Voici le rapport et merci d'avance pour votre aide
ComboFix 09-07-14.08 - ACCES SECURISE 16/07/2009 16:44.1.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.3067.2649 [GMT 2:00]
Running from: c:\documents and settings\Administrateur.IND_PC\Bureau\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090716-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-4191265072-3133045890-1185931964-1000
c:\docume~1\ADMINI~1.IND\LOCALS~1\Temp\tmp2.tmp
c:\documents and settings\Administrateur.IND_PC\Local Settings\Application Data\kmouu.dat
c:\documents and settings\Administrateur.IND_PC\Local Settings\Application Data\kmouu.exe
c:\documents and settings\Administrateur.IND_PC\Local Settings\Application Data\kmouu_nav.dat
c:\documents and settings\Administrateur.IND_PC\Local Settings\Application Data\kmouu_navps.dat
c:\windows\Installer\698e7.msp
c:\windows\Installer\6a3f6.msi
c:\windows\Installer\a3b808.msi
c:\windows\system32\wget.exe
c:\windows\system32\zip32.dll
.
((((((((((((((((((((((((( Files Created from 2009-06-16 to 2009-07-16 )))))))))))))))))))))))))))))))
.
2009-07-16 14:37 . 2009-07-16 14:38 -------- d-----w- C:\hijack
2009-07-15 18:51 . 2009-07-15 18:51 -------- d-----w- c:\program files\zabkat
2009-07-15 18:47 . 2009-07-15 18:47 -------- d-----w- c:\documents and settings\Administrateur.IND_PC\Application Data\FPC
2009-07-15 18:47 . 2009-07-15 18:47 -------- d-----w- c:\documents and settings\Administrateur.IND_PC\Local Settings\Application Data\FPC
2009-07-15 18:41 . 2009-07-15 18:44 -------- d-----w- c:\program files\Fichiers communs\PC Tools
2009-07-09 22:00 . 2009-07-14 10:36 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\ThumbnailCache4R
2009-07-09 21:59 . 2009-07-09 22:01 -------- d-----w- c:\program files\SimpleOCR
2009-07-09 21:50 . 2009-07-09 21:50 -------- d-----w- c:\windows\Documalis Free Scanner 1.0
2009-07-09 21:50 . 2009-07-09 21:50 -------- d-----w- c:\program files\Documalis Free
2009-07-01 13:25 . 2009-07-01 13:25 -------- d-----w- c:\windows\system32\Adobe
2009-07-01 13:23 . 1998-10-07 11:08 327168 ----a-w- c:\windows\IsUn040c.exe
2009-06-25 21:42 . 2009-07-09 21:59 -------- d-----w- c:\documents and settings\Administrateur.IND_PC\Application Data\Lexmark Productivity Studio
2009-06-23 21:13 . 2009-06-23 21:13 -------- d-sh--w- c:\documents and settings\LocalService.AUTORITE NT\PrivacIE
2009-06-23 21:13 . 2009-06-23 21:13 -------- d-----r- c:\documents and settings\LocalService.AUTORITE NT\Favoris
2009-06-23 11:33 . 2009-06-23 11:33 -------- d-sh--w- c:\documents and settings\LocalService.AUTORITE NT\IETldCache
2009-06-23 11:08 . 2009-07-15 18:42 -------- d---a-w- c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2009-06-22 00:23 . 2009-06-22 00:23 -------- d-sh--w- c:\documents and settings\Administrateur.IND_PC\IECompatCache
2009-06-21 14:42 . 2009-06-21 14:42 -------- d-sh--w- c:\documents and settings\Administrateur.IND_PC\PrivacIE
2009-06-21 14:40 . 2009-06-21 14:40 -------- d-sh--w- c:\documents and settings\Administrateur.IND_PC\IETldCache
2009-06-21 14:38 . 2009-06-21 14:38 -------- d--h--w- c:\windows\msdownld.tmp
2009-06-21 14:36 . 2009-06-21 14:38 -------- dc-h--w- c:\windows\ie8
2009-06-20 17:11 . 2009-06-20 17:11 -------- d-----w- c:\program files\AviSynth 2.5
2009-06-20 17:09 . 2009-06-20 17:55 -------- d-----w- c:\program files\Ripp-it_AM
2009-06-20 16:38 . 2009-06-20 17:30 -------- d-----w- c:\program files\CamStudio
2009-06-19 21:19 . 2009-06-19 21:19 -------- d-----w- C:\Poker
2009-06-16 21:44 . 2009-02-05 20:06 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-06-16 21:44 . 2009-02-05 20:06 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-06-16 21:44 . 2009-02-05 20:05 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-06-16 21:44 . 2009-02-05 20:04 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-06-16 21:44 . 2009-02-05 20:08 93296 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-06-16 21:44 . 2009-02-05 20:08 94032 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-06-16 21:44 . 2009-02-05 20:07 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-06-16 21:44 . 2009-02-05 20:07 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-06-16 21:44 . 2009-02-05 20:11 1256296 ----a-w- c:\windows\system32\aswBoot.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-16 11:03 . 2005-12-15 12:00 80344 ----a-w- c:\windows\system32\perfc00C.dat
2009-07-16 11:03 . 2005-12-15 12:00 498062 ----a-w- c:\windows\system32\perfh00C.dat
2009-07-14 11:53 . 2009-01-30 16:23 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-14 09:39 . 2009-01-31 01:30 67328 ----a-w- c:\documents and settings\Administrateur.IND_PC\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-13 19:49 . 2009-04-09 15:16 -------- d-----w- c:\documents and settings\Administrateur.IND_PC\Application Data\gtk-2.0
2009-07-10 10:52 . 2009-04-01 22:25 -------- d-----w- c:\program files\Lexmark 2600 Series
2009-07-09 21:58 . 2009-04-01 22:25 -------- d-----w- c:\program files\Lexmark Tools for Office
2009-07-01 13:26 . 2009-01-30 16:36 -------- d-----w- c:\program files\Fichiers communs\Adobe
2009-06-25 11:31 . 2009-02-03 11:54 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft Help
2009-06-20 23:29 . 2009-05-01 23:33 -------- d-----w- c:\program files\PKR
2009-06-20 14:48 . 2009-01-30 20:04 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\CyberLink
2009-06-16 15:49 . 2009-06-05 11:02 -------- d-----w- c:\program files\3DYAMS_XP
2009-06-09 15:02 . 2009-01-30 17:16 -------- d-----w- c:\program files\Launch Manager
2009-06-04 14:49 . 2009-06-04 14:49 -------- d-----w- c:\program files\Code Postal
2009-05-22 12:01 . 2009-05-22 12:01 -------- d-----w- c:\program files\Dia
2009-05-10 18:36 . 2009-01-30 20:09 1024 ---h--r- c:\windows\system32\NTIMP3.dll
2009-07-16 10:59 . 2009-07-01 13:37 13867 --sha-w- c:\program files\internet explorer\plugins\HiJack.dll
2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"lxdnmon.exe"="c:\program files\Lexmark 2600 Series\lxdnmon.exe" [2009-05-20 660136]
"lxdnamon"="c:\program files\Lexmark 2600 Series\lxdnamon.exe" [2009-05-20 16040]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-08-05 13541376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="move" [X]
"nlhr"="c:\windows\System32\AdvPack.Dll" [2009-03-08 128512]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2005-12-15 44544]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{01F6EB6F-AB5C-1FDD-6E5B-FB6EE3CC6CD6}"= "c:\program files\Internet Explorer\PLUGINS\HiJack.dll" [2009-07-16 13867]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"=hex(2):58,50,69,7a,65,5f,4c,6f,67,6f,6e,2e,65,78,65,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\AWinNotifyVitaKey MC3000]
2009-01-30 19:25 2972160 ----a-w- c:\program files\Acer\Acer Bio Protection\WinNotify.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Démarrer^Programmes^Démarrage^Adobe Gamma Loader.exe.lnk]
path=c:\documents and settings\All Users.WINDOWS\Menu Démarrer\Programmes\Démarrage\Adobe Gamma Loader.exe.lnk
backup=c:\windows\pss\Adobe Gamma Loader.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS^Menu Démarrer^Programmes^Démarrage^TClock.lnk]
path=c:\documents and settings\All Users.WINDOWS\Menu Démarrer\Programmes\Démarrage\TClock.lnk
backup=c:\windows\pss\TClock.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Lexmark 2600 Series\\lxdnlscn.exe"=
"c:\\Program Files\\Lexmark 2600 Series\\lxdnmon.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 AlfaFF;AlfaFF File System mini-filter;c:\windows\system32\drivers\AlfaFF.sys [30/01/2009 21:24 43184]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [16/06/2009 23:44 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [16/06/2009 23:44 20560]
R2 IGBASVC;iGroupTec Service;c:\program files\Acer\Acer Bio Protection\BASVC.exe [30/01/2009 21:24 3471360]
R2 libusbd;LibUsb-Win32 - Daemon, Version 0.1.10.1;system32\libusbd-nt.exe --> system32\libusbd-nt.exe [?]
R2 lxdn_device;lxdn_device;c:\windows\system32\lxdncoms.exe -service --> c:\windows\system32\lxdncoms.exe -service [?]
R3 hidshim;Service for HID-KMDF Shim layer;c:\windows\system32\drivers\hidshim.sys [03/06/2008 13:37 5632]
R3 JMCR;JMCR;c:\windows\system32\drivers\jmcr.sys [30/01/2009 22:40 81296]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;c:\windows\system32\drivers\libusb0.sys [15/02/2009 01:36 33792]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [21/04/2008 05:14 38560]
R3 winbondhidcir;Winbond HID CIR Receiver;c:\windows\system32\drivers\winbondhidcir.sys [03/06/2008 13:37 23040]
S2 lxdnCATSCustConnectService;lxdnCATSCustConnectService;c:\windows\system32\spool\drivers\w32x86\3\lxdnserv.exe [02/04/2009 00:26 98984]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [15/03/2009 09:34 216232]
S3 XPADFL02;XPAD Filter Service 02;c:\windows\system32\drivers\xPADFL02.sys [15/02/2009 01:37 27904]
.
Contents of the 'Scheduled Tasks' folder
2009-07-16 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-02 20:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.fr/
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-07-16 16:52
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-343818398-1580818891-725345543-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,44,e1,52,82,91,da,e7,4b,b1,c7,b8,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,44,e1,52,82,91,da,e7,4b,b1,c7,b8,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(948)
c:\program files\Acer\Acer Bio Protection\CompPtc.dll
c:\program files\Acer\Acer Bio Protection\CustomRes.dll
c:\windows\system32\ATSC70.DLL
c:\windows\system32\ATSC70PBA.dll
c:\program files\Acer\Acer Bio Protection\WinNotify.dll
- - - - - - - > 'explorer.exe'(2560)
c:\windows\system32\ieframe.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\agrsmsvc.exe
c:\windows\system32\libusbd-nt.exe
c:\program files\Fichiers communs\LightScribe\LSSrvc.exe
c:\windows\system32\lxdncoms.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Cyberlink\Shared files\RichVideo.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\windows\system32\wscntfy.exe
c:\program files\Lexmark 2600 Series\lxdnmsdmon.exe
.
**************************************************************************
.
Completion time: 2009-07-16 16:55 - machine was rebooted
ComboFix-quarantined-files.txt 2009-07-16 14:55
Pre-Run: 45 195 096 064 octets libres
Post-Run: 45 832 765 440 octets libres
195 --- E O F --- 2009-05-13 21:29