Voila j’ai tous fais.
Rapport de Combofix :
ComboFix 09-01-02.01 - gabriel 2009-01-03 22:22:04.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.1022.574 [GMT 1:00]
Lancé depuis: c:\documents and settings\gabriel.D2D39647DCF14A2\Mes documents\ComboFix.exe
- Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\outlook
c:\windows\system32\auufpdto.ini
c:\windows\system32\bglwvrsj.ini
c:\windows\system32\byhnpgkw.ini
c:\windows\system32\chywkjvg.ini
c:\windows\system32\deaojexq.ini
c:\windows\system32\dprrxgqe.ini
c:\windows\system32\drivers_wff.sys
c:\windows\system32\dttynqtv.ini
c:\windows\system32\errrnwmc.ini
c:\windows\system32\fcfbvcec.ini
c:\windows\system32\fikxpmnr.ini
c:\windows\system32\ggjlm.bak1
c:\windows\system32\ggjlm.bak2
c:\windows\system32\ggjlm.ini
c:\windows\system32\ggjlm.ini2
c:\windows\system32\ggjlm.tmp
c:\windows\system32\htoocrrw.ini
c:\windows\system32\hxorsxww.ini
c:\windows\system32\jbgljjhu.ini
c:\windows\system32\jeayfjqy.ini
c:\windows\system32\kbscrwuw.ini
c:\windows\system32\kosakqns.ini
c:\windows\system32\liddwjcr.ini
c:\windows\system32\mufkkpqv.ini
c:\windows\system32\ndomcchl.ini
c:\windows\system32\nshidfce.ini
c:\windows\system32\ogglenky.ini
c:\windows\system32\oherxwqo.ini
c:\windows\system32\opgafyob.ini
c:\windows\system32\oppvyysj.ini
c:\windows\system32\otrvtwxf.ini
c:\windows\system32\pncreect.ini
c:\windows\system32\qginansx.ini
c:\windows\system32\qqtnfdsw.ini
c:\windows\system32\rbcmtwnr.ini
c:\windows\system32\rrwdtvyd.ini
c:\windows\system32\taskkill.exe
c:\windows\system32\ttayxsmc.ini
c:\windows\system32\vpamclgn.ini
c:\windows\system32\vpfbnwhs.ini
c:\windows\system32\vqqhiufq.ini
c:\windows\system32\wegpicpd.ini
c:\windows\system32\xbadd.bak2
c:\windows\system32\xbadd.ini
c:\windows\system32\xbadd.ini2
c:\windows\system32\xbadd.tmp
c:\windows\system32\xcteuast.ini
c:\windows\system32\xrwrrsqt.ini
c:\windows\system32\xxculmrn.ini
c:\windows\system32\yufmwqfr.ini
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CORE
-------\Legacy_WASFSD
-------\Legacy__WFF
-------\Service__wff
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-03 au 2009-01-03 ))))))))))))))))))))))))))))))))))))
.
2009-01-03 20:31 . 2009-01-03 22:05 d-------- c:\program files\Navilog1
2009-01-03 18:52 . 2009-01-03 18:52 d-------- c:\program files\Malwarebytes’ Anti-Malware
2009-01-03 18:52 . 2009-01-03 18:52 d-------- c:\documents and settings\gabriel.D2D39647DCF14A2\Application Data\Malwarebytes
2009-01-03 18:52 . 2009-01-03 18:52 d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-03 18:52 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-03 18:52 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-03 00:53 . 2009-01-03 00:53 d-------- c:\program files\CCleaner
2009-01-02 18:43 . 2009-01-02 18:43 d-------- c:\program files\Winamp
2009-01-02 18:43 . 2009-01-02 18:53 d-------- c:\documents and settings\gabriel.D2D39647DCF14A2\Application Data\Winamp
2009-01-02 00:45 . 2007-03-08 00:51 129,784 --------- c:\windows\system32\pxafs.dll
2009-01-02 00:45 . 2007-03-08 00:51 9,464 --------- c:\windows\system32\drivers\cdralw2k.sys
2009-01-02 00:45 . 2007-03-08 00:51 9,336 --------- c:\windows\system32\drivers\cdr4_xp.sys
2008-12-31 00:59 . 2009-01-01 16:13 d-------- c:\documents and settings\gabriel.D2D39647DCF14A2\Application Data\gtk-2.0
2008-12-31 00:59 . 2008-12-31 00:59 d-------- c:\documents and settings\gabriel.D2D39647DCF14A2.thumbnails
2008-12-31 00:57 . 2009-01-02 02:25 d-------- c:\documents and settings\gabriel.D2D39647DCF14A2.gimp-2.6
2008-12-31 00:57 . 2008-12-31 00:57 d-------- c:\documents and settings\gabriel.D2D39647DCF14A2.gegl-0.0
2008-12-31 00:56 . 2008-12-31 00:56 d-------- c:\program files\GIMP-2.0
2008-12-26 02:07 . 2008-12-28 23:43 54,156 --ah----- c:\windows\QTFont.qfn
2008-12-26 02:07 . 2008-12-26 02:07 1,409 --a------ c:\windows\QTFont.for
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-03 21:27 --------- d-----w c:\program files\Wanadoo
2009-01-03 00:02 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-02 01:08 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-01-01 22:55 --------- d-----w c:\documents and settings\gabriel.D2D39647DCF14A2\Application Data\uTorrent
2008-12-22 21:43 --------- d-----w c:\program files\eMule
2008-12-20 18:00 --------- d-----w c:\program files\Slayers Online
2008-12-20 17:47 --------- d-----w c:\documents and settings\All Users\Application Data\Messenger Plus!
2008-12-17 18:47 --------- d-----w c:\documents and settings\gabriel.D2D39647DCF14A2\Application Data\mIRC
2008-12-17 18:44 --------- d-----w c:\program files\mIRC
2008-12-17 17:21 --------- d-----w c:\program files\Java
2008-12-14 01:51 --------- d-----w c:\program files\Free Video Converter
2008-12-14 01:23 2,782 ----a-w c:\documents and settings\gabriel.D2D39647DCF14A2\Application Data\wklnhst.dat
2008-11-25 09:40 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2008-11-24 02:06 43,872 ------w c:\windows\system32\drivers\PxHelp20.sys
2008-11-12 20:37 --------- d-----w c:\program files\MSXML 4.0
2008-11-10 14:34 --------- d-----w c:\program files\Incomplete
2008-11-10 14:24 --------- d-----w c:\program files\Lavasoft
2008-11-10 14:23 --------- d-----w c:\documents and settings\gabriel.D2D39647DCF14A2\Application Data\LimeWire
2007-04-22 15:42 57,512 ----a-w c:\documents and settings\gabriel.D2D39647DCF14A2\Application Data\GDIPFONTCACHEV1.DAT
2005-11-29 17:28 0 ----a-w c:\documents and settings\christiane.D2D39647DCF14A2\Application Data\wklnhst.dat
2008-09-19 17:56 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008091920080920\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“WooCnxMon”=“00” [X]
“MsnMsgr”=“c:\program files\Windows Live\Messenger\msnmsgr.exe” [2007-10-18 5724184]
“MSMSGS”=“c:\program files\Messenger\msmsgs.exe” [2008-04-14 1695232]
“swg”=“c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [2007-06-23 68856]
“SpybotSD TeaTimer”=“c:\program files\Spybot - Search & Destroy\TeaTimer.exe” [2008-09-16 1833296]
“ctfmon.exe”=“c:\windows\system32\ctfmon.exe” [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“SynTPLpr”=“c:\program files\Synaptics\SynTP\SynTPLpr.exe” [2004-08-17 102400]
“SynTPEnh”=“c:\program files\Synaptics\SynTP\SynTPEnh.exe” [2004-08-17 684032]
“NvCplDaemon”=“c:\windows\system32\NvCpl.dll” [2004-11-10 4636672]
“Keyboard Manager Utility”=“c:\program files\Keyboard Manager\Manager Utility\KeyboardManager.exe” [2004-12-28 2924544]
“RemoteControl”=“c:\program files\CyberLink\PowerDVD\PDVDServ.exe” [2004-07-15 32768]
“PCMService”=“c:\program files\CyberLink\PowerCinema\PCMService.exe” [2005-03-28 127118]
“WOOWATCH”=“c:\progra~1\Wanadoo\Watch.exe” [2005-01-27 20480]
“WOOTASKBARICON”=“c:\progra~1\Wanadoo\GestMaj.exe” [2005-01-27 32768]
“DTVRemote”=“c:\program files\DTV\RemoteControl.exe” [2005-06-10 40960]
“vmtalk”=“c:\program files\Fichiers communs\Talkway\vmtalk.exe” [2003-07-24 61440]
“iTunesHelper”=“c:\program files\iTunes\iTunesHelper.exe” [2005-10-18 278528]
“QuickTime Task”=“c:\program files\QuickTime\qttask.exe” [2005-12-18 155648]
“avast!”=“c:\progra~1\ALWILS~1\Avast4\ashDisp.exe” [2008-11-26 81000]
“mmtask”=“c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe” [2006-01-17 53248]
“IMJPMIG8.1”=“c:\windows\IME\imjp8_1\IMJPMIG.EXE” [2004-08-05 208952]
“MSPY2002”=“c:\windows\system32\IME\PINTLGNT\ImScInst.exe” [2004-08-05 59392]
“PHIME2002ASync”=“c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE” [2004-08-05 455168]
“PHIME2002A”=“c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE” [2004-08-05 455168]
“TkBellExe”=“c:\program files\Fichiers communs\Real\Update_OB\realsched.exe” [2008-02-23 185896]
“SunJavaUpdateSched”=“c:\program files\Java\jre6\bin\jusched.exe” [2008-11-10 136600]
“SMSERIAL”=“sm56hlpr.exe” [2004-10-21 c:\windows\sm56hlpr.exe]
“nwiz”=“nwiz.exe” [2004-11-10 c:\windows\system32\nwiz.exe]
“SoundMan”=“SOUNDMAN.EXE” [2004-11-02 c:\windows\SOUNDMAN.EXE]
“AlcWzrd”=“ALCWZRD.EXE” [2004-11-29 c:\windows\ALCWZRD.EXE]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“c:\windows\system32\CTFMON.EXE” [2008-04-14 15360]
c:\documents and settings\All Users\Menu D?marrer\Programmes\D?marrage
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
“msacm.clmp3enc”= c:\progra~1\CYBERL~1\Power2Go\CLMP3Enc.ACM
“vidc.div3”= DivXc32.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *[u]0[/u]lsdelete
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“c:\Program Files\CyberLink\PowerCinema\PowerCinema.exe”=
“c:\Program Files\iTunes\iTunes.exe”=
“c:\Program Files\eMule\emule.exe”=
“%windir%\Network Diagnostic\xpnetdiag.exe”=
“c:\WINDOWS\system32\dpvsetup.exe”=
“c:\Program Files\VideoLAN\VLC\vlc.exe”=
“c:\Program Files\uTorrent\uTorrent.exe”=
“c:\Program Files\mIRC\mirc.exe”=
“c:\Program Files\Windows Live\Messenger\msnmsgr.exe”=
“c:\Program Files\Windows Live\Messenger\livecall.exe”=
“c:\Program Files\Skype\Phone\Skype.exe”=
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
“10140:TCP”= 10140:TCP:rox
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-03-30 111184]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-03-30 20560]
S1 M9207;USB 2.0 DVB-T Hybrid TV BOX;c:\windows\system32\drivers\M9207BDA.sys [2005-11-29 26880]
S3 AVHybrid;AVHybrid service;c:\windows\system32\drivers\AVHybrid.sys [2005-09-05 988672]
S3 LVHybrid;LVHybrid service;c:\windows\system32\drivers\LVHybrid.sys [2005-04-27 1000064]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2{e57e10da-d687-11dd-8697-0013ce5bde39}]
\Shell\AutoRun\command - E:\Launch.exe
.
-
-
-
- ORPHELINS SUPPRIMES - - - -
BHO-{21DA6B32-E5D3-4A99-8114-B7131991FDF7} - (no file)
BHO-{CF7A11A0-C37A-4F86-A937-7BD5411C8DC6} - (no file)
HKCU-Run-Power2GoExpress - (no file)
Notify-ddabx - c:\windows\system32\ddabx.dll
Notify-mljgg - c:\windows\system32\mljgg.dll
.
------- Examen supplémentaire -------
.
uStart Page = www.jeuxvideo.com…
uInternet Settings,ProxyServer = 10.255.1.23:3128
uSearchURL,(Default) = g.msn.fr…
IE: Télécharger avec &BitSpirit - c:\program files\BitSpirit\bsurl.htm
O16 -: Microsoft XML Parser for Java - [c:\windows\Java\classes\xmldso.cab…](file://c:\windows\Java\classes\xmldso.cab)
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, www.gmer.net…
Rootkit scan 2009-01-03 22:27:18
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés …
Recherche d’éléments en démarrage automatique cachés …
Recherche de fichiers cachés …
Scan terminé avec succès
Fichiers cachés: 0
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
c:\program files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
c:\program files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
c:\windows\system32\FTRTSVC.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\progra~1\Wanadoo\TaskBarIcon.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\Windows Live\Messenger\usnsvc.exe
.
.
Heure de fin: 2009-01-03 22:33:28 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-01-03 21:33:25
Avant-CF: 3 086 860 288 octets libres
Après-CF: 3,171,713,024 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[Boot Loader]
Timeout=2
Default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[Operating Systems]
c:\cmdcons\BOOTSECT.DAT=“Microsoft Windows Recovery Console” /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS=“Microsoft Windows XP dition familiale” /noexecute=optin /fastdetect
239 — E O F — 2008-12-18 22:36:21