alors voici les rapports
Combofix=>
ComboFix 09-01-08.05 - sebastien Carut 2009-01-09 20:06:13.1 - NTFSx86 MINIMAL
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.1022.585 [GMT 1:00]
Lancé depuis: C:\Users\sebastien Carut\Desktop\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\PROGRA~2\Microsoft\Network\Downloader\qmgr0.dat
C:\PROGRA~2\Microsoft\Network\Downloader\qmgr1.dat
C:\Users\SEBAST~1\AppData\Local\MICROS~1\Windows\TEMPOR~1\fbk.sts
C:\Users\SEBAST~1\AppData\Roaming\gadcom
C:\Users\SEBAST~1\AppData\Roaming\gadcom\gadcom.exe
C:\Users\sebastien Carut\AppData\Local\Microsoft\Windows\Temporary Internet Files\fbk.sts
C:\Users\sebastien Carut\AppData\Roaming\gadcom\gadcom.exe
C:\Windows\system32\404Fix.exe
C:\Windows\System32\aaKUBJlm.ini
C:\Windows\system32\aaKUBJlm.ini2
C:\Windows\system32\ahtn.htm
C:\Windows\system32\dumphive.exe
C:\Windows\system32\frmwrk32.exe
C:\Windows\system32\IEDFix.C.exe
C:\Windows\system32\IEDFix.exe
C:\Windows\system32\mlJBUKaa.dll
C:\Windows\system32\ntdll64.exe
C:\Windows\system32\o4Patch.exe
C:\Windows\system32\Process.exe
C:\Windows\system32\qadalukd.ini
C:\Windows\system32\SrchSTS.exe
C:\Windows\system32\tmp.reg
C:\Windows\system32\uniq.tll
C:\Windows\system32\VACFix.exe
C:\Windows\system32\VCCLSID.exe
C:\Windows\system32\warning.gif
C:\Windows\system32\win32hlp.cnf
C:\Windows\system32\WS2Fix.exe
----- BITS: Il y a peut-être des sites infectés -----
hxxp://childhe.com
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_FreezeScreenSaver
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-09 au 2009-01-09 ))))))))))))))))))))))))))))))))))))
.
2009-01-09 20:01 . 2008-12-12 00:57 78,336 --a------ C:\Windows\System32\Agent.OMZ.Fix.exe
2009-01-09 20:01 . 2009-01-09 20:01 691 --a------ C:\Users\sebastien Carut\AppData\Roaming\GetValue.vbs
2009-01-09 20:01 . 2009-01-09 20:01 691 --a------ C:\Users\SEBAST~1\AppData\Roaming\GetValue.vbs
2009-01-09 20:01 . 2009-01-09 20:01 35 --a------ C:\Users\sebastien Carut\AppData\Roaming\SetValue.bat
2009-01-09 20:01 . 2009-01-09 20:01 35 --a------ C:\Users\SEBAST~1\AppData\Roaming\SetValue.bat
2009-01-09 19:59 . 2009-01-09 20:01 <REP> d-------- C:\ToolBar SD
2009-01-07 10:41 . 2009-01-07 17:32 5 --a------ C:\Windows\sbacknt.bin
2009-01-07 10:40 . 2009-01-07 19:27 <REP> d-------- C:\Users\sebastien Carut\AppData\Roaming\vghd
2009-01-07 10:40 . 2009-01-07 19:27 <REP> d-------- C:\Users\SEBAST~1\AppData\Roaming\vghd
2009-01-07 10:40 . 2009-01-07 19:35 <REP> d-------- C:\Program Files\vghd
2009-01-07 10:40 . 2009-01-07 10:40 152,904 --a------ C:\Windows\System32\vghd.scr
2009-01-07 10:40 . 2009-01-07 10:40 45,568 --a------ C:\Windows\System32\mlJASLFw.dll
2008-12-30 17:54 . 2008-12-30 17:54 <REP> d-------- C:\Program Files\Philips
2008-12-30 17:53 . 2008-12-30 17:53 <REP> d-------- C:\Philips
2008-12-30 17:53 . 2008-06-20 18:27 19,840 --a------ C:\Windows\System32\drivers\StMp3Rec.sys
2008-12-22 07:13 . 2008-12-22 07:13 <REP> d-------- C:\Users\All Users\Azureus
2008-12-22 07:13 . 2008-12-22 07:13 <REP> d-------- C:\PROGRA~2\Azureus
2008-12-22 07:12 . 2009-01-03 17:32 <REP> d-------- C:\Users\sebastien Carut\AppData\Roaming\Azureus
2008-12-22 07:12 . 2009-01-03 17:32 <REP> d-------- C:\Users\SEBAST~1\AppData\Roaming\Azureus
2008-12-22 07:12 . 2008-12-22 07:12 <REP> d-------- C:\Program Files\Vuze
2008-12-19 20:22 . 2009-01-09 19:48 <REP> d-------- C:\Users\sebastien Carut\Tracing
2008-12-19 20:21 . 2008-12-19 20:21 <REP> d-------- C:\Program Files\Microsoft Office Outlook Connector
2008-12-19 20:20 . 2008-12-19 20:20 <REP> d-------- C:\Program Files\Microsoft Sync Framework
2008-12-19 20:20 . 2008-12-08 17:01 55,264 --a------ C:\Windows\System32\drivers\fssfltr.sys
2008-12-19 20:17 . 2008-12-19 20:17 <REP> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2008-12-19 20:14 . 2008-12-19 20:21 <REP> d-------- C:\Program Files\Microsoft
2008-12-19 20:13 . 2008-12-19 20:13 <REP> d-------- C:\Program Files\Windows Live SkyDrive
2008-12-19 20:06 . 2008-12-19 20:06 <REP> d-------- C:\Program Files\Common Files\Windows Live
2008-12-13 18:26 . 2008-12-13 18:35 <REP> d-------- C:\Program Files\RegCleaner
2008-12-12 03:09 . 2008-10-22 02:22 2,048 --a------ C:\Windows\System32\tzres.dll
2008-12-11 07:03 . 2008-11-01 02:21 4,240,384 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
2008-12-11 07:03 . 2008-10-29 07:29 2,927,104 --a------ C:\Windows\explorer.exe
2008-12-11 07:03 . 2008-10-21 06:25 296,960 --a------ C:\Windows\System32\gdi32.dll
2008-12-11 07:03 . 2008-11-01 04:44 28,672 --a------ C:\Windows\System32\Apphlpdm.dll
2008-12-11 07:02 . 2008-06-23 02:59 2,868,736 --a------ C:\Windows\System32\mf.dll
2008-12-11 07:02 . 2008-06-23 02:59 996,352 --a------ C:\Windows\System32\WMNetMgr.dll
2008-12-11 07:02 . 2008-10-16 05:47 827,392 --a------ C:\Windows\System32\wininet.dll
2008-12-11 07:02 . 2008-06-23 02:58 94,720 --a------ C:\Windows\System32\logagent.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-09 19:01 --------- d-----w C:\Program Files\Google
2009-01-09 04:51 --------- d-----w C:\PROGRA~2\Google Updater
2009-01-08 17:44 --------- d-----w C:\Program Files\Navilog1
2008-12-30 16:54 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-12-28 15:14 --------- d-----w C:\Program Files\Java
2008-12-19 19:20 --------- d-----w C:\Program Files\Windows Live
2008-12-18 12:17 --------- d-----w C:\Program Files\Sports Interactive
2008-12-17 17:52 183,112 ----a-w C:\Windows\System32\PnkBstrB.exe
2008-12-17 17:52 138,184 ----a-w C:\Windows\system32\drivers\PnkBstrK.sys
2008-12-12 02:27 --------- d-----w C:\Program Files\Windows Mail
2008-12-08 14:19 66,872 ----a-w C:\Windows\System32\PnkBstrA.exe
2008-12-08 13:52 --------- d-----w C:\Users\sebastien Carut\AppData\Roaming\Leadertech
2008-12-08 13:52 --------- d-----w C:\Users\SEBAST~1\AppData\Roaming\Leadertech
2008-12-08 13:32 --------- d-----w C:\Program Files\EA Games
2008-12-08 13:17 --------- d---a-w C:\PROGRA~2\Sports Interactive
2008-12-06 19:08 --------- d-----w C:\PROGRA~2\Media Center Programs
2008-12-05 19:00 --------- d-----w C:\PROGRA~2\NVIDIA
2008-12-05 18:32 --------- d-----w C:\Users\sebastien Carut\AppData\Roaming\SystemRequirementsLab
2008-12-05 18:32 --------- d-----w C:\Users\SEBAST~1\AppData\Roaming\SystemRequirementsLab
2008-12-05 18:32 --------- d-----w C:\Program Files\SystemRequirementsLab
2008-12-05 18:29 --------- d-----w C:\Program Files\Lavalys
2008-12-04 23:11 308,584 ----a-w C:\Windows\WLXPGSS.SCR
2008-12-02 21:37 49,480 ----a-w C:\Windows\System32\sirenacm.dll
2008-12-01 06:15 --------- d-----w C:\Program Files\MSN Pictures Displayer
2008-11-30 17:54 --------- d-----w C:\Users\sebastien Carut\AppData\Roaming\Sports Interactive
2008-11-30 17:54 --------- d-----w C:\Users\SEBAST~1\AppData\Roaming\Sports Interactive
2008-11-20 17:07 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-11-20 16:53 --------- d-----w C:\Program Files\Dofus
2008-11-20 07:46 --------- d---a-w C:\PROGRA~2\TEMP
2008-11-20 07:41 --------- d-----w C:\PROGRA~2\Arcade Lab
2008-11-20 07:40 --------- d-----w C:\Program Files\Oberon Media
2008-11-18 18:02 51,792 ----a-w C:\Windows\system32\drivers\aswMonFlt.sys
2008-11-13 19:10 --------- d-----w C:\Program Files\Managed DirectX (0901)
2008-11-10 04:43 410,984 ----a-w C:\Windows\System32\deploytk.dll
2008-11-09 11:24 2,196,846 ----a-w C:\Windows\System32\Fille au Tambour.scr
2008-11-09 11:24 --------- d-----w C:\Program Files\www.ttdown.com
2008-11-09 08:01 --------- d-----w C:\Program Files\UtopiaBOX 2.02
2008-11-01 03:44 541,696 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-11-01 03:44 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-11-01 03:44 460,288 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-11-01 03:44 2,154,496 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-11-01 03:44 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-10-27 18:00 36,734 ----a-w C:\Windows\System32\OggDSuninst.exe
2008-10-27 09:04 70,992 ----a-w C:\Windows\System32\XAPOFX1_2.dll
2008-10-27 09:04 514,384 ----a-w C:\Windows\System32\XAudio2_3.dll
2008-10-27 09:04 235,856 ----a-w C:\Windows\System32\xactengine3_3.dll
2008-10-27 09:04 23,376 ----a-w C:\Windows\System32\X3DAudio1_5.dll
2008-10-22 03:57 241,152 ----a-w C:\Windows\System32\PortableDeviceApi.dll
2008-10-21 05:25 1,645,568 ----a-w C:\Windows\System32\connect.dll
2008-10-16 21:13 1,809,944 ----a-w C:\Windows\System32\wuaueng.dll
2008-10-16 21:12 561,688 ----a-w C:\Windows\System32\wuapi.dll
2008-10-16 21:09 51,224 ----a-w C:\Windows\System32\wuauclt.exe
2008-10-16 21:09 43,544 ----a-w C:\Windows\System32\wups2.dll
2008-10-16 21:08 34,328 ----a-w C:\Windows\System32\wups.dll
2008-10-16 20:56 1,524,736 ----a-w C:\Windows\System32\wucltux.dll
2008-10-16 20:55 83,456 ----a-w C:\Windows\System32\wudriver.dll
2008-10-16 13:08 162,064 ----a-w C:\Windows\System32\wuwebv.dll
2008-10-16 12:56 31,232 ----a-w C:\Windows\System32\wuapp.exe
2008-10-10 03:52 452,440 ----a-w C:\Windows\System32\d3dx10_40.dll
2008-10-10 03:52 4,379,984 ----a-w C:\Windows\System32\D3DX9_40.dll
2008-10-10 03:52 2,036,576 ----a-w C:\Windows\System32\D3DCompiler_40.dll
2008-06-26 19:36 174 --sha-w C:\Program Files\desktop.ini
2008-02-16 08:45 22,328 ----a-w C:\Users\sebastien Carut\AppData\Roaming\PnkBstrK.sys
2008-02-16 08:45 22,328 ----a-w C:\Users\SEBAST~1\AppData\Roaming\PnkBstrK.sys
2007-07-25 16:37 278,528 ----a-w C:\Program Files\Common Files\FDEUnInstaller.exe
2007-04-23 12:21 269,824 ----a-w C:\Windows\inf\WG111v3\Vista64\wg111v3.sys
2007-04-23 12:19 227,328 ----a-w C:\Windows\inf\WG111v3\WG111v3.sys
2007-04-23 12:19 227,328 ----a-w C:\Windows\inf\WG111v3\Vista\wg111v3.sys
2006-12-15 09:30 98,304 ----a-w C:\Windows\inf\WG111v3\UScanM.exe
2006-12-15 09:30 315,392 ----a-w C:\Windows\inf\WG111v3\InstallDriver.exe
2006-12-15 09:30 28,672 ----a-w C:\Windows\inf\WG111v3\SetDrv.exe
2006-12-15 09:30 212,992 ----a-w C:\Windows\inf\WG111v3\CopyWHQLDriver.exe
2006-12-15 09:30 20,480 ----a-w C:\Windows\inf\WG111v3\RTWUPath.exe
2006-12-15 09:30 19,968 ----a-w C:\Windows\inf\WG111v3\RTWREFU.EXE
Smitfraud=>
SmitFraudFix v2.388
Scan done at 20:01:47,73, 09/01/2009
Run from C:\Users\sebastien Carut\Desktop\SmitfraudFix
OS: Microsoft Windows [version 6.0.6001] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» hosts
127.0.0.1 localhost
::1 localhost
»»»»»»»»»»»»»»»»»»»»»»»» VACFix
VACFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix
S!Ri's WS2Fix: LSP not Found.
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
C:\Program Files\VideoAccessCodec\ Deleted
C:\Program Files\Google\googletoolbar1.dll Deleted
»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
IEDFix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
Agent.OMZ.Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» 404Fix
404Fix
Credits: Malware Analysis & Diagnostic
Code: S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» RK
»»»»»»»»»»»»»»»»»»»»»»»» DNS
HKLM\SYSTEM\CCS\Services\Tcpip\..\{B7AB96CE-87EB-4B18-87E3-F5DBFEE7069A}: DhcpNameServer=192.168.1.1
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
toolbar =>
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) D CPU 2.80GHz )
BIOS : Phoenix - AwardBIOS v6.00PG
USER : sebastien Carut ( Administrator )
BOOT : Fail-safe boot
Antivirus : avast! antivirus 4.8.1229 [VPS 081124-0] 4.8.1229 (Activated)
C:\ (Local Disk) - NTFS - Total:226 Go (Free:98 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
K:\ (CD or DVD)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 09/01/2009|20:00 )
[ UAC => 0 ]
-----------\\ SUPPRESSION
Supprime! - C:\Program Files\GamesBar\Localization-French.ini
Supprime! - C:\ProgramData\GamesBar
Supprime! - C:\Program Files\GamesBar
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\Windows\\system32\\blank.htm"
"Search Page"="http://www.google.com"
"Start Page"="http://www.orange.fr/"
"Search Bar"="http://www.google.com/ie"
"Url"="http://go.microsoft.com/fwlink/?LinkId=75720"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.msn.com/"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Default_Search_URL"="http://recherche.neuf.fr/"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
--------------------\\ Recherche d'autres infections
C:\Windows\system32\aaKUBJlm.ini
C:\Windows\system32\aaKUBJlm.ini2
C:\Windows\system32\mlJBUKaa.dll
==> VUNDO <==
--------------------\\ Cracks & Keygens ..
C:\Users\SEBAST~1\AppData\Local\Microsoft\Messenger\babas52@hotmail.com\SharingMetadata\noem52@hotmail.com\DFSR\Installing\Football Manager 2008 - [ Full - crack - serial]-{37B88796-415A-4412-A879-240FCC948715}-v28.zip
C:\Users\SEBAST~1\AppData\Local\Microsoft\Messenger\babas52@hotmail.com\SharingMetadata\noem52@hotmail.com\DFSR\Installing\Football Manager 2008 - [ Full - crack - serial]-{37B88796-415A-4412-A879-240FCC948715}-v34.zip
C:\Users\SEBAST~1\AppData\Roaming\Microsoft\Windows\Recent\[PC Game] Football Manager 2009 (fm 09). Crack + Patch 9.1.0 by Bridon.lnk
C:\Users\SEBAST~1\Desktop\logiciel de modif music et film\GoldWave.v5.25.Incl-Keygen.[emule-island.com]
C:\Users\SEBAST~1\Desktop\logiciel de modif music et film\GoldWave.v5.25.Incl-Keygen.[emule-island.com]\Bienvenue sur eMule-Island !.url
C:\Users\SEBAST~1\Desktop\logiciel de modif music et film\GoldWave.v5.25.Incl-Keygen.[emule-island.com]\GoldWave 5.25 SERIAL.txt
C:\Users\SEBAST~1\Desktop\logiciel de modif music et film\GoldWave.v5.25.Incl-Keygen.[emule-island.com]\GoldWave.v5.25.Incl-Keygen.[emule-island.com].rar
C:\Users\SEBAST~1\Desktop\logiciel de modif music et film\GoldWave.v5.25.Incl-Keygen.[emule-island.com]\gwave525.exe
C:\Users\SEBAST~1\Desktop\logiciel de modif music et film\GoldWave.v5.25.Incl-Keygen.[emule-island.com]\Keygen
C:\Users\SEBAST~1\Desktop\logiciel de modif music et film\GoldWave.v5.25.Incl-Keygen.[emule-island.com]\Keygen\keygen.exe
C:\Users\SEBAST~1\Documents\jeux\fm 2008\[Pc game ita] Football Manager 2008 [FM2008 + crack + ita,eng,fr,de] by Peppe.iso
C:\Users\SEBAST~1\Documents\Need.For.Speed.Undercover.FRENCH-ReVOLVeR\Need.For.Speed.Undercover.FRENCH-ReVOLVeR\Crack
C:\Users\SEBAST~1\Documents\Need.For.Speed.Undercover.FRENCH-ReVOLVeR\Need.For.Speed.Undercover.FRENCH-ReVOLVeR\Crack\nfs.exe
C:\Users\SEBAST~1\Documents\Need.For.Speed.Undercover.FRENCH-ReVOLVeR\Need.For.Speed.Undercover.FRENCH-ReVOLVeR\Crack\rld-nfsk.exe
[ UAC => 1 ]
1 - "C:\ToolBar SD\TB_1.txt" - 09/01/2009|20:01 - Option : [2]
-----------\\ Fin du rapport a 20:01:01,67
et enfin hijackthis=>
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:21, on 2009-01-09
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\PixArt\Pac207\Monitor.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Windows\WindowsMobile\wmdSync.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10a.exe
C:\Users\sebastien Carut\Desktop\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: metaspinner media GmbH - {12FC9A49-CFE0-49AA-BE9E-8F4EEAFC9443} - C:\PROGRA~1\YETISP~1\IEBUTT~1.DLL
O2 - BHO: (no name) - {4CA230B6-9318-4457-BC45-6EBD5C8F503D} - C:\Windows\system32\mlJBUKaa.dll (file missing)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Monitor] C:\Windows\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog (User 'Default user')
O4 - Global Startup: NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
O8 - Extra context menu item: &Recherche AOL Toolbar -
res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xporter vers Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\Windows\system32\Shdocvw.dll
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
O13 - Gopher Prefix:
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
--
End of file - 8297 bytes
mon ordi a redemarrer entre le scan combofix et CCleaner mais je pense que c'est normal et j'ai eu un message d'erreur disant que "execute processes remotely a cesser de fonctionner.
Sinon l'icone en bas a droite (la fameuse croix a disparue) et mon gestionnaire des taches est revenu.
Merci beaucoup