C'est fait ! Je me souviens d'avoir déjà utilisé ce logiciel.
Voici le rapport :
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\emMON.exe
c:\windows\kb913800.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\kmd.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\temp#01.exe
c:\windows\system32\tmp.reg
E:\autorun.inf
Une copie infectée de c:\windows\system32\tftp.exe a été trouvée et désinfectée
Copie restaurée à partir de - c:\i386\tftp.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-09-19 au 2009-10-19 ))))))))))))))))))))))))))))))))))))
.
2009-10-19 16:42 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-19 16:42 . 2009-10-19 16:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-10-19 16:42 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-19 16:42 . 2009-10-19 16:42 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-14 22:05 . 2009-10-19 15:42 -------- d-----w- c:\program files\Mozilla Thunderbird
2009-10-02 06:31 . 2009-10-02 06:31 -------- d-----w- c:\documents and settings\LocalService\Menu Démarrer
2009-10-02 06:31 . 2009-10-02 07:53 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-10-02 06:31 . 2009-03-30 08:32 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2009-10-02 06:31 . 2009-02-13 10:28 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2009-10-02 06:31 . 2009-02-13 10:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2009-10-02 06:30 . 2009-10-02 06:30 -------- d-----w- c:\program files\Avira
2009-10-02 06:30 . 2009-10-02 06:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-16 09:44 . 2005-09-01 05:53 86712 ----a-w- c:\windows\system32\perfc00C.dat
2009-10-16 09:44 . 2005-09-01 05:53 515286 ----a-w- c:\windows\system32\perfh00C.dat
2009-10-02 06:59 . 2006-01-26 15:16 5642 --sha-w- c:\windows\system32\KGyGaAvL.sys
2009-10-02 06:59 . 2006-01-26 15:16 104 --sh--r- c:\windows\system32\A19A462C6B.sys
2009-10-01 08:46 . 2007-02-25 15:56 -------- d-----w- c:\program files\Wanadoo
2009-09-11 14:12 . 2005-09-01 05:53 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 20:46 . 2005-09-01 05:53 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 07:28 . 2005-09-01 05:53 832512 ----a-w- c:\windows\system32\wininet.dll
2009-08-29 07:28 . 2005-09-01 05:53 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-08-29 07:28 . 2005-09-01 05:53 17408 ----a-w- c:\windows\system32\corpol.dll
2009-08-26 08:15 . 2005-09-01 05:53 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-05 09:06 . 2005-09-01 05:53 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 17:52 . 2009-08-04 17:52 1193832 ----a-w- c:\windows\system32\FM20.DLL
2009-08-04 17:16 . 2004-08-04 00:48 2065024 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-08-04 17:16 . 2005-09-01 05:53 2188032 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-09-13 155648]
"SunJavaUpdateSched"="c:\program files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 32881]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-05 344064]
"Dell QuickSet"="c:\program files\Dell\QuickSet\quickset.exe" [2005-09-01 684032]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\program files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-11-26 155648]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-02-16 185896]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-15 385024]
"EOUApp"="c:\program files\Intel\Wireless\Bin\EOUWiz.exe" [2004-10-15 356352]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"PspUsbCf"="PspUsbCf.exe" - c:\windows\system32\pspusbcf.exe [2005-12-06 94208]
"PspContr"="PspContr.Exe" - c:\windows\system32\pspcontr.exe [2005-12-06 389120]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-10 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-1-22 24576]
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-2-25 954475]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2004-10-15 09:27 110592 ----a-w- c:\program files\Intel\Wireless\Bin\LgNotify.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R0 pnpshark;pnpshark;c:\windows\system32\drivers\pnpshark.sys [02/10/2003 04:16 119552]
R0 st3shark;st3shark;c:\windows\system32\drivers\st3shark.sys [27/09/2003 15:37 5504]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [02/10/2009 08:31 108289]
S3 se57bus;Sony Ericsson Device 087 driver (WDM);c:\windows\system32\drivers\se57bus.sys [12/11/2007 20:51 61536]
S3 se57mdfl;Sony Ericsson Device 087 USB WMC Modem Filter;c:\windows\system32\drivers\se57mdfl.sys [12/11/2007 20:52 9360]
S3 se57mdm;Sony Ericsson Device 087 USB WMC Modem Driver;c:\windows\system32\drivers\se57mdm.sys [12/11/2007 20:52 97088]
S3 se57mgmt;Sony Ericsson Device 087 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\se57mgmt.sys [12/11/2007 20:53 88624]
S3 se57nd5;Sony Ericsson Device 087 USB Ethernet Emulation SEMC57 (NDIS);c:\windows\system32\drivers\se57nd5.sys [12/11/2007 20:53 18704]
S3 se57obex;Sony Ericsson Device 087 USB WMC OBEX Interface;c:\windows\system32\drivers\se57obex.sys [12/11/2007 20:53 86432]
S3 se57unic;Sony Ericsson Device 087 USB Ethernet Emulation SEMC57 (WDM);c:\windows\system32\drivers\se57unic.sys [12/11/2007 20:53 90800]
.
Contenu du dossier 'Tâches planifiées'
2006-01-25 c:\windows\Tasks\Rappel d'abonnement 1 auprès de l'ISP.job
- c:\windows\system32\OOBE\oobebaln.exe [2005-09-01 12:00]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.sfr.fr/kit/adsl/
mStart Page = hxxp://www.google.com
uInternet Connection Wizard,ShellNext = iexplore
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
Trusted Zone: amaena.com
Trusted Zone: onerateld.com
FF - ProfilePath - c:\documents and settings\Eloïse\Application Data\Mozilla\Firefox\Profiles\g3y9ucwp.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPOJI610.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- PARAMETRES FIREFOX ----
FF - user.js: dom.disable_open_during_load - false // Popupblocker control handled by McAfee Privacy Service
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{D1AC450E-43E6-41B6-82F5-8A18FB00C030} - c:\program files\MSN Gaming Zone\qubogyhc:\windows\system32\uwce9\renamd83122.exe.dll
BHO-{F29115DF-35E9-4BCF-996C-E03D0CDB9D03} - c:\program files\MSN Gaming Zone\qubogyhc:\docume~1\ELOSE~1\LOCALS~1\Temp\mst455101.exe.dll
HKCU-Run-ActHlpApi - c:\windows\system32\fuhgnufo.exe
HKLM-Run-emMON - emMON.exe
HKLM-Run-CBC9CFCFCCCFD0CB - E4E2E8E8E5E8E9.exe
HKLM-Explorer_Run-TKKTvaxoHb - c:\documents and settings\All Users\Application Data\dcpgfyvu\zstmjupw.exe
SSODL-shen-{2E5A65BB-B055-C0DD-0118-09975F2EE086} - c:\program files\uqbjlwd\shen.dll
AddRemove-HijackThis - c:\documents and settings\Eloïse\Local Settings\Temp\HiJackThis\HijackThis.exe
AddRemove-ShockwaveFlash - c:\windows\system32\Macromed\Flash\FlashUtil9c.exe
AddRemove-{1ADE23D7-7A1E-4AEC-BA5D-EB8A01BED943} - c:\program files\Astonsoft\DeepBurner\Uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-19 22:09
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-1350362592-3614670746-442946434-1005\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:21,5e,5f,8a,12,81,a0,c2,c2,2f,f9,d9,a9,be,9b,19,4a,aa,40,0b,9b,ce,c8,
27,b8,e9,f9,9c,49,0d,ae,b5,13,3a,f7,e9,fa,01,d8,ab,6a,5d,0d,32,1d,fc,21,10,\
"??"=hex:3c,71,d0,ac,60,dd,45,5e,54,21,59,c6,74,fa,62,2e
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"C040211900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(1052)
c:\windows\system32\Ati2evxx.dll
c:\program files\Intel\Wireless\Bin\LgNotify.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Dell\NicConfigSvc\NicConfigSvc.exe
c:\program files\Intel\Wireless\Bin\OProtSvc.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Intel\Wireless\Bin\ZCfgSvc.exe
c:\windows\system32\ati2evxx.exe
c:\windows\ehome\mcrdsvc.exe
c:\progra~1\Intel\Wireless\Bin\1XConfig.exe
c:\windows\system32\dllhost.exe
c:\combofix\CF27427.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Apoint\ApntEx.exe
.
**************************************************************************
.
Heure de fin: 2009-10-19 22:14 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-10-19 20:14
Avant-CF: 6,649,540,608 octets libres
Après-CF: 6,635,999,232 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
- - End Of File - - 7266A19AB9346977C6EFDF491685D0F1