Voici le scan qu'a sorti Combofix.
Par contre, je pense avoir fait des erreurs, je suis pas sûre d'avoir bien désactiver la protection en temps réél d'avast (j'ai juste arrêter la protection en cours de l'agent des fichiers, si c'est pas cela qu'il fallait faire , pourrais-tu m'expliquer la manip) et de plus, je n'ai pas désactiver CCleaner (je sais pas si c'est un antispywares). J'attend une réponse de ta part pour savoir si je dois recommencer la manip ou pas.
L'ordi a l'air d'être mieux mais c'est pas encore ca.
ComboFix 10-04-12.04 - Rosalie 13/04/2010 8:56.1.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.33.1036.18.447.181 [GMT 2:00]
Lancé depuis: c:\documents and settings\Rosalie\Bureau\Adeshi.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Un nouveau point de restauration a été créé
.
Les fichiers ci-dessous ont été désactivés pendant l'exécution:
c:\program files\Fichiers communs\Logitech\LVMVFM\LVPrcInj.dll
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\apps\skype\Phone\Skype.exe
c:\documents and settings\All Users\Application Data\fiosejgfse.dll
c:\documents and settings\All Users\Bureau\nudetube.com.lnk
c:\documents and settings\All Users\Bureau\pornotube.com.lnk
c:\documents and settings\All Users\Bureau\youporn.com.lnk
c:\documents and settings\All Users\Favoris\_favdata.dat
c:\program files\Digital Protection\digprot.exe
c:\program files\Dynamic Toolbar
c:\program files\Dynamic Toolbar\batch.bat
c:\program files\Dynamic Toolbar\Cache\go.bmp
c:\program files\Dynamic Toolbar\Cache\home.bmp
c:\program files\Dynamic Toolbar\Cache\logo_pb.bmp
c:\program files\Dynamic Toolbar\Cache\parent_off.bmp
c:\program files\Dynamic Toolbar\Cache\parent_on.bmp
c:\program files\Dynamic Toolbar\Cache\pbfrv2tb0200.cfg
c:\program files\Dynamic Toolbar\Cache\popup_off.bmp
c:\program files\Dynamic Toolbar\Cache\popup_on.bmp
c:\program files\Dynamic Toolbar\Cache\search.bmp
c:\program files\Dynamic Toolbar\Cache\services.bmp
c:\program files\Dynamic Toolbar\Cache\skin.bmp
c:\program files\Dynamic Toolbar\Cache\skin1.bmp
c:\program files\Dynamic Toolbar\Cache\skin2.bmp
c:\program files\Dynamic Toolbar\Cache\skin3.bmp
c:\program files\Dynamic Toolbar\Cache\skin4.bmp
c:\program files\Dynamic Toolbar\Cache\skin5.bmp
c:\program files\Dynamic Toolbar\Cache\store.bmp
c:\program files\Dynamic Toolbar\Cache\style.css
c:\program files\Dynamic Toolbar\Cache\support.bmp
c:\program files\Dynamic Toolbar\Cache\ticker.xml
c:\program files\Dynamic Toolbar\PBFRV2\Cache\go.bmp
c:\program files\Dynamic Toolbar\PBFRV2\Cache\home.bmp
c:\program files\Dynamic Toolbar\PBFRV2\Cache\logo_pb.bmp
c:\program files\Dynamic Toolbar\PBFRV2\Cache\parent_off.bmp
c:\program files\Dynamic Toolbar\PBFRV2\Cache\parent_on.bmp
c:\program files\Dynamic Toolbar\PBFRV2\Cache\pbfrv2tb0200.cfg
c:\program files\Dynamic Toolbar\PBFRV2\Cache\popup_off.bmp
c:\program files\Dynamic Toolbar\PBFRV2\Cache\popup_on.bmp
c:\program files\Dynamic Toolbar\PBFRV2\Cache\search.bmp
c:\program files\Dynamic Toolbar\PBFRV2\Cache\services.bmp
c:\program files\Dynamic Toolbar\PBFRV2\Cache\skin.bmp
c:\program files\Dynamic Toolbar\PBFRV2\Cache\skin1.bmp
c:\program files\Dynamic Toolbar\PBFRV2\Cache\skin2.bmp
c:\program files\Dynamic Toolbar\PBFRV2\Cache\skin3.bmp
c:\program files\Dynamic Toolbar\PBFRV2\Cache\skin4.bmp
c:\program files\Dynamic Toolbar\PBFRV2\Cache\skin5.bmp
c:\program files\Dynamic Toolbar\PBFRV2\Cache\store.bmp
c:\program files\Dynamic Toolbar\PBFRV2\Cache\style.css
c:\program files\Dynamic Toolbar\PBFRV2\Cache\support.bmp
c:\program files\Dynamic Toolbar\PBFRV2\Cache\ticker.xml
c:\program files\Dynamic Toolbar\unins000.dat
c:\program files\Dynamic Toolbar\unins000.exe
c:\program files\QuickTime\qttask .exe
c:\program files\QuickTime\qttask .exe
c:\program files\QuickTime\qttask.exe
c:\program files\SFR\Kit\WiFi\9wifi .exe
c:\program files\SFR\Kit\WiFi\9wifi .exe
c:\program files\SFR\Kit\WiFi\9wifi.exe
c:\program files\Sony Ericsson\Mobile2\Application Launcher\application launcher.exe
c:\windows\system32\ctfmon .exe
c:\windows\system32\drivers\eicon.txt
c:\windows\system32\drivers\icon .exe
c:\windows\system32\drivers\stdsb .exe
c:\windows\system32\drivers\str.sys
c:\windows\system32\Thumbs.db
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-03-13 au 2010-04-13 ))))))))))))))))))))))))))))))))))))
.
2010-04-10 13:06 . 2010-04-10 13:06 -------- d-----w- c:\documents and settings\Rosalie\Local Settings\Application Data\Threat Expert
2010-04-10 12:54 . 2010-04-10 13:17 -------- d-----w- c:\program files\ZHPDiag
2010-04-10 12:21 . 2010-04-10 13:28 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-04-09 17:22 . 2010-04-09 17:22 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2010-04-09 17:16 . 2010-04-09 17:16 -------- d-----w- c:\windows\system32\wbem\Repository
2010-03-16 20:41 . 2010-03-16 20:41 -------- d-----w- c:\program files\SFR
2010-03-16 13:32 . 2003-03-15 23:15 90112 ----a-w- c:\windows\unvise32.exe
2010-03-16 13:31 . 2010-03-16 13:32 -------- d-----w- c:\program files\ArkMicro
2010-03-16 12:35 . 2010-03-16 12:36 -------- d-----w- C:\challenge_agriculture
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-13 07:02 . 2008-12-16 16:53 -------- d-----w- c:\program files\QuickTime
2010-04-13 07:02 . 2010-04-10 18:26 -------- d-----w- c:\program files\Digital Protection
2010-04-13 06:37 . 2010-04-13 06:37 1028816 ----a-w- C:\UsbFix_Upload_Me_Ordi.zip
2010-04-12 11:27 . 2008-12-16 11:31 1 ----a-w- c:\documents and settings\Rosalie\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-04-10 18:19 . 2010-04-10 18:43 90624 ------w- c:\windows\system32\trz4.tmp
2010-04-10 17:21 . 2010-04-10 17:21 -------- d-----w- c:\program files\Trend Micro
2010-04-02 20:43 . 2009-03-21 22:16 -------- d-----w- c:\documents and settings\Rosalie\Application Data\dvdcss
2010-03-28 11:24 . 2004-08-16 15:41 84964 ----a-w- c:\windows\system32\perfc00C.dat
2010-03-28 11:24 . 2004-08-16 15:41 510980 ----a-w- c:\windows\system32\perfh00C.dat
2010-03-27 11:33 . 2009-04-05 15:56 -------- d-----w- c:\documents and settings\Rosalie\Application Data\Skype
2010-03-25 21:00 . 2009-04-05 16:10 -------- d-----w- c:\documents and settings\Rosalie\Application Data\skypePM
2010-03-09 11:24 . 2008-12-16 09:05 153184 ----a-w- c:\windows\system32\aswBoot.exe
2010-03-09 11:12 . 2008-12-16 09:06 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-03-09 11:12 . 2008-12-16 09:06 162640 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-03-09 11:09 . 2008-12-16 09:06 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-03-09 11:08 . 2008-12-16 09:06 100432 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-03-09 11:08 . 2008-12-16 09:06 94800 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-03-09 11:08 . 2008-12-16 09:06 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-03-09 11:08 . 2008-12-16 09:06 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-02-25 06:17 . 2004-08-16 15:41 916480 ----a-w- c:\windows\system32\wininet.dll
2010-02-21 11:23 . 2010-02-21 11:23 -------- d-----w- c:\documents and settings\Rosalie\Application Data\AlauxSoft
2010-02-20 11:33 . 2010-02-20 11:33 -------- d-----w- c:\program files\Microsoft
2010-02-20 11:32 . 2008-12-16 11:38 -------- d-----w- c:\program files\Windows Live
2010-02-20 11:32 . 2010-02-20 11:32 -------- d-----w- c:\program files\Windows Live SkyDrive
2010-02-19 21:26 . 2010-02-19 21:26 15256 ----a-w- c:\documents and settings\Rosalie\Application Data\Microsoft\IdentityCRL\ppcrlconfig.dll
2010-02-19 07:36 . 2008-12-16 09:05 -------- d-----w- c:\program files\Alwil Software
2010-02-19 07:29 . 2010-02-19 07:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-02-12 10:03 . 2010-02-27 09:32 293376 ------w- c:\windows\system32\browserchoice.exe
2010-02-11 18:53 . 2008-12-16 09:06 38848 ----a-w- c:\windows\system32\avastSS.scr
.
[code]<pre>
c:\program files\Adobe\Reader 9.0\Reader\reader_sl .exe
c:\program files\Digital Protection\digprot .exe
c:\program files\Java\jre1.5.0_04\bin\jusched .exe
c:\program files\Logitech\Desktop Messenger\8876480\Program\logitechdesktopmessenger .exe
c:\program files\Logitech\Video\cameraassistant .exe
c:\program files\Logitech\Video\installhelper .exe
c:\program files\QuickTime\qttask .exe
c:\program files\SFR\Kit\WiFi\9wifi .exe
c:\program files\Sony Ericsson\Mobile2\Application Launcher\application launcher .exe
c:\program files\Synaptics\SynTP\syntpenh .exe
c:\program files\Synaptics\SynTP\syntplpr .exe
c:\windows\ime\IMJP8_1\imjpmig .exe
c:\windows\system32\IME\TINTLGNT\tintsetp .exe
</pre>
/code
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Skype"="c:\apps\skype\Phone\Skype.exe" [N/A]
"Digital Protection"="c:\program files\Digital Protection\digprot.exe" [N/A]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"VTTimer"="VTTimer.exe" [2005-03-08 53248]
"VTTrayp"="VTtrayp.exe" [2005-09-14 167936]
"SoundMan"="SOUNDMAN.EXE" [2005-08-17 90112]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [N/A]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-03-09 2769336]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-05 15360]
c:\documents and settings\All Users\Menu D'marrer\Programmes\D'marrage\
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2008-12-30 450560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HonorAutoRunSetting"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"HonorAutoRunSetting"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\APPS\\Inventime\\my.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [16/12/2008 11:06 162640]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [16/12/2008 11:06 19024]
.
Contenu du dossier 'Tâches planifiées'
2010-04-13 c:\windows\Tasks\User_Feed_Synchronization-{47E35A36-E021-442C-A0CC-C8236C7903DD}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 03:31]
.
.
------- Examen supplémentaire -------
.
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
.
- - - - ORPHELINS SUPPRIMES - - - -
AddRemove-Digital Protection - c:\program files\Digital Protection\Pklkvqdii+'}'
AddRemove-Dynamic Toolbar_is1 - c:\program files\Dynamic Toolbar\unins000.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-04-13 09:12
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySqlInventime]
"ImagePath"="c:\mysql\bin\mysqld-max-nt MySqlInventime"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(5208)
c:\program files\Fichiers communs\Logitech\LVMVFM\LVPrcInj.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
c:\progra~1\FICHIE~1\AOL\ACS\AOLacsd.exe
c:\apps\Powercinema\Kernel\TV\CLCapSvc.exe
c:\program files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
c:\apps\HIDSERVICE\HIDSERVICE.exe
c:\windows\system32\slmdmsr.exe
c:\program files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
c:\windows\system32\VTTimer.exe
c:\windows\system32\VTtrayp.exe
c:\windows\SOUNDMAN.EXE
c:\apps\Powercinema\Kernel\TV\CLSched.exe
.
**************************************************************************
.
Heure de fin: 2010-04-13 09:18:02 - La machine a redémarré
ComboFix-quarantined-files.txt 2010-04-13 07:17
Avant-CF: 2 186 031 104 octets libres
Après-CF: 2 464 985 088 octets libres
- - End Of File - - DC9723F265B9C0F80BC9349291B6E6EA