salut merci de ne pas faire de double sujet( je remet ici la suite de ton suje)t+
----
-
désole je n'ai pas réussit sur le site miraclesalad alors je vous envoi la suite
Logfile of random\'s system information tool 1.06 (written by random/random)
Run by rose at 2009-12-21 23:09:08
Microsoft Windows XP Professionnel Service Pack 2
System drive C: has 7 GB (49%) free of 15 GB
Total RAM: 511 MB (41% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:09:30, on 21/12/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\\WINDOWS\\System32\\smss.exe
C:\\WINDOWS\\system32\\winlogon.exe
C:\\WINDOWS\\system32\\services.exe
C:\\WINDOWS\\system32\\lsass.exe
C:\\WINDOWS\\system32\\svchost.exe
C:\\WINDOWS\\System32\\svchost.exe
C:\\WINDOWS\\Explorer.EXE
C:\\WINDOWS\\system32\\spoolsv.exe
C:\\Program Files\\Eset\\nod32kui.exe
C:\\Program Files\\Brother\\Brmfcmon\\BrMfcWnd.exe
C:\\Program Files\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe
C:\\Documents and Settings\\rose\\bagat.exe
C:\\Program Files\\Brother\\ControlCenter3\\brccMCtl.exe
C:\\PROGRA~1\\FICHIE~1\\France Telecom\\Shared Modules\\FTRTSVC\\0\\FTRTSVC.exe
C:\\Program Files\\OrangeHSS\\Launcher\\Launcher.exe
C:\\Program Files\\Eset\\nod32krn.exe
C:\\PROGRA~1\\FICHIE~1\\France Telecom\\Shared Modules\\AlertModule\\0\\AlertModule.exe
C:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaPort\\SeaPort.exe
C:\\WINDOWS\\system32\\svchost.exe
C:\\Program Files\\OrangeHSS\\systray\\systrayapp.exe
C:\\Program Files\\OrangeHSS\\Deskboard\\deskboard.exe
C:\\Program Files\\OrangeHSS\\connectivity\\connectivitymanager.exe
C:\\Program Files\\OrangeHSS\\connectivity\\CoreCom\\CoreCom.exe
C:\\Program Files\\OrangeHSS\\connectivity\\CoreCom\\OraConfigRecover.exe
C:\\PROGRA~1\\FICHIE~1\\France Telecom\\Shared Modules\\FTCOMModule\\0\\FTCOMModule.exe
C:\\Program Files\\Internet Explorer\\iexplore.exe
C:\\Program Files\\Windows Live\\Toolbar\\wltuser.exe
C:\\WINDOWS\\system32\\wuauclt.exe
C:\\WINDOWS\\system32\\NOTEPAD.EXE
C:\\Documents and Settings\\rose\\Bureau\\RSIT.exe
C:\\Program Files\\trend micro\\rose.exe
R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Start Page =
http://www.google.fr/R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Start Page =
http://www.troner.net/R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Search,SearchAssistant =
http://search.live.com/sphome.aspxR1 - HKCU\\Software\\Microsoft\\Internet Explorer\\SearchURL,(Default) =
http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBRR0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\\Program Files\\OrangeHSS\\SearchURLHook\\SearchPageURL.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\\Program Files\\Fichiers communs\\Adobe\\Acrobat\\ActiveX\\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\\Program Files\\Microsoft\\Search Enhancement Pack\\Search Helper\\SEPsearchhelperie.dll
O2 - BHO: Programme d\'aide de l\'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Windows Live\\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\\Program Files\\Windows Live\\Toolbar\\wltcore.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\\Program Files\\Windows Live\\Toolbar\\wltcore.dll
O4 - HKLM\\..\\Run: [ORAHSSSessionManager] C:\\Program Files\\OrangeHSS\\SessionManager\\SessionManager.exe
O4 - HKLM\\..\\Run: [nod32kui] \"C:\\Program Files\\Eset\\nod32kui.exe\" /WAITSERVICE
O4 - HKLM\\..\\Run: [BrMfcWnd] C:\\Program Files\\Brother\\Brmfcmon\\BrMfcWnd.exe /AUTORUN
O4 - HKLM\\..\\Run: [SetDefPrt] C:\\Program Files\\Brother\\Brmfl06a\\BrStDvPt.exe
O4 - HKLM\\..\\Run: [ControlCenter3] C:\\Program Files\\Brother\\ControlCenter3\\brctrcen.exe /autorun
O4 - HKLM\\..\\Run: [SoftwareHelper] C:\\Documents and Settings\\rose\\Application Data\\eoRezo\\SoftwareUpdate\\SoftwareUpdateHP.exe
O4 - HKLM\\..\\Run: [Adobe Reader Speed Launcher] \"C:\\Program Files\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe\"
O4 - HKCU\\..\\Run: [rose] C:\\Documents and Settings\\rose\\rose.exe
O4 - HKCU\\..\\Run: [bagat] C:\\Documents and Settings\\rose\\bagat.exe
O4 - HKCU\\..\\Run: [Zeldar] C:\\DOCUME~1\\rose\\LOCALS~1\\Temp\\c.exe
O4 - HKCU\\..\\Run: [4VDD85L8NF] C:\\WINDOWS\\msa.exe
O4 - HKUS\\S-1-5-19\\..\\RunOnce: [Config] %systemroot%\\system32\\run.cmd (User \'SERVICE LOCAL\')
O4 - HKUS\\S-1-5-19\\..\\RunOnce: [nlsf] cmd.exe /C move /Y \"%SystemRoot%\\System32\\syssetub.dll\" \"%SystemRoot%\\System32\\syssetup.dll\" (User \'SERVICE LOCAL\')
O4 - HKUS\\S-1-5-19\\..\\RunOnce: [tscuninstall] %systemroot%\\system32\\tscupgrd.exe (User \'SERVICE LOCAL\')
O4 - HKUS\\S-1-5-20\\..\\RunOnce: [Config] %systemroot%\\system32\\run.cmd (User \'SERVICE RÉSEAU\')
O4 - HKUS\\S-1-5-18\\..\\RunOnce: [Config] %systemroot%\\system32\\run.cmd (User \'SYSTEM\')
O4 - HKUS\\.DEFAULT\\..\\RunOnce: [Config] %systemroot%\\system32\\run.cmd (User \'Default user\')
O8 - Extra context menu item: E&xporter vers Microsoft Excel -
res://C:\\PROGRA~1\\MICROS~2\\OFFICE11\\EXCEL.EXE/3000O8 - Extra context menu item: Ouvrir dans un nouvel onglet d\'arrière-plan -
res://C:\\Program Files\\Windows Live Toolbar\\Components\\fr-fr\\msntabres.dll.mui/229?5f6275cf148a4acb8c39c1e53a897958
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan -
res://C:\\Program Files\\Windows Live Toolbar\\Components\\fr-fr\\msntabres.dll.mui/230?5f6275cf148a4acb8c39c1e53a897958
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\\Program Files\\Windows Live\\Writer\\WriterBrowserExtension.dll
O9 - Extra \'Tools\' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\\Program Files\\Windows Live\\Writer\\WriterBrowserExtension.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\\PROGRA~1\\MICROS~2\\OFFICE11\\REFIEBAR.DLL
O15 - Trusted Zone:
http://*.mappy.comO15 - Trusted Zone:
http://*.orange.frO15 - Trusted Zone:
http://rw.search.ke.voila.frO15 - Trusted Zone:
http://orange.weborama.frO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cabO16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) -
http://download.eset.com/special/eos/OnlineScanner.cabO16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) -
http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cabO16 - DPF: {D6ED542B-6339-11D2-91A8-00A0C9B760DB} (RteDocumatDoc Control) -
http://cabs.rte.fr/RteAllCabsMFC.cabO16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) -
http://gfx1.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cabO23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\\PROGRA~1\\FICHIE~1\\France Telecom\\Shared Modules\\FTRTSVC\\0\\FTRTSVC.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\\Program Files\\Fichiers communs\\LogiShrd\\SrvLnch\\SrvLnch.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\\Program Files\\Eset\\nod32krn.exe
--
End of file - 6915 bytes
======Scheduled tasks folder======
C:\\WINDOWS\\tasks\\WGASetup.job
======Registry dump======
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\\Program Files\\Fichiers communs\\Adobe\\Acrobat\\ActiveX\\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
Search Helper - C:\\Program Files\\Microsoft\\Search Enhancement Pack\\Search Helper\\SEPsearchhelperie.dll [2009-05-19 137600]
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d\'aide de l\'Assistant de connexion Windows Live - C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Windows Live\\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Browser Helper Objects\\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10}]
Windows Live Toolbar Helper - C:\\Program Files\\Windows Live\\Toolbar\\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Internet Explorer\\Toolbar]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\\Program Files\\Windows Live\\Toolbar\\wltcore.dll [2009-02-06 1068904]
[HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run]
\"ORAHSSSessionManager\"=C:\\Program Files\\OrangeHSS\\SessionManager\\SessionManager.exe [2007-12-12 107248]
\"nod32kui\"=C:\\Program Files\\Eset\\nod32kui.exe [2009-06-29 949376]
\"BrMfcWnd\"=C:\\Program Files\\Brother\\Brmfcmon\\BrMfcWnd.exe [2006-03-28 622592]
\"SetDefPrt\"=C:\\Program Files\\Brother\\Brmfl06a\\BrStDvPt.exe [2005-01-26 49152]
\"ControlCenter3\"=C:\\Program Files\\Brother\\ControlCenter3\\brctrcen.exe [2006-04-10 61440]
\"EoEngine\"= []
\"SoftwareHelper\"=C:\\Documents and Settings\\rose\\Application Data\\eoRezo\\SoftwareUpdate\\SoftwareUpdateHP.exe []
\"Adobe Reader Speed Launcher\"=C:\\Program Files\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe [2009-02-27 35696]
[HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run]
\"rose\"=C:\\Documents and Settings\\rose\\rose.exe []
\"bagat\"=C:\\Documents and Settings\\rose\\bagat.exe [2009-12-19 81920]
\"Zeldar\"=C:\\DOCUME~1\\rose\\LOCALS~1\\Temp\\c.exe []
\"4VDD85L8NF\"=C:\\WINDOWS\\msa.exe []
[HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\System]
\"dontdisplaylastusername\"=0
\"legalnoticecaption\"=
\"legalnoticetext\"=
\"shutdownwithoutlogon\"=1
\"undockwithoutlogon\"=1
[HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\explorer]
\"NoDriveTypeAutoRun\"=145
\"MemCheckBoxInRunDlg\"=1
\"NoSMBalloonTip\"=1
\"NoDesktopCleanupWizard\"=1
\"NoWelcomeScreen\"=1
\"NoStrCmpLogical\"=0
\"NoInstrumentation\"=0
\"NoDriveAutorun\"=0
[HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\explorer]
\"HonorAutoRunSetting\"=
[HKEY_LOCAL_MACHINE\\system\\currentcontrolset\\services\\sharedaccess\\parameters\\firewallpolicy\\standardprofile\\authorizedapplications\\list]
\"%windir%\\system32\\sessmgr.exe\"=\"%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019\"
\"C:\\Program Files\\MSN Messenger\\msncall.exe\"=\"C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)\"
\"C:\\Program Files\\MSN Messenger\\livecall.exe\"=\"C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)\"
\"C:\\Program Files\\OrangeHSS\\Connectivity\\ConnectivityManager.exe\"=\"C:\\Program Files\\OrangeHSS\\Connectivity\\ConnectivityManager.exe:*:enabled:CSS\"
\"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe\"=\"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call\"
\"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe\"=\"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger\"
[HKEY_LOCAL_MACHINE\\system\\currentcontrolset\\services\\sharedaccess\\parameters\\firewallpolicy\\domainprofile\\authorizedapplications\\list]
\"%windir%\\system32\\sessmgr.exe\"=\"%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019\"
\"C:\\Program Files\\MSN Messenger\\msncall.exe\"=\"C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)\"
\"C:\\Program Files\\MSN Messenger\\livecall.exe\"=\"C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)\"
\"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe\"=\"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call\"
\"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe\"=\"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger\"
[HKEY_CURRENT_USER\\software\\microsoft\\windows\\currentversion\\explorer\\mountpoints2\\{5140a62c-ec87-11de-a840-0002a5e14266}]
shell\\AutoRun\\command - C:\\WINDOWS\\system32\\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sEB.eXE
[HKEY_CURRENT_USER\\software\\microsoft\\windows\\currentversion\\explorer\\mountpoints2\\{beab712e-b114-11de-a80c-0002a5e14266}]
shell\\AutoRun\\command - C:\\WINDOWS\\system32\\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL SeB.EXe
======List of files/folders created in the last 1 months======
2009-12-21 23:05:01 ----D---- C:\\Program Files\\trend micro
2009-12-21 23:04:57 ----D---- C:\\rsit
2009-12-21 21:35:32 ----D---- C:\\Documents and Settings\\rose\\Application Data\\Malwarebytes
2009-12-21 21:35:05 ----D---- C:\\Documents and Settings\\All Users\\Application Data\\Malwarebytes
2009-12-21 21:34:59 ----D---- C:\\Program Files\\Malwarebytes\' Anti-Malware
2009-12-20 18:20:31 ----D---- C:\\spoolerlogs
2009-12-18 21:23:18 ----D---- C:\\Documents and Settings\\rose\\Application Data\\MAGIX
2009-12-18 21:20:35 ----D---- C:\\Program Files\\Fichiers communs\\MAGIX Shared
2009-12-18 21:20:28 ----A---- C:\\WINDOWS\\system32\\msxml4a.dll
2009-12-18 21:20:26 ----A---- C:\\WINDOWS\\system32\\TTIC32.dll
2009-12-18 21:20:26 ----A---- C:\\WINDOWS\\system32\\TTI32.dll
2009-12-18 21:20:26 ----A---- C:\\WINDOWS\\system32\\STRING32.dll
2009-12-18 21:20:26 ----A---- C:\\WINDOWS\\system32\\MXRestore.exe
2009-12-18 21:20:26 ----A---- C:\\WINDOWS\\system32\\mgxcdr.txt
2009-12-18 21:20:26 ----A---- C:\\WINDOWS\\system32\\DLLTPO32.dll
2009-12-18 21:20:26 ----A---- C:\\WINDOWS\\system32\\DLLRES32.dll
2009-12-18 21:20:26 ----A---- C:\\WINDOWS\\system32\\DLLRD32.dll
2009-12-18 21:20:26 ----A---- C:\\WINDOWS\\system32\\DLLPTL32.dll
2009-12-18 21:20:26 ----A---- C:\\WINDOWS\\system32\\DLLPRJ32.dll
2009-12-18 21:20:26 ----A---- C:\\WINDOWS\\system32\\DLLPRF32.dll
2009-12-18 21:20:26 ----A---- C:\\WINDOWS\\system32\\DLLPNT32.dll
2009-12-18 21:20:26 ----A---- C:\\WINDOWS\\system32\\DLLMSC32.dll
2009-12-18 21:20:26 ----A---- C:\\WINDOWS\\system32\\DLLIX.dll
2009-12-18 21:20:26 ----A---- C:\\WINDOWS\\system32\\DLLISO32.dll
2009-12-18 21:20:26 ----A---- C:\\WINDOWS\\system32\\DLLIO32.dll
2009-12-18 21:20:26 ----A---- C:\\WINDOWS\\system32\\DLLIMG32.dll
2009-12-18 21:20:26 ----A---- C:\\WINDOWS\\system32\\DLLDRV32.dll
2009-12-18 21:20:26 ----A---- C:\\WINDOWS\\system32\\DLLDIR32.dll
2009-12-18 21:20:26 ----A---- C:\\WINDOWS\\system32\\DLLDEV32.dll
2009-12-18 21:20:26 ----A---- C:\\WINDOWS\\system32\\DLLCPY32.dll
2009-12-18 21:20:26 ----A---- C:\\WINDOWS\\system32\\DLLCDF32.dll
2009-12-18 21:20:26 ----A---- C:\\WINDOWS\\system32\\DLLCDA32.dll
2009-12-18 21:20:26 ----A---- C:\\WINDOWS\\system32\\DLLAV32.dll
2009-12-18 21:18:32 ----D---- C:\\Documents and Settings\\All Users\\Application Data\\MAGIX
2009-12-18 21:17:51 ----A---- C:\\WINDOWS\\system32\\DLLDEV32i.dll
2009-12-18 21:17:01 ----D---- C:\\Program Files\\Fichiers communs\\MAGIX Services
2009-12-11 21:48:52 ----HDC---- C:\\WINDOWS\\$NtUninstallKB970430$
2009-12-11 21:48:00 ----HDC---- C:\\WINDOWS\\$NtUninstallKB974318$
2009-12-11 21:46:52 ----HDC---- C:\\WINDOWS\\$NtUninstallKB976325$
2009-12-11 21:46:34 ----HDC---- C:\\WINDOWS\\$NtUninstallKB973904$
2009-12-11 21:46:21 ----HDC---- C:\\WINDOWS\\$NtUninstallKB974392$
2009-12-11 21:46:01 ----HDC---- C:\\WINDOWS\\$NtUninstallKB971737$
2009-12-01 23:19:10 ----HDC---- C:\\WINDOWS\\$NtUninstallKB961118$
2009-12-01 23:18:24 ----HDC---- C:\\WINDOWS\\$NtUninstallKB925720$
2009-11-29 18:36:31 ----D---- C:\\WINDOWS\\system32\\XPSViewer
2009-11-29 18:36:25 ----D---- C:\\Program Files\\MSBuild
2009-11-29 18:36:22 ----D---- C:\\WINDOWS\\system32\\en-US
2009-11-29 18:36:13 ----D---- C:\\Program Files\\Reference Assemblies
2009-11-29 18:35:25 ----N---- C:\\WINDOWS\\system32\\xpssvcs.dll
2009-11-29 18:35:25 ----N---- C:\\WINDOWS\\system32\\xpsshhdr.dll
2009-11-29 18:35:25 ----N---- C:\\WINDOWS\\system32\\prntvpt.dll
2009-11-29 18:35:24 ----D---- C:\\41f134ba0fbbe3c602e5
2009-11-29 18:30:17 ----D---- C:\\Program Files\\MSXML 6.0
2009-11-25 19:28:45 ----D---- C:\\Program Files\\Microsoft Office Outlook Connector
2009-11-25 19:24:16 ----RSD---- C:\\WINDOWS\\assembly
2009-11-25 19:23:13 ----D---- C:\\WINDOWS\\Microsoft.NET
2009-11-25 19:05:30 ----HDC---- C:\\WINDOWS\\$NtUninstallKB976098-v2$
2009-11-25 19:05:14 ----HDC---- C:\\WINDOWS\\$NtUninstallKB973687$
======List of files/folders modified in the last 1 months======
2009-12-21 23:05:55 ----D---- C:\\WINDOWS\\Prefetch
2009-12-21 23:05:01 ----RD---- C:\\Program Files
2009-12-21 22:57:41 ----D---- C:\\WINDOWS\\Temp
2009-12-21 22:51:29 ----D---- C:\\WINDOWS\\WinSxS
2009-12-21 22:51:29 ----D---- C:\\WINDOWS\\system32\\drivers
2009-12-21 22:50:55 ----A---- C:\\WINDOWS\\SchedLgU.Txt
2009-12-21 22:47:56 ----SD---- C:\\WINDOWS\\Tasks
2009-12-21 21:14:33 ----D---- C:\\WINDOWS\\system32
2009-12-21 21:14:33 ----D---- C:\\WINDOWS
2009-12-21 19:00:43 ----SHD---- C:\\System Volume Information
2009-12-21 19:00:43 ----D---- C:\\WINDOWS\\system32\\Restore
2009-12-21 16:09:31 ----SD---- C:\\WINDOWS\\Downloaded Program Files
2009-12-21 16:09:28 ----D---- C:\\WINDOWS\\system32\\CatRoot2
2009-12-21 16:09:17 ----D---- C:\\Program Files\\ESET
2009-12-21 12:54:43 ----D---- C:\\Program Files\\WinRAR
2009-12-20 17:32:55 ----RD---- C:\\WINDOWS\\Web
2009-12-20 16:58:42 ----D---- C:\\WINDOWS\\SHELLNEW
2009-12-20 02:21:00 ----SHD---- C:\\WINDOWS\\Installer
2009-12-19 15:58:01 ----HD---- C:\\WINDOWS\\inf
2009-12-19 11:29:23 ----D---- C:\\Documents and Settings\\rose\\Application Data\\vlc
2009-12-18 21:40:25 ----D---- C:\\Program Files\\Opera
2009-12-18 21:39:16 ----D---- C:\\Documents and Settings\\rose\\Application Data\\EoRezo
2009-12-18 21:38:52 ----D---- C:\\Program Files\\Windows Live
2009-12-18 21:34:28 ----HD---- C:\\Program Files\\InstallShield Installation Information
2009-12-18 21:33:50 ----D---- C:\\Program Files\\eMule
2009-12-18 21:20:35 ----D---- C:\\Program Files\\Fichiers communs
2009-12-18 21:20:34 ----RSD---- C:\\WINDOWS\\Fonts
2009-12-13 21:47:26 ----SD---- C:\\Documents and Settings\\rose\\Application Data\\Microsoft
2009-12-12 10:42:25 ----A---- C:\\WINDOWS\\system32\\PerfStringBackup.INI
2009-12-11 21:48:54 ----RSHDC---- C:\\WINDOWS\\system32\\dllcache
2009-12-11 21:48:06 ----A---- C:\\WINDOWS\\imsins.BAK
2009-12-11 21:47:00 ----D---- C:\\Program Files\\Internet Explorer
2009-12-11 21:46:31 ----HD---- C:\\WINDOWS\\$hf_mig$
2009-12-01 23:19:57 ----D---- C:\\WINDOWS\\system32\\CatRoot
2009-11-29 18:35:51 ----D---- C:\\WINDOWS\\system32\\spool
2009-11-25 19:28:53 ----D---- C:\\Program Files\\Microsoft
2009-11-25 19:28:46 ----D---- C:\\Program Files\\Fichiers communs\\System
2009-11-25 19:21:35 ----D---- C:\\WINDOWS\\system32\\DirectX
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 nod32drv;nod32drv; C:\\WINDOWS\\system32\\drivers\\nod32drv.sys [2009-06-29 15424]
R1 StarOpen;StarOpen; C:\\WINDOWS\\system32\\drivers\\StarOpen.sys [2006-07-24 5632]
R1 WS2IFSL;Environnement de prise en charge de Fournisseur de services non-IFS Windows Sockets 2.0; C:\\WINDOWS\\System32\\drivers\\ws2ifsl.sys [2001-08-24 12032]
R2 AMON;AMON; C:\\WINDOWS\\system32\\drivers\\amon.sys [2009-06-29 512096]
R3 ac97intc;Service d\'installation du pilote audio Intel(r) 82801 (WDM); C:\\WINDOWS\\system32\\drivers\\ac97intc.sys [2001-08-17 96256]
R3 E100B;Pilote de carte Intel (R) PRO; C:\\WINDOWS\\system32\\DRIVERS\\e100b325.sys [2001-08-23 117760]
R3 LVUSBSta;Logitech USB Monitor Filter; C:\\WINDOWS\\system32\\drivers\\LVUSBSta.sys [2007-02-03 41504]
R3 nv;nv; C:\\WINDOWS\\system32\\DRIVERS\\nv4_mini.sys [2004-08-03 1897408]
R3 PCANDIS5;PCANDIS5 NDIS Protocol Driver; \\??\\C:\\WINDOWS\\system32\\PCANDIS5.SYS []
R3 PID_0928;Logitech QuickCam Express(PID_0928); C:\\WINDOWS\\system32\\DRIVERS\\LV561AV.SYS [2007-02-03 490784]
R3 usbhub;Concentrateur USB2; C:\\WINDOWS\\system32\\DRIVERS\\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\\WINDOWS\\system32\\DRIVERS\\usbuhci.sys [2004-08-03 20480]
S3 BrScnUsb;Brother USB Still Image driver; C:\\WINDOWS\\system32\\DRIVERS\\BrScnUsb.sys [2004-10-15 15295]
S3 CamDrL;Logitech QuickCam Pro 3000(CamDrl); C:\\WINDOWS\\system32\\DRIVERS\\Camdrl.sys [2007-02-03 1075360]
S3 CCDECODE;Décodeur sous-titre fermé; C:\\WINDOWS\\system32\\DRIVERS\\CCDECODE.sys [2004-08-03 17024]
S3 hidusb;Pilote de classe HID Microsoft; C:\\WINDOWS\\system32\\DRIVERS\\hidusb.sys [2001-08-24 9600]
S3 LVcKap;Logitech AEC Driver; C:\\WINDOWS\\system32\\DRIVERS\\LVcKap.sys [2007-02-06 1691808]
S3 LVMVDrv;Logitech Machine Vision Engine Loader; C:\\WINDOWS\\system32\\DRIVERS\\LVMVDrv.sys [2007-02-06 1964064]
S3 mouhid;Pilote HID de souris; C:\\WINDOWS\\system32\\DRIVERS\\mouhid.sys [2006-03-09 12288]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\\WINDOWS\\system32\\drivers\\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;Codec NABTS/FEC VBI; C:\\WINDOWS\\system32\\DRIVERS\\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Connection TV/vidéo Microsoft; C:\\WINDOWS\\system32\\DRIVERS\\NdisIP.sys [2004-08-03 10880]
S3 PALLADIA;Palladia 300/400 Usb Adsl Modem; C:\\WINDOWS\\system32\\DRIVERS\\usbiad.sys [2005-06-13 31579]
S3 PCAMPR5;PCAMPR5 NDIS Protocol Driver; \\??\\C:\\WINDOWS\\system32\\PCAMPR5.SYS []
S3 SLIP;Détrameur décalage BDA; C:\\WINDOWS\\system32\\DRIVERS\\SLIP.sys [2004-08-03 11136]
S3 ssm_bus;SAMSUNG Mobile USB Device II 1.0 driver (WDM); C:\\WINDOWS\\system32\\DRIVERS\\ssm_bus.sys [2005-08-30 58320]
S3 ssm_mdfl;SAMSUNG Mobile USB Modem II 1.0 Filter; C:\\WINDOWS\\system32\\DRIVERS\\ssm_mdfl.sys [2005-08-30 8336]
S3 ssm_mdm;SAMSUNG Mobile USB Modem II 1.0 Drivers; C:\\WINDOWS\\system32\\DRIVERS\\ssm_mdm.sys [2005-08-30 94000]
S3 streamip;BDA IPSink; C:\\WINDOWS\\system32\\DRIVERS\\StreamIP.sys [2004-08-03 15360]
S3 usbaudio;Pilote USB audio (WDM); C:\\WINDOWS\\system32\\drivers\\usbaudio.sys [2004-08-03 59264]
S3 usbccgp;Pilote parent générique USB Microsoft; C:\\WINDOWS\\system32\\DRIVERS\\usbccgp.sys [2004-08-03 31616]
S3 usbprint;Classe d\'imprimantes USB Microsoft; C:\\WINDOWS\\system32\\DRIVERS\\usbprint.sys [2004-08-03 25856]
S3 usbscan;Pilote de scanneur USB; C:\\WINDOWS\\system32\\DRIVERS\\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;Pilote de stockage de masse USB; C:\\WINDOWS\\system32\\DRIVERS\\USBSTOR.SYS [2004-08-03 26496]
S3 WSTCODEC;Codec Teletext standard; C:\\WINDOWS\\system32\\DRIVERS\\WSTCODEC.SYS [2004-08-03 19328]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 FTRTSVC;France Telecom Routing Table Service; C:\\PROGRA~1\\FICHIE~1\\France Telecom\\Shared Modules\\FTRTSVC\\0\\FTRTSVC.exe [2007-12-11 65536]
R2 NOD32krn;NOD32 Kernel Service; C:\\Program Files\\Eset\\nod32krn.exe [2009-06-29 552064]
R2 SeaPort;SeaPort; C:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaPort\\SeaPort.exe [2009-05-19 240512]
S2 LVSrvLauncher;LVSrvLauncher; C:\\Program Files\\Fichiers communs\\LogiShrd\\SrvLnch\\SrvLnch.exe [2007-02-06 105248]
S3 aspnet_state;ASP.NET State Service; C:\\WINDOWS\\Microsoft.NET\\Framework\\v2.0.50727\\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\\WINDOWS\\Microsoft.NET\\Framework\\v2.0.50727\\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\\WINDOWS\\Microsoft.NET\\Framework\\v3.0\\WPF\\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; c:\\WINDOWS\\Microsoft.NET\\Framework\\v3.0\\Windows Communication Foundation\\infocard.exe [2008-07-29 881664]
S3 ose;Office Source Engine; C:\\Program Files\\Fichiers communs\\Microsoft Shared\\Source Engine\\OSE.EXE [2003-07-28 89136]
S3 UMWdf;Infrastructure de pilote-mode utilisateur Windows; C:\\WINDOWS\\system32\\wdfmgr.exe [2005-01-27 38912]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\\WINDOWS\\Microsoft.NET\\Framework\\v3.0\\Windows Communication Foundation\\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------
******************************************************************************************************************************************************************************************************************************************
GMER 1.0.15.15281 -
http://www.gmer.netRootkit scan 2009-12-22 09:52:18
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\\DOCUME~1\\rose\\LOCALS~1\\Temp\\uwnyifob.sys
---- Kernel code sections - GMER 1.0.15 ----
? vufepc.sys Le fichier spécifié est introuvable. !
.rsrc C:\\WINDOWS\\system32\\drivers\\atapi.sys entry point in \".rsrc\" section [0xF848E3A4]
---- User code sections - GMER 1.0.15 ----
.text C:\\WINDOWS\\system32\\svchost.exe[96] kernel32.dll!TerminateThread 7C81CE13 1 Byte [C3]
.text C:\\WINDOWS\\system32\\svchost.exe[404] kernel32.dll!TerminateThread 7C81CE13 1 Byte [C3]
.text C:\\Program Files\\Eset\\nod32krn.exe[408] kernel32.dll!TerminateThread 7C81CE13 1 Byte [C3]
.text C:\\PROGRA~1\\FICHIE~1\\France Telecom\\Shared Modules\\AlertModule\\0\\AlertModule.exe[444] kernel32.dll!TerminateProcess 7C801E16 1 Byte [C3]
.text C:\\PROGRA~1\\FICHIE~1\\France Telecom\\Shared Modules\\AlertModule\\0\\AlertModule.exe[444] kernel32.dll!TerminateThread 7C81CE13 1 Byte [C3]
.text C:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaPort\\SeaPort.exe[464] kernel32.dll!TerminateThread 7C81CE13 1 Byte [C3]
.text C:\\WINDOWS\\system32\\csrss.exe[604] KERNEL32.dll!TerminateThread 7C81CE13 1 Byte [C3]
.text C:\\WINDOWS\\system32\\winlogon.exe[628] kernel32.dll!TerminateThread 7C81CE13 1 Byte [C3]
.text C:\\WINDOWS\\system32\\services.exe[672] kernel32.dll!TerminateThread 7C81CE13 1 Byte [C3]
.text ...
.text C:\\WINDOWS\\system32\\svchost.exe[860] ole32.dll!CoCreateInstance 774BFAC3 5 Bytes JMP 00DA000A
.text C:\\WINDOWS\\system32\\svchost.exe[936] kernel32.dll!TerminateThread 7C81CE13 1 Byte [C3]
.text C:\\WINDOWS\\System32\\svchost.exe[1072] kernel32.dll!TerminateThread 7C81CE13 1 Byte [C3]
.text C:\\WINDOWS\\system32\\svchost.exe[1148] kernel32.dll!TerminateThread 7C81CE13 1 Byte [C3]
.text C:\\DOCUME~1\\rose\\LOCALS~1\\Temp\\7zO2AE.tmp\\gmer.exe[1336] kernel32.dll!TerminateProcess 7C801E16 1 Byte [C3]
.text C:\\DOCUME~1\\rose\\LOCALS~1\\Temp\\7zO2AE.tmp\\gmer.exe[1336] kernel32.dll!TerminateThread 7C81CE13 1 Byte [C3]
.text C:\\WINDOWS\\Explorer.EXE[1484] kernel32.dll!TerminateThread 7C81CE13 1 Byte [C3]
.text C:\\WINDOWS\\system32\\spoolsv.exe[1512] kernel32.dll!TerminateThread 7C81CE13 1 Byte [C3]
.text C:\\WINDOWS\\System32\\alg.exe[1680] kernel32.dll!TerminateThread 7C81CE13 1 Byte [C3]
.text C:\\Program Files\\OrangeHSS\\systray\\systrayapp.exe[1780] kernel32.dll!TerminateProcess 7C801E16 1 Byte [C3]
.text C:\\Program Files\\OrangeHSS\\systray\\systrayapp.exe[1780] kernel32.dll!TerminateThread 7C81CE13 1 Byte [C3]
.text C:\\Program Files\\Eset\\nod32kui.exe[1840] kernel32.dll!TerminateProcess 7C801E16 1 Byte [C3]
.text C:\\Program Files\\Eset\\nod32kui.exe[1840] kernel32.dll!TerminateThread 7C81CE13 1 Byte [C3]
.text C:\\Program Files\\Brother\\Brmfcmon\\BrMfcWnd.exe[1848] kernel32.dll!TerminateProcess 7C801E16 1 Byte [C3]
.text C:\\Program Files\\Brother\\Brmfcmon\\BrMfcWnd.exe[1848] kernel32.dll!TerminateThread 7C81CE13 1 Byte [C3]
.text C:\\Documents and Settings\\rose\\bagat.exe[1912] kernel32.dll!TerminateThread 7C81CE13 1 Byte [C3]
.text C:\\Program Files\\Brother\\ControlCenter3\\brccMCtl.exe[1928] kernel32.dll!TerminateProcess 7C801E16 1 Byte [C3]
.text C:\\Program Files\\Brother\\ControlCenter3\\brccMCtl.exe[1928] kernel32.dll!TerminateThread 7C81CE13 1 Byte [C3]
.text C:\\PROGRA~1\\FICHIE~1\\France Telecom\\Shared Modules\\FTRTSVC\\0\\FTRTSVC.exe[1956] kernel32.dll!TerminateThread 7C81CE13 1 Byte [C3]
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[2024] kernel32.dll!TerminateProcess 7C801E16 1 Byte [C3]
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[2024] kernel32.dll!TerminateThread 7C81CE13 1 Byte [C3]
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[2024] WS2_32.dll!getaddrinfo 719F2A6F 5 Bytes JMP 46CAE71D C:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaNote\\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[2024] WS2_32.dll!socket 719F3B91 5 Bytes JMP 46CAE59E C:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaNote\\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[2024] WS2_32.dll!connect 719F406A 5 Bytes JMP 46CAE62A C:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaNote\\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[2024] WS2_32.dll!send 719F428A 5 Bytes JMP 46CAE9ED C:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaNote\\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[2024] WS2_32.dll!recv 719F615A 5 Bytes JMP 46CAF1C3 C:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaNote\\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\\Program Files\\Internet Explorer\\iexplore.exe[2024] WS2_32.dll!closesocket 719F9639 5 Bytes JMP 46CAEEE9 C:\\Program Files\\Microsoft\\Search Enhancement Pack\\SeaNote\\SeaNote.dll (Microsoft Search Note/Microsoft Corporation)
.text C:\\WINDOWS\\system32\\wuauclt.exe[2228] kernel32.dll!TerminateProcess 7C801E16 1 Byte [C3]
.text C:\\WINDOWS\\system32\\wuauclt.exe[2228] kernel32.dll!TerminateThread 7C81CE13 1 Byte [C3]
.text C:\\Program Files\\Windows Live\\Toolbar\\wltuser.exe[2488] kernel32.dll!TerminateProcess 7C801E16 1 Byte [C3]
.text C:\\Program Files\\Windows Live\\Toolbar\\wltuser.exe[2488] kernel32.dll!TerminateThread 7C81CE13 1 Byte [C3]
---- Devices - GMER 1.0.15 ----
AttachedDevice \\FileSystem\\Ntfs \\Ntfs amon.sys (Amon monitor/Eset )
AttachedDevice \\FileSystem\\Fastfat \\Fat amon.sys (Amon monitor/Eset )
Device -> \\Driver\\atapi \\Device\\Harddisk0\\DR0 8235E618
---- Files - GMER 1.0.15 ----
File C:\\WINDOWS\\system32\\drivers\\atapi.sys suspicious modification
---- EOF - GMER 1.0.15 ----
merci bonne journée