En mode normal ça marche je n'ai ni spyware guard 2009 qui se lance ni de page erreur bleue.
voila le rapport :
ComboFix 09-01-13.04 - Administrateur 2009-01-14 17:36:59.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.2046.1624 [GMT 1:00]
Lancé depuis: d:\documents and settings\Administrateur\Bureau\Streekyledestructeur.exe
AV: avast! antivirus 4.8.1229 [VPS 090111-1] *On-access scanning disabled* (Outdated)
[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/B/COLOR
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
d:\documents and settings\Administrateur\Application Data\.#
d:\documents and settings\Administrateur\Application Data\.#\MBX@528@3841A8.###
d:\documents and settings\Administrateur\Application Data\.#\MBX@528@3841D8.###
d:\documents and settings\Administrateur\Application Data\.#\MBX@528@384208.###
d:\documents and settings\Administrateur\Application Data\.#\MBX@54C@3841A8.###
d:\documents and settings\Administrateur\Application Data\.#\MBX@54C@3841D8.###
d:\documents and settings\Administrateur\Application Data\.#\MBX@54C@384208.###
d:\documents and settings\Administrateur\Application Data\.#\MBX@EB8@3841A8.###
d:\documents and settings\Administrateur\Application Data\.#\MBX@EB8@3841D8.###
d:\documents and settings\Administrateur\Application Data\.#\MBX@EB8@384208.###
d:\documents and settings\All Users\Application Data\Microsoft\Internet Explorer\DLLs\ieModule.dll
d:\documents and settings\All Users\Application Data\Microsoft\Protect\svhost.exe
d:\documents and settings\All Users\Application Data\svhost.exe
d:\install\install.exe
d:\windows\reged.exe
d:\windows\spoolsystem.exe
d:\windows\sys.com
d:\windows\syscert.exe
d:\windows\sysexplorer.exe
d:\windows\system32\drivers\TDSSpaxt.sys
d:\windows\system32\TDSScfum.dll
d:\windows\system32\TDSSfxwp.dll
d:\windows\system32\TDSSnmxh.log
d:\windows\system32\TDSSnrsr.dll
d:\windows\system32\TDSSofxh.dll
d:\windows\system32\TDSSosvd.dat
d:\windows\system32\TDSSrhym.log
d:\windows\system32\TDSSriqp.dll
d:\windows\system32\TDSSsbhc.dll
d:\windows\system32\TDSStkdv.log
d:\windows\system32\Update.exe
d:\windows\system32\uquerkeyfhqyzztqc.dll
d:\windows\system32\winscenter.exe
d:\windows\vmreg.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_TDSSSERV.SYS
-------\Legacy_TDSSSERV.SYS
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-14 au 2009-01-14 ))))))))))))))))))))))))))))))))))))
.
2009-01-14 16:42 . 2009-01-14 17:08 <REP> d-------- d:\program files\Navilog1
2009-01-14 16:32 . 2009-01-14 16:32 <REP> d-------- D:\rsit
2009-01-14 16:32 . 2009-01-14 16:32 <REP> d-------- d:\program files\trend micro
2009-01-14 14:48 . 2009-01-14 14:48 <REP> d-------- d:\program files\Spyware Guard 2009
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-14 16:08 --------- d-----w d:\program files\EoRezo
2009-01-14 16:08 --------- d-----w d:\documents and settings\Administrateur\Application Data\EoRezo
2009-01-14 14:38 16,608 ----a-w d:\windows\gdrv.sys
2009-01-14 14:38 --------- d---a-w d:\documents and settings\All Users\Application Data\TEMP
2009-01-14 13:42 --------- d-----w d:\program files\Bonjour
2009-01-12 07:38 --------- d-----w d:\documents and settings\All Users\Application Data\Google Updater
2009-01-12 07:25 --------- d-----w d:\program files\ItsLabel
2009-01-08 08:59 --------- d-----w d:\documents and settings\Administrateur\Application Data\Canon
2008-12-30 20:29 --------- d-----w d:\program files\Everest Poker
2008-12-18 14:10 56,726 ----a-w d:\windows\system32\uquerkeyfhqyzztqc.dll-uninst.exe
2008-12-12 21:14 --------- d-----w d:\documents and settings\All Users\Application Data\Microsoft Help
2008-11-25 16:27 47,897 ----a-w d:\windows\system32\ntrduihktxtnavasn.exe
2008-11-16 12:56 --------- d-----w d:\documents and settings\Administrateur\Application Data\Sports Interactive
2008-11-16 12:36 --------- d-----w d:\documents and settings\All Users\Application Data\Sports Interactive
2008-10-23 12:36 286,720 ----a-w d:\windows\system32\gdi32.dll
2008-10-16 20:18 826,368 ----a-w d:\windows\system32\wininet.dll
2008-10-16 13:13 202,776 ----a-w d:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w d:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w d:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w d:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w d:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w d:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w d:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w d:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w d:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w d:\windows\system32\muweb.dll
2008-10-14 20:13 844,090 ----a-w d:\windows\goujon.audrey.imageshack.com.zip
2008-10-14 20:13 844,080 ----a-w d:\windows\pagamine.imageshack.com.zip
2008-10-14 20:13 844,080 ----a-w d:\windows\grizly45.imageshack.com.zip
2008-10-14 20:13 844,076 ----a-w d:\windows\pic0382.zip
2008-10-14 20:13 844,076 ----a-w d:\windows\maxlir.imageshack.com.zip
2008-09-07 19:10 32,768 --sha-w d:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008090720080908\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="d:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ctfmon.exe"="d:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="d:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GEST"="d:\program files\GIGABYTE\GEST\RUN.exe" [2008-09-07 236040]
"JMB36X IDE Setup"="d:\windows\RaidTool\xInsIDE.exe" [2007-03-20 36864]
"36X Raid Configurer"="d:\windows\system32\xRaidSetup.exe" [2007-08-29 1966080]
"StartCCC"="d:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"avast!"="d:\logiciel\avast\ashDisp.exe" [2008-07-19 78008]
"Adobe Reader Speed Launcher"="d:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"OpwareSE2"="d:\logiciel\scansoft\OpwareSE2.exe" [2003-05-08 49152]
"QuickTime Task"="d:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"spywareguard"="d:\program files\Spyware Guard 2009\spywareguard.exe" [2009-01-14 1025536]
"RTHDCPL"="RTHDCPL.EXE" [2007-09-19 d:\windows\RTHDCPL.exe]
d:\documents and settings\Administrateur\Menu D‚marrer\Programmes\D‚marrage\
Eurobarre.lnk - d:\logiciel\Eurobarre\eb.exe [2008-08-02 113664]
d:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.lnk - d:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2008-09-07 110592]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
--a------ 2008-07-24 16:02 490952 d:\logiciel\DAEMON Tools Lite\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ItsTV]
--a------ 2007-04-26 15:19 2908160 d:\program files\ItsLabel\ItsTV.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-10-01 17:57 289576 d:\logiciel\itunes\iTunesHelper.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\jeux\\Football managaer 2008\\fm.exe"=
"d:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\GIGABYTE\\GEST\\run.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"d:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"d:\\Logiciel\\itunes\\iTunes.exe"=
"d:\\jeux\\wharammer online\\WAR_VO_French.exe"=
"d:\\jeux\\FM2009\\fm.exe"=
"d:\\Documents and Settings\\Administrateur\\Local Settings\\netdetect.exe"=
R1 aswSP;avast! Self Protection;d:\windows\system32\drivers\aswSP.sys [2008-08-01 78416]
R4 aswFsBlk;aswFsBlk;d:\windows\system32\drivers\aswFsBlk.sys [2008-08-01 20560]
S3 GEST Service;GEST Service for program management.;d:\program files\GIGABYTE\GEST\gsvr.exe [2007-01-01 55816]
S3 SIS163u;SiS163 USB Wireless LAN Adapter Driver;d:\windows\system32\drivers\sis163u.sys [2007-01-01 217088]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b1067f0c-7e8a-11dd-b5a0-0018e711bfbd}]
\Shell\AutoRun\command - G:\memorybar.exe
.
Contenu du dossier 'Tâches planifiées'
2008-12-18 d:\windows\Tasks\AppleSoftwareUpdate.job
- d:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{F0D31CDD-7BE0-E0D1-388D-3AC2A38D6510} - d:\windows\system32\uquerkeyfhqyzztqc.dll
HKCU-Run-NFREN - E:\Setup.exe
HKCU-Run-RIOTBOT - Update.exe
HKLM-Run-vjsqglvrunkhx - d:\windows\system32\xmhtkumpbn.dll
HKLM-Run-RIOTBOT - Update.exe
HKLM-Run-EoEngine - (no file)
HKLM-RunServices-RIOTBOT - Update.exe
MSConfigStartUp-EoEngine - d:\program files\EoRezo\EoEngine.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://lo.st#home
uInternet Settings,ProxyOverride = *.local
IE: E&xporter vers Microsoft Excel - d:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Easy-WebPrint Ajouter à la liste d'impressions - d:\logiciel\MP150\Easy-WebPrint\Resource.dll/RC_AddToList.html
IE: Easy-WebPrint Impression rapide - d:\logiciel\MP150\Easy-WebPrint\Resource.dll/RC_HSPrint.html
IE: Easy-WebPrint Imprimer - d:\logiciel\MP150\Easy-WebPrint\Resource.dll/RC_Print.html
IE: Easy-WebPrint Prévisualiser - d:\logiciel\MP150\Easy-WebPrint\Resource.dll/RC_Preview.html
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-14 17:38:33
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(728)
d:\windows\system32\Ati2evxx.dll
.
Heure de fin: 2009-01-14 17:39:09
ComboFix-quarantined-files.txt 2009-01-14 16:39:07
Avant-CF: 416,074,600,448 octets libres
Après-CF: 416,044,965,888 octets libres
Current=2 Default=2 Failed=1 LastKnownGood=4 Sets=1,2,3,4
183 --- E O F --- 2008-12-17 20:55:33