Euh par contre il a redémarré mon ordi lors du scan avec bien sur mes logiciels de protections!!! j'espère que ça craint pas trop?
voici le rapport:
ComboFix 09-07-02.02 - laurent 03/07/2009 19:02.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.2046.1610 [GMT 2:00]
Lancé depuis: c:\documents and settings\laurent\Bureau\ComboFix.exe
AV: Avira AntiVir PersonalEdition Classic *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\laurent\Application Data\Microsoft\rsvp.exe
c:\documents and settings\laurent\Local Settings\Application Data\cisvc.exe
c:\documents and settings\laurent\Local Settings\Application Data\cmstp.exe
c:\program files\INSTALL.LOG
c:\windows\Installer\WMEncoder.msi
c:\windows\sc32.dll
c:\windows\SoftwareProtection\Windows External Security Update.exe
c:\windows\system\dllhst3g.exe
c:\windows\system\logman.exe
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASC3550P
((((((((((((((((((((((((((((( Fichiers créés du 2009-06-03 au 2009-07-03 ))))))))))))))))))))))))))))))))))))
.
2009-07-03 17:05 . 2009-04-22 13:42 61440 ----a-w- c:\windows\system32\drivers\dllhst3g.exe
2009-07-03 17:05 . 2009-04-22 13:42 61440 ----a-w- c:\windows\logman.exe
2009-07-03 10:11 . 2009-04-22 13:42 61440 ----a-w- c:\windows\system\mstsc.exe
2009-07-03 10:09 . 2009-04-22 13:42 61440 ----a-w- c:\windows\system\cmstp.exe
2009-07-02 11:09 . 2009-07-02 11:10 -------- d-----w- c:\program files\Windows Live Safety Center
2009-07-02 11:05 . 2008-12-03 23:25 120832 ----a-w- c:\documents and settings\laurent\Application Data\Mozilla\Firefox\Profiles\mbxje88k.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}\plugins\npietab.dll
2009-07-01 10:28 . 2009-07-01 10:28 -------- d-----w- c:\documents and settings\laurent\Application Data\Malwarebytes
2009-07-01 10:28 . 2009-06-17 09:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-01 10:28 . 2009-07-01 10:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-01 10:28 . 2009-06-17 09:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-12 08:43 . 2009-06-12 08:43 -------- d-----w- c:\program files\LAURENT-0CE109D
2009-06-06 07:36 . 2009-06-06 07:36 -------- d-----w- c:\documents and settings\laurent\Local Settings\Application Data\Babylon
2009-06-06 07:36 . 2009-06-06 07:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Babylon
2009-06-06 07:36 . 2009-06-06 07:37 -------- d-----w- c:\documents and settings\laurent\Application Data\Babylon
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-03 17:06 . 2008-05-29 09:26 -------- d-----w- c:\program files\lx_cats
2009-07-03 16:00 . 2008-12-22 00:07 -------- d-----w- c:\program files\Fichiers communs\Symantec Shared
2009-07-03 16:00 . 2008-12-22 00:07 -------- d-----w- c:\program files\Norton Security Scan
2009-07-03 14:39 . 2008-05-12 13:23 848 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-06-29 20:55 . 2008-05-07 22:18 189072 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-06-29 20:27 . 2008-05-07 22:18 138920 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-06-03 09:04 . 2008-12-24 08:04 75096 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-06-02 10:13 . 2009-06-02 10:13 -------- d-----w- c:\program files\Ubi Soft
2009-06-02 10:12 . 2009-06-02 10:12 -------- d-----w- c:\documents and settings\laurent\Application Data\ubi.com
2009-06-02 10:12 . 2009-06-02 10:12 -------- d-----w- c:\program files\Fichiers communs\PocketSoft
2009-06-02 10:12 . 2008-05-07 20:59 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-23 08:14 . 2001-08-28 12:00 601274 ----a-w- c:\windows\system32\perfh00C.dat
2009-05-23 08:14 . 2001-08-28 12:00 108120 ----a-w- c:\windows\system32\perfc00C.dat
2009-04-29 16:02 . 2008-05-07 09:28 34440 ----a-w- c:\documents and settings\laurent\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-04-27 09:21 . 2009-04-27 09:21 160258 ----a-w- c:\windows\Sqirlz Morph Uninstaller.exe
2009-04-25 16:16 . 2009-04-10 15:09 345600 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-04-21 22:20 . 2009-04-21 22:20 14311680 ----a-w- c:\windows\system32\xlive.dll
2009-04-21 22:20 . 2009-04-21 22:20 13642496 ----a-w- c:\windows\system32\xlivefnt.dll
1998-09-25 11:16 . 2008-10-23 15:45 270848 ----a-w- c:\program files\UNWISE.EXE
2009-02-25 14:45 . 2009-02-25 14:39 24 --sh--w- c:\windows\SCE25DB7D.tmp
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="i:\spybot\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UVS10 Preload"="i:\video studio 10+\uvPL.exe" [2006-03-06 36864]
"avgnt"="i:\antivir\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"LXCRCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll" [2006-11-21 106496]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2009-01-23 185872]
"CloneCDTray"="i:\clone cd\CloneCD\CloneCDTray.exe" [2006-09-28 57344]
"Corel Photo Downloader"="c:\program files\Fichiers communs\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe" [2007-08-16 531272]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-05-16 1630208]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"DllHst"="c:\docume~1\laurent\LOCALS~1\APPLIC~1\MICROS~1\dllhst3g.exe" [2009-04-22 61440]
[HKEY_USERS\.DEFAULT\software\microsoft\windows\Currentversion\policies\explorer\Run]
"ClipSrv"="c:\docume~1\laurent\LOCALS~1\APPLIC~1\MICROS~1\clipsrv.exe" [2009-04-22 61440]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Microsoft Office.lnk - i:\office xp 2002\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=c:\docume~1\laurent\LOCALS~1\Temp\logman.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"i:\\EMULE\\emule.exe"=
"e:\\GTR2\\GTR2.exe"=
"e:\\COD 4\\iw3sp.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"e:\\ASSASSIN'S CREED\\AssassinsCreed_Dx9.exe"=
"e:\\ASSASSIN'S CREED\\AssassinsCreed_Dx10.exe"=
"e:\\ASSASSIN'S CREED\\AssassinsCreed_Launcher.exe"=
"c:\\WINDOWS\\system32\\lxcrcoms.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"e:\\FSX\\fsx.exe"=
"c:\\Program Files\\Alice_Triway_WiFi\\Wizard\\CTD_FirmwareUpgrader.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Fichiers communs\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\WINDOWS\\Windl\\mirc.exe"=
"e:\\COD 4\\iw3mp.exe"=
"i:\\REALPLAYER\\realplay.exe"=
"d:\\GRAND THEFT AUTO IV\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"d:\\GRAND THEFT AUTO IV\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"d:\\GRAND THEFT AUTO IV\\Grand Theft Auto IV\\GTAIV.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [02/01/2009 00:33 28544]
R3 L6DP;L6DP;c:\windows\system32\drivers\l6dp.sys [10/12/2005 02:07 27392]
R3 L6TPortA;Service - Line 6 TonePort UX1;c:\windows\system32\drivers\L6TPortA.sys [10/12/2005 02:06 393216]
R3 WsAudioDevice_383;WsAudioDevice_383;c:\windows\system32\drivers\WsAudioDevice_383.sys [09/04/2009 09:08 16640]
S3 GVTDrv;GVTDrv;c:\windows\system32\drivers\GVTDrv.sys [07/05/2008 23:32 24944]
S3 Tileproxy;Tileproxy;c:\windows\system32\DRIVERS\tileproxy.sys --> c:\windows\system32\DRIVERS\tileproxy.sys [?]
.
Contenu du dossier 'Tâches planifiées'
2009-06-11 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 12:57]
2009-07-03 c:\windows\Tasks\Norton Security Scan for laurent.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 19:20]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-Uniblue RegistryBooster 2009 - e:\jeux johan\Uniblue\RegistryBooster\RegistryBooster.exe
HKCU-Run-AdobeBridge - (no file)
HKLM-Explorer_Run-SessMgr - c:\windows\System32\drivers\sessmgr.exe
HKLM-Explorer_Run-Cisvc - c:\docume~1\laurent\APPLIC~1\MICROS~1\cisvc.exe
HKLM-Explorer_Run-Spool - c:\docume~1\laurent\APPLIC~1\spoolsv.exe
HKLM-Explorer_Run-ClipSrv - c:\docume~1\laurent\APPLIC~1\clipsrv.exe
HKCU-Explorer_Run-DllHst - c:\docume~1\laurent\APPLIC~1\MICROS~1\dllhst3g.exe
HKCU-Explorer_Run-SessMgr - c:\docume~1\laurent\APPLIC~1\MICROS~1\sessmgr.exe
HKCU-Explorer_Run-Cisvc - c:\docume~1\laurent\LOCALS~1\APPLIC~1\MICROS~1\cisvc.exe
HKCU-Explorer_Run-IEudinit - c:\docume~1\laurent\LOCALS~1\APPLIC~1\MICROS~1\ieudinit.exe
HKCU-Explorer_Run-MqtgSVC - c:\docume~1\laurent\LOCALS~1\APPLIC~1\mqtgsvc.exe
HKCU-Explorer_Run-MstInit - c:\docume~1\laurent\LOCALS~1\APPLIC~1\MICROS~1\mstinit.exe
HKCU-Explorer_Run-Esent Utl - c:\docume~1\laurent\LOCALS~1\APPLIC~1\MICROS~1\esentutl.exe
HKU-Default-Explorer_Run-Spool - c:\docume~1\laurent\APPLIC~1\spoolsv.exe
HKU-Default-Explorer_Run-Esent Utl - c:\docume~1\laurent\APPLIC~1\esentutl.exe
HKU-Default-Explorer_Run-MqtgSVC - c:\docume~1\laurent\LOCALS~1\APPLIC~1\MICROS~1\mqtgsvc.exe
HKU-Default-Explorer_Run-Logman - c:\docume~1\laurent\APPLIC~1\logman.exe
.
------- Examen supplémentaire -------
.
uStart Page = about:blank
uInternet Connection Wizard,ShellNext = hxxp://www.fsinsider.com/downloads/Pages/FlightSimulatorXServicePack1.aspx
IE: Ajouter la cible du lien à un fichier PDF existant - c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Ajouter à un fichier PDF existant - c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir au format Adobe PDF - c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir la cible du lien au format Adobe PDF - c:\program files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: E&xporter vers Microsoft Excel - i:\office~1\Office10\EXCEL.EXE/3000
IE: Save Flash - e:\jeux johan\Flash Saving Plugin\FlashSButton.dll/210
IE: Save YouTube Video - e:\jeux johan\Flash Saving Plugin\FlashSButton.dll/217
IE: Translate this web page with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
IE: {{F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
Trusted Zone: line6.net
FF - ProfilePath - c:\documents and settings\laurent\Application Data\Mozilla\Firefox\Profiles\mbxje88k.default\
FF - prefs.js: browser.startup.homepage - hxxp://my.ebay.fr/ws/eBayISAPI.dll?MyEbayBeta&CurrentPage=MyeBayNextSold&ssPageName=STRK:ME:LNLK:MESOX|http://webmail.aliceadsl.fr/cgi-bin/webmail|http://onecare.live.com/site/fr-be/article/firefox.htm
FF - component: i:\realplayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\Fichiers communs\ParallelGraphics\Cortona\npCortona.dll
FF - plugin: i:\firefox\plugins\npCortona.dll
FF - plugin: i:\quicktime\Plugins\npqtplugin.dll
FF - plugin: i:\quicktime\Plugins\npqtplugin2.dll
FF - plugin: i:\quicktime\Plugins\npqtplugin3.dll
FF - plugin: i:\quicktime\Plugins\npqtplugin4.dll
FF - plugin: i:\quicktime\Plugins\npqtplugin5.dll
FF - plugin: i:\quicktime\Plugins\npqtplugin6.dll
FF - plugin: i:\quicktime\Plugins\npqtplugin7.dll
FF - plugin: i:\realplayer\Netscape6\nppl3260.dll
FF - plugin: i:\realplayer\Netscape6\nprjplug.dll
FF - plugin: i:\realplayer\Netscape6\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-03 19:06
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCRCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-1343024091-1682526488-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{1AE02F12-784A-9EF9-8015-9228D1D5254C}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"iaikgkcedfnfgcolpc"=hex:69,61,6b,70,6c,65,6c,6a,6b,6d,6c,63,64,63,6a,6c,62,6b,
00,7c
"haokmkpemjmohaec"=hex:6a,61,69,70,62,66,62,6f,61,63,70,67,6f,6b,6e,6d,69,6c,
6c,6d,00,8a
[HKEY_USERS\S-1-5-21-1343024091-1682526488-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:7d,0c,1c,0d,24,20,e4,05,82,69,1c,43,10,db,94,8a,d8,1b,c5,35,8c,d4,05,
4f,4f,20,12,82,53,02,22,fd,9c,6f,12,55,c4,ae,f8,a7,c8,f0,8e,df,7f,3d,2f,c7,\
"??"=hex:f9,91,82,34,80,a5,8d,80,95,ba,8d,02,c8,36,22,6a
[HKEY_USERS\S-1-5-21-1343024091-1682526488-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:2e,bb,c5,52,96,9d,7f,f5,57,2e,86,26,6d,f7,79,74,76,7d,c3,ac,61,
73,2f,85,f3,2a,be,b1,78,44,b0,24,07,82,01,89,07,96,89,d3,85,13,ba,ad,b8,20,\
"rkeysecu"=hex:66,93,26,cc,ab,cc,99,51,be,ea,7a,43,6a,9b,88,f1
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(1048)
c:\program files\Fichiers communs\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
- - - - - - - > 'lsass.exe'(1104)
c:\windows\system32\relog_ap.dll
- - - - - - - > 'explorer.exe'(3152)
c:\windows\system32\nview.dll
c:\windows\system32\NVWRSFR.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
i:\antivir\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\windows\system32\rundll32.exe
c:\program files\Fichiers communs\Acronis\Schedule2\schedul2.exe
i:\antivir\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\windows\system32\lxcrcoms.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\PSIService.exe
c:\program files\Fichiers communs\Acronis\Fomatik\TrueImageTryStartService.exe
c:\program files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2009-07-03 19:08 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-07-03 17:08
Avant-CF: 3 122 700 288 octets libres
Après-CF: 3 080 544 256 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect /noguiboot
248 --- E O F --- 2009-05-23 06:56