Voilla
J'ai encore win32.delf.giy et mon pc est encorelent et mon internet explorer n'affiche pas les images.
ComboFix 09-01-21.04 - Sylvain 2009-01-30 8:58:38.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.502.251 [GMT -5:00]
Lancé depuis: c:\documents and settings\Sylvain\Bureau\ComboFix.exe
AV: avast! antivirus 4.8.1296 [VPS 090129-0] *On-access scanning disabled* (Updated)
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
[i] ADS - svchost.exe: deleted 32256 bytes in 1 streams. /i
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\CrucialSoft Ltd
c:\documents and settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\LOG\20090130083832858.log
c:\documents and settings\All Users\Application Data\CrucialSoft Ltd\MS AntiSpyware 2009\msas2009.exe
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\Sylvain\Application Data\inst.exe
c:\documents and settings\Sylvain\Local Settings\Temporary Internet Files\fbk.sts
c:\program files\INSTALL.LOG
c:\windows\system32\_000228_.tmp.dll
c:\windows\system32\drivers\seneka.sys
c:\windows\system32\drivers\senekadqvrhlub.sys
c:\windows\system32\Drivers\TDSSpaxt.sys
c:\windows\system32\msupdte.exe
c:\windows\system32\rs32net.exe
c:\windows\system32\ryhhzmb.dll
c:\windows\system32\senekahetxufsl.dll
c:\windows\system32\senekahpivfhiv.dll
c:\windows\system32\senekajjigbgrm.dat
c:\windows\system32\senekakibwfhri.dat
c:\windows\system32\senekashxcqoji.dll
c:\windows\system32\tmp.reg
C:\winlogon.exe
----- BITS: Il y a peut-être des sites infectés -----
hxxp://dealsforfun.com
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_FCI
-------\Legacy_icf
-------\Service_fci
-------\Service_icf
-------\Service_seneka
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-28 au 2009-01-30 ))))))))))))))))))))))))))))))))))))
.
2009-01-30 09:02 . 2009-01-30 09:02 <REP> d-------- c:\documents and settings\All Users\Application Data\CrucialSoft Ltd
2009-01-30 08:35 . 2009-01-30 09:02 144,896 --a------ c:\windows\sch32.exe
2009-01-29 22:47 . 2009-01-29 21:47 336,136 --a------ c:\documents and settings\Sylvain\setup.exe
2009-01-29 21:31 . 2009-01-29 21:33 <REP> d-------- C:\ToolBar SD
2009-01-29 20:13 . 2009-01-29 21:01 <REP> d-------- C:\SmitfraudFix
2009-01-29 07:25 . 2009-01-29 07:25 133,120 --a------ c:\windows\ocohikilugoqora.dll
2009-01-29 07:12 . 2009-01-29 07:12 43,008 --a------ c:\windows\Tnarepayuka.dll
2009-01-29 07:12 . 2009-01-29 07:12 43,008 --a------ c:\windows\system32\chert10-303361.exe
2009-01-29 07:00 . 2009-01-30 08:39 32,768 --a------ c:\windows\system32\drivers\ati7otxx.sys
2009-01-29 06:59 . 2009-01-30 09:02 93,550 --a------ c:\windows\system32\drivers\cff2a44a.sys
2009-01-29 06:58 . 2009-01-30 08:02 <REP> d-------- c:\documents and settings\Sylvain\Application Data\cogad
2009-01-29 06:58 . 2009-01-29 06:58 151,040 --a------ c:\windows\scvhost32.exe
2009-01-29 06:58 . 2009-01-29 06:58 2 --a------ C:\-1069336754
2009-01-29 05:00 . 2009-01-29 06:57 <REP> d-------- c:\documents and settings\Sylvain\Application Data\_5c540bbd0dccfb1fb342c25d0aed6f6c
2009-01-29 05:00 . 2009-01-29 05:00 796,787 --a------ C:\xzCodec_v.1010.1.exe
2009-01-29 05:00 . 2009-01-29 05:00 796,787 --a------ c:\documents and settings\Sylvain\Application Data\svchost.exe
2009-01-29 04:54 . 2009-01-29 04:54 135,168 --a------ C:\fidexterle.exe
2009-01-28 19:21 . 2009-01-28 19:21 135,168 --a------ C:\fu667ndexter.exe
2009-01-27 11:27 . 2009-01-27 11:27 135,168 --a------ C:\fise34le.exe
2009-01-27 08:54 . 2009-01-27 08:54 108,336 --a------ c:\windows\system32\mswinsck.ocx
2009-01-26 19:00 . 2009-01-26 19:00 <REP> d-------- c:\documents and settings\Sylvain\Application Data\Xilisoft Corporation
2009-01-26 18:59 . 2009-01-20 21:22 237,568 --a------ c:\windows\callsysnt.exe
2009-01-21 18:55 . 2009-01-21 18:55 <REP> dr------- c:\documents and settings\Sylvain\Application Data\Brother
2009-01-19 16:41 . 2009-01-19 16:41 34,248 --ah----- c:\windows\system32\mlfcache.dat
2009-01-18 09:41 . 2009-01-18 09:41 <REP> d-------- c:\documents and settings\Sylvain\Application Data\JAlbum
2009-01-16 09:07 . 2009-01-16 09:08 <REP> d-------- c:\program files\Jalbum8.1
2009-01-15 19:22 . 2009-01-19 20:55 <REP> d-------- c:\documents and settings\Sylvain\Application Data\FileZilla
2009-01-15 19:21 . 2009-01-15 19:21 <REP> d-------- c:\program files\FileZilla FTP Client
2009-01-15 19:16 . 2009-01-16 08:54 <REP> d-------- c:\documents and settings\All Users\Application Data\FLEXnet
2009-01-15 19:04 . 2009-01-15 19:04 <REP> d-------- c:\program files\Fichiers communs\Macrovision Shared
2009-01-08 19:28 . 2009-01-08 19:28 <REP> d-------- c:\program files\DVD Shrink
2009-01-08 19:28 . 2009-01-08 19:28 <REP> d-------- c:\documents and settings\All Users\Application Data\DVD Shrink
2009-01-04 14:39 . 2007-03-08 17:18 18,432 --a------ c:\windows\system32\drivers\grmngen.sys
2009-01-04 14:39 . 2007-03-08 17:18 8,320 --a------ c:\windows\system32\drivers\grmnusb.sys
2008-12-08 16:47 . 2008-12-08 16:47 <REP> d-------- c:\program files\MARS
2008-12-08 16:47 . 2001-05-30 00:00 352,256 --a------ c:\windows\system32\ijl15.dll
2008-12-08 16:47 . 2001-12-20 18:20 205,824 --a------ c:\windows\system32\VIC32.DLL
2008-12-08 16:47 . 2002-05-07 12:36 147,456 --a------ c:\windows\system32\mr310ipc.dll
2008-12-08 16:47 . 2002-09-09 15:19 130,309 --a------ c:\windows\system32\drivers\MR97310c.sys
2008-12-08 16:47 . 2002-08-26 18:38 61,440 --a------ c:\windows\system32\mr310ifc.dll
2008-12-08 16:47 . 2001-10-12 10:57 36,864 --a------ c:\windows\system32\mr310exv.dll
2008-12-08 16:47 . 2001-10-12 10:58 28,672 --a------ c:\windows\system32\mr310exd.dll
2008-12-08 16:47 . 2000-12-07 10:13 15,164 --a------ c:\windows\mr310twc.ini
2008-12-08 16:47 . 2002-04-12 15:31 12,106 --a------ c:\windows\mr310twc.src
2008-12-08 16:47 . 2009-01-10 11:04 37 --a------ c:\windows\marscam.ini
2008-12-07 15:34 . 2008-12-07 15:34 <REP> d-------- c:\documents and settings\Sylvain\Application Data\Vso
2008-12-07 15:34 . 2008-12-07 15:34 47,360 --a------ c:\windows\system32\drivers\pcouffin.sys
2008-12-07 15:34 . 2008-12-07 15:34 47,360 --a------ c:\documents and settings\Sylvain\Application Data\pcouffin.sys
2008-12-07 15:33 . 2008-12-07 15:34 <REP> d-------- c:\program files\DVDFab 5
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-30 13:51 --------- d-----w c:\documents and settings\All Users\Application Data\Sonic
2009-01-27 23:05 --------- d-----w c:\documents and settings\Sylvain\Application Data\GARMIN
2009-01-26 23:59 --------- d-----w c:\documents and settings\Sylvain\Application Data\LimeWire
2009-01-26 23:55 --------- d-----w c:\documents and settings\Sylvain\Application Data\Azureus
2009-01-16 00:16 --------- d-----w c:\program files\Google
2009-01-16 00:06 --------- d-----w c:\program files\Fichiers communs\Adobe
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-08 23:29 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-08 23:16 --------- d-----w c:\program files\Yahoo!
2008-12-05 13:40 --------- d-----w c:\program files\Java
2008-11-30 23:53 --------- d-----w c:\documents and settings\Sylvain\Application Data\Roxio
2008-11-30 22:58 --------- d-----w c:\documents and settings\LocalService\Application Data\DivX
2008-11-29 00:42 --------- d-----w c:\program files\NOS
2008-11-29 00:42 --------- d-----w c:\documents and settings\All Users\Application Data\NOS
2008-10-29 22:54 155,995 ----a-w c:\windows\java\Packages\CUDNNN37.ZIP
2002-06-04 09:06 65,536 ------w c:\windows\inf\copyinf.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-01 68856]
"settings"="c:\windows\callsysnt.exe" [2009-01-20 237568]
"Installer"="c:\documents and settings\Sylvain\Application Data\_5c540bbd0dccfb1fb342c25d0aed6f6c\down\1030000.exe" [2009-01-30 81931]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-19 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-19 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-19 114688]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"RoxWatchTray"="c:\program files\Fichiers communs\Roxio Shared\11.0\SharedCOM\RoxWatchTray11.exe" [2008-08-14 240112]
"CPMonitor"="c:\program files\Roxio Creator 2009\5.0\CPMonitor.exe" [2008-08-10 80368]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"AdobeCS4ServiceManager"="c:\program files\Fichiers communs\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"*svchostBoot"="c:\documents and settings\Sylvain\Application Data\svchost.exe" [2009-01-29 796787]
"svchost32"="c:\windows\scvhost32.exe" [2009-01-29 151040]
"Acudujikapak"="c:\windows\Tnarepayuka.dll" [2009-01-29 43008]
"Pfedixipabusax"="c:\windows\ocohikilugoqora.dll" [2009-01-29 133120]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\Currentversion\policies\explorer\Run]
"settings"="c:\windows\callsysnt.exe" [2009-01-20 237568]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= c:\progra~1\FICHIE~1\ULEADS~1\Vio\Dvacm.acm
"msacm.MPEGacm"= c:\progra~1\FICHIE~1\ULEADS~1\MPEG\MPEGacm.acm
"msacm.ulmp3acm"= c:\progra~1\FICHIE~1\ULEADS~1\MPEG\ulmp3acm.acm
"VIDC.SP40"= SP40_32.DLL
"VIDC.SP41"= SP4X_32.DLL
"VIDC.SP42"= SP4X_32.DLL
"VIDC.SP43"= SP4X_32.DLL
"VIDC.SP44"= SP4X_32.DLL
"VIDC.SP45"= SP4X_32.DLL
"VIDC.SP46"= SP4X_32.DLL
"VIDC.SP47"= SP4X_32.DLL
"vidc.MJPG"= m3jpeg32.dll
"vidc.dmb1"= m3jpeg32.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati7otxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-06-12 02:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UVS10 Preload]
--------- 2006-08-09 08:27 36864 c:\program files\Ulead Systems\Ulead VideoStudio SE DVD\uvPL.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Fichiers communs\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R0 ati7otxx;ati7otxx;c:\windows\system32\drivers\ati7otxx.sys [2009-01-29 32768]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-10-29 111184]
R4 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-10-29 20560]
S3 Roxio UPnP Renderer 11;Roxio UPnP Renderer 11;c:\program files\Roxio Creator 2009\Digital Home 11\RoxioUPnPRenderer11.exe [2008-08-14 313840]
S3 RoxMediaDB11;RoxMediaDB11;c:\program files\Fichiers communs\Roxio Shared\11.0\SharedCOM\RoxMediaDB11.exe [2008-08-14 1124848]
S4 Roxio Upnp Server 11;Roxio Upnp Server 11;c:\program files\Roxio Creator 2009\Digital Home 11\RoxioUpnpService11.exe [2008-08-14 367088]
S4 RoxLiveShare11;LiveShare P2P Server 11;c:\program files\Fichiers communs\Roxio Shared\11.0\SharedCOM\RoxLiveShare11.exe [2008-08-14 309744]
S4 RoxWatch11;Roxio Hard Drive Watcher 11;c:\program files\Fichiers communs\Roxio Shared\11.0\SharedCOM\RoxWatch11.exe [2008-08-14 170480]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4f03fe46-b73e-11dd-ae5b-0013209ad288}]
\Shell\AutoRun\command - ij.bat
\Shell\explore\Command - ij.bat
\Shell\open\Command - ij.bat
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{0355IH63-F7N5-8B0Y-75Y4-160E764T6PB4}]
"c:\docume~1\Sylvain\LOCALS~1\Temp\winlogon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5468461G-KC11-0H37-3770-766E451UICQ4}]
"c:\windows\callsysnt.exe"
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-rs32net - c:\windows\System32\rs32net.exe
HKCU-Run-sysguard - c:\windows\sysguard.exe
HKLM-Run-Microsoft WinUpdate - c:\windows\system32\msupdte.exe
HKU-Default-Run-tezrtsjhfr84iusjfo84f - c:\windows\TEMP\csrssc.exe
.
------- Examen supplémentaire -------
.
mWindow Title =
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-30 09:02:20
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cff2a44a]
"ImagePath"="\SystemRoot\System32\drivers\cff2a44a.sys"
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\savedump.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\StkASv2K.exe
c:\program files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\wscntfy.exe
c:\program files\Internet Explorer\iexplore.exe
.
**************************************************************************
.
Heure de fin: 2009-01-30 9:04:04 - La machine a redémarré [Sylvain]
ComboFix-quarantined-files.txt 2009-01-30 14:04:02
Avant-CF: 11,327,860,736 octets libres
Après-CF: 11,268,562,944 octets libres
227 --- E O F --- 2009-01-15 08:01:47