Mes amis
aprés l'excution de combofix et le redémarrge la connexion internet a coupé completement sur le PC infecté mais pas sur les autres
voici le rapport de Combofix et Hijack This aprés l'escecution de combofix
Combofix
ComboFix 09-02-12.03 - Cybermedi@ 2009-02-13 17:25:01.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.1527.1124 [GMT 1:00]
Lancé depuis: c:\documents and settings\Cybermedi@\Bureau\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated)
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated)
FW: ESET Personal firewall *disabled*
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
D:\Autorun.inf
[COLOR=RED] c:\windows\explorer.exe . . . est infecté!!/COLOR
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_Passthru
((((((((((((((((((((((((((((( Fichiers créés du 2009-01-13 au 2009-02-13 ))))))))))))))))))))))))))))))))))))
.
2009-02-13 16:14 . 2009-02-13 16:14 <REP> d-------- c:\documents and settings\Administrateur\Application Data\Malwarebytes
2009-02-13 16:01 . 2009-02-13 16:02 <REP> d-------- c:\windows\ERUNT
2009-02-13 15:58 . 2009-02-13 16:07 <REP> d-------- C:\SDFix
2009-02-13 15:56 . 2009-02-13 15:56 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-13 15:56 . 2009-02-13 15:56 <REP> d-------- c:\documents and settings\Cybermedi@\Application Data\Malwarebytes
2009-02-13 15:56 . 2009-02-13 15:56 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-13 15:56 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-13 15:56 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-13 15:42 . 2009-02-13 15:42 <REP> d-------- c:\program files\Panda Security
2009-02-13 15:42 . 2008-06-19 16:24 28,544 --a------ c:\windows\system32\drivers\pavboot.sys
2009-02-12 13:11 . 2009-02-12 13:12 437,038 --a------ C:\Dft32_User_Guide.pdf
2009-02-12 13:06 . 2009-02-12 13:10 <REP> d-------- c:\documents and settings\Administrateur\Application Data\IDM
2009-02-12 13:06 . 2009-02-12 13:10 <REP> d-------- c:\documents and settings\Administrateur\Application Data\DMCache
2009-02-12 12:24 . 2009-02-09 16:57 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage réseau
2009-02-12 12:24 . 2009-02-09 16:57 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage d'impression
2009-02-12 12:24 . 2009-02-09 16:24 <REP> d--h----- c:\documents and settings\Administrateur\Modèles
2009-02-12 12:24 . 2009-02-12 13:10 <REP> d-------- c:\documents and settings\Administrateur\Mes documents
2009-02-12 12:24 . 2009-02-09 16:57 <REP> dr------- c:\documents and settings\Administrateur\Menu Démarrer
2009-02-12 12:24 . 2009-02-09 16:57 <REP> d-------- c:\documents and settings\Administrateur\Favoris
2009-02-12 12:24 . 2009-02-13 16:04 <REP> d-------- c:\documents and settings\Administrateur\Bureau
2009-02-12 12:24 . 2009-02-12 12:24 <REP> d-------- c:\documents and settings\Administrateur
2009-02-12 12:21 . 2009-02-12 12:21 <REP> d-------- c:\documents and settings\Cybermedi@\Application Data\Lavasoft
2009-02-12 12:20 . 2009-02-12 12:20 <REP> d-------- c:\documents and settings\Cybermedi@\DoctorWeb
2009-02-12 12:03 . 2009-02-12 12:03 <REP> d-------- c:\program files\CCleaner
2009-02-12 10:22 . 2009-02-12 10:22 <REP> d-------- c:\windows\Sun
2009-02-12 10:21 . 2009-02-12 10:21 <REP> d-------- c:\program files\Java
2009-02-12 10:21 . 2009-02-12 10:21 410,984 --a------ c:\windows\system32\deploytk.dll
2009-02-12 10:21 . 2009-02-12 10:21 73,728 --a------ c:\windows\system32\javacpl.cpl
2009-02-12 09:36 . 2008-06-14 18:33 272,768 --------- c:\windows\system32\drivers\bthport.sys
2009-02-12 09:36 . 2008-06-14 18:33 272,768 -----c--- c:\windows\system32\dllcache\bthport.sys
2009-02-12 09:30 . 2008-08-14 14:23 2,191,232 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-12 09:30 . 2008-08-14 14:23 2,147,328 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-02-12 09:30 . 2008-08-14 14:23 2,068,096 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-12 09:30 . 2008-08-14 14:23 2,025,984 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2009-02-12 09:27 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2009-02-12 09:15 . 2005-06-28 10:21 22,752 --a------ c:\windows\system32\spupdsvc.exe
2009-02-11 21:15 . 2009-02-11 21:59 <REP> d-------- C:\TEMP
2009-02-11 17:21 . 2009-02-11 17:21 <REP> d-------- c:\program files\Yahoo!
2009-02-11 17:21 . 2009-02-11 17:23 <REP> d-------- c:\documents and settings\All Users\Application Data\Yahoo!
2009-02-11 16:37 . 2009-02-11 16:37 <REP> d-------- c:\program files\Fichiers communs\Adobe
2009-02-11 16:31 . 2007-05-23 16:54 260,248 --a------ c:\windows\system32\QMO.dll
2009-02-11 16:31 . 2007-05-23 16:54 92,312 --a------ c:\windows\system32\QMOCameraDll.dll
2009-02-11 16:31 . 2007-05-23 16:54 80,024 --a------ c:\windows\system32\TXGYUploader.dll
2009-02-10 22:41 . 2009-02-10 22:41 <REP> d-------- c:\documents and settings\Cybermedi@\Application Data\Media Player Classic
2009-02-10 17:07 . 2009-02-10 17:07 <REP> d-------- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-02-10 15:57 . 2009-02-13 15:34 69 --a------ c:\windows\NeroDigital.ini
2009-02-10 15:15 . 2009-02-10 15:15 <REP> d-------- c:\program files\Messenger Plus! Live
2009-02-10 15:15 . 2009-02-12 09:18 <REP> d-------- c:\program files\Circle Developement
2009-02-10 14:21 . 2009-02-10 14:21 <REP> d-------- c:\program files\K-Lite Codec Pack
2009-02-10 13:19 . 2009-02-10 13:19 <REP> d-------- c:\documents and settings\Cybermedi@\Application Data\Ahead
2009-02-10 12:52 . 2009-02-13 17:18 <REP> d-------- c:\program files\Internet Download Manager
2009-02-10 12:52 . 2009-02-10 12:52 <REP> d-------- c:\documents and settings\Cybermedi@\Application Data\IDM
2009-02-10 12:38 . 2009-02-10 12:38 <REP> d-------- c:\program files\Nero
2009-02-10 12:38 . 2009-02-10 12:40 <REP> d-------- c:\program files\Fichiers communs\Ahead
2009-02-10 12:30 . 2008-04-13 11:46 85,248 --a------ c:\windows\system32\drivers\NABTSFEC.sys
2009-02-10 12:30 . 2008-04-13 11:46 19,200 --a------ c:\windows\system32\drivers\WSTCODEC.SYS
2009-02-10 12:30 . 2008-04-13 11:46 17,024 --a------ c:\windows\system32\drivers\CCDECODE.sys
2009-02-10 12:30 . 2008-04-13 19:34 16,384 --a------ c:\windows\system32\ipsink.ax
2009-02-10 12:30 . 2008-04-13 11:46 15,232 --a------ c:\windows\system32\drivers\StreamIP.sys
2009-02-10 12:30 . 2008-04-13 11:46 11,136 --a------ c:\windows\system32\drivers\SLIP.sys
2009-02-10 12:30 . 2008-04-13 11:46 10,880 --a------ c:\windows\system32\drivers\NdisIP.sys
2009-02-10 12:30 . 2008-04-13 11:39 5,504 --a------ c:\windows\system32\drivers\MSTEE.sys
2009-02-10 12:27 . 2008-04-13 19:34 92,160 --a------ c:\windows\system32\kswdmcap.ax
2009-02-10 12:27 . 2008-04-13 19:34 61,952 --a------ c:\windows\system32\kstvtune.ax
2009-02-10 12:27 . 2008-04-13 19:33 54,784 --a------ c:\windows\system32\vfwwdm32.dll
2009-02-10 12:27 . 2008-04-13 19:34 43,008 --a------ c:\windows\system32\ksxbar.ax
2009-02-10 12:27 . 2008-04-13 19:34 28,672 --a------ c:\windows\system32\vidcap.ax
2009-02-10 12:26 . 2009-02-11 21:00 <REP> d-------- c:\program files\Fichiers communs\snpstd3
2009-02-10 12:26 . 2009-02-10 12:26 <REP> d-------- c:\documents and settings\Cybermedi@\Application Data\InstallShield
2009-02-10 12:26 . 2007-07-25 16:59 10,372,096 --a------ c:\windows\system32\drivers\snpstd3.sys
2009-02-10 12:26 . 2007-05-10 13:18 835,584 --------- c:\windows\VSNPSTD3.EXE
2009-02-10 12:26 . 2007-04-21 09:37 270,336 --a------ c:\windows\TSNPSTD3.EXE
2009-02-10 12:26 . 2007-07-23 18:04 155,648 --a------ c:\windows\system32\rsnpstd3.dll
2009-02-10 12:26 . 2006-07-03 10:31 98,304 --a------ c:\windows\AMCAP.EXE
2009-02-10 12:26 . 2007-07-23 17:52 57,344 --a------ c:\windows\system32\vsnpstd3.dll
2009-02-10 12:26 . 2005-11-23 13:55 53,248 --a------ c:\windows\system32\csnpstd3.dll
2009-02-10 12:26 . 2005-11-23 13:55 53,248 --a------ c:\windows\csnpstd3.dll
2009-02-10 12:26 . 2007-07-11 16:09 20,480 --a------ c:\windows\FIXCAMERA.EXE
2009-02-10 12:26 . 2004-02-27 17:36 15,498 --a------ c:\windows\snpstd3.ini
2009-02-10 12:26 . 2004-02-27 17:36 13,023 --a------ c:\windows\snpstd3.src
2009-02-10 11:32 . 2006-10-26 19:58 30,512 --a------ c:\windows\system32\mdimon.dll
2009-02-10 11:31 . 2009-02-10 11:31 <REP> d-------- c:\program files\MSBuild
2009-02-10 11:31 . 2009-02-10 11:31 <REP> d-------- c:\program files\Microsoft Works
2009-02-10 11:28 . 2009-02-10 11:31 <REP> d-------- c:\windows\SHELLNEW
2009-02-10 11:27 . 2009-02-10 11:27 <REP> dr-h----- C:\MSOCache
2009-02-10 11:27 . 2009-02-10 11:32 <REP> d-------- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-02-10 11:20 . 2009-02-10 11:33 <REP> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2009-02-10 11:17 . 2009-02-10 13:02 <REP> d-------- c:\program files\Trojan Remover
2009-02-10 11:17 . 2006-05-25 14:52 162,304 --a------ c:\windows\system32\ztvunrar36.dll
2009-02-10 11:17 . 2003-02-02 19:06 153,088 --a------ c:\windows\system32\UNRAR3.dll
2009-02-10 11:17 . 2005-08-26 00:50 77,312 --a------ c:\windows\system32\ztvunace26.dll
2009-02-10 11:17 . 2002-03-06 00:00 75,264 --a------ c:\windows\system32\unacev2.dll
2009-02-10 11:17 . 2006-06-19 12:01 69,632 --a------ c:\windows\system32\ztvcabinet.dll
2009-02-10 11:12 . 2009-02-10 11:12 128 --a------ c:\windows\system32\356.tmp
2009-02-10 11:01 . 2009-02-10 11:01 128 --a------ c:\windows\system32\96.tmp
2009-02-10 10:10 . 2009-02-10 10:10 128 --a------ c:\windows\system32\3C.tmp
2009-02-10 10:10 . 2009-02-10 10:10 0 --a------ c:\windows\system32\45.tmp
2009-02-10 10:09 . 2009-02-11 07:34 130 --a------ c:\windows\adobe.bat
2009-02-10 10:09 . 2009-02-10 10:09 128 --a------ c:\windows\system32\31.tmp
2009-02-10 10:09 . 2009-02-10 10:09 0 --a------ c:\windows\_id.dat
2009-02-10 09:47 . 2009-02-11 21:02 <REP> d-------- c:\program files\Spybot - Search & Destroy
2009-02-10 09:47 . 2009-02-12 12:19 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-10 09:32 . 2009-02-10 09:32 128 --a------ c:\windows\system32\D2.tmp
2009-02-10 09:31 . 2009-02-10 09:31 <REP> d-------- c:\program files\Trend Micro
2009-02-10 09:17 . 2009-02-12 09:50 <REP> d-------- c:\windows\BDOSCAN8
2009-02-10 09:05 . 2009-02-10 09:05 128 --a------ c:\windows\system32\30.tmp
2009-02-10 08:01 . 2009-02-10 08:01 0 --a------ c:\windows\system32\AE.tmp
2009-02-10 06:59 . 2009-02-10 06:59 172 --a------ c:\windows\system32\A2.tmp
2009-02-10 06:41 . 2009-02-10 06:41 0 --a------ c:\windows\system32\9F.tmp
2009-02-10 06:38 . 2009-02-10 06:38 172 --a------ c:\windows\system32\93.tmp
2009-02-10 06:24 . 2009-02-10 06:24 0 --a------ c:\windows\system32\90.tmp
2009-02-10 06:22 . 2009-02-10 06:22 172 --a------ c:\windows\system32\82.tmp
2009-02-10 06:22 . 2009-02-10 06:22 0 --a------ c:\windows\system32\8E.tmp
2009-02-10 06:22 . 2009-02-10 06:22 0 --a------ c:\windows\system32\85.tmp
2009-02-10 06:21 . 2009-02-10 06:22 172 --a------ c:\windows\system32\75.tmp
2009-02-10 05:47 . 2009-02-10 05:47 0 --a------ c:\windows\system32\5D.tmp
2009-02-10 05:44 . 2009-02-10 05:44 172 --a------ c:\windows\system32\51.tmp
2009-02-10 05:30 . 2009-02-10 05:30 0 --a------ c:\windows\system32\37.tmp
2009-02-10 04:53 . 2009-02-10 04:53 0 --a------ c:\windows\system32\758C.tmp
2009-02-10 04:51 . 2009-02-10 04:51 172 --a------ c:\windows\system32\7586.tmp
2009-02-10 04:51 . 2009-02-10 04:51 0 --a------ c:\windows\system32\7588.tmp
2009-02-10 04:49 . 2009-02-10 04:49 0 --a------ c:\windows\system32\7583.tmp
2009-02-10 04:46 . 2009-02-10 04:46 172 --a------ c:\windows\system32\757D.tmp
2009-02-10 04:46 . 2009-02-10 04:46 0 --a------ c:\windows\system32\757F.tmp
2009-02-10 04:04 . 2009-02-10 04:04 0 --a------ c:\windows\system32\74F6.tmp
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-12 12:33 155,648 ----a-w c:\windows\system32\wscript.exe
2009-02-12 12:33 135,168 ----a-w c:\windows\system32\cscript.exe
2009-02-11 20:02 --------- d-----w c:\program files\Windows Media Connect 2
2009-02-10 16:07 90,112 ----a-w c:\windows\DUMP3c6c.tmp
2009-02-10 09:58 90,112 ----a-w c:\windows\DUMP35b6.tmp
2009-02-10 08:19 90,112 ----a-w c:\windows\DUMP3884.tmp
2009-02-10 08:02 90,112 ----a-w c:\windows\DUMP3539.tmp
2009-02-10 04:17 90,112 ----a-w c:\windows\DUMP474a.tmp
2009-02-10 01:44 90,112 ----a-w c:\windows\DUMP3558.tmp
2009-02-10 01:40 90,112 ----a-w c:\windows\DUMP3df3.tmp
2009-02-10 01:32 90,112 ----a-w c:\windows\DUMP33e1.tmp
2009-02-09 20:48 90,112 ----a-w c:\windows\DUMP32f6.tmp
2009-02-09 15:28 --------- d-----w c:\program files\microsoft frontpage
2009-02-09 15:26 --------- d-----w c:\program files\Services en ligne
2009-01-22 14:49 206,256 ----a-w c:\windows\system32\idmmbc.dll
.
------- Sigcheck -------
2008-04-13 18:34 1037824 34d64cb8a5bcd3f5262d0cf9b14fed0e c:\windows\EXPLORER.EXE
2008-04-13 18:34 1054208 0f6069c320bb8deef916642f33af7994 c:\windows\system32\dllcache\explorer.exe
2008-04-13 18:34 15360 aa0163de6e56e278979c3db01a21bda0 c:\windows\system32\ctfmon.exe
2008-04-13 18:34 31744 15e01529691e92477d5945d49a6b0588 c:\windows\system32\dllcache\ctfmon.exe
2008-04-13 18:34 26624 084363967d39a56091b5fdbe6a920260 c:\windows\system32\USERINIT.EXE
2009-02-12 13:33 26624 c60b2f6c494fd9aa2c45d4efea2d0aa4 c:\windows\system32\dllcache\userinit.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Caffe-Server"="c:\program files\Caffe\Server.exe" [2009-02-09 5405696]
"IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2009-02-10 2745776]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-07-01 1447168]
"FixCamera"="c:\windows\FixCamera.exe" [2007-07-11 20480]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2007-04-21 270336]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ rmvirut.nt
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\kcxrjmoq.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
c:\windows\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2007-05-11 03:06 40048 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2006-11-16 19:04 139264 c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2008-04-13 18:34 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 2006-10-06 12:13 114688 c:\windows\system32\hkcmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IDMan]
--a------ 2009-02-10 13:31 2745776 c:\program files\Internet Download Manager\IDMan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 2006-10-06 12:11 98304 c:\windows\system32\igfxtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
--a------ 2008-10-16 21:57 4347120 c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 11:34 5724184 c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 15:40 155648 c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
--a------ 2006-10-06 12:10 110592 c:\windows\system32\igfxpers.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snpstd3]
--------- 2007-05-10 13:18 835584 c:\windows\VSNPSTD3.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2009-01-26 15:31 2144088 c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2009-02-12 10:21 148888 c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tsnpstd3]
--a------ 2007-04-21 09:37 270336 c:\windows\TSNPSTD3.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
--a------ 2005-05-03 18:43 69632 c:\windows\Alcmtr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
--a------ 2006-10-30 19:49 16269312 c:\windows\RTHDCPL.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
--a------ 2006-05-16 18:04 2882560 c:\windows\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Caffe\\Server.exe"=
R0 kcxrjmoq;kcxrjmoq;c:\windows\system32\drivers\kcxrjmoq.sys [2009-02-09 33920]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-02-13 28544]
R1 BIOS;BIOS;c:\windows\system32\drivers\BIOS.sys [2009-02-09 13696]
R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2008-07-01 468224]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKU-Default-Run-services - c:\windows\services.exe
MSConfigStartUp-AVG8_TRAY - c:\progra~1\AVG\AVG8\avgtray.exe
MSConfigStartUp-Rxuxobeyitamewi - c:\windows\Bsosuy.dll
MSConfigStartUp-services - c:\windows\SERVICES.EXE
.
------- Examen supplémentaire -------
.
uInternet Settings,ProxyOverride = local
uInternet Settings,ProxyServer = 127.0.0.1:9666
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Télécharger avec IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: Télécharger le contenu de video FLV avec IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Télécharger tous les liens avec IDM - c:\program files\Internet Download Manager\IEGetAll.htm
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
FF - ProfilePath - c:\documents and settings\Cybermedi@\Application Data\Mozilla\Firefox\Profiles\7jnfpkmt.default\
FF - component: c:\documents and settings\Cybermedi@\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-13 17:28:22
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\mdm.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2009-02-13 17:29:45 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-02-13 16:29:43
Avant-CF: 35,723,550,720 octets libres
Après-CF: 35,767,373,824 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
294 --- E O F --- 2009-02-12 19:00:38
Hijack This
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:36:43, on 13/02/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ESET\ESET Smart Security\ekrn.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\mdm.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\ESET\ESET Smart Security\egui.exe
C:\WINDOWS\FixCamera.exe
C:\WINDOWS\tsnpstd3.exe
C:\Program Files\Internet Download Manager\IDMan.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Download Manager\IEMonitor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:9666
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe
O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
O4 - HKCU\..\Run: [Caffe-Server] C:\Program Files\Caffe\Server.exe
O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Télécharger avec IDM - C:\Program Files\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: Télécharger le contenu de video FLV avec IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
O8 - Extra context menu item: Télécharger tous les liens avec IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O23 - Service: avp - Kaspersky Lab - D:\Mes Documents\Downloads\Compressed\1227KASPAV2009PO_www.softarchive.net\1227KASPAV2009PO_www.softarchive.net\Setup\Portable KAV\avp.exe
O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe
O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
End of file - 5567 bytes