Merci Ced-king,
Alors voici le post et aussi pkoi cette citation en fin de message?
ComboFix 09-05-12.04 - Alexandre 2009-05-12 16:46.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.2.1036.18.2047.1663 [GMT -4:00]
Lancé depuis: c:\documents and settings\Alexandre\Bureau\ComboFix.exe
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Updated)
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\S-6-9-24-100016942-100024230-100025629-7891.com
c:\windows\system32\drivers\gxvxcfrxnrjlktevxfqrsswewbfamtnqllisi.sys
c:\windows\system32\drivers\gxvxcjwmrflovhesiuyxmwbwewxnsiqqpfwxi.sys
c:\windows\system32\drivers\gxvxcyblyavbdmybwwksdpmupqytxkdagighx.sys
c:\windows\system32\gxvxccounter
c:\windows\system32\gxvxclwbypheucjblrfubkxtputhndcbmsngx.dll
c:\windows\system32\lsprst7.dll
c:\windows\system32\tmp.reg
e:\recycler\S-3-0-42-100016893-100020757-100019879-8528.com
e:\recycler\S-3-2-89-100009039-100009979-100019659-9195.com
e:\recycler\S-6-9-24-100016942-100024230-100025629-7891.com
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_gxvxcserv.sys
-------\Legacy_NPF
((((((((((((((((((((((((((((( Fichiers créés du 2009-04-12 au 2009-05-12 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier créé dans ce laps de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-12 20:48 . 2009-01-09 22:02 630816 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-05-12 20:48 . 2009-01-09 22:02 4284 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-05-12 20:48 . 2009-01-09 22:02 3103776 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-05-12 20:48 . 2009-01-09 22:02 27424 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-05-12 13:24 . 2001-08-28 12:00 77242 ----a-w c:\windows\system32\perfc00C.dat
2009-05-12 13:24 . 2001-08-28 12:00 474646 ----a-w c:\windows\system32\perfh00C.dat
2009-05-12 02:18 . 2009-05-12 02:18 -------- d-----w c:\program files\CCleaner
2009-05-08 23:29 . 2009-05-08 23:27 -------- d-----w c:\program files\trend micro
2009-05-07 15:10 . 2009-05-07 15:10 172 ----a-w C:\curr_ver.tmp
2009-05-07 02:13 . 2009-05-07 02:13 96559 ----a-w c:\windows\system32\drivers\klin.dat
2009-05-07 02:13 . 2009-05-07 02:13 87855 ----a-w c:\windows\system32\drivers\klick.dat
2009-05-07 02:13 . 2009-05-07 02:13 -------- d-----w c:\program files\Kaspersky Lab
2009-05-07 02:11 . 2009-05-07 02:11 -------- d-----w c:\program files\Pure Networks
2009-05-07 02:11 . 2009-05-07 02:11 -------- d-----w c:\program files\Fichiers communs\Pure Networks Shared
2009-05-07 01:46 . 2009-05-07 01:46 -------- d-----w c:\program files\Panda Security
2009-05-06 21:09 . 2009-05-06 21:09 -------- d-----w c:\program files\DIFX
2009-05-04 14:33 . 2009-04-07 21:53 -------- d-----w c:\program files\NOS
2009-05-04 03:19 . 2009-05-04 03:19 -------- d-----w c:\program files\Fichiers communs\Adobe
2009-04-23 16:09 . 2009-04-23 13:26 103511 ------w c:\windows\hpoins04.dat
2009-04-21 19:21 . 2009-04-21 19:21 -------- d-----w c:\program files\MGiS
2009-04-21 19:21 . 2009-01-06 17:02 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-15 14:33 . 2009-01-06 21:35 -------- d-----w c:\program files\Java
2009-04-07 21:56 . 2009-04-07 21:53 -------- d-----w c:\program files\Google
2009-03-30 14:44 . 2009-02-10 21:54 -------- d-----w c:\program files\ENDNOTE X2
2009-03-15 13:26 . 2009-01-06 19:34 30504 ----a-w c:\documents and settings\Alexandre\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-14 16:50 . 2009-03-14 16:48 -------- d-----w c:\program files\Fichiers communs\SPSS
2009-03-14 16:47 . 2009-03-14 16:47 -------- d-----w c:\program files\SPSSInc
2009-03-14 15:47 . 2009-03-14 16:47 1025 ----a-w c:\windows\system32\sysprs7.dll
2009-03-09 09:19 . 2009-01-06 21:35 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-06 14:20 . 2004-08-19 21:09 286720 ----a-w c:\windows\system32\pdh.dll
2009-03-03 00:13 . 2004-08-19 21:09 826368 ----a-w c:\windows\system32\wininet.dll
2009-02-20 17:10 . 2004-08-19 21:09 78336 ----a-w c:\windows\system32\ieencode.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-07 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-29 61440]
"CloneCDTray"="c:\program files\SlySoft\CloneCD\CloneCDTray.exe" [2005-05-19 57344]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2003-07-13 155648]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-11 49152]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2008-09-10 177448]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-02-10 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"nmctxth"="c:\program files\Fichiers communs\Pure Networks Shared\Platform\nmctxth.exe" [2008-05-16 648504]
"nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2008-05-21 451896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Vuze\\Azureus.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\SPSSInc\\Statistics17\\statistics.exe"=
"c:\\Program Files\\SPSSInc\\Statistics17\\statistics.com"=
"c:\\Program Files\\SPSSInc\\Statistics17\\SPSSWinWrapIDE.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service
R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\system32\drivers\klbg.sys [2008-01-29 32784]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-05-06 28544]
R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [2008-09-10 156968]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2008-04-30 24592]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1e51x86.sys [2009-01-06 38400]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [2009-01-06 845184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenu du dossier 'Tâches planifiées'
2009-05-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-HDAudDeck - c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe
.
------- Examen supplémentaire -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
FF - ProfilePath - c:\documents and settings\Alexandre\Application Data\Mozilla\Firefox\Profiles\aczxot14.default\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-12 16:49
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HDAudDeck = c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe 1????????????????????????????????????????????????
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-790525478-492894223-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:b2,53,23,86,48,cc,5f,a2,54,b1,ab,45,65,66,9d,1b,5a,2c,9d,49,5c,
99,b6,1b,76,85,19,85,4b,3d,6e,43,8a,5e,d6,9b,ce,aa,5b,dc,98,20,cc,5f,d7,8b,\
"rkeysecu"=hex:72,aa,7d,04,1b,c0,46,c0,e2,bc,9d,1c,ed,7f,ec,a6
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(992)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2900)
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Fichiers communs\Pure Networks Shared\Platform\nmsrvc.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\windows\system32\wscntfy.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
.
**************************************************************************
.
Heure de fin: 2009-05-12 16:51 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-05-12 20:51
Avant-CF: 70 101 401 600 octets libres
Après-CF: 70 031 835 136 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
187 --- E O F --- 2009-05-06 02:41