Voici le rapport apres avoir retrouver mon internet.
ComboFix 08-08-21.02 - LAGDER 2008-08-22 23:06:54.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.431 [GMT 2:00]
Endroit: C:\Documents and Settings\LAGDER\Mes documents\ComboFix.exe
- Création d’un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N’EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\LAGDER\Local Settings\Application Data\ffxtcbe.dat
c:\Documents and Settings\LAGDER\Local Settings\Application Data\ffxtcbe_nav.dat
c:\Documents and Settings\LAGDER\Local Settings\Application Data\ffxtcbe_navps.dat
C:\WINDOWS\pi.exe
C:\WINDOWS\system32\a.exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\WINDOWS\system32\lphc3f8j0eaaa.exe
C:\WINDOWS\system32\nvs2.inf
C:\WINDOWS\system32\phc3f8j0eaaa.bmp
C:\WINDOWS\system32\tdssadw.dll
C:\WINDOWS\system32\tdssinit.dll
C:\WINDOWS\system32\tdssservers.dat
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TDSSSERV
-------\Service_tdssserv
((((((((((((((((((((((((((((( Fichiers cr??s 2008-07-22 to 2008-08-22 ))))))))))))))))))))))))))))))))))))
.
2008-08-22 22:37 . 2008-08-22 23:12 2,312 --a------ C:\WINDOWS\system32\Config.MPF
2008-08-22 22:35 . 2006-03-03 11:07 143,360 --a------ C:\WINDOWS\system32\dunzip32.dll
2008-08-22 22:34 . 2007-01-09 16:44 107,608 --a------ C:\WINDOWS\system32\drivers\Mpfp.sys
2008-08-22 22:33 . 2008-08-22 22:33 d-------- C:\Program Files\McAfee.com
2008-08-22 22:32 . 2008-08-22 22:35 d-------- C:\WINDOWS\LastGood.Tmp
2008-08-22 22:32 . 2008-08-22 22:36 d-------- C:\Program Files\McAfee
2008-08-22 22:32 . 2008-08-22 22:35 d-------- C:\Program Files\Fichiers communs\McAfee
2008-08-22 22:30 . 2008-08-22 22:37 d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2008-08-22 20:02 . 2008-08-22 23:13 d–hs---- C:\WINDOWS\system32\sysproc64
2008-08-22 20:02 . 2008-08-22 20:02 d–hs---- C:\Documents and Settings\LocalService\Application Data\sysproc64
2008-08-22 20:02 . 2008-08-22 20:02 12,288 --a------ C:\WINDOWS\system32\tdssserf.dll
2008-08-20 13:24 . 2004-08-04 00:54 21,504 --a------ C:\WINDOWS\system32\hidserv.dll
2008-08-20 13:24 . 2004-08-04 00:54 21,504 --a–c— C:\WINDOWS\system32\dllcache\hidserv.dll
2008-08-20 13:24 . 2004-08-04 00:45 14,848 --a------ C:\WINDOWS\system32\drivers\kbdhid.sys
2008-08-20 13:24 . 2004-08-04 00:45 14,848 --a–c— C:\WINDOWS\system32\dllcache\kbdhid.sys
2008-08-15 12:52 . 2008-05-01 16:31 331,776 -----c— C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-03 19:34 . 2008-08-03 19:34 121 --a------ C:\WINDOWS\Winchat.ini
2008-07-26 17:22 . 2008-07-26 17:22 d-------- C:\TIVOLA
2008-07-26 17:22 . 2008-07-26 17:22 29 --a------ C:\WINDOWS\max2f.ini
2008-07-26 17:22 . 2008-07-26 17:22 17 --a------ C:\WINDOWS\max2.ini
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-22 17:47 --------- d-----w C:\Documents and Settings\LAGDER\Application Data\Azureus
2008-08-19 17:16 --------- d-----w C:\Documents and Settings\LAGDER\Application Data\LimeWire
2008-08-16 09:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-07-18 14:10 --------- d-----w C:\Program Files\MediaCoder
2008-07-17 19:54 1,212 ----a-w C:\Documents and Settings\LAGDER\Application Data\filterclsid.dat
2008-07-17 19:51 --------- d-----w C:\Documents and Settings\LAGDER\Application Data\Samsung
2008-07-17 19:45 --------- d–h--w C:\Program Files\InstallShield Installation Information
2008-07-17 19:44 --------- d-----w C:\Program Files\Samsung
2008-06-30 10:33 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-06-30 10:23 --------- d-----w C:\Program Files\Nokia
2008-06-30 10:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2008-06-30 10:21 --------- d-----w C:\Program Files\TomTom HOME
2008-06-29 23:22 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-06-26 23:19 --------- d-----w C:\Program Files\eMule
2008-06-26 17:19 --------- d-----w C:\Program Files\Azureus
2007-12-07 13:06 734 ----a-w C:\Documents and Settings\LAGDER\Application Data\wklnhst.dat
2006-08-06 14:34 278,528 -c–a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note les ?l?ments vides & les ?l?ments initiaux l?gitimes ne sont pas list?s
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-10 14:00 15360]
“H/PC Connection Agent”=“C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE” [2005-01-19 15:18 405583]
“MSMSGS”=“C:\Program Files\Messenger\msmsgs.exe” [2004-10-13 18:24 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“NvCplDaemon”=“C:\WINDOWS\system32\NvCpl.dll” [2006-03-06 10:33 7557120]
“Apoint”=“C:\Program Files\Apoint\Apoint.exe” [2004-11-17 13:47 118784]
“ehTray”=“C:\WINDOWS\ehome\ehtray.exe” [2005-08-05 14:34 64512]
“VAIOCameraUtility”=“C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe” [2005-12-27 14:58 69632]
“SonyPowerCfg”=“C:\Program Files\Sony\VAIO Power Management\SPMgr.exe” [2005-12-13 23:43 217088]
“ISBMgr.exe”=“C:\Program Files\Sony\ISB Utility\ISBMgr.exe” [2004-02-20 15:12 32768]
“Switcher.exe”=“C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe” [2006-02-14 13:11 176128]
“PDService.exe”=“C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe” [2004-07-06 15:15 40960]
“Acrobat Assistant 7.0”=“C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe” [2005-03-03 22:47 483328]
“QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [2006-08-06 16:41 98304]
“VAIO Update 3”=“C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe” [2007-01-25 21:41 546936]
“Autoconfigurateur WiFi Neuf”=“C:\Program Files\Neuf\Kit\WiFi\9wifi.exe” [2007-02-14 13:06 181752]
“Adobe Reader Speed Launcher”=“C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe” [2006-10-23 01:48 40048]
“MskAgentexe”=“C:\Program Files\McAfee\MSK\MskAgent.exe” [2007-01-17 17:30 152144]
“Mouse Suite 98 Daemon”=“ICO.EXE” [2002-03-14 17:46 45056 C:\WINDOWS\system32\ico.exe]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-10 14:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“InstallVisualStyle”= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
“InstallTheme”= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
“Userinit”=“C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\oembios.exe,”
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2005-05-20 18:42 73728 C:\WINDOWS\system32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“VIDC.dvsd”= C:\PROGRA~1\FICHIE~1\SONYSH~1\VideoLib\sonydv.dll
“MSACM.CEGSM”= mobilev.acm
“vidc.yv12”= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
“AntiVirusDisableNotify”=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
“DisableMonitoring”=dword:00000001
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
“EnableFirewall”= 0 (0x0)
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“C:\Program Files\Adobe\Photoshop Elements 4.0\AdobePhotoshopElementsMediaServer.exe”=
“C:\Program Files\Microsoft ActiveSync\wcescomm.exe”=
“C:\Program Files\Microsoft ActiveSync\WCESMgr.exe”=
“C:\Program Files\MSN Messenger\msnmsgr.exe”=
“C:\Program Files\MSN Messenger\livecall.exe”=
“C:\Program Files\eMule\emule.exe”=
“C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtPCS.exe”=
“C:\Program Files\Messenger\msmsgs.exe”=
“C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE”=
“C:\Program Files\Azureus\Azureus.exe”=
“C:\Hager\Taloha\Apps\rteng9.exe”=
“C:\WINDOWS\system32\dpvsetup.exe”=
“C:\Program Files\Fichiers communs\McAfee\MNA\McNASvc.exe”=
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
“61323:TCP”= 61323:TCP:emule tcp
“63800:UDP”= 63800:UDP:emule UDP
“3776:UDP”= 3776:UDP:Service de Media Center Extender
“3390:TCP”= 3390:TCP:Services Media Center à distance
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 16:35]
R1 PrivateDisk;PrivateDisk;C:\WINDOWS\system32\Drivers\PrivateDiskM.sys [2004-07-06 15:07]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 16:37]
R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe [2002-12-17 18:55]
R2 NwSapAgent;Agent SAP;C:\WINDOWS\system32\svchost.exe [2004-08-10 14:00]
R2 RMSvc;Media Center Extender Resource Monitor;C:\WINDOWS\ehome\RMSvc.exe [2005-10-20 20:55]
R3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys [2005-11-19 03:13]
R3 SonyImgF;Sony Image Conversion Filter Driver;C:\WINDOWS\system32\DRIVERS\SonyImgF.sys [2005-12-27 08:22]
R3 ti21sony;ti21sony;C:\WINDOWS\system32\drivers\ti21sony.sys [2006-02-21 11:32]
S2 0049631219437233mcinstcleanup;McAfee Application Installer Cleanup (0049631219437233);C:\DOCUME~1\LAGDER\LOCALS~1\Temp[u]0[/u]04963~1.EXE C:\PROGRA~1\FICHIE~1\McAfee\INSTAL~1\cleanup.ini []
S3 Boonty Games;Boonty Games;C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe [2008-06-14 14:25]
S3 Image Converter video recording monitor for VAIO Entertainment;Image Converter video recording monitor for VAIO Entertainment;C:\Program Files\Sony\Image Converter 2\IcVzMon.exe [2005-07-14 20:10]
S3 MobileAdapter;Huawei Mobile Adapter USB Modem and USB Serial;C:\WINDOWS\system32\DRIVERS\hmvmdm.sys [2007-09-04 21:39]
S3 QWAVE;QWAVE service;C:\WINDOWS\system32\svchost.exe [2004-08-10 14:00]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE [2002-12-17 18:23]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
QWAVE REG_MULTI_SZ QWAVE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\I]
\Shell\Auto\command - I:\AdobeR.exe e
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{3817c533-2258-11dd-b937-0002c7e51f97}]
\Shell\AutoRun\command - H:\VFPcAssistant.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{407f152e-22a6-11dd-b938-0002c7e51f97}]
\Shell\AutoRun\command - H:\VFPcAssistant.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{407f152f-22a6-11dd-b938-0002c7e51f97}]
\Shell\AutoRun\command - H:\VFPcAssistant.exe
Newly Created Service - 0049631219437233MCINSTCLEANUP
.
Contenu du dossier ‘Scheduled Tasks/T?ches planifi?es’
2008-08-22 C:\WINDOWS\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-01-17 18:02]
2008-08-22 C:\WINDOWS\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-01-17 18:02]
.
-
HKCU-Run-Skype - C:\Program Files\Skype\Phone\Skype.exe
HKCU-Run-BitTorrent - C:\Program Files\BitTorrent\bittorrent.exe
HKCU-Run-updateMgr - C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
HKLM-Run-lphc3f8j0eaaa - C:\WINDOWS\system32\lphc3f8j0eaaa.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\LAGDER\Application Data\Mozilla\Firefox\Profiles\f3ovuvhs.default
FireFox -: prefs.js - SEARCH.DEFAULTURL - www.google.com…
FF -: plugin - C:\Documents and Settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_06\bin\NPJava11.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_06\bin\NPJava12.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_06\bin\NPJava13.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_06\bin\NPJava14.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_06\bin\NPJava32.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_06\bin\NPJPI150_06.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_06\bin\NPOJI610.dll
FF -: plugin - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF -: plugin - C:\Program Files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, www.gmer.net…
Rootkit scan 2008-08-22 23:14:20
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach?s …
Balayage cach? autostart entries …
Balayage des fichiers cach?s …
Scan termin? avec succ?s
Les fichiers cach?s: 0
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Fichiers communs\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
C:\PROGRA~1\FICHIE~1\McAfee\McProxy\McProxy.exe
C:\PROGRA~1\FICHIE~1\McAfee\RedirSvc\RedirSvc.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\Program Files\McAfee\MSK\msksrver.exe
C:\PROGRA~1\McAfee\MSC\mcregist.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Apoint\ApntEx.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\McAfee\MPF\MC\MpfAlert.exe
C:\WINDOWS\ehome\McrdSvc.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\WINDOWS\ehome\RMSysTry.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHSP.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosOBEX.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtProc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
.
.
Temps d’accomplissement: 2008-08-22 23:20:31 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-22 21:20:27
Pre-Run: 13,028,651,008 octets libres
Post-Run: 13,329,018,880 octets libres
251 — E O F — 2008-08-16 09:27:41
Point positif j’ai retrouver mon fond d’écran d’origine je n’ai plus le message WARNING! Spyware detected on your computer! Install an antivirus or spyware remover to clean your computer.
Warning! Win32/Adware.Virtumonde
Warning! Win32/privacyremover.M64. dans un rectangle danger.