MERCI pour le coup de main !!
Malheureusement combofix à redémarré windows et du coup par la même occasion mes protections résidente
qui ont bloqué l'écriture du fichier TXT ...
il y avait au moins 10 fichiers de supprimés ( 2 exe dans windows et des dll dans windows/system .. )
j'en ai donc refais un deuxième ..
ComboFix 08-09-05.09 - Administrateur 2008-09-08 21:39:32.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.680 [GMT 2:00]
Endroit: C:\Documents and Settings\Administrateur\Bureau\ComboFix.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\Documents and Settings\Administrateur\Application Data\Adobe\crc.dat
C:\Documents and Settings\Administrateur\Application Data\Adobe\Manager.exe
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\install\install.exe
C:\WINDOWS\21.6426.exe
C:\WINDOWS\eqrn.exe
C:\WINDOWS\esab.exe
C:\WINDOWS\system32\cKmUCfhk.ini
C:\WINDOWS\system32\cKmUCfhk.ini2
C:\WINDOWS\system32\fgyafngs.ini
C:\WINDOWS\system32\lngiabsv.dll
C:\WINDOWS\system32\mx84866.dll
C:\WINDOWS\system32\myioss.dll
C:\WINDOWS\system32\pxxeejap.dll
C:\WINDOWS\system32\qvajjynb.dll
C:\WINDOWS\system32\rtl60.bpl
C:\WINDOWS\system32\vsbaignl.ini
C:\WINDOWS\system32\WGjRsvut.ini
C:\WINDOWS\system32\WGjRsvut.ini2
C:\WINDOWS\system32\wsadaq.dll
F:\RECYCLER\mxfilerelatedcache.mxc2
.
((((((((((((((((((((((((((((( Fichiers créés 2008-08-08 to 2008-09-08 ))))))))))))))))))))))))))))))))))))
.
2008-09-08 20:33 . 2008-09-08 20:33 <REP> d-------- C:\VundoFix Backups
2008-09-08 20:22 . 2008-09-08 20:24 <REP> d-------- C:\Program Files\Navilog1
2008-09-08 19:37 . 2008-09-08 19:43 <REP> d-------- C:\Program Files\Spyware Terminator
2008-09-08 19:37 . 2008-09-08 19:37 <REP> d-------- C:\Program Files\Crawler
2008-09-08 19:37 . 2008-09-08 19:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-09-08 19:37 . 2008-09-08 19:43 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Spyware Terminator
2008-09-08 19:37 . 2008-09-08 19:37 141,312 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-09-08 19:36 . 2008-09-08 20:09 <REP> d-------- C:\Program Files\MSA
2008-09-08 18:59 . 2008-09-08 18:59 <REP> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-09-08 18:58 . 2008-09-08 18:58 <REP> d-------- C:\Program Files\SUPERAntiSpyware
2008-09-08 18:58 . 2008-09-08 18:58 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\SUPERAntiSpyware.com
2008-09-08 17:07 . 2008-09-08 17:32 31,232 --a------ C:\x
2008-09-08 13:40 . 2008-09-08 18:54 139,264 --a------ C:\WINDOWS\mqgldfvo.exe
2008-09-07 11:31 . 2008-09-08 00:46 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-09-07 11:31 . 2008-09-07 11:31 1,409 --a------ C:\WINDOWS\QTFont.for
2008-08-31 20:39 . 2008-09-03 12:25 <REP> d-------- C:\Program Files\CSV2ASC
2008-08-27 18:41 . 2008-08-27 18:56 <REP> d-------- C:\AVIA_TEST_DVD
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-08 19:04 --------- d-----w C:\Program Files\Hijackthis Version Française
2008-09-08 16:58 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-09-08 13:05 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\uTorrent
2008-09-04 16:54 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\skypePM
2008-09-04 16:54 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Skype
2008-08-31 19:44 --------- d-----w C:\Program Files\Mio DigiWalker
2008-08-27 16:16 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Ahead
2008-08-25 16:28 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\U3
2008-08-07 18:14 --------- d-----w C:\Program Files\DivX
2008-08-03 20:11 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-08-03 20:10 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\AdobeUM
2008-08-02 08:55 --------- d-----w C:\Program Files\Java
2008-07-25 08:36 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2008-07-23 16:50 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-07-23 16:48 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2008-07-23 16:48 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2008-07-23 16:46 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2008-07-22 18:15 --------- d-----w C:\Program Files\Mio Technology
2008-07-13 15:47 --------- d-----w C:\Program Files\Lavasoft
2008-07-13 15:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-13 15:36 --------- d-----w C:\Program Files\HTV
2006-07-29 12:42 73,728 ---ha-w C:\Documents and Settings\Administrateur\Application Data\RBRegEx350.dll
2006-07-29 12:42 64,512 ---ha-w C:\Documents and Settings\Administrateur\Application Data\rbap450.dll
.
------- Sigcheck -------
2005-05-25 21:07 359936 63fdfea54eb53de2d863ee454937ce1e C:\WINDOWS\$hf_mig$\KB893066\SP2QFE\tcpip.sys
2004-08-18 11:22 359040 27a5959c94ee173a063ca06bd14f021a C:\WINDOWS\$NtUninstallKB893066$\tcpip.sys
2006-04-02 17:32 359808 e68b798389848699012723b3f1a79e25 C:\WINDOWS\system32\drivers\TCPIP.SYS
2004-08-23 00:35 1036288 998f3f568f6074a35ab08cd3395a9dc2 C:\WINDOWS\explorer.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ba87e218-93dd-48d7-87d8-1a40c2361aa3}]
C:\WINDOWS\system32\myioss.dll [BU]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2005-01-04 1937408]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-09-03 1576176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-01 7618560]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-17 49152]
"ALDI_FotoSuite_Download"="C:\Program Files\ALDI Service Photo\ALDI_Service_Photo\FotoSuite.exe" [2007-07-04 1171456]
"WinSys2"="C:\WINDOWS\system32\winsys2.exe" [2006-10-03 217088]
"8cee4822"="C:\WINDOWS\system32\lngiabsv.dll" [BU]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-09-08 1783808]
"nwiz"="nwiz.exe" [2006-06-01 C:\WINDOWS\system32\nwiz.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-09-22 C:\WINDOWS\soundman.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 C:\WINDOWS\AGRSMMSG.exe]
"NvMediaCenter"="NvMCTray.dll" [2006-06-01 C:\WINDOWS\system32\nvmctray.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [BU]
C:\Documents and Settings\Administrateur\Menu D‚marrer\Programmes\D‚marrage\
ashDisp.lnk - C:\Program Files\Alwil Software\Avast4\ashDisp.exe [2005-10-29 78008]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 16:28 352256 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wsadaq.dll myioss.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.CEGSM"= mobilev.acm
"VIDC.ACDV"= ACDV.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\LeechFTP\\Leechftp.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Visicom Media\\FTP Expert 3\\ftpxpert3.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\HP\\HP Software Update\\HPWUCli.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\SpeedCams_Serveur\\SpeedCams_Serveur.exe"=
"C:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6346:TCP"= 6346:TCP:shareaza
"6346:UDP"= 6346:UDP:shaeazaudp
R0 viasraid;viasraid;C:\WINDOWS\system32\DRIVERS\viasraid.sys [2003-10-31 77312]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\WINDOWS\system32\drivers\sp_rsdrv2.sys [2008-09-08 141312]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
S3 3xHybrid;Pinnacle PCTV Stereo service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2003-12-05 556416]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;C:\Program Files\ALDI Service Photo\Common\Database\bin\fbserver.exe [2005-11-17 1527900]
S3 M2400;IEEE 802.11b Wireless Network Driver;C:\WINDOWS\system32\DRIVERS\M2400.sys [2003-10-13 51328]
S3 SetupNTGLM7X;SetupNTGLM7X;I:\NTGLM7X.sys [ ]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\6ru3ry1k.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.orange.fr/
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-08 21:40:29
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-09-08 21:40:52
ComboFix-quarantined-files.txt 2008-09-08 19:40:51
Pre-Run: 124,069,953,536 octets libres
Post-Run: 124,059,557,888 octets libres
174