ci-dessous le report de fixwareout
Username "Propri‚taire" - 01/05/2008 19:15:43 [Fixwareout edited 9/01/2007]
~~~~~ Prerun check
Cache de résolution DNS vidé.
System was rebooted successfully.
~~~~~ Postrun check
....
....
~~~~~ Misc files.
....
~~~~~ Checking for older varients.
....
Il ne s'est pas affiché à la fin du fix, il a fallu que j'aille le chercher dans les fichiers créés *.txt j'espére que c'est le bon
ci-dessous le report de combofix :
ComboFix 08-04-29.5 - Propriétaire 2008-05-01 18:51:45.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.1.1252.1.1036.18.218 [GMT 2:00]
Endroit: C:\autrenom.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
.
((((((((((((((((((((((((((((( Fichiers créés 2008-04-01 to 2008-05-01 ))))))))))))))))))))))))))))))))))))
.
2008-05-01 18:29 . 2008-05-01 18:29 1,780,380 --a------ C:\autrenom.exe
2008-05-01 18:25 . 2008-05-01 18:25 <REP> d-------- C:\Program Files\Trend Micro
2008-05-01 18:24 . 2008-04-19 21:16 812,344 --a------ C:\Futurpapa.exe
2008-05-01 18:16 . 2008-05-01 18:16 23 --a------ C:\hosts
2008-05-01 18:11 . 2008-05-01 18:12 <REP> d-------- C:\fixwareout
2008-05-01 18:11 . 2008-04-24 20:34 486,449 --a------ C:\Fixwareout.exe
2008-04-29 22:53 . 2008-04-29 22:53 <REP> d---s---- C:\Documents and Settings\Propriétaire\UserData
2008-04-29 22:53 . 2008-04-29 22:53 <REP> d---s---- C:\Documents and Settings\Propriétaire\UserData
2008-04-29 22:46 . 2002-08-29 12:23 57,728 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2008-04-29 22:46 . 2001-08-17 22:59 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2008-04-29 22:45 . 2001-08-23 18:47 70,144 --a------ C:\WINDOWS\system32\usbui.dll
2008-04-29 22:45 . 2001-08-17 21:12 31,232 --a------ C:\WINDOWS\system32\drivers\sisnic.sys
2008-04-29 22:45 . 2001-08-17 22:57 14,080 --a------ C:\WINDOWS\system32\drivers\battc.sys
2008-04-29 22:45 . 2002-08-29 02:09 13,184 --a------ C:\WINDOWS\system32\drivers\CmBatt.sys
2008-04-29 22:45 . 2001-08-17 22:58 9,344 --a------ C:\WINDOWS\system32\drivers\compbatt.sys
2008-04-29 22:43 . 2008-05-01 18:50 <REP> d-------- C:\WINDOWS\system32\CatRoot2
2008-04-29 22:43 . 2008-04-29 22:43 <REP> d--h----- C:\Documents and Settings\Default User\Voisinage réseau
2008-04-29 22:43 . 2008-04-29 22:43 <REP> d--h----- C:\Documents and Settings\Default User\Voisinage d'impression
2008-04-29 22:43 . 2008-04-29 21:49 <REP> d--h----- C:\Documents and Settings\Default User\Modèles
2008-04-29 22:43 . 2008-04-29 22:43 <REP> d-------- C:\Documents and Settings\Default User\Mes documents
2008-04-29 22:43 . 2008-04-29 22:43 <REP> dr------- C:\Documents and Settings\Default User\Menu Démarrer
2008-04-29 22:43 . 2008-04-29 22:43 <REP> d-------- C:\Documents and Settings\Default User\Favoris
2008-04-29 22:43 . 2008-04-29 22:43 <REP> d-------- C:\Documents and Settings\Default User\Bureau
2008-04-29 22:43 . 2008-04-29 22:43 <REP> d--h----- C:\Documents and Settings\All Users\Modèles
2008-04-29 22:43 . 2008-04-29 21:55 <REP> dr------- C:\Documents and Settings\All Users\Menu Démarrer
2008-04-29 22:43 . 2008-04-29 22:43 <REP> d-------- C:\Documents and Settings\All Users\Favoris
2008-04-29 22:43 . 2008-04-29 21:50 <REP> dr------- C:\Documents and Settings\All Users\Documents
2008-04-29 22:43 . 2008-04-29 22:50 <REP> d-------- C:\Documents and Settings\All Users\Bureau
2008-04-29 22:37 . 2008-04-29 22:37 <REP> d-------- C:\Program Files\USB Driver-Express
2008-04-29 22:37 . 2004-07-14 18:52 31,547 --a------ C:\WINDOWS\system32\usbiad.sys
2008-04-29 22:37 . 2004-07-14 18:52 31,547 --a------ C:\WINDOWS\system32\drivers\usbiad.sys
2008-04-29 22:31 . 2008-04-29 22:37 <REP> d--h----- C:\Program Files\InstallShield Installation Information
2008-04-29 22:31 . 1997-03-05 09:53 48,128 --a------ C:\WINDOWS\system32\SMMSCRPT.DLL
2008-04-29 22:31 . 1996-10-15 09:40 9,728 --a------ C:\WINDOWS\system32\RNAPH.DLL
2008-04-29 22:30 . 2008-04-29 22:50 <REP> d-------- C:\Program Files\Fichiers communs\InstallShield
2008-04-29 22:23 . 2008-04-29 22:24 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-29 22:23 . 2008-04-29 22:33 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-29 22:20 . 2008-05-01 13:24 <REP> d-------- C:\Documents and Settings\Propriétaire\Application Data\AVG7
2008-04-29 22:20 . 2008-04-29 22:20 <REP> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-04-29 22:20 . 2008-04-29 22:20 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-04-29 22:20 . 2008-04-29 22:20 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2008-04-29 22:18 . 2008-04-29 22:18 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-04-29 22:18 . 2008-04-29 23:02 <REP> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-04-29 22:11 . 2008-04-29 22:11 <REP> d-------- C:\Program Files\Avira
2008-04-29 22:11 . 2008-04-29 22:11 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-04-29 22:06 . 2008-04-29 22:06 <REP> d---s---- C:\WINDOWS\system32\Microsoft
2008-04-29 22:03 . 2008-04-29 22:03 <REP> d-------- C:\Program Files\Tall Emu
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-01 16:16 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\OnlineArmor
2008-04-29 21:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\OnlineArmor
2008-04-29 19:53 --------- d-----w C:\Program Files\microsoft frontpage
2008-04-29 19:52 --------- d-----w C:\Program Files\Services en ligne
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-29 22:56 262401]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-04-29 23:02 579584]
"OnlineArmor GUI"="C:\Program Files\Tall Emu\Online Armor\oaui.exe" [2008-02-25 09:46 5497920]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2003-04-24 14:00 13312]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-04-29 22:18 219136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
--a------ 2003-04-24 14:00 13312 C:\WINDOWS\System32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-01-28 11:43 2097488 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
R0 avgntmgr;avgntmgr;C:\WINDOWS\System32\DRIVERS\avgntmgr.sys [2008-04-29 22:56]
R1 avgntdd;avgntdd;C:\WINDOWS\System32\DRIVERS\avgntdd.sys [2008-04-29 22:56]
R1 OADevice;OADriver;C:\WINDOWS\system32\drivers\OADriver.sys [2008-02-23 05:45]
R1 OAmon;OAmon;C:\WINDOWS\system32\drivers\OAmon.sys [2008-02-23 05:45]
R1 OAnet;OAnet;C:\WINDOWS\system32\drivers\OAnet.sys [2007-12-26 05:14]
R3 PALLADIA;Palladia 300/400 Usb Adsl Modem;C:\WINDOWS\System32\DRIVERS\usbiad.sys [2004-07-14 18:52]
S2 SvcOnlineArmor;Online Armor;"C:\Program Files\Tall Emu\Online Armor\oasrv.exe" [2008-02-25 09:46]
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-01 18:52:35
Windows 5.1.2600 Service Pack 1 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\C:\WINDOWS\TEMP\mc21.tmp"
.
Temps d'accomplissement: 2008-05-01 18:53:06
ComboFix-quarantined-files.txt 2008-05-01 16:53:04
Pre-Run: 15,860,252,672 octets libres
Post-Run: 15,862,206,464 octets libres
105 --- E O F --- 2008-04-29 21:32:24
et ci-dessous le post de hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:26:13, on 01/05/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Tall Emu\Online Armor\oasrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Tall Emu\Online Armor\oaui.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [OnlineArmor GUI] "C:\Program Files\Tall Emu\Online Armor\oaui.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/...
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Online Armor (SvcOnlineArmor) - Unknown owner - C:\Program Files\Tall Emu\Online Armor\oasrv.exe
ci-dessous le rapport de Hijackthis
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:18:22, on 19/04/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\SB.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\ftp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\ftp.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\System32\msiexec.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\ftp.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SB] C:\WINDOWS\System32\SB.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe