Ben il n'y a riend e plus que ça :
ComboFix 11-06-11.01 - marla 11/06/2011 22:31:53.1.1 - x86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.511.201 [GMT 2:00]
Lancé depuis: c:\documents and settings\marla\Mes documents\TÚlÚchargements\Melissa.exe
.
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\marla\Application Data\19.tmp
c:\documents and settings\marla\Application Data\1A.tmp
c:\documents and settings\marla\Application Data\1B.tmp
c:\documents and settings\marla\Application Data\1C.tmp
c:\documents and settings\marla\Application Data\Jkfafj.exe
c:\program files\Search Settings
c:\windows\jodrive32.exe
c:\windows\system32\61.exe
c:\windows\system32\ac32.exe
c:\windows\system32\msconfig.exe
.
.
((((((((((((((((((((((((((((( Fichiers créés du 2011-05-11 au 2011-06-11 ))))))))))))))))))))))))))))))))))))
.
.
2011-06-11 20:40 . 2011-06-11 20:40 -------- d-----w- c:\windows\system32\wbem\snmp
2011-06-11 20:40 . 2011-06-11 20:40 -------- d-----w- c:\windows\system32\xircom
2011-06-11 20:40 . 2011-06-11 20:40 -------- d-----w- c:\windows\srchasst
2011-06-11 20:40 . 2011-06-11 20:40 -------- d-----w- c:\program files\microsoft frontpage
2011-06-11 20:34 . 2011-06-11 20:34 21893 ----a-w- c:\documents and settings\marla\Application Data\29.tmp
2011-06-11 20:34 . 2011-06-11 20:34 21893 ----a-w- c:\documents and settings\marla\Application Data\28.tmp
2011-06-11 20:34 . 2011-06-11 20:34 93184 ----a-w- c:\documents and settings\marla\Application Data\27.tmp
2011-06-11 20:34 . 2011-06-11 20:34 90112 ----a-w- C:\scn32.exe
2011-06-11 20:34 . 2011-06-11 20:34 47616 ----a-w- c:\documents and settings\marla\Application Data\26.tmp
2011-06-11 20:19 . 2011-06-11 20:19 46615 ------w- c:\windows\system32\crssc.exe
2011-06-11 20:13 . 2011-06-11 20:34 60779 ----a-w- c:\windows\d139.exe
2011-06-11 00:03 . 2011-06-11 00:03 512 ----a-w- C:\PhysicalDisk0_MBR.bin
2011-06-10 23:58 . 2011-06-11 00:03 -------- d-----w- c:\program files\ZHPDiag
2011-06-10 21:02 . 2011-06-10 21:02 112128 ------w- c:\documents and settings\NetworkService\Application Data\Jkfafj.exe
2011-06-09 18:01 . 2011-06-09 18:02 -------- d-----w- c:\documents and settings\marla\Local Settings\Application Data\Google
2011-06-09 18:00 . 2011-06-09 18:01 -------- d-----w- c:\program files\Google
2011-06-09 17:48 . 2011-06-11 20:40 -------- d-----w- c:\program files\Fichiers communs\Akamai
.
.
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-04-13 22:40 . 2011-04-13 22:40 4284416 ----a-w- c:\windows\system32\GPhotos.scr
2011-04-03 16:38 . 2011-01-22 18:04 137656 ----a-w- c:\windows\system32\drivers\avipbb.sys
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2008-04-29 . 030DC4D48CC2B894FEE2F390D8E66AD5 . 361344 . . [5.1.2600.5512] . . c:\windows\system32\drivers\tcpip.sys
.
[-] 2008-06-04 . 478B314098276163EDD8FCD47CC15BE5 . 102400 . . [5.4.3790.5512] . . c:\windows\system32\wuauclt.exe
.
[-] 2008-06-04 . D1EA0A366973ECA3E03F1ACBEFDA8F43 . 979968 . . [6.00.2900.5512] . . c:\windows\explorer.exe
.
.
[-] 2008-04-28 . 1697B0EFD4E0FF0181F70CB73F04A518 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
[-] 2008-06-15 . 6A5F236CD5A33FAA882592834056DCA0 . 2207872 . . [5.1.2600.5512] . . c:\windows\system32\ntkrnlpa.exe
.
[-] 2008-06-04 . 3EBD4417CA19355C7E095E915EF7C432 . 2331008 . . [5.1.2600.5512] . . c:\windows\system32\ntoskrnl.exe
.
c:\windows\System32\wscntfy.exe ... manque !!
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LClock"="c:\windows\LSD\LClock\lclock.exe" [2004-09-19 65536]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-08-17 281768]
"ACU"="c:\program files\Atheros\ACU.exe" [2004-04-18 278528]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-12 342312]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 577536]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-01-30 35736]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2010-10-29 249064]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-11 689488]
"name_me"="c:\documents and settings\marla\Application Data\29.tmp" [2011-06-11 21893]
"name_meexuii"="c:\documents and settings\marla\Application Data\28.tmp" [2011-06-11 21893]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
"Jkfafj"="c:\documents and settings\NetworkService\Application Data\Jkfafj.exe" [2011-06-10 112128]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nltide_2"="shell32" [X]
"WinLSD_SP3"="c:\windows\LSD\end.cmd" [2008-06-17 9944]
"nltide_3"="advpack.dll" [2008-04-23 124928]
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoSMBalloonTip"= 0 (0x0)
.
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1035:TCP"= 1035:TCP:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:Akamai NetSession Interface
.
R2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe -k Akamai [14/04/2008 01:34 14336]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [22/01/2011 20:04 136360]
R2 Netmanm;Network Connections to Monitor;c:\windows\system32\crssc.exe [11/06/2011 22:19 46615]
R3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\drivers\wg111v2.sys [22/01/2011 19:09 272128]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [09/01/2011 14:52 310640]
.
--- Autres Services/Pilotes en mémoire ---
.
*NewlyCreated* - HELPSVC
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
.
Contenu du dossier 'Tâches planifiées'
.
2011-01-23 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.winlsd.org/
uInternet Connection Wizard,ShellNext = hxxp://www.winlsd.org/
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
TCP: DhcpNameServer = 212.27.40.241 212.27.40.242
FF - ProfilePath - c:\documents and settings\marla\Application Data\Mozilla\Firefox\Profiles\jmzgulko.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
.
- - - - ORPHELINS SUPPRIMES - - - -
.
HKCU-Run-Jkfafj - c:\documents and settings\marla\Application Data\Jkfafj.exe
HKLM-Run-Microsoft Config Setup - c:\windows\jodrive32.exe
HKLM-Run-ac32 - c:\windows\system32\ac32.exe
HKU-Default-RunOnce-tscuninstall - c:\windows\system32\tscupgrd.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-06-11 22:40
Windows 5.1.2600 Service Pack 3 NTFS
.
Recherche de processus cachés ...
.
Recherche d'éléments en démarrage automatique cachés ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
name_me = c:\documents and settings\marla\Application Data\29.tmp?@?(?????|?"?|?"? ???????o??|??(?@?????????>???(?????@?"???>?????????x?(???>???????"?????\?"????|???|????P?????(????|@???????h?(?????h?(???????(??9>?|?"????????|??(?H?"?!??|??(?=??|??(?????A???x?>?L?????(
name_meexuii = c:\documents and settings\marla\Application Data\28.tmp?@?(?????|?"?|?"? ???????o??|??(?@?????????>???(?????@?"???>?????????x?(???>???????"?????\?"????|???|????P?????(????|@???????h?(?????h?(???????(??9>?|?"????????|??(?H?"?!??|??(?=??|??(?????A???x?>?L?????(
.
Recherche de fichiers cachés ...
.
Scan terminé avec succès
Fichiers cachés: 0
.
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
.
- - - - - - - > 'winlogon.exe'(720)
c:\windows\system32\athgina.dll
c:\windows\system32\athcfg11.dll
.
- - - - - - - > 'lsass.exe'(776)
c:\windows\system32\scecli.dll
.
- - - - - - - > 'explorer.exe'(3168)
c:\windows\system32\SHDOCVW.dll
c:\windows\system32\ntshrui.dll
c:\windows\system32\msi.dll
c:\windows\system32\NETSHELL.dll
c:\windows\system32\credui.dll
c:\windows\system32\eappprxy.dll
c:\windows\LSD\LClock\LC.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\acs.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Canon\IJPLM\IJPLMSVC.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\SOUNDMAN.EXE
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Heure de fin: 2011-06-11 22:44:38 - La machine a redémarré
ComboFix-quarantined-files.txt 2011-06-11 20:44
.
Avant-CF: 30 384 488 448 octets libres
Après-CF: 30 530 207 744 octets libres
.
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
.
- - End Of File - - 544A724B6530490F2C6AD4348A0D0F06