Bonjour,
J’ai lancé Combofix et voici le rapport:
ComboFix 08-09-24.11 - melanie 2008-09-25 13:02:43.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.33.1036.18.146 [GMT -4:00]
Lancé depuis: C:\Documents and Settings\melanie\Bureau\ComboFix.exe
- Un nouveau point de restauration a été créé
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N’EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\FBrowserAdvisor
C:\Program Files\FBrowsingAdvisor
C:\Program Files\FBrowsingAdvisor\IXPCOMEvents.xpt
C:\Program Files\FBrowsingAdvisor\Logo.png
C:\Program Files\FBrowsingAdvisor\main.db
C:\Program Files\FBrowsingAdvisor\unins000.dat
C:\Program Files\FBrowsingAdvisor\unins000.exe
C:\WINDOWS\BM9b586028.txt
C:\WINDOWS\BM9b586028.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\mcrh.tmp
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-08-25 au 2008-09-25 ))))))))))))))))))))))))))))))))))))
.
2008-09-24 18:17 . 2008-09-24 18:17 d-------- C:\VundoFix Backups
2008-09-24 18:16 . 2004-08-04 00:54 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-09-24 18:16 . 2004-08-04 00:45 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-09-23 23:28 . 2008-09-23 23:28 d–h----- C:$AVG8.VAULT$
2008-09-23 22:37 . 2008-09-23 22:39 d-------- C:\WINDOWS\system32\drivers\Avg
2008-09-23 22:37 . 2008-09-23 22:37 d-------- C:\Program Files\AVG
2008-09-23 22:37 . 2008-09-23 22:37 d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-09-23 22:37 . 2008-09-23 22:37 97,928 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-09-23 22:37 . 2008-09-23 22:37 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-09-23 02:51 . 2008-09-23 02:50 410,976 --a------ C:\WINDOWS\system32\deploytk.dll
2008-09-23 02:51 . 2008-09-23 02:50 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-09-23 02:44 . 2008-09-23 02:44 d-------- C:\Documents and Settings\melanie.housecall6.6
2008-09-23 00:00 . 2008-09-23 00:00 d-------- C:\Documents and Settings\melanie\Application Data\Malwarebytes
2008-09-22 23:59 . 2008-09-23 00:00 d-------- C:\Program Files\Malwarebytes’ Anti-Malware
2008-09-22 23:59 . 2008-09-22 23:59 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-22 23:59 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-22 23:59 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-22 23:48 . 2008-09-22 23:48 119,808 --a------ C:\WINDOWS\system32\ejqothbu.dll
2008-09-22 23:42 . 2008-09-22 23:42 90,112 --a------ C:\WINDOWS\system32\qcvydwlb.dll
2008-09-22 23:42 . 2008-09-22 23:42 90,112 --a------ C:\WINDOWS\system32\awmgfnmw.dll
2008-09-19 18:06 . 2008-09-19 18:06 d-------- C:\Program Files\Trend Micro
2008-09-18 19:07 . 2008-09-18 19:07 d-------- C:\Program Files\Kaspersky Lab
2008-09-18 19:02 . 2008-09-18 19:02 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-09-18 18:23 . 2008-09-18 18:23 90,112 --a------ C:\WINDOWS\system32\jssclxxy.dll
2008-09-17 22:59 . 2008-09-19 18:31 d-------- C:\Program Files\Spyware Terminator
2008-09-17 22:59 . 2008-09-19 17:37 d-------- C:\Documents and Settings\melanie\Application Data\Spyware Terminator
2008-09-17 22:59 . 2008-09-19 18:31 d-------- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-09-17 22:59 . 2008-09-17 22:59 141,312 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-09-17 21:29 . 2008-09-22 23:42 1,047,705 —hs---- C:\WINDOWS\system32\hhsvqwhb.ini
2008-09-17 21:16 . 2008-09-17 21:16 d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-09-17 21:13 . 2008-09-17 21:21 d-------- C:\WINDOWS\system32\CatRoot_bak
2008-09-04 18:22 . 2008-09-04 18:22 d—s---- C:\Documents and Settings\BAS\UserData
2008-09-03 20:19 . 2008-09-03 20:20 d-------- C:\Documents and Settings\BAS\Application Data\MailFrontier
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-23 06:50 --------- d-----w C:\Program Files\Java
2008-09-18 23:05 --------- d-----w C:\Program Files\Microsoft AntiSpyware
2008-09-18 01:31 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-18 01:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-18 01:17 92,259 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2008_09_17_21_13_52_small.dmp.zip
2008-09-15 16:32 512 ----a-w C:\ScanSectorLog.dat
2008-08-25 01:51 --------- d-----w C:\Program Files\Fichiers communs\Pure Networks Shared
2008-08-25 01:50 --------- d-----w C:\Program Files\Pure Networks
2008-08-25 01:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Pure Networks
2008-08-18 01:00 --------- d–h--w C:\Program Files\Zero G Registry
2008-08-18 01:00 --------- d-----w C:\Program Files\LimeWire
2008-08-17 23:44 --------- d-----w C:\Program Files\Lphant
2008-08-17 23:09 --------- d-----w C:\Documents and Settings\melanie\Application Data\Ahead
2008-08-17 22:44 --------- d-----w C:\Program Files\Fichiers communs\Ahead
2008-08-17 22:38 --------- d-----w C:\Program Files\Nero
2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-19 02:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-07 20:31 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-14 03:24 2,768 ----a-w C:\Documents and Settings\melanie\Application Data\ViewerApp.dat
2004-12-03 17:06 149 ----a-w C:\Program Files\INSTALL.LOG
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ctfmon.exe”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-05 15360]
“BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}”=“C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe” [2006-10-09 139264]
“WMPNSCFG”=“C:\Program Files\Windows Media Player\WMPNSCFG.exe” [2006-11-03 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“SynTPLpr”=“C:\Program Files\Synaptics\SynTP\SynTPLpr.exe” [2002-12-05 126976]
“SunJavaUpdateSched”=“C:\Program Files\Java\jre6\bin\jusched.exe” [2008-09-23 144792]
“NeroFilterCheck”=“C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe” [2006-01-12 155648]
“nmapp”=“C:\Program Files\Pure Networks\Network Magic\nmapp.exe” [2006-06-21 1069056]
“AVG8_TRAY”=“C:\PROGRA~1\AVG\AVG8\avgtray.exe” [2008-09-23 1235736]
“BM9b586028”=“C:\WINDOWS\system32\qcvydwlb.dll” [2008-09-22 90112]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-05 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
2003-12-16 16:49 110592 C:\WINDOWS\system32\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
“AppInit_DLLs”=bzbyui.dll,avgrsstx.dll
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gdOmúNa?
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
“gcasServ”=“C:\Program Files\Microsoft AntiSpyware\gcasServ.exe”
“HotKeysCmds”=C:\WINDOWS\system32\hkcmd.exe
“HP Component Manager”=“C:\Program Files\HP\hpcoretech\hpcmpmgr.exe”
“HP Software Update”=“c:\Program Files\HP\HP Software Update\HPWuSchd2.exe”
“IgfxTray”=C:\WINDOWS\system32\igfxtray.exe
“IPInSightLAN 01”=“C:\Program Files\Visual Networks\Visual IP InSight\Sympatico Consumer\IPClient.exe” -l
“IPInSightMonitor 01”=“C:\Program Files\Visual Networks\Visual IP InSight\Sympatico Consumer\IPMon32.exe”
“PRONoMgr.exe”=C:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
“SoundMan”=SOUNDMAN.EXE
“SynTPEnh”=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
“AntiVirusDisableNotify”=dword:00000001
“UpdatesDisableNotify”=dword:00000001
“AntiVirusOverride”=dword:00000001
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
“EnableFirewall”= 0 (0x0)
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“C:\Program Files\MSN Messenger\msnmsgr.exe”=
“C:\Program Files\MSN Messenger\livecall.exe”=
“C:\Program Files\Messenger\msmsgs.exe”=
“C:\Program Files\Lphant\eLePhantClient.exe”=
“C:\Program Files\AVG\AVG8\avgupd.exe”=
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
“67:UDP”= 67:UDP:DHCP Discovery Service
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-09-23 97928]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-23 231704]
R2 nmservice;Pure Networks Network Magic Service;C:\Program Files\Pure Networks\Network Magic\nmsrvc.exe [2006-06-21 278528]
R2 vnccom;vnccom;C:\WINDOWS\system32\Drivers\vnccom.SYS [2004-05-21 6016]
S3 PCASp50Q;PCASp50Q NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50Q.sys [2005-11-30 18304]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{f94c6cf1-e3f1-11dc-9d4d-000e35295915}]
\Shell\AutoRun\command - G:\setupSNK.exe
Newly Created Service - PROCEXP90
.
.
------- Examen supplémentaire -------
.
FireFox -: Profile - C:\Documents and Settings\melanie\Application Data\Mozilla\Firefox\Profiles\9wg877bi.default
FF -: plugin - C:\Program Files\Adobe\Acrobat 6.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\Java\jre6\bin\new_plugin\npdeploytk.dll
FF -: plugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll
.
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, www.gmer.net…
Rootkit scan 2008-09-25 13:05:11
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés …
Recherche d’éléments en démarrage automatique cachés …
Recherche de fichiers cachés …
Scan terminé avec succès
Fichiers cachés: 0
.
Heure de fin: 2008-09-25 13:07:07
ComboFix-quarantined-files.txt 2008-09-25 17:07:02
Avant-CF: 23ÿ842ÿ422ÿ784 octets libres
Après-CF: 23,833,436,160 octets libres
170 — E O F — 2008-09-11 01:21:36
Je vois que ce problème semble difficile à résoudre, je vais probablement opter pour un formatage du disque dur. À la rigueur, étant donné que tout fonctionne bien avec google chrome, j’ai juste à abandonner ie et firefox pour l’instant.
Merci beaucoup pour votre aide!