Après une bonne heure et demie de désinfection,voici les rapports mon commandant :
1.Navilog
Search Navipromo version 2.0.2 commencé le 08/10/2008 à 9:24:53,74
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Poster ce rapport sur le forum pour le faire analyser !!!
!!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!
Fix lancé depuis E:Program Files
avilog1
Mise a jour le 17.05.2007 a 23h00 by IL-MAFIOSO
Executé en mode normal
*** Recherche Programmes installes ***
*** Recherche dossiers dans E:WINDOWS ***
*** Recherche dossiers dans E:Program Files ***
*** Recherche dossiers dans E:Documents and SettingsAll UsersApplication Data ***
*** Recherche dossiers dans E:Documents and SettingssebApplication Data ***
*** Recherche avec BlackLight Engine/F-secure ***
BlackLight Engine est un produit de F-secure, pour + d'infos :
http://www.f-secure.com/blacklight/blacklight_help.html
F-SECURE BLACKLIGHT ROOTKIT ELIMINATOR
======================================
Copyright 2005-2006 F-Secure Corporation. All rights reserved.
This is a beta version. It will expire on 1st of April, 2007.
Version information: 2.2.1061.
[+] Started on 10/08/08 at 09:24:54.
[-] ERROR: This version of F-Secure BlackLight has expired.
[+] Exited on 10/08/08 at 09:24:54 (return code = 3).
*** Recherche fichiers ***
*** Recherche cles registre ***
Recherche dans [HKLMSOFTWAREMicrosoftWindowsCurrentVersionSharedDLLs]
Recherche dans [HKLMSOFTWAREMicrosoftWindowsCurrentVersionModuleUsage]
Recherche Clé Magic Control
*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)
1)Recherche fichiers connus:
2)Recherche Heuristique :
*
**
***
****
*****
******
*******
********
E:WINDOWSsystem32deadlink.exe trouvé !
E:WINDOWSsystem32Siw.exe trouvé !
*** Analyse Terminé le 08/10/2008 à 9:25:00,39 ***
2- combofix
ComboFix 08-10-08.01 - seb 2008-10-08 22:05:09.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1656 [GMT 2:00]
Lancé depuis: E:Documents and SettingssebBureaulalaibi.4.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
E:Documents and SettingsAll UsersApplication DataMicrosoftNetworkDownloaderqmgr0.dat
E:Documents and SettingsAll UsersApplication DataMicrosoftNetworkDownloaderqmgr1.dat
E:Documents and SettingssebApplication DataAdobecrc.dat
E:Documents and SettingssebApplication DataAdobePlayer.exe
E:WINDOWSsystem321.ico
E:WINDOWSsystem32cbXOIyAP.dll
E:WINDOWSsystem32emleca.dll
E:WINDOWSsystem32fccaAron.dll
E:WINDOWSsystem32hgGxYOIy.dll
E:WINDOWSsystem32irhaaaco.ini
E:WINDOWSsystem32jwugmjdx.dll
E:WINDOWSsystem32lnvntxkw.ini
E:WINDOWSsystem32mjmxssxo.dll
E:WINDOWSsystem32msxml71.dll
E:WINDOWSsystem32
orAaccf.ini
E:WINDOWSsystem32
orAaccf.ini2
E:WINDOWSsystem32ocaaahri.dll
E:WINDOWSsystem32ssqOFVME.dll
E:WINDOWSsystem32unnehb.dll
E:WINDOWSsystem32wkxtnvnl.dll
----- BITS: Il y a peut-être des sites infectés -----
hxxp://78.157.143.198
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-08 au 2008-10-08 ))))))))))))))))))))))))))))))))))))
.
2008-10-08 10:30 . 2008-10-08 10:34 <REP> d-------- E:Documents and SettingssebApplication DataFileZilla
2008-10-08 10:29 . 2008-10-08 10:29 <REP> d-------- E:Program FilesFileZilla FTP Client
2008-10-08 10:17 . 2008-10-08 15:44 <REP> d-------- E:Documents and SettingssebApplication DataCanon
2008-10-08 09:28 . 2007-09-06 00:22 289,144 --a------ E:WINDOWSsystem32VCCLSID.exe
2008-10-08 09:22 . 2008-10-08 22:01 <REP> d-------- E:Program FilesNavilog1
2008-10-08 09:02 . 2008-10-08 09:02 <REP> d-------- E:Program FilesTrend Micro
2008-10-07 21:52 . 2008-10-07 21:52 0 --ah----- E:WINDOWSsystem32driversMsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-10-07 21:52 . 2008-10-07 21:52 0 --ah----- E:WINDOWSsystem32driversMsft_Kernel_xusb21_01005.Wdf
2008-10-07 21:42 . 2008-10-07 21:42 <REP> d-------- E:Documents and SettingssebApplication DataDisney Interactive Studios
2008-10-07 12:42 . 2008-10-07 21:13 <REP> d-------- E:Documents and SettingssebApplication Datavlc
2008-10-07 12:03 . 2008-10-07 12:03 <REP> d-------- E:Program FilesMSXML 6.0
2008-10-07 12:00 . 2004-08-19 19:09 221,184 --a------ E:WINDOWSsystem32wmpns.dll
2008-10-07 10:53 . 2008-10-07 10:53 <REP> d-------- E:Program FilesAlwil Software
2008-10-07 01:04 . 2008-10-07 01:45 <REP> d-------- E:WINDOWSsystem32CatRoot_bak
2008-10-06 23:56 . 2008-10-07 12:03 <REP> d--h----- E:WINDOWS$hf_mig$
2008-10-06 23:49 . 2008-10-08 15:38 <REP> d-------- E:Program FilesMozilla Thunderbird
2008-10-06 23:49 . 2008-10-06 23:49 <REP> d-------- E:Documents and SettingssebApplication DataThunderbird
2008-10-06 23:45 . 2008-10-07 10:52 <REP> d-------- E:Documents and SettingsAll UsersApplication DataMcAfee
2008-10-06 23:42 . 2008-10-06 23:42 <REP> d-------- E:Program FilesNero
2008-10-06 23:42 . 2008-10-06 23:42 <REP> d-------- E:Program FilesFichiers communsNero
2008-10-06 23:42 . 2008-10-06 23:42 <REP> d-------- E:Documents and SettingsAll UsersApplication DataNero
2008-10-06 23:42 . 2006-03-17 11:45 1,757,184 --a------ E:WINDOWSsystem32imagX7.dll
2008-10-06 23:42 . 2006-03-17 11:45 802,816 --a------ E:WINDOWSsystem32imagXRA7.dll
2008-10-06 23:42 . 2006-03-17 11:45 497,296 --a------ E:WINDOWSsystem32imagXpr7.dll
2008-10-06 23:42 . 2006-03-17 14:49 368,640 --a------ E:WINDOWSsystem32TwnLib4.dll
2008-10-06 23:42 . 2006-03-17 11:45 258,048 --a------ E:WINDOWSsystem32imagXR7.dll
2008-10-06 23:40 . 2008-10-06 23:40 <REP> d-------- E:Documents and SettingsAll UsersApplication DataCanonIJPLM
2008-10-06 23:38 . 2008-10-06 23:38 <REP> d-------- E:Program FilesFichiers communsScanSoft Shared
2008-10-06 23:38 . 2008-10-06 23:38 <REP> d-------- E:Documents and SettingssebApplication DataScanSoft
2008-10-06 23:38 . 2008-10-06 23:38 <REP> d-------- E:Documents and SettingsAll UsersApplication DataScanSoft
2008-10-06 23:38 . 2008-10-06 23:38 <REP> d-------- E:Documents and SettingsAll UsersApplication DataInstallShield
2008-10-06 23:38 . 2004-08-03 23:01 25,856 --a------ E:WINDOWSsystem32driversusbprint.sys
2008-10-06 23:38 . 2004-08-03 22:58 15,104 --a------ E:WINDOWSsystem32driversusbscan.sys
2008-10-06 23:38 . 2008-10-06 23:38 412 --a------ E:WINDOWSMAXLINK.INI
2008-10-06 23:37 . 2008-10-06 23:37 <REP> d-------- E:Program FilesScanSoft
2008-10-06 23:37 . 2008-10-06 23:37 <REP> d-------- E:Program FilesFichiers communsCANON
2008-10-06 23:35 . 2008-10-06 23:35 <REP> d--h----- E:Documents and SettingsAll UsersApplication DataCanonBJ
2008-10-06 23:34 . 2008-10-06 23:34 <REP> d--h----- E:WINDOWSsystem32CanonIJ Uninstaller Information
2008-10-06 23:34 . 2008-10-06 23:34 <REP> d--h----- E:Program FilesCanonBJ
2008-10-06 23:34 . 2007-03-23 09:30 1,400,832 --a------ E:WINDOWSsystem32CNC520C.DLL
2008-10-06 23:34 . 2007-05-21 22:00 215,040 --a------ E:WINDOWSsystem32CNMLM94.DLL
2008-10-06 23:34 . 2007-03-19 03:23 200,704 --a------ E:WINDOWSsystem32CNC520L.DLL
2008-10-06 23:34 . 2007-03-15 07:12 188,416 --a------ E:WINDOWSsystem32CNC520O.DLL
2008-10-06 23:34 . 2007-03-23 09:29 98,304 --a------ E:WINDOWSsystem32CNC520I.DLL
2008-10-06 23:31 . 2008-10-06 23:31 0 --a------ E:WINDOWS
sreg.dat
2008-10-06 23:30 . 2008-10-06 23:39 <REP> d-------- E:Program FilesCanon
2008-10-06 23:27 . 2008-10-06 23:27 <REP> d-------- E:Program FilesLogitech
2008-10-06 23:27 . 2008-10-06 23:27 <REP> d-------- E:Documents and SettingsAll UsersApplication DataLogitech
2008-10-06 23:25 . 2008-10-06 23:25 0 --a------ E:WINDOWSmsicpl.ini
2008-10-06 23:21 . 2006-03-17 00:22 76,288 -ra------ E:WINDOWSsystem32SilSupp.cpl
2008-10-06 23:21 . 2004-11-01 21:21 10,368 -ra------ E:WINDOWSsystem32driversSiWinAcc.sys
2008-10-06 23:21 . 2005-10-18 21:15 5,504 -ra------ E:WINDOWSsystem32driversSiRemFil.sys
2008-10-06 23:09 . 2008-10-06 23:09 <REP> d-------- E:Program FilesAnalog Devices
2008-10-06 23:07 . 2008-10-06 23:07 <REP> d-------- E:WINDOWSASUSInstAll
2008-10-06 23:05 . 2008-10-06 23:05 <REP> d-------- E:Program FilesNVIDIA Corporation
2008-10-06 23:05 . 2008-10-07 00:10 <REP> d--h----- E:Program FilesInstallShield Installation Information
2008-10-06 23:04 . 2008-10-06 23:38 <REP> d-------- E:Program FilesFichiers communsInstallShield
2008-10-06 23:03 . 2008-10-06 23:21 34,183 --a------ E:WINDOWSAscd_tmp.ini
2008-10-06 23:03 . 2006-10-11 05:33 10,288 --a------ E:WINDOWSsystem32driversASUSHWIO.SYS
2008-10-06 23:03 . 2004-08-13 04:56 5,810 -ra------ E:WINDOWSsystem32driversASACPI.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-08 19:03 --------- d-----w E:Documents and SettingssebApplication Datasp2
2008-10-08 09:09 --------- d-----w E:Documents and SettingssebApplication DataAzureus
2008-10-06 22:47 --------- d-----w E:Documents and SettingsAll UsersApplication DataAzureus
2008-10-06 22:44 --------- d-----w E:Program FilesVideoLAN
2008-10-06 22:38 --------- d---a-w E:Documents and SettingsAll UsersApplication DataTEMP
2008-10-06 22:34 --------- d-----w E:Documents and SettingsAll UsersApplication DataMicrosoft Help
2008-10-06 22:33 --------- d-----w E:Program FilesMSBuild
2008-10-06 22:33 --------- d-----w E:Program FilesMicrosoft Works
2008-10-06 22:33 --------- d-----w E:Documents and SettingssebApplication DataURSoft
2008-10-06 22:32 --------- d-----w E:Program FilesMicrosoft.NET
2008-10-06 22:31 --------- d-----w E:Program FilesMicrosoft Visual Studio 8
2008-10-06 22:13 --------- d-----w E:Documents and SettingsLocalServiceApplication DataSACore
2008-10-06 22:09 --------- d-----w E:Documents and SettingssebApplication DataInstallShield
2008-10-06 22:08 --------- d-----w E:Program FilesElaborate Bytes
2008-10-06 22:00 --------- d-----w E:Documents and SettingsAll UsersApplication DataSiteAdvisor
2008-10-06 20:55 --------- d---a-w E:Documents and SettingssebApplication Datagtopala
2008-10-06 20:55 --------- d---a-w E:Documents and SettingssebApplication Dataaignes
2008-10-06 20:51 --------- d-----w E:Program FilesJava
2008-10-06 20:51 --------- d-----w E:Program FilesFichiers communsJava
2008-10-06 20:50 --------- d-----w E:Program FilesWMV9_VCM
2008-10-06 20:50 --------- d-----w E:Program FilesWindows Media Connect 2
2008-10-06 20:44 --------- d-----w E:Program FilesWSTARTUP
2008-10-06 20:44 --------- d-----w E:Program FilesUTILS
2008-10-06 20:44 --------- d-----w E:Program FilesMSXML 4.0
2008-10-06 20:44 --------- d-----w E:Program FilesJEUX
2008-10-06 20:40 --------- d-----w E:Program Filesmicrosoft frontpage
2008-10-06 19:45 266,240 ----a-w E:qmafxprs.dll
.
------- Sigcheck -------
2006-11-19 01:59 1035264 7ba68df484b550c1f75dd80ae1d7ef67 E:WINDOWSexplorer.exe
2008-04-14 04:34 1037824 f2317622d29f9ff0f88aeecd5f60f0dd E:WINDOWSSoftwareDistributionDownload44b6174a4a693136d02d4a7ecd7cbd54explorer.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
":::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::SOFTWAREMicrosoftWindowsCurrentVersionRun"="::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::SOFTWAREMicrosoftWindowsCurrentVersionRun" [X]
"ctfmon.exe"="E:WINDOWSsystem32ctfmon.exe" [2004-08-19 15360]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
":::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::SOFTWAREMicrosoftWindowsCurrentVersionRun"="::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::SOFTWAREMicrosoftWindowsCurrentVersionRun" [X]
"SoundMAXPnP"="E:Program FilesAnalog DevicesCoresmax4pnp.exe" [2006-12-18 868352]
"NvCplDaemon"="E:WINDOWSsystem32NvCpl.dll" [2007-10-25 8527872]
"WinSys2"="E:WINDOWSsystem32winsys2.exe" [2007-10-30 208896]
"NvMediaCenter"="E:WINDOWSsystem32NvMcTray.dll" [2007-10-25 81920]
"Launch LCDMon"="E:Program FilesLogitechGamePanel SoftwareLCD ManagerLCDMon.exe" [2007-07-18 1687824]
"Launch LGDCore"="E:Program FilesLogitechGamePanel SoftwareG-series SoftwareLGDCore.exe" [2007-07-18 2094352]
"CanonSolutionMenu"="E:Program FilesCanonSolutionMenuCNSLMAIN.exe" [2007-05-14 644696]
"CanonMyPrinter"="E:Program FilesCanonMyPrinterBJMyPrt.exe" [2007-04-03 1603152]
"SSBkgdUpdate"="E:Program FilesFichiers communsScansoft SharedSSBkgdUpdateSSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="E:Program FilesScanSoftOmniPageSE4OpwareSE4.exe" [2007-02-04 79400]
"VirtualCloneDrive"="E:Program FilesElaborate BytesVirtualCloneDriveVCDDaemon.exe" [2004-08-20 45056]
"nwiz"="nwiz.exe" [2007-10-25 E:WINDOWSsystem32
wiz.exe]
E:Documents and SettingssebMenu D,marrerProgrammesD,marrage
IcoSauve.lnk - E:WINDOWSsystem32IcoSauve.exe [2008-10-06 112128]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionpoliciessystem]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionpoliciesexplorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoSimpleStartMenu"= 0 (0x0)
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionpoliciesexplorer]
"NoStrCmpLogical"= 0 (0x0)
"LockTaskbar"= 0 (0x0)
"NoResolveTrack"= 0 (0x0)
"NoResolveSearch"= 0 (0x0)
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMFUprogramsList"= 0 (0x0)
"NoUserNameInStartMenu"= 0 (0x0)
"MaxRecentDocs"= 15 (0xf)
"NoInstrumentation"= 0 (0x0)
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoSMBalloonTip"= 0 (0x0)
"DisallowCpl"= 1 (0x1)
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionwindows]
"AppInit_DLLs"=emleca.dll
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
"%windir%\Network Diagnostic\xpnetdiag.exe"=
"%windir%\system32\sessmgr.exe"=
"E:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"=
"C:\logiciels\azureus\Vuze\Azureus.exe"=
"C:\logiciels\emule\emule.exe"=
R1 aswSP;avast! Self Protection;E:WINDOWSsystem32driversaswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;E:WINDOWSsystem32DRIVERSaswFsBlk.sys [2008-07-19 20560]
R2 IJPLMSVC;PIXMA Extended Survey Program;E:Program FilesCanonIJPLMIJPLMSVC.EXE [2007-04-13 101528]
S3 SetupNTGLM7X;SetupNTGLM7X;G:NTGLM7X.sys [ ]
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{46B95367-6BA4-4137-B830-53B1FF284056} - E:WINDOWSsystem32hgGxYOIy.dll
BHO-{79f32d91-8636-41f9-837b-f16a1ef49b4f} - E:WINDOWSsystem32emleca.dll
BHO-{A2E1CC01-E47E-44AF-B0FC-12D50ABA5DFC} - E:WINDOWSsystem32fccaAron.dll
HKCU-Run-MSFox - E:WINDOWSTEMPa.exe
HKLM-Run-f6de23ca - E:WINDOWSsystem32wkxtnvnl.dll
ShellExecuteHooks-{46B95367-6BA4-4137-B830-53B1FF284056} - E:WINDOWSsystem32hgGxYOIy.dll
.
------- Examen supplémentaire -------
.
FireFox -: Profile - E:Documents and SettingssebApplication DataMozillaFirefoxProfilesk56hnqd7.default
FF -: plugin - E:Program FilesJavajre1.6.0in
pjava11.dll
FF -: plugin - E:Program FilesJavajre1.6.0in
pjava12.dll
FF -: plugin - E:Program FilesJavajre1.6.0in
pjava13.dll
FF -: plugin - E:Program FilesJavajre1.6.0in
pjava14.dll
FF -: plugin - E:Program FilesJavajre1.6.0in
pjava32.dll
FF -: plugin - E:Program FilesJavajre1.6.0in
pjpi160.dll
FF -: plugin - E:Program FilesJavajre1.6.0in
poji610.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-08 22:49:44
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
E:Program FilesAlwil SoftwareAvast4aswUpdSv.exe
E:Program FilesAlwil SoftwareAvast4ashServ.exe
E:WINDOWSsystem32
undll32.exe
E:Program FilesLogitechGamePanel SoftwareLCD ManagerAppletsLCDClock.exe
E:Program FilesLogitechGamePanel SoftwareLCD ManagerAppletsLCDCountdown.exe
E:WINDOWSsystem32
vsvc32.exe
E:Program FilesNVIDIA CorporationNetworkAccessManagerin
SvcAppFlt.exe
E:Program FilesNVIDIA CorporationNetworkAccessManagerin
SvcIp.exe
E:Program FilesAlwil SoftwareAvast4ashMaiSv.exe
E:Program FilesAlwil SoftwareAvast4ashWebSv.exe
E:ibi.4pv.cfexe
E:ibi.4pv.cfexe
.
**************************************************************************
.
Heure de fin: 2008-10-08 22:50:38 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-10-08 20:50:36
Avant-CF: 21 362 905 088 octets libres
Après-CF: 21,305,491,456 octets libres
236 --- E O F --- 2008-10-07 21:10:50
3- 2éme partie pour combofix
ComboFix 08-10-08.01 - seb 2008-10-08 22:58:36.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1636 [GMT 2:00]
Lancé depuis: E:Documents and SettingssebBureaulalaibi.4.exe
Commutateurs utilisés :: E:Documents and SettingssebBureauCFScript.txt
* Un nouveau point de restauration a été créé
FILE ::
E:WINDOWSsystem321.ico
E:WINDOWSsystem32deadlink.exe
E:WINDOWSsystem32drivers dssserv.sys
E:WINDOWSsystem32Siw.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-08 au 2008-10-08 ))))))))))))))))))))))))))))))))))))
.
2008-10-08 22:50 . 2008-10-08 22:50 <REP> d-------- E:WINDOWSLastGood
2008-10-08 10:30 . 2008-10-08 10:34 <REP> d-------- E:Documents and SettingssebApplication DataFileZilla
2008-10-08 10:29 . 2008-10-08 10:29 <REP> d-------- E:Program FilesFileZilla FTP Client
2008-10-08 10:17 . 2008-10-08 15:44 <REP> d-------- E:Documents and SettingssebApplication DataCanon
2008-10-08 09:28 . 2007-09-06 00:22 289,144 --a------ E:WINDOWSsystem32VCCLSID.exe
2008-10-08 09:28 . 2006-04-27 17:49 288,417 --a------ E:WINDOWSsystem32SrchSTS.exe
2008-10-08 09:28 . 2008-09-08 23:38 88,576 --a------ E:WINDOWSsystem32AntiXPVSTFix.exe
2008-10-08 09:28 . 2008-10-01 15:51 87,552 --a------ E:WINDOWSsystem32VACFix.exe
2008-10-08 09:28 . 2008-09-19 12:26 82,944 --a------ E:WINDOWSsystem32o4Patch.exe
2008-10-08 09:28 . 2008-05-18 21:40 82,944 --a------ E:WINDOWSsystem32IEDFix.exe
2008-10-08 09:28 . 2008-09-19 12:26 82,944 --a------ E:WINDOWSsystem32IEDFix.C.exe
2008-10-08 09:28 . 2008-08-18 12:19 82,432 --a------ E:WINDOWSsystem32404Fix.exe
2008-10-08 09:28 . 2004-07-31 18:50 51,200 --a------ E:WINDOWSsystem32dumphive.exe
2008-10-08 09:28 . 2007-10-04 00:36 25,600 --a------ E:WINDOWSsystem32WS2Fix.exe
2008-10-08 09:28 . 2008-10-08 09:28 3,630 --a------ E:WINDOWSsystem32 mp.reg
2008-10-08 09:22 . 2008-10-08 22:01 <REP> d-------- E:Program FilesNavilog1
2008-10-08 09:02 . 2008-10-08 09:02 <REP> d-------- E:Program FilesTrend Micro
2008-10-07 21:52 . 2008-10-07 21:52 0 --ah----- E:WINDOWSsystem32driversMsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-10-07 21:52 . 2008-10-07 21:52 0 --ah----- E:WINDOWSsystem32driversMsft_Kernel_xusb21_01005.Wdf
2008-10-07 21:42 . 2008-10-07 21:42 <REP> d-------- E:Documents and SettingssebApplication DataDisney Interactive Studios
2008-10-07 12:42 . 2008-10-07 21:13 <REP> d-------- E:Documents and SettingssebApplication Datavlc
2008-10-07 12:03 . 2008-10-07 12:03 <REP> d-------- E:Program FilesMSXML 6.0
2008-10-07 12:00 . 2004-08-19 19:09 221,184 --a------ E:WINDOWSsystem32wmpns.dll
2008-10-07 10:53 . 2008-10-07 10:53 <REP> d-------- E:Program FilesAlwil Software
2008-10-07 01:04 . 2008-10-07 01:45 <REP> d-------- E:WINDOWSsystem32CatRoot_bak
2008-10-06 23:56 . 2008-10-07 12:03 <REP> d--h----- E:WINDOWS$hf_mig$
2008-10-06 23:49 . 2008-10-08 15:38 <REP> d-------- E:Program FilesMozilla Thunderbird
2008-10-06 23:49 . 2008-10-06 23:49 <REP> d-------- E:Documents and SettingssebApplication DataThunderbird
2008-10-06 23:45 . 2008-10-07 10:52 <REP> d-------- E:Documents and SettingsAll UsersApplication DataMcAfee
2008-10-06 23:42 . 2008-10-06 23:42 <REP> d-------- E:Program FilesNero
2008-10-06 23:42 . 2008-10-06 23:42 <REP> d-------- E:Program FilesFichiers communsNero
2008-10-06 23:42 . 2008-10-06 23:42 <REP> d-------- E:Documents and SettingsAll UsersApplication DataNero
2008-10-06 23:42 . 2006-03-17 11:45 1,757,184 --a------ E:WINDOWSsystem32imagX7.dll
2008-10-06 23:42 . 2006-03-17 11:45 802,816 --a------ E:WINDOWSsystem32imagXRA7.dll
2008-10-06 23:42 . 2006-03-17 11:45 497,296 --a------ E:WINDOWSsystem32imagXpr7.dll
2008-10-06 23:42 . 2006-03-17 14:49 368,640 --a------ E:WINDOWSsystem32TwnLib4.dll
2008-10-06 23:42 . 2006-03-17 11:45 258,048 --a------ E:WINDOWSsystem32imagXR7.dll
2008-10-06 23:40 . 2008-10-06 23:40 <REP> d-------- E:Documents and SettingsAll UsersApplication DataCanonIJPLM
2008-10-06 23:38 . 2008-10-06 23:38 <REP> d-------- E:Program FilesFichiers communsScanSoft Shared
2008-10-06 23:38 . 2008-10-06 23:38 <REP> d-------- E:Documents and SettingssebApplication DataScanSoft
2008-10-06 23:38 . 2008-10-06 23:38 <REP> d-------- E:Documents and SettingsAll UsersApplication DataScanSoft
2008-10-06 23:38 . 2008-10-06 23:38 <REP> d-------- E:Documents and SettingsAll UsersApplication DataInstallShield
2008-10-06 23:38 . 2004-08-03 23:01 25,856 --a------ E:WINDOWSsystem32driversusbprint.sys
2008-10-06 23:38 . 2004-08-03 22:58 15,104 --a------ E:WINDOWSsystem32driversusbscan.sys
2008-10-06 23:38 . 2008-10-06 23:38 412 --a------ E:WINDOWSMAXLINK.INI
2008-10-06 23:37 . 2008-10-06 23:37 <REP> d-------- E:Program FilesScanSoft
2008-10-06 23:37 . 2008-10-06 23:37 <REP> d-------- E:Program FilesFichiers communsCANON
2008-10-06 23:35 . 2008-10-06 23:35 <REP> d--h----- E:Documents and SettingsAll UsersApplication DataCanonBJ
2008-10-06 23:34 . 2008-10-06 23:34 <REP> d--h----- E:WINDOWSsystem32CanonIJ Uninstaller Information
2008-10-06 23:34 . 2008-10-06 23:34 <REP> d--h----- E:Program FilesCanonBJ
2008-10-06 23:34 . 2007-03-23 09:30 1,400,832 --a------ E:WINDOWSsystem32CNC520C.DLL
2008-10-06 23:34 . 2007-05-21 22:00 215,040 --a------ E:WINDOWSsystem32CNMLM94.DLL
2008-10-06 23:34 . 2007-03-19 03:23 200,704 --a------ E:WINDOWSsystem32CNC520L.DLL
2008-10-06 23:34 . 2007-03-15 07:12 188,416 --a------ E:WINDOWSsystem32CNC520O.DLL
2008-10-06 23:34 . 2007-03-23 09:29 98,304 --a------ E:WINDOWSsystem32CNC520I.DLL
2008-10-06 23:31 . 2008-10-06 23:31 0 --a------ E:WINDOWS
sreg.dat
2008-10-06 23:30 . 2008-10-06 23:39 <REP> d-------- E:Program FilesCanon
2008-10-06 23:27 . 2008-10-06 23:27 <REP> d-------- E:Program FilesLogitech
2008-10-06 23:27 . 2008-10-06 23:27 <REP> d-------- E:Documents and SettingsAll UsersApplication DataLogitech
2008-10-06 23:25 . 2008-10-06 23:25 0 --a------ E:WINDOWSmsicpl.ini
2008-10-06 23:21 . 2006-03-17 00:22 76,288 -ra------ E:WINDOWSsystem32SilSupp.cpl
2008-10-06 23:21 . 2004-11-01 21:21 10,368 -ra------ E:WINDOWSsystem32driversSiWinAcc.sys
2008-10-06 23:21 . 2005-10-18 21:15 5,504 -ra------ E:WINDOWSsystem32driversSiRemFil.sys
2008-10-06 23:09 . 2008-10-06 23:09 <REP> d-------- E:Program FilesAnalog Devices
2008-10-06 23:07 . 2008-10-06 23:07 <REP> d-------- E:WINDOWSASUSInstAll
2008-10-06 23:05 . 2008-10-06 23:05 <REP> d-------- E:Program FilesNVIDIA Corporation
2008-10-06 23:05 . 2008-10-07 00:10 <REP> d--h----- E:Program FilesInstallShield Installation Information
2008-10-06 23:04 . 2008-10-06 23:38 <REP> d-------- E:Program FilesFichiers communsInstallShield
2008-10-06 23:03 . 2008-10-06 23:21 34,183 --a------ E:WINDOWSAscd_tmp.ini
2008-10-06 23:03 . 2006-10-11 05:33 10,288 --a------ E:WINDOWSsystem32driversASUSHWIO.SYS
2008-10-06 23:03 . 2004-08-13 04:56 5,810 -ra------ E:WINDOWSsystem32driversASACPI.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-08 19:03 --------- d-----w E:Documents and SettingssebApplication Datasp2
2008-10-08 09:09 --------- d-----w E:Documents and SettingssebApplication DataAzureus
2008-10-06 22:47 --------- d-----w E:Documents and SettingsAll UsersApplication DataAzureus
2008-10-06 22:44 --------- d-----w E:Program FilesVideoLAN
2008-10-06 22:38 --------- d---a-w E:Documents and SettingsAll UsersApplication DataTEMP
2008-10-06 22:34 --------- d-----w E:Documents and SettingsAll UsersApplication DataMicrosoft Help
2008-10-06 22:33 --------- d-----w E:Program FilesMSBuild
2008-10-06 22:33 --------- d-----w E:Program FilesMicrosoft Works
2008-10-06 22:33 --------- d-----w E:Documents and SettingssebApplication DataURSoft
2008-10-06 22:32 --------- d-----w E:Program FilesMicrosoft.NET
2008-10-06 22:31 --------- d-----w E:Program FilesMicrosoft Visual Studio 8
2008-10-06 22:13 --------- d-----w E:Documents and SettingsLocalServiceApplication DataSACore
2008-10-06 22:12 107,888 ----a-w E:WINDOWSsystem32CmdLineExt.dll
2008-10-06 22:09 --------- d-----w E:Documents and SettingssebApplication DataInstallShield
2008-10-06 22:08 --------- d-----w E:Program FilesElaborate Bytes
2008-10-06 22:00 --------- d-----w E:Documents and SettingsAll UsersApplication DataSiteAdvisor
2008-10-06 20:55 --------- d---a-w E:Documents and SettingssebApplication Datagtopala
2008-10-06 20:55 --------- d---a-w E:Documents and SettingssebApplication Dataaignes
2008-10-06 20:51 --------- d-----w E:Program FilesJava
2008-10-06 20:51 --------- d-----w E:Program FilesFichiers communsJava
2008-10-06 20:50 --------- d-----w E:Program FilesWMV9_VCM
2008-10-06 20:50 --------- d-----w E:Program FilesWindows Media Connect 2
2008-10-06 20:44 --------- d-----w E:Program FilesWSTARTUP
2008-10-06 20:44 --------- d-----w E:Program FilesUTILS
2008-10-06 20:44 --------- d-----w E:Program FilesMSXML 4.0
2008-10-06 20:44 --------- d-----w E:Program FilesJEUX
2008-10-06 20:40 --------- d-----w E:Program Filesmicrosoft frontpage
2008-10-06 19:45 266,240 ----a-w E:qmafxprs.dll
2008-07-31 08:41 68,616 ----a-w E:WINDOWSsystem32XAPOFX1_1.dll
2008-07-31 08:41 238,088 ----a-w E:WINDOWSsystem32xactengine3_2.dll
2008-07-31 08:40 509,448 ----a-w E:WINDOWSsystem32XAudio2_2.dll
2008-07-18 20:10 94,920 ----a-w E:WINDOWSsystem32cdm.dll
2008-07-18 20:10 53,448 ----a-w E:WINDOWSsystem32wuauclt.exe
2008-07-18 20:10 45,768 ----a-w E:WINDOWSsystem32wups2.dll
2008-07-18 20:10 36,552 ----a-w E:WINDOWSsystem32wups.dll
2008-07-18 20:09 563,912 ----a-w E:WINDOWSsystem32wuapi.dll
2008-07-18 20:09 325,832 ----a-w E:WINDOWSsystem32wucltui.dll
2008-07-18 20:09 205,000 ----a-w E:WINDOWSsystem32wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w E:WINDOWSsystem32wuaueng.dll
2008-07-12 06:18 467,984 ----a-w E:WINDOWSsystem32d3dx10_39.dll
2008-07-12 06:18 3,851,784 ----a-w E:WINDOWSsystem32D3DX9_39.dll
2008-07-12 06:18 1,493,528 ----a-w E:WINDOWSsystem32D3DCompiler_39.dll
.
------- Sigcheck -------
2006-11-19 01:59 1035264 7ba68df484b550c1f75dd80ae1d7ef67 E:WINDOWSexplorer.exe
2008-04-14 04:34 1037824 f2317622d29f9ff0f88aeecd5f60f0dd E:WINDOWSSoftwareDistributionDownload44b6174a4a693136d02d4a7ecd7cbd54explorer.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
":::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::SOFTWAREMicrosoftWindowsCurrentVersionRun"="::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::SOFTWAREMicrosoftWindowsCurrentVersionRun" [X]
"ctfmon.exe"="E:WINDOWSsystem32ctfmon.exe" [2004-08-19 15360]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
":::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::SOFTWAREMicrosoftWindowsCurrentVersionRun"="::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::SOFTWAREMicrosoftWindowsCurrentVersionRun" [X]
"SoundMAXPnP"="E:Program FilesAnalog DevicesCoresmax4pnp.exe" [2006-12-18 868352]
"NvCplDaemon"="E:WINDOWSsystem32NvCpl.dll" [2007-10-25 8527872]
"WinSys2"="E:WINDOWSsystem32winsys2.exe" [2007-10-30 208896]
"NvMediaCenter"="E:WINDOWSsystem32NvMcTray.dll" [2007-10-25 81920]
"Launch LCDMon"="E:Program FilesLogitechGamePanel SoftwareLCD ManagerLCDMon.exe" [2007-07-18 1687824]
"Launch LGDCore"="E:Program FilesLogitechGamePanel SoftwareG-series SoftwareLGDCore.exe" [2007-07-18 2094352]
"CanonSolutionMenu"="E:Program FilesCanonSolutionMenuCNSLMAIN.exe" [2007-05-14 644696]
"CanonMyPrinter"="E:Program FilesCanonMyPrinterBJMyPrt.exe" [2007-04-03 1603152]
"SSBkgdUpdate"="E:Program FilesFichiers communsScansoft SharedSSBkgdUpdateSSBkgdupdate.exe" [2006-10-25 210472]
"OpwareSE4"="E:Program FilesScanSoftOmniPageSE4OpwareSE4.exe" [2007-02-04 79400]
"VirtualCloneDrive"="E:Program FilesElaborate BytesVirtualCloneDriveVCDDaemon.exe" [2004-08-20 45056]
"nwiz"="nwiz.exe" [2007-10-25 E:WINDOWSsystem32
wiz.exe]
E:Documents and SettingssebMenu D,marrerProgrammesD,marrage
IcoSauve.lnk - E:WINDOWSsystem32IcoSauve.exe [2008-10-06 112128]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionpoliciessystem]
"SynchronousMachineGroupPolicy"= 0 (0x0)
"SynchronousUserGroupPolicy"= 0 (0x0)
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionpoliciesexplorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoSimpleStartMenu"= 0 (0x0)
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionpoliciesexplorer]
"NoStrCmpLogical"= 0 (0x0)
"LockTaskbar"= 0 (0x0)
"NoResolveTrack"= 0 (0x0)
"NoResolveSearch"= 0 (0x0)
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMFUprogramsList"= 0 (0x0)
"NoUserNameInStartMenu"= 0 (0x0)
"MaxRecentDocs"= 15 (0xf)
"NoInstrumentation"= 0 (0x0)
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoSMBalloonTip"= 0 (0x0)
"DisallowCpl"= 1 (0x1)
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionwindows]
"AppInit_DLLs"=emleca.dll
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
"%windir%\Network Diagnostic\xpnetdiag.exe"=
"%windir%\system32\sessmgr.exe"=
"E:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"=
"C:\logiciels\azureus\Vuze\Azureus.exe"=
"C:\logiciels\emule\emule.exe"=
R1 aswSP;avast! Self Protection;E:WINDOWSsystem32driversaswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;E:WINDOWSsystem32DRIVERSaswFsBlk.sys [2008-07-19 20560]
R2 IJPLMSVC;PIXMA Extended Survey Program;E:Program FilesCanonIJPLMIJPLMSVC.EXE [2007-04-13 101528]
S3 SetupNTGLM7X;SetupNTGLM7X;G:NTGLM7X.sys [ ]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-08 22:59:40
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-10-08 22:59:56
ComboFix-quarantined-files.txt 2008-10-08 20:59:55
ComboFix2.txt 2008-10-08 20:50:39
Avant-CF: 21 287 038 976 octets libres
Après-CF: 21,276,491,776 octets libres
208 --- E O F --- 2008-10-07 21:10:50
4- sdfix
b]SDFix: Version 1.233 [/b]
Run by seb on 08/10/2008 at 23:19
Microsoft Windows XP [version 5.1.2600]
Running From: E:SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Restoring Missing Security Center Service
Rebooting
Checking Files :
Trojan Files Found:
E:Documents and SettingssebApplication DataAdobePlayer.exe.bak - Deleted
E:Documents and SettingssebFavorisMalware Defender.url - Deleted
E:Documents and SettingssebFavorisProtect Your Privacy.url - Deleted
E:Documents and SettingssebFavorisSystem Error Fixer.url - Deleted
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-08 23:22:01
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicystandardprofileauthorizedapplicationslist]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"E:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="E:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\logiciels\azureus\Vuze\Azureus.exe"="C:\logiciels\azureus\Vuze\Azureus.exe:*:Enabled:Azureus"
"C:\logiciels\emule\emule.exe"="C:\logiciels\emule\emule.exe:*:Enabled:eMule"
[HKEY_LOCAL_MACHINEsystemcurrentcontrolsetservicessharedaccessparametersfirewallpolicydomainprofileauthorizedapplicationslist]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
Remaining Files :
File Backups: - E:SDFixackupsackups.zip
Files with Hidden Attributes :
Thu 15 Feb 2007 308,832 A..H. --- "E:Program FilesCanonMP Navigator EX 1.0Maint.exe"
Mon 25 Apr 2005 61,440 A..H. --- "E:Program FilesCanonMP Navigator EX 1.0uinstrsc.dll"
Finished!
5-smitfraudix
SmitFraudFix v2.357
Rapport fait à 9:28:47,25, 08/10/2008
Executé à partir de E:Documents and SettingssebBureaulalaSmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode normal
»»»»»»»»»»»»»»»»»»»»»»»» Process
E:WINDOWSSystem32smss.exe
E:WINDOWSsystem32winlogon.exe
E:WINDOWSsystem32services.exe
E:WINDOWSsystem32lsass.exe
E:WINDOWSsystem32svchost.exe
E:WINDOWSSystem32svchost.exe
E:Program FilesAlwil SoftwareAvast4aswUpdSv.exe
E:Program FilesAlwil SoftwareAvast4ashServ.exe
E:WINDOWSsystem32spoolsv.exe
E:WINDOWSExplorer.EXE
E:Program FilesAnalog DevicesCoresmax4pnp.exe
E:Program FilesAnalog DevicesSoundMAXSmax4.exe
E:WINDOWSsystem32RUNDLL32.EXE
E:Program FilesLogitechGamePanel SoftwareLCD ManagerLCDMon.exe
E:Program FilesLogitechGamePanel SoftwareG-series SoftwareLGDCore.exe
E:Program FilesScanSoftOmniPageSE4OpwareSE4.exe
E:Program FilesElaborate BytesVirtualCloneDriveVCDDaemon.exe
E:PROGRA~1ALWILS~1Avast4ashDisp.exe
E:WINDOWSsystem32ctfmon.exe
E:Program FilesLogitechGamePanel SoftwareLCD ManagerAppletsLCDClock.exe
E:Program FilesLogitechGamePanel SoftwareLCD ManagerAppletsLCDCountdown.exe
E:Program FilesLogitechGamePanel SoftwareLCD ManagerAppletsLCDPop3.exe
E:Program FilesLogitechGamePanel SoftwareLCD ManagerAppletsLCDMedia.exe
E:WINDOWSsystem32IcoSauve.exe
E:Program FilesCanonIJPLMIJPLMSVC.EXE
E:WINDOWSsystem32
vsvc32.exe
E:WINDOWSsystem32svchost.exe
E:Program FilesNVIDIA CorporationNetworkAccessManagerin
SvcAppFlt.exe
E:Program FilesNVIDIA CorporationNetworkAccessManagerin
SvcIp.exe
E:Program FilesMozilla Firefoxfirefox.exe
C:logicielsazureusVuzeAzureus.exe
E:Documents and SettingssebBureaulalaSmitfraudFixPolicies.exe
E:WINDOWSsystem32cmd.exe
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» E:
»»»»»»»»»»»»»»»»»»»»»»»» E:WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» E:WINDOWSsystem
»»»»»»»»»»»»»»»»»»»»»»»» E:WINDOWSWeb
»»»»»»»»»»»»»»»»»»»»»»»» E:WINDOWSsystem32
E:WINDOWSsystem321.ico PRESENT !
E:WINDOWSsystem32drivers dssserv.sys détecté, utilisez un scanner de Rootkit
»»»»»»»»»»»»»»»»»»»»»»»» E:Documents and Settingsseb
»»»»»»»»»»»»»»»»»»»»»»»» E:Documents and SettingssebApplication Data
»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer
»»»»»»»»»»»»»»»»»»»»»»»» E:DOCUME~1sebFavoris
»»»»»»»»»»»»»»»»»»»»»»»» Bureau
»»»»»»»»»»»»»»»»»»»»»»»» E:Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues
»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau
[HKEY_CURRENT_USERSoftwareMicrosoftInternet ExplorerDesktopComponents ]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"
»»»»»»»»»»»»»»»»»»»»»»»» o4Patch
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
o4Patch
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» VACFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
AntiXPVSTFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWindows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindows NTCurrentVersionWinlogon]
"Userinit"="E:\WINDOWS\system32\userinit.exe,"
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» RK
»»»»»»»»»»»»»»»»»»»»»»»» DNS
HKLMSYSTEMCS2ServicesTcpip..{16138661-65AD-4DBF-AC89-605ADD0DB788}: DhcpNameServer=212.27.40.240 212.27.40.241
HKLMSYSTEMCS2ServicesTcpipParameters: DhcpNameServer=212.27.40.240 212.27.40.241
»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin
bon cette fois j'ai tout fais comme demandé,le pc à l'ir clean,mais avec les virus et malware,clean n'est jamais d'actualité....
Je te remercie encore et si echec,je posterai encore
Bonne soirée et @+
lestat31