Salut,
Voici les 2 rapports:
ComboFix 09-01-11.04 - yanick lussier 2009-01-13 15:38:37.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.33.1036.18.1527.1154 [GMT -5:00]
Lancé depuis: c:\documents and settings\yanick lussier\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\yanick lussier\Bureau\CFScript.txt
AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Outdated)
* Un nouveau point de restauration a été créé
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-13 au 2009-01-13 ))))))))))))))))))))))))))))))))))))
.
2009-01-13 14:00 . 2009-01-13 14:01 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-13 14:00 . 2009-01-13 14:00 <REP> d-------- c:\documents and settings\yanick lussier\Application Data\Malwarebytes
2009-01-13 14:00 . 2009-01-13 14:00 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-13 14:00 . 2009-01-04 18:38 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-13 14:00 . 2009-01-04 18:38 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-13 04:38 . 2009-01-13 04:39 1,374 --a------ c:\windows\imsins.BAK
2009-01-13 03:57 . 2009-01-13 03:57 <REP> d-------- C:\_OTMoveIt
2009-01-13 03:27 . 2009-01-13 03:28 <REP> d-------- C:\Rooter$
2009-01-13 00:48 . 2009-01-13 00:48 <REP> d-------- c:\program files\Trend Micro
2009-01-12 21:42 . 2009-01-12 21:42 211 --a------ c:\windows\wininit.ini
2009-01-12 20:56 . 2009-01-12 20:58 <REP> d-------- c:\program files\Spybot - Search & Destroy
2009-01-12 20:56 . 2009-01-12 20:59 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-12 20:31 . 2009-01-12 20:31 <REP> d-------- c:\documents and settings\yanick lussier\Application Data\Nero
2009-01-12 20:26 . 2009-01-12 20:26 <REP> d-------- c:\program files\Nero
2009-01-12 20:26 . 2009-01-12 20:27 <REP> d-------- c:\program files\Fichiers communs\Nero
2009-01-12 20:26 . 2009-01-12 20:26 <REP> d-------- c:\documents and settings\All Users\Application Data\Nero
2009-01-12 01:13 . 2009-01-12 01:13 <REP> d-------- c:\windows\system32\LogFiles
2009-01-10 22:44 . 2009-01-11 20:16 69 --a------ c:\windows\NeroDigital.ini
2009-01-09 22:47 . 2009-01-12 22:34 1,905 --a------ c:\windows\diagwrn.xml
2009-01-09 22:47 . 2009-01-12 22:34 1,905 --a------ c:\windows\diagerr.xml
2009-01-09 22:34 . 2009-01-09 22:34 <REP> d-------- c:\program files\DAEMON Tools
2009-01-09 18:53 . 2009-01-09 18:53 <REP> d-------- c:\program files\Alcohol Soft
2009-01-09 00:33 . 2006-03-02 07:00 25,088 --a------ c:\windows\system32\stus.exe
2009-01-08 19:18 . 2009-01-08 19:18 <REP> d-------- c:\windows\Sun
2008-12-26 19:32 . 2006-03-02 07:00 221,184 --a------ c:\windows\system32\wmpns.dll
2008-12-25 16:39 . 2008-12-25 16:39 <REP> d-------- c:\documents and settings\yanick lussier\Application Data\vlc
2008-12-19 06:38 . 2008-12-19 06:38 <REP> d-------- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-12-19 06:17 . 2009-01-11 00:28 <REP> d-------- c:\documents and settings\yanick lussier\Shared
2008-12-19 06:17 . 2009-01-11 00:28 <REP> d-------- c:\documents and settings\yanick lussier\Incomplete
2008-12-19 06:16 . 2008-12-27 22:17 <REP> d-------- c:\documents and settings\yanick lussier\Application Data\LimeWire
2008-12-19 05:37 . 2008-12-19 05:36 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-19 05:10 . 2008-12-19 05:10 <REP> d-------- c:\program files\ESET
2008-12-19 05:10 . 2008-12-19 05:10 <REP> d-------- c:\documents and settings\All Users\Application Data\ESET
2008-12-19 05:09 . 2008-12-19 05:36 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-12-19 05:08 . 2008-12-19 05:09 <REP> d-------- c:\program files\LimeWire
2008-12-19 05:08 . 2008-12-19 05:36 <REP> d-------- c:\program files\Java
2008-12-19 05:08 . 2008-12-19 05:08 <REP> d-------- c:\program files\Fichiers communs\Java
2008-12-19 05:03 . 2008-12-19 05:05 <REP> d-------- c:\windows\Internet Logs
2008-12-19 04:48 . 2008-12-27 20:35 <REP> d-------- c:\program files\eMule
2008-12-19 04:47 . 2008-12-19 04:47 <REP> d-------- c:\documents and settings\yanick lussier\Application Data\DAEMON Tools
2008-12-19 04:47 . 2008-12-19 04:47 717,296 --a------ c:\windows\system32\drivers\sptd.sys
2008-12-19 04:45 . 2008-12-19 04:45 <REP> d-------- c:\program files\uTorrent
2008-12-19 04:45 . 2009-01-12 21:43 <REP> d-------- c:\documents and settings\yanick lussier\Application Data\uTorrent
2008-12-19 04:44 . 2008-12-19 04:44 <REP> d-------- c:\program files\Yahoo!
2008-12-19 04:44 . 2008-12-19 04:44 <REP> d-------- c:\program files\VideoLAN
2008-12-19 04:44 . 2008-12-19 04:44 <REP> d-------- c:\program files\Ares
2008-12-19 04:43 . 2008-12-19 04:43 <REP> d-------- c:\program files\K-Lite Codec Pack
2008-12-19 04:43 . 2008-12-19 04:43 <REP> d-------- c:\program files\DVD Shrink
2008-12-19 04:43 . 2008-12-19 04:44 <REP> d-------- c:\program files\CCleaner
2008-12-19 04:43 . 2008-12-19 04:43 <REP> d-------- c:\documents and settings\All Users\Application Data\DVD Shrink
2008-12-19 04:40 . 2004-11-01 20:04 167,936 -ra------ c:\windows\system32\igfxres.dll
2008-12-19 04:33 . 2008-12-19 04:33 <REP> d-------- c:\program files\Realtek AC97
2008-12-19 04:33 . 2005-07-22 01:56 18,763,776 -ra------ c:\windows\system32\ALSNDMGR.CPL
2008-12-19 04:32 . 2004-11-01 20:17 2,289,664 -ra------ c:\windows\system32\ialmgicd.dll
2008-12-19 04:31 . 2008-12-19 04:31 <REP> d-------- c:\program files\Intel
2008-12-19 04:22 . 2008-12-19 04:22 13,646 --a------ c:\windows\system32\wpa.bak
2008-12-19 04:01 . 2009-01-12 03:33 <REP> d-------- c:\program files\Fichiers communs\Ahead
2008-12-19 04:00 . 2008-12-19 04:33 <REP> d--h----- c:\program files\InstallShield Installation Information
2008-12-19 04:00 . 2008-12-19 04:32 <REP> d-------- c:\program files\Fichiers communs\InstallShield
2008-12-19 04:00 . 2008-12-19 04:00 <REP> d-------- c:\program files\CyberLink DVD Solution
2008-12-19 04:00 . 2004-10-01 15:00 40,960 --a------ c:\program files\Uninstall_CDS.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-19 08:33 --------- d-----w c:\program files\microsoft frontpage
2008-12-19 08:31 --------- d-----w c:\program files\Services en ligne
2008-10-23 13:00 283,648 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 19:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\system32\wups.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2006-03-02 15360]
"ares"="c:\program files\Ares\Ares.exe" [2007-07-16 961536]
"PowerBar"="c:\program files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe" [2004-04-21 86016]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" [2007-12-13 1688872]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-11-01 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-11-01 126976]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-19 136600]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-02-20 1443072]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2006-09-14 157592]
"NeroFilterCheck"="c:\program files\Fichiers communs\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-12-03 2213160]
"SoundMan"="SOUNDMAN.EXE" [2005-07-22 c:\windows\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-03-02 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"VIDC.X264"= x264vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.i263"= i263_32.drv
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"msacm.imc"= imc32.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [2008-02-20 33800]
R4 ekrn;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [2007-12-21 468224]
.
.
------- Examen supplémentaire -------
.
uInternet Settings,ProxyOverride = *.local;<local>
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-13 15:39:44
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2009-01-13 15:40:52
ComboFix-quarantined-files.txt 2009-01-13 20:40:50
ComboFix2.txt 2009-01-13 09:39:16
Avant-CF: 53 156 487 168 octets libres
Après-CF: 53,151,891,456 octets libres
146 --- E O F --- 2009-01-13 10:24:48
HJT maintenant:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:47:22, on 2009-01-13
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HJT.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [PowerBar] "C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe" /AtBootTime
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
End of file - 5357 bytes
À +