Merci gen-hackman pour la procedure de combofix
mon pc est plus rapide et pour le moment tout semble ok
Cordialement
ComboFix 09-02-17.02 - Propriétaire 2009-02-18 21:08:04.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.959.573 [GMT 1:00]
Running from: c:\documents and settings\Propriétaire\Bureau\moi.exe
AV: avast! antivirus 4.8.1335 [VPS 090217-0] *On-access scanning disabled* (Updated)
AV: Bitdefender Antivirus *On-access scanning enabled* (Updated)
FW: ZoneAlarm Firewall *disabled*
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\INSTALL.LOG
c:\windows\Downloaded Program Files\ODCTOOLS
c:\windows\pack.epk
c:\windows\system32\_004437_.tmp.dll
c:\windows\system32\_004438_.tmp.dll
c:\windows\system32\_004439_.tmp.dll
c:\windows\system32\_004440_.tmp.dll
c:\windows\system32\_004447_.tmp.dll
c:\windows\system32\_004448_.tmp.dll
c:\windows\system32\_004449_.tmp.dll
c:\windows\system32\_004450_.tmp.dll
c:\windows\system32\_004452_.tmp.dll
c:\windows\system32\_004453_.tmp.dll
c:\windows\system32\_004456_.tmp.dll
c:\windows\system32\_004457_.tmp.dll
c:\windows\system32\_004459_.tmp.dll
c:\windows\system32\_004460_.tmp.dll
c:\windows\system32\_004461_.tmp.dll
c:\windows\system32\_004463_.tmp.dll
c:\windows\system32\_004466_.tmp.dll
c:\windows\system32\_004467_.tmp.dll
c:\windows\system32\_004471_.tmp.dll
c:\windows\system32\_004472_.tmp.dll
c:\windows\system32\_004474_.tmp.dll
c:\windows\system32\_004477_.tmp.dll
c:\windows\system32\_004479_.tmp.dll
c:\windows\system32\_004480_.tmp.dll
c:\windows\system32\_004481_.tmp.dll
c:\windows\system32\_004482_.tmp.dll
c:\windows\system32\_004483_.tmp.dll
c:\windows\system32\_004486_.tmp.dll
c:\windows\system32\_004487_.tmp.dll
c:\windows\system32\_004488_.tmp.dll
c:\windows\system32\_004489_.tmp.dll
c:\windows\system32\_004490_.tmp.dll
c:\windows\system32\_004495_.tmp.dll
c:\windows\system32\_004497_.tmp.dll
c:\windows\system32\d3d8caps.dat
.
((((((((((((((((((((((((( Files Created from 2009-01-18 to 2009-02-18 )))))))))))))))))))))))))))))))
.
2009-02-18 09:30 . 2009-02-18 09:30 <REP> d-------- c:\documents and settings\Propriétaire\Application Data\Malwarebytes
2009-02-18 09:30 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-18 09:30 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-18 09:29 . 2009-02-18 09:29 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-16 12:34 . 2009-02-16 12:34 21 --a------ c:\windows\kit.ini
2009-02-16 12:32 . 2009-02-16 12:34 <REP> d-------- c:\program files\Wanadoo
2009-02-12 19:22 . 2009-02-12 20:53 <REP> d-------- c:\documents and settings\Propriétaire\Application Data\XnView
2009-02-12 18:51 . 2004-10-06 14:08 606,208 --a------ c:\windows\system32\BtnPlus1.ocx
2009-02-12 18:51 . 2004-10-06 14:24 471,040 --a------ c:\windows\system32\FraPlus1.ocx
2009-02-12 18:51 . 2006-05-11 02:22 233,472 --a------ c:\windows\system32\ZNsofttool2003.ocx
2009-02-12 18:51 . 2006-04-17 00:06 225,280 --a------ c:\windows\system32\ZNsoftMenu2003.ocx
2009-02-12 18:45 . 2009-02-12 18:49 <REP> d-------- c:\documents and settings\Propriétaire\Application Data\IcoFX
2009-02-08 19:18 . 2009-02-08 19:18 <REP> d-------- c:\program files\JRE
2009-02-05 11:00 . 2009-02-05 11:00 <REP> d--hs---- c:\documents and settings\Propriétaire\IETldCache
2009-02-05 11:00 . 2009-02-05 11:00 <REP> d--hs---- c:\documents and settings\Propriétaire\IETldCache
2009-02-05 10:50 . 2009-02-05 10:53 <REP> d--h-c--- c:\windows\ie8
2009-02-03 12:47 . 2009-02-03 12:47 <REP> d-------- c:\program files\Windows Installer 4.5 SDK
2009-01-26 21:32 . 2009-01-26 21:32 <REP> d-------- c:\documents and settings\Propriétaire\Application Data\Samsung
2009-01-26 21:09 . 2006-05-03 22:53 174,592 --a------ c:\windows\system32\framedyn.dll
2009-01-26 21:07 . 2009-01-26 21:30 5,632 --a------ c:\windows\system32\drivers\StarOpen.sys
2009-01-26 20:25 . 2005-08-30 01:49 94,000 --a------ c:\windows\system32\drivers\ssm_mdm.sys
2009-01-26 20:25 . 2005-08-30 01:47 58,320 --a------ c:\windows\system32\drivers\ssm_bus.sys
2009-01-26 20:25 . 2005-08-30 01:49 8,336 --a------ c:\windows\system32\drivers\ssm_mdfl.sys
2009-01-26 20:25 . 2005-08-30 01:49 6,176 --a------ c:\windows\system32\drivers\ssm_cmnt.sys
2009-01-26 20:25 . 2005-08-30 01:49 6,176 --a------ c:\windows\system32\drivers\ssm_cm.sys
2009-01-26 20:25 . 2005-08-30 01:47 5,840 --a------ c:\windows\system32\drivers\ssm_whnt.sys
2009-01-26 20:25 . 2005-08-30 01:47 5,840 --a------ c:\windows\system32\drivers\ssm_wh.sys
2009-01-26 20:24 . 2009-01-26 21:09 <REP> d-------- c:\windows\system32\Samsung_USB_Drivers
2009-01-26 20:24 . 2005-08-28 20:51 766 --a------ c:\windows\system32\Uninstall.ico
2009-01-26 15:28 . 2009-01-26 15:28 <REP> d-------- c:\program files\Microsoft Silverlight
2009-01-22 14:51 . 2009-02-02 09:38 <REP> d-------- C:\tmp
2009-01-22 12:16 . 2009-01-22 12:18 <REP> d-------- c:\documents and settings\Propriétaire\Application Data\vlc
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-18 20:36 22,431,776 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-02-18 20:16 263,804 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-02-18 18:34 --------- d-----w c:\documents and settings\LocalService\Application Data\SACore
2009-02-18 18:02 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-18 16:34 161,792 ----a-w c:\windows\Internet Logs\xDB1.tmp
2009-02-17 08:08 --------- d-----w c:\program files\Mozilla Firefox 3 Beta 1
2009-02-17 07:04 4,291,365 ----a-w c:\windows\Internet Logs\tvDebug.zip
2009-02-14 18:22 --------- d-----w c:\program files\Windows Live
2009-02-08 18:17 --------- d-----w c:\program files\OpenOffice.org 3
2009-01-26 20:07 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-26 19:23 --------- d-----w c:\program files\Fichiers communs\InstallShield
2009-01-12 10:21 --------- d-----w c:\documents and settings\Propriétaire\Application Data\WinPatrol
2009-01-01 20:41 1,409 ----a-w c:\windows\Fonts\SncfPre.fot
2008-12-23 08:51 --------- d-----w c:\program files\McAfee
2008-12-23 07:44 --------- d-----w c:\documents and settings\All Users\Application Data\SiteAdvisor
2008-12-22 12:38 --------- d-----w c:\documents and settings\All Users\Application Data\McAfee
2008-12-22 12:37 --------- d-----w c:\program files\Fichiers communs\McAfee
2008-12-21 20:21 --------- d-----w c:\documents and settings\Propriétaire\Application Data\OpenOffice.org
2008-12-21 19:11 --------- d-----w c:\documents and settings\Propriétaire\Application Data\OpenOffice.org2
2008-12-18 19:48 --------- d-----w c:\program files\Fichiers communs\Windows Live
2008-12-04 09:21 15,600 ----a-w c:\windows\gdrv.sys
2008-04-14 09:44 155,536 ----a-w c:\documents and settings\Propriétaire\sfdrvrem.exe
2008-04-14 09:44 155,536 ----a-w c:\documents and settings\Propriétaire\sfdrvrem.exe
2004-10-01 13:00 40,960 ----a-w c:\program files\Uninstall_CDS.exe
2001-10-05 10:53 21,866 ----a-w c:\program files\Fichiers communs\tppupd2k.dll
2008-05-07 11:48 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008050720080508\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-27 68856]
"Google Update"="c:\documents and settings\Propriétaire\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-01-16 133104]
"SpybotSD TeaTimer"="c:\programmes divers\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TPP Auto Loader"="c:\windows\tppaldr.exe" [2001-10-05 118784]
"CoolSwitch"="c:\windows\system32\taskswitch.exe" [2002-03-19 45632]
"avast!"="c:\progra~2\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-10-24 144792]
"BDMCon"="c:\progra~1\Softwin\BITDEF~1\bdmcon.exe" [2007-08-06 290816]
"BDAgent"="c:\program files\Softwin\BitDefender10\bdagent.exe" [2007-03-26 69632]
"SecurDisc"="c:\program files\Nero\Nero 7\InCD\NBHGui.exe" [2007-05-15 1628208]
"NeroFilterCheck"="c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
"InCD"="c:\program files\Nero\Nero 7\InCD\InCD.exe" [2007-05-15 1057328]
"ORAHSSSessionManager"="c:\program files\OrangeHSS\SessionManager\SessionManager.exe" [2007-10-16 102400]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-12-13 919016]
"WinPatrol"="c:\programmes divers\BillP Studios\WinPatrol\winpatrol.exe" [2008-10-09 333120]
"SoundMan"="SOUNDMAN.EXE" [2004-02-09 c:\windows\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"DWQueuedReporting"="c:\progra~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=sockspy.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\[u]0/ulsdelete\[u]0/uaswBoot.exe /M:55e74b2cb\[u]0/u
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^DSLMON.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HPAiODevice(hp psc 700 series) - 1.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^NewShortcut12.lnk]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox 3 Beta 1\\firefox.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\OrangeHSS\\Connectivity\\ConnectivityManager.exe"=
"c:\\Programmes divers\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-04-05 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-04-05 20560]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2008-12-22 206096]
R3 PAC207;SoC PC-Camer@;c:\windows\system32\drivers\PFC027.sys [2005-02-24 162176]
R3 WacomVHidPen;Wacom Virtual HID Digitizer Driver;c:\windows\system32\drivers\wacomvhidpen.sys [2006-08-02 9216]
S3 cpuz129;cpuz129;c:\programmes divers\PC Wizard 2008\pcwiz32.sys [2008-06-12 9600]
S3 phil2vid;phil2vid;c:\windows\system32\drivers\philcam2.sys [2006-08-01 173696]
S3 TPP200;USB Storage Adapter V2 (TPP);c:\windows\system32\drivers\TPP200.SYS [2007-06-26 35541]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1f72b059-218a-11db-887f-00112ff1ae6f}]
\Shell\AutoRun\command - F:\Setup.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-01-27 c:\windows\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1227786419.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-06 00:52]
2009-02-18 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1177238915-1275210071-839522115-1003.job
- c:\documents and settings\Propri []
2009-02-18 c:\windows\Tasks\User_Feed_Synchronization-{F21DA4CC-23C8-4E24-9AD6-7CD777A16940}.job
- c:\windows\system32\msfeedssync.exe [2009-01-15 02:01]
.
.
------- Supplementary Scan -------
.
uStart Page = about:blank
uDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: { - c:\program files\Messenger\msmsgs.exe
DPF: CabBuilder - hxxp://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
FF - ProfilePath - c:\documents and settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\lila2p3b.default\
FF - prefs.js: browser.startup.homepage -
FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?mkt=fr-FR&FORM=MIMWA2&q=
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\program files\Mozilla Firefox 3 Beta 1\plugins\NPMyrMus.dll
FF - plugin: c:\programmes divers\Google\Picasa3\npPicasa2.dll
FF - plugin: c:\programmes divers\Google\Picasa3\npPicasa3.dll
---- FIREFOX POLICIES ----
FF - user.js: network.proxy.type - 0
FF - user.js: browser.shell.checkDefaultBrowser - false
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-18 21:35:43
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\Applications\WINWORD.EXE\TaskbarExceptionsIcons]
@DACL=(02 0000)
[HKEY_LOCAL_MACHINE\software\Microsoft\Advanced INF Setup\IE40.BrowseUI\RegBackup]
@DACL=(02 0000)
.
------------------------ Other Running Processes ------------------------
.
c:\programmes divers\Alwil Software\Avast4\aswUpdSv.exe
c:\programmes divers\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\FTRTSVC.exe
c:\program files\Nero\Nero 7\InCD\InCDsrv.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\PAStiSvc.exe
c:\windows\system32\Tablet.exe
c:\program files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
c:\program files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
c:\program files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
c:\program files\Softwin\BitDefender10\vsserv.exe
.
**************************************************************************
.
Completion time: 2009-02-18 21:40:36 - machine was rebooted [Propriétaire]
ComboFix-quarantined-files.txt 2009-02-18 20:40:29
Pre-Run: 147,428,859,904 octets libres
Post-Run: 147,343,536,128 octets libres
Current=1 Default=1 Failed=0 LastKnownGood=4 Sets=1,2,3,4
240 --- E O F --- 2009-02-11 19:45:44