Bonjour,
je fais 1sanc avec spyware doctor , et on me decouvre le probleme suivant comme quoi j'ai un dialer.insatnt_acces sur mon ordinateur et un virus trojan small jmh ..alor j'aimerai savoir si quelqu'un pourait a m'en debarraser de tout cela, se serai vraiment gentil pcq j'ai essayer de supprimer mais cela revient tout le temps....
et j'ai audssi mon pare feu bloquer , il est griser en mode desactiver et cela a eu comme consequence d'avoir ses virus....
merci de votre aide d'avance, c vraiment urgent ..
je poste le log avec combofix
ComboFix 08-03-01.3 - HP_Administrateur 2008-03-01 11:21:00.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.435 [GMT 1:00]
Endroit: C:\DOCUME~1\HP_ADM~1\Bureau\combofix.exe
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\WebMediaPlayer
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\WebMediaPlayer\Conditions générales.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\WebMediaPlayer\Confidentialité.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\WebMediaPlayer\WebMediaPlayer.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\WebMediaPlayer\Website.lnk
C:\Documents and Settings\HP_Administrateur\Application Data\MessengerSkinner
C:\Documents and Settings\HP_Administrateur\Application Data\MessengerSkinner\Userdata\languages_v2.xml
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\wnvcxgfgi.dat
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\wnvcxgfgi.exe
C:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\wnvcxgfgi_nav.dat
c:\Documents and Settings\HP_Administrateur\Local Settings\Application Data\wnvcxgfgi_navps.dat
C:\Program Files\messengerskinner
C:\Program Files\messengerskinner\MessengerSkinnerDll.dll
C:\WINDOWS\pack.epk
C:\WINDOWS\system32\Cache
C:\WINDOWS\system32\vdrziwembj.dat
C:\WINDOWS\system32\vdrziwembj_nav.dat
C:\WINDOWS\system32\vdrziwembj_navps.dat
D:\Autorun.inf
.
((((((((((((((((((((((((((((( Fichiers créés 2008-02-01 to 2008-03-01 ))))))))))))))))))))))))))))))))))))
.
2008-02-29 19:21 . 2008-02-29 19:21 9,296 --a------ C:\WINDOWS\system32\bmhcsr.exe
2008-02-29 19:04 . 2007-08-14 17:02 82,248 --------- C:\WINDOWS\system32\drivers\iksyssec.sys
2008-02-29 19:04 . 2007-08-14 17:02 57,672 --------- C:\WINDOWS\system32\drivers\iksysflt.sys
2008-02-29 19:04 . 2007-08-14 17:02 40,264 --------- C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-02-29 19:04 . 2007-08-14 17:02 29,000 --------- C:\WINDOWS\system32\drivers\kcom.sys
2008-02-29 19:03 . 2008-02-29 19:57 <REP> d-------- C:\Program Files\Spyware Doctor
2008-02-29 19:03 . 2008-02-29 19:03 <REP> d-------- C:\Documents and Settings\HP_Administrateur\Application Data\PC Tools
2008-02-29 19:03 . 2005-09-23 07:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2008-02-28 23:39 . 2008-02-28 23:39 12,644,785 --a------ C:\upload_moi_NOM-FB9B15D2723.tar.gz
2008-02-28 12:47 . 2008-02-28 22:50 <REP> d-------- C:\WINDOWS\system32\NtmsData
2008-02-28 07:40 . 2008-02-28 07:40 244 --ah----- C:\sqmnoopt19.sqm
2008-02-28 07:40 . 2008-02-28 07:40 232 --ah----- C:\sqmdata19.sqm
2008-02-28 01:37 . 2007-12-04 14:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-02-28 01:37 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-02-28 01:37 . 2007-12-04 13:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-02-28 01:37 . 2007-12-04 15:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-02-28 01:37 . 2007-12-04 15:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-02-28 01:37 . 2007-12-04 15:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-02-28 01:37 . 2007-12-04 15:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-02-28 01:37 . 2007-12-04 15:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-02-28 01:34 . 2008-02-28 01:34 244 --ah----- C:\sqmnoopt18.sqm
2008-02-28 01:34 . 2008-02-28 01:34 232 --ah----- C:\sqmdata18.sqm
2008-02-28 01:30 . 2008-02-28 01:30 244 --ah----- C:\sqmnoopt17.sqm
2008-02-28 01:30 . 2008-02-28 01:30 232 --ah----- C:\sqmdata17.sqm
2008-02-28 01:02 . 2008-02-28 01:02 244 --ah----- C:\sqmnoopt16.sqm
2008-02-28 01:02 . 2008-02-28 01:02 232 --ah----- C:\sqmdata16.sqm
2008-02-27 22:54 . 2008-02-27 22:54 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-02-27 20:20 . 2008-02-27 20:20 45,768 --a------ C:\WINDOWS\system32\drivers\MiniIcpt.sys
2008-02-27 20:17 . 2008-02-27 20:53 <REP> d-------- C:\Program Files\G DATA AntiVirus Trial
2008-02-27 11:34 . 2008-02-27 11:34 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-02-27 11:33 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-02-27 11:33 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-02-27 11:33 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-02-26 21:29 . 2008-02-26 21:29 <REP> d-------- C:\Program Files\Messenger Plus! Live
2008-02-26 17:20 . 2008-02-26 20:45 <REP> d-------- C:\Program Files\Windows Live
2008-02-26 17:20 . 2008-02-26 20:44 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-02-26 17:20 . 2008-02-26 20:44 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-14 21:53 . 2008-02-14 21:53 360,448 --a------ C:\WINDOWS\system32\bspjdz.exe
2008-02-13 21:29 . 2008-02-13 21:29 299,008 --a------ C:\WINDOWS\system32\ghrpmvzrxu.exe
2008-02-13 20:15 . 2008-02-13 20:15 295,936 --a------ C:\WINDOWS\system32\fekhpp.exe
2008-02-13 07:29 . 2008-02-13 07:29 333,824 --a------ C:\WINDOWS\system32\ywmuqoq.exe
2008-02-11 07:08 . 2008-02-11 07:08 296,960 --a------ C:\WINDOWS\system32\msqlsu.exe
2008-02-10 12:47 . 2008-02-10 12:47 313,344 --a------ C:\WINDOWS\system32\vtzpre.exe
2008-02-09 19:27 . 2008-02-12 19:14 304,128 --a------ C:\WINDOWS\system32\mfulqed.exe
2008-02-09 13:03 . 2008-02-09 13:03 342,016 --a------ C:\WINDOWS\system32\lawehinpt.exe
2008-02-05 23:57 . 2008-02-25 14:10 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-05 23:57 . 2008-02-05 23:57 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-01 10:20 --------- d-----w C:\Program Files\Wanadoo
2008-03-01 09:48 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-29 21:59 7,946 ----a-w C:\Documents and Settings\HP_Administrateur\Application Data\wklnhst.dat
2008-02-28 00:37 --------- d-----w C:\Program Files\Alwil Software
2008-02-27 19:17 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-26 19:45 --------- d-----w C:\Program Files\MSN Messenger
2008-02-25 17:56 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\LimeWire
2008-02-23 00:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ulead Systems
2008-02-23 00:02 --------- d-----w C:\Program Files\Ulead Systems
2008-02-22 23:56 --------- d-----w C:\Program Files\OpenOffice.org 2.3
2008-02-22 23:54 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\OpenOffice.org2
2008-02-03 16:00 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\SopCast
2008-01-28 21:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-01-28 21:20 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-01-28 21:20 --------- d-----w C:\Program Files\Bonjour
2008-01-28 21:10 --------- d-----w C:\Program Files\Fichiers communs\Macrovision Shared
2008-01-26 14:54 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-01-26 14:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-26 10:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-25 12:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-25 12:34 --------- d-----w C:\Program Files\Lavasoft
2008-01-25 12:34 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-01-23 05:58 --------- d-----w C:\Program Files\FinePixViewer
2008-01-16 21:57 --------- d-----w C:\Program Files\MessengerPlus! 3
2008-01-16 20:57 --------- d-----w C:\Program Files\Fichiers communs\PasenDommagement
2008-01-12 19:28 --------- d-----w C:\Program Files\SopCast
2008-01-06 16:26 --------- d-----w C:\Program Files\TVAnts
2008-01-05 11:51 --------- d-----w C:\Documents and Settings\HP_Administrateur\Application Data\gtk-2.0
2008-01-04 22:06 --------- d-----w C:\Program Files\Ubisoft
2008-01-03 18:19 --------- d-----w C:\Program Files\GIMP-2.0
2008-01-02 17:48 --------- d-----w C:\Program Files\Fichiers communs\InterVideo
2007-12-26 12:45 159,744 ----a-w C:\WINDOWS\system32\Netlog24Uninstaller.exe
2007-12-18 09:51 179,584 ----a-w C:\WINDOWS\system32\dllcache\mrxdav.sys
2007-12-16 19:29 556 ---ha-w C:\os357577.bin
2007-12-14 10:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2007-12-06 10:05 18,432 ----a-w C:\WINDOWS\system32\dllcache\iedw.exe
2007-12-04 18:41 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-12-04 18:41 550,912 ----a-w C:\WINDOWS\system32\dllcache\oleaut32.dll
2007-01-28 13:45 278,528 ----a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
2007-01-14 12:15 251 ----a-w C:\Program Files\wt3d.ini
2006-02-19 08:28 12,288 ----a-w C:\WINDOWS\Fonts\RandFont.dll
2006-11-03 19:01 22 --sha-w C:\WINDOWS\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WOOKIT"="C:\Program Files\Wanadoo\Shell.exe" [2004-08-23 14:50 122880]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 19:34 64512]
"ftutil2"="ftutil2.dll" [2004-06-07 13:05 106496 C:\WINDOWS\system32\ftutil2.dll]
"RTHDCPL"="RTHDCPL.EXE" [2006-06-14 04:05 16239616 C:\WINDOWS\RTHDCPL.EXE]
"AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 01:15 77312 C:\WINDOWS\arpwrmsg.exe]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-05-09 23:50 7311360]
"nwiz"="nwiz.exe" [2006-05-09 23:50 1519616 C:\WINDOWS\system32\nwiz.exe]
"DMAScheduler"="c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 08:05 90112]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-22 21:14 237568]
"PCDrProfiler"="" []
"HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 21:34 249856]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-12-15 10:18 49152]
"REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.exe" [2002-02-04 21:32 53248]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-08-14 15:02 180269]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-05-17 17:38 155648]
"WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 14:49 20480]
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 16:55 32768]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [ ]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"ISUSPM Startup"="C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 22:50 221184]
"RegistryMechanic"="" []
"SDTray"="C:\Program Files\Spyware Doctor\SDTrayApp.exe" [2007-08-14 17:02 1063752]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-10-23 22:18 443968]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
C:\Documents and Settings\HP_Administrateur\Menu D‚marrer\Programmes\D‚marrage\
Outil de d‚tection de support Picture Motion Browser.lnk - C:\Program Files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2007-07-05 15:33:30 344064]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-12-15 10:40:44 282624]
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R3 usbstor;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-10 12:00]
S3 SIS163u;SiS163 USB Wireless LAN Adapter Driver;C:\WINDOWS\system32\DRIVERS\sis163u.sys [2006-03-01 18:37]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 21:58]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-01 11:26:07
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwClose
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-03-01 11:27:02
ComboFix-quarantined-files.txt 2008-03-01 10:26:59
.
2008-02-27 21:54:33 --- E O F ---
