Salut,
Rapport toolbarS&D :
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
X86-based PC ( Uniprocessor Free : Intel(R) Pentium(R) 4 CPU 2.80GHz )
BIOS : Phoenix ROM BIOS PLUS Version 1.10 A03
USER : Administrateur ( Administrator )
BOOT : Normal boot
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:39 Go (Free:26 Go)
D:\ (Local Disk) - NTFS - Total:35 Go (Free:2 Go)
E:\ (CD or DVD)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 23/06/2009|16:36 )
-----------\\ Recherche de Fichiers / Dossiers ...
C:\Program Files\Mozilla Firefox\searchplugins\crawlersrch.xml
-----------\\ Extensions
(Administrateur) - {635abd67-4fe9-1b23-4f01-e679fa7484c1} => ytoolbar
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="http://www.google.fr/"
"Search Page"="http://www.google.com"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page Redirect Cache"="http://fr.msn.com/?ocid=iehp"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
--------------------\\ Recherche d'autres infections
--------------------\\ Cracks & Keygens ..
C:\DOCUME~1\ADMINI~1\Favoris\Cracks - Serials
C:\DOCUME~1\ADMINI~1\Favoris\Cracks - Serials\Astalavista.box.sk.url
1 - "C:\ToolBar SD\TB_1.txt" - 23/06/2009|16:39 - Option : [1]
-----------\\ Fin du rapport a 16:39:18,07
------------------------------------------------------------------------
Rapport ComBoFix
ComboFix 09-06-22.0D - Administrateur 23/06/2009 17:01.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.510.231 [GMT 0:00]
Lancé depuis: c:\documents and settings\Administrateur\Bureau\ComboFix.exe.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\driver
c:\windows\system32\drivers\kl1.sys
c:\windows\system32\msconfig.exe
c:\windows\system32\Process.exe
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DRIVER
-------\Legacy_DRIVERDRV
-------\Service_AVPsys
((((((((((((((((((((((((((((( Fichiers créés du 2009-05-23 au 2009-06-23 ))))))))))))))))))))))))))))))))))))
.
2009-06-23 13:20 . 2009-06-23 13:20 -------- d-sh--w- c:\documents and settings\Administrateur\UserData
2009-06-23 10:06 . 2009-06-23 16:39 -------- d-----w- C:\ToolBar SD
2009-06-22 20:45 . 2009-06-22 20:45 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Malwarebytes
2009-06-22 20:45 . 2009-06-17 11:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-22 20:45 . 2009-06-22 20:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-22 20:45 . 2009-06-17 11:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-22 20:45 . 2009-06-22 20:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-22 09:56 . 2009-06-22 09:56 -------- d-----w- c:\program files\Trend Micro
2009-06-22 09:51 . 2009-06-21 18:06 2052888 ----a-w- c:\documents and settings\All Users\Application Data\avg8\update\backup\avgcorex.dll
2009-06-22 00:50 . 2009-06-22 20:34 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-06-22 00:50 . 2009-06-22 00:51 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-06-22 00:06 . 2009-06-22 00:06 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\AVG Security Toolbar
2009-06-21 22:15 . 2009-06-14 16:08 1004800 ----a-w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar\IEToolbar.dll
2009-06-21 18:08 . 2009-06-23 12:27 -------- d--h--w- C:\$AVG8.VAULT$
2009-06-21 18:07 . 2009-06-21 18:07 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-06-21 18:07 . 2009-06-21 18:07 12552 ----a-w- c:\windows\system32\drivers\avgrkx86.sys
2009-06-21 18:07 . 2009-06-21 18:07 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-06-21 18:07 . 2009-06-21 18:07 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-06-21 18:07 . 2009-06-21 18:07 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-06-21 18:06 . 2009-06-23 12:56 -------- d-----w- c:\windows\system32\drivers\Avg
2009-06-21 18:06 . 2009-06-22 12:46 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-06-21 18:05 . 2009-06-21 18:05 -------- d-----w- c:\program files\AVG
2009-06-21 18:05 . 2009-06-21 18:05 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-06-21 17:34 . 2009-06-21 17:34 -------- d-----w- c:\documents and settings\Administrateur\Application Data\AVG8
2009-06-21 00:24 . 2009-06-21 00:24 2 ----a-w- c:\windows\010112010146118114.dat
2009-05-25 19:20 . 2009-05-25 19:20 -------- d-sh--w- C:\found.000
2009-05-24 20:26 . 2008-07-10 22:31 53248 ----a-w- c:\windows\system32\bsicon.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-23 17:21 . 2009-01-18 11:31 1337632 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-06-23 17:21 . 2009-01-18 11:31 44679968 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-06-23 17:17 . 2009-01-18 11:31 602288 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-06-23 17:17 . 2009-01-18 11:31 129464 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-06-22 16:21 . 2009-01-18 11:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-05-18 21:16 . 2009-02-09 23:00 -------- d-----w- c:\documents and settings\Administrateur\Application Data\dvdcss
.
------- Sigcheck -------
[-] 2004-12-01 21:41 359040 1F29C2657B8C08DE92899889C99C049A c:\windows\system32\drivers\tcpip.sys
[-] 2004-10-31 16:59 8704 AB3D62010AF342203FFA60C2D94DBC68 c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5}]
2009-03-04 08:43 311808 ----a-w- c:\progra~1\SITERA~1\SiteRank.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-06-14 16:08 1004800 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"msnmsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"STYLEXP"="c:\program files\TGTSoft\StyleXP\StyleXP.exe" [2006-05-24 1372160]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-10 39408]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-01-26 2144088]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-04-01 94208]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-04-01 77824]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-04-01 114688]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-04-01 1404928]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-01-18 29744]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2009-03-31 198160]
"SiteRanker"="c:\program files\SiteRanker\SiteRankTray.exe" [2009-03-04 273920]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-21 1948440]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2009-1-16 1205840]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-06-21 18:07 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\French\\setup.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Ahead\\Nero StartSmart\\NeroStartSmart.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\WinRAR\\WinRAR.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [21/06/2009 18:07 12552]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [21/06/2009 18:07 327688]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [21/06/2009 18:07 108552]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [21/06/2009 18:05 298776]
R2 PoliceService;PoliceService;c:\windows\system32\srksrv.exe [29/01/2009 19:16 453120]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [13/12/2007 13:28 24592]
S2 ELOADER;General Purpose USB Driver (adildr.sys);c:\windows\system32\drivers\adildr.sys [16/01/2009 16:04 56088]
S2 gupdate1c9b1945d8a0f98;Service Google Update (gupdate1c9b1945d8a0f98);c:\program files\Google\Update\GoogleUpdate.exe [31/03/2009 00:04 133104]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [18/01/2009 14:31 29744]
.
Contenu du dossier 'Tâches planifiées'
2009-05-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-06-23 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-31 00:03]
2009-03-25 c:\windows\Tasks\SHUTDOWN.EXE.job
- c:\windows\system32\shutdown.exe [2004-08-04 00:55]
2009-06-23 c:\windows\Tasks\User_Feed_Synchronization-{BBB93111-7BF5-40C5-BFA3-A8EDF5B2AD0D}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 04:31]
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{140BD8E3-C167-11D4-B4A3-080000180323} - (no file)
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Ajouter à Kaspersky Anti-Bannière - c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~1\Office12\EXCEL.EXE/3000
TCP: {64F20833-C70C-45E8-861B-95E8C688499C} = 62.251.229.223 62.251.229.237
Handler: inbox - {37540F19-DD4C-478B-B2DF-C19281BCAF27} - c:\progra~1\INBOXT~1\Inbox.dll
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-23 17:19
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-1202660629-1060284298-725345543-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,3f,10,38,5b,03,68,ac,41,9a,b3,f1,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,3f,10,38,5b,03,68,ac,41,9a,b3,f1,\
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(976)
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\windows\system32\klogon.dll
- - - - - - - > 'lsass.exe'(1032)
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\fssync.dll
- - - - - - - > 'explorer.exe'(3952)
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\fssync.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\scrchpg.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\TGTSoft\StyleXP\StyleXPService.exe
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wdfmgr.exe
c:\progra~1\AVG\AVG8\avgam.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\program files\AVG\AVG8\avgscanx.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
.
**************************************************************************
.
Heure de fin: 2009-06-23 17:25 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-06-23 17:25
Avant-CF: 28 524 408 832 octets libres
Après-CF: 28 578 996 224 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
202