Voila findykill
############################## [ FindyKill V4.728 ]
# User : Administrateur (Administrateurs) # SWEET-45A8F2C90
# Update on 03/05/09 by Chiquitine29
# Start at: 17:40:58 | 09/05/2009
# Website : http://pagesperso-orange.fr/NosTools/findykill.html
# AMD Athlon(tm)
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
# Internet Explorer 8.0.6001.18702
# Windows Firewall Status : Disabled
# AV : AntiVir Desktop 9.0.1.26 [ Enabled | Updated ]
# A:\ # Lecteur de disquettes 3 ½ pouces
# C:\ # Disque fixe local # 29,29 Go (16,9 Go free) # NTFS
# D:\ # Disque fixe local # 45,23 Go (12,38 Go free) # NTFS
# E:\ # Disque CD-ROM
############################## [ Processus actifs ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe
D:\java\bin\jqs.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
C:\WINDOWS\system32\Pen_Tablet.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
D:\IPOD\iTunesHelper.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
D:\eMule\emule.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
################## [ Fichiers / Dossiers infectieux ]
################## [ Infected Temp Files ]
################## [ Registre / Clés infectieuses ]
################## [ Recherche dans supports amovibles]
################## [ Registre / Mountpoints2 ]
# -> Not found !
################## [ ! Fin du rapport # FindyKill V4.728 ! ]
et combofix
ComboFix 09-05-08.03 - Administrateur 09/05/2009 17:54.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.767.487 [GMT 2:00]
Lancé depuis: c:\documents and settings\Administrateur\Bureau\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated)
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-04-09 au 2009-05-09 ))))))))))))))))))))))))))))))))))))
.
2009-05-09 07:27 . 2009-05-09 15:35 -------- d-----w c:\program files\Navilog1
2009-05-09 07:11 . 2009-05-09 07:11 579072 -c--a-w c:\windows\system32\dllcache\user32.dll
2009-05-09 07:10 . 2009-05-09 07:10 -------- d-----w c:\windows\ERUNT
2009-05-09 07:02 . 2009-05-09 07:23 -------- d-----w C:\SDFix
2009-05-08 10:10 . 2009-05-08 10:10 -------- d-sh--w c:\documents and settings\Administrateur\IECompatCache
2009-05-08 10:07 . 2009-05-08 10:07 -------- d-sh--w c:\documents and settings\Administrateur\PrivacIE
2009-05-08 07:04 . 2009-05-08 07:04 -------- d-sh--w c:\documents and settings\Administrateur\IETldCache
2009-05-07 17:35 . 2009-05-07 17:35 -------- d--h--w c:\windows\msdownld.tmp
2009-05-07 17:35 . 2009-05-07 17:35 -------- d-----w c:\windows\ie8updates
2009-05-07 17:25 . 2009-05-07 17:28 -------- dc-h--w c:\windows\ie8
2009-05-07 17:16 . 2009-04-25 05:30 102400 -c----w c:\windows\system32\dllcache\iecompat.dll
2009-05-07 17:04 . 2009-05-07 17:04 -------- d-----w c:\program files\Microsoft Silverlight
2009-05-05 18:50 . 2009-03-24 14:07 55640 ----a-w c:\windows\system32\drivers\avgntflt.sys
2009-05-05 18:50 . 2009-05-05 18:50 -------- d-----w c:\program files\Avira
2009-05-05 18:50 . 2009-05-05 18:50 -------- d-----w c:\documents and settings\All Users\Application Data\Avira
2009-04-22 18:39 . 2009-04-22 18:39 -------- d-----w c:\program files\SafeSoft
2009-04-19 16:15 . 2009-04-19 16:15 767328 ----a-w c:\windows\system32\kdfinj.dll
2009-04-19 16:15 . 2008-10-17 08:50 131072 ----a-w c:\windows\system32\drivers\Mkd2kfNT.sys
2009-04-19 16:15 . 2008-10-17 08:50 79104 ----a-w c:\windows\system32\drivers\Mkd2Nadr.sys
2009-04-19 16:13 . 2009-04-19 16:13 -------- d-----w c:\program files\AhnLab
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-09 07:22 . 2002-09-06 23:00 73260 ----a-w c:\windows\system32\perfc00C.dat
2009-05-09 07:22 . 2002-09-06 23:00 464892 ----a-w c:\windows\system32\perfh00C.dat
2009-05-09 07:20 . 2008-04-29 11:22 86331 ----a-w c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-05-06 12:14 . 2008-04-29 11:47 -------- d-----w c:\program files\BitDefender
2009-05-06 12:14 . 2008-04-29 11:46 -------- d-----w c:\program files\Fichiers communs\BitDefender
2009-05-05 18:24 . 2008-06-25 07:12 81984 -c--a-w c:\windows\system32\bdod.bin
2009-04-15 08:22 . 2008-06-28 09:41 1388 -c--a-w c:\documents and settings\Administrateur\Application Data\ViewerApp.dat
2009-03-08 02:34 . 2008-02-03 10:12 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 02:34 . 2008-01-23 20:40 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 02:33 . 2008-01-23 20:39 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 02:33 . 2008-01-23 20:40 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 02:32 . 2008-02-03 10:07 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 02:32 . 2008-02-03 10:08 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 02:31 . 2004-08-04 03:54 34816 ----a-r c:\windows\system32\imgutil.dll
2009-03-08 02:31 . 2008-01-23 20:40 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 02:31 . 2008-02-03 10:09 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 02:22 . 2008-01-23 20:40 156160 ----a-w c:\windows\system32\msls31.dll
2009-02-25 16:35 . 2009-02-25 14:08 421888 ----a-w c:\windows\NEXON_EU_DownloaderUpdater.exe
.
------- Sigcheck -------
[-] 2008-04-14 02:33 579584 E853F84D3CE2FAA2A802E33CF89AC023 c:\windows\SoftwareDistribution\Download\44b6174a4a693136d02d4a7ecd7cbd54\user32.dll
[-] 2008-02-03 10:12 579072 D631FBC2A8B9AF181A8612276FC56154 c:\windows\system32\user32.dll
[-] 2009-05-09 07:11 579072 D631FBC2A8B9AF181A8612276FC56154 c:\windows\system32\dllcache\user32.dll
[-] 2008-04-14 02:34 512000 DD73D6B9F6B4CB630CF35B438B540174 c:\windows\SoftwareDistribution\Download\44b6174a4a693136d02d4a7ecd7cbd54\winlogon.exe
[-] 2008-02-03 10:12 555520 DF3ED75D36BB55FEDF9F02EC863BDF3F c:\windows\system32\winlogon.exe
[-] 2008-02-03 10:08 1573376 BAA0E1B7DA39D7BFCB2E0306B3E98EC1 c:\windows\explorer.exe
[-] 2008-04-14 02:34 1037824 F2317622D29F9FF0F88AEECD5F60F0DD c:\windows\SoftwareDistribution\Download\44b6174a4a693136d02d4a7ecd7cbd54\explorer.exe
[-] 2008-04-14 02:33 15360 59DC5BB82E4C8E0B3EADCFDBC44BA6E4 c:\windows\SoftwareDistribution\Download\44b6174a4a693136d02d4a7ecd7cbd54\ctfmon.exe
[-] 2008-02-03 10:08 40960 D91EE13BFFBBDC87E59FCC101247D1F5 c:\windows\system32\ctfmon.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2008-01-21 5724184]
"eMuleAutoStart"="d:\emule\emule.exe" [2007-05-13 5308416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-08-02 185896]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"AppleSyncNotifier"="c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
"iTunesHelper"="d:\ipod\iTunesHelper.exe" [2009-01-06 290088]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"AsioReg"="CTASIO.DLL" - c:\windows\system32\CTASIO.DLL [2006-08-17 74752]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"ShowDeskFix"="shell32" [X]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544]
"SetDefaultMIDI"="MIDIDEF.EXE" - c:\windows\MIDIDEF.EXE [2006-08-17 25600]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Picture Package Menu.lnk - c:\program files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe [2008-6-28 151552]
Picture Package VCD Maker.lnk - c:\program files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe [2008-6-28 106496]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 0 (0x0)
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMBalloonTip"= 0 (0x0)
"NoSMConfigurePrograms"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [05/05/2009 20:50 108289]
R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [28/07/2008 19:22 1373480]
S3 Mkd2kfNt;Mkd2kfNt;c:\windows\system32\drivers\Mkd2kfNT.sys [19/04/2009 18:15 131072]
S3 Mkd2Nadr;Mkd2Nadr;c:\windows\system32\drivers\Mkd2Nadr.sys [19/04/2009 18:15 79104]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
.
Contenu du dossier 'Tâches planifiées'
2008-08-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 10:34]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-BitDefender Antiphishing Helper - c:\program files\BitDefender\BitDefender 2008\IEShow.exe
.
------- Examen supplémentaire -------
.
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - plugin: c:\program files\AhnLab\ASP\MyKeyDefense 2.5\npmkd25aos.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npOGAPlugin.dll
FF - plugin: d:\ipod\Mozilla Plugins\npitunes.dll
FF - plugin: d:\java\bin\new_plugin\npdeploytk.dll
FF - plugin: d:\java\bin\new_plugin\npjp2.dll
FF - plugin: d:\real player\Netscape6\nppl3260.dll
FF - plugin: d:\real player\Netscape6\nprjplug.dll
FF - plugin: d:\real player\Netscape6\nprpjplug.dll
FF - plugin: d:\scene caster\SceneCaster\Version 3.11.16\NPSceneCaster.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-09 17:56
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-527237240-1682526488-1801674531-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,7a,92,35,5e,0a,77,c3,43,b1,3c,32,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,7a,92,35,5e,0a,77,c3,43,b1,3c,32,\
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(660)
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\cscui.dll
- - - - - - - > 'lsass.exe'(716)
c:\windows\system32\setupapi.dll
- - - - - - - > 'explorer.exe'(468)
c:\windows\system32\COMRes.dll
c:\windows\System32\cscui.dll
c:\windows\system32\msi.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\SETUPAPI.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.dll
c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\PDFShell.FRA
c:\windows\system32\webcheck.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
.
Heure de fin: 2009-05-09 17:58
ComboFix-quarantined-files.txt 2009-05-09 15:58
Avant-CF: 18 247 692 288 octets libres
Après-CF: 18 275 119 104 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
181 --- E O F --- 2008-11-03 10:48
merci de ton aide et désolée de te priver de ton temps ^^' bon ben bonsoir xD
.. vais me coucher