Voilà. Bon je l'avais téléchargé hier soir déjà Combofix. Ca ne pose pas de souci ?
j'ai du double cliquer 2 fois avant qu'il se lance, et j'ai pas vu passer le choix 1 yes. mais bon le scan s'est fait. au lancement il m'a dit que je n'avais pas la console de récupération Windows, mais j'ai refusé de la télécharger (à vous de me dire). il le signale dans le rapport du reste.
vala :
ComboFix 09-06-05.09 - Administrateur 07.06.2009 19:18.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.41.1036.18.1023.581 [GMT 2:00]
Lancé depuis: c:\documents and settings\Administrateur\Bureau\ComboFix.exe
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-05-07 au 2009-06-07 ))))))))))))))))))))))))))))))))))))
.
2009-06-07 17:11 . 2009-06-07 17:11 -------- d-----w- C:\rsit
2009-06-07 16:17 . 2009-06-07 16:17 -------- d-----w- c:\program files\Trend Micro
2009-06-06 22:35 . 2009-06-06 22:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
2009-06-06 22:13 . 2009-06-07 16:11 -------- d-----w- C:\FindyKill
2009-06-06 21:49 . 2009-06-06 21:49 -------- d-----w- c:\program files\CCleaner
2009-06-06 21:34 . 2009-06-06 21:34 -------- d--h--w- c:\windows\system32\GroupPolicy
2009-06-06 21:30 . 2009-06-06 21:30 -------- d-----w- c:\program files\Vilma
2009-06-06 18:24 . 2009-06-06 18:26 -------- d-----w- c:\documents and settings\All Users\Application Data\WinZip
2009-06-04 16:40 . 2009-06-04 16:40 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-06-03 22:57 . 2009-06-03 22:57 -------- d-sh--w- c:\documents and settings\Administrateur\PrivacIE
2009-06-03 22:56 . 2009-06-03 22:56 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-06-03 22:51 . 2009-06-03 22:51 -------- d-sh--w- c:\documents and settings\Administrateur\IETldCache
2009-06-03 22:48 . 2006-06-29 11:07 14048 ------w- c:\windows\system32\spmsg2.dll
2009-06-03 22:42 . 2009-06-03 22:42 -------- d-----w- c:\windows\system32\XPSViewer
2009-06-03 22:41 . 2009-06-03 22:41 -------- d-----w- c:\program files\Reference Assemblies
2009-06-03 22:41 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-06-03 22:41 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-06-03 22:41 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-06-03 22:41 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-06-03 22:41 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-06-03 22:41 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-06-03 22:41 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-06-03 22:36 . 2009-06-06 19:14 -------- d-----w- c:\windows\ie8updates
2009-06-03 22:36 . 2009-05-12 05:11 102912 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-06-03 22:32 . 2009-02-20 17:10 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-03 22:32 . 2009-02-20 17:10 78336 ----a-w- c:\windows\system32\dllcache\ieencode.dll
2009-06-02 19:21 . 2004-09-02 21:18 379456 ----a-w- c:\windows\system32\drivers\WlanUIG.sys
2009-06-02 19:21 . 2004-09-02 21:18 15781 ----a-w- c:\windows\system32\drivers\mdc8021x.sys
2009-06-02 19:21 . 2004-09-02 21:18 147456 ----a-w- c:\windows\system32\ssleay32.dll
2009-06-02 19:21 . 2004-09-02 21:18 929792 ----a-w- c:\windows\system32\AegisE5.dll
2009-06-02 19:21 . 2004-09-02 21:18 651264 ----a-w- c:\windows\system32\libeay32.dll
2009-06-02 19:21 . 2009-06-02 19:21 -------- d-----w- c:\program files\SAGEM Wi-Fi USB 802.11g
2009-05-17 08:57 . 2009-05-17 08:57 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-05-16 09:47 . 2009-05-16 09:47 -------- d-----w- C:\gen5
2009-05-16 09:46 . 1999-07-23 11:17 86016 ----a-w- c:\windows\unvise32qt.exe
2009-05-16 09:46 . 2009-05-16 09:46 -------- d-----w- c:\windows\system32\QuickTime
2009-05-16 09:45 . 2009-05-16 09:46 -------- d-----w- c:\program files\QuickTime
2009-05-16 09:39 . 1994-09-20 22:00 6736 ----a-w- c:\windows\system32\WINGDIB.DRV
2009-05-16 09:39 . 1994-09-20 22:00 92208 ----a-w- c:\windows\system32\WING.DLL
2009-05-16 09:39 . 1994-09-20 22:00 12800 ----a-w- c:\windows\system32\WING32.DLL
2009-05-16 09:39 . 1994-08-23 22:00 188960 ----a-w- c:\windows\system32\WINGDE.DLL
2009-05-16 09:39 . 2009-05-16 09:39 -------- d-----w- C:\TLCWIN
2009-05-16 09:38 . 1996-02-08 07:54 284160 ----a-w- c:\windows\unin040c.exe
2009-05-16 09:38 . 2009-05-16 09:38 -------- d-----w- c:\documents and settings\Administrateur\WINDOWS
2009-05-09 14:43 . 2009-05-09 14:43 -------- d-----w- c:\windows\system32\KB905474
2009-05-09 14:43 . 2009-03-10 20:26 1438080 ----a-w- c:\windows\system32\KB905474\wganotifypackageinner.exe
2009-05-09 14:43 . 2009-03-10 20:18 531848 ----a-w- c:\windows\system32\KB905474\wgasetup.exe
2009-05-09 14:41 . 2009-05-09 14:41 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-05-09 14:36 . 2009-05-09 14:36 -------- d-----w- c:\program files\MSXML 4.0
2009-05-09 12:14 . 2009-03-06 14:20 286720 -c----w- c:\windows\system32\dllcache\pdh.dll
2009-05-09 12:14 . 2009-02-09 11:23 111104 -c----w- c:\windows\system32\dllcache\services.exe
2009-05-09 12:14 . 2009-02-06 10:10 227840 -c----w- c:\windows\system32\dllcache\wmiprvse.exe
2009-05-09 12:14 . 2009-02-09 10:53 735744 -c----w- c:\windows\system32\dllcache\lsasrv.dll
2009-05-09 12:14 . 2009-02-09 10:53 739840 -c----w- c:\windows\system32\dllcache\ntdll.dll
2009-05-09 12:14 . 2009-02-09 10:53 685568 -c----w- c:\windows\system32\dllcache\advapi32.dll
2009-05-09 12:14 . 2009-02-09 10:53 473600 -c----w- c:\windows\system32\dllcache\fastprox.dll
2009-05-09 12:14 . 2009-02-09 10:53 453120 -c----w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-05-09 12:14 . 2009-02-09 10:53 401408 -c----w- c:\windows\system32\dllcache\rpcss.dll
2009-05-09 12:13 . 2008-12-16 12:31 354304 -c----w- c:\windows\system32\dllcache\winhttp.dll
2009-05-09 12:12 . 2008-04-21 21:15 219136 -c----w- c:\windows\system32\dllcache\wordpad.exe
2009-05-09 12:08 . 2008-10-16 12:06 268648 ----a-w- c:\windows\system32\mucltui.dll
2009-05-09 12:08 . 2008-10-16 12:06 208744 ----a-w- c:\windows\system32\muweb.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-07 16:13 . 2001-08-28 12:00 85404 ----a-w- c:\windows\system32\perfc00C.dat
2009-06-07 16:13 . 2001-08-28 12:00 513080 ----a-w- c:\windows\system32\perfh00C.dat
2009-06-06 22:35 . 2009-02-01 11:48 -------- d-----w- c:\program files\Google
2009-06-06 21:53 . 2009-01-23 00:24 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-06 14:01 . 2009-02-05 23:31 -------- d-----w- c:\program files\Fichiers communs\Panda Software
2009-06-04 11:48 . 2009-01-22 18:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-06-04 11:43 . 2009-01-20 22:40 47360 ----a-w- c:\documents and settings\Administrateur\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-03 22:41 . 2009-01-22 19:03 -------- d-----w- c:\program files\MSBuild
2009-06-03 22:26 . 2009-01-22 19:05 -------- d-----w- c:\program files\Microsoft Works
2009-06-03 21:39 . 2009-02-01 11:39 -------- d-----w- c:\documents and settings\Administrateur\Application Data\ZoomBrowser EX
2009-06-03 19:27 . 2009-02-01 11:35 -------- d-----w- c:\documents and settings\Administrateur\Application Data\CameraWindowDC
2009-06-03 17:36 . 2009-01-26 21:15 -------- d-----w- c:\documents and settings\Administrateur\Application Data\HPAppData
2009-06-02 19:21 . 2009-01-21 20:40 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-01 18:30 . 2009-05-01 18:30 3366912 ----a-w- c:\windows\system32\GPhotos.scr
2009-04-11 17:32 . 2009-04-11 17:32 -------- d-----w- c:\program files\Fichiers communs\datavers
2009-04-11 17:32 . 2009-04-11 17:31 -------- d-----w- c:\program files\SimulEmprunt
.
((((((((((((((((((((((((((((( SnapShot@2009-06-06_22.19.15 )))))))))))))))))))))))))))))))))))))))))
.
- 2001-08-28 12:00 . 2009-06-04 12:04 71904 c:\windows\system32\perfc009.dat
+ 2001-08-28 12:00 . 2009-06-07 16:13 71904 c:\windows\system32\perfc009.dat
+ 2001-08-28 12:00 . 2009-06-07 16:13 444028 c:\windows\system32\perfh009.dat
- 2001-08-28 12:00 . 2009-06-04 12:04 444028 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-23 39408]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1773056]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 154624]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 126976]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 565248]
"Adobe Version Cue CS2"="c:\program files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe" [2005-04-06 925696]
"Raccourci vers la page des propriétés de High Definition Audio"="HDAudPropShortcut.exe" - c:\windows\system32\Hdaudpropshortcut.exe [2004-03-17 135680]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 183296]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 283992]
Lancement rapide d'Adobe Acrobat.lnk - c:\windows\Installer\{AC76BA86-1033-F400-7760-000000000002}\SC_Acrobat.exe [2009-1-23 25214]
Sagem - Utilitaire r‚seau pour Cl‚ USB Wi-Fi 802.11g.lnk - c:\program files\SAGEM Wi-Fi USB 802.11g\WLANUTL.exe [2009-6-2 753664]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-10-8 394856]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"= 1 (0x1)
"DisableRegistryTools"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Adobe\\Adobe Version Cue CS2\\bin\\VersionCueCS2.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"= c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqSTE08.exe
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\KB905474\\wgasetup.exe"=
"c:\\WINDOWS\\system32\\HDAudPropShortcut.exe"=
"c:\\Program Files\\Adobe\\Adobe Acrobat 7.0\\Acrobat\\acrobat_sl.exe"=
"c:\\Program Files\\SAGEM\\SAGEM F@st 3202\\RunHttpCfg.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqgpc01.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPWuSchd2.exe"=
"c:\\Program Files\\Adobe\\Adobe Version Cue CS2\\ControlPanel\\VersionCueCS2Tray.exe"=
"c:\\WINDOWS\\UninstWiFi.exe"=
"c:\\Program Files\\SAGEM Wi-Fi USB 802.11g\\WLANUTL.exe"=
"c:\\Program Files\\Adobe\\Adobe Version Cue CS2\\data\\database\\bin\\mysqladmin.exe"=
"c:\\Program Files\\Adobe\\Adobe Version Cue CS2\\data\\database\\bin\\mysqld-nt.exe"=
"c:\\Program Files\\Fichiers communs\\Adobe\\Calibration\\Adobe Gamma Loader.exe"=
"c:\\Program Files\\Adobe\\Adobe Acrobat 7.0\\Distillr\\Acrotray.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\WINWORD.EXE"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqSRMon.exe"=
"c:\\Program Files\\Google\\Common\\Google Updater\\GoogleUpdaterService.exe"=
R3 abp470n5;abp470n5;\??\c:\windows\system32\drivers\gvnsso.sys --> c:\windows\system32\drivers\gvnsso.sys [?]
S3 cmudax;C-Media High Definition Audio Interface;c:\windows\system32\drivers\cmudax.sys [21.01.2009 22:40 1264320]
S3 WlanUIG;Sagem 802.11g Wireless LAN USB Adapter Driver;c:\windows\system32\drivers\WlanUIG.sys [02.06.2009 21:21 379456]
--- Autres Services/Pilotes en mémoire ---
*NewlyCreated* - EAPHOST
*NewlyCreated* - IP6FW
*NewlyCreated* - PCANDIS5
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenu du dossier 'Tâches planifiées'
2009-06-07 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-02-01 22:35]
2009-05-30 c:\windows\Tasks\WebReg HP Deskjet F2200 series.job
- c:\program files\HP\Digital Imaging\bin\hpqwrg.exe [2007-10-14 19:40]
2009-06-07 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-05-09 20:18]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.ch/
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Convertir en Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir en un fichier PDF existant - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir la cible du lien en Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir la cible du lien en un fichier PDF existant - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir la sélection en Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir la sélection en un fichier PDF existant - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir les liens sélectionnés en fichier Adobe PDF - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convertir les liens sélectionnés en un fichier PDF existant - c:\program files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: secuser.com\www
Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - c:\program files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-07 19:20
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-1993962763-1292428093-839522115-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,22,ca,ba,d0,ba,e8,6e,49,a1,07,53,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,22,ca,ba,d0,ba,e8,6e,49,a1,07,53,\
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(692)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(1428)
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Heure de fin: 2009-06-07 19:21
ComboFix-quarantined-files.txt 2009-06-07 17:21
Avant-CF: 13'829'165'056 octets libres
Après-CF: 13'832'634'368 octets libres
237 --- E O F --- 2009-06-04 11:48