| Refais un nouveau rapport hijackthis stp Répondre à geoffrey5 | 21 dadou, le 6 jan 2009 à 00:00:39Voici,
ComboFix 09-01-05.02 - edwige 2009-01-05 23:39:00.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.1014.568 [GMT 1:00]
Lancé depuis: c:\documents and settings\edwige\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\Downloaded Program Files\setup.inf
c:\windows\system32\404Fix.exe
c:\windows\system32\abeyugas.ini
c:\windows\system32\alanokeh.ini
c:\windows\system32\anagoval.ini
c:\windows\system32\azidadur.ini
c:\windows\system32\drivers\npf.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\ezejiweb.ini
c:\windows\system32\idulojoz.ini
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\imawowan.ini
c:\windows\system32\imobeyaw.ini
c:\windows\system32\imozuhiw.ini
c:\windows\system32\jogopamo.dll
c:\windows\system32\kugeyugu.dll
c:\windows\system32\lifemima.dll
c:\windows\system32\o4Patch.exe
c:\windows\system32\ohisimak.ini
c:\windows\system32\olapehop.ini
c:\windows\system32\ozarelak.ini
c:\windows\system32\packet.dll
c:\windows\system32\pivumedo.dll
c:\windows\system32\Process.exe
c:\windows\system32\pthreadVC.dll
c:\windows\system32\ratifuya.dll
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\toyedofi.dll
c:\windows\system32\uvizapuz.ini
c:\windows\system32\uzidigem.ini
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\vetuyija.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
c:\windows\system32\WS2Fix.exe
D:\Autorun.inf
----- BITS: Il y a peut-être des sites infectés -----
hxxp://77.74.48.105
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_NPF
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-05 au 2009-01-05 ))))))))))))))))))))))))))))))))))))
.
2009-01-05 22:00 . 2009-01-05 22:17 <REP> d-------- C:\Lop SD
2009-01-05 21:47 . 2009-01-05 21:47 <REP> d-------- c:\program files\Trend Micro
2009-01-04 01:00 . 2006-01-06 05:25 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage réseau
2009-01-04 01:00 . 2006-01-06 05:25 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage d'impression
2009-01-04 01:00 . 2006-01-06 05:25 <REP> d--h----- c:\documents and settings\Administrateur\Modèles
2009-01-04 01:00 . 2006-01-06 05:36 <REP> dr------- c:\documents and settings\Administrateur\Mes documents
2009-01-04 01:00 . 2006-01-06 05:25 <REP> dr------- c:\documents and settings\Administrateur\Menu Démarrer
2009-01-04 01:00 . 2006-01-06 05:36 <REP> dr------- c:\documents and settings\Administrateur\Favoris
2009-01-04 01:00 . 2006-01-06 05:25 <REP> d-------- c:\documents and settings\Administrateur\Bureau
2009-01-04 01:00 . 2009-01-04 01:00 <REP> d-------- c:\documents and settings\Administrateur
2009-01-02 14:41 . 2009-01-02 14:41 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-12-29 00:04 . 2007-11-14 15:18 553 --a------ c:\windows\USetup.iss
2008-12-29 00:03 . 2008-12-29 00:03 <REP> d-------- c:\program files\Realtek
2008-12-28 22:26 . 2008-12-30 23:14 <REP> d-------- C:\Downloads
2008-12-28 22:24 . 2009-01-05 23:17 <REP> d-------- c:\documents and settings\edwige\Application Data\Software Informer
2008-12-28 22:23 . 2008-12-28 22:23 <REP> d-------- c:\program files\Software Informer
2008-12-28 22:23 . 2008-12-30 23:16 <REP> d-------- c:\program files\Free Download Manager
2008-12-28 20:42 . 2008-12-30 23:19 <REP> d-------- c:\program files\ma-config.com
2008-12-28 20:42 . 2008-12-30 23:18 <REP> d-------- c:\documents and settings\All Users\Application Data\ma-config.com
2008-12-28 17:06 . 2008-12-28 17:06 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-28 17:06 . 2008-12-28 17:06 <REP> d-------- c:\documents and settings\edwige\Application Data\Malwarebytes
2008-12-28 17:06 . 2008-12-28 17:06 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-28 17:06 . 2008-12-03 19:54 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-28 17:06 . 2008-12-03 19:54 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-28 15:18 . 2008-12-28 15:18 <REP> d-------- c:\documents and settings\All Users\Application Data\Grisoft
2008-12-28 14:15 . 2008-12-28 14:15 <REP> d-------- c:\program files\Lavasoft
2008-12-28 14:15 . 2008-12-28 14:17 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-28 13:43 . 2009-01-02 14:41 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-28 13:36 . 2008-12-28 13:36 2,724 ---hs---- c:\windows\system32\nezogeju.dll
2008-12-20 19:37 . 2008-04-13 19:45 60,032 --a------ c:\windows\system32\drivers\USBAUDIO.sys
2008-12-20 19:37 . 2008-04-13 19:45 60,032 --a------ c:\windows\system32\dllcache\usbaudio.sys
2008-12-20 19:36 . 2008-12-20 19:36 <REP> d-------- c:\program files\Guillemot
2008-12-20 19:36 . 2007-03-23 14:57 118,784 --a------ c:\windows\system32\HDJAPI.dll
2008-12-20 19:36 . 2005-01-28 12:49 106,496 --a------ c:\windows\system32\GUStrLib.dll
2008-12-20 19:36 . 2007-01-09 14:47 86,016 --a------ c:\windows\system32\HRFDongle.dll
2008-12-20 19:36 . 2007-02-08 19:23 39,296 --a------ c:\windows\system32\drivers\HDJMidi.sys
2008-12-20 19:36 . 2007-03-23 14:58 23,040 --a------ c:\windows\system32\HDJSAPI.dll
2008-12-07 19:52 . 2008-12-07 19:52 <REP> d-------- c:\program files\Avira
2008-12-07 19:52 . 2008-12-07 19:52 <REP> d-------- c:\documents and settings\All Users\Application Data\Avira
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-05 22:44 --------- d-----w c:\documents and settings\edwige\Application Data\OpenOffice.org2
2009-01-05 20:28 --------- d-----w c:\documents and settings\edwige\Application Data\uTorrent
2009-01-04 00:02 --------- d-----w c:\program files\Navilog1
2009-01-02 21:07 --------- d-----w c:\documents and settings\edwige\Application Data\LimeWire
2009-01-02 20:52 --------- d-----w c:\program files\Windows Media Connect 2
2009-01-02 13:41 --------- d-----w c:\program files\Java
2008-12-28 23:03 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-28 17:11 --------- d-----w c:\program files\InternetProgram
2008-12-28 14:03 --------- d-----w c:\documents and settings\edwige\Application Data\Samsung
2008-12-28 13:14 --------- d-----w c:\program files\Fichiers communs\Wise Installation Wizard
2008-12-23 17:12 4,967,424 ----a-w c:\windows\system32\drivers\RtkHDAud.sys
2008-12-23 10:34 18,077,696 ----a-w c:\windows\RTHDCPL.EXE
2008-11-13 00:14 --------- d-----w c:\program files\MSXML 6.0
2008-10-30 16:19 7,142 ----a-w c:\documents and settings\edwige\Application Data\wklnhst.dat
2008-10-23 16:42 290,816 ----a-w c:\windows\vncutil.exe
2008-04-14 02:33 65,024 --sha-w c:\windows\system32\asycfilt.dll
2008-04-14 02:33 617,472 --sha-w c:\windows\system32\comctl32.dll
2008-04-14 02:33 1,028,096 --sha-w c:\windows\system32\mfc42.dll
2004-08-05 03:00 57,344 --sha-w c:\windows\system32\mfc42loc.dll
2008-04-14 02:33 413,696 --sha-w c:\windows\system32\msvcp60.dll
2008-04-14 02:33 343,040 --sha-w c:\windows\system32\msvcrt.dll
2004-08-05 03:00 253,952 --sha-w c:\windows\system32\msvcrt20.dll
1601-01-01 00:12 39,936 --sha-w c:\windows\system32\nunuwege.dll
1601-01-01 00:12 40,960 --sha-w c:\windows\system32\vawinaso.dll
2008-04-14 02:33 30,749 --sha-w c:\windows\system32\vbajet32.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Software Informer"="c:\program files\Software Informer\softinfo.exe" [2008-12-18 1667141]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-01-07 102491]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-01-07 692315]
"PCMService"="c:\program files\Acer\Acer Arcade\PCMService.exe" [2005-08-31 147456]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-18 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-18 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-18 114688]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2005-10-19 69632]
"EPM-DM"="c:\acer\Empowering Technology\ePower\epm-dm.exe" [2005-11-25 212992]
"Acer ePower Management"="c:\acer\Empowering Technology\ePower\Acer ePower Management.exe" [2005-11-09 3084288]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2005-12-01 458752]
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2005-09-17 52848]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\Monitor.exe" [2005-11-16 397312]
"ADMTray.exe"="c:\acer\Empowering Technology\admtray.exe" [2005-10-24 2462208]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"EPSON Stylus DX3800 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE" [2005-02-08 98304]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2006-11-12 157592]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-12-09 185896]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-02 136600]
"RTHDCPL"="RTHDCPL.EXE" [2008-12-23 c:\windows\RTHDCPL.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-09-28 443968]
c:\documents and settings\edwige\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 393216]
wkcalrem.LNK - c:\program files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe [2004-07-12 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\[u]0/ulsdelete
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Acer\\Acer Arcade\\PCMService.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Lavasoft\\Ad-Aware\\aawservice.exe"=
"c:\\Program Files\\CyberLink\\Shared Files\\RichVideo.exe"=
"c:\\Program Files\\Logitech\\Video\\LogiTray.exe"=
"c:\\Program Files\\Avira\\AntiVir PersonalEdition Classic\\avgnt.exe"=
"c:\\WINDOWS\\system32\\igfxpers.exe"=
"c:\\Acer\\Empowering Technology\\ePower\\epm-dm.exe"=
"c:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"=
"c:\\WINDOWS\\system32\\igfxtray.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\E_FATIACE.EXE"=
"c:\\Program Files\\Fichiers communs\\Microsoft Shared\\Works Shared\\WksCal.exe"=
"c:\\Program Files\\OpenOffice.org 2.4\\program\\soffice.bin"=
"c:\\Program Files\\Avira\\AntiVir PersonalEdition Classic\\sched.exe"=
R1 OsaFsLoc;OsaFsLoc;c:\windows\system32\drivers\OsaFsLoc.sys [2006-08-10 12106]
R3 NdisFilt;OSA NdisFilter Protocol;c:\windows\system32\drivers\NdisFilt.sys [2006-08-10 4392]
R4 EpmPsd;Acer EPM Power Scheme Driver;c:\windows\system32\drivers\epm-psd.sys [2006-08-10 4096]
R4 EpmShd;Acer EPM System Hardware Driver;c:\windows\system32\drivers\epm-shd.sys [2006-08-10 78208]
R4 osaio;osaio;c:\windows\system32\drivers\osaio.sys [2006-08-10 7296]
R4 osanbm;osanbm;c:\windows\system32\drivers\osanbm.sys [2006-08-10 4010]
S3 Bulk;HDJBulk;c:\windows\system32\Drivers\HDJBulk.sys --> c:\windows\system32\Drivers\HDJBulk.sys [?]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;\??\c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt --> c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt [?]
S3 HDJAsioK;HDJAsioK;c:\windows\system32\Drivers\HDJAsioK.sys --> c:\windows\system32\Drivers\HDJAsioK.sys [?]
S3 HDJMidi;Hercules DJ Console MIDI;c:\windows\system32\drivers\HDJMidi.sys [2008-12-20 39296]
S3 ZDCndis5;ZDCndis5 Protocol Driver;\??\c:\windows\system32\ZDCndis5.SYS --> c:\windows\system32\ZDCndis5.SYS [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - UBHELPER
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\setupSNK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{81e72898-2c81-11db-bc5b-00166f44482b}]
\Shell\AutoRun\command - F:\Loader.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e6697df4-8425-11dd-bf6c-00166f44482b}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ef177916-99d0-11dc-be48-00166f44482b}]
\Shell\AutoRun\command - setupSNK.exe
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-WOOKIT - c:\progra~1\WANADOO\Shell.exe
HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Fichiers communs\Nero\Lib\NMBgMonitor.exe
HKCU-Run-fsm - (no file)
HKLM-Run-NBKeyScan - c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.orange.fr
IE: &Sample Toolband Serach - c:\windows\system32\ToolBand.dll/MENUSEARCH.HTM
O16 -: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - hxxp://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection_3_1_0_4.cab
c:\windows\Downloaded Program Files\hardwaredetection.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-05 23:43:09
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(724)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Fichiers communs\Symantec Shared\ccSetMgr.exe
c:\program files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\acer\Empowering Technology\admServ.exe
c:\program files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
c:\program files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
c:\program files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
c:\program files\OpenOffice.org 2.4\program\soffice.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\OpenOffice.org 2.4\program\soffice.bin
c:\program files\Logitech\Video\FxSvr2.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
.
**************************************************************************
.
Heure de fin: 2009-01-05 23:47:40 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-01-05 22:47:31
Avant-CF: 6 680 393 728 octets libres
Après-CF: 6,868,678,656 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
288 --- E O F --- 2008-12-20 17:31:51 Répondre à dadou |
| 22 dadou, le 6 jan 2009 à 00:00:49Voici,
ComboFix 09-01-05.02 - edwige 2009-01-05 23:39:00.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.1014.568 [GMT 1:00]
Lancé depuis: c:\documents and settings\edwige\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\Downloaded Program Files\setup.inf
c:\windows\system32\404Fix.exe
c:\windows\system32\abeyugas.ini
c:\windows\system32\alanokeh.ini
c:\windows\system32\anagoval.ini
c:\windows\system32\azidadur.ini
c:\windows\system32\drivers\npf.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\ezejiweb.ini
c:\windows\system32\idulojoz.ini
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\imawowan.ini
c:\windows\system32\imobeyaw.ini
c:\windows\system32\imozuhiw.ini
c:\windows\system32\jogopamo.dll
c:\windows\system32\kugeyugu.dll
c:\windows\system32\lifemima.dll
c:\windows\system32\o4Patch.exe
c:\windows\system32\ohisimak.ini
c:\windows\system32\olapehop.ini
c:\windows\system32\ozarelak.ini
c:\windows\system32\packet.dll
c:\windows\system32\pivumedo.dll
c:\windows\system32\Process.exe
c:\windows\system32\pthreadVC.dll
c:\windows\system32\ratifuya.dll
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\toyedofi.dll
c:\windows\system32\uvizapuz.ini
c:\windows\system32\uzidigem.ini
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\vetuyija.dll
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
c:\windows\system32\WS2Fix.exe
D:\Autorun.inf
----- BITS: Il y a peut-être des sites infectés -----
hxxp://77.74.48.105
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_NPF
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-05 au 2009-01-05 ))))))))))))))))))))))))))))))))))))
.
2009-01-05 22:00 . 2009-01-05 22:17 <REP> d-------- C:\Lop SD
2009-01-05 21:47 . 2009-01-05 21:47 <REP> d-------- c:\program files\Trend Micro
2009-01-04 01:00 . 2006-01-06 05:25 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage réseau
2009-01-04 01:00 . 2006-01-06 05:25 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage d'impression
2009-01-04 01:00 . 2006-01-06 05:25 <REP> d--h----- c:\documents and settings\Administrateur\Modèles
2009-01-04 01:00 . 2006-01-06 05:36 <REP> dr------- c:\documents and settings\Administrateur\Mes documents
2009-01-04 01:00 . 2006-01-06 05:25 <REP> dr------- c:\documents and settings\Administrateur\Menu Démarrer
2009-01-04 01:00 . 2006-01-06 05:36 <REP> dr------- c:\documents and settings\Administrateur\Favoris
2009-01-04 01:00 . 2006-01-06 05:25 <REP> d-------- c:\documents and settings\Administrateur\Bureau
2009-01-04 01:00 . 2009-01-04 01:00 <REP> d-------- c:\documents and settings\Administrateur
2009-01-02 14:41 . 2009-01-02 14:41 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-12-29 00:04 . 2007-11-14 15:18 553 --a------ c:\windows\USetup.iss
2008-12-29 00:03 . 2008-12-29 00:03 <REP> d-------- c:\program files\Realtek
2008-12-28 22:26 . 2008-12-30 23:14 <REP> d-------- C:\Downloads
2008-12-28 22:24 . 2009-01-05 23:17 <REP> d-------- c:\documents and settings\edwige\Application Data\Software Informer
2008-12-28 22:23 . 2008-12-28 22:23 <REP> d-------- c:\program files\Software Informer
2008-12-28 22:23 . 2008-12-30 23:16 <REP> d-------- c:\program files\Free Download Manager
2008-12-28 20:42 . 2008-12-30 23:19 <REP> d-------- c:\program files\ma-config.com
2008-12-28 20:42 . 2008-12-30 23:18 <REP> d-------- c:\documents and settings\All Users\Application Data\ma-config.com
2008-12-28 17:06 . 2008-12-28 17:06 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-28 17:06 . 2008-12-28 17:06 <REP> d-------- c:\documents and settings\edwige\Application Data\Malwarebytes
2008-12-28 17:06 . 2008-12-28 17:06 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-28 17:06 . 2008-12-03 19:54 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-28 17:06 . 2008-12-03 19:54 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-28 15:18 . 2008-12-28 15:18 <REP> d-------- c:\documents and settings\All Users\Application Data\Grisoft
2008-12-28 14:15 . 2008-12-28 14:15 <REP> d-------- c:\program files\Lavasoft
2008-12-28 14:15 . 2008-12-28 14:17 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-28 13:43 . 2009-01-02 14:41 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-28 13:36 . 2008-12-28 13:36 2,724 ---hs---- c:\windows\system32\nezogeju.dll
2008-12-20 19:37 . 2008-04-13 19:45 60,032 --a------ c:\windows\system32\drivers\USBAUDIO.sys
2008-12-20 19:37 . 2008-04-13 19:45 60,032 --a------ c:\windows\system32\dllcache\usbaudio.sys
2008-12-20 19:36 . 2008-12-20 19:36 <REP> d-------- c:\program files\Guillemot
2008-12-20 19:36 . 2007-03-23 14:57 118,784 --a------ c:\windows\system32\HDJAPI.dll
2008-12-20 19:36 . 2005-01-28 12:49 106,496 --a------ c:\windows\system32\GUStrLib.dll
2008-12-20 19:36 . 2007-01-09 14:47 86,016 --a------ c:\windows\system32\HRFDongle.dll
2008-12-20 19:36 . 2007-02-08 19:23 39,296 --a------ c:\windows\system32\drivers\HDJMidi.sys
2008-12-20 19:36 . 2007-03-23 14:58 23,040 --a------ c:\windows\system32\HDJSAPI.dll
2008-12-07 19:52 . 2008-12-07 19:52 <REP> d-------- c:\program files\Avira
2008-12-07 19:52 . 2008-12-07 19:52 <REP> d-------- c:\documents and settings\All Users\Application Data\Avira
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-05 22:44 --------- d-----w c:\documents and settings\edwige\Application Data\OpenOffice.org2
2009-01-05 20:28 --------- d-----w c:\documents and settings\edwige\Application Data\uTorrent
2009-01-04 00:02 --------- d-----w c:\program files\Navilog1
2009-01-02 21:07 --------- d-----w c:\documents and settings\edwige\Application Data\LimeWire
2009-01-02 20:52 --------- d-----w c:\program files\Windows Media Connect 2
2009-01-02 13:41 --------- d-----w c:\program files\Java
2008-12-28 23:03 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-28 17:11 --------- d-----w c:\program files\InternetProgram
2008-12-28 14:03 --------- d-----w c:\documents and settings\edwige\Application Data\Samsung
2008-12-28 13:14 --------- d-----w c:\program files\Fichiers communs\Wise Installation Wizard
2008-12-23 17:12 4,967,424 ----a-w c:\windows\system32\drivers\RtkHDAud.sys
2008-12-23 10:34 18,077,696 ----a-w c:\windows\RTHDCPL.EXE
2008-11-13 00:14 --------- d-----w c:\program files\MSXML 6.0
2008-10-30 16:19 7,142 ----a-w c:\documents and settings\edwige\Application Data\wklnhst.dat
2008-10-23 16:42 290,816 ----a-w c:\windows\vncutil.exe
2008-04-14 02:33 65,024 --sha-w c:\windows\system32\asycfilt.dll
2008-04-14 02:33 617,472 --sha-w c:\windows\system32\comctl32.dll
2008-04-14 02:33 1,028,096 --sha-w c:\windows\system32\mfc42.dll
2004-08-05 03:00 57,344 --sha-w c:\windows\system32\mfc42loc.dll
2008-04-14 02:33 413,696 --sha-w c:\windows\system32\msvcp60.dll
2008-04-14 02:33 343,040 --sha-w c:\windows\system32\msvcrt.dll
2004-08-05 03:00 253,952 --sha-w c:\windows\system32\msvcrt20.dll
1601-01-01 00:12 39,936 --sha-w c:\windows\system32\nunuwege.dll
1601-01-01 00:12 40,960 --sha-w c:\windows\system32\vawinaso.dll
2008-04-14 02:33 30,749 --sha-w c:\windows\system32\vbajet32.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Software Informer"="c:\program files\Software Informer\softinfo.exe" [2008-12-18 1667141]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2005-01-07 102491]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2005-01-07 692315]
"PCMService"="c:\program files\Acer\Acer Arcade\PCMService.exe" [2005-08-31 147456]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-18 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-18 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-18 114688]
"eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2005-10-19 69632]
"EPM-DM"="c:\acer\Empowering Technology\ePower\epm-dm.exe" [2005-11-25 212992]
"Acer ePower Management"="c:\acer\Empowering Technology\ePower\Acer ePower Management.exe" [2005-11-09 3084288]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2005-12-01 458752]
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2005-09-17 52848]
"eRecoveryService"="c:\acer\Empowering Technology\eRecovery\Monitor.exe" [2005-11-16 397312]
"ADMTray.exe"="c:\acer\Empowering Technology\admtray.exe" [2005-10-24 2462208]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-07-19 221184]
"LogitechVideoRepair"="c:\program files\Logitech\Video\ISStart.exe" [2005-06-08 458752]
"LogitechVideoTray"="c:\program files\Logitech\Video\LogiTray.exe" [2005-06-08 217088]
"EPSON Stylus DX3800 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE" [2005-02-08 98304]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2006-11-12 157592]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-12-09 185896]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-02 136600]
"RTHDCPL"="RTHDCPL.EXE" [2008-12-23 c:\windows\RTHDCPL.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-09-28 443968]
c:\documents and settings\edwige\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 2.4.lnk - c:\program files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 393216]
wkcalrem.LNK - c:\program files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe [2004-07-12 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\[u]0/ulsdelete
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Acer\\Acer Arcade\\PCMService.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\StubInstaller.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Lavasoft\\Ad-Aware\\aawservice.exe"=
"c:\\Program Files\\CyberLink\\Shared Files\\RichVideo.exe"=
"c:\\Program Files\\Logitech\\Video\\LogiTray.exe"=
"c:\\Program Files\\Avira\\AntiVir PersonalEdition Classic\\avgnt.exe"=
"c:\\WINDOWS\\system32\\igfxpers.exe"=
"c:\\Acer\\Empowering Technology\\ePower\\epm-dm.exe"=
"c:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"=
"c:\\WINDOWS\\system32\\igfxtray.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\E_FATIACE.EXE"=
"c:\\Program Files\\Fichiers communs\\Microsoft Shared\\Works Shared\\WksCal.exe"=
"c:\\Program Files\\OpenOffice.org 2.4\\program\\soffice.bin"=
"c:\\Program Files\\Avira\\AntiVir PersonalEdition Classic\\sched.exe"=
R1 OsaFsLoc;OsaFsLoc;c:\windows\system32\drivers\OsaFsLoc.sys [2006-08-10 12106]
R3 NdisFilt;OSA NdisFilter Protocol;c:\windows\system32\drivers\NdisFilt.sys [2006-08-10 4392]
R4 EpmPsd;Acer EPM Power Scheme Driver;c:\windows\system32\drivers\epm-psd.sys [2006-08-10 4096]
R4 EpmShd;Acer EPM System Hardware Driver;c:\windows\system32\drivers\epm-shd.sys [2006-08-10 78208]
R4 osaio;osaio;c:\windows\system32\drivers\osaio.sys [2006-08-10 7296]
R4 osanbm;osanbm;c:\windows\system32\drivers\osanbm.sys [2006-08-10 4010]
S3 Bulk;HDJBulk;c:\windows\system32\Drivers\HDJBulk.sys --> c:\windows\system32\Drivers\HDJBulk.sys [?]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;\??\c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt --> c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt [?]
S3 HDJAsioK;HDJAsioK;c:\windows\system32\Drivers\HDJAsioK.sys --> c:\windows\system32\Drivers\HDJAsioK.sys [?]
S3 HDJMidi;Hercules DJ Console MIDI;c:\windows\system32\drivers\HDJMidi.sys [2008-12-20 39296]
S3 ZDCndis5;ZDCndis5 Protocol Driver;\??\c:\windows\system32\ZDCndis5.SYS --> c:\windows\system32\ZDCndis5.SYS [?]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - UBHELPER
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\setupSNK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{81e72898-2c81-11db-bc5b-00166f44482b}]
\Shell\AutoRun\command - F:\Loader.EXE
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e6697df4-8425-11dd-bf6c-00166f44482b}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ef177916-99d0-11dc-be48-00166f44482b}]
\Shell\AutoRun\command - setupSNK.exe
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-WOOKIT - c:\progra~1\WANADOO\Shell.exe
HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Fichiers communs\Nero\Lib\NMBgMonitor.exe
HKCU-Run-fsm - (no file)
HKLM-Run-NBKeyScan - c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.orange.fr
IE: &Sample Toolband Serach - c:\windows\system32\ToolBand.dll/MENUSEARCH.HTM
O16 -: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - hxxp://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection_3_1_0_4.cab
c:\windows\Downloaded Program Files\hardwaredetection.inf
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-05 23:43:09
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(724)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Fichiers communs\Symantec Shared\ccSetMgr.exe
c:\program files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\acer\Empowering Technology\admServ.exe
c:\program files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
c:\program files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
c:\program files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
c:\program files\OpenOffice.org 2.4\program\soffice.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\igfxsrvc.exe
c:\program files\OpenOffice.org 2.4\program\soffice.bin
c:\program files\Logitech\Video\FxSvr2.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\Internet Explorer\iexplore.exe
c:\program files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
.
**************************************************************************
.
Heure de fin: 2009-01-05 23:47:40 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-01-05 22:47:31
Avant-CF: 6 680 393 728 octets libres
Après-CF: 6,868,678,656 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
288 --- E O F --- 2008-12-20 17:31:51 Répondre à dadou |
|