Une nuit de sommeil plus tard voici le log de Combofix =>
ComboFix 08-10-02.04 - Guillaume 2008-10-03 18:02:28.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.210 [GMT 2:00]
Lancé depuis: C:\Documents and Settings\Guillaume\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
* Resident AV is active
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Guillaume\Cookies\guillaume@edt02[1].txt
C:\WINDOWS\Downloaded Program Files\setup.inf
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-03 au 2008-10-03 ))))))))))))))))))))))))))))))))))))
.
2008-10-02 23:18 . 2008-10-02 23:18 <REP> d-------- C:\Documents and Settings\Guillaume\Application Data\Malwarebytes
2008-10-02 23:18 . 2008-10-02 23:18 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-02 23:18 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-02 23:18 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-02 22:46 . 2008-10-03 00:05 2,136 --a------ C:\Documents and Settings\Orph.egd
2008-10-02 22:41 . 2008-10-03 00:06 <REP> d-------- C:\ToolBar SD
2008-09-30 23:37 . 2008-09-30 23:37 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-09-30 23:37 . 2008-09-30 23:37 1,409 --a------ C:\WINDOWS\QTFont.for
2008-09-29 21:35 . 2008-09-29 21:35 <REP> d-------- C:\Program Files\Google
2008-09-16 10:46 . 2008-09-16 10:46 <REP> d-------- C:\WINDOWS\system32\fr
2008-09-16 10:46 . 2008-09-16 10:46 <REP> d-------- C:\WINDOWS\system32\bits
2008-09-16 10:46 . 2008-09-16 10:46 <REP> d-------- C:\WINDOWS\l2schemas
2008-09-16 10:16 . 2008-04-14 04:33 712,704 --------- C:\WINDOWS\system32\windowscodecs.dll
2008-09-16 10:16 . 2008-04-14 04:33 346,112 --------- C:\WINDOWS\system32\windowscodecsext.dll
2008-09-16 10:16 . 2008-04-14 04:33 276,992 --------- C:\WINDOWS\system32\wmphoto.dll
2008-09-16 10:16 . 2008-04-14 04:33 69,120 --------- C:\WINDOWS\system32\wlanapi.dll
2008-09-16 10:14 . 2008-04-14 04:33 651,264 --------- C:\WINDOWS\system32\dot3ui.dll
2008-09-16 10:13 . 2008-04-14 04:33 233,472 --------- C:\WINDOWS\system32\azroles.dll
2008-09-16 10:13 . 2008-04-14 04:33 136,192 --------- C:\WINDOWS\system32\aaclient.dll
2008-09-16 10:13 . 2008-04-14 04:33 7,168 --------- C:\WINDOWS\system32\bitsprx4.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-02 21:07 2,128 ----a-w C:\WINDOWS\system32\tmp.reg
2008-10-02 19:57 --------- d-----w C:\Documents and Settings\Guillaume\Application Data\uTorrent
2008-10-01 13:51 87,552 ----a-w C:\WINDOWS\system32\VACFix.exe
2008-09-19 10:26 82,944 ----a-w C:\WINDOWS\system32\o4Patch.exe
2008-09-19 10:26 82,944 ----a-w C:\WINDOWS\system32\IEDFix.C.exe
2008-09-08 21:38 88,576 ----a-w C:\WINDOWS\system32\AntiXPVSTFix.exe
2008-08-31 14:00 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-30 20:57 44,440 ----a-w C:\WINDOWS\system32\MtpAccess.dll
2008-08-30 20:57 102,400 ----a-w C:\WINDOWS\system32\ProgHelp.dll
2008-08-30 20:57 1,060,864 ----a-w C:\WINDOWS\system32\mfc71.dll
2008-08-30 20:20 --------- d-----w C:\Program Files\Samsung
2008-08-26 17:25 --------- d-----w C:\Program Files\GSpot
2008-08-18 10:19 82,432 ----a-w C:\WINDOWS\system32\404Fix.exe
2008-08-17 19:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\TVU Networks
2008-08-14 19:48 --------- d-----w C:\Documents and Settings\Guillaume\Application Data\vlc
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:28 253,952 ----a-w C:\WINDOWS\system32\es.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2004-02-24 401491]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-06-21 921600]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 C:\WINDOWS\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= vdrcodec.dll
"MSACM.CEGSM"= mobilev.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiHacker]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Utilitaires\\adslTV\\adsltv.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"C:\\Utilitaires\\eMule\\emule.exe"=
"C:\\Utilitaires\\uTorrent\\utorrent.exe"=
"C:\\Utilitaires\\SopCast\\SopCast.exe"=
"C:\\Utilitaires\\adslTV\\vlc.exe"=
"C:\\Documents and Settings\\Guillaume\\Application Data\\SopCast\\adv\\SopAdver.exe"=
"C:\\Utilitaires\\PPMate\\PPMate\\ppmate.exe"=
"C:\\Utilitaires\\PPMate\\ppmate.exe"=
"C:\\Poker\\SunPoker.com\\UA.exe"=
"C:\\Utilitaires\\TVAnts\\Tvants.exe"=
"C:\\Utilitaires\\PPMate\\ppamnet.exe"=
"C:\\Utilitaires\\Freeplayer\\vlc\\vlc.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\WcesMgr.exe"=
"C:\\Utilitaires\\Mozilla Firefox\\firefox.exe"=
"C:\\Utilitaires\\FileZilla\\FileZilla.exe"=
"C:\\Utilitaires\\iTunes\\iTunes.exe"=
"C:\\Utilitaires\\SopCast\\adv\\SopAdver.exe"=
"C:\\Utilitaires\\HomePlayer1.5.3.1\\HomePlayer.exe"=
"C:\\Utilitaires\\TVUPlayer\\TVUPlayer.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R0 Klpf;Klpf;C:\WINDOWS\system32\drivers\Klpf.sys [2006-05-11 28979]
R0 Klpid;Klpid;C:\WINDOWS\system32\drivers\Klpid.sys [2006-05-11 36534]
R0 SI3112r;Silicon Image SiI 3112 SATARaid Controller;C:\WINDOWS\system32\DRIVERS\SI3112r.sys [2006-01-12 102528]
R0 VOBID;VOBID;C:\WINDOWS\system32\DRIVERS\vobid.sys [2003-08-01 29239]
R1 vobiw;vobiw;C:\WINDOWS\system32\drivers\vobiw.sys [2004-09-01 188416]
R2 BT848;WinFast TV2000 XP WDM Video Capture;C:\WINDOWS\system32\drivers\wf2kvcap.sys [2004-07-22 75925]
R2 tv2ktunr;WinFast TV2000 XP WDM TVTuner;C:\WINDOWS\system32\drivers\wf2ktunr.sys [2004-07-22 36583]
R2 Tv2kXbar;WinFast TV2000 XP WDM Crossbar;C:\WINDOWS\system32\drivers\wf2kxbar.sys [2004-07-22 10005]
R3 cdrdrv;Cdrdrv;C:\WINDOWS\system32\Drivers\Cdrdrv.sys [2004-08-03 62976]
S3 WFIOCTL;WFIOCTL;C:\Program Files\WinFast\WFTVFM\WFIOCTL.SYS [2003-09-10 9510]
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Tâches planifiées'
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{11DFB01A-0852-4955-9747-C59E21DBBDA5} - C:\WINDOWS\dfmlxbpkvlo.dll
Notify-WgaLogon - (no file)
.
------- Examen supplémentaire -------
.
FireFox -: Profile - C:\Documents and Settings\Guillaume\Application Data\Mozilla\Firefox\Profiles\a7kdd2iv.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.accroprono.com/
FF -: plugin - C:\Documents and Settings\Guillaume\Application Data\Mozilla\Firefox\Profiles\a7kdd2iv.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF -: plugin - C:\Utilitaires\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - C:\Utilitaires\DivX\DivX Web Player\npdivx32.dll
FF -: plugin - C:\Utilitaires\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\Utilitaires\Mozilla Firefox\plugins\np-mswmp.dll
FF -: plugin - C:\Utilitaires\Mozilla Firefox\plugins\np32dsw.dll
FF -: plugin - C:\Utilitaires\Mozilla Firefox\plugins\npdivx32.dll
FF -: plugin - C:\Utilitaires\Mozilla Firefox\plugins\npdolctl.dll
FF -: plugin - C:\Utilitaires\Mozilla Firefox\plugins\npnul32.dll
FF -: plugin - C:\Utilitaires\Mozilla Firefox\plugins\NPOFFICE.DLL
FF -: plugin - C:\Utilitaires\Mozilla Firefox\plugins\nppdf32.dll
FF -: plugin - C:\Utilitaires\Mozilla Firefox\plugins\npqtplugin.dll
FF -: plugin - C:\Utilitaires\Mozilla Firefox\plugins\npqtplugin2.dll
FF -: plugin - C:\Utilitaires\Mozilla Firefox\plugins\npqtplugin3.dll
FF -: plugin - C:\Utilitaires\Mozilla Firefox\plugins\npqtplugin4.dll
FF -: plugin - C:\Utilitaires\Mozilla Firefox\plugins\npqtplugin5.dll
FF -: plugin - C:\Utilitaires\Mozilla Firefox\plugins\npqtplugin6.dll
FF -: plugin - C:\Utilitaires\Mozilla Firefox\plugins\npqtplugin7.dll
FF -: plugin - C:\Utilitaires\Picasa2\npPicasa2.dll
FF -: plugin - C:\Utilitaires\QuickTime\Plugins\npqtplugin.dll
FF -: plugin - C:\Utilitaires\QuickTime\Plugins\npqtplugin2.dll
FF -: plugin - C:\Utilitaires\QuickTime\Plugins\npqtplugin3.dll
FF -: plugin - C:\Utilitaires\QuickTime\Plugins\npqtplugin4.dll
FF -: plugin - C:\Utilitaires\QuickTime\Plugins\npqtplugin5.dll
FF -: plugin - C:\Utilitaires\QuickTime\Plugins\npqtplugin6.dll
FF -: plugin - C:\Utilitaires\QuickTime\Plugins\npqtplugin7.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-03 18:05:36
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
PROCESSUS: C:\WINDOWS\system32\lsass.exe
-> C:\Program Files\Eset\pr_imon.dll
.
Heure de fin: 2008-10-03 18:07:08
ComboFix-quarantined-files.txt 2008-10-03 16:07:04
Avant-CF: 7ÿ538ÿ008ÿ064 octets libres
Après-CF: 7,719,395,328 octets libres
182 --- E O F --- 2008-09-16 13:39:37