الموضوع: مشكل بالجهاز...
عرض مشاركة واحدة
قديم 24-03-2009, 15:51   #8
معلومات العضو
كلثوم كويم
نجمة الأمل
الصورة الرمزية كلثوم كويم







كلثوم كويم غير متصل

آخر مواضيعي

افتراضي

التقرير

كود:
ComboFix 09-03-23.01 - kawim 2009-03-24 15:27:18.1 - NTFSx86 MINIMAL
Microsoft Windows XP Professionnel  5.1.2600.2.1252.1.1036.18.223.141 [GMT 0:00]
Lancé depuis: c:\documents and settings\kawim\Bureau\ComboFix.exe
AV: AntiVir Desktop *On-access scanning enabled* (Updated)

AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.

(((((((((((((((((((((((((((((   Fichiers créés du 2009-02-24 au 2009-03-24  ))))))))))))))))))))))))))))))))))))
.

2009-03-24 10:12 . 2009-03-24 10:12	<REP>	d--------	c:\program files\MSXML 4.0
2009-03-23 16:29 . 2009-03-23 23:01	<REP>	d--------	c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-03-23 16:22 . 2009-03-23 16:22	<REP>	d--------	c:\program files\WinASO
2009-03-23 16:16 . 2009-03-23 16:16	<REP>	d--------	c:\program files\Ares
2009-03-23 16:07 . 2009-03-23 16:07	<REP>	d--------	c:\program files\Messenger Plus! Live
2009-03-23 16:07 . 2009-03-23 16:07	<REP>	d--------	c:\program files\Circle Developement
2009-03-23 15:56 . 2009-03-23 15:59	<REP>	d--------	c:\program files\Free Window Sweeper
2009-03-23 14:48 . 2009-03-24 12:11	<REP>	d--------	c:\windows\system32\CatRoot_bak
2009-03-23 14:35 . 2008-08-14 13:44	2,182,400	-----c---	c:\windows\system32\dllcache\ntoskrnl.exe
2009-03-23 14:35 . 2008-08-14 13:44	2,138,112	-----c---	c:\windows\system32\dllcache\ntkrnlmp.exe
2009-03-23 14:35 . 2008-08-14 13:44	2,059,776	-----c---	c:\windows\system32\dllcache\ntkrnlpa.exe
2009-03-23 14:35 . 2008-08-14 13:44	2,017,792	-----c---	c:\windows\system32\dllcache\ntkrpamp.exe
2009-03-23 14:34 . 2008-10-24 11:10	453,632	-----c---	c:\windows\system32\dllcache\mrxsmb.sys
2009-03-23 14:10 . 2009-03-24 10:19	<REP>	d--h-----	c:\windows\$hf_mig$
2009-03-23 14:10 . 2005-02-25 03:35	22,752	--a------	c:\windows\system32\spupdsvc.exe
2009-03-22 13:37 . 2009-03-22 13:37	<REP>	d--------	c:\program files\Atomic Alarm Clock
2009-03-22 13:23 . 2009-03-22 13:23	<REP>	d--------	c:\windows\Sun
2009-03-22 13:22 . 2009-03-22 13:21	410,984	--a------	c:\windows\system32\deploytk.dll
2009-03-22 13:22 . 2009-03-22 13:21	73,728	--a------	c:\windows\system32\javacpl.cpl
2009-03-22 13:21 . 2009-03-22 13:21	<REP>	d--------	c:\program files\Java
2009-03-22 13:11 . 2009-03-22 13:11	<REP>	d--------	c:\program files\Fichiers communs\Adobe
2009-03-22 13:00 . 2009-03-22 13:00	<REP>	d--------	c:\program files\Eazel-FR
2009-03-22 13:00 . 2009-03-22 13:00	<REP>	d--------	c:\program files\Conduit
2009-03-22 11:00 . 2009-03-22 11:00	<REP>	d--------	c:\program files\ADSL Autoconnect
2009-03-21 20:31 . 2009-03-21 20:31	<REP>	d---s----	c:\documents and settings\kawim\UserData
2009-03-21 20:18 . 2009-03-21 20:18	64,868	--a------	c:\windows\BricoPackUninst.cmd
2009-03-21 20:18 . 2009-03-21 20:18	268	--ah-----	C:\sqmdata01.sqm
2009-03-21 20:18 . 2009-03-21 20:18	244	--ah-----	C:\sqmnoopt01.sqm
2009-03-21 20:17 . 2009-03-21 20:17	2,359,350	--a------	c:\windows\BricoPack Wallpaper.bmp
2009-03-21 20:13 . 2009-03-21 20:18	5,997	--a------	c:\windows\BricoPackFoldersDelete.cmd
2009-03-21 19:58 . 2009-03-21 20:08	<REP>	d--------	c:\windows\BricoPacks
2009-03-21 19:42 . 2009-03-21 19:42	<REP>	d--------	c:\program files\LG Electronics
2009-03-21 19:42 . 2009-03-21 19:42	<REP>	d--------	c:\documents and settings\All Users\Application Data\InstallShield
2009-03-21 19:42 . 2007-08-28 15:17	21,632	--a------	c:\windows\system32\drivers\lgevdomodem.sys
2009-03-21 19:42 . 2007-08-28 15:17	19,840	--a------	c:\windows\system32\drivers\lgevdodiag.sys
2009-03-21 19:42 . 2007-08-28 15:17	19,840	--a------	c:\windows\system32\drivers\lgevdoatc.sys
2009-03-21 19:42 . 2007-08-28 15:17	12,800	--a------	c:\windows\system32\drivers\lgevdobus.sys
2009-03-21 19:17 . 2009-03-21 19:17	<REP>	d--------	c:\program files\Avira
2009-03-21 19:17 . 2009-03-21 19:17	<REP>	d--------	c:\documents and settings\All Users\Application Data\Avira
2009-03-21 19:11 . 2009-03-21 19:11	268	--ah-----	C:\sqmdata00.sqm
2009-03-21 19:11 . 2009-03-21 19:11	244	--ah-----	C:\sqmnoopt00.sqm
2009-03-21 19:00 . 2008-01-24 16:36	4,127,488	-ra------	c:\windows\system32\drivers\alcxwdm.sys
2009-03-21 18:59 . 2009-03-21 19:00	<REP>	d--------	c:\program files\Realtek AC97
2009-03-21 18:59 . 2006-11-17 05:40	18,804,736	--a------	c:\windows\system32\alsndmgr.cpl
2009-03-21 18:59 . 2006-12-08 15:20	10,528,768	--a------	c:\windows\system32\RTLCPL.exe
2009-03-21 18:59 . 2007-04-16 15:28	577,536	--a------	c:\windows\soundman.exe
2009-03-21 18:59 . 2006-07-31 11:19	315,392	--a------	c:\windows\alcupd.exe
2009-03-21 18:59 . 2006-07-31 11:27	217,088	--a------	c:\windows\Alcrmv.exe
2009-03-21 18:59 . 2006-10-18 02:53	147,456	--a------	c:\windows\system32\RtlCPAPI.dll
2009-03-21 18:59 . 2002-02-05 13:54	141,016	--a------	c:\windows\system32\alsndmgr.wav
2009-03-21 18:56 . 2009-03-23 23:32	<REP>	d--------	c:\documents and settings\kawim\Contacts
2009-03-21 18:54 . 2009-03-21 19:03	<REP>	d--------	c:\windows\SxsCaPendDel
2009-03-21 18:46 . 2009-02-13 11:31	55,640	--a------	c:\windows\system32\drivers\avgntflt.sys

.
((((((((((((((((((((((((((((((((((   Compte-rendu de Find3M   ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-21 20:18	219,648	----a-w	c:\windows\system32\uxtheme.dll
2009-03-21 19:42	---------	d--h--w	c:\program files\InstallShield Installation Information
2009-03-21 19:42	---------	d-----w	c:\program files\Fichiers communs\InstallShield
2009-03-21 17:46	---------	d-----w	c:\program files\Menara
2009-03-21 17:38	---------	d-----w	c:\program files\Windows Live
2009-03-21 17:34	---------	d-----w	c:\documents and settings\kawim\Application Data\ESET
2009-03-21 17:31	---------	d-----w	c:\documents and settings\All Users\Application Data\ESET
2009-03-21 17:17	---------	d-----w	c:\program files\microsoft frontpage
2009-03-21 17:13	---------	d-----w	c:\program files\Services en ligne
2009-02-09 14:17	1,846,400	----a-w	c:\windows\system32\win32k.sys
.

------- Sigcheck -------

2008-04-14 02:34  14336  e4bdf223cd75478bf44567b4d5c2634d	c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\svchost.exe
2004-08-04 04:55  14336  1bd6c2f707a275cb7c16fd99fe0f31ca	c:\windows\system32\svchost.exe
2004-08-04 04:55  14336  1bd6c2f707a275cb7c16fd99fe0f31ca	c:\windows\system32\dllcache\svchost.exe

2008-04-14 02:33  579584  e853f84d3ce2faa2a802e33cf89ac023	c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\user32.dll
2004-08-04 04:54  578048  e46fb493e3b33704f0715020cf52106b	c:\windows\system32\user32.dll
2004-08-04 04:54  578048  e46fb493e3b33704f0715020cf52106b	c:\windows\system32\dllcache\user32.dll

2008-04-14 02:33  82432  fb836f9e62d82904c983ad21296a5d9c	c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\ws2_32.dll
2004-08-04 04:54  82944  bc41f51a39d3b255805fdb759b7814ae	c:\windows\system32\ws2_32.dll
2004-08-04 04:54  82944  bc41f51a39d3b255805fdb759b7814ae	c:\windows\system32\dllcache\ws2_32.dll

2008-10-16 10:38  663552  4bad064ed3fb5008af94d427dd77fddd	c:\windows\SoftwareDistribution\Download\0b3ac415e34ab665ed966c5d247670be\SP2GDR\wininet.dll
2008-10-16 10:23  671744  f9ae6dbb4ec5b4d1a82bf2f0cb7ee200	c:\windows\SoftwareDistribution\Download\0b3ac415e34ab665ed966c5d247670be\SP2QFE\wininet.dll
2008-10-16 01:01  670208  05033943ff61abd13b93c00337d04e92	c:\windows\SoftwareDistribution\Download\0b3ac415e34ab665ed966c5d247670be\SP3GDR\wininet.dll
2008-10-16 01:04  671232  1c6e9fdab1f4cb983a39efba6f131acc	c:\windows\SoftwareDistribution\Download\0b3ac415e34ab665ed966c5d247670be\SP3QFE\wininet.dll
2008-04-14 02:33  670208  4a6e04ea20f48d750d9bfed8600d516b	c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\wininet.dll
2004-08-04 04:54  694784  f6ad4c0f992b3b51c044ad74d9e2e854	c:\windows\system32\wininet.dll
2004-08-04 04:54  694784  f6ad4c0f992b3b51c044ad74d9e2e854	c:\windows\system32\dllcache\wininet.dll

2008-04-14 02:34  512000  dd73d6b9f6b4cb630cf35b438b540174	c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\winlogon.exe
2004-08-04 04:55  506368  d2de785aeab0bb8ca4c14a8a199dbe4e	c:\windows\system32\winlogon.exe
2004-08-04 04:55  506368  d2de785aeab0bb8ca4c14a8a199dbe4e	c:\windows\system32\dllcache\winlogon.exe

2008-04-13 19:20  182656  1df7f42665c94b825322fae71721130d	c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\ndis.sys
2004-08-04 03:14  182912  558635d3af1c7546d26067d5d9b6959e	c:\windows\system32\dllcache\ndis.sys
2004-08-04 03:14  182912  558635d3af1c7546d26067d5d9b6959e	c:\windows\system32\drivers\ndis.sys

2008-04-13 18:53  36608  3bb22519a194418d5fec05d800a19ad0	c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\ip6fw.sys
2004-08-04 03:00  29056  4448006b6bc60e6c027932cfc38d6855	c:\windows\system32\dllcache\ip6fw.sys
2004-08-04 03:00  29056  4448006b6bc60e6c027932cfc38d6855	c:\windows\system32\drivers\ip6fw.sys

2004-08-04 04:54  978432  9f3b76c8cf787449a47f05abab4e13e6	c:\windows\explorer.exe
2008-04-14 02:34  1037824  f2317622d29f9ff0f88aeecd5f60f0dd	c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\explorer.exe
2004-08-04 04:54  978432  9f3b76c8cf787449a47f05abab4e13e6	c:\windows\system32\dllcache\explorer.exe

2008-04-14 02:34  109056  54cb50058851d95e56ec70d09f70857f	c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\services.exe
2004-08-04 04:55  108544  732e0b1abaace15d80ec19056b0a2af9	c:\windows\system32\services.exe
2004-08-04 04:55  108544  732e0b1abaace15d80ec19056b0a2af9	c:\windows\system32\dllcache\services.exe

2008-04-14 02:34  13312  91e6024d6d4dcdecdb36c43ecf9bbecb	c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\lsass.exe
2004-08-04 04:54  13312  9f3744a5c6f49291a7a685040a013399	c:\windows\system32\lsass.exe
2004-08-04 04:54  13312  9f3744a5c6f49291a7a685040a013399	c:\windows\system32\dllcache\lsass.exe

2008-04-14 02:33  15360  59dc5bb82e4c8e0b3eadcfdbc44ba6e4	c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\ctfmon.exe
2004-08-04 04:54  15360  5584247b568c2e53934873f4b655fe6a	c:\windows\system32\ctfmon.exe
2004-08-04 04:54  15360  5584247b568c2e53934873f4b655fe6a	c:\windows\system32\dllcache\ctfmon.exe

2008-04-14 02:34  57856  460e4ce148bd07218da0b6a3d31885a9	c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\spoolsv.exe
2004-08-04 04:55  57856  b4ef928e4fad79364a80acba6d999934	c:\windows\system32\spoolsv.exe
2004-08-04 04:55  57856  b4ef928e4fad79364a80acba6d999934	c:\windows\system32\dllcache\spoolsv.exe

2008-04-14 02:34  112640  7e3defe771cb451b0ff630bfa435417e	c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\wuauclt.exe
2008-10-16 14:09  66584  2275f45e257d46e6500558b2930cb9a4	c:\windows\system32\wuauclt.exe
2008-10-16 14:09  66584  2275f45e257d46e6500558b2930cb9a4	c:\windows\system32\dllcache\wuauclt.exe

2008-04-14 02:34  26624  e74ddb12188c2ff57a78624dbf7332fc	c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\userinit.exe
2004-08-04 04:55  25088  d6d65ea32b190401b57edb6706f29669	c:\windows\system32\userinit.exe
2004-08-04 04:55  25088  d6d65ea32b190401b57edb6706f29669	c:\windows\system32\dllcache\userinit.exe

2008-04-14 02:33  297984  710bc85a8c22626ee094439e3ea0d38c	c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\termsrv.dll
2004-08-04 04:54  297984  7d521b8cf926459e270d18c559323815	c:\windows\system32\termsrv.dll
2004-08-04 04:54  297984  7d521b8cf926459e270d18c559323815	c:\windows\system32\dllcache\termsrv.dll

2008-04-14 02:33  1054720  3ac8886dfa5ab641417df4d3b7f5512e	c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\kernel32.dll
2004-08-04 04:54  1048576  7830e20c74611281b1bdae5888cd50f5	c:\windows\system32\kernel32.dll
2004-08-04 04:54  1048576  7830e20c74611281b1bdae5888cd50f5	c:\windows\system32\dllcache\kernel32.dll

2008-04-14 02:33  17408  9f2c862e39bf8e8fc51c3f6a6bceb415	c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\powrprof.dll
2004-08-04 04:54  17408  b02e4ddbe0e98f42f3b61292ddb3a104	c:\windows\system32\powrprof.dll
2004-08-04 04:54  17408  b02e4ddbe0e98f42f3b61292ddb3a104	c:\windows\system32\dllcache\powrprof.dll

2008-04-14 02:33  110080  0469b73db32e5520f342c5e163aa3cca	c:\windows\SoftwareDistribution\Download\51f93922a72f4cba24d116598e161b49\imm32.dll
2004-08-04 04:54  110080  39ee5faf56260ebb8d77a08f525ebbb4	c:\windows\system32\imm32.dll
2004-08-04 04:54  110080  39ee5faf56260ebb8d77a08f525ebbb4	c:\windows\system32\dllcache\imm32.dll
.
(((((((((((((((((((((((((((((((((   Points de chargement Reg   ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés 
REGEDIT4

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}"= "c:\program files\Eazel-FR\tbEaze.dll" [2009-02-16 1882136]

[HKEY_CLASSES_ROOT\clsid\{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}]
2009-02-16 15:44	1882136	--a------	c:\program files\Eazel-FR\tbEaze.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}"= "c:\program files\Eazel-FR\tbEaze.dll" [2009-02-16 1882136]

[HKEY_CLASSES_ROOT\clsid\{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{A8F9752D-E2B8-4E7A-86B5-499F4330E2FE}"= "c:\program files\Eazel-FR\tbEaze.dll" [2009-02-16 1882136]

[HKEY_CLASSES_ROOT\clsid\{a8f9752d-e2b8-4e7a-86b5-499f4330e2fe}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"UMService"="c:\program files\LG Electronics\Modem USB LG Electronics\UMAService.exe" [2008-05-09 28672]
"SkinClock"="c:\program files\Atomic Alarm Clock\AtomicAlarmClock.exe" [2007-10-31 1707008]
"ares"="c:\program files\Ares\Ares.exe" [2008-11-23 880640]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-22 148888]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 c:\windows\soundman.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

c:\documents and settings\kawim\Menu D‚marrer\Programmes\D‚marrage\
RocketDock.lnk - c:\windows\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-18 630784]

c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
DSLMON.lnk - c:\program files\Menara\dslmon.exe [2009-03-21 839680]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=

S2 ADSLAutoconnect;ADSLAutoconnect;c:\program files\ADSL Autoconnect\ADSL Autoconnect.exe [2009-03-22 446464]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-03-21 108289]
S2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);c:\windows\system32\drivers\e4ldr.sys [2009-03-21 63555]
S3 e4usbaw;USB ADSL2 WAN Adapter;c:\windows\system32\drivers\e4usbaw.sys [2009-03-21 114616]
S3 UsbEvdoAtc;LGE EVDO USB Serial Port;c:\windows\system32\drivers\lgevdoatc.sys [2009-03-21 19840]
S3 usbevdobus;LGE EVDO Composite USB Device;c:\windows\system32\drivers\lgevdobus.sys [2009-03-21 12800]
S3 UsbEvdoDiag;LGE EVDO USB Serial DM Port;c:\windows\system32\drivers\lgevdodiag.sys [2009-03-21 19840]
S3 USBEVDOModem;LGE EVDO USB Modem;c:\windows\system32\drivers\lgevdomodem.sys [2009-03-21 21632]

--- Autres Services/Pilotes en mémoire ---

*NewlyCreated* - IKANLOADER2
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = hxxp://www.menara.ma/
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-24 15:29:48
Windows 5.1.2600 Service Pack 2 NTFS

Recherche de processus cachés ... 

Recherche d'éléments en démarrage automatique cachés ... 

Recherche de fichiers cachés ... 

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************
.
Heure de fin: 2009-03-24 15:31:51
ComboFix-quarantined-files.txt  2009-03-24 15:31:49

Avant-CF: 16****256****856****064 octets libres
Après-CF: 16,437,088,256 octets libres

205	--- E O F ---	2009-03-23 14:18:11



التوقيع


تعلمت أن أمسح بمنديل الأمل
دمعــــة اليـــــــأس،،
وأن أسخر من الزمــــن
بآبـتســــامـــة..

^_^