![]() |
| |||||||
| S'inscrire | Site Spy | Liste des membres | Faire un don | Recherche | Aujourd'hui, les postes | Marquer les forums comme lus | Forum Rules |
|
![]() |
| | Thread Tools |
|
#1
| |||
| |||
| Logfile de Trend Micro HijackThis v2.0.2 Scan sauvé à 12:01:37 PM, le 9.21.2008 Plate-forme: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C: \ WINDOWS \ System32 \ smss.exe C: \ WINDOWS \ system32 \ csrss.exe C: \ WINDOWS \ system32 \ winlogon.exe C: \ WINDOWS \ system32 \ services.exe C: \ WINDOWS \ system32 \ lsass.exe C: \ WINDOWS \ system32 \ ibmpmsvc.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ Program Files \ Intel \ Wireless \ Bin \ S24EvMon.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccsetmgr.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccEvtMgr.exe C: \ Program Files \ Common Files \ Symantec Shared \ SPBBC \ spbbcsvc.exe C: \ Program Files \ Lavasoft \ Ad-Aware \ aawservice.exe C: \ WINDOWS \ system32 \ spoolsv.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ Centenn.ial \ Audit \ CAgent32.exe C: \ Centenn.ial \ Audit \ xferwan.exe C: \ Program Files \ Cisco VPN Client \ cvpnd.exe C: \ Program Files \ Symantec AntiVirus \ DefWatch.exe C: \ Program Files \ Intel \ Wireless \ Bin \ EvtEng.exe C: \ Program Files \ Fichiers communs \ Microsoft Shared \ VS7DEBUG \ Mdm.exe C: \ Program Files \ Intel \ Wireless \ Bin \ RegSrvc.exe C: \ Program Files \ Symantec AntiVirus \ SavRoam.exe C: \ Program Files \ Symantec AntiVirus \ Rtvscan.exe C: \ Program Files \ Common Files \ Lenovo \ tvt_reg_monitor_svc.exe C: \ WINDOWS \ System32 \ TPHDEXLG.exe C: \ Program Files \ Common Files \ Lenovo \ Scheduler \ tvtsched.exe c: \ _integra \ bin \ ccmagent.exe c: \ program files \ lenovo \ system update \ suservice.exe C: \ WINDOWS \ System32 \ alg.exe C: \ WINDOWS \ system32 \ calc.exe C: \ WINDOWS \ system32 \ calc.exe c: \ _integra \ bin \ shstart.exe C: \ WINDOWS \ Explorer.EXE C: \ WINDOWS \ system32 \ tp4mon.exe C: \ WINDOWS \ system32 \ igfxtray.exe C: \ WINDOWS \ system32 \ hkcmd.exe C: \ WINDOWS \ system32 \ igfxpers.exe C: \ WINDOWS \ system32 \ NWTRAY.EXE C: \ Program Files \ Common Files \ Symantec Shared \ ccapp.exe C: \ PROGRA ~ 1 \ SYMANT ~ 1 \ VPTray.exe C: \ Program Files \ Lenovo \ HotKey \ TPOSDSVC.exe C: \ WINDOWS \ system32 \ igfxsrvc.exe C: \ WINDOWS \ system32 \ dla \ tfswctrl.exe C: \ PROGRA ~ 1 \ ThinkPad \ UTILIT ~ 1 \ EzEjMnAp.Exe C: \ PROGRA ~ 1 \ THINKV ~ 1 \ PrdCtr \ LPMGR.exe C: \ WINDOWS \ system32 \ TpShocks.exe C: \ Program Files \ Lenovo \ HotKey \ TPONSCR.exe C: \ Program Files \ Common Files \ Lenovo \ Scheduler \ scheduler_proxy.exe C: \ Program Files \ Lenovo \ Zoom \ TpScrex.exe C: \ Program Files \ Fichiers communs \ Real \ Update_OB \ realsched.exe C: \ WINDOWS \ system32 \ ctfmon.exe C: \ Program Files \ Yahoo! \ Messenger \ ymsgr_tray.exe C: \ WINDOWS \ system32 \ taskmgr.exe C: \ Program Files \ Internet Explorer \ IEXPLORE.EXE C: \ Program Files \ Internet Explorer \ IEXPLORE.EXE C: \ Program Files \ Internet Explorer \ IEXPLORE.EXE C: \ WINDOWS \ system32 \ Wuauclt.exe C: \ WINDOWS \ system32 \ wbem \ wmiprvse.exe C: \ Program Files \ Trend Micro \ HijackThis \ HijackThis.exe C: \ WINDOWS \ system32 \ wbem \ wmiprvse.exe F2 - REG: system.ini: Userinit = c: \ windows \ system32 \ userinit.exe, c: \ _inte gra \ bin \ shstart.exe O2 - BHO: AcroIEHlprObj Class - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Adobe \ Acrobat 7.0 \ ActiveX \ AcroIEHelper.dll O2 - BHO: DriveLetterAccess - (5CA3D70E-1895-11CF-8E15-001234567890) - C: \ WINDOWS \ system32 \ dla \ tfswshx.dll O4 - HKLM \ .. \ Run: [TrackPointSrv] tp4mon.exe O4 - HKLM \ .. \ Run: [IgfxTray] C: \ WINDOWS \ system32 \ igfxtray.exe O4 - HKLM \ .. \ Run: [HotKeysCmds] C: \ WINDOWS \ system32 \ hkcmd.exe O4 - HKLM \ .. \ Run: [Persistence] C: \ WINDOWS \ system32 \ igfxpers.exe O4 - HKLM \ .. \ Run: [NWTRAY] NWTRAY.EXE O4 - HKLM \ .. \ Run: [ccApp] "C: \ Program Files \ Common Files \ Symantec Shared \ ccapp.exe" O4 - HKLM \ .. \ Run: [vptray] C: \ PROGRA ~ 1 \ SYMANT ~ 1 \ VPTray.exe O4 - HKLM \ .. \ Run: [TPHOTKEY] C: \ Program Files \ Lenovo \ HotKey \ TPOSDSVC.exe O4 - HKLM \ .. \ Run: [UpdateManager] "C: \ Program Files \ Common Files \ Sonic \ Update Manager \ sgtray.exe" / r O4 - HKLM \ .. \ Run: [dla] C: \ WINDOWS \ system32 \ dla \ tfswctrl.exe O4 - HKLM \ .. \ Run: [EZEJMNAP] C: \ PROGRA ~ 1 \ ThinkPad \ UTILIT ~ 1 \ EzEjMnAp.Exe O4 - HKLM \ .. \ Run: [LPManager] C: \ PROGRA ~ 1 \ THINKV ~ 1 \ PrdCtr \ LPMGR.exe O4 - HKLM \ .. \ Run: [TpShocks] TpShocks.exe O4 - HKLM \ .. \ Run: [TVT Scheduler Proxy] C: \ Program Files \ Common Files \ Lenovo \ Scheduler \ scheduler_proxy.exe O4 - HKLM \ .. \ Run: [TkBellExe] "C: \ Program Files \ Fichiers communs \ Real \ Update_OB \ realsched.exe"-osboot O4 - HKCU \ .. \ Run: [ctfmon.exe] C: \ WINDOWS \ system32 \ ctfmon.exe O4 - HKCU \ .. \ Run: [Yahoo! Pager] "C: \ Program Files \ Yahoo! \ Messenger \ YahooMessenger.exe"-quiet O4 - HKUS \ S-1-5-19 \ .. \ Run: [Communicator] "C: \ Program Files \ Microsoft Office Communicator \ Communicator.exe" (User 'LOCAL SERVICE') O4 - HKUS \ S-1-5-20 \ .. \ Run: [Communicator] "C: \ Program Files \ Microsoft Office Communicator \ Communicator.exe" (User 'NETWORK SERVICE') O4 - HKUS \ S-1-5-18 \ .. \ Run: [Communicator] "C: \ Program Files \ Microsoft Office Communicator \ Communicator.exe" (User 'SYSTEM') O4 - HKUS \. DEFAULT \ .. \ Run: [Communicator] "C: \ Program Files \ Microsoft Office Communicator \ Communicator.exe" (User 'Default user') O8 - Extra du menu contextuel: E & xporter vers Microsoft Excel - res: / / C: \ PROGRA ~ 1 \ MICROS ~ 2 \ OFFICE11 \ EXCEL.EXE/3000 O9 - Extra button: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ OFFICE11 \ REFIEBAR.DLL O9 - Extra button: @ C: \ Program Files \ Messenger \ Msgslang.dll, -61144 - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe O9 - Extra 'Tools' menuitem: @ C: \ Program Files \ Messenger \ Msgslang.dll, -61144 - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe O16 - DPF: (215B8138-A3CF-44C5-803F-8226143CFC0A) (Trend Micro ActiveX Scan Agent 6.6) -- http://housecall65.trendmicro.com/ho...vex/hcImpl.cab O17 - HKLM \ System \ CCS \ Services \ Tcpip \ .. \ (B8E7B489-2160-4DE7-B592-9FD03D16CC74): Domain = keane.com O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C: \ Program Files \ Lavasoft \ Ad-Aware \ aawservice.exe O23 - Service: Application Management Service (AppMgSvc) - Unknown owner - C: \ Program.exe (file missing) O23 - Service: Service BHCP (BHsrv) - Unknown owner - C: \ Program.exe (file missing) O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccsetmgr.exe O23 - Service: CentennialClientAgent - Centennial Software Limited - C: \ Centenn.ial \ Audit \ CAgent32.exe O23 - Service: CentennialIPTransferAgent - Centennial Software Limited - C: \ Centenn.ial \ Audit \ xferwan.exe O23 - Service: Service de mise à jour du client Novell (cusrvc) - Novell, Inc - C: \ WINDOWS \ system32 \ cusrvc.exe O23 - Service: Cisco Systems, Inc VPN Service (CVPND) - Cisco Systems, Inc - C: \ Program Files \ Cisco VPN Client \ cvpnd.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C: \ Program Files \ Symantec AntiVirus \ DefWatch.exe O23 - Service: Intel (R) PROSet / Wireless Event Log (EvtEng) - Intel Corporation - C: \ Program Files \ Intel \ Wireless \ Bin \ EvtEng.exe O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C: \ WINDOWS \ system32 \ ibmpmsvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C: \ PROGRA ~ 1 \ Symantec \ LIVEUP ~ 1 \ LUCOMS ~ 1.EXE O23 - Service: Intel (R) PROSet / Wireless Registry Service (RegSrvc) - Intel Corporation - C: \ Program Files \ Intel \ Wireless \ Bin \ RegSrvc.exe O23 - Service: Intel (R) PROSet / Wireless Service (S24EventMonitor) - Intel Corporation - C: \ Program Files \ Intel \ Wireless \ Bin \ S24EvMon.exe O23 - Service: SAVRoam (SavRoam) - symantec - C: \ Program Files \ Symantec AntiVirus \ SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ sndsrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ SPBBC \ spbbcsvc.exe O23 - Service: System Update (SUService) - Lenovo Group Limited - c: \ program files \ lenovo \ system update \ suservice.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C: \ Program Files \ Symantec AntiVirus \ Rtvscan.exe O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C: \ Program Files \ Common Files \ Lenovo \ tvt_reg_monitor_svc.exe O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C: \ WINDOWS \ System32 \ TPHDEXLG.exe O23 - Service: TVT Scheduler - Lenovo Group Limited - C: \ Program Files \ Common Files \ Lenovo \ Scheduler \ tvtsched.exe O23 - Service: Symantec LiveState Agent for Windows (WControl) - Symantec Corporation - c: \ _integra \ bin \ ccmagent.exe -- Fin de file - 8621 bytes |
|
#2
| |||
| |||
| Télécharger Malwarebytes' Anti-Malware (MBAM)
Note supplémentaire: Si MBAM rencontre un fichier qui est difficile à enlever, il vous sera présenté avec 1 de 2 messages, cliquez sur OK à deux et laissez-passer MBAM avec le processus de désinfection, en cas de demande de redémarrer l'ordinateur, s'il vous plaît le faire immédiatement. |
|
#3
| |||
| |||
| Pas de malware trouvé, voici le rapport -------------------------------------------------- ---- Windows 5.1.2600 Service Pack 2 9/21/2008 6:16:07 PM Mbam-log-2008-09-21 (18-16-07). txt Scan type: Quick Scan Objects scanned: 52621 Temps écoulé: 4 minute (s), 41 second (s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Fichiers infectés: 0 Memory Processes Infected: (Articles n ° malveillants détectés) Memory Modules Infected: (Articles n ° malveillants détectés) Registry Keys Infected: (Articles n ° malveillants détectés) Registry Values Infected: (Articles n ° malveillants détectés) Registry Data Items Infected: (Articles n ° malveillants détectés) Folders Infected: (Articles n ° malveillants détectés) Fichiers infectés: (Articles n ° malveillants détectés) |
|
#4
| |||
| |||
| Il n'y a pas de logiciels malveillants en montrant soit log. Qu'est-ce qui se passe? |
|
#5
| |||
| |||
| Multiple IEXPLORER.EXE processus sont spwaning dans la liste des processus. Ils ont immédiatement pop up si je les tuer un par un. Parfois, j'ai aussi entendre certains sons comme un de ceux qui dirigent une fenêtre de navigateur, mais pas visible. Il est certainement faux, ils ne sont pas censés exister. |
|
#6
| |||
| |||
| Télécharger ComboFix par SUBS de l'un des liens ci-dessous. Assurez-vous haut mettre à la Desktop. Lien # 1 Link # 2 ** Note: Il est important de le sauvegarder directement sur votre bureau Fermez tous les navigateurs Web. (Firefox, Internet Explorer, etc) avant de lancer ComboFix. Momentanément désactiver ton antivirus, Et tout antispyware protection en temps réel avant effectuer une analyse. Cliquez sur ce lien pour voir la liste des programmes de sécurité qui doit être désactivé et comment les désactiver. Double-cliquez sur combofix.exe et suivre les instructions. Lorsque vous avez terminé ComboFix va produire un journal pour vous. Publier le ComboFix log et un nouveau HijackThis log dans votre prochaine réponse. Important: Ne pas ComboFix clic de souris, la fenêtre en cours d'exécution. Cela mai à cause de décrochage. N'oubliez pas de réactiver votre antivirus et antispyware protection ComboFix est terminée. |
|
#7
| |||
| |||
| Log ComboFix ----------------------- ComboFix 08-09-20.05 - 012466 2008-09-21 19:31:50.1 - NTFSx86 Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1033.18.473 [GMT -7:00] Running from: C: \ Keanetools \ ComboFix.exe * Création d'un nouveau point de restauration ATTENTION CETTE MACHINE-N'A PAS LA CONSOLE DE RECUPERATION INSTALLED! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))) )))))))))))))))))))))))))))))))))))))))) . C: \ Documents and Settings \ LocalService \ Cookies \ system@ad.yieldmanag er [1]. Txt C: \ WINDOWS \ system32 \ x64 . ((((((((((((((((((((((((((((((((((((((( Pilotes / Services )))))))) ))))))))))))))))))))))))))))))))))))))))) . ------- \ Legacy_BHSRV ------- \ Service_BHsrv Créée à partir de ((((((((((((((((((((((((( Files 2008-08-22 au 2008-09-22 ))))))))))) )))))))))))))))))))) . 2008-09-21 18:09. 2008-09-21 18:10 <DIR> d -------- C: \ Program Files \ Malwarebytes' Anti-Malware 2008-09-21 18:09. 2008-09-21 18:09 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ Malwarebytes 2008-09-21 18:09. 2008-09-21 18:09 <DIR> d -------- C: \ Documents and Settings \012466 \ Application Data \ Malwarebytes 2008-09-21 18:09. 2008-09-10 00:04 38.528 - a ------ C: \ WINDOWS \ system32 \ drivers \ mbamswissarmy.sys 2008-09-21 18:09. 2008-09-10 00:03 17.200 - a ------ C: \ WINDOWS \ system32 \ drivers \ mbam.sys 2008-09-21 11:07. 2008-09-21 11:07 <DIR> d -------- C: \ Program Files \ Lavasoft 2008-09-21 11:07. 2008-09-21 11:08 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ Lavasoft 2008-09-21 11:06. 2008-09-21 11:06 <DIR> d -------- C: \ Program Files \ Common Files \ Wise Installation Wizard 2008-09-20 23:40. 2008-09-20 23:40 <DIR> d -------- C: \ Program Files \ Trend Micro 2008-09-19 09:03. 2008-09-19 09:08 <DIR> d -------- C: \ WINDOWS \ SxsCaPendDel 2008-09-19 00:49. 2008-09-19 00:52 <DIR> d -------- C: \ Documents and Settings \012466 \. Housecall6.6 2008-09-19 00:27. 2008-09-19 09:04 <DIR> da ------ C: \ Documents and Settings \ All Users \ Application Data \ TEMP 2008-09-18 20:25. 2002-02-04 06:22 1.230.336 - a ------ C: \ WINDOWS \ system32 \ msxml4.dll 2008-09-18 20:25. 2007-09-14 05:01 922,920 --------- C: \ WINDOWS \ system32 \ ahlprun.exe 2008-09-18 20:25. 2002-02-04 06:13 82.432 - a ------ C: \ WINDOWS \ system32 \ Msxml4r.dll 2008-09-18 20:25. 2002-02-04 06:13 44.544 - a ------ C: \ WINDOWS \ system32 \ msxml4a.dll 2008-09-18 20:25. 2002-02-07 18:43 9.679 - a ------ C: \ WINDOWS \ system32 \ msxml4r.cat 2008-09-18 20:25. 2002-02-07 18:43 9.675 - a ------ C: \ WINDOWS \ system32 \ msxml4.cat 2008-09-18 20:25. 2002-02-06 20:31 3.489 - a ------ C: \ WINDOWS \ system32 \ msxml4.Manifest 2008-09-18 20:25. 2002-02-06 20:31 500 - a ------ C: \ WINDOWS \ system32 \ msxml4r.Manifest 2008-09-18 20:21. 2008-09-18 20:21 <DIR> d -------- C: \ Program Files \ Common Files \ Lenovo 2008-09-18 18:27. 2008-09-21 11:54 21.272 - a ------ C: \ WINDOWS \ system32 \ bynpea.key 2008-09-18 18:25. 2008-09-18 18:25 1 - a ------ C: \ WINDOWS \ system32 \004fdb9.imi 2008-09-15 14:23. 2008-09-15 14:23 332.800 --- hs ---- C: \ WINDOWS \ system32 \ _Bhsrv.msi 2008-09-15 12:15. 2008-09-18 15:57 69.942 - a ------ C: \ WINDOWS \ system32 \ rrjack.key 2008-09-15 12:15. 2008-09-15 12:15 1 - a ------ C: \ WINDOWS \ system32 \0048444.imi 2008-09-13 19:27. 2008-09-13 19:27 24 - a ------ C: \ WINDOWS \ cdplayer.ini 2008-09-13 19:26. 2008-09-13 19:26 <DIR> d -------- C: \ Program Files \ Real 2008-09-13 19:26. 2008-09-13 19:26 <DIR> d -------- C: \ Program Files \ Common Files \ xing partagée 2008-09-13 19:26. 2008-09-13 19:26 <DIR> d -------- C: \ Program Files \ Fichiers communs \ Real . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))) )))))))))))))))))))))))))))))))))))))))))))) . 2008-09-22 02:33 --------- d ----- w C: \ Program Files \ Symantec AntiVirus 2008-09-22 02:33 --------- d ----- w C: \ Program Files \ Cisco VPN client 2008-09-21 18:56 16 - sh - r C: \ MSCIOTL.SYS 2008-09-21 18:55 8.416 ---- aw C: \ WINDOWS \ system32 \ drivers \ CDProbe.SYS 2008-09-20 19:26 430.816 - sh - w C: \ Program Files \ _MsInfo.msi 2008-09-19 03:25 --------- d - h - w C: \ Program Files \ InstallShield Installation Information 2008-09-19 03:25 --------- d ----- w C: \ Program Files \ ThinkVantage 2008-09-19 03:21 --------- d ----- w C: \ Program Files \ Lenovo . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))) )))))))))))))))))))))))))))))))))))))))) . . * Note * empty entries & legit entrées par défaut ne sont pas indiquées REGEDIT4 [HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ Curré ntVersion \ Run] "ctfmon.exe" = "C: \ WINDOWS \ system32 \ ctfmon.exe" [2004-08-04 15360] "Yahoo! Pager" = "C: \ Program Files \ Yahoo! \ Messenger \ YahooMessenger.exe" [2007-08-30 4670704] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ Run] "IgfxTray" = "C: \ WINDOWS \ system32 \ igfxtray.exe" [2007-08-15 141848] "HotKeysCmds" = "C: \ WINDOWS \ system32 \ hkcmd.exe" [2007-08-15 162328] "Persistence" = "C: \ WINDOWS \ system32 \ igfxpers.ex e" [2007-08-15 137752] "ccApp" = "C: \ Program Files \ Common Files \ Symantec Shared \ ccapp.exe" [2006-03-24 53408] "vptray" = "C: \ PROGRA ~ 1 \ SYMANT ~ 1 \ VPTray.exe" [2006-06-14 124656] "TPHOTKEY" = "C: \ Program Files \ Lenovo \ HotKey \ TPOSDSVC.exe" [2007-03-09 66176] "UpdateManager" = "C: \ Program Files \ Common Files \ Sonic \ Update Manager \ sgtray.exe" [2003-08-18 110592] "dla" = "C: \ WINDOWS \ system32 \ dla \ tfswctrl.exe" [2005-05-19 127037] "EZEJMNAP" = "C: \ PROGRA ~ 1 \ ThinkPad \ UTILIT ~ 1 \ EzEjMnAp. Exe" [2007-04-26 243248] "LPManager" = "C: \ PROGRA ~ 1 \ THINKV ~ 1 \ PrdCtr \ LPMGR.exe" [2007-03-22 120368] "TVT Scheduler Proxy" = "C: \ Program Files \ Common Files \ Lenovo \ Scheduler \ scheduler_proxy.exe" [2008-03-04 487424] "TkBellExe" = "C: \ Program Files \ Fichiers communs \ Real \ Update_OB \ realsched.exe" [2008-09-13 185896] "TrackPointSrv" = "tp4mon.exe" [2004-08-03 C: \ WINDOWS \ system32 \ tp4mon.exe] "NWTRAY" = "NWTRAY.EXE" [2002-03-12 C: \ WINDOWS \ system32 \ nwtray.exe] "TpShocks" = "TpShocks.exe" [2007-03-29 C: \ WINDOWS \ system32 \ TpShocks.exe] [HKEY_USERS \. DEFAULT \ Software \ Microsoft \ Windows \ Cur rentVersion \ Run] "Communicator" = "C: \ Program Files \ Microsoft Office Communicator \ Communicator.exe" [2005-05-12 4167376] [HKEY_LOCAL_MACHINE \ software \ microsoft \ windows \ curr entversion \ policies \ system] "CompatibleRUPSecurity" = 1 (0x1) [HKEY_USERS \. DEFAULT \ Software \ Microsoft \ Windows \ actu rentversion \ Policies \ Explorer] "StartMenuLogOff" = 1 (0x1) [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon \ Notify \ tpfnf2] 2006-09-06 13:37 34344 C: \ Program Files \ Lenovo \ HotKey \ notifyf2.dll [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon \ Notify \ tphotkey] 2006-12-14 08:06 28672 C: \ Program Files \ Lenovo \ HotKey \ tphklock.dll [HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ contro l \ Lsa] Authentication Packages REG_MULTI_SZ MSV1_0 nwv1_0 [HKEY_LOCAL_MACHINE \ software \ microsoft \ security center \ Monitoring \ SymantecAntiVirus] "DisableMonitoring" = dword: 00000001 [HKLM \ ~ \ Services \ SharedAccess \ Parameters \ firewallpo licy \ StandardProfile \ AuthorizedApplications \ List] "% windir% \ \ system32 \ \ sessmgr.exe" = "C: \ \ Program Files \ \ Yahoo! \ \ Messenger \ \ YahooMessenger.exe" = "C: \ \ Program Files \ \ Yahoo! \ \ Messenger \ \ YServer.exe" = R0 Shockprf; Shockprf; C: \ WINDOWS \ system32 \ drivers \ Apsx 86.sys [2007-03-02 100656] R0 TPDIGIMN; TPDIGIMN; C: \ WINDOWS \ system32 \ drivers \ ApsH M86.sys [2007-03-02 19760] R2 smefs; SMEFileSystem; C: \ WINDOWS \ system32 \ drivers \ sm efs.sys [2006-02-08 20508] R3 CdProbe; CdProbe; C: \ WINDOWS \ system32 \ drivers \ cdprob e.sys [2008-09-21 8416] R3 smedrv; SMEDriver; C: \ WINDOWS \ system32 \ drivers \ smedr v.sys [2006-02-08 9516] S2 AppMgSvc; Application Management Services, C: \ Program Files \ Fichiers communs \ Microsoft Shared \ Msinfo \ MsInfo.msi [2008-09-20 430816] S2 yraebbgi; yraebbgi; C: \ WINDOWS \ system32 \ drivers \ bynp ea.sys [] S2 yrtxzgwh; yrtxzgwh; C: \ WINDOWS \ system32 \ drivers \ rrja ck.sys [] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ svchost] wrtxzg REG_MULTI_SZ wrtxzg nraebb REG_MULTI_SZ nraebb . . Supplementary Scan ------- ------- . R0 -: HKCU-Main, Start Page = hxxp: / / www.google.com/ O8 -: E & xporter vers Microsoft Excel - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ OFFICE11 \ EXCEL.EXE/3000 . ************************************************** ************************ catchme 0.3.1361 W2K/XP/Vista - rootkit / stealth malware detector par Gmer, http://www.gmer.net Rootkit scan 2008-09-21 19:35:12 Windows 5.1.2600 Service Pack 2 NTFS scanning processus cachés ... scanning hidden autostart entries ... de balayage des fichiers cachés ... scan effectué avec succès les fichiers cachés: 0 ************************************************** ************************ [HKEY_LOCAL_MACHINE \ System \ ControlSet001 \ Services \ A ppMgSvc] "ImagePath" = "C: \ Program Files \ Fichiers communs \ Microsoft Shared \ Msinfo \ MsInfo.msi" . --------------------- DLLs Loaded Sous Running Processes --------------------- PROCESSUS: C: \ WINDOWS \ system32 \ winlogon.exe -> C: \ Program Files \ Lenovo \ HotKey \ tphklock.dll . ------------------------ Autres processus en cours ----------------------- -- . C: \ WINDOWS \ system32 \ ibmpmsvc.exe C: \ Program Files \ Intel \ Wireless \ Bin \ S24EvMon.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccsetmgr.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccEvtMgr.exe C: \ Program Files \ Common Files \ Symantec Shared \ SPBBC \ spbbcsvc.exe C: \ Program Files \ Lavasoft \ Ad-Aware \ aawservice.exe C: \ _integra \ bin \ shstart.exe C: \ WINDOWS \ system32 \ igfxsrvc.exe C: \ Program Files \ Lenovo \ HotKey \ TPONSCR.exe C: \ Program Files \ Lenovo \ ZOOM \ TpScrex.exe C: \ Program Files \ Symantec AntiVirus \ DoScan.exe C: \ Program Files \ Internet Explorer \ IEXPLORE.EXE C: \ CENTENN.IAL \ AUDIT \ CAgent32.exe C: \ CENTENN.IAL \ AUDIT \ xferwan.exe C: \ Program Files \ Cisco VPN Client \ cvpnd.exe C: \ Program Files \ Symantec AntiVirus \ DefWatch.exe C: \ Program Files \ Intel \ Wireless \ Bin \ EvtEng.exe C: \ Program Files \ Fichiers communs \ Microsoft Shared \ VS7DEBUG \ Mdm.exe C: \ Program Files \ Intel \ Wireless \ Bin \ RegSrvc.exe C: \ Program Files \ Yahoo! \ Messenger \ Ymsgr_tray.exe C: \ WINDOWS \ system32 \ calc.exe C: \ Program Files \ Symantec AntiVirus \ SavRoam.exe C: \ Program Files \ Symantec AntiVirus \ Rtvscan.exe C: \ Program Files \ Common Files \ Lenovo \ tvt_reg_monitor_svc.exe C: \ WINDOWS \ system32 \ TPHDEXLG.exe C: \ Program Files \ Common Files \ Lenovo \ Scheduler \ tvtsched.exe C: \ _integra \ bin \ ccmagent.exe C: \ Program Files \ Lenovo \ System Update \ SUService.exe C: \ WINDOWS \ system32 \ wscntfy.exe C: \ ComboFix \ pv.cfexe . ************************************************** ************************ . Délai: 2008-09-21 19:36:58 - machine a redémarré ComboFix-quarantaine-files.txt 2008-09-22 02:36:54 Pre-Run: 64333811712 octets libres Post-Run: 64523264000 octets libres 175 Log HijackThis ----------------------------------- Logfile de Trend Micro HijackThis v2.0.2 Scan sauvé à 7:38:41 PM, le 9.21.2008 Plate-forme: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C: \ WINDOWS \ System32 \ smss.exe C: \ WINDOWS \ system32 \ winlogon.exe C: \ WINDOWS \ system32 \ services.exe C: \ WINDOWS \ system32 \ lsass.exe C: \ WINDOWS \ system32 \ ibmpmsvc.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ Program Files \ Intel \ Wireless \ Bin \ S24EvMon.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccsetmgr.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccEvtMgr.exe C: \ Program Files \ Common Files \ Symantec Shared \ SPBBC \ spbbcsvc.exe C: \ Program Files \ Lavasoft \ Ad-Aware \ aawservice.exe C: \ WINDOWS \ system32 \ spoolsv.exe c: \ _integra \ bin \ shstart.exe C: \ WINDOWS \ system32 \ tp4mon.exe C: \ WINDOWS \ system32 \ igfxtray.exe C: \ WINDOWS \ system32 \ hkcmd.exe C: \ WINDOWS \ system32 \ igfxpers.exe C: \ WINDOWS \ system32 \ NWTRAY.EXE C: \ Program Files \ Common Files \ Symantec Shared \ ccapp.exe C: \ PROGRA ~ 1 \ SYMANT ~ 1 \ VPTray.exe C: \ WINDOWS \ system32 \ igfxsrvc.exe C: \ Program Files \ Lenovo \ HotKey \ TPOSDSVC.exe C: \ WINDOWS \ system32 \ dla \ tfswctrl.exe C: \ PROGRA ~ 1 \ ThinkPad \ UTILIT ~ 1 \ EzEjMnAp.Exe C: \ Program Files \ Lenovo \ HotKey \ TPONSCR.exe C: \ Program Files \ Lenovo \ Zoom \ TpScrex.exe C: \ PROGRA ~ 1 \ THINKV ~ 1 \ PrdCtr \ LPMGR.exe C: \ WINDOWS \ system32 \ TpShocks.exe C: \ Program Files \ Common Files \ Lenovo \ Scheduler \ scheduler_proxy.exe C: \ Program Files \ Fichiers communs \ Real \ Update_OB \ realsched.exe C: \ WINDOWS \ system32 \ ctfmon.exe C: \ Program Files \ Internet Explorer \ IEXPLORE.EXE C: \ WINDOWS \ system32 \ svchost.exe C: \ Centenn.ial \ Audit \ CAgent32.exe C: \ Centenn.ial \ Audit \ xferwan.exe C: \ Program Files \ Cisco VPN Client \ cvpnd.exe C: \ Program Files \ Symantec AntiVirus \ DefWatch.exe C: \ Program Files \ Intel \ Wireless \ Bin \ EvtEng.exe C: \ Program Files \ Fichiers communs \ Microsoft Shared \ VS7DEBUG \ Mdm.exe C: \ Program Files \ Intel \ Wireless \ Bin \ RegSrvc.exe C: \ Program Files \ Yahoo! \ Messenger \ ymsgr_tray.exe C: \ WINDOWS \ system32 \ calc.exe C: \ Program Files \ Symantec AntiVirus \ SavRoam.exe C: \ Program Files \ Symantec AntiVirus \ Rtvscan.exe C: \ Program Files \ Common Files \ Lenovo \ tvt_reg_monitor_svc.exe C: \ WINDOWS \ System32 \ TPHDEXLG.exe C: \ Program Files \ Common Files \ Lenovo \ Scheduler \ tvtsched.exe c: \ _integra \ bin \ ccmagent.exe c: \ program files \ lenovo \ system update \ suservice.exe C: \ WINDOWS \ system32 \ wscntfy.exe C: \ WINDOWS \ system32 \ Wuauclt.exe C: \ WINDOWS \ system32 \ Wuauclt.exe C: \ WINDOWS \ Explorer.exe C: \ Program Files \ Trend Micro \ HijackThis \ HijackThis.exe R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 O2 - BHO: AcroIEHlprObj Class - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Adobe \ Acrobat 7.0 \ ActiveX \ AcroIEHelper.dll O2 - BHO: DriveLetterAccess - (5CA3D70E-1895-11CF-8E15-001234567890) - C: \ WINDOWS \ system32 \ dla \ tfswshx.dll O4 - HKLM \ .. \ Run: [TrackPointSrv] tp4mon.exe O4 - HKLM \ .. \ Run: [IgfxTray] C: \ WINDOWS \ system32 \ igfxtray.exe O4 - HKLM \ .. \ Run: [HotKeysCmds] C: \ WINDOWS \ system32 \ hkcmd.exe O4 - HKLM \ .. \ Run: [Persistence] C: \ WINDOWS \ system32 \ igfxpers.exe O4 - HKLM \ .. \ Run: [NWTRAY] NWTRAY.EXE O4 - HKLM \ .. \ Run: [ccApp] "C: \ Program Files \ Common Files \ Symantec Shared \ ccapp.exe" O4 - HKLM \ .. \ Run: [vptray] C: \ PROGRA ~ 1 \ SYMANT ~ 1 \ VPTray.exe O4 - HKLM \ .. \ Run: [TPHOTKEY] C: \ Program Files \ Lenovo \ HotKey \ TPOSDSVC.exe O4 - HKLM \ .. \ Run: [UpdateManager] "C: \ Program Files \ Common Files \ Sonic \ Update Manager \ sgtray.exe" / r O4 - HKLM \ .. \ Run: [dla] C: \ WINDOWS \ system32 \ dla \ tfswctrl.exe O4 - HKLM \ .. \ Run: [EZEJMNAP] C: \ PROGRA ~ 1 \ ThinkPad \ UTILIT ~ 1 \ EzEjMnAp.Exe O4 - HKLM \ .. \ Run: [LPManager] C: \ PROGRA ~ 1 \ THINKV ~ 1 \ PrdCtr \ LPMGR.exe O4 - HKLM \ .. \ Run: [TpShocks] TpShocks.exe O4 - HKLM \ .. \ Run: [TVT Scheduler Proxy] C: \ Program Files \ Common Files \ Lenovo \ Scheduler \ scheduler_proxy.exe O4 - HKLM \ .. \ Run: [TkBellExe] "C: \ Program Files \ Fichiers communs \ Real \ Update_OB \ realsched.exe"-osboot O4 - HKCU \ .. \ Run: [ctfmon.exe] C: \ WINDOWS \ system32 \ ctfmon.exe O4 - HKCU \ .. \ Run: [Yahoo! Pager] "C: \ Program Files \ Yahoo! \ Messenger \ YahooMessenger.exe"-quiet O4 - HKUS \ S-1-5-19 \ .. \ Run: [Communicator] "C: \ Program Files \ Microsoft Office Communicator \ Communicator.exe" (User 'LOCAL SERVICE') O4 - HKUS \ S-1-5-20 \ .. \ Run: [Communicator] "C: \ Program Files \ Microsoft Office Communicator \ Communicator.exe" (User 'NETWORK SERVICE') O4 - HKUS \ S-1-5-18 \ .. \ Run: [Communicator] "C: \ Program Files \ Microsoft Office Communicator \ Communicator.exe" (User 'SYSTEM') O4 - HKUS \. DEFAULT \ .. \ Run: [Communicator] "C: \ Program Files \ Microsoft Office Communicator \ Communicator.exe" (User 'Default user') O8 - Extra du menu contextuel: E & xporter vers Microsoft Excel - res: / / C: \ PROGRA ~ 1 \ MICROS ~ 2 \ OFFICE11 \ EXCEL.EXE/3000 O9 - Extra button: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ OFFICE11 \ REFIEBAR.DLL O9 - Extra button: @ C: \ Program Files \ Messenger \ Msgslang.dll, -61144 - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe O9 - Extra 'Tools' menuitem: @ C: \ Program Files \ Messenger \ Msgslang.dll, -61144 - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe O16 - DPF: (215B8138-A3CF-44C5-803F-8226143CFC0A) (Trend Micro ActiveX Scan Agent 6.6) -- http://housecall65.trendmicro.com/ho...vex/hcImpl.cab O17 - HKLM \ System \ CCS \ Services \ Tcpip \ .. \ (B8E7B489-2160-4DE7-B592-9FD03D16CC74): Domain = keane.com O17 - HKLM \ System \ CCS \ Services \ Tcpip \ .. \ (D239A412-22C2-4683-95BC-1FFAA687D0DF): NameServer = 172.21.18.101,172.21.18.102 O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C: \ Program Files \ Lavasoft \ Ad-Aware \ aawservice.exe O23 - Service: Application Management Service (AppMgSvc) - Unknown owner - C: \ Program.exe (file missing) O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ ccsetmgr.exe O23 - Service: CentennialClientAgent - Centennial Software Limited - C: \ Centenn.ial \ Audit \ CAgent32.exe O23 - Service: CentennialIPTransferAgent - Centennial Software Limited - C: \ Centenn.ial \ Audit \ xferwan.exe O23 - Service: Service de mise à jour du client Novell (cusrvc) - Novell, Inc - C: \ WINDOWS \ system32 \ cusrvc.exe O23 - Service: Cisco Systems, Inc VPN Service (CVPND) - Cisco Systems, Inc - C: \ Program Files \ Cisco VPN Client \ cvpnd.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C: \ Program Files \ Symantec AntiVirus \ DefWatch.exe O23 - Service: Intel (R) PROSet / Wireless Event Log (EvtEng) - Intel Corporation - C: \ Program Files \ Intel \ Wireless \ Bin \ EvtEng.exe O23 - Service: ThinkPad PM Service (IBMPMSVC) - Lenovo - C: \ WINDOWS \ system32 \ ibmpmsvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C: \ PROGRA ~ 1 \ Symantec \ LIVEUP ~ 1 \ LUCOMS ~ 1.EXE O23 - Service: Intel (R) PROSet / Wireless Registry Service (RegSrvc) - Intel Corporation - C: \ Program Files \ Intel \ Wireless \ Bin \ RegSrvc.exe O23 - Service: Intel (R) PROSet / Wireless Service (S24EventMonitor) - Intel Corporation - C: \ Program Files \ Intel \ Wireless \ Bin \ S24EvMon.exe O23 - Service: SAVRoam (SavRoam) - symantec - C: \ Program Files \ Symantec AntiVirus \ SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ sndsrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C: \ Program Files \ Common Files \ Symantec Shared \ SPBBC \ spbbcsvc.exe O23 - Service: System Update (SUService) - Lenovo Group Limited - c: \ program files \ lenovo \ system update \ suservice.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C: \ Program Files \ Symantec AntiVirus \ Rtvscan.exe O23 - Service: ThinkVantage Registry Monitor Service - Lenovo Group Limited - C: \ Program Files \ Common Files \ Lenovo \ tvt_reg_monitor_svc.exe O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C: \ WINDOWS \ System32 \ TPHDEXLG.exe O23 - Service: TVT Scheduler - Lenovo Group Limited - C: \ Program Files \ Common Files \ Lenovo \ Scheduler \ tvtsched.exe O23 - Service: Symantec LiveState Agent for Windows (WControl) - Symantec Corporation - c: \ _integra \ bin \ ccmagent.exe -- Fin de file - 8581 bytes |
|
#8
| |||
| |||
| Note: les instructions ci-dessous ont été créées spécifiquement pour cet utilisateur. Si vous n'êtes pas cet utilisateur, NE PAS suivre ces instructions, sous peine d'endommager le fonctionnement de votre système Supprimer ces fichiers / dossiers, comme suit: 1. Aller à Démarrer > Courir > Type Notepad.exe et cliquez sur OK pour ouvrir le Bloc-notes. Il devoir être Bloc-notes, Wordpad pas. 2. Copiez le texte ci-dessous dans la case code en mettant en lumière tout le texte et en appuyant sur Ctrl + C Code: Killall: Driver:: BHSRV BHsrv File:: C: \ WINDOWS \ system32 \ bynpea.key C: \ WINDOWS \ system32 \ 004fdb9.imi C: \ WINDOWS \ system32 \ _Bhsrv.msi C: \ WINDOWS \ system32 \ rrjack. touche C: \ WINDOWS \ system32 \ 0048444.imi C: \ WINDOWS \ system32 \ drivers \ bynpea.sys C: \ WINDOWS \ system32 \ drivers \ rrjack.sys C: \ WINDOWS \ system32 \ calc.exe 4. Ensuite, cliquez sur Fichier > Sauver 5. Nom du fichier CFScript.txt - Enregistrez le fichier sur votre bureau 6. Ensuite, faites glisser le CFScript (maintenez enfoncé le bouton gauche tout en faisant glisser le fichier) et déposez-le (la libération du bouton gauche de la souris) dans ComboFix.exe comme vous le voyez sur la capture d'écran ci-dessous. Important: Exécutez cette instruction attentivement! ![]() ComboFix va commencer à exécuter, il suffit de suivre les instructions. Après un redémarrage (dans le cas où il demande de redémarrer l'ordinateur), il va produire un journal pour vous. Post que log (Combofix.txt) dans votre prochaine réponse. Note: Ne pas ComboFix clic de souris, la fenêtre en cours d'exécution. Cette mai cause votre système de gel |
|
#9
| |||
| |||
| ComboFix log après avoir exécuté CFSCript -------------------------------------------------- -------- ComboFix 08-09-20.05 - 012466 2008-09-21 22:11:45.2 - NTFSx86 Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1033.18.598 [GMT -7:00] Running from: C: \ Keanetools \ ComboFix.exe Command commutateurs utilisés:: C: \ Documents and Settings \012466 \ Desktop \ CFScript.txt * Création d'un nouveau point de restauration ATTENTION CETTE MACHINE-N'A PAS LA CONSOLE DE RECUPERATION INSTALLED! FILE:: C: \ WINDOWS \ system32 \ _Bhsrv.msi C: \ WINDOWS \ system32 \0048444.imi C: \ WINDOWS \ system32 \004fdb9.imi C: \ WINDOWS \ system32 \ bynpea.key C: \ WINDOWS \ system32 \ calc.exe C: \ WINDOWS \ system32 \ drivers \ bynpea.sys C: \ WINDOWS \ system32 \ drivers \ rrjack.sys C: \ WINDOWS \ system32 \ rrjack.key . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))) )))))))))))))))))))))))))))))))))))))))) . C: \ WINDOWS \ system32 \ _Bhsrv.msi C: \ WINDOWS \ system32 \0048444.imi C: \ WINDOWS \ system32 \004fdb9.imi C: \ WINDOWS \ system32 \ bynpea.key C: \ WINDOWS \ system32 \ calc.exe C: \ WINDOWS \ system32 \ rrjack.key . Créée à partir de ((((((((((((((((((((((((( Files 2008-08-22 au 2008-09-22 ))))))))))) )))))))))))))))))))) . 2008-09-21 18:09. 2008-09-21 18:10 <DIR> d -------- C: \ Program Files \ Malwarebytes' Anti-Malware 2008-09-21 18:09. 2008-09-21 18:09 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ Malwarebytes 2008-09-21 18:09. 2008-09-21 18:09 <DIR> d -------- C: \ Documents and Settings \012466 \ Application Data \ Malwarebytes 2008-09-21 18:09. 2008-09-10 00:04 38.528 - a ------ C: \ WINDOWS \ system32 \ drivers \ mbamswissarmy.sys 2008-09-21 18:09. 2008-09-10 00:03 17.200 - a ------ C: \ WINDOWS \ system32 \ drivers \ mbam.sys 2008-09-21 11:07. 2008-09-21 11:07 <DIR> d -------- C: \ Program Files \ Lavasoft 2008-09-21 11:07. 2008-09-21 11:08 <DIR> d -------- C: \ Documents and Settings \ All Users \ Application Data \ Lavasoft 2008-09-21 11:06. 2008-09-21 11:06 <DIR> d -------- C: \ Program Files \ Common Files \ Wise Installation Wizard 2008-09-20 23:40. 2008-09-20 23:40 <DIR> d -------- C: \ Program Files \ Trend Micro 2008-09-19 09:03. 2008-09-19 09:08 <DIR> d -------- C: \ WINDOWS \ SxsCaPendDel 2008-09-19 00:49. 2008-09-19 00:52 <DIR> d -------- C: \ Documents and Settings \012466 \. Housecall6.6 2008-09-19 00:27. 2008-09-19 09:04 <DIR> da ------ C: \ Documents and Settings \ All Users \ Application Data \ TEMP 2008-09-18 20:25. 2002-02-04 06:22 1.230.336 - a ------ C: \ WINDOWS \ system32 \ msxml4.dll 2008-09-18 20:25. 2007-09-14 05:01 922,920 --------- C: \ WINDOWS \ system32 \ ahlprun.exe 2008-09-18 20:25. 2002-02-04 06:13 82.432 - a ------ C: \ WINDOWS \ system32 \ Msxml4r.dll 2008-09-18 20:25. 2002-02-04 06:13 44.544 - a ------ C: \ WINDOWS \ system32 \ msxml4a.dll 2008-09-18 20:25. 2002-02-07 18:43 9.679 - a ------ C: \ WINDOWS \ system32 \ msxml4r.cat 2008-09-18 20:25. 2002-02-07 18:43 9.675 - a ------ C: \ WINDOWS \ system32 \ msxml4.cat 2008-09-18 20:25. 2002-02-06 20:31 3.489 - a ------ C: \ WINDOWS \ system32 \ msxml4.Manifest 2008-09-18 20:25. 2002-02-06 20:31 500 - a ------ C: \ WINDOWS \ system32 \ msxml4r.Manifest 2008-09-18 20:21. 2008-09-18 20:21 <DIR> d -------- C: \ Program Files \ Common Files \ Lenovo 2008-09-13 19:27. 2008-09-13 19:27 24 - a ------ C: \ WINDOWS \ cdplayer.ini 2008-09-13 19:26. 2008-09-13 19:26 <DIR> d -------- C: \ Program Files \ Real 2008-09-13 19:26. 2008-09-13 19:26 <DIR> d -------- C: \ Program Files \ Common Files \ xing partagée 2008-09-13 19:26. 2008-09-13 19:26 <DIR> d -------- C: \ Program Files \ Fichiers communs \ Real . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))) )))))))))))))))))))))))))))))))))))))))))))) . 2008-09-22 05:14 8.416 ---- aw C: \ WINDOWS \ system32 \ drivers \ CDProbe.SYS 2008-09-22 05:14 16 - sh - r C: \ MSCIOTL.SYS 2008-09-22 05:14 --------- d ----- w C: \ Program Files \ Symantec AntiVirus 2008-09-22 03:07 --------- d ----- w C: \ Program Files \ Cisco VPN client 2008-09-20 19:26 430.816 - sh - w C: \ Program Files \ _MsInfo.msi 2008-09-19 03:25 --------- d - h - w C: \ Program Files \ InstallShield Installation Information 2008-09-19 03:25 --------- d ----- w C: \ Program Files \ ThinkVantage 2008-09-19 03:21 --------- d ----- w C: \ Program Files \ Lenovo . ((((((((((((((((((((((((((((( Snapshot@2008-09-21_19.36.38.64 )))))))))) ))))))))))))))))))))))))))))))) . - 2008-09-21 18:59:45 71.370 ---- aw C: \ WINDOWS \ system32 \ Perfc009.dat + 2008-09-22 02:39:43 71.370 ---- aw C: \ WINDOWS \ system32 \ Perfc009.dat - 2008-09-21 18:59:45 439.832 ---- aw C: \ WINDOWS \ system32 \ Perfh009.dat + 2008-09-22 02:39:43 439.832 ---- aw C: \ WINDOWS \ system32 \ Perfh009.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))) )))))))))))))))))))))))))))))))))))))))) . . * Note * empty entries & legit entrées par défaut ne sont pas indiquées REGEDIT4 [HKEY_CURRENT_USER \ SOFTWARE \ Microsoft \ Windows \ Curré ntVersion \ Run] "ctfmon.exe" = "C: \ WINDOWS \ system32 \ ctfmon.exe" [2004-08-04 15360] "Yahoo! Pager" = "C: \ Program Files \ Yahoo! \ Messenger \ YahooMessenger.exe" [2007-08-30 4670704] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows \ Curr entVersion \ Run] "IgfxTray" = "C: \ WINDOWS \ system32 \ igfxtray.exe" [2007-08-15 141848] "HotKeysCmds" = "C: \ WINDOWS \ system32 \ hkcmd.exe" [2007-08-15 162328] "Persistence" = "C: \ WINDOWS \ system32 \ igfxpers.ex e" [2007-08-15 137752] "ccApp" = "C: \ Program Files \ Common Files \ Symantec Shared \ ccapp.exe" [2006-03-24 53408] "vptray" = "C: \ PROGRA ~ 1 \ SYMANT ~ 1 \ VPTray.exe" [2006-06-14 124656] "TPHOTKEY" = "C: \ Program Files \ Lenovo \ HotKey \ TPOSDSVC.exe" [2007-03-09 66176] "UpdateManager" = "C: \ Program Files \ Common Files \ Sonic \ Update Manager \ sgtray.exe" [2003-08-18 110592] "dla" = "C: \ WINDOWS \ system32 \ dla \ tfswctrl.exe" [2005-05-19 127037] "EZEJMNAP" = "C: \ PROGRA ~ 1 \ ThinkPad \ UTILIT ~ 1 \ EzEjMnAp. Exe" [2007-04-26 243248] "LPManager" = "C: \ PROGRA ~ 1 \ THINKV ~ 1 \ PrdCtr \ LPMGR.exe" [2007-03-22 120368] "TVT Scheduler Proxy" = "C: \ Program Files \ Common Files \ Lenovo \ Scheduler \ scheduler_proxy.exe" [2008-03-04 487424] "TkBellExe" = "C: \ Program Files \ Fichiers communs \ Real \ Update_OB \ realsched.exe" [2008-09-13 185896] "TrackPointSrv" = "tp4mon.exe" [2004-08-03 C: \ WINDOWS \ system32 \ tp4mon.exe] "NWTRAY" = "NWTRAY.EXE" [2002-03-12 C: \ WINDOWS \ system32 \ nwtray.exe] "TpShocks" = "TpShocks.exe" [2007-03-29 C: \ WINDOWS \ system32 \ TpShocks.exe] [HKEY_USERS \. DEFAULT \ Software \ Microsoft \ Windows \ Cur rentVersion \ Run] "Communicator" = "C: \ Program Files \ Microsoft Office Communicator \ Communicator.exe" [2005-05-12 4167376] [HKEY_LOCAL_MACHINE \ software \ microsoft \ windows \ curr entversion \ policies \ system] "CompatibleRUPSecurity" = 1 (0x1) [HKEY_USERS \. DEFAULT \ Software \ Microsoft \ Windows \ actu rentversion \ Policies \ Explorer] "StartMenuLogOff" = 1 (0x1) [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon \ Notify \ tpfnf2] 2006-09-06 13:37 34344 C: \ Program Files \ Lenovo \ HotKey \ notifyf2.dll [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ Winlogon \ Notify \ tphotkey] 2006-12-14 08:06 28672 C: \ Program Files \ Lenovo \ HotKey \ tphklock.dll [HKEY_LOCAL_MACHINE \ SYSTEM \ CurrentControlSet \ contro l \ Lsa] Authentication Packages REG_MULTI_SZ MSV1_0 nwv1_0 [HKEY_LOCAL_MACHINE \ software \ microsoft \ security center \ Monitoring \ SymantecAntiVirus] "DisableMonitoring" = dword: 00000001 [HKLM \ ~ \ Services \ SharedAccess \ Parameters \ firewallpo licy \ StandardProfile \ AuthorizedApplications \ List] "% windir% \ \ system32 \ \ sessmgr.exe" = "C: \ \ Program Files \ \ Yahoo! \ \ Messenger \ \ YahooMessenger.exe" = "C: \ \ Program Files \ \ Yahoo! \ \ Messenger \ \ YServer.exe" = R0 Shockprf; Shockprf; C: \ WINDOWS \ system32 \ drivers \ Apsx 86.sys [2007-03-02 100656] R0 TPDIGIMN; TPDIGIMN; C: \ WINDOWS \ system32 \ drivers \ ApsH M86.sys [2007-03-02 19760] R2 smefs; SMEFileSystem; C: \ WINDOWS \ system32 \ drivers \ sm efs.sys [2006-02-08 20508] R3 CdProbe; CdProbe; C: \ WINDOWS \ system32 \ drivers \ cdprob e.sys [2008-09-21 8416] R3 smedrv; SMEDriver; C: \ WINDOWS \ system32 \ drivers \ smedr v.sys [2006-02-08 9516] S2 AppMgSvc; Application Management Services, C: \ Program Files \ Fichiers communs \ Microsoft Shared \ Msinfo \ MsInfo.msi [2008-09-20 430816] S2 yraebbgi; yraebbgi; C: \ WINDOWS \ system32 \ drivers \ bynp ea.sys [] S2 yrtxzgwh; yrtxzgwh; C: \ WINDOWS \ system32 \ drivers \ rrja ck.sys [] [HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Windows NT \ CurrentVersion \ svchost] wrtxzg REG_MULTI_SZ wrtxzg nraebb REG_MULTI_SZ nraebb . ************************************************** ************************ catchme 0.3.1361 W2K/XP/Vista - rootkit / stealth malware detector par Gmer, http://www.gmer.net Rootkit scan 2008-09-21 22:16:04 Windows 5.1.2600 Service Pack 2 NTFS scanning processus cachés ... scanning hidden autostart entries ... de balayage des fichiers cachés ... C: \ WINDOWS \ system32 \ calc.exe scan effectué avec succès les fichiers cachés: 1 ************************************************** ************************ [HKEY_LOCAL_MACHINE \ System \ ControlSet001 \ Services \ A ppMgSvc] "ImagePath" = "C: \ Program Files \ Fichiers communs \ Microsoft Shared \ Msinfo \ MsInfo.msi" . --------------------- DLLs Loaded Sous Running Processes --------------------- PROCESSUS: C: \ WINDOWS \ system32 \ winlogon.exe -> C: \ Program Files \ Lenovo \ HotKey \ tphklock.dll . ------------------------ Autres processus en cours ----------------------- -- . C: \ WINDOWS \ system32 \ ibmpmsvc.exe C: \ Program Files \ Intel \ Wireless \ Bin \ S24EvMon.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccsetmgr.exe C: \ Program Files \ Common Files \ Symantec Shared \ ccEvtMgr.exe C: \ Program Files \ Common Files \ Symantec Shared \ SPBBC \ spbbcsvc.exe C: \ Program Files \ Lavasoft \ Ad-Aware \ aawservice.exe C: \ Program Files \ Internet Explorer \ IEXPLORE.EXE C: \ CENTENN.IAL \ AUDIT \ CAgent32.exe C: \ CENTENN.IAL \ AUDIT \ xferwan.exe C: \ Program Files \ Cisco VPN Client \ cvpnd.exe C: \ Program Files \ Symantec AntiVirus \ DefWatch.exe C: \ Program Files \ Intel \ Wireless \ Bin \ EvtEng.exe C: \ Program Files \ Fichiers communs \ Microsoft Shared \ VS7DEBUG \ Mdm.exe C: \ Program Files \ Intel \ Wireless \ Bin \ RegSrvc.exe C: \ Program Files \ Symantec AntiVirus \ SavRoam.exe C: \ Program Files \ Symantec AntiVirus \ Rtvscan.exe C: \ Program Files \ Common Files \ Lenovo \ tvt_reg_monitor_svc.exe C: \ WINDOWS \ system32 \ TPHDEXLG.exe C: \ Program Files \ Common Files \ Lenovo \ Scheduler \ tvtsched.exe C: \ _integra \ bin \ ccmagent.exe C: \ Program Files \ Lenovo \ System Update \ SUService.exe C: \ _integra \ bin \ shstart.exe C: \ WINDOWS \ system32 \ igfxsrvc.exe C: \ Program Files \ Lenovo \ HotKey \ TPONSCR.exe C: \ Program Files \ Lenovo \ ZOOM \ TpScrex.exe C: \ Program Files \ Symantec AntiVirus \ DoScan.exe C: \ Program Files \ Yahoo! \ Messenger \ Ymsgr_tray.exe C: \ ComboFix \ pv.cfexe . ************************************************** ************************ . Délai: 2008-09-21 22:17:28 - machine a redémarré ComboFix-quarantaine-files.txt 2008-09-22 05:17:23 ComboFix2.txt 2008-09-22 02:36:59 Pre-Run: 64509464576 octets libres Post-Run: 64505421824 octets libres 181 |
|
#10
| |||
| |||
| Télécharger OTMoveIt2 par Oldtimeret de l'enregistrer sur votre Desktop. Note: Si vous êtes en cours d'exécution sur Vista, cliquez avec le bouton droit et choisissez le OTMoveIt2.exe Exécuter en tant qu'administrateur. 1. Double-cliquez sur OTMoveIt2.exe pour l'exécuter. 2. Copiez les lignes de la codebox ci-dessous. Code: [kill explorer] C: \ WINDOWS \ system32 \ calc.exe HKEY_LOCAL_MACHINE \ System \ ControlSet001 \ Services \ AppMgSvc EmptyTemp [start explorer] 4. Cliquez sur le rouge Moveit! bouton. 5. Copier tout dans la fenêtre des résultats (sous la barre verte) et collez-le dans votre prochaine réponse. 6. Fermer OTMoveIt2 Note: Si un fichier ou un dossier ne peut pas être déplacé immédiatement mai-vous être demandé de redémarrer votre ordinateur afin de terminer le processus de déménagement. Si on vous demande de redémarrer l'ordinateur, choisissez Oui. Si non, le redémarrage de toute façon. |
![]() |
|
| Bookmarks |
Similar Threads | ||||
| Fil | Thread Starter | Forum | Réponses | Last Post |
| Suppression de virus iexplore.exe / Hijack log | xalice15x | Virus, Spyware et sécurité | 16 | 12 Nov 2008 19:43 |
| Iexplorer.exe virus - s'il vous plaît aidez-moi! | Giant Panda | Virus, Spyware et sécurité | 2 | 6 oct 2008 14:55 |
| Je reçois le bone.exe virus pour mon iexplorer | damandg | Virus, Spyware et sécurité | 12 | 14 Jul 2008 14:31 |
| Iexplorer.exe virus | iuboy2006 | Virus, Spyware et sécurité | 9 | 26 Mar 2008 08:12 |
| Avssytemcare popup virus et grands - (comprend hijack this) | sournois | Virus, Spyware et sécurité | 23 | 4e Sep 2007 16:15 |
| Thread Tools | |
| |