CONNEXION
  • RetourJeux
    • Sorties
    • Hit Parade
    • Les + populaires
    • Les + attendus
    • Soluces
    • Tous les Jeux
    • Gaming
  • RetourActu Gaming
    • News
    • Astuces
    • Tests
    • Previews
    • Toute l'actu gaming
  • RetourBons plans
    • Bons plans
    • Bons plans Smartphone
    • Bons plans Hardware
    • Bons plans Image et Son
    • Bons plans Amazon
    • Bons plans Cdiscount
    • Bons plans Decathlon
    • Bons plans Fnac
    • Tous les Bons plans
  • RetourJVTech
    • Actus High-Tech
    • Intelligence Artificielle
    • Smartphones
    • Mobilité urbaine
    • Hardware
    • Image et son
    • Tutoriels
    • Tests produits High-Tech
    • Guides d'achat High-Tech
    • JVTech
  • RetourCulture
    • Actus Culture
    • Culture
  • RetourVidéos
    • A la une
    • Gaming Live
    • Vidéos Tests
    • Vidéos Previews
    • Gameplay
    • Trailers
    • Chroniques
    • Replay Web TV
    • Toutes les vidéos
  • RetourForums
    • Hardware PC
    • PS5
    • Switch 2
    • Xbox Series
    • Switch
    • Pokemon pocket
    • FC 25 Ultimate Team
    • League of Legends
    • Tous les Forums
  • PC
  • PS5
  • Xbox Series
  • Switch 2
  • PS4
  • One
  • Switch
  • iOS
  • Android
  • MMO
  • RPG
  • FPS
En ce moment Genshin Impact Valhalla Breath of the wild Animal Crossing GTA 5 Red dead 2
Liste des sujets

Help me [virus]

noname_2008
noname_2008
Niveau 2
28 août 2008 à 14:41:23

Bonjour bon voilà je pense que j'ai des virus, c'est plutôt bitdefender qui le dit. Alors je fais appel a tous les experts de hijackthis pour examiner ce rapport :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:25:16, on 28/08/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16711)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\hp\support\hpsysdrv.exe
C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Softwin\BitDefender10\bdmcon.exe
C:\Program Files\Softwin\BitDefender10\bdagent.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\schtasks.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\hp\kbd\kbd.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_FR&c=74&bd=Pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_FR&c=74&bd=Pavilion&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: HP Print Clips - {053F9267-DC04-4294-A72C-58F732D338C0} - C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program
Files\Google\GoogleToolbarNotifier\2.1.1119.1736\s
wg.dll
O2 - BHO: (no name) - {C2A1C5CB-C0EF-4689-9436-F62CCA1C5383} - C:\Program Files\Video Add-on\isfmdl.dll (file missing)
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - c:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec
Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\
PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec
Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\
AlertEng.dll"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\KORKMAZ\AppData\Local\Temp\cbaxv.dll,#1
O4 - HKCU\..\Run: [MS Juan] rundll32
"C:\Users\KORKMAZ\AppData\Local\Temp\ujpdiwag.dll"
,run
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\KORKMAZ\AppData\Local\Temp\tuvvt.dll,c
O4 - HKCU\..\Run: [308db4c4] rundll32.exe
"C:\Users\KORKMAZ\AppData\Local\Temp\veocqjvt.dll"
,b
O4 - HKCU\..\Run: [swg] C:\Program
Files\Google\GoogleToolbarNotifier\GoogleToolbarNo
tifier.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKLM\..\Policies\Explorer\Run: [start] C:\Program Files\Video Add-on\isfmntr.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: Registration Ghost Recon Advanced Warfighter® 2 Demo SP.LNK = C:\Program Files\UBISOFT\Ghost Recon Advanced Warfighter 2 Demo SP\Support\Register\RegistrationReminder.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.freeietool.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.freeietool.com/redirect.php (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab3.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequiremirementslab.com/sysreqlab2.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/m/player/DivXBrowserPlugin.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://config.zebulon.fr//plugins/hardwaredetection.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - c:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec
Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\
PIFSvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe

--
End of file - 12380 bytes

Merci d'avance pour vos futur réponses

noname_2008
noname_2008
Niveau 2
28 août 2008 à 15:37:01

:up: :svp:

goldendemon
goldendemon
Niveau 8
28 août 2008 à 15:41:46

salut fixe les lignes :

wg.dll

O2 - BHO: (no name) - {C2A1C5CB-C0EF-4689-9436-F62CCA1C5383} - C:\Program Files\Video Add-on\isfmdl.dll (file missing)

Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\

AlertEng.dll"

O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe

O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.freeietool.com/redirect.php (file missing)

O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.freeietool.com/redirect.php (file missing)

ensuite telecharge malwarebyte antimalware ici

http://www.commentcamarche.net/telecharger/telecharger-34055379-malwarebyte-s-anti-malware

met le a jour et fais un scan minutieux.

noname_2008
noname_2008
Niveau 2
28 août 2008 à 17:10:18

Ça dure combien de temps ce scan minutieux ?
Parce-que la ça dure depuis 45min.

noname_2008
noname_2008
Niveau 2
28 août 2008 à 18:00:36

J'ai fait le scan et il m'affiche les résultat, alors maintenant je supprime ce qu'il a trouver ?

noname_2008
noname_2008
Niveau 2
28 août 2008 à 18:48:54

UP je serai très heureux si quelqu'un me repond

widemeo
widemeo
Niveau 9
28 août 2008 à 18:50:33

Salut,

Infection Vundo/Virtumonde.

Important : Désactive TeaTimer, le résident de Spybot, il va gêner la désinfection en empêchant la modification des BHO.

---> Démarre Spybot, clique sur Mode, coche Mode avancé
---> A gauche, clique sur Outils, puis sur Résident
---> Décoche la case devant Résident "TeaTimer" :
http://apu.mabul.org/up/5/apu-5-gpdx9e06cwz2dypom2q7n6nc.jpg
---> Quitte Spybot

Note : Je te conseille de ne pas le réactiver, il a été incapable d'empêcher l'infection de ton PC.

---> Télécharge ComboFix.exe de sUBs sur ton Bureau :
http://download.bleepingccomputer.com/sUBs/ComboFix.exe

/!\ Déconnecte-toi du net et ferme toutes les applications, antivirus et antispyware y compris /!\

---> Double-clique sur Combofix.exe
Un "pop-up" va apparaître qui dit que "ComboFix est utilisé à vos risques et avec aucune garantie...".
Accepte en cliquant sur "Oui"

---> Mets-le en langue française F
Tape sur la touche 1 (Yes) pour démarrer le scan.

/!\ Ne touche à rien tant que le scan n'est pas terminé. /!\

En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

/!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

Note : Le rapport se trouve également là : C:\ComboFix.txt

widemeo
widemeo
Niveau 9
28 août 2008 à 18:51:07

---> Désactive l'UAC le temps de la désinfection :
http://www.zebulon.fr/astuces/220-desactiver-l-uac-dans-vista.html

:-)))

noname_2008
noname_2008
Niveau 2
28 août 2008 à 19:00:53

Euhh... sa dure combien de temps, c'est parce que j'ai pas le temps 30 min grand max

widemeo
widemeo
Niveau 9
28 août 2008 à 19:07:26

Le scan avec ComboFix prend moins de 30 minutes normalement.

noname_2008
noname_2008
Niveau 2
28 août 2008 à 19:37:35

ComboFix 08-08-27.06 - KORKMAZ 2008-08-28 19:18:11.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.1055 [GMT 2:00]
Endroit: C:\Users\KORKMAZ\Desktop\ComboFix.exe
* Création d'un nouveau point de restauration
.
[color=purple]The following files were disabled during the run:[/color]
C:\Windows\system32\sockspy.dll

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Users\KORKMAZ\AppData\Local\snhelkxex_navup.dat

C:\Users\KORKMAZ\AppData\Roaming\macromedia\Flash
Player\#SharedObjects\F8ZJPMS9\bin.clearspring.com

C:\Users\KORKMAZ\AppData\Roaming\macromedia\Flash
Player\#SharedObjects\F8ZJPMS9\bin.clearspring.com
\clearspring.sol
C:\Users\KORKMAZ\AppData\Roaming\macromedia\Flash
Player\macromedia.com\support\flashplayer\sys\#bin
.clearspring.com
C:\Users\KORKMAZ\AppData\Roaming\macromedia\Flash
Player\macromedia.com\support\flashplayer\sys\#bin
.clearspring.com\settings.sol

C:\Users\KORKMAZ\AppData\Roaming\Microsoft\Windows
\Cookies\korkmaz@bluestreak[1].txt
C:\Windows\Downloaded Program Files\setup.inf
C:\Windows\system32\AutoRun.inf
C:\Windows\system32\jusched.exe

.
((((((((((((((((((((((((((((( Fichiers créés 2008-07-28 to 2008-08-28 ))))))))))))))))))))))))))))))))))))
.

Pas de nouveau fichier créé dans cet espace de temps

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-28
17:18 81,984 ----a-w C:\Windows\System32\bdod.bin

2008-08-28
14:18 --------- d-----w C:\Users\KORKMAZ\AppData\R
oaming\Malwarebytes
2008-08-28
14:18 --------- d-----w C:\ProgramData\Malwarebyte
s
2008-08-28 12:25 --------- d-----w C:\Program Files\Trend Micro
2008-08-28 10:34 --------- d-----w C:\ProgramData\Google Updater
2008-08-26 17:38 --------- d---a-w C:\ProgramData\TEMP
2008-08-26 16:55 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-26 16:12 --------- d-----w C:\ProgramData\Trymedia
2008-08-26 12:45 --------- d-----w C:\ProgramData\HP Product Assistant
2008-08-21 13:13 --------- d-----w C:\Program Files\MafiaDemo
2008-08-21 13:12 --------- d-----w C:\Program Files\Creative
2008-08-21 12:50 --------- d-----w C:\Program Files\MafiaDemo (US) Install Files
2008-08-19 14:52 --------- d-----w C:\Program Files\LimeWire
2008-08-18
17:20 --------- d-----w C:\Users\KORKMAZ\AppData\R
oaming\LimeWire
2008-08-18 17:20 --------- d-----w C:\Program Files\Incomplete
2008-08-16
16:26 --------- d-----w C:\Users\KORKMAZ\AppData\R
oaming\Azureus
2008-08-15 18:28 --------- d-----w C:\Program Files\Common Files\Steam
2008-08-15 10:28 --------- d-----w C:\Program Files\Windows Mail
2008-07-30 09:31 --------- d-----w C:\Program Files\Google
2008-07-19
05:10 53,448 ----a-w C:\Windows\System32\wuauclt.e
xe
2008-07-19
05:10 45,768 ----a-w C:\Windows\System32\wups2.dll

2008-07-19
05:10 36,552 ----a-w C:\Windows\System32\wups.dll

2008-07-19
05:09 563,912 ----a-w C:\Windows\System32\wuapi.dl
l
2008-07-19
05:09 1,811,656 ----a-w C:\Windows\System32\wuauen
g.dll
2008-07-19
03:44 83,456 ----a-w C:\Windows\System32\wudriver.
dll
2008-07-19
03:44 1,524,736 ----a-w C:\Windows\System32\wucltu
x.dll
2008-07-18
20:08 163,904 ----a-w C:\Windows\System32\wuwebv.d
ll
2008-07-18
18:44 31,232 ----a-w C:\Windows\System32\wuapp.exe

2008-07-15
23:48 2,048 ----a-w C:\Windows\System32\tzres.dll

2008-07-09 23:08 174 --sha-w C:\Program Files\desktop.ini
2008-06-27
03:54 826,368 ----a-w C:\Windows\System32\wininet.
dll
2008-06-27
03:54 56,320 ----a-w C:\Windows\System32\iesetup.d
ll
2008-06-27
03:54 52,736 ----a-w C:\Windows\AppPatch\iebrshim.
dll
2008-06-27
03:54 26,624 ----a-w C:\Windows\System32\ieUnatt.e
xe
2008-06-26
00:34 7,964,672 ----a-w C:\Windows\System32\NlsLex
icons0024.dll
2008-06-26
00:33 9,892,864 ----a-w C:\Windows\System32\NlsLex
icons000a.dll
2008-06-19
03:25 61,440 ----a-w C:\Windows\System32\winipsec.
dll
2008-06-19
03:25 361,984 ----a-w C:\Windows\System32\IPSECSVC
.DLL
2008-06-19
03:25 28,672 ----a-w C:\Windows\System32\FwRemoteS
vr.dll
2008-06-19
03:25 272,896 ----a-w C:\Windows\System32\polstore
.dll
2008-06-12
06:54 537,600 ----a-w C:\Windows\AppPatch\AcLayers
.dll
2008-06-12
06:54 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal
.dll
2008-06-12
01:21 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll

2007-11-30
15:23 0 ----a-w C:\Users\KORKMAZ\AppData\Roaming\w
klnhst.dat
2007-12-15
11:19 16,384 --sha-w C:\Windows\ServiceProfiles\Lo
calService\AppData\Local\Microsoft\Windows\History
\History.IE5\index.dat
2007-12-15
11:19 32,768 --sha-w C:\Windows\ServiceProfiles\Lo
calService\AppData\Local\Microsoft\Windows\Tempora
ry Internet Files\Content.IE5\index.dat
2007-12-15
11:19 16,384 --sha-w C:\Windows\ServiceProfiles\Lo
calService\AppData\Roaming\Microsoft\Windows\Cooki
es\index.dat
.

noname_2008
noname_2008
Niveau 2
28 août 2008 à 19:38:27

((((((((((((((((((((((((((((((((( Point de chargement Reg
)))))))))))))))))))))))))))))))))))))))))))))))))

.
.

  • Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curr
entVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-10 13:01 1232896]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 14:35 125440]
"swg"="C:\Program
Files\Google\GoogleToolbarNotifier\GoogleToolbarNo
tifier.exe" [2008-04-19 12:51 68856]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 14:36 201728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Cur
rentVersion\Run]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 17:01 65536]
"KBD"="C:\HP\KBD\KbdStub.EXE" [2006-12-08 18:16 65536]
"OsdMaestro"="C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 13:59 118784]
"HP Health Check Scheduler"="c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-05-24 13:13 71176]

"SunJavaUpdateReg"="C:\Windows\system32\jureg.exe"
[2007-04-07 02:56 54936]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 22:34 49152]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 16:59 115816]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec
Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\
PIFSvc.exe" [2007-03-12 11:22 517768]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-07-06 21:15 86016]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-07-06 21:15 8466432]

"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll"
[2007-07-06 21:15 81920]
"BDMCon"="C:\Program Files\Softwin\BitDefender10\bdmcon.exe" [2007-04-02 17:48 290816]
"BDAgent"="C:\Program Files\Softwin\BitDefender10\bdagent.exe" [2007-03-26 16:49 69632]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"RtHDVCpl"="RtHDVCpl.exe" [2007-07-06 13:06 4669440 C:\Windows\RtHDVCpl.exe]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 22:26:24 210520]
Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-04-19 12:51:18 124400]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\cur
rentversion\policies\system]
"EnableLUA"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallp
olicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallp
olicy\FirewallRules]
"{DEC36261-5AB9-41D1-ACC4-6F14434D1CDD}"= UDP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{129BA438-B2D2-4F67-A961-A21310B872EC}"= TCP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{B2E7445D-B0D9-4217-BAAE-6678D4FE3EF1}"= UDP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{C8440C08-52C1-46F4-BC65-7667A38BDC28}"= TCP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{79938E34-4489-4CD8-9F09-136A607A1439}"= UDP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{7FFDE0CF-B675-412A-A9A5-0ED1D6028EF9}"= TCP:C:\Program Files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
"{A6246A58-35C3-41F0-BF12-BD962198CE51}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{542F77D6-AC51-4114-B80B-FA276A115180}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{50240819-6109-4E56-8A81-465C1F75AB45}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire

[HKLM\~\services\sharedaccess\parameters\firewallp
olicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallp
olicy\RestrictedServices\Static\System]
"DFSR-1"=
RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|S
vc=DFSR:Allow inbound TCP traffic|

[HKLM\~\services\sharedaccess\parameters\firewallp
olicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R1 IDSvix86;Symantec Intrusion Prevention
Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsd
efs\20071220.001\IDSvix86.sys [2007-11-06 18:28]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2007-08-31 17:46]
R3
SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMN
DISV.SYS [2007-10-30 20:55]
S3 Steam Client Service;Steam Client Service;C:\Program Files\Common Files\Steam\SteamService.exe [2008-08-15 11:21]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

  • Newly Created Service* - CATCHME
  • Newly Created Service* - COMHOST
  • Newly Created Service* - PROCEXP90

.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'

2008-08-18 C:\Windows\Tasks\Norton Internet Security - Analyse système complète - KORKMAZ.job
- c:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exe [2007-01-13 20:09]

2008-08-28
C:\Windows\Tasks\User_Feed_Synchronization-{4B51D2
0B-1740-45C2-A2DE-B00520FF6DB2}.job
- C:\Windows\system32\msfeedssync.exe [2006-11-02 11:45]

2008-08-28
C:\Windows\Tasks\User_Feed_Synchronization-{E0D15A
AA-5F8B-4340-BD6F-095CE99F9360}.job
- C:\Windows\system32\msfeedssync.exe [2006-11-02 11:45]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile -
C:\Users\KORKMAZ\AppData\Roaming\Mozilla\Firefox\P
rofiles\ge9xwwii.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL -
hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8
&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://en-us.start.mozilla.com/firefox?client=fire
fox-a&rls=org.mozilla:fr:official
FF -: plugin - C:\Program Files\Google\Google Updater\2.2.1202.1501\npCIDetect11.dll
.

    • ***********************************************
    • *********************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-28 19:22:23
Windows 6.0.6000 NTFS

Balayage processus cachés ...

Balayage caché autostart entries ...

Balayage des fichiers cachés ...

Scan terminé avec succès
Les fichiers cachés: 0

    • ***********************************************
    • *********************

.
Temps d'accomplissement: 2008-08-28 19:24:17
ComboFix-quarantined-files.txt 2008-08-28 17:23:48

Pre-Run: Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
Post-Run: 237,453,012,992 octets libres

175 --- E O F --- 2008-08-27 08:55:59

widemeo
widemeo
Niveau 9
28 août 2008 à 19:40:01

Bien.

---> Fais un scan rapide avec MBAM, supprime tout ce qu'il trouve et poste le rapport :
http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.htm

noname_2008
noname_2008
Niveau 2
28 août 2008 à 19:41:59

oufff J'espère que c'est bientôt fini (mon petit cerveau surchauffe)

désolé pour avoir poster le rapport en deux part c'est parce que j'ai pas encore 10 jours d'encienté

noname_2008
noname_2008
Niveau 2
28 août 2008 à 19:45:31

J'ai déjà fait se scan approfondit avec se logiciel il faut encore faire en rapide ? :ouch2:

widemeo
widemeo
Niveau 9
28 août 2008 à 19:49:35

Tu peux m'uploader le rapport sur mediafire s'il te plaît ?

noname_2008
noname_2008
Niveau 2
28 août 2008 à 19:55:39

Arrff...

je suis un idiot, j'ai désinstaller le log et le rapport mais j'ai fais supprimer tout ce qui a détecter .

noname_2008
noname_2008
Niveau 2
28 août 2008 à 20:01:11

Désolé widemeo mais je doit y aller a demain si tu est là

widemeo
widemeo
Niveau 9
28 août 2008 à 20:16:41

Ok, sans problème.

Sous forums
  • Aide à l'achat Mac
  • Internet
  • Macintosh
  • Création de sites web
  • Création de Jeux
  • Linux
  • Programmation
  • Steam Deck
  • Hardware
La vidéo du moment