Ok, voilà c'est fait, il m'a supprimé un certain nombres de fichiers et avast s'est enfin lancé au démarrage:
ComboFix 10-01-04.01 - El picador 06/01/2010 13:11:27.1.1 - x86
Microsoft Windows XP Professionnel 5.1.2600.0.1252.33.1036.18.511.289 [GMT 1:00]
Lancé depuis: c:\documents and settings\El picador\Bureau\PICA.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\El picador\Application Data\inst.exe
C:\LOG.TXT
C:\Thumbs.db
c:\windows\Downloaded Program Files\RdxIE.dll
c:\windows\patch.exe
c:\windows\system32\drivers\H8SRTuypbxrqmny.sys
c:\windows\system32\drivers\kungsfvsoyqbfd.sys
c:\windows\system32\drivers\SKYNETextpdmlf.sys
c:\windows\system32\dumphive.exe
c:\windows\system32\H8SRTbctoswvihw.dat
c:\windows\system32\H8SRTbrerfvpefw.dll
c:\windows\system32\H8SRTielewqoerm.dll
c:\windows\system32\H8SRTnxnmfdjivc.dll
c:\windows\system32\kungsfablwhwax.dat
c:\windows\system32\kungsfbkieewbl.dll
c:\windows\system32\kungsfdcpiesru.dat
c:\windows\system32\kungsftklplmyr.dll
c:\windows\system32\musln.dll
c:\windows\System32\ntSVc.ocx
c:\windows\system32\Process.exe
c:\windows\system32\rnaph.dll
c:\windows\system32\SrchSTS.exe
c:\windows\system32\srcr.dat
c:\windows\system32\tmp.reg
c:\windows\system32\tzhqs.dat
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_H8SRTd.sys
-------\Legacy_H8SRTd.sys
-------\Service_kungsfwkeqalqe
-------\Legacy_kungsfwkeqalqe
-------\Service_SKYNETpqjxvkse
-------\Legacy_SKYNETpqjxvkse
-------\Legacy_SYSLOAD
-------\Service_Sysload
((((((((((((((((((((((((((((( Fichiers créés du 2009-12-06 au 2010-01-06 ))))))))))))))))))))))))))))))))))))
.
2010-01-06 11:10 . 2010-01-06 11:15 -------- d-----w- c:\program files\trend micro
2010-01-06 11:10 . 2010-01-06 11:11 -------- d-----w- C:\rsit
2010-01-06 09:52 . 2009-03-30 09:32 96104 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-01-06 09:52 . 2009-02-13 11:28 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-01-06 09:52 . 2009-02-13 11:17 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-01-06 09:52 . 2010-01-06 09:52 -------- d-----w- c:\program files\Avira
2010-01-06 09:52 . 2010-01-06 09:52 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2010-01-06 09:15 . 2010-01-06 09:15 -------- d-----w- c:\documents and settings\El picador\Application Data\Uniblue
2010-01-03 17:25 . 2009-04-06 10:37 704384 ----a-w- c:\windows\system32\drivers\SandBox.sys
2010-01-03 17:25 . 2009-02-10 15:15 257432 ----a-w- c:\windows\system32\drivers\afwcore.sys
2010-01-03 17:23 . 2009-02-18 16:30 31128 ----a-w- c:\windows\system32\drivers\afw.sys
2010-01-03 17:23 . 2010-01-03 17:23 -------- d-----w- c:\program files\Agnitum
2010-01-03 17:22 . 2010-01-03 17:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Agnitum
2010-01-03 17:06 . 2010-01-03 17:06 -------- d-----w- c:\documents and settings\El picador\Application Data\AVG8
2009-12-23 12:51 . 2009-11-24 23:49 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-12-23 12:51 . 2009-11-24 23:48 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-12-23 12:51 . 2009-11-24 23:47 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-12-23 12:51 . 2009-11-24 23:51 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-12-23 12:51 . 2009-11-24 23:50 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-12-23 12:51 . 2009-11-24 23:50 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-12-23 12:51 . 2009-11-24 23:47 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-12-23 12:51 . 2009-11-24 23:54 1280480 ----a-w- c:\windows\system32\aswBoot.exe
2009-12-23 11:57 . 2009-12-23 11:57 -------- d-----w- c:\program files\Sunbelt Software
2009-12-23 01:35 . 2010-01-06 09:10 880 ----a-w- c:\windows\system32\krl32mainweq.dll
2009-12-13 17:47 . 2009-12-13 17:47 -------- d-----w- c:\program files\VID_0E8F&PID_3013
2009-12-13 16:04 . 2009-12-13 16:04 -------- d-----w- c:\program files\KONAMI
2009-12-12 18:48 . 2009-12-12 18:48 -------- d-----w- c:\temp\FrankProtocol
2009-12-12 18:48 . 2009-12-12 18:48 -------- d-----w- c:\temp\FrankPacManager
2009-12-12 18:48 . 2009-12-12 18:48 -------- d-----w- c:\temp\FrankMedium
2009-12-12 18:48 . 2009-12-12 18:48 -------- d-----w- c:\temp\FrankHandler
2009-12-12 18:48 . 2009-12-12 18:48 -------- d-----w- c:\temp\FrankFormat
2009-12-12 18:48 . 2009-12-12 18:48 -------- d-----w- c:\temp\FrankDevice
2009-12-12 18:48 . 2009-12-12 18:48 -------- d-----w- c:\temp\FrankContents
2009-12-12 18:48 . 2009-12-12 18:48 -------- d-----w- c:\temp\Frank
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-06 12:26 . 2001-09-28 12:00 445016 ----a-w- c:\windows\system32\perfh00C.dat
2010-01-06 12:26 . 2001-09-28 12:00 63614 ----a-w- c:\windows\system32\perfc00C.dat
2010-01-06 11:37 . 2006-10-05 16:59 -------- d-----w- c:\program files\Mozilla Thunderbird
2010-01-06 09:45 . 2004-02-11 14:38 -------- d-----w- c:\program files\Fichiers communs\Symantec Shared
2010-01-06 09:45 . 2004-02-11 14:38 -------- d-----w- c:\program files\Symantec
2010-01-06 09:43 . 2004-10-17 18:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2010-01-06 09:28 . 2007-05-20 13:30 -------- d-----w- c:\program files\CCleaner
2010-01-05 18:05 . 2007-12-06 20:57 -------- d-----w- c:\documents and settings\El picador\Application Data\uTorrent
2009-12-22 18:33 . 2008-09-20 23:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Soulseek
2009-12-20 13:09 . 2006-03-17 07:43 -------- d-----w- c:\program files\laMule
2009-12-13 17:47 . 2004-01-08 07:18 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-12 17:16 . 2007-10-04 19:45 -------- d-----w- c:\documents and settings\El picador\Application Data\OpenOffice.org2
2009-11-30 13:37 . 2007-09-05 20:22 -------- d-----w- c:\documents and settings\El picador\Application Data\Audacity
2008-04-15 22:20 . 2008-04-15 17:17 81920 --sha-w- c:\program files\Thumbs.db
2006-02-23 11:39 . 2005-10-21 17:18 278528 ----a-w- c:\program files\Fichiers communs\FDEUnInstaller.exe
.
------- Sigcheck -------
[-] 2004-08-19 . 8558905BA81F6EFAAF9667139BB117DD . 13824 . . [5.1.2600.2180] . . c:\windows\SoftwareDistribution\Download\dfd63227c75f2f41fff1e2c80885381e\wscntfy.exe
[-] 2004-08-19 . 912591E2055E26566D1CB54092A7E8B0 . 129536 . . [5.1.2600.2180] . . c:\windows\SoftwareDistribution\Download\dfd63227c75f2f41fff1e2c80885381e\xmlprov.dll
c:\windows\System32\wscntfy.exe ... manque !!
c:\windows\System32\xmlprov.dll ... manque !!
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-20 148888]
"OutpostMonitor"="c:\program files\Agnitum\Outpost Firewall\op_mon.exe" [2009-04-28 2374464]
"OutpostFeedBack"="c:\program files\Agnitum\Outpost Firewall\feedback.exe" [2009-04-28 428032]
"nwiz"="nwiz.exe" [2003-10-06 741376]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-10-06 5058560]
"EM_EXEC"="c:\progra~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE" [2002-05-24 28672]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"ASUS Probe"="c:\program files\ASUS\Probe\AsusProb.exe" [2002-12-06 617984]
"AdaptecDirectCD"="c:\program files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-12-17 684032]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2001-09-28 13312]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
backup=c:\windows\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Pinnacle Scheduler.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Pinnacle Scheduler.lnk
backup=c:\windows\pss\Pinnacle Scheduler.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
???????? [?]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iexplore.exe]
2001-09-28 12:00 91136 ----a-w- c:\program files\Internet Explorer\IEXPLORE.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
2006-07-09 15:34 36864 ----a-w- c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
2003-12-16 21:37 188416 ----a-w- c:\program files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
2003-12-16 21:39 77824 ----a-w- c:\program files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2001-07-09 08:50 155648 ----a-w- c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2005-04-26 09:06 98304 ----a-w- c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
2004-08-17 15:44 10039488 ----a-w- c:\program files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SsAAD.exe]
2007-02-05 08:11 476728 ----a-w- c:\progra~1\Sony\SONICS~1\SSAAD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
2006-03-30 15:45 313472 ----a-r- c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\zBrowser Launcher]
2002-05-29 00:59 520192 ----a-w- c:\program files\Logitech\iTouch\iTouch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"AVG Anti-Spyware Guard"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
R0 avgntmgr;avgntmgr;c:\windows\system32\drivers\avgntmgr.sys [06/01/2010 10:52 22360]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [23/12/2009 13:51 114768]
R1 avgntdd;avgntdd;c:\windows\system32\drivers\avgntdd.sys [06/01/2010 10:52 45416]
R1 SandBox;SandBox;c:\windows\system32\drivers\SandBox.sys [03/01/2010 18:25 704384]
R3 afw;Agnitum firewall driver;c:\windows\system32\drivers\afw.sys [03/01/2010 18:23 31128]
R3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [03/01/2010 18:25 257432]
R3 pctvvbi;PCTVVBI;c:\windows\system32\drivers\pctvvbi.sys [08/01/2004 08:19 6400]
S2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [06/01/2010 10:52 108289]
S3 NETMDSHA;MDSHA031;c:\windows\system32\drivers\MDSHA031.sys [08/06/2005 19:27 35331]
S3 vaxscsi;vaxscsi;c:\windows\System32\Drivers\vaxscsi.sys --> c:\windows\System32\Drivers\vaxscsi.sys [?]
S4 autopro;Norton AntiVirus Auto Protection;"c:\windows\System32\navap32.exe" -service --> c:\windows\System32\navap32.exe [?]
S4 minpad;Windows Mini-Notepad;"c:\windows\System32\windows-pad.exe" -service --> c:\windows\System32\windows-pad.exe [?]
S4 Monitor service;Monitor;"c:\windows\System32\explore.exe" -service --> c:\windows\System32\explore.exe [?]
S4 NSM;Network Service Manager;"c:\windows\System32\netsvc.exe" -service --> c:\windows\System32\netsvc.exe [?]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [20/03/2006 22:27 639224]
S4 WVL;Windos Video Link;"c:\windows\System32\video_lnk32.exe" -service --> c:\windows\System32\video_lnk32.exe [?]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
mStart Page = hxxp://www.google.fr
uInternet Settings,ProxyOverride = localhost
TCP: {75E127F9-6102-4315-97B7-07B4EE6485CA} = 192.168.1.1
TCP: {E5240FB0-BC5C-4FF7-938A-E8113870BD8D} = 192.168.1.1,192.168.1.5
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\El picador\Application Data\Mozilla\Firefox\Profiles\kueb3mkv.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - plugin: c:\documents and settings\El picador\Application Data\Mozilla\Firefox\Profiles\kueb3mkv.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nppl3260.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprjplug.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprpjplug.dll
FF - plugin: c:\program files\Veetle\Player\npvlc.dll
FF - plugin: c:\program files\Veetle\plugins\npVeetle.dll
---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.homepage.dontask - true.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-TkBellExe - c:\program files\Fichiers communs\Real\Update_OB\realsched.exe
HKU-Default-Run-ALUAlert - c:\program files\Symantec\LiveUpdate\ALUNotify.exe
MSConfigStartUp-ccApp - c:\program files\Fichiers communs\Symantec Shared\ccApp.exe
MSConfigStartUp-HPDJ Taskbar Utility - c:\windows\System32\spool\drivers\w32x86\3\hpztsb05.exe
MSConfigStartUp-Malware Defense - c:\program files\Malware Defense\mdefense.exe
MSConfigStartUp-ppmate - c:\program files\PPMate\PPMate\ppmate.exe
MSConfigStartUp-richtx64 - c:\docume~1\ELPICA~1\LOCALS~1\Temp\richtx64.exe
MSConfigStartUp-SSC_UserPrompt - c:\program files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-06 13:26
Windows 5.1.2600 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(1212)
c:\windows\system32\ODBC32.dll
c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll
- - - - - - - > 'lsass.exe'(1280)
c:\windows\system32\RASAPI32.dll
c:\windows\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\comctl32.dll
c:\windows\System32\dssenh.dll
- - - - - - - > 'explorer.exe'(3400)
c:\progra~1\Logitech\MOUSEW~1\SYSTEM\LGMOUSHK.dll
c:\windows\system32\WS2_32.dll
c:\windows\system32\WS2HELP.dll
c:\windows\system32\RASAPI32.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\System32\nvsvc32.exe
c:\windows\System32\wdfmgr.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Java\jre6\bin\jucheck.exe
.
**************************************************************************
.
Heure de fin: 2010-01-06 13:35:48 - La machine a redémarré
ComboFix-quarantined-files.txt 2010-01-06 12:35
Avant-CF: 37 289 443 328 octets libres
Après-CF: 37 309 857 792 octets libres
WinXP_FR_PRO_BF.EXE
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /fastdetect
- - End Of File - - E223A10275E3102D5605167FE90D7189