Partiels obligent, je pouvais vous répondre mais je viens d'appliquer les différentes méthodes et poste les rapports ( celui de combo fix et hijack)
ComboFix 10-05-29.03 - moib 30/05/2010 1:18.1.2 - x86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.2030.1455 [GMT 2:00]
Lancé depuis: c:\documents and settings\moib\Bureau\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\moib\Application Data\avdrn.dat
c:\documents and settings\moib\Application Data\inst.exe
c:\documents and settings\moib\Local Settings\Application Data\paair.dat
c:\documents and settings\moib\Local Settings\Application Data\paair_nav.dat
c:\documents and settings\moib\Local Settings\Application Data\paair_navps.dat
c:\documents and settings\moib\RavMonLog
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013
c:\windows\system32\driVERs\flqzzkgc.sys
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\lowsec\user.ds.lll
c:\windows\system32\muzapp.exe
c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
c:\windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SSHNAS
-------\Service_SSHNAS
-------\Legacy_flqzzkgc
-------\Service_flqzzkgc
((((((((((((((((((((((((((((( Fichiers créés du 2010-04-28 au 2010-05-29 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier créé dans ce laps de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-05-29 23:25 . 2009-10-29 14:32 -------- d-----w- c:\documents and settings\moib\Application Data\uTorrent
2010-05-29 23:24 . 2009-12-18 14:14 256 ----a-w- c:\windows\system32\pool.bin
2010-05-29 23:21 . 2009-03-19 22:48 -------- d-----w- c:\program files\uTorrent
2010-05-23 23:06 . 2008-07-28 14:20 -------- d-----w- c:\program files\Symantec
2010-05-23 23:06 . 2008-07-28 14:19 -------- d-----w- c:\program files\Fichiers communs\Symantec Shared
2010-05-23 23:06 . 2008-07-28 14:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2010-04-28 20:15 . 2004-11-19 09:44 81790 ----a-w- c:\windows\system32\perfc00C.dat
2010-04-28 20:15 . 2004-11-19 09:44 504042 ----a-w- c:\windows\system32\perfh00C.dat
2010-04-20 19:51 . 2008-06-20 17:23 -------- d-----w- c:\program files\ThinkVantage Fingerprint Software
2010-04-20 19:50 . 2008-09-28 19:09 -------- d-----w- c:\program files\Java Web Start
2010-04-20 19:50 . 2008-08-05 09:44 -------- d-----w- c:\program files\NetWaiting
2010-04-20 19:48 . 2010-04-04 22:58 -------- d-----w- c:\program files\iMesh Applications
2010-04-11 20:08 . 2008-06-20 16:48 161256 ----a-w- c:\windows\system32\nvModes.dat
2010-04-08 22:13 . 2010-04-03 11:55 -------- d-----w- c:\documents and settings\moib\Application Data\DataCast
2010-04-07 21:59 . 2009-12-18 14:10 69632 ----a-r- c:\documents and settings\moib\Application Data\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut600_C6ABA3677F944B9FBB00F060701B0B5A.exe
2010-04-07 21:59 . 2009-12-18 14:10 69632 ----a-r- c:\documents and settings\moib\Application Data\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut60_C6ABA3677F944B9FBB00F060701B0B5A.exe
2010-04-07 21:59 . 2009-12-18 14:10 69632 ----a-r- c:\documents and settings\moib\Application Data\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut6_C6ABA3677F944B9FBB00F060701B0B5A.exe
2010-04-07 21:59 . 2009-12-18 14:10 69632 ----a-r- c:\documents and settings\moib\Application Data\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut5_C6ABA3677F944B9FBB00F060701B0B5A.exe
2010-04-07 21:59 . 2009-12-18 14:10 49152 ----a-r- c:\documents and settings\moib\Application Data\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\RedirectorEXE2_770DFD1204C24F4DA163D64FACCB5CBD.exe
2010-04-07 21:59 . 2009-12-18 14:10 69632 ----a-r- c:\documents and settings\moib\Application Data\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut4_C6ABA3677F944B9FBB00F060701B0B5A.exe
2010-04-07 21:59 . 2009-12-18 14:10 69632 ----a-r- c:\documents and settings\moib\Application Data\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut3_C6ABA3677F944B9FBB00F060701B0B5A.exe
2010-04-07 21:59 . 2009-12-18 14:10 69632 ----a-r- c:\documents and settings\moib\Application Data\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\NewShortcut12_C6ABA3677F944B9FBB00F060701B0B5A.exe
2010-04-07 21:59 . 2009-12-18 14:10 69632 ----a-r- c:\documents and settings\moib\Application Data\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\DesktopMgr.exe
2010-04-07 21:59 . 2009-12-18 14:10 49152 ----a-r- c:\documents and settings\moib\Application Data\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\RedirectorEXE1_770DFD1204C24F4DA163D64FACCB5CBD.exe
2010-04-07 21:59 . 2009-12-18 14:10 49152 ----a-r- c:\documents and settings\moib\Application Data\Microsoft\Installer\{205A5182-EFC8-4C25-B61D-C164F8FF4048}\RedirectorEXE_770DFD1204C24F4DA163D64FACCB5CBD.exe
2010-04-03 23:09 . 2010-04-03 23:09 -------- d-----w- c:\documents and settings\moib\Application Data\FreeAudioPack
2010-04-03 16:02 . 2010-04-03 16:02 -------- d-----w- c:\program files\MyFree Codec
2010-04-03 11:55 . 2010-04-03 11:55 -------- d-----w- c:\program files\MarkAny
2010-04-03 11:54 . 2008-06-20 16:58 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-04-03 11:53 . 2010-04-03 11:53 -------- d-----w- c:\program files\Samsung
2010-04-03 11:52 . 2008-09-28 19:25 348160 ----a-w- c:\windows\system32\msvcr71.dll
2010-04-01 00:53 . 2010-04-01 00:53 8 ----a-w- c:\documents and settings\moib\Application Data\jasltw.dat
2010-03-31 19:52 . 2009-02-26 14:07 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-08-19 08:42 . 2009-08-19 08:42 336 ----a-w- c:\program files\setup.ini
2008-10-20 20:48 . 2008-10-20 20:48 614400 ----a-w- c:\program files\Firefox_3.0.1.exe
2008-08-07 14:54 . 2008-08-07 14:18 59392 ----a-w- c:\program files\windows installer 3.1 EULA.doc
2008-07-25 23:43 . 2008-07-25 23:43 56 --sh--r- c:\windows\system32\55BCC84F9A.sys
2008-07-25 23:43 . 2008-07-25 23:43 1682 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-05-06 39408]
"uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2009-10-29 289072]
"ISUSPM"="c:\program files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" [2008-10-24 206112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-03-21 13524992]
"nwiz"="nwiz.exe" [2008-03-21 1630208]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-03-21 86016]
"PSQLLauncher"="c:\program files\ThinkVantage Fingerprint Software\launcher.exe" [2007-08-16 48904]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2008-04-24 1036288]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-27 149280]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"BlackBerryAutoUpdate"="c:\program files\Fichiers communs\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2010-03-10 648536]
"RoxWatchTray"="c:\program files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2009-07-08 236016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-10 417792]
"iTunesHelper"="D:\iTunesHelper.exe" [2009-07-13 292128]
"TrayServer"="d:\program files\MAGIX\Video_deluxe_16_Version_a_telecharger\TrayServer.exe" [2008-09-01 90112]
"SMSTray"="c:\program files\Samsung\EmoDio\SMSTray.exe" [2009-03-21 484888]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-11-19 15360]
c:\documents and settings\moib\Menu D'marrer\Programmes\D'marrage\
Desktop Manager.lnk - c:\program files\Research In Motion\BlackBerry\DesktopMgr.exe [2010-3-10 1819992]
c:\documents and settings\All Users\Menu D'marrer\Programmes\D'marrage\
BTTray.lnk - c:\program files\ThinkPad\Bluetooth Software\BTTray.exe [2007-2-27 561213]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-8-5 50688]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2007-08-16 22:54 89600 ----a-w- c:\windows\system32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"d:\\Programs\\RM.exe"=
"d:\\Programs\\umi.exe"=
"d:\\Programs\\VideoSpin.exe"=
"d:\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6134:TCP"= 6134:TCP:tiuajaz
"13747:TCP"= 13747:TCP:NortonAV
"17485:TCP"= 17485:TCP:NortonAV
"17557:TCP"= 17557:TCP:NortonAV
"13344:TCP"= 13344:TCP:NortonAV
"13134:TCP"= 13134:TCP:NortonAV
"14464:TCP"= 14464:TCP:NortonAV
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [09/11/2009 02:35 108289]
R2 smihlp;SMI Helper Driver (smihlp);c:\program files\Fichiers communs\ThinkVantage Fingerprint Software\Drivers\smihlp.sys [17/08/2007 00:46 10896]
S?2 doqnp;Microsoft Security;c:\windows\system32\svchost.exe -k netsvcs [19/11/2004 11:45 14336]
S?2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [31/01/2010 00:18 135664]
S0 pmdwducz;pmdwducz; [x]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
doqnp
.
Contenu du dossier 'Tâches planifiées'
2010-03-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2010-05-29 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 22:17]
2010-05-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-30 22:17]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://search.imesh.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = <local>;*.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
FF - ProfilePath - c:\documents and settings\moib\Application Data\Mozilla\Firefox\Profiles\izui7uov.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.girondins.com/
FF - prefs.js: keyword.URL - hxxp://search.imesh.com/web?src=ffb&q=
FF - prefs.js: network.proxy.type - 4
FF - plugin: c:\documents and settings\moib\Application Data\Mozilla\plugins\np-mswmp.dll
FF - plugin: c:\program files\Fichiers communs\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPDFXCviewNPPlugin.dll
FF - plugin: c:\program files\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll
FF - plugin: d:\mozilla plugins\npitunes.dll
---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-wsctf.exe - wsctf.exe
HKCU-Run-paair - c:\documents and settings\moib\local settings\application data\paair.exe
ActiveSetup-{28ABC5C0-4FCB-11CF-AAX5-81CX1C635612} - c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\win32.exe
AddRemove-paair - c:\documents and settings\moib\local settings\application data\paair.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-05-30 01:26
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\doqnp]
"ServiceDll"="c:\windows\system32\eqyjoskm.dll"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(1264)
c:\windows\system32\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\program files\ThinkVantage Fingerprint Software\infra.dll
c:\program files\ThinkVantage Fingerprint Software\homepass.dll
c:\program files\ThinkVantage Fingerprint Software\bio.dll
c:\program files\ThinkVantage Fingerprint Software\ps2css.dll
c:\program files\ThinkVantage Fingerprint Software\remote.dll
c:\program files\ThinkVantage Fingerprint Software\pscssint.dll
c:\program files\ThinkVantage Fingerprint Software\crypto.dll
- - - - - - - > 'lsass.exe'(1320)
c:\windows\system32\psqlpwd.dll
c:\program files\ThinkVantage Fingerprint Software\homefus2.dll
c:\program files\ThinkVantage Fingerprint Software\infra.dll
- - - - - - - > 'explorer.exe'(412)
c:\windows\system32\nview.dll
c:\windows\system32\NVWRSFR.DLL
c:\windows\system32\btmmhook.dll
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\nvwddi.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\ibmpmsvc.exe
c:\program files\ThinkPad\Bluetooth Software\bin\btwdins.exe
c:\program files\Intel\WiFi\bin\S24EvMon.exe
c:\windows\system32\acs.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\program files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\system32\rundll32.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Fichiers communs\Intel\WirelessCommon\RegSrvc.exe
c:\program files\Fichiers communs\Research In Motion\RIMDeviceManager\RIMDeviceManager.exe
c:\program files\Fichiers communs\Research In Motion\USB Drivers\BbDevMgr.exe
c:\windows\system32\imapi.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
.
**************************************************************************
.
Heure de fin: 2010-05-30 01:27:30 - La machine a redémarré
ComboFix-quarantined-files.txt 2010-05-29 23:27
Avant-CF: 1 008 058 368 octets libres
Après-CF: 1 119 236 096 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /fastdetect /NoExecute=OptIn
- - End Of File - - FB135B7CE6C7D0C14F21499698BEBC6A