voici le rapport:
ComboFix 09-02-06.01 - dell 2009-02-06 21:45:21.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1015.636 [GMT 1:00]
Lancé depuis: c:\documents and settings\dell\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\windows\system32\artbgccp.ini
c:\windows\system32\BbJPYJjl.ini
c:\windows\system32\BbJPYJjl.ini2
c:\windows\system32\cwgujqrk.ini
c:\windows\system32\dfdkvmgp.dll
c:\windows\system32\dhstyhks.ini
c:\windows\system32\dtugggfd.ini
c:\windows\system32\finobefe.dll
c:\windows\system32\gomevlhy.ini
c:\windows\system32\hgwgulsi.ini
c:\windows\system32\iwfqqtrx.ini
c:\windows\system32\jqenebrs.ini
c:\windows\system32\mmpnncds.ini
c:\windows\system32\ochtay.dll
c:\windows\system32\tmaqhdmg.ini
c:\windows\system32\vifozaye.dll.tmp
c:\windows\system32\vkhshhmu.ini
c:\windows\system32\wabatase.dll.tmp
c:\windows\system32\wnkdwxba.ini
c:\windows\system32\yahisiwe.dll.tmp
.
---- Exécution préalable -------
.
c:\windows\ktd32.atm
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
c:\windows\Tasks\htssvzrf.job
----- BITS: Il y a peut-être des sites infectés -----
hxxp://childhe.com
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-01-06 au 2009-02-06 ))))))))))))))))))))))))))))))))))))
.
2009-02-05 20:28 . 2009-02-05 20:28 <REP> d-------- C:\rsit
2009-02-05 20:28 . 2009-02-05 20:28 <REP> d-------- c:\program files\trend micro
2009-02-04 17:32 . 2009-02-04 17:32 <REP> d-------- c:\documents and settings\dell\Application Data\Malwarebytes
2009-02-04 17:31 . 2009-02-04 17:32 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-04 17:31 . 2009-02-04 17:31 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-04 17:31 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-04 17:31 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-04 07:23 . 2009-02-04 07:23 149 --a------ c:\windows\wininit.ini
2009-02-03 21:26 . 2004-03-31 12:28 131,072 --a------ c:\windows\system32\TBD22F.tmp
2009-02-03 21:19 . 2009-02-03 21:19 <REP> d-------- c:\program files\Spybot - Search & Destroy
2009-02-03 21:19 . 2009-02-03 21:20 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-03 21:15 . 2009-02-03 21:15 <REP> d-------- c:\documents and settings\dell\Application Data\BitDefender
2009-02-03 21:15 . 2009-02-03 21:15 <REP> d-------- C:\csscod
2009-02-03 21:13 . 2009-02-03 21:26 <REP> d-------- c:\program files\Fichiers communs\BitDefender
2009-02-01 18:24 . 2009-02-02 10:34 <REP> d-------- c:\program files\AskBarDis
2009-02-01 18:23 . 2009-02-01 18:23 <REP> d-------- c:\program files\Foxit Software
2009-02-01 18:23 . 2009-02-01 18:23 <REP> d-------- c:\documents and settings\dell\Application Data\Foxit
2009-02-01 15:10 . 2009-02-01 15:10 <REP> d-------- c:\program files\CCleaner
2009-02-01 14:57 . 2009-02-01 14:59 <REP> d-------- C:\ToolBar SD
2009-02-01 13:01 . 2009-02-01 13:01 <REP> d-------- c:\windows\system32\Kaspersky Lab
2009-01-31 11:52 . 2009-01-31 11:52 <REP> d-------- c:\program files\[u]0
/u07 James Bond NightFire
2009-01-30 20:27 . 2009-01-31 18:42 <REP> d-------- c:\windows\SxsCaPendDel
2009-01-30 20:19 . 2009-01-30 20:23 <REP> d-------- c:\program files\Max Payne
2009-01-29 20:50 . 2009-01-30 17:19 <REP> d-------- c:\program files\EA GAMES
2009-01-29 07:28 . 2009-01-29 07:28 43,520 --a------ c:\windows\system32\CmdLineExt03.dll
2009-01-29 07:14 . 2009-01-29 07:14 <REP> d-------- c:\program files\Eidos
2009-01-28 15:29 . 2009-01-28 15:30 <REP> d-------- c:\program files\gXiso
2009-01-23 22:38 . 2009-01-23 22:38 <REP> d-------- c:\program files\EA SPORTS
2009-01-19 18:05 . 2009-01-19 18:07 <REP> d-------- C:\Mes Sites Web
2009-01-19 18:04 . 2009-01-19 18:04 <REP> d-------- c:\program files\WinHTTrack
2009-01-18 17:31 . 2009-01-18 17:31 <REP> d-------- c:\documents and settings\All Users\Application Data\Activision
2009-01-18 15:14 . 2009-01-18 17:31 <REP> d-------- c:\documents and settings\dell\Application Data\Activision
2009-01-18 14:48 . 2009-01-18 14:48 307 --a------ c:\windows\game.ini
2009-01-18 14:30 . 2009-01-18 14:30 <REP> d--hs---- c:\windows\ftpcache
2009-01-14 19:15 . 2009-01-14 19:15 <REP> d-------- C:\Fraps
2009-01-14 15:36 . 2009-01-25 21:18 <REP> d-------- c:\program files\Windows Live Safety Center
2009-01-13 21:57 . 2004-01-28 15:03 21,456 --a------ c:\windows\system32\drivers\SilvrLnk.sys
2009-01-13 21:56 . 2009-01-13 21:56 <REP> d-------- c:\program files\Fichiers communs\TI Shared
2009-01-13 21:24 . 1999-08-30 14:51 9,152 --a------ c:\windows\system32\drivers\Ticalc.sys
2009-01-13 21:24 . 2009-01-13 22:34 286 --a------ c:\windows\Wlink83p.ini
2009-01-13 21:10 . 2009-01-13 21:10 <REP> d-------- c:\windows\F07AE5AB516C4CEBA0AAAD083B9182C6.TMP
2009-01-13 21:10 . 2009-01-13 21:56 <REP> d-------- c:\program files\Fichiers communs\Wise Installation Wizard
2009-01-13 20:59 . 2009-01-13 20:59 <REP> d-------- c:\documents and settings\dell\Application Data\Publish Providers
2009-01-13 20:54 . 2009-01-13 20:54 <REP> d-------- c:\documents and settings\dell\Application Data\Sony
2009-01-13 20:54 . 1998-10-29 15:45 306,688 --a------ c:\windows\IsUninst.exe
2009-01-13 20:54 . 2002-12-17 16:23 33,340 --------- c:\windows\system32\dbmsqlgc.dll
2009-01-13 20:54 . 2002-10-20 14:05 24,576 --------- c:\windows\system32\dbmsgnet.dll
2009-01-13 20:53 . 2009-02-01 16:00 <REP> d-------- c:\program files\Sony
2009-01-13 20:53 . 2009-02-01 16:00 <REP> d-------- c:\documents and settings\All Users\Application Data\Sony
2009-01-13 20:47 . 2009-01-13 20:47 <REP> d-------- c:\program files\Sony Setup
2009-01-10 12:31 . 2009-01-10 12:36 <REP> d-------- c:\program files\Internet Download Manager
2009-01-10 12:31 . 2009-01-22 19:14 <REP> d-------- c:\documents and settings\dell\Application Data\IDM
2009-01-09 23:31 . 2004-08-03 23:08 31,616 --a------ c:\windows\system32\drivers\usbccgp.sys
2009-01-09 23:31 . 2004-08-03 23:08 31,616 --a--c--- c:\windows\system32\dllcache\usbccgp.sys
2009-01-08 22:26 . 2009-01-08 22:41 <REP> d-------- c:\program files\Counter-Strike Source
2009-01-07 20:34 . 2009-01-24 22:45 <REP> d-------- c:\program files\Counter-Strike 1.6
2009-01-06 21:00 . 2009-01-06 21:00 <REP> d-------- c:\program files\KONAMI
2009-01-06 20:56 . 2009-01-06 20:56 <REP> d-------- c:\program files\Ares
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-06 20:45 --------- d-----w c:\documents and settings\dell\Application Data\DMCache
2009-01-30 19:19 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-24 19:25 --------- d-----w c:\program files\FlashFXP
2009-01-22 18:18 --------- d-----w c:\program files\Google
2009-01-18 19:47 --------- d-----w c:\documents and settings\dell\Application Data\Nokia
2009-01-14 18:26 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-01-03 14:54 --------- d-----w c:\program files\Amor AVI MPEG WMV RM to MP3 Converter
2009-01-03 13:58 --------- d-----w c:\program files\Free Video Converter
2009-01-03 13:48 --------- d-----w c:\documents and settings\dell\Application Data\Xilisoft Corporation
2009-01-03 09:32 --------- d-----w c:\program files\PC Inspector File Recovery
2008-12-28 13:34 --------- d-----w c:\documents and settings\dell\Application Data\U3
2008-12-26 12:54 --------- d-----w c:\documents and settings\All Users\Application Data\Sports Interactive
2008-12-26 12:09 --------- d-----w c:\program files\7-Zip
2008-12-25 02:19 --------- d-----w c:\program files\SK's
2008-12-24 23:06 --------- d-----w c:\program files\SystemRequirementsLab
2008-12-23 16:23 --------- d-----w c:\program files\Eidos Interactive
2008-12-16 21:07 --------- d-----w c:\program files\MSN Messenger
2008-12-16 08:37 --------- d-----w c:\documents and settings\All Users\Application Data\Trymedia
2008-12-16 07:51 --------- d-----w c:\program files\Fichiers communs\InstallShield
2008-12-15 21:39 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf
2008-12-15 21:39 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_ccdcmb_01007.Wdf
2008-12-15 21:39 --------- d-----w c:\documents and settings\dell\Application Data\PC Suite
2008-12-15 21:38 --------- d-----w c:\documents and settings\All Users\Application Data\PC Suite
2008-12-15 21:37 --------- d-----w c:\program files\PC Connectivity Solution
2008-12-15 21:37 --------- d-----w c:\program files\Nokia
2008-12-15 21:37 --------- d-----w c:\program files\Fichiers communs\PCSuite
2008-12-15 21:37 --------- d-----w c:\program files\Fichiers communs\Nokia
2008-12-15 21:37 --------- d-----w c:\program files\DIFX
2008-12-15 21:36 --------- d-----w c:\documents and settings\All Users\Application Data\Installations
2008-12-13 17:40 --------- d-----w c:\program files\Windows Live
2008-12-13 15:57 --------- d-----w c:\documents and settings\dell\Application Data\MSNInstaller
2008-12-13 15:48 --------- d-----w c:\program files\VS Revo Group
2008-12-11 22:52 --------- d-----w c:\program files\Microsoft SQL Server
2008-12-11 22:52 --------- d-----w c:\program files\Microsoft Silverlight
2008-12-11 22:50 --------- d-----w c:\program files\Microsoft.NET
2008-12-11 22:44 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-12-11 22:43 --------- d-----w c:\program files\Microsoft Visual Studio 9.0
2008-12-11 22:40 --------- d-----w c:\program files\Fichiers communs\Merge Modules
2008-12-11 22:38 --------- d-----w c:\program files\Microsoft SDKs
2008-12-11 22:34 --------- d-----w c:\program files\Reference Assemblies
2008-12-11 22:34 --------- d-----w c:\program files\MSBuild
2008-12-11 22:31 --------- d-----w c:\program files\MSXML 6.0
2008-12-11 15:49 --------- d-----w c:\program files\directx
2008-12-10 16:34 --------- dc-h--w c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2008-12-10 16:34 --------- d-----w c:\program files\Uniblue
2008-12-10 16:34 --------- d-----w c:\documents and settings\dell\Application Data\Uniblue
2008-12-10 16:26 --------- d-----w c:\program files\Wingen
2008-12-06 03:05 --------- d--h--r c:\documents and settings\dell\Application Data\SecuROM
2008-12-01 17:05 119,120 ----a-w c:\windows\dxsdkuninst.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-11-18 12:58 333192 --a------ c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-18 333192]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-11-18 333192]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-04-01 486856]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-15 68856]
"ares"="c:\program files\Ares\Ares.exe" [2009-01-03 893952]
"Uniblue RegistryBooster 2009"="c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe" [2008-08-29 1007104]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"Steam"="c:\valve\Steam\Steam.exe" [2003-11-11 1081344]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-01-10 2577840]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-05-25 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-05-25 126976]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\FlashFXP\\FlashFXP.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\WINDOWS\\system32\\drivers\\Wingen\\system.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [2008-10-17 104328]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6ead652e-b886-11dd-a9b9-001372987398}]
\Shell\AutoRun\command - ph.com
\Shell\explore\Command - ph.com
\Shell\open\Command - ph.com
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{B1C673EF-5999-4572-8255-E29D4A94C28D} - (no file)
HKLM-Run-BDWizReg - c:\program files\BitDefender\BitDefender 2009\bdwizreg.exe
HKLM-Run-CPM773fc7df - c:\windows\system32\gagoliro.dll
HKLM-Run-vewotunapu - c:\windows\system32\yahisiwe.dll
HKLM-Run-740cf443 - c:\windows\system32\pifapipa.dll
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {6CCE3920-3183-4B3D-808A-B12EB769DE12} - hxxp://www.commandondemand.com/eval/cod/cabs/cssweb.cab
FF - ProfilePath - c:\documents and settings\dell\Application Data\Mozilla\Firefox\Profiles\fn8dpgsu.default\
FF - component: c:\documents and settings\dell\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
FF - component: c:\program files\Nokia\Nokia PC Suite 7\bkmrksync\components\BkMrkExt.dll
FF - plugin: c:\program files\Microsoft Silverlight\npctrl.1.0.20926.0.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
---- PARAMETRES FIREFOX ----
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-02-06 21:49:00
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):7a,82,77,54,ff,32,ab,a9,70,f4,0b,dc,2f,14,8d,d1,f3,70,8c,e8,c0,
87,d5,94,fb,34,cc,b6,44,04,dd,ca,1f,02,0b,6a,24,b0,7b,33,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{cf8d0da6-32a8-436e-8d90-d9a86c953d9e}]
@Denied: (Full) (Everyone)
"Model"=dword:00000004
"Therad"=dword:0000001e
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\system32\wscntfy.exe
c:\program files\PC Connectivity Solution\ServiceLayer.exe
c:\program files\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\program files\PC Connectivity Solution\Transports\NclRSSrv.exe
c:\program files\Internet Download Manager\IEMonitor.exe
c:\program files\MSN Messenger\usnsvc.exe
c:\windows\SoftwareDistribution\Download\8d1470bed452b5d6aa1e9ba186868288\update\update.exe
c:\windows\SoftwareDistribution\Download\ddec8f7d123cd4e907c458df2b73ea48\update\update.exe
.
**************************************************************************
.
Heure de fin: 2009-02-06 21:57:36 - La machine a redémarré [dell]
ComboFix-quarantined-files.txt 2009-02-06 20:57:29
Avant-CF: 7,195,840,512 octets libres
Après-CF: 6,569,955,328 octets libres
279 --- E O F --- 2009-01-14 02:11:58
A toi merci car certains ne le font pas sa.
Biz