Merci Anthony,
Voici le rapport:
ComboFix 09-03-15.01 - Asus 2009-03-17 13:48:24.1 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.3070.1903 [GMT 1:00]
Lancé depuis: c:\users\Asus\Desktop\C-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\recycler\S-7-6-68-100011081-100017854-100011048-4585.com
c:\windows\system32\404Fix.exe
c:\windows\system32\acovcnt.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\drivers\gaopdxotepxixmonitvjyxpcnmbjfpbfrrblst.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\gaopdxqoqduqwsmppqomxhqpttxcsckhulmdpc.dll
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\skinboxer43.dll
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
c:\windows\the123.dll
D:\Autorun.inf
d:\recycler\S-7-6-68-100011081-100017854-100011048-4585.com
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_gaopdxserv.sys
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-17 au 2009-03-17 ))))))))))))))))))))))))))))))))))))
.
2009-03-17 13:39 . 2009-03-17 13:40 <REP> d-------- C:\32788R22FWJFW
2009-03-15 20:37 . 2009-03-15 20:37 <REP> d-------- c:\programdata\Malwarebytes
2009-03-15 20:37 . 2009-03-15 20:37 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-15 20:37 . 2009-02-11 10:19 38,496 --a------ c:\windows\System32\drivers\mbamswissarmy.sys
2009-03-15 20:37 . 2009-02-11 10:19 15,504 --a------ c:\windows\System32\drivers\mbam.sys
2009-03-15 18:48 . 2009-03-15 18:48 56 --ah----- c:\windows\System32\ezsidmv.dat
2009-03-15 10:54 . 2009-03-15 10:54 <REP> d-------- c:\program files\Sony Setup
2009-03-11 17:37 . 2009-03-11 17:38 <REP> d-------- C:\rsit
2009-03-11 17:37 . 2009-03-11 17:57 <REP> d-------- c:\program files\trend micro
2009-03-06 18:13 . 2009-03-06 18:13 <REP> d-------- c:\windows\BDOSCAN8
2009-03-05 23:14 . 2009-03-17 13:47 4 --a------ c:\windows\System32\gaopdxcounter
2009-03-04 22:26 . 2009-03-04 22:34 <REP> d-------- c:\program files\MagicISO
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-17 12:32 --------- d-----w c:\programdata\Avg8
2009-03-16 19:33 --------- d-----w c:\users\Asus\AppData\Roaming\Skype
2009-03-16 17:04 --------- d-----w c:\users\Asus\AppData\Roaming\skypePM
2009-03-15 08:03 --------- d-----w c:\users\Asus\AppData\Roaming\Azureus
2009-03-14 21:00 --------- d-----w c:\program files\Azureus
2009-03-04 20:11 --------- d-----w c:\program files\Mp3 Song Plays Increaser
2009-02-17 12:17 --------- d-----w c:\program files\FriendBlasterPro
2009-02-12 17:06 --------- d-----w c:\users\Asus\AppData\Roaming\dvdcss
2009-02-12 02:01 --------- d-----w c:\programdata\Microsoft Help
2009-02-12 02:00 --------- d-----w c:\program files\Windows Mail
2009-02-10 19:44 --------- d-----w c:\program files\Search Settings
2009-02-07 15:13 --------- d-----w c:\program files\Atomic Email Hunter
2009-02-07 14:06 --------- d-----w c:\users\Asus\AppData\Roaming\Download Manager
2009-02-06 22:27 --------- d-----w c:\program files\VideoPostRobot
2009-02-05 21:57 --------- d-----w c:\users\Asus\AppData\Roaming\FileZilla
2009-01-31 03:12 325,128 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-01-29 02:00 --------- d-----w c:\program files\MSXML 4.0
2009-01-28 19:42 --------- d-----w c:\program files\EmailList Master
2009-01-27 20:37 --------- d-----w c:\users\Asus\AppData\Roaming\Nero
2009-01-27 20:24 --------- d-----w c:\programdata\LightScribe
2009-01-27 20:13 --------- d-----w c:\program files\Common Files\Nero
2009-01-27 19:49 --------- d-----w c:\program files\Nero
2009-01-27 19:39 --------- d-----w c:\programdata\Nero
2009-01-26 20:17 --------- d-----w c:\program files\Common Files\Adobe
2009-01-20 10:34 --------- d-----w c:\program files\MFB-MySpace Friend Bomber
2009-01-19 00:00 --------- d-----w c:\users\Asus\AppData\Roaming\NCH Software
2009-01-18 23:59 --------- d-----w c:\programdata\NCH Software
2009-01-18 23:58 --------- d-----w c:\program files\NCH Software
2009-01-18 23:43 --------- d-----w c:\users\Asus\AppData\Roaming\Xilisoft Corporation
2009-01-18 17:12 --------- d-----w c:\program files\FileZilla FTP Client
2009-01-17 20:46 --------- d-----w c:\programdata\eMule
2008-09-30 08:44 96,254 ----a-w c:\program files\Common Files\Engines.lnl
2008-01-21 02:43 174 --sha-w c:\program files\desktop.ini
2006-11-30 13:49 368,640 ----a-w c:\users\Asus\AppData\Roaming\Rewire.dll
2006-11-30 13:49 233,472 ----a-w c:\users\Asus\AppData\Roaming\REX Shared Library.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{E312764E-7706-43F1-8DAB-FCDD2B1E416D}"= "c:\program files\Search Settings\kb127\SearchSettings.dll" [2008-06-12 1111904]
[HKEY_CLASSES_ROOT\clsid\{e312764e-7706-43f1-8dab-fcdd2b1e416d}]
[HKEY_CLASSES_ROOT\SearchSettings.BHO.1]
[HKEY_CLASSES_ROOT\TypeLib\{CD082CCA-086F-4FD8-8FD7-247A0DBBD1CC}]
[HKEY_CLASSES_ROOT\SearchSettings.BHO]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
2008-06-12 16:57 1111904 --a------ c:\program files\Search Settings\kb127\SearchSettings.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2008-06-09 2363392]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]
"Audio Kontrol 1"="c:\program files\Native Instruments\Audio Kontrol 1\Audio Kontrol 1.exe" [2006-09-18 6336512]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CLMLServer"="c:\program files\CyberLink\Power2Go\CLMLSvc.exe" [2008-07-19 104936]
"P2Go_Menu"="c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
"HControlUser"="c:\program files\ATK Hotkey\HcontrolUser.exe" [2008-01-12 98304]
"ATKOSD2"="c:\program files\ATKOSD2\ATKOSD2.exe" [2008-01-23 7766016]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2008-01-25 1208320]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2007-12-07 1029416]
"CognizanceTS"="c:\progra~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll" [2003-12-22 17920]
"ATKMEDIA"="c:\program files\ASUS\ATK Media\DMEDIA.EXE" [2008-02-01 61440]
"PowerForPhone"="c:\program files\P4P\P4P.exe" [2007-08-03 778240]
"ASUS Screen Saver Protector"="c:\windows\AsScrPro.exe" [2008-09-07 3054136]
"ASUS Camera ScreenSaver"="c:\windows\AsScrProlog.exe" [2008-09-07 47672]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-31 1601304]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"H2O"="c:\program files\SyncroSoft\Pos\H2O\cledx.exe" [2005-10-23 385024]
"SearchSettings"="c:\program files\Search Settings\SearchSettings.exe" [2008-06-12 991584]
"RtHDVCpl"="RtHDVCpl.exe" [2008-04-01 c:\windows\RtHDVCpl.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=APSHook.dll avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3codecp"= l3codecp.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli ASWLNPkg
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{88C5F668-6BAE-4B65-8A29-209ACD7F1732}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{5A22F50C-2040-4BD1-B483-02CDD23A982F}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"{622F8411-8450-40AC-9234-92FC46C1FCE7}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{31B78C56-8CE5-4737-A8C9-C2E2C06CBC4D}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{D49399F6-1BF3-43E4-A7E8-E9D61421CE7C}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{3E72BC3D-FEA5-411E-82A2-F5D81C2B926F}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{74E5D688-3AB8-40D5-876F-0905BB16453A}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{FE75BAEB-B68B-4944-8F0E-91C4AEBB7BBD}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{852D4DCB-4E67-4847-8795-3593A7A5C524}"= c:\program files\Skype\Phone\Skype.exe:Skype
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [2008-11-07 325128]
R2 ASBroker;Logon Session Broker;c:\windows\System32\svchost.exe -k Cognizance [2008-01-21 21504]
R2 ASChannel;Local Communication Channel;c:\windows\System32\svchost.exe -k Cognizance [2008-01-21 21504]
R3 CLEDX;Team H2O CLEDX service;c:\windows\System32\drivers\cledx.sys [2008-11-11 33792]
R3 NETw5v32;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 32 Bit ;c:\windows\System32\drivers\NETw5v32.sys [2008-04-28 3658752]
S3 ak1avs;ak1avs;c:\windows\System32\drivers\ak1avs.sys [2008-11-11 25088]
S3 ak1usb;ak1usb;c:\windows\System32\drivers\ak1usb.sys [2008-11-11 84992]
S4 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-11-07 298264]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - sptd
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Cognizance REG_MULTI_SZ ASBroker ASChannel
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1aff7c7d-8e25-11dd-a9b2-002215ec1454}]
\shell\Auto\command - Start.exe
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8c8fec26-8fb1-11dd-ae4b-002215ec1454}]
\shell\Auto\command - Start.exe
\shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-LSA Shellu - c:\users\Asus\lsass.exe
HKLM-Run-igfxtray.exe - c:\program files\Adobe\Adobe Photoshop CS4\Patch.exe
HKLM-Run-EoEngine - (no file)
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-17 13:54:13
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'lsass.exe'(768)
c:\program files\ASUS Security Center\ASUS Security Protect Manager\bin\ASWLNPkg.dll
c:\program files\ASUS Security Center\ASUS Security Protect Manager\bin\ItMsg.dll
- - - - - - - > 'Explorer.exe'(3580)
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItClient.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\System32\Ati2evxx.exe
c:\windows\System32\audiodg.exe
c:\windows\System32\Ati2evxx.exe
c:\program files\ATK Hotkey\AsLdrSrv.exe
c:\program files\ATKGFNEX\GFNEXSrv.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\program files\ASUS\NB Probe\SPM\spmgr.exe
c:\windows\servicing\TrustedInstaller.exe
c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\asghost.exe
c:\windows\System32\conime.exe
c:\program files\ATK Hotkey\HControl.exe
c:\program files\ATK Hotkey\MsgTranAgt.exe
c:\program files\P4G\BatteryLife.exe
c:\program files\ATK Hotkey\ATKOSD.exe
c:\program files\ATK Hotkey\KBFiltr.exe
c:\program files\ATK Hotkey\WDC.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Synaptics\SynTP\SynTPHelper.exe
c:\windows\System32\wbem\WMIADAP.exe
c:\windows\System32\dllhost.exe
.
**************************************************************************
.
Heure de fin: 2009-03-17 13:57:33 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-03-17 12:57:24
Avant-CF: 88,874,246,144 octets libres
Après-CF: 88,640,901,120 octets libres
247 --- E O F --- 2009-03-06 07:34:38