetSight\meter2\nielprt.cat
c:\program files\NetRatingsNetSight\NetSight\meter2\nielprt.inf
c:\program files\NetRatingsNetSight\NetSight\meter2\nielprt.sys
c:\program files\NetRatingsNetSight\NetSight\meter2\nielprt2.inf
c:\program files\NetRatingsNetSight\NetSight\meter2\nielprt2.sys
c:\program files\NetRatingsNetSight\NetSight\meter2\NielsenTestCert.cer
c:\program files\NetRatingsNetSight\NetSight\meter2\nnrnstdi.sys
c:\program files\NetRatingsNetSight\NetSight\meter2\NNRNSTDI.VXD
c:\program files\NetRatingsNetSight\NetSight\meter2\npap.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\npdav3.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\npfilters.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\npftp.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\nphooks.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\nphttp.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\npiptool.exe
c:\program files\NetRatingsNetSight\NetSight\meter2\npitune.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\npmms.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\npnsobsvr.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\npsession.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\npshtool.exe
c:\program files\NetRatingsNetSight\NetSight\meter2\npsocket.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\npsp1.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\npsurvey.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\nptdi.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\nptrackers.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\npwmi.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\nscore.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\nsgkff10.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\nsgkff15.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\nsgkff20.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\nsgkff30.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\nsgkff31.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\nsitplg.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\nslog\log.log
c:\program files\NetRatingsNetSight\NetSight\meter2\nsstmt.exe
c:\program files\NetRatingsNetSight\NetSight\meter2\nsupload.ini
c:\program files\NetRatingsNetSight\NetSight\meter2\pkginfo.xml
c:\program files\NetRatingsNetSight\NetSight\meter2\spsys.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\WdfCoInstaller01007.dll
c:\program files\NetRatingsNetSight\NetSight\meter2\wmpplugin.dll
c:\program files\NetRatingsNetSight\NetSight\mmcfg.xml
c:\program files\NetRatingsNetSight\NetSight\NielsenOnline.exe
c:\program files\NetRatingsNetSight\NetSight\nsinfo.ini
c:\program files\NetRatingsNetSight\NetSight\nsmgrutil.exe
c:\program files\NetRatingsNetSight\NetSight\nsmmc.dll
c:\program files\NetRatingsNetSight\NetSight\nsmmgr.dll
c:\program files\NetRatingsNetSight\NetSight\NSSetup.exe
c:\program files\NetRatingsNetSight\NetSight\setup.ini
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-11-20 au 2009-12-20 ))))))))))))))))))))))))))))))))))))
.
2009-12-20 18:49 . 2009-12-20 18:50 -------- d-----w- C:\KittyFix
2009-12-19 15:18 . 2009-12-19 15:18 -------- d-----w- c:\program files\Trend Micro
2009-12-18 16:32 . 2009-12-18 16:32 -------- d-----w- c:\documents and settings\Jocelyne\Application Data\Malwarebytes
2009-12-18 16:32 . 2009-12-03 15:14 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-12-18 16:32 . 2009-12-18 16:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-12-18 16:32 . 2009-12-03 15:13 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-12-18 16:32 . 2009-12-18 16:32 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-12-17 15:58 . 2009-12-17 15:58 -------- d-----w- c:\program files\ToniArts
2009-11-29 16:07 . 2009-11-29 16:07 -------- d-----w- c:\program files\iPod
2009-11-29 16:07 . 2009-11-29 16:09 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-12-18 04:08 . 2008-07-06 08:33 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-12-17 18:19 . 2008-07-06 08:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-12-17 15:58 . 2006-11-14 07:28 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-15 03:38 . 2004-09-23 17:12 86380 ----a-w- c:\windows\system32\perfc00C.dat
2009-12-15 03:38 . 2004-09-23 17:12 514626 ----a-w- c:\windows\system32\perfh00C.dat
2009-11-29 16:09 . 2009-04-22 05:01 -------- d-----w- c:\program files\iTunes
2009-11-29 16:08 . 2008-06-14 17:24 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-11-29 16:07 . 2008-10-22 13:48 -------- d-----w- c:\program files\Fichiers communs\Apple
2009-11-29 16:03 . 2006-11-14 07:44 -------- d-----w- c:\program files\QuickTime
2009-11-29 15:14 . 2009-11-29 15:14 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-11-29 14:10 . 2009-06-23 10:01 -------- d-----w- c:\program files\Safari
2009-11-29 13:58 . 2009-11-29 13:58 79144 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe
2009-11-24 23:54 . 2008-10-18 16:39 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-11-24 23:51 . 2008-10-18 16:40 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-11-24 23:50 . 2008-10-18 16:40 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-11-24 23:50 . 2008-10-18 16:40 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-11-24 23:50 . 2008-10-18 16:40 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-11-24 23:49 . 2008-10-18 16:40 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-11-24 23:48 . 2008-10-18 16:40 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-11-24 23:47 . 2008-10-18 16:40 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-11-24 23:47 . 2008-10-18 16:40 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-11-22 16:59 . 2007-03-06 09:40 -------- d-----w- c:\documents and settings\Jocelyne\Application Data\Canon
2009-11-12 05:14 . 2009-10-24 10:17 130656 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-09 17:02 . 2007-01-27 14:02 130656 -c--a-w- c:\documents and settings\Jocelyne\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-11-06 11:52 . 2006-11-14 07:39 -------- d-----w- c:\program files\Java
2009-11-06 10:29 . 2009-11-06 10:29 -------- d-----w- c:\program files\Microsoft Office Outlook Connector
2009-11-06 10:27 . 2008-04-20 10:10 -------- d-----w- c:\program files\Windows Live
2009-11-06 08:14 . 2009-11-06 08:14 152576 ----a-w- c:\documents and settings\Jocelyne\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2009-11-06 03:22 . 2009-10-27 15:46 98304 ----a-w- c:\documents and settings\All Users\Application Data\NexonEU\NGM\nxgameeu.dll
2009-11-06 03:22 . 2009-10-27 15:46 532480 ----a-w- c:\documents and settings\All Users\Application Data\NexonEU\NGM\NGMDll.dll
2009-11-06 03:22 . 2009-10-27 15:46 331776 ----a-w- c:\documents and settings\All Users\Application Data\NexonEU\NGM\NGMResource.dll
2009-11-06 03:22 . 2009-10-27 15:46 258352 ----a-w- c:\documents and settings\All Users\Application Data\NexonEU\NGM\unicows.dll
2009-11-06 03:22 . 2009-10-27 15:46 155648 ----a-w- c:\documents and settings\All Users\Application Data\NexonEU\NGM\NGM.exe
2009-10-31 10:43 . 2009-10-27 15:46 -------- d-----w- c:\documents and settings\All Users\Application Data\NexonEU
2009-10-29 07:42 . 2004-09-23 17:11 916480 ------w- c:\windows\system32\wininet.dll
2009-10-27 16:43 . 2006-11-14 07:43 -------- d-----w- c:\program files\Fichiers communs\Adobe
2009-10-27 10:14 . 2009-10-27 10:14 421888 ----a-w- c:\windows\NEXON_EU_DownloaderUpdater.exe
2009-10-24 10:17 . 2009-10-24 10:17 -------- d-----w- c:\documents and settings\LocalService\Application Data\ATI
2009-10-21 05:39 . 2004-09-23 17:11 75776 ----a-w- c:\windows\system32\strmfilt.dll
2009-10-21 05:39 . 2004-09-23 17:10 25088 ----a-w- c:\windows\system32\httpapi.dll
2009-10-20 16:20 . 2004-08-03 22:00 265728 ----a-w- c:\windows\system32\drivers\http.sys
2009-10-13 10:33 . 2004-09-23 17:11 271360 ----a-w- c:\windows\system32\oakley.dll
2009-10-12 13:39 . 2004-09-23 17:11 79872 ----a-w- c:\windows\system32\raschap.dll
2009-10-12 13:39 . 2004-09-23 17:11 150528 ----a-w- c:\windows\system32\rastls.dll
2009-10-11 03:17 . 2008-12-16 18:57 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-10-02 18:57 . 2009-06-06 18:08 2352 -c--a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-09-22 09:05 . 2009-09-22 09:05 286720 -c--a-w- c:\documents and settings\Jocelyne\Local Settings\Application Data\plupz.exe
2008-10-27 09:37 . 2008-10-27 09:37 699488 -c--a-w- c:\program files\JUN2007_d3dx10_34_x86.cab
2008-10-27 09:36 . 2008-10-27 09:36 526160 -c--a-w- c:\program files\DXSETUP.exe
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
--- c:\documents and settings\Jocelyne\Local Settings\Application Data\plupz.exe ---
Company: ------
File Description: ------
File Version: ------
Product Name: ------
Copyright: ------
Original Filename: ------
File size: 286720
Created time: 2009-09-22 09:05
Modified time: 2009-09-22 09:05
MD5: 57783B91EC854151402A64DEE6E952D3
SHA1: 1AAA22341E50D160BCA33CF40E60952DCA55F5B1
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\lib\NMBgMonitor.exe" [2006-02-01 98304]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-25 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"RTHDCPL"="RTHDCPL.EXE" [2006-05-18 16207872]
"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]
"OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152]
"FixCamera"="c:\windows\FixCamera.exe" [2007-07-11 20480]
"tsnp2std"="c:\windows\tsnp2std.exe" [2007-05-12 270336]
"snp2std"="c:\windows\vsnp2std.exe" [2007-05-10 344064]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"VX1000"="c:\windows\vVX1000.exe" [2008-08-04 721936]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2008-08-04 160800]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Jocelyne\Menu D‚marrer\Programmes\D‚marrage\
MOH.lnk - c:\program files\OLITEC\MOH\LtMoh.exe [2006-6-29 188416]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
backup=c:\windows\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logiciel Kodak EasyShare.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Logiciel Kodak EasyShare.lnk
backup=c:\windows\pss\Logiciel Kodak EasyShare.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACTIVBOARD]
2003-05-02 09:31 24576 -c--a-w- c:\apps\ABOARD\ABOARD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DetectorApp]
2005-10-20 05:15 102400 -c--a-w- c:\program files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
2005-08-05 12:34 64512 ----a-w- c:\windows\ehome\ehtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
2004-08-10 13:00 208952 -c--a-w- c:\windows\ime\IMJP8_1\imjpmig.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 15:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-11-10 22:08 417792 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2006-11-14 07:44 26112 ----a-w- c:\program files\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmpcSys]
2005-11-17 08:51 975360 -c----w- c:\apps\SMP\SMPSYS.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"C-DillaCdaC11BA"=2 (0x2)
"USBDeviceService"=2 (0x2)
"ose"=3 (0x3)
"UleadBurningHelper"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AOL 9.0\\waol.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Firefly Studios\\Stronghold Legends\\StrongholdLegends.exe"=
"c:\\Program Files\\Firefly Studios\\Stronghold 2\\Stronghold2.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires III\\age3x.exe"=
"c:\\Program Files\\HD Publishing\\Joint Task Force\\jtf.exe"=
"c:\\Nexon\\NEXON_EU_Downloader\\NEXON_EU_Downloader_Engine.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonEU\\NGM\\NGM.exe"=
"c:\\Nexon\\Combat Arms EU\\NMService.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [18/10/2008 17:40 114768]
R1 nnrnstdi;nnrnstdi;c:\windows\system32\drivers\nnrnstdi.sys [24/04/2009 15:46 14336]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [18/10/2008 17:40 20560]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [15/03/2009 15:52 54752]
R3 3xHybrid;ASUSTek SAA713x PCI Card;c:\windows\system32\drivers\3xHybrid.sys [14/11/2006 08:29 882688]
R3 km_filter;km_filter;c:\windows\system32\drivers\km_filter.sys [24/04/2009 15:46 8832]
R3 X10Hid;X10 Hid Device;c:\windows\system32\drivers\x10hid.sys [14/11/2006 08:30 7040]
S0 nielprt;Nielsen Patch Service;c:\windows\system32\DRIVERS\nielprt.sys --> c:\windows\system32\DRIVERS\nielprt.sys [?]
S3 fsssvc;Service Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [05/08/2009 22:48 704864]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [19/12/2008 16:54 195752]
S3 NielGfx;Nielsen USB GFX;c:\windows\system32\drivers\nielgfx.sys --> c:\windows\system32\drivers\nielgfx.sys [?]
.
------- Examen supplémentaire -------
.
uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page =
hxxp://www.orange.fr/uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) =
hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBRIE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
DPF: {5392B545-31A5-4724-BEF3-4FED1D56FDAC} - file:///C:/Documents%20and%20Settings/Jocelyne/Local%20Settings/Application%20Data/Oberon%20Media/Oberon%20Games%20Host/DinerDash2_fr.1.0.0.70.cab
DPF: {741747F6-83B4-4FB9-A268-8CA4010762C8} -
hxxp://www3.snapfish.fr/SnapfishActivia2.cabDPF: {775879E2-7309-4619-BB02-AADE41F4B690} -
hxxp://jeuxenligne.orange.fr/orange2.0/ ... .0.0.9.cab.
- - - - ORPHELINS SUPPRIMES - - - -
AddRemove-NetSight - c:\progra~1\NETRAT~1\NetSight\NSSetup.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-12-20 20:03
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
c:\docume~1\Jocelyne\LOCALS~1\Temp\211062.cvr 308 bytes
c:\docume~1\Jocelyne\LOCALS~1\Temp\34C1D.dmp 822906 bytes
Scan terminé avec succès
Fichiers cachés: 2
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-2491051371-2032680782-3602060665-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h–€|ÿÿÿÿ¤•€|ù•9~*]
"C040AC1900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(516)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3696)
c:\program files\ScanSoft\OmniPageSE2.0\ophookSE2.dll
c:\progra~1\WINDOW~3\wmpband.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\progra~1\FICHIE~1\AOL\ACS\AOLacsd.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\eHome\ehRecvr.exe
c:\windows\eHome\ehSched.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\progra~1\COMMON~1\X10\Common\x10nets.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\RTHDCPL.EXE
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\dllhost.exe
.
**************************************************************************
.
Heure de fin: 2009-12-20 20:10:37 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-12-20 19:10
ComboFix2.txt 2009-12-19 15:06
Avant-CF: 142 586 503 168 octets libres
Après-CF: 142 630 125 568 octets libres
Current=4 Default=4 Failed=3 LastKnownGood=5 Sets=2,3,4,5
- - End Of File - - B12FCE03E3B1F9BA2915A20FAAD4FAB1