Concernant le service pack 3, franchement pour moi il s'agit d'une usine a gaz qui n'apporte rien de notable, si ce n'est pour les failles bien evidement mais sa fait un gros patch juste pour des faille du coup, au dela de cela je ne suis pas vraiment chaud pour modifier une configuration qui marche. J'essayerai donc de trouver uniquement les fix.
je mets le rapport combofix ci-dessous :
ComboFix 09-07-09.07 - Quequete tueuse 10/07/2009 11:16.1.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.2046.1633 [GMT 2:00]
Lancé depuis: c:\documents and settings\Quequete tueuse\Bureau\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Quequete tueuse\Application Data\inst.exe
c:\recycler\S-1-5-21-1078081533-1682526488-725345543-1003
C:\svcipa.exe
c:\temp\1cb
c:\temp\1cb\syscheck.log
c:\windows\Installer\11a4a9d.msi
c:\windows\Installer\4fb35.msi
c:\windows\Installer\5fb433.msi
c:\windows\Installer\6b420.msi
c:\windows\Installer\87b2ee.msi
c:\windows\Installer\8bdd56.msi
c:\windows\Installer\903c89.msi
c:\windows\Installer\988727.msi
c:\windows\Installer\b6cb59.msi
c:\windows\Installer\bcbabb.msi
c:\windows\msettings.ini
c:\windows\OPTIONS\CABS\_desktop.ini
c:\windows\patch.exe
c:\windows\system32\_id.dat
c:\windows\system32\ert
c:\windows\system32\open.ico
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_OREANS32
-------\Service_oreans32
((((((((((((((((((((((((((((( Fichiers créés du 2009-06-10 au 2009-07-10 ))))))))))))))))))))))))))))))))))))
.
2009-07-08 21:53 . 2009-07-08 21:53 3561743 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-07-08 16:15 . 2009-07-08 16:15 -------- d-----w- C:\_OTM
2009-07-06 21:10 . 2009-07-06 21:10 -------- d-----w- C:\rsit
2009-06-23 10:45 . 2009-03-30 08:32 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-06-23 10:45 . 2009-03-24 14:07 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-06-23 10:45 . 2009-02-13 10:28 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-06-23 10:45 . 2009-02-13 10:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-06-23 10:45 . 2009-06-23 10:45 -------- d-----w- c:\program files\Avira
2009-06-23 10:45 . 2009-06-23 10:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2009-06-19 20:44 . 2009-06-19 20:44 -------- d-----w- c:\documents and settings\Quequete tueuse\Local Settings\Application Data\vdownloader
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-10 08:35 . 2001-08-28 12:00 75506 ----a-w- c:\windows\system32\perfc00C.dat
2009-07-10 08:35 . 2001-08-28 12:00 468490 ----a-w- c:\windows\system32\perfh00C.dat
2009-07-09 21:12 . 2005-10-31 09:27 -------- d-----w- c:\documents and settings\Quequete tueuse\Application Data\Azureus
2009-07-08 21:56 . 2008-10-31 14:50 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-06 21:17 . 2006-10-16 17:39 -------- d-----w- c:\program files\Trend Micro
2009-07-06 21:03 . 2007-09-13 08:41 -------- d-----w- c:\program files\CCleaner
2009-06-24 20:26 . 2005-10-31 09:10 -------- d-----w- c:\program files\eMule
2009-06-17 09:27 . 2008-10-31 14:50 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-17 09:27 . 2008-10-31 14:50 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-05-05 19:54 . 2009-05-05 19:54 55572 ---ha-w- c:\windows\system32\mlfcache.dat
2009-04-26 13:42 . 2009-04-26 13:42 15360 ----a-r- c:\documents and settings\Quequete tueuse\Application Data\Microsoft\Installer\{DD8408E9-9421-484F-979D-DB6361E3E828}\IconDD8408E910.exe
2009-04-26 13:42 . 2009-04-26 13:42 11264 ----a-r- c:\documents and settings\Quequete tueuse\Application Data\Microsoft\Installer\{DD8408E9-9421-484F-979D-DB6361E3E828}\IconDD8408E96.exe
2007-09-10 20:30 . 2007-09-10 20:30 278528 ----a-w- c:\program files\Fichiers communs\FDEUnInstaller.exe
.
------- Sigcheck -------
[7] 2002-08-29 00:58 332928 244A2F9816BC9B593957281EF577D976 c:\windows\$NtServicePackUninstall$\tcpip.sys
[-] 2007-04-30 15:16 359040 27A5959C94EE173A063CA06BD14F021A c:\windows\system32\drivers\TCPIP.SYS
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-19 15360]
"Picasa Media Detector"="c:\program files\Picasa\PicasaMediaDetector.exe" [2008-02-26 443968]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-10-31 110592]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0autocheck lsdelete
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\WINDOWS\\system32\\mshta.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"x:\\Stranglehold.PC-Rip.Full.Game.English.Skullptura\\Stranglehold\\Binaries\\Retail-Stranglehold.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver MX 2004\\Dreamweaver.exe"=
"c:\\Program Files\\MUTE\\fileSharingMUTE.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\UbiSoft\\Far Cry 2\\bin\\FarCry2.exe"=
"c:\\Program Files\\UbiSoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"c:\\Program Files\\UbiSoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\Program Files\\Dawn of War\\W40kWA.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [23/06/2009 12:45 108289]
R2 DigiNet;Digidesign Ethernet Support;c:\windows\system32\drivers\diginet.sys [09/12/2008 23:24 11776]
S2 ousbehci;NEC PCI to USB Enhanced Host Controller;c:\windows\system32\drivers\ousbehci.sys [13/01/2006 20:55 36096]
S3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [20/02/2008 19:43 472832]
S3 HexTunnelDevice;Hexago Multi-Virtual Tunnel Adapter;c:\windows\system32\drivers\hextun.sys [20/12/2007 05:02 22176]
S3 ousb2hub;OrangeWare USB 2.0 Hub Support;c:\windows\system32\drivers\ousb2hub.sys [13/01/2006 20:55 53248]
S3 ST330;ST330;c:\windows\system32\drivers\st330.sys [27/01/2007 18:04 30464]
S3 STBUS;STBUS;c:\windows\system32\drivers\stbus.sys [27/01/2007 18:04 12672]
S3 stppp;Speedtouch PPP Adapter Adapter;c:\windows\system32\drivers\stppp.sys [27/01/2007 18:04 32000]
S3 wsvad_driver;WS Audio Device;c:\windows\system32\drivers\VirtualAudio.sys [12/12/2008 17:47 16896]
S4 msagent;FireDaemon Service: msagent;c:\windows\security\FireDaemon.exe -s --> c:\windows\security\FireDaemon.exe -s [?]
S4 netclient;FireDaemon Service: netclient;c:\windows\security\FireDaemon.exe -s --> c:\windows\security\FireDaemon.exe -s [?]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan8/oscan8.cab
FF - ProfilePath - c:\documents and settings\Quequete tueuse\Application Data\Mozilla\Firefox\Profiles\ukb6cykk.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava11.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava12.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava13.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava14.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJava32.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPJPI150_05.dll
FF - plugin: c:\program files\Java\jre1.5.0_05\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-10 11:21
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"cd042efbbd7f7af1647644e76e06692b"=hex:e2,63,26,f1,3f,c8,ff,68,1c,9a,75,69,2d,
67,b9,ba,e2,63,26,f1,3f,c8,ff,68,8f,34,63,fb,ca,1e,1c,5b,e2,63,26,f1,3f,c8,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"bca643cdc5c2726b20d2ecedcc62c59b"=hex:6a,9c,d6,61,af,45,84,18,b0,95,40,29,6c,
a2,2c,61,6a,9c,d6,61,af,45,84,18,d4,d7,4c,4d,9b,61,17,8d,6a,9c,d6,61,af,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"2c81e34222e8052573023a60d06dd016"=hex:ff,7c,85,e0,43,d4,0e,fe,d2,af,3f,3d,3f,
20,7c,a2,ff,7c,85,e0,43,d4,0e,fe,f1,e3,bc,d2,ea,4d,ba,b2,ff,7c,85,e0,43,d4,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"2582ae41fb52324423be06337561aa48"=hex:86,8c,21,01,be,91,eb,e7,e5,c3,1a,69,31,
56,65,3c,86,8c,21,01,be,91,eb,e7,1f,b8,f5,fa,a4,eb,41,c1,86,8c,21,01,be,91,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"caaeda5fd7a9ed7697d9686d4b818472"=hex:cd,44,cd,b9,a6,33,6c,cd,4d,8e,39,3c,7e,
43,78,dd,f5,1d,4d,73,a8,13,5c,05,5a,23,2e,ff,71,66,09,ef,f5,1d,4d,73,a8,13,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,ce,04,9e,d2,92,
cf,48,61,df,20,58,62,78,6b,cf,c8,53,65,ea,11,0d,51,97,60,df,20,58,62,78,6b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"4d370831d2c43cd13623e232fed27b7b"=hex:fb,a7,78,e6,12,2f,9a,ea,81,aa,84,07,3c,
2c,ce,ac,fb,a7,78,e6,12,2f,9a,ea,00,92,e7,8b,7c,25,7d,65,fb,a7,78,e6,12,2f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,2e,3c,1c,9b,09,
58,49,a0,01,3a,48,fc,e8,04,4a,f1,61,7c,5a,bd,29,f8,a2,ee,01,3a,48,fc,e8,04,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,ee,89,05,87,ac,
f1,22,e2,f6,0f,4e,58,98,5b,89,c9,1e,2f,36,14,e5,c8,20,07,f6,0f,4e,58,98,5b,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"f5f62a6129303efb32fbe080bb27835b"=hex:3d,ce,ea,26,2d,45,aa,78,61,9f,50,e3,e2,
dc,1b,ec,3d,ce,ea,26,2d,45,aa,78,74,75,22,7d,4b,7f,3f,01,3d,ce,ea,26,2d,45,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,e7,2a,41,aa,4e,
5b,cb,a2,2a,b7,cc,b5,b9,7f,41,e7,83,8d,61,0d,d5,68,d5,36,2a,b7,cc,b5,b9,7f,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
"ThreadingModel"="Apartment"
@="c:\\WINDOWS\\System32\\OLE32.DLL"
"8a8aec57dd6508a385616fbc86791ec2"=hex:fa,ea,66,7f,d4,3b,6b,70,b9,1e,d5,8a,47,
c5,60,87,6c,43,2d,1e,aa,22,2f,9c,c3,e4,d5,cd,f2,10,8a,81,6c,43,2d,1e,aa,22,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\System*]
"OODEFRAG08.00.00.01WORKSTATION"="59A4F4699FB1C80F14D4E1D34E574AA42E7EE10F346C90C5E78FB7C4100275B87362E2FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74C8EDD5E5BE2F6E6675D575E7D6A3B9808C038D530D6EB34528EDD5E5BE2F6E667168C2BD012DE04815196BAF9D94015F5170AF9A38A80D4D0E29510C47294BC1E2CF8B7AB292A6988DFA8E7808A2C14006635109449188E373B08E1028AA0D7E511F12B9C1523BDE48A094135106C9394FECDFAA452CE6F1AD1B0B9B13E017FDF5AD80ABCB25A6A755744C2C488CFC53677AFCD37A250943EEED6660A095F5BB6A101F7369C95C06CD05A8D714F59453B6C264340787B0041E1B25756AD1974EB842E4349B74F72508640638C0ABE0D4E7D7236C8D865969277F224F3313D3A55A49ED8C728B318788ADC2E819FEAFD6F4EC92AEF8CD4A2F587BA07555B917E9AA700CA1B5AA42D14740CF74A3AFC5BEF86D542E49FC5CF82E79E5C013A8DF8B7B776523C7AB710255C1FF1F74A464F77D134C76EE1E5B0A57829A7911FDDC1FE0218C8BBFAB6058163D86FAD03CD657F5F73A7E4671B3B9D97D80E359FE25895386FAD3D13A0B2D22CF1E826D94D8E59639A71B6097C47FE2A9ED8AC14B220F2907C24763CA325165B96F9AB8AB51E2515225CE2E0D314319961F6CF1A93DE634331F1B4B4A74B1D1E66611F15274DDAB0774101D122C0EE527B7A881383BD898F7603557E45F80FA17505F43CF938C5F5F91BBA7E9BD4CAC43998D5A232CC583625E5CCE04A65E4984BEBB507B76084A7810CCACFA53926E5DE2BC83305FD1AFC0ECD22E2392C6C39E4C1FC411E28098E545883705DBAB9ADA0B008F115A6EAAD7311EF56464DC6BEB1D6FAF9A0D81AF431E84B52120B1199A94A4E50AC03BB168BAB67CBDB2A6AE8179EF302662053ABC8CC1A2847BF8C2A973E69024E30D10803BAC919168C21786B314174C88C23853F317D6B34D15E637D76BB022D314458F7836FD8C79D09B57ACB4E29D6934CDA2F6E98D6449E8FCD5E01BA0CB3EB0261FC6A4369F5EE93E905CB1CC1D38CE58724FA1DEB1768FBF63790F2227B2C4A809A7CC4EBDA710764BF363D1FB4B5D9E92075D76E015353EFF5F88089571E3297CAE686C7637F7B78D1345BE9A42E6866181E236688E919CB7AB596CA4C55220CFBFD3126B0D2DF7B578FB28C827AA2E574D8F29F6999A5A41DE47BB211C758C792387EF51A8AF548E03A93B6E00270511230CAAA93B2231727C789531351E3B8E430BEE9A62B543F724662DA06130C9BC25044DBAAEA13425543AE81F1AEAACFBDA45576959A624082EC1631EC5D04B5CB0A8C4A065DC84BDA63EC5604036583DBF8B7D5D6A561B47F893DB4C375BB18E452E5533084EBDBDDD4DA2FCF54214CF3B3740912FADF85C79CF523"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(704)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(4064)
c:\windows\system32\msi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\windows\system32\scardsvr.exe
c:\program files\a-squared\a2service.exe
c:\program files\Fichiers communs\Maxtor\Schedule2\schedul2.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Digidesign\Drivers\MMERefresh.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2009-07-10 11:24 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-07-10 09:24
Avant-CF: 9 943 887 872 octets libres
Après-CF: 9 875 189 760 octets libres
Current=1 Default=1 Failed=0 LastKnownGood=6 Sets=1,2,3,4,5,6
233