Bsr
voila le log de combofix
ComboFix 09-04-01.01 - BOB 2009-04-02 20:17:30.3 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.958.522 [GMT 2:00]
Lancé depuis: c:\documents and settings\BOB\Bureau\ComboFix.exe
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Updated)
* Un nouveau point de restauration a été créé
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\patch.exe
c:\windows\system32\kmd.exe
c:\windows\system32\lsprst7.dll
c:\windows\system32\ssprs.dll
.
---- Exécution préalable -------
.
c:\windows\images.zip
c:\windows\system32\lsprst7.dll
c:\windows\system32\ssprs.dll
c:\windows\system32\svvwa.ini
c:\windows\system32\svvwa.ini2
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-03-02 au 2009-04-02 ))))))))))))))))))))))))))))))))))))
.
2009-04-02 20:12 . 2006-03-03 00:42 73,728 --a------ C:\pv.exe
2009-03-28 22:42 . 2009-03-28 22:42 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-28 22:42 . 2009-03-28 22:42 <REP> d-------- c:\documents and settings\BOB\Application Data\Malwarebytes
2009-03-28 22:42 . 2009-03-28 22:42 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-28 22:42 . 2009-03-26 17:49 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-28 22:42 . 2009-03-26 17:49 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-28 21:01 . 2009-03-28 21:01 <REP> d-------- C:\rsit
2009-03-28 18:24 . 2009-03-28 18:24 <REP> d-------- c:\program files\Uniblue
2009-03-28 18:24 . 2009-03-28 18:24 <REP> d-------- c:\documents and settings\BOB\Application Data\Uniblue
2009-03-20 20:27 . 2009-03-20 20:30 <REP> d-------- c:\program files\FilmFX2
2009-03-20 20:07 . 1999-10-06 15:25 1,089,536 --------- c:\windows\system32\gear81sd.DLL
2009-03-20 20:07 . 2001-02-13 04:30 120,032 --a------ c:\windows\system32\SHSMP.DLL
2009-03-20 19:46 . 2009-03-20 19:59 <REP> d-------- c:\program files\Alpha Magic
2009-03-20 19:46 . 1999-04-05 12:48 86,016 --a------ c:\windows\unvise32.exe
2009-03-20 19:45 . 2009-03-20 19:45 56 --a------ c:\windows\system32\571348.dlx
2009-03-13 00:07 . 2009-03-13 00:19 50,498 --a------ C:\eqp19510829.jpg
2009-03-13 00:06 . 2009-03-13 00:18 48,480 --a------ C:\eqp19501019.jpg
2009-03-12 11:01 . 2009-03-12 11:01 1,822,238 --a------ C:\Audacity_tutoriel.pdf
2009-03-12 10:57 . 2009-03-12 10:57 <REP> d-------- c:\program files\Audacity
2009-03-11 16:59 . 2009-04-02 00:18 64 --a------ c:\windows\HFREP.INI
2009-03-11 16:36 . 2009-04-02 02:01 <REP> d-------- C:\proShop
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-02 18:21 32,825,376 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-04-02 18:03 --------- d-----w c:\program files\Mozilla Thunderbird
2009-04-02 00:03 387,596 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-03-29 19:07 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-29 18:58 --------- d-----w c:\program files\CCleaner
2009-03-28 23:48 --------- d-----w c:\documents and settings\BOB\Application Data\Desktopicon
2009-03-28 20:40 --------- d-----w c:\program files\Fichiers communs\Wise Installation Wizard
2009-03-28 20:39 --------- d-----w c:\program files\Lavasoft
2009-03-28 16:28 --------- d-----w c:\program files\Lettriq
2009-03-26 21:36 --------- d-----w c:\program files\PKR
2009-03-24 22:48 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-20 19:45 50,456 ----a-w c:\documents and settings\BOB\Application Data\GDIPFONTCACHEV1.DAT
2009-03-20 18:14 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-26 07:13 9,610,653 ----a-w c:\windows\Internet Logs\tvDebug.zip
2009-02-04 19:03 --------- d-----w c:\program files\Virtual Earth 3D
2009-01-31 01:27 2,759,168 ----a-w c:\windows\Internet Logs\xDB4.tmp
2008-12-19 21:38 67,688 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2008-12-19 21:38 54,368 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-19 21:38 34,944 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2008-12-19 21:38 46,712 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-12-19 21:38 172,136 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1667584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-01-24 7311360]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-01-24 86016]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2008-01-20 217088]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-02-13 185896]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-17 266497]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-12-13 919016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"nwiz"="nwiz.exe" [2006-01-24 c:\windows\system32\nwiz.exe]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 c:\windows\system32\HdAShCut.exe]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-17 c:\windows\LOGI_MWX.EXE]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-10-10 c:\windows\KHALMNPR.Exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2006-11-23 113664]
D‚marrage rapide de HP Photosmart Premier.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2006-02-10 73728]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-01-30 809488]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-11-07 17:41 72208 c:\program files\Fichiers communs\Logishrd\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.dfsc"= dfsc.dll
"msacm.dfscacm"= dfscacm.dll
"VIDC.HFYU"= huffyuv.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^BOB^Menu Démarrer^Programmes^Démarrage^Pinnacle Systems - Studio Family.lnk]
path=c:\documents and settings\BOB\Menu Démarrer\Programmes\Démarrage\Pinnacle Systems - Studio Family.lnk
backup=c:\windows\pss\Pinnacle Systems - Studio Family.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:55 5674352 c:\program files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 12:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
--a------ 2008-02-13 14:41 214560 c:\program files\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UnlockerAssistant]
--a------ 2008-03-01 07:10 15872 c:\program files\Unlocker\UnlockerAssistant.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.321\\English\\setup.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII.SP1\\Win32\\RpcDataSrv.exe"=
"c:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII.SP1\\RpcSandraSrv.exe"=
"c:\\WINDOWS\\system32\\ZoneLabs\\avsys\\ScanningProcess.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R2 HDDTService;HDD Temperature;c:\program files\PalickSoft\HDD Temperature\HDDTSvc.exe [2004-11-24 384512]
R2 LBeepKE;LBeepKE;c:\windows\system32\drivers\LBeepKE.sys [2009-01-30 10384]
R3 CTL511Plus;Video Blaster WebCam 3/WebCam Plus (WDM);c:\windows\system32\drivers\webc3vid.sys [2008-11-12 166504]
R3 SDVPlus;Pinnacle Studio DVplus WDM Renderer;c:\windows\system32\drivers\SDVPlus.sys [2006-11-23 63862]
S2 BestSyncSvc;BestSync Service;c:\program files\RiseFly\BestSync\BestSyncSvc.exe [2007-11-17 487424]
S3 ST330;ST330;c:\windows\system32\drivers\st330.sys [2006-11-23 30464]
S3 STBUS;STBUS;c:\windows\system32\drivers\stbus.sys [2006-11-23 12672]
S3 stppp;Speedtouch PPP Adapter Adapter;c:\windows\system32\drivers\stppp.sys [2006-11-23 32000]
S4 Oebc550;Oebc550;c:\windows\system32\drivers\aeaudio.sys [2006-11-22 127872]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenu du dossier 'Tâches planifiées'
2009-04-02 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-06-20 09:23]
2009-04-02 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
- c:\program files\Spybot - Search & Destroy\SpybotSD.exe [2008-07-30 14:45]
.
- - - - ORPHELINS SUPPRIMES - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
.
------- Examen supplémentaire -------
.
uInternet Settings,ProxyOverride = *.local;<local>
uInternet Settings,ProxyServer = localhost:8800
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
Trusted Zone: voila.fr\tchat
TCP: {31C66E2F-7C52-475F-9BB8-1F1388028E68} = 80.10.246.1,80.10.246.132
FF - ProfilePath - c:\documents and settings\BOB\Application Data\Mozilla\Firefox\Profiles\o57hfwp3.Utilisateur par défaut\
FF - prefs.js: browser.startup.homepage - hxxp://www.olweb.fr
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-02 20:20:56
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\HDDTService]
"ImagePath"="c:\program files\PalickSoft\HDD Temperature\HDDTSvc.exe /startedbyscm:916B11C7-40E287F3-HDDTService"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:87,2b,b0,8d,4f,2f,9b,60,95,50,e2,7c,07,18,27,a9,81,ad,83,b8,8a,
8a,57,6c,05,65,02,0c,89,98,fa,23,53,a4,f4,44,ce,ad,a3,af,3b,d1,23,3b,ec,be,\
[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:87,2b,b0,8d,4f,2f,9b,60,95,50,e2,7c,07,18,27,a9,81,ad,83,b8,8a,
8a,57,6c,05,65,02,0c,89,98,fa,23,53,a4,f4,44,ce,ad,a3,af,3b,d1,23,3b,ec,be,\
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(756)
c:\program files\fichiers communs\logishrd\bluetooth\LBTWlgn.dll
c:\program files\fichiers communs\logishrd\bluetooth\LBTServ.dll
.
Heure de fin: 2009-04-02 20:23:33
ComboFix-quarantined-files.txt 2009-04-02 18:23:31
Avant-CF: 12,650,385,408 octets libres
Après-CF: 12,710,359,040 octets libres
215