Rapport combofix:
ComboFix 09-05-09.05 - KIMI 10/05/2009 22:43.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.1270.859 [GMT 1:00]
Lancé depuis: d:\documents and settings\KIMI\Bureau\ComboFix.exe
Commutateurs utilisés :: d:\documents and settings\KIMI\Bureau\WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated)
FW: Kaspersky Internet Security *disabled*
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\RECYCLER .exe
d:\documents and settings\KIMI\Application Data\addons.dat
d:\windows\system32\adednbas.ini
d:\windows\system32\aevagwtk.ini
d:\windows\system32\anqntdrb.ini
d:\windows\system32\aqberdfp.ini
d:\windows\system32\auraqlgn.ini
d:\windows\system32\awnadtrf.ini
d:\windows\system32\bcyihljq.ini
d:\windows\system32\bgtokhjn.ini
d:\windows\system32\bhdsdrsu.ini
d:\windows\system32\bthwjeme.ini
d:\windows\system32\bvhvjlse.ini
d:\windows\system32\cjboikln.ini
d:\windows\system32\ddgjnchy.ini
d:\windows\system32\dlillmrb.ini
d:\windows\system32\dpyprvdu.ini
d:\windows\system32\ejbskpry.ini
d:\windows\system32\EMSAdMoq.ini
d:\windows\system32\EMSAdMoq.ini2
d:\windows\system32\ewotpgxk.ini
d:\windows\system32\fhbrmaya.ini
d:\windows\system32\fwswmpla.ini
d:\windows\system32\ghdsoycb.ini
d:\windows\system32\gijkoxgd.ini
d:\windows\system32\grjmaqfq.ini
d:\windows\system32\hpvuerdc.ini
d:\windows\system32\hqpynqfn.ini
d:\windows\system32\iavtohhf.ini
d:\windows\system32\jecboyte.ini
d:\windows\system32\jhmchm.dll
d:\windows\system32\jyoubmst.ini
d:\windows\system32\kdcohgnx.ini
d:\windows\system32\kqesusio.ini
d:\windows\system32\ljhqpoop.dll
d:\windows\system32\lmqiivjp.ini
d:\windows\system32\logondll.dll
d:\windows\system32\lwpuojuu.ini
d:\windows\system32\mcmupqax.ini
d:\windows\system32\mjpddnow.ini
d:\windows\system32\mqehhdbj.ini
d:\windows\system32\nhpbakvy.ini
d:\windows\system32\nrcnfauk.ini
d:\windows\system32\ntfjsoks.ini
d:\windows\system32\nydavynm.ini
d:\windows\system32\oinlmylo.ini
d:\windows\system32\ojetkhso.ini
d:\windows\system32\oxtfxtoe.ini
d:\windows\system32\oydcki.dll
d:\windows\system32\pkfnfnev.ini
d:\windows\system32\qxudfbss.ini
d:\windows\system32\rislonph.ini
d:\windows\system32\sagrpgwc.ini
d:\windows\system32\sgxdviyq.ini
d:\windows\system32\tjftubkk.ini
d:\windows\system32\tunnxqaj.ini
d:\windows\system32\uabrtokf.ini
d:\windows\system32\umaekiqv.ini
d:\windows\system32\usleuyeq.ini
d:\windows\system32\vqiwnnof.ini
d:\windows\system32\vqjsbovx.ini
d:\windows\system32\wcpyxfru.ini
d:\windows\system32\wwsixjmh.ini
d:\windows\system32\xbbakdxl.ini
d:\windows\system32\xceyihmw.ini
d:\windows\system32\xheabuxb.dll
d:\windows\system32\xtjpbu.dll
d:\windows\system32\ygqllvur.dll
d:\windows\system32\ynmdslxp.ini
d:\windows\system32\ypsfpmci.ini
d:\windows\system32\yrucjmif.ini
d:\windows\system32\yskeccll.ini
d:\windows\system32\yudemyro.ini
d:\windows\system32\yuyuxxpc.ini
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-04-10 au 2009-05-10 ))))))))))))))))))))))))))))))))))))
.
2009-05-10 21:00 . 2009-05-10 21:00 -------- d-----w d:\documents and settings\KIMI\Application Data\Malwarebytes
2009-05-10 21:00 . 2009-04-06 14:32 15504 ----a-w d:\windows\system32\drivers\mbam.sys
2009-05-10 21:00 . 2009-04-06 14:32 38496 ----a-w d:\windows\system32\drivers\mbamswissarmy.sys
2009-05-10 21:00 . 2009-05-10 21:00 -------- d-----w d:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-10 21:00 . 2009-05-10 21:00 -------- d-----w d:\program files\Malwarebytes' Anti-Malware
2009-05-10 19:17 . 2009-05-10 19:55 -------- d-----w D:\UsbFix
2009-05-10 19:01 . 2009-05-10 19:01 -------- d-----w D:\rsit
2009-05-10 18:58 . 2009-05-10 18:58 -------- d-----w d:\program files\Trend Micro
2009-05-10 15:41 . 2009-05-10 15:41 -------- d-----w d:\program files\DAEMON Tools Lite
2009-05-10 15:39 . 2009-05-10 15:39 717296 ----a-w d:\windows\system32\drivers\sptd.sys
2009-05-10 15:39 . 2009-05-10 15:39 -------- d-----w d:\documents and settings\KIMI\Application Data\DAEMON Tools
2009-05-10 11:13 . 1998-06-25 12:13 28160 ----a-w d:\windows\UnSetup.exe
2009-05-10 11:13 . 1998-01-26 19:45 155648 ----a-w d:\windows\FraUinst.exe
2009-05-10 11:13 . 2009-05-10 16:41 -------- d-----w d:\windows\Lhsp
2009-05-06 20:02 . 2009-05-06 20:02 -------- d-----w d:\documents and settings\KIMI\Local Settings\Application Data\Identities
2009-05-05 19:18 . 2009-05-05 19:18 -------- d-----w d:\documents and settings\KIMI\WINDOWS
2009-05-05 19:18 . 2009-05-05 19:18 -------- d-----w d:\documents and settings\KIMI\Local Settings\Application Data\Help
2009-05-03 15:16 . 2009-05-03 15:16 -------- d-----w d:\program files\uTorrent
2009-05-03 15:16 . 2009-05-10 17:15 -------- d-----w d:\documents and settings\KIMI\Application Data\uTorrent
2009-05-03 09:17 . 2009-05-03 09:17 -------- d-----w d:\documents and settings\KIMI\Application Data\dvdcss
2009-05-02 11:46 . 2009-05-02 11:46 -------- d-----w d:\documents and settings\KIMI\Local Settings\Application Data\vdownloader
2009-05-02 11:45 . 2009-05-02 11:46 -------- d-----w d:\program files\VDOWNLOADER
2009-04-27 18:05 . 2009-04-27 18:05 -------- d-----w d:\program files\Fichiers communs\xing shared
2009-04-27 18:05 . 2009-04-27 18:05 -------- d-----w d:\program files\Real
2009-04-26 17:07 . 2009-04-26 17:07 -------- d-----w d:\documents and settings\KIMI\Application Data\Wireshark
2009-04-26 17:04 . 2009-04-26 17:04 -------- d-----w d:\program files\WinPcap
2009-04-26 17:03 . 2009-04-26 17:04 -------- d-----w d:\program files\Wireshark
2009-04-26 16:56 . 2009-04-26 16:56 -------- d-----w d:\program files\NeoTrace Express
2009-04-23 18:48 . 2009-04-23 18:48 -------- d-----w d:\documents and settings\KIMI\Local Settings\Application Data\Logitech
2009-04-22 15:56 . 2009-04-22 16:01 -------- d-----w d:\program files\PhotoFiltre
2009-04-14 09:46 . 2009-04-14 10:18 101287 ----a-w d:\windows\system32\drivers\klin.dat
2009-04-14 09:46 . 2009-04-14 10:18 89601 ----a-w d:\windows\system32\drivers\klick.dat
2009-04-14 09:44 . 2009-05-10 21:47 -------- d-----w d:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-04-14 09:44 . 2009-05-10 21:46 1336864 --sha-w d:\windows\system32\drivers\fidbox.dat
2009-04-14 09:44 . 2009-05-10 21:46 270368 --sha-w d:\windows\system32\drivers\fidbox2.dat
2009-04-13 15:25 . 2009-04-13 15:25 -------- d-----w d:\program files\UnH Solutions
2009-04-11 15:40 . 2009-04-11 15:40 -------- d-----w d:\program files\KP Software
2009-04-11 15:25 . 2009-04-11 15:25 -------- d-----w d:\program files\TechSmith
2009-04-11 14:52 . 2009-04-11 14:52 -------- d-----w d:\program files\CCleaner
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-10 21:46 . 2009-04-14 09:44 3052 --sha-w d:\windows\system32\drivers\fidbox2.idx
2009-05-10 21:46 . 2009-04-14 09:44 12572 --sha-w d:\windows\system32\drivers\fidbox.idx
2009-05-05 18:50 . 2009-05-01 22:27 1536547935 ----a-w d:\program files\Tell Me More Espanol Cd 1,2,3,4 - Learn Spanish Spanish Course-Cours D'espagnol-Corso Di Spagnolo-Spanischkurs.rar
2009-05-01 21:33 . 2009-03-05 11:25 -------- d-----w d:\program files\Faronics
2009-04-27 18:05 . 2009-03-03 11:35 -------- d-----w d:\program files\Fichiers communs\Real
2009-04-23 18:43 . 2009-03-03 11:37 -------- d-----w d:\program files\Fichiers communs\Logitech
2009-04-23 18:43 . 2009-03-03 11:36 -------- d-----w d:\program files\Logitech
2009-04-14 10:18 . 2008-01-29 16:29 33808 ----a-w d:\windows\system32\drivers\klbg.sys
2009-04-06 15:19 . 2009-04-06 15:19 56 ---ha-w d:\windows\system32\ezsidmv.dat
2009-04-06 15:18 . 2009-04-06 15:18 -------- d-----w d:\program files\Skype
2009-04-06 15:18 . 2009-04-06 15:18 -------- d-----w d:\program files\Fichiers communs\Skype
2009-03-15 19:53 . 2009-03-04 19:11 -------- d-----w d:\program files\Internet Download Manager
2009-03-05 11:25 . 2009-03-05 11:25 16299862 ------w D:\Persi0.sys
2009-03-05 11:10 . 2009-03-03 11:20 2048 --s-a-w d:\windows\bootstet.dat
2009-03-04 20:16 . 2004-08-04 04:54 219648 ----a-w d:\windows\system32\uxtheme.dll
2009-03-04 17:19 . 2009-03-04 17:19 107888 ----a-w d:\windows\system32\CmdLineExt.dll
2009-03-04 11:27 . 2009-03-03 11:16 86331 ----a-w d:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-03-03 11:28 . 2002-09-07 00:00 367658 ----a-w d:\windows\system32\perfh00C.dat
2009-03-03 11:28 . 2002-09-07 00:00 48616 ----a-w d:\windows\system32\perfc00C.dat
2009-03-03 11:24 . 2009-03-03 11:24 12328 ----a-w d:\documents and settings\KIMI\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-03 11:16 . 2002-09-07 00:00 67 --sha-w d:\windows\Fonts\desktop.ini
2009-03-03 11:13 . 2009-03-03 11:13 21892 ----a-w d:\windows\system32\emptyregdb.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IDMan"="d:\program files\Internet Download Manager\IDMan.exe" [2007-12-21 2573744]
"DAEMON Tools Lite"="d:\program files\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVP"="d:\program files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe" [2009-04-14 206088]
"Start WingMan Profiler"="d:\program files\Logitech\Gaming Software\LWEMon.exe" [2008-04-04 88584]
"TkBellExe"="d:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2009-04-27 185872]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\drwtsn32.exe]
"Debugger"=d:\windows\system32\wscript.exe /E:vbs d:\windows\system32\winjpg.jpg
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /k:C /k:D *
[HKLM\~\startupfolder\D:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^SnagIt 7.lnk]
path=d:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\SnagIt 7.lnk
backup=d:\windows\pss\SnagIt 7.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"d:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"d:\\Program Files\\MSN Messenger\\livecall.exe"=
"d:\\Program Files\\uTorrent\\uTorrent.exe"=
"d:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 DeepFrz;DeepFrz;d:\windows\system32\drivers\DeepFrz.sys [25/10/2007 13:52 131472]
R0 klbg;Kaspersky Lab Boot Guard Driver;d:\windows\system32\drivers\klbg.sys [29/01/2008 17:29 33808]
R2 LF30FS;LF30FS;d:\program files\Everstrike Software\Lock Folder XP 3.6\LF30XP.sys [19/11/2004 18:07 101488]
R3 KLFLTDEV;Kaspersky Lab KLFltDev;d:\windows\system32\drivers\klfltdev.sys [13/03/2008 18:02 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;d:\windows\system32\drivers\klim5.sys [30/04/2008 17:06 24592]
S3 NPF;NetGroup Packet Filter Driver;d:\windows\system32\drivers\npf.sys [06/11/2007 21:22 34064]
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{31D1305D-195C-4836-AB15-CE560FA8C578} - (no file)
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
Notify-cbXNHyaA - cbXNHyaA.dll
Notify-DfLogon - LogonDll.dll
Notify-fccbXonN - fccbXonN.dll
Notify-hgGwTlLb - hgGwTlLb.dll
Notify-khfCtuvu - khfCtuvu.dll
Notify-pmnnkLFX - pmnnkLFX.dll
Notify-rqRHyxvw - rqRHyxvw.dll
Notify-tuvUNedD - tuvUNedD.dll
.
------- Examen supplémentaire -------
.
IE: &NeoTrace It! - d:\progra~1\NEOTRA~1\NTXcontext.htm
IE: Download all links with IDM - d:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - d:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - d:\program files\Internet Download Manager\IEExt.htm
TCP: {3DE1C12C-295B-4ED4-93C7-92DEFB761E72} = 208.67.222.222 193.55.10.102
FF - ProfilePath - d:\documents and settings\KIMI\Application Data\Mozilla\Firefox\Profiles\vlpqyo9i.default\
FF - prefs.js: browser.startup.homepage - www.google.fr
FF - component: d:\documents and settings\KIMI\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
FF - component: d:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - component: d:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-10 22:47
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):80,1b,50,e0,09,23,90,57,13,b6,d2,51,a0,86,32,27,0a,78,4f,79,0b,
db,8f,2d,40,80,b1,9f,57,e5,ca,2d,7d,5a,b1,e8,5c,ff,9e,b5,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{8373e3f2-d69e-4d36-a4cc-e056fef53b2f}]
@Denied: (Full) (Everyone)
"Model"=dword:00000081
"Therad"=dword:00000009
"MData"=hex(0):cb,9b,ad,ef,27,7d,29,69,f5,02,f0,76,aa,4a,f1,7c,d3,d9,67,7f,6a,
4b,7b,ad,04,7a,b1,b5,76,9b,27,47,63,2b,00,4c,e2,45,41,d2,ba,ae,b4,01,47,72,\
.
------------------------ Autres processus actifs ------------------------
.
d:\program files\Faronics\Deep Freeze\Install D-0\DF5Serv.exe
d:\program files\Faronics\Deep Freeze\Install D-0\_$Df\FrzState2k.exe
d:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2009-05-10 22:49 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-05-10 21:49
Avant-CF: 1 210 441 728 octets libres
Après-CF: 989 843 456 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
256