voici le rapport:
ComboFix 10-09-13.04 - Max 14/09/2010 18:22:22.1.2 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1015.726 [GMT 2:00]
Lancé depuis: c:\documents and settings\Max\Bureau\ComboFix.exe
AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\brxmnsab.dll
c:\windows\system32\drivers\ivkmupgs.sys
c:\windows\system32\Drivers\ucwkck.sys
c:\windows\system32\drivers\vdfkfleo.sys
c:\windows\system32\goiupof.dll
c:\windows\system32\qanxlvb.dll
c:\windows\system32\Thumbs.db
Une copie infectée de c:\windows\system32\drivers\iaStor.sys a été trouvée et désinfectée
Copie restaurée à partir de - Kitty had a snack :p
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IVKMUPGS
-------\Legacy_SSHNAS
-------\Legacy_WFUOPOMX
-------\Service_ivkmupgs
-------\Service_wfuopomx
((((((((((((((((((((((((((((( Fichiers créés du 2010-08-14 au 2010-09-14 ))))))))))))))))))))))))))))))))))))
.
2010-09-14 11:20 . 2010-09-14 11:20 -------- d-----w- C:\TDSSKiller_Quarantine
2010-09-13 23:14 . 2010-09-13 23:14 -------- d-----w- c:\documents and settings\All Users\Application Data\LogiShrd
2010-09-13 23:12 . 2010-09-13 23:12 -------- d-----w- c:\documents and settings\Max\Local Settings\Application Data\LogiShrd
2010-09-13 23:09 . 2010-09-13 23:09 -------- d-----w- c:\documents and settings\Max\Application Data\Leadertech
2010-09-13 23:09 . 2010-09-13 23:09 53248 ----a-r- c:\documents and settings\Max\Application Data\Microsoft\Installer\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}\ARPPRODUCTICON.exe
2010-09-13 23:07 . 2010-09-14 16:32 -------- d-----w- c:\windows\system32\logishrd
2010-09-13 23:06 . 2010-09-13 23:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Logitech
2010-09-13 23:06 . 2010-09-13 23:06 -------- d-----w- c:\program files\Fichiers communs\LWS
2010-09-13 23:06 . 2010-09-13 23:06 -------- d-----w- c:\program files\Common Files
2010-09-13 23:06 . 2010-09-13 23:10 -------- d-----w- c:\program files\Logitech
2010-09-13 23:06 . 2010-09-13 23:08 -------- d-----w- c:\program files\Fichiers communs\LogiShrd
2010-09-13 23:06 . 2008-04-13 09:45 60032 -c--a-w- c:\windows\system32\dllcache\usbaudio.sys
2010-09-13 23:06 . 2008-04-13 09:45 60032 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2010-09-12 19:57 . 2010-09-12 19:57 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-09-12 19:56 . 2010-09-14 15:51 -------- d-----w- c:\documents and settings\Max\Application Data\skypePM
2010-09-12 19:55 . 2010-09-14 15:53 -------- d-----w- c:\documents and settings\Max\Application Data\Skype
2010-09-12 19:54 . 2010-09-12 19:54 -------- d-----w- c:\program files\Fichiers communs\Skype
2010-09-12 19:54 . 2010-09-12 19:55 -------- d-----r- c:\program files\Skype
2010-09-05 20:28 . 2010-09-07 14:52 165584 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-09-05 20:28 . 2010-09-07 14:47 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-09-05 20:28 . 2010-09-07 14:47 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-09-05 20:28 . 2010-09-07 14:52 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-09-05 20:28 . 2010-09-07 14:47 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-09-05 20:28 . 2010-09-07 14:47 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-09-05 20:28 . 2010-09-07 14:46 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-09-05 20:27 . 2010-09-07 15:12 38848 ----a-w- c:\windows\avastSS.scr
2010-09-05 20:27 . 2010-09-07 15:11 167592 ----a-w- c:\windows\system32\aswBoot.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-14 16:25 . 2009-05-12 21:31 85742 ----a-w- c:\windows\system32\perfc00C.dat
2010-09-14 16:25 . 2009-05-12 21:31 510860 ----a-w- c:\windows\system32\perfh00C.dat
2010-09-14 10:16 . 2009-09-29 13:11 -------- d-----w- c:\documents and settings\Max\Application Data\vlc
2010-09-14 08:57 . 2010-03-17 22:40 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-09-14 08:57 . 2010-03-17 22:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-09-13 23:15 . 2010-09-13 23:07 0 ----a-w- c:\windows\system32\drivers\logiflt.iad
2010-09-13 22:45 . 2009-05-12 21:32 327192 ----a-w- c:\windows\system32\drivers\iaStor.sys
2010-09-12 22:48 . 2010-09-12 22:48 396 ----a-w- c:\program files\.js
2010-09-12 19:54 . 2009-05-12 20:58 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2010-09-05 21:03 . 2010-04-26 16:13 -------- d-----w- c:\documents and settings\All Users\Application Data\77e025f
2010-09-05 20:27 . 2010-03-16 11:05 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-07-27 08:15 . 2010-07-27 08:15 23904 ----a-w- c:\windows\system32\drivers\lvuvcflt.sys
2010-07-27 08:14 . 2010-07-27 08:14 6842464 ----a-w- c:\windows\system32\drivers\lvuvc.sys
2010-07-27 08:14 . 2010-07-27 08:14 539232 ----a-w- c:\windows\system32\LVUI2RC.dll
2010-07-27 08:14 . 2010-07-27 08:14 543328 ----a-w- c:\windows\system32\LVUI2.dll
2010-07-27 08:12 . 2010-07-27 08:12 282336 ----a-w- c:\windows\system32\drivers\lvrs.sys
2010-07-27 08:12 . 2010-07-27 08:12 114784 ----a-w- c:\windows\system32\drivers\lvpopflt.sys
2010-07-27 08:08 . 2010-07-27 08:08 203360 ----a-w- c:\windows\system32\lvci1311021.dll
2010-07-27 08:07 . 2010-07-27 08:07 416352 ----a-w- c:\windows\system32\lvcodec2.dll
2010-07-27 08:03 . 2010-07-27 08:03 10829656 ----a-w- c:\windows\system32\LogiDPP.dll
2010-07-27 08:03 . 2010-07-27 08:03 102744 ----a-w- c:\windows\system32\LogiDPPApp.exe
2010-07-27 08:03 . 2010-07-27 08:03 290648 ----a-w- c:\windows\system32\DevManagerCore.dll
2010-07-27 07:56 . 2010-07-27 07:56 266828 ----a-w- c:\windows\system32\drivers\LVAFT.cfg
2010-07-27 07:55 . 2010-07-27 07:55 37518 ----a-w- c:\windows\system32\Repository.reg
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Eee Docking"="c:\program files\ASUS\Eee Docking\Eee Docking.exe" [2009-05-08 395776]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-09-02 13351304]
"Logitech Vid"="c:\program files\Logitech\Vid\Vid.exe" [2010-05-11 6061400]
"Logitech Vid HD"="c:\program files\Logitech\Vid\vid.exe" [2010-05-11 6061400]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2009-04-16 630784]
"AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2009-03-13 98304]
"AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2009-04-16 118784]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-06 1434920]
"SynAsusAcpi"="c:\program files\Synaptics\SynTP\SynAsusAcpi.exe" [2009-03-06 79144]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-15 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-15 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-15 131072]
"RTHDCPL"="RTHDCPL.EXE" [2010-01-19 18790432]
"avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]
"LWS"="c:\program files\Logitech\LWS\Webcam Software\LWS.exe" [2010-05-07 165208]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Max\Menu D'marrer\Programmes\D'marrage\
Logitech . Enregistrement du produit.lnk - c:\program files\Logitech\Ereg\eReg.exe [2009-11-16 517384]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0aswBoot.exe /M:55089d29b99
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2007-05-11 01:06 40048 ----a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-02-06 16:51 3885408 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Logitech\\Vid\\Vid.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"19687:TCP"= 19687:TCP:spport
"12764:TCP"= 12764:TCP:spport
"16937:TCP"= 16937:TCP:spport
"29379:TCP"= 29379:TCP:spport
"14111:TCP"= 14111:TCP:spport
"24700:TCP"= 24700:TCP:spport
"15008:TCP"= 15008:TCP:spport
"6987:TCP"= 6987:TCP:spport
"25409:TCP"= 25409:TCP:spport
"28832:TCP"= 28832:TCP:spport
"26628:TCP"= 26628:TCP:spport
"20425:TCP"= 20425:TCP:spport
"22229:TCP"= 22229:TCP:spport
"20156:TCP"= 20156:TCP:spport
"8651:TCP"= 8651:TCP:spport
"20222:TCP"= 20222:TCP:spport
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [05/09/2010 22:28 165584]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [05/09/2010 22:28 17744]
R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [28/04/2009 03:59 38912]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [12/05/2009 22:04 1691480]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [26/01/2010 18:45 243056]
S3 RT80x86;Ralink 802.11n Wireless Driver;c:\windows\system32\drivers\rt2860.sys [12/05/2009 22:06 966912]
S3 SRS_PremiumSound_Service;SRS Labs Premium Sound;c:\windows\system32\drivers\SRS_PremiumSound_i386.sys [12/05/2009 23:14 232872]
S3 uvclf;uvclf;c:\windows\system32\drivers\uvclf.sys [28/04/2009 07:47 39040]
--- Autres Services/Pilotes en mémoire ---
*NewlyCreated* - IVKMUPGS
*Deregistered* - ivkmupgs
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-kiibaj - c:\documents and settings\Max\kiibaj.exe
MSConfigStartUp-SRS Premium Sound - c:\program files\SRS Labs\SRS Premium Sound\SRSPremiumSoundBig_Small.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-09-14 18:33
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(3660)
c:\windows\system32\logishrd\LVPrcInj01.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Alwil Software\Avast5\AvastSvc.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\RTHDCPL.EXE
c:\windows\system32\igfxext.exe
c:\program files\Fichiers communs\Logishrd\LVMVFM\LVPrcSrv.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\program files\Logitech\LWS\Webcam Software\CameraHelperShell.exe
c:\program files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Heure de fin: 2010-09-14 18:37:08 - La machine a redémarré
ComboFix-quarantined-files.txt 2010-09-14 16:37
Avant-CF: 67 279 069 184 octets libres
Après-CF: 67 372 224 512 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
Current=3 Default=3 Failed=2 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - A93AD5A295DB56D9DE5C1491C5761120