bonjour
donc voila j ai suivi les conseilles de "boule" via un forum et me voila donc j ai suivi ces conseilles pour supprimer des dos indesirable et la j attend la suite
j ai fini le scane avec combosfix voila le resulta et aussi une autre question AV7 c est instalé chez moi pas moyen de le supprimé si une personne pouvait m aider MERCI D AVANCE
ComboFix 10-03-27.03 - djamila 28/03/2010 11:58:39.1.1 - x86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.2037.972 [GMT 2:00]
Lancé depuis: c:\users\djamila\Documents\halfelin.exe.exe
SP: Spybot - Search and Destroy *disabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-3020705556-3743191606-2487699894-500
c:\recycled\Recycled
c:\users\djamila\AppData\Local\pipyjs.dat
c:\users\djamila\AppData\Local\pipyjs_nav.dat
c:\users\djamila\AppData\Local\pipyjs_navps.dat
c:\users\djamila\AppData\Roaming\PCPrivacyCleaner
c:\users\djamila\AppData\Roaming\PCPrivacyCleaner\Logs\scns.log
c:\windows\system32\bcmwl6.inf
c:\windows\System32\Desktop_.ini
c:\windows\system32\MSVolumeRDFr.dll
c:\windows\system32\oem83.inf
D:\Autorun.inf
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-02-28 au 2010-03-28 ))))))))))))))))))))))))))))))))))))
.
2010-03-28 10:13 . 2010-03-28 10:13 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-03-28 01:26 . 2010-03-28 05:32 -------- d-----w- c:\program files\a-squared Free
2010-03-27 19:02 . 2010-03-27 19:02 357376 ----a-w- c:\windows\system32\UpdateExplorer.dll
2010-03-22 00:02 . 2010-03-22 00:02 -------- d-----w- c:\users\djamila\Nouveau dossier (1)
2010-03-16 18:59 . 2010-03-16 18:55 754984 ----a-w- c:\programdata\DivX\Setup\Resource.dll
2010-03-16 18:59 . 2010-03-16 18:55 986904 ----a-w- c:\programdata\DivX\Setup\DivXSetup.exe
2010-03-16 18:57 . 2009-05-30 05:12 521809 ----a-w- c:\programdata\DivX\DivX7\DivX Converter\DivXConverterUninstall.exe
2010-03-16 18:57 . 2010-03-16 18:57 56766 ----a-w- c:\programdata\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-03-16 18:57 . 2010-03-16 18:57 56978 ----a-w- c:\programdata\DivX\WebPlayer\Uninstaller.exe
2010-03-16 18:57 . 2010-03-16 18:57 53600 ----a-w- c:\programdata\DivX\Update\Uninstaller.exe
2010-03-16 18:57 . 2010-03-16 18:57 57409 ----a-w- c:\programdata\DivX\ControlPanel\Uninstaller.exe
2010-03-16 18:57 . 2010-03-16 18:57 52963 ----a-w- c:\programdata\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-03-16 18:56 . 2010-03-16 18:56 54073 ----a-w- c:\programdata\DivX\Qt4.5\Uninstaller.exe
2010-03-16 18:55 . 2010-03-16 18:55 62776 ----a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-03-16 18:55 . 2010-03-16 18:57 -------- d-----w- c:\programdata\DivX
2010-03-11 02:01 . 2010-02-20 23:06 24064 ----a-w- c:\windows\system32\nshhttp.dll
2010-03-11 02:01 . 2010-02-20 20:53 411648 ----a-w- c:\windows\system32\drivers\http.sys
2010-03-11 02:01 . 2010-02-20 23:05 30720 ----a-w- c:\windows\system32\httpapi.dll
2010-03-03 01:08 . 2010-03-03 01:08 -------- d-----w- c:\program files\Conduit
2010-03-03 01:08 . 2010-03-03 01:08 -------- d-----w- c:\program files\Megastreaming
2010-03-01 10:43 . 2010-03-01 10:43 -------- d-----w- c:\users\djamila\AppData\Local\HP
2010-03-01 10:10 . 2010-03-01 10:10 -------- d-----w- c:\users\djamila\Nouveau dossier
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-28 08:41 . 2009-09-08 15:42 -------- d-----w- c:\program files\AskTBar
2010-03-28 08:31 . 2009-08-09 16:48 -------- d-----w- c:\programdata\Iso Web Bags Else
2010-03-28 08:31 . 2009-08-09 16:47 -------- d-----w- c:\programdata\Axis hole lies
2010-03-27 23:29 . 2006-11-02 15:48 49472 ----a-w- c:\windows\system32\perfh00C.dat
2010-03-27 23:29 . 2006-11-02 15:48 11720 ----a-w- c:\windows\system32\perfc00C.dat
2010-03-27 18:47 . 2009-11-22 13:42 -------- d-----w- c:\users\djamila\AppData\Roaming\vlc
2010-03-23 16:15 . 2008-02-25 18:17 -------- d-----w- c:\users\djamila\AppData\Roaming\Azureus
2010-03-23 12:14 . 2007-11-04 01:54 3128 ----a-w- c:\users\djamila\AppData\Roaming\wklnhst.dat
2010-03-16 18:59 . 2008-03-14 12:34 -------- d-----w- c:\program files\Google
2010-03-16 18:57 . 2008-02-28 15:09 -------- d-----w- c:\program files\DivX
2010-03-16 18:56 . 2009-05-30 05:12 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-03-11 02:34 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-03-10 14:40 . 2008-02-23 20:23 -------- d-----w- c:\users\djamila\AppData\Roaming\Apple Computer
2010-03-01 10:43 . 2009-11-04 14:31 -------- d-----w- c:\users\djamila\AppData\Roaming\HP
2010-03-01 10:42 . 2009-11-04 14:19 -------- d-----w- c:\programdata\HP
2010-02-27 10:56 . 2010-01-01 23:55 -------- d-----w- c:\users\djamila\AppData\Roaming\dvdcss
2010-02-24 13:17 . 2007-11-01 20:09 71064 ----a-w- c:\users\djamila\AppData\Local\GDIPFONTCACHEV1.DAT
2010-02-24 09:16 . 2009-10-03 05:08 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-12 10:32 . 2010-02-25 06:01 293376 ----a-w- c:\windows\system32\browserchoice.exe
2010-02-11 21:05 . 2009-07-10 16:21 91 ----a-w- c:\users\djamila\AppData\Local\qgyai.bat
2010-02-03 21:39 . 2010-02-03 21:39 -------- d-----w- c:\users\djamila\AppData\Roaming\Megaupload
2010-02-03 21:22 . 2010-02-03 21:22 -------- d-----w- c:\program files\Megaupload
2010-02-03 21:22 . 2007-07-31 08:14 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-02-02 21:31 . 2010-02-02 21:31 2560 ----a-w- c:\windows\_MSRSTRT.EXE
2010-02-02 21:24 . 2008-02-25 17:09 -------- d-----w- c:\program files\Java
2010-02-02 21:12 . 2009-11-22 11:52 -------- d-----w- c:\program files\AVS4YOU
2010-02-02 21:08 . 2009-11-22 11:53 -------- d-----w- c:\program files\Common Files\AVSMedia
2010-01-29 08:52 . 2010-01-25 20:35 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-01-28 01:23 . 2010-01-25 20:35 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-01-25 12:00 . 2010-02-23 23:34 471552 ----a-w- c:\windows\system32\secproc_isv.dll
2010-01-25 12:00 . 2010-02-23 23:34 152576 ----a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-01-25 12:00 . 2010-02-23 23:34 152064 ----a-w- c:\windows\system32\secproc_ssp.dll
2010-01-25 12:00 . 2010-02-23 23:34 471552 ----a-w- c:\windows\system32\secproc.dll
2010-01-25 11:58 . 2010-02-23 23:34 332288 ----a-w- c:\windows\system32\msdrm.dll
2010-01-25 08:21 . 2010-02-23 23:34 526336 ----a-w- c:\windows\system32\RMActivate_isv.exe
2010-01-25 08:21 . 2010-02-23 23:34 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-01-25 08:21 . 2010-02-23 23:34 518144 ----a-w- c:\windows\system32\RMActivate.exe
2010-01-25 08:21 . 2010-02-23 23:34 347136 ----a-w- c:\windows\system32\RMActivate_ssp.exe
2010-01-23 09:26 . 2010-02-23 23:41 2048 ----a-w- c:\windows\system32\tzres.dll
2010-01-14 22:51 . 2010-01-14 22:52 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-01-06 15:39 . 2010-02-23 23:34 1696256 ----a-w- c:\windows\system32\gameux.dll
2010-01-06 15:38 . 2010-02-23 23:34 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
2010-01-06 15:38 . 2010-02-23 23:34 173056 ----a-w- c:\windows\AppPatch\AcXtrnal.dll
2010-01-06 15:38 . 2010-02-23 23:34 542720 ----a-w- c:\windows\AppPatch\AcLayers.dll
2010-01-06 15:38 . 2010-02-23 23:34 458752 ----a-w- c:\windows\AppPatch\AcSpecfc.dll
2010-01-06 15:38 . 2010-02-23 23:34 2159616 ----a-w- c:\windows\AppPatch\AcGenral.dll
2010-01-06 13:30 . 2010-02-23 23:34 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
2010-01-02 06:38 . 2010-01-22 06:52 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-01-22 06:52 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-02 06:32 . 2010-01-22 06:52 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-01-02 04:57 . 2010-01-22 06:52 133632 ----a-w- c:\windows\system32\ieUnatt.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9CB65206-89C4-402c-BA80-02D8C59F9B1D}"= "c:\program files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL" [2009-09-08 57344]
"{0dfe5d0d-5bbc-44a9-af7b-4f4dc8a6d740}"= "c:\program files\Megastreaming\tbMega.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{9cb65206-89c4-402c-ba80-02d8c59f9b1d}]
[HKEY_CLASSES_ROOT\clsid\{0dfe5d0d-5bbc-44a9-af7b-4f4dc8a6d740}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0dfe5d0d-5bbc-44a9-af7b-4f4dc8a6d740}]
2010-02-22 11:05 2353176 ----a-w- c:\program files\Megastreaming\tbMega.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AE445072-6642-44B1-BD0E-FF64E03E10B5}]
2010-03-27 19:02 357376 ----a-w- c:\windows\System32\UpdateExplorer.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{0dfe5d0d-5bbc-44a9-af7b-4f4dc8a6d740}"= "c:\program files\Megastreaming\tbMega.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{0dfe5d0d-5bbc-44a9-af7b-4f4dc8a6d740}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{0DFE5D0D-5BBC-44A9-AF7B-4F4DC8A6D740}"= "c:\program files\Megastreaming\tbMega.dll" [2010-02-22 2353176]
[HKEY_CLASSES_ROOT\clsid\{0dfe5d0d-5bbc-44a9-af7b-4f4dc8a6d740}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Flaw burn"="c:\programdata\Else type type.i8irbq" [X]
"Bags Else Hole Lite"="c:\programdata\Else Slow Mags.c0feiz" [X]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-03-14 171448]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2009-08-25 2356088]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Shockwave Updater"="c:\windows\system32\Adobe\Shockwave 11\SwHelper_1150595.exe" [2009-03-19 460216]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-18 1008184]
"RtHDVCpl"="RtHDVCpl.exe" [2007-07-06 4669440]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-04-25 457216]
"PLFSet"="c:\windows\PLFSet.dll" [2007-04-25 45056]
"LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2007-07-16 768520]
"PlayMovie"="c:\program files\Acer Arcade Deluxe\Play Movie\PMVService.exe" [2007-05-24 206952]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-06-06 159744]
"Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-05-22 151552]
"WarReg_PopUp"="c:\acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 57344]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-01-02 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-01-02 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-01-02 133656]
"Skytel"="Skytel.exe" [2007-06-15 1826816]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-04 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-14 149280]
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2010-03-05 1135912]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2007-7-31 535336]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2008-10-16 214360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\eNetHook.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(b):40,7d,37,e9,e9,58,ca,01
R2 ALaunchService;ALaunch Service;c:\acer\ALaunch\ALaunchSvc.exe [2007-01-26 50688]
R2 gupdate1cac53a685cb59b;Service Google Update (gupdate1cac53a685cb59b);c:\program files\Google\Update\GoogleUpdate.exe [2010-03-16 133104]
R3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\DRIVERS\wg111v3.sys [x]
S2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796};{49DE1C67-83F8-4102-99E0-C16DCC7EEC796};c:\program files\Acer Arcade Deluxe\Play Movie\000.fcl [2006-11-02 13560]
S2 a2free;a-squared Free Service;c:\program files\a-squared Free\a2service.exe [2009-10-01 1858144]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\b57nd60x.sys [2007-06-05 179712]
S3 WSDPrintDevice;Prise en charge de l’impression WSD via UMB;c:\windows\system32\DRIVERS\WSDPrint.sys [2008-01-18 16896]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contenu du dossier 'Tâches planifiées'
2010-03-27 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-16 18:56]
2010-03-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-16 18:56]
2010-03-27 c:\windows\Tasks\User_Feed_Synchronization-{31B01340-7218-4E8F-A674-829A2C5DAEE9}.job
- c:\windows\system32\msfeedssync.exe [2010-01-22 04:56]
.
.
------- Examen supplémentaire -------
.
uSearchMigratedDefaultURL =
hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7uStart Page =
hxxp://search.conduit.com?SearchSource=10&ctid=CT2405725mStart Page =
hxxp://www.cooxer.com/uInternet Settings,ProxyOverride =
;*.local
IE: Download Link Using Mega Manager... - c:\program files\Megaupload\Mega Manager\mm_file.htm
IE: {{FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - c:\program files\PokerStars.NET\PokerStarsUpdate.exe
Trusted Zone: alloshowtv.com\www
DPF: {04CB5B64-5915-4629-B869-8945CEBADD21} - hxxps://static.impots.gouv.fr/abos/static/securite/certdgi1.cab
DPF: {4ECE056F-E50F-4F9D-B069-EB342D21F26A} - hxxp://www3.snapfish.fr/SnapfishActivia3.cab
DPF: {DFB5BCF1-06AE-4ABB-BFA8-1E228F41C50A} - hxxp://bobtv.fr/download/cfweb_www.bobtv.fr-download_instmodule.exe
DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} - hxxps://plugins.valueactive.eu/flashax/iefax.cab
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-Acer Tour Reminder - (no file)
HKCU-Run-pipyjs - c:\users\djamila\appdata\local\pipyjs.exe
HKLM-Run-Acer Tour - (no file)
HKLM-Run-eRecoveryService - (no file)
MSConfigStartUp-AV7 - c:\program files\AV7\antivirus7.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2010-03-28 12:14
Windows 6.0.6002 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{49DE1C67-83F8-4102-99E0-C16DCC7EEC796}]
"ImagePath"="\??\c:\program files\Acer Arcade Deluxe\Play Movie\000.fcl"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Heure de fin: 2010-03-28 12:20:15
ComboFix-quarantined-files.txt 2010-03-28 10:19
Avant-CF: 12 781 580 288 octets libres
Après-CF: 12 775 518 208 octets libres
- - End Of File - - 82F788637356A78E9E00962DCCF487F3