Alors voici tout les rapport demander sauf (D) pour googleupdaterservice.exe que jai totalement suprimé car je le trouvai trop gourmand à mon gout =P
/Clean rapport :
Script execute en mode sans echec
Rapport clean par Malekal_morte - http://www.malekal.com
Script execute en mode sans echec 25/06/2007 a 15:51:01,57
Microsoft Windows XP [version 5.1.2600]
*** Suppression des fichiers dans C:
*** Suppression des fichiers dans C:\WINDOWS\
*** Suppression des fichiers dans C:\WINDOWS\system32
tentative de suppression de "C:\WINDOWS\Downloaded Program Files\CONFLICT.1"
*** Suppression des fichiers dans C:\Program Files
*** Suppression des clefs du registre effectuee..
*** Fin du rapport !
__________________________
Combo fix
"BOOBOO" - 2007-06-25 16:15:16 - ComboFix 07-06-25.3 - Service Pack 2 NTFS [SAFE MODE]
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\xpdx.sys
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\xpdx
((((((((((((((((((((((((( Files Created from 2007-05-25 to 2007-06-25 )))))))))))))))))))))))))))))))
2007-06-25 16:14 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-25 15:59 <REP> d-------- C:\Program Files\backups
2007-06-25 15:38 1,308,216 --a------ C:\Program Files\HiJackThis_v2.exe
2007-06-24 23:15 524,288 --ah----- C:\DOCUME~1\ADMINI~1\NTUSER.DAT
2007-06-24 23:15 <REP> dr------- C:\DOCUME~1\ADMINI~1\Menu D‚marrer
2007-06-24 23:15 <REP> d--h----- C:\DOCUME~1\ADMINI~1\Voisinage r‚seau
2007-06-24 23:15 <REP> d--h----- C:\DOCUME~1\ADMINI~1\Voisinage d'impression
2007-06-24 23:15 <REP> d--h----- C:\DOCUME~1\ADMINI~1\ModŠles
2007-06-24 23:15 <REP> d-------- C:\DOCUME~1\ADMINI~1\Mes documents
2007-06-24 23:15 <REP> d-------- C:\DOCUME~1\ADMINI~1\Favoris
2007-06-24 23:15 <REP> d-------- C:\DOCUME~1\ADMINI~1\Bureau
2007-06-24 22:44 <REP> d-------- C:\DOCUME~1\BOOBOO\APPLIC~1\Help
2007-06-24 19:32 <REP> d-------- C:\WINDOWS\pss
2007-06-24 19:07 <REP> d-------- C:\WINDOWS\system32\ActiveScan
2007-06-24 05:05 1,156 --a------ C:\WINDOWS\mozver.dat
2007-06-24 04:25 0 --a------ C:\WINDOWS\nsreg.dat
2007-06-24 04:19 <REP> d-------- C:\DOCUME~1\BOOBOO\APPLIC~1\Talkback
2007-06-23 03:23 8,748 --ah----- C:\WINDOWS\system32\mlfcache.dat
2007-06-21 14:51 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\nView_Profiles
2007-06-21 08:41 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\AntiVir PersonalEdition Classic
2007-06-21 05:46 208,896 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2007-06-21 05:46 208,896 --a------ C:\WINDOWS\system32\nvudisp.exe
2007-06-21 05:46 <REP> d-------- C:\WINDOWS\nview
2007-06-20 02:35 <REP> d-------- C:\DOCUME~1\BOOBOO\APPLIC~1\EoRezo
2007-06-16 20:12 <REP> d-------- C:\Program Files\Half-Life Model Viewer
2007-06-15 18:58 <REP> d-------- C:\Program Files\PowerQuest
2007-06-15 04:03 <REP> d-------- C:\Program Files\X'nBeep 1.1
2007-06-14 15:37 <REP> d-------- C:\Program Files\uTorrent
2007-06-14 15:37 <REP> d-------- C:\DOCUME~1\BOOBOO\APPLIC~1\uTorrent
2007-06-13 14:30 <REP> d--hs---- C:\found.000
2007-06-10 22:21 <REP> d-------- C:\DOCUME~1\BOOBOO\APPLIC~1\GameServerBrowser
2007-06-10 22:21 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\GameServerBrowser
2007-06-10 21:59 <REP> d-------- C:\Program Files\The All-Seeing Eye
2007-06-09 15:40 <REP> d-------- C:\DOCUME~1\BOOBOO\APPLIC~1\teamspeak2
2007-06-09 15:39 <REP> d-------- C:\Program Files\Teamspeak2_RC2
2007-06-07 15:47 <REP> d-------- C:\Valve
2007-06-06 21:09 196,608 --a------ C:\WINDOWS\system32\ssleay32.dll
2007-06-06 21:09 1,040,384 --a------ C:\WINDOWS\system32\libeay32.dll
2007-06-06 16:54 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
2007-06-06 16:51 <REP> d-------- C:\Program Files\Fichiers communs\Jasc Software Inc
2007-06-06 16:51 <REP> d-------- C:\DOCUME~1\BOOBOO\APPLIC~1\Jasc Software Inc
2007-06-06 16:50 <REP> d-------- C:\Program Files\Jasc Software Inc
2007-06-06 13:54 <REP> d-------- C:\WINDOWS\Downloaded Installations
2007-06-05 20:02 <REP> d--h----- C:\WINDOWS\system32\GroupPolicy
2007-06-05 19:42 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-06-05 02:40 <REP> d-------- C:\WINDOWS\system32\PreInstall
2007-06-04 19:25 <REP> d-------- C:\WINDOWS\Prefetch
2007-06-04 19:18 95,424 --------- C:\WINDOWS\system32\drivers\slnthal.sys
2007-06-04 19:18 938,496 --------- C:\WINDOWS\system32\winbrand.dll
2007-06-04 19:18 9,728 --------- C:\WINDOWS\system32\comsdupd.exe
2007-06-04 19:18 896,512 --------- C:\WINDOWS\system32\wmspdmoe.dll
2007-06-04 19:18 88,064 --------- C:\WINDOWS\system32\p2pnetsh.dll
2007-06-04 19:18 870,784 --------- C:\WINDOWS\system32\ati3d1ag.dll
2007-06-04 19:18 86,016 --------- C:\WINDOWS\system32\p2pgasvc.dll
2007-06-04 19:18 86,016 --------- C:\WINDOWS\system32\mdmxsdk.dll
2007-06-04 19:18 81,920 --------- C:\WINDOWS\system32\ieencode.dll
2007-06-04 19:18 81,408 --------- C:\WINDOWS\system32\wscsvc.dll
2007-06-04 19:18 8,192 --------- C:\WINDOWS\system32\smbinst.exe
2007-06-04 19:18 78,464 --------- C:\WINDOWS\system32\drivers\usbvideo.sys
2007-06-04 19:18 75,776 --------- C:\WINDOWS\system32\strmfilt.dll
2007-06-04 19:18 73,832 --------- C:\WINDOWS\system32\slcoinst.dll
2007-06-04 19:18 73,796 --------- C:\WINDOWS\system32\slserv.exe
2007-06-04 19:18 73,216 --------- C:\WINDOWS\system32\drivers\atintuxx.sys
2007-06-04 19:18 71,680 --------- C:\WINDOWS\system32\blastcln.exe
2007-06-04 19:18 701,440 --------- C:\WINDOWS\system32\drivers\ati2mtag.sys
2007-06-04 19:18 7,680 --------- C:\WINDOWS\system32\kbdsmsno.dll
2007-06-04 19:18 7,680 --------- C:\WINDOWS\system32\kbdsmsfi.dll
2007-06-04 19:18 7,168 --------- C:\WINDOWS\system32\kbdukx.dll
2007-06-04 19:18 7,168 --------- C:\WINDOWS\system32\kbdno1.dll
2007-06-04 19:18 7,168 --------- C:\WINDOWS\system32\kbdfi1.dll
2007-06-04 19:18 7,168 --------- C:\WINDOWS\system32\hccoin.dll
2007-06-04 19:18 685,056 --------- C:\WINDOWS\system32\drivers\hsfcxts2.sys
2007-06-04 19:18 67,584 --------- C:\WINDOWS\system32\drivers\sdbus.sys
2007-06-04 19:18 63,663 --------- C:\WINDOWS\system32\drivers\ati1rvxx.sys
2007-06-04 19:18 63,488 --------- C:\WINDOWS\system32\drivers\atinxsxx.sys
2007-06-04 19:18 60,416 --------- C:\WINDOWS\system32\fwcfg.dll
2007-06-04 19:18 6,656 --------- C:\WINDOWS\system32\kbdinmal.dll
2007-06-04 19:18 6,656 --------- C:\WINDOWS\system32\kbdinben.dll
2007-06-04 19:18 6,144 --------- C:\WINDOWS\system32\kbdmlt48.dll
2007-06-04 19:18 6,144 --------- C:\WINDOWS\system32\kbdmlt47.dll
2007-06-04 19:18 6,144 --------- C:\WINDOWS\system32\kbdinbe1.dll
2007-06-04 19:18 6,016 --------- C:\WINDOWS\system32\drivers\smbali.sys
2007-06-04 19:18 59,648 --------- C:\WINDOWS\system32\drivers\rfcomm.sys
2007-06-04 19:18 57,856 --------- C:\WINDOWS\system32\drivers\atinbtxx.sys
2007-06-04 19:18 56,623 --------- C:\WINDOWS\system32\drivers\ati1btxx.sys
2007-06-04 19:18 526,848 --------- C:\WINDOWS\system32\p2psvc.dll
2007-06-04 19:18 52,736 --------- C:\WINDOWS\system32\mspmsnsv.dll
2007-06-04 19:18 52,224 --------- C:\WINDOWS\system32\drivers\atinraxx.sys
2007-06-04 19:18 516,768 --------- C:\WINDOWS\system32\ativvaxx.dll
2007-06-04 19:18 50,688 --------- C:\WINDOWS\system32\btpanui.dll
2007-06-04 19:18 50,176 --------- C:\WINDOWS\system32\xmlprovi.dll
2007-06-04 19:18 5,632 --------- C:\WINDOWS\system32\kbdmaori.dll
2007-06-04 19:18 49,152 --------- C:\WINDOWS\system32\powercfg.exe
2007-06-04 19:18 484,864 --------- C:\WINDOWS\system32\wmspdmod.dll
2007-06-04 19:18 48,640 --------- C:\WINDOWS\system32\pnrpnsp.dll
2007-06-04 19:18 46,464 --------- C:\WINDOWS\system32\drivers\gagp30kx.sys
2007-06-04 19:18 452,736 --------- C:\WINDOWS\system32\drivers\mtxparhm.sys
2007-06-04 19:18 44,928 --------- C:\WINDOWS\system32\drivers\agpcpq.sys
2007-06-04 19:18 44,672 --------- C:\WINDOWS\system32\drivers\uagp35.sys
2007-06-04 19:18 44,032 --------- C:\WINDOWS\system32\twext.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-06-05 12:22:41 48,616 ----a-w C:\WINDOWS\system32\perfc00C.dat
2007-06-05 12:22:41 367,658 ----a-w C:\WINDOWS\system32\perfh00C.dat
2007-05-16 15:13:53 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-04-16 20:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2007-04-02 10:35]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 14:29]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages scecli scecli
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Driver]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\AVG Anti-Spyware Guard]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Outil de mise à jour Google.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Outil de mise à jour Google.lnk
backup=C:\WINDOWS\pss\Outil de mise à jour Google.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"sdCoreService"=2 (0x2)
"sdAuxService"=2 (0x2)
"a2free"=2 (0x2)
**************************************************************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-06-25 16:18:57
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-06-25 16:20:22 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-06-25 16:20
--- E O F ---
_____________________________
nouveau rapport hijackthis déplacer dans programes files
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 16:23:17, on 25/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HiJackThis_v2.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
End of file - 3238 bytes
______________________________________
et pour la question du par feu non je ne trouve pas du totu ca normal parceque je le voi activé dans le centre de securité :s
L'erreur 203 et 204 du service.exe on l`ere d'avoir disparue mais je ne ne suis pas vriament sur a 100% encore