Mille Merci pour tout ce travail!
voila les deux rapports:
1/ OTM:
All processes killed
========== FILES ==========
File move failed. G:\ZOUK 09.exe scheduled to be moved on reboot.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrateur
->Temp folder emptied: 3004716 bytes
->Temporary Internet Files folder emptied: 7495815 bytes
->FireFox cache emptied: 49454345 bytes
->Google Chrome cache emptied: 15316361 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Invité
->Temp folder emptied: 989148 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 402 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2119154 bytes
%systemroot%\System32 .tmp files removed: 3072 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 131072 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 75,00 mb
OTM by OldTimer - Version 3.1.5.0 log created on 01152010_161912
Files moved on Reboot...
File move failed. G:\ZOUK 09.exe scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
C:\WINDOWS\temp\Perflib_Perfdata_530.dat moved successfully.
Registry entries deleted on Reboot...
2/Combofix:
ComboFix 10-01-14.06 - Administrateur 15/01/2010 17:49:36.1.1 - x86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.503.293 [GMT 1:00]
Lancé depuis: c:\documents and settings\Administrateur\Bureau\ComboFix.exe
AV: avast! antivirus 4.8.1296 [VPS 100115-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\38416A
c:\windows\system32\38416A\41a664.txt
c:\windows\system32\38416A\742679.txt
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-12-15 au 2010-01-15 ))))))))))))))))))))))))))))))))))))
.
2010-01-15 15:19 . 2010-01-15 15:19 -------- d-----w- C:\_OTM
2010-01-14 14:40 . 2010-01-14 14:40 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Malwarebytes
2010-01-14 14:40 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-14 14:40 . 2010-01-14 14:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-01-14 14:40 . 2010-01-14 14:40 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-01-14 14:40 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-13 20:32 . 2010-01-13 20:32 -------- d-----w- c:\program files\CCleaner
2010-01-11 20:14 . 2010-01-15 11:00 -------- d-----w- C:\UsbFix
2010-01-11 15:54 . 2010-01-11 16:08 -------- d-----w- c:\program files\ZHPDiag
2010-01-07 16:15 . 2010-01-07 16:15 -------- d-sh--w- c:\documents and settings\Administrateur\IECompatCache
2010-01-07 16:11 . 2010-01-07 16:11 -------- d-sh--w- c:\documents and settings\Administrateur\PrivacIE
2010-01-07 16:10 . 2010-01-07 16:10 -------- d-sh--w- c:\documents and settings\Administrateur\IETldCache
2010-01-07 16:01 . 2009-01-07 17:21 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2010-01-07 16:00 . 2010-01-07 16:02 -------- dc-h--w- c:\windows\ie8
2010-01-07 16:00 . 2010-01-07 16:01 -------- d-----w- c:\windows\system32\fr-FR
2010-01-07 14:34 . 2010-01-07 14:37 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Notepad++
2010-01-07 14:34 . 2010-01-07 14:34 -------- d-----w- c:\program files\Notepad++
2010-01-07 13:50 . 2010-01-07 13:50 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\PCHealth
2010-01-07 13:33 . 2001-08-28 12:00 1677824 -c--a-w- c:\windows\system32\dllcache\chsbrkr.dll
2010-01-07 13:33 . 2001-08-28 12:00 1677824 ----a-w- c:\windows\system32\chsbrkr.dll
2010-01-07 13:33 . 2001-08-28 12:00 838144 -c--a-w- c:\windows\system32\dllcache\chtbrkr.dll
2010-01-07 13:33 . 2001-08-28 12:00 838144 ----a-w- c:\windows\system32\chtbrkr.dll
2010-01-07 13:33 . 2001-08-28 12:00 70656 -c--a-w- c:\windows\system32\dllcache\korwbrkr.dll
2010-01-07 13:33 . 2001-08-28 12:00 70656 ----a-w- c:\windows\system32\korwbrkr.dll
2010-01-07 13:33 . 2001-08-28 12:00 98304 -c--a-w- c:\windows\system32\dllcache\msir3jp.dll
2010-01-07 13:33 . 2001-08-28 12:00 98304 ----a-w- c:\windows\system32\msir3jp.dll
2010-01-07 13:33 . 2001-08-28 12:00 19456 -c--a-w- c:\windows\system32\dllcache\agt0404.dll
2010-01-07 13:31 . 2001-08-28 12:00 57398 -c--a-w- c:\windows\system32\dllcache\imjpdadm.exe
2010-01-06 20:41 . 2008-11-26 17:16 50864 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-01-06 20:41 . 2008-11-26 17:16 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-01-06 20:41 . 2008-11-26 17:15 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-01-06 20:41 . 2008-11-26 17:15 97480 ----a-w- c:\windows\system32\AvastSS.scr
2010-01-06 20:41 . 2008-11-26 17:18 93296 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-01-06 20:41 . 2008-11-26 17:18 94032 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-01-06 20:41 . 2008-11-26 17:17 111184 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-01-06 20:41 . 2008-11-26 17:17 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-01-06 20:40 . 2008-11-26 17:21 1236208 ----a-w- c:\windows\system32\aswBoot.exe
2010-01-06 20:40 . 2003-03-18 20:20 1060864 ----a-w- c:\windows\system32\MFC71.dll
2010-01-06 20:40 . 2010-01-06 20:40 -------- d-----w- c:\program files\Alwil Software
2010-01-04 21:10 . 2010-01-14 14:48 -------- d--h--w- c:\windows\system32\CBCCFC
2010-01-04 21:10 . 2010-01-07 09:35 -------- d--h--w- c:\windows\system32\8F36D6
2010-01-04 21:10 . 2010-01-05 15:39 -------- d--h--w- c:\windows\system32\8A6D2B
2010-01-04 20:40 . 2001-08-23 16:47 8704 -c--a-w- c:\windows\system32\dllcache\kbdjpn.dll
2010-01-04 20:40 . 2001-08-23 16:47 8704 ----a-w- c:\windows\system32\kbdjpn.dll
2010-01-04 20:40 . 2001-08-23 16:47 8192 -c--a-w- c:\windows\system32\dllcache\kbdkor.dll
2010-01-04 20:40 . 2001-08-23 16:47 8192 ----a-w- c:\windows\system32\kbdkor.dll
2010-01-04 20:40 . 2001-08-17 21:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd106.dll
2010-01-04 20:40 . 2001-08-17 21:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd101c.dll
2010-01-04 20:40 . 2001-08-17 21:55 6144 -c--a-w- c:\windows\system32\dllcache\kbd101b.dll
2010-01-04 20:40 . 2001-08-17 21:55 6144 ----a-w- c:\windows\system32\kbd106.dll
2010-01-04 20:40 . 2001-08-17 21:55 6144 ----a-w- c:\windows\system32\kbd101c.dll
2010-01-04 20:40 . 2001-08-17 21:55 6144 ----a-w- c:\windows\system32\kbd101b.dll
2010-01-04 20:40 . 2001-08-17 21:55 5632 -c--a-w- c:\windows\system32\dllcache\kbd103.dll
2010-01-04 20:40 . 2001-08-17 21:55 5632 ----a-w- c:\windows\system32\kbd103.dll
2010-01-04 14:00 . 2008-01-14 16:50 88960 ----a-w- c:\windows\system32\drivers\hmemdm.sys
2010-01-04 14:00 . 2010-01-04 14:00 -------- d-----w- c:\program files\Huawei technologies
2010-01-03 17:26 . 2010-01-03 17:26 -------- d-----w- c:\program files\AMT
2010-01-03 17:22 . 2010-01-03 17:22 -------- d-----w- c:\program files\Fichiers communs\xing shared
2010-01-03 17:22 . 2010-01-03 17:22 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-01-03 17:22 . 2010-01-03 17:22 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-01-03 17:22 . 2010-01-03 17:22 -------- d-----w- c:\program files\Real
2010-01-03 17:22 . 2010-01-03 17:22 -------- d-----w- c:\program files\Fichiers communs\Real
2010-01-02 14:59 . 2010-01-02 15:03 -------- d-----w- c:\program files\Dactylo
2010-01-01 14:59 . 2010-01-09 21:14 -------- d-----w- c:\documents and settings\Invité
2010-01-01 08:04 . 2010-01-01 08:04 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2010-01-01 08:02 . 2010-01-01 08:02 -------- d-----w- c:\documents and settings\Default User\Local Settings\Application Data\Adobe
2010-01-01 08:01 . 2010-01-01 08:01 -------- d-----w- c:\program files\Fichiers communs\Adobe
2010-01-01 07:49 . 2010-01-01 07:49 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee Security Scan
2010-01-01 07:49 . 2010-01-11 08:18 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\Adobe
2010-01-01 07:33 . 2010-01-01 07:33 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
2009-12-31 23:28 . 2010-01-01 07:50 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\Dictionnaire Freelang
2009-12-31 23:14 . 2009-12-31 23:14 0 ----a-w- c:\windows\nsreg.dat
2009-12-31 23:14 . 2009-12-31 23:14 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\Mozilla
2009-12-31 23:11 . 2010-01-15 01:06 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\Temp
2009-12-31 23:11 . 2009-12-31 23:11 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-12-31 23:11 . 2010-01-01 07:46 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\Google
2009-12-31 23:11 . 2009-12-31 23:43 -------- d-----w- c:\program files\Google
2009-12-31 19:48 . 2010-01-14 13:55 -------- d-----w- c:\documents and settings\Administrateur\Application Data\dvdcss
2009-12-31 19:46 . 2007-08-24 18:45 101120 ----a-r- c:\windows\system32\drivers\ewusbmdm.sys
2009-12-31 19:46 . 2007-08-24 18:45 24448 ----a-r- c:\windows\system32\drivers\ewdcsc.sys
2009-12-31 19:37 . 2004-08-03 22:08 31616 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2009-12-31 19:37 . 2004-08-03 22:08 31616 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2009-12-31 19:36 . 2009-12-31 19:46 -------- d-----w- c:\program files\Mobile Partner
2009-12-31 19:03 . 2009-12-31 19:03 68464 ----a-w- c:\documents and settings\Administrateur\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-31 16:34 . 2004-08-03 22:01 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2009-12-31 16:34 . 2004-08-03 22:01 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2009-12-24 17:10 . 2010-01-15 11:46 -------- d-----w- c:\documents and settings\Administrateur\Application Data\vlc
2009-12-24 17:10 . 2009-12-24 17:10 -------- d-----w- c:\program files\VideoLAN
2009-12-24 17:08 . 2002-11-22 14:56 118784 ----a-w- c:\windows\ShowBmp.exe
2009-12-24 17:08 . 2002-10-01 13:43 119798 ----a-w- c:\windows\system32\drivers\spca561.sys
2009-12-24 17:08 . 2002-08-13 17:01 53248 ----a-w- c:\windows\ap561.exe
2009-12-24 17:08 . 2009-12-24 17:08 -------- d-----w- c:\windows\Setup2K
2009-12-24 17:03 . 2001-11-05 08:23 299923 ----a-w- c:\windows\system32\drivers\sonyhcs.sys
2009-12-24 17:03 . 2001-07-03 19:39 3654 ----a-w- c:\windows\system32\drivers\Sonyhcp.dll
2009-12-24 17:03 . 2009-12-24 17:08 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-12-24 17:03 . 2009-12-24 17:03 -------- d-----w- C:\Drivers
2009-12-24 17:03 . 2002-10-15 21:41 102220 ----a-w- c:\windows\system32\drivers\sonypvs1.sys
2009-12-24 17:03 . 2001-11-05 08:23 38739 ----a-w- c:\windows\system32\drivers\sonyhcc.sys
2009-12-24 17:03 . 2001-11-05 08:23 6097 ----a-w- c:\windows\system32\drivers\sonyhcb.sys
2009-12-24 17:03 . 2001-07-03 19:33 53248 ----a-w- c:\windows\system32\SONYHCY.DLL
2009-12-24 17:03 . 2009-12-24 17:03 -------- d-----w- c:\program files\Fichiers communs\InstallShield
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-01-07 13:48 . 2009-12-24 11:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-01-06 21:40 . 2003-11-30 10:18 72968 ----a-w- c:\windows\system32\perfc00C.dat
2010-01-06 21:40 . 2003-11-30 10:18 464452 ----a-w- c:\windows\system32\perfh00C.dat
2010-01-01 21:57 . 2009-12-24 10:48 86331 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2009-12-24 11:09 . 2009-12-24 11:09 -------- d-----w- c:\program files\Microsoft Works
2009-12-24 11:09 . 2009-12-24 11:09 -------- d-----w- c:\program files\MSBuild
2009-12-24 10:49 . 2009-12-24 10:49 -------- d-----w- c:\program files\microsoft frontpage
2009-12-24 10:47 . 2009-12-24 10:47 -------- d-----w- c:\program files\Services en ligne
2009-12-24 10:45 . 2009-12-24 10:45 21892 ----a-w- c:\windows\system32\emptyregdb.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1667584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-04-01 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-04-01 126976]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2010-01-03 198160]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-03 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-03 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-03 455168]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HonorAutoRunSetting"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"HonorAutoRunSetting"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [06/01/2010 21:41 111184]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [06/01/2010 21:41 20560]
R3 MobileAdapter;Huawei Mobile Adapter USB Modem and USB Serial;c:\windows\system32\drivers\hmemdm.sys [04/01/2010 15:00 88960]
S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [01/01/2010 00:11 135664]
.
Contenu du dossier 'Tâches planifiées'
2010-01-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-31 23:11]
2010-01-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-31 23:11]
2010-01-15 c:\windows\Tasks\User_Feed_Synchronization-{3780E5E8-9F33-4393-A424-178C60858DFC}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
.
.
------- Examen supplémentaire -------
.
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\cawroqgy.default\
FF - component: c:\program files\Real\RealPlayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-tppoll - c:\program files\Topro\tppoll.exe
HKLM-Run-24CF32 - c:\windows\system32\CBCCFC\24CF32.EXE
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-01-15 17:52
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-796845957-1220945662-725345543-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a0,73,9d,cd,f9,e9,16,4f,9b,f7,a4,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,a0,73,9d,cd,f9,e9,16,4f,9b,f7,a4,\
.
Heure de fin: 2010-01-15 17:54:23
ComboFix-quarantined-files.txt 2010-01-15 16:54
Avant-CF: 33 916 227 584 octets libres
Après-CF: 33 886 015 488 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
- - End Of File - - 6FF6BEF0EB7EC30404AC2BF4D981E87B