Allo!!
Voici le log de combo
ComboFix 09-07-09.08 - Marie-Eve 2009-07-11 18:19.1.1 - FAT32x86
Lancé depuis: c:\documents and settings\Marie-Eve\Bureau\combo-fix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycled\NPROTECT
c:\windows\Installer\436ecb64.msi
c:\windows\Installer\d3fa4.msi
c:\windows\patch.exe
c:\windows\start.exe
c:\windows\system\msvbvm60.dll
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\imas3r
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\windows.scr
c:\windows\system32\WS2Fix.exe
c:\windows\Web\default.htt
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MSASVC
-------\Legacy_WINCOM32
-------\Service_MsaSvc
((((((((((((((((((((((((((((( Fichiers créés du 2009-06-11 au 2009-07-11 ))))))))))))))))))))))))))))))))))))
.
2018-04-02 23:15 . 2003-11-04 19:10 69632 ----a-w- c:\windows\system32\lfgif13n.dll
2018-04-02 23:15 . 2004-05-14 20:53 462848 ----a-w- c:\windows\system32\ltkrn13n.dll
2018-04-02 23:15 . 2004-05-14 20:53 450560 ----a-w- c:\windows\system32\ltimg13n.dll
2018-04-02 23:15 . 2004-05-14 20:53 299008 ----a-w- c:\windows\system32\ltdis13n.dll
2018-04-02 23:15 . 2004-05-14 20:53 163840 ----a-w- c:\windows\system32\ltfil13n.dll
2018-04-02 23:15 . 2004-05-14 20:53 57344 ----a-w- c:\windows\system32\lfbmp13n.dll
2018-04-02 23:15 . 2004-05-14 20:53 401408 ----a-w- c:\windows\system32\lfcmp13n.dll
2018-04-02 23:15 . 2004-01-12 06:09 206336 ----a-w- c:\windows\system32\ltefx13n.dll
2018-03-29 01:31 . 2002-08-29 05:27 4992 ----a-w- c:\windows\system32\drivers\MSTEE.sys
2018-03-29 01:30 . 2001-08-18 02:07 8064 ----a-w- c:\windows\system32\drivers\NdisIP.sys
2018-03-29 01:30 . 2001-08-18 02:07 14592 ----a-w- c:\windows\system32\drivers\StreamIP.sys
2018-03-29 01:30 . 2001-08-18 02:07 10752 ----a-w- c:\windows\system32\drivers\SLIP.sys
2018-03-29 01:30 . 2001-08-18 02:07 18560 ----a-w- c:\windows\system32\drivers\WSTCODEC.SYS
2018-03-29 01:30 . 2001-08-18 02:07 83712 ----a-w- c:\windows\system32\drivers\NABTSFEC.sys
2018-03-29 01:30 . 2002-08-29 05:33 16384 ----a-w- c:\windows\system32\drivers\CCDECODE.sys
2018-03-29 01:30 . 2001-08-23 21:47 45568 ----a-w- c:\windows\system\IYUV_32.DLL
2018-03-29 01:30 . 2002-08-29 15:45 286720 ----a-w- c:\windows\system\MSH263.DRV
2018-03-29 01:30 . 2002-08-29 15:45 50688 ----a-w- c:\windows\system32\vfwwdm32.dll
2018-03-29 01:29 . 2002-08-29 05:32 56832 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2018-02-09 03:13 . 2018-02-09 03:13 499712 ----a-w- c:\windows\system32\msvcp71.dll
2018-02-09 03:13 . 2018-02-09 03:13 348160 ----a-w- c:\windows\system32\msvcr71.dll
2018-02-08 23:19 . 2004-12-20 17:37 20016 ------w- c:\windows\system32\drivers\pxhelp20.sys
2018-02-01 20:44 . 2002-10-21 15:37 515803 ----a-w- c:\windows\system32\drivers\Ca533av.sys
2018-02-01 20:44 . 2002-07-25 15:19 10986 ----a-w- c:\windows\system32\drivers\Bulk533.sys
2018-02-01 20:44 . 2002-01-19 19:33 131072 ----a-w- c:\windows\system32\Sp5x_32.dll
2018-02-01 20:44 . 2002-01-19 19:33 131072 ----a-w- c:\windows\system\SP5X_32.DLL
2018-02-01 20:44 . 2018-02-01 20:44 -------- d-----w- c:\windows\Setup533
2018-02-01 20:43 . 2018-02-01 20:43 -------- d-----w- c:\windows\CameraInstall
2018-01-30 16:19 . 2018-01-30 16:19 333 ------w- c:\temp\msbb_gdf.dat
2018-01-30 16:15 . 2018-02-07 18:47 8457743 ----a-w- c:\temp\msbb_kyf.dat
2009-07-11 22:03 . 2009-07-11 22:03 -------- d-s---w- C:\ComboFix
2009-07-09 22:29 . 2009-07-09 22:29 -------- d-----w- c:\windows\ERUNT
2009-07-09 22:27 . 2008-11-06 06:03 -------- d-----w- C:\SDFix
2009-07-09 21:49 . 2009-03-30 14:33 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-07-09 21:49 . 2009-02-13 16:29 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-07-09 21:49 . 2009-02-13 16:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-07-09 21:48 . 2009-07-09 21:48 -------- d-----w- c:\program files\Avira
2009-07-09 21:48 . 2009-07-09 21:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-07-07 20:29 . 2003-03-18 19:20 1060864 ----a-w- c:\windows\system32\MFC71.dll
2009-07-07 20:29 . 2009-07-07 20:29 -------- d-----w- c:\program files\Alwil Software
2009-07-07 18:04 . 2009-07-07 18:04 -------- d-----w- c:\program files\TeaTimer (Spybot - Search & Destroy)
2009-07-07 18:04 . 2009-07-07 18:04 -------- d-----w- c:\program files\SDHelper (Spybot - Search & Destroy)
2009-07-07 18:04 . 2009-07-07 18:04 -------- d-----w- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2009-07-07 18:04 . 2009-07-07 18:04 -------- d-----w- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-07-07 01:20 . 2009-07-07 01:20 -------- d-----w- c:\documents and settings\Marie-Eve\Application Data\Malwarebytes
2009-07-07 01:20 . 2009-07-07 01:20 -------- d-----w- c:\documents and settings\Marie-Eve\Application Data\Malwarebytes
2009-07-07 01:19 . 2009-06-17 15:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-07 01:19 . 2009-07-07 01:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-07-07 01:19 . 2009-06-17 15:27 18456 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-07 01:19 . 2009-07-07 01:19 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-06 23:47 . 2009-07-06 23:47 -------- d-----w- c:\program files\Navilog1
2009-07-06 00:41 . 2009-07-06 00:41 -------- d-----w- C:\GenProc
2009-07-06 00:22 . 2009-07-06 00:22 -------- d-----w- c:\program files\backups
2009-07-05 23:56 . 2009-07-05 23:56 -------- d-----w- c:\program files\CCleaner
2009-07-05 21:46 . 2009-07-05 21:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Avg7
2009-07-05 20:36 . 2009-07-05 20:36 -------- d-----w- C:\VundoFix Backups
2009-07-05 19:22 . 2009-07-05 19:22 396288 ----a-w- c:\program files\HijackThis.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2018-02-01 01:05 . 2004-03-09 21:38 12400 ----a-w- c:\windows\system32\drivers\secdrv.sys
2018-02-01 01:04 . 2002-11-21 17:33 1844 ----a-w- c:\windows\eReg.dat
2009-07-08 00:17 . 2009-07-05 19:24 4755 ----a-w- c:\program files\hijackthis.log
2009-07-07 01:13 . 2004-03-09 21:44 48616 ----a-w- c:\windows\system32\perfc00C.dat
2009-07-07 01:13 . 2004-03-09 21:44 367658 ----a-w- c:\windows\system32\perfh00C.dat
2002-11-14 01:15 . 2002-11-14 01:15 23506 ---h--w- c:\program files\folder.htt
2006-04-26 00:58 . 2006-04-26 00:58 0 --sha-w- c:\windows\SYSTEM32\wupdmgr.tmp
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\MSN Messenger\MSNMSGR.EXE" [2006-01-25 7094272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2005-12-21 278528]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2002-09-07 13312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"Printing Migration"="c:\windows\System32\spool\migrate.dll" [2002-09-07 30720]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"msnmsgr"="c:\program files\MSN MESSENGER\MSNMSGR.EXE" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"3dfx Tools"=rundll32.exe 3dfxCmn.dll,CMNUpdateOnBoot
"WinampAgent"="c:\program files\WINAMP\WINAMPa.exe"
"AudioHQ"=c:\program files\Creative\SBLive\AudioHQ\AHQTB.EXE
"KAZAA"="c:\program files\KAZAA LITE K++\KPP.EXE" "c:\program files\KAZAA LITE K++\KAZAA.KPP" /SYSTRAY
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\setup\disabledrunkeys]
"LoadPowerProfile"=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
"SM56ACL"=sm56hlpr.exe
"LoadQM"=loadqm.exe
"NewsUpd"=c:\program files\Creative\News\NewsUpd.EXE /q
"Détecteur de disque"=c:\program files\Creative\ShareDLL\CtNotify.exe
"couponsandoffers"=wjview /cp:p "c:\program files\couponsandoffers\System\Code" Main lp: "c:\program files\couponsandoffers"
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe"
"Advanced Tools Check"=c:\progra~1\NORTON~1\ADVTOOLS\ADVCHK.EXE
"NPROTECT"=c:\progra~1\NORTON~1\ADVTOOLS\NPROTECT.EXE
R0 avgntmgr;avgntmgr;c:\windows\SYSTEM32\DRIVERS\avgntmgr.sys [2009-07-09 22360]
R1 avgntdd;avgntdd;c:\windows\SYSTEM32\DRIVERS\avgntdd.sys [2009-07-09 45416]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-07-09 108289]
R3 3dfxvs;3dfxvs;c:\windows\SYSTEM32\DRIVERS\3dfxvsm.sys [2001-10-03 148352]
S2 Ca533av;Polaroid Digital Cam Video;c:\windows\SYSTEM32\DRIVERS\Ca533av.sys [2018-02-01 515803]
S3 Ip6FwHlp;Pare-feu de connexion Internet IPv6;c:\windows\System32\svchost.exe -k netsvcs [2004-03-09 12800]
S3 NtApm;Pilote d'interface NT APM/hérité;c:\windows\SYSTEM32\DRIVERS\NtApm.sys [2004-03-09 9472]
S3 USBCamera;Icatch(IV) Still Camera Device;c:\windows\SYSTEM32\DRIVERS\Bulk533.sys [2018-02-01 10986]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"c:\progra~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:WIN9X /user /install
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
"c:\progra~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:WIN9X /user /install
"c:\progra~1\OUTLOO~1\setup50.exe" /APP:OE /CALLER:IE50 /user /install
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
"c:\progra~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
"c:\progra~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:WIN9X /user /install
"c:\progra~1\OUTLOO~1\setup50.exe" /APP:WAB /CALLER:IE50 /user /install
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9EF0045A-CDD9-438e-95E6-02B9AFEC8E11}]
c:\windows\SYSTEM32\updcrl.exe -e -u c:\windows\SYSTEM\verisignpub1.crl
.
Contenu du dossier 'Tâches planifiées'
2009-07-11 c:\windows\Tasks\Rappel d'expiration de la désinstallation.job
- c:\windows\System32\OOBE\oobebaln.exe [2004-03-09 04:00]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-SysOps - c:\windows\System32\termcaps.exe
HKCU-Run-SWClient - c:\windows\System32\termcaps.exe
HKCU-Run-slipaccel.exe - c:\program files\Netscape Online Accélérateur\slipaccel.exe
HKCU-Run-NetscapeCC - c:\program files\Netscape Online\ICC\NetscapeCC.exe
HKCU-Run-hkgaqge - c:\windows\System32\termcaps.exe
HKCU-Run-AdRoarUpdate - c:\windows\System32\termcaps.exe
HKLM-Run-win32hp - c:\windows\System32\winalt32.exe
HKLM-Run-wdokbye.dll - c:\documents and settings\Simon\Local Settings\Application Data\wdokbye.dll
HKLM-Run-avast! - c:\progra~1\ALWILS~1\Avast4\ashDisp.exe
.
------- Examen supplémentaire -------
.
Trusted Zone: microsoft.com\v4.windowsupdate
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-11 18:36
Windows 5.1.2600 Service Pack 1 FAT NTAPI
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(508)
c:\windows\System32\ODBC32.dll
- - - - - - - > 'lsass.exe'(564)
c:\windows\System32\dssenh.dll
- - - - - - - > 'explorer.exe'(164)
c:\windows\System32\msi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\AVIRA\ANTIVIR DESKTOP\AVGUARD.EXE
c:\windows\SYSTEM32\WDFMGR.EXE
c:\program files\iPod\bin\iPodService.exe
c:\windows\System32\devldr32.exe
.
**************************************************************************
.
Heure de fin: 2009-07-11 18:44 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-07-11 22:44
Avant-CF: 109 641 728 octets libres
Après-CF: 220 168 192 octets libres
winxpsp1_fr_pro_bf.exe
[boot loader]
timeout = 30
default = multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS = "Microsoft Windows XP Professionnel" /fastdetect
215