Bon jusqu'ici j'ai tout allait comme sur des roulettes jusqu'à se que combofix finisse son scan, mais je ne sai pas pourquoi mon antivirus(avast pro) n'arrive pas à activer la protection résidente j'ai lancer un scan pour vir ce que ça va donner ou bien je m'y prends mal, en attendant voici le rapport après scan de combofix :
ComboFix 08-11-05.02 - CHERIF_HUGUES 2008-11-06 14:43:30.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.123 [GMT 1:00]
Lancé depuis: c:\documents and settings\CHERIF_HUGUES\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/B/COLOR
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\CHERIF~1\LOCALS~1\Temp\E_4
c:\docume~1\CHERIF~1\LOCALS~1\Temp\E_4\com.run
c:\docume~1\CHERIF~1\LOCALS~1\Temp\E_4\dp1.fne
c:\docume~1\CHERIF~1\LOCALS~1\Temp\E_4\eAPI.fne
c:\docume~1\CHERIF~1\LOCALS~1\Temp\E_4\internet.fne
c:\docume~1\CHERIF~1\LOCALS~1\Temp\E_4\krnln.fnr
c:\docume~1\CHERIF~1\LOCALS~1\Temp\E_4\RegEx.fnr
c:\docume~1\CHERIF~1\LOCALS~1\Temp\E_4\shell.fne
c:\docume~1\CHERIF~1\LOCALS~1\Temp\E_4\spec.fne
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\nq0cq.cmd
c:\windows\system32\biktumxc.ini
c:\windows\system32\com.run
c:\windows\system32\cxmutkib.dll
c:\windows\system32\dp1.fne
c:\windows\system32\eAPI.fne
c:\windows\system32\hkSAKRqr.ini
c:\windows\system32\hkSAKRqr.ini2
c:\windows\system32\internet.fne
c:\windows\system32\krnln.fnr
c:\windows\system32\mudqgchl.ini
c:\windows\system32\og.dll
c:\windows\system32\og.edt
c:\windows\system32\RegEx.fnr
c:\windows\system32\rqRKASkh.dll
c:\windows\system32\shell.fne
c:\windows\system32\spec.fne
c:\windows\system32\ul.dll
E:\cqdis.cmd
E:\nq0cq.cmd
----- BITS: Il y a peut-être des sites infectés -----
hxxp://www.securityenchancement.com
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-06 au 2008-11-06 ))))))))))))))))))))))))))))))))))))
.
2008-11-02 21:03 . 2008-11-02 21:03 <REP> d-------- c:\program files\Free Audio Pack
2008-11-02 20:48 . 2008-11-02 20:48 <REP> d-------- c:\documents and settings\CHERIF_HUGUES\Application Data\TuneUp Software
2008-11-02 20:48 . 2008-11-02 20:48 354,560 --a------ c:\windows\system32\TuneUpDefragService.exe
2008-11-02 20:48 . 2008-04-04 14:51 28,416 --a------ c:\windows\system32\uxtuneup.dll
2008-11-02 20:46 . 2008-11-02 20:48 <REP> d-------- c:\program files\TuneUp Utilities 2008
2008-11-02 20:46 . 2008-11-02 20:46 <REP> d-------- c:\documents and settings\All Users\Application Data\TuneUp Software
2008-11-02 20:44 . 2008-11-02 20:44 <REP> d-------- c:\program files\Fichiers communs\Wise Installation Wizard
2008-11-02 15:40 . 2002-11-06 17:49 <REP> d-------- c:\program files\A4Proxy
2008-11-02 11:17 . 2008-11-02 11:17 <REP> d-------- C:\740bd83450f134a56e2a8b1325
2008-11-01 09:07 . 2008-11-01 09:07 <REP> d-------- c:\documents and settings\CHERIF_HUGUES\Application Data\Yahoo!
2008-11-01 09:07 . 2008-11-01 09:07 <REP> d-------- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2008-11-01 08:54 . 2008-11-01 08:59 <REP> d-------- c:\program files\Yahoo!
2008-11-01 08:54 . 2008-11-01 09:00 <REP> d-------- c:\documents and settings\All Users\Application Data\Yahoo!
2008-10-31 17:53 . 2008-11-06 14:52 <REP> d-------- c:\windows\system32\CatRoot_bak
2008-10-31 16:15 . 2008-10-31 16:15 <REP> d-------- c:\documents and settings\CHERIF_HUGUES\Application Data\AdobeUM
2008-10-31 16:11 . 2008-08-14 14:39 2,188,032 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-10-31 16:11 . 2008-08-14 14:39 2,144,768 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-10-31 16:11 . 2008-08-14 14:39 2,065,024 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-31 16:11 . 2008-08-14 14:39 2,022,912 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-10-31 12:27 . 2008-06-14 18:59 272,768 --------- c:\windows\system32\drivers\bthport.sys
2008-10-31 12:27 . 2008-06-14 18:59 272,768 -----c--- c:\windows\system32\dllcache\bthport.sys
2008-10-31 11:08 . 2005-02-25 04:35 22,752 --a------ c:\windows\system32\spupdsvc.exe
2008-10-31 09:23 . 2002-11-07 09:51 69 --a------ c:\windows\NeroDigital.ini
2008-10-28 18:39 . 2008-10-28 18:39 <REP> d-------- c:\documents and settings\CHERIF_HUGUES\Application Data\Anonymizer
2008-10-28 18:38 . 2008-10-28 18:38 <REP> d-------- c:\documents and settings\All Users\Application Data\Anonymizer
2008-10-28 17:38 . 2002-11-06 21:59 <REP> d-------- C:\Downloads
2008-10-28 17:22 . 2002-11-07 14:22 <REP> d-------- c:\documents and settings\CHERIF_HUGUES\Application Data\Free Download Manager
2008-10-28 17:21 . 2008-10-28 17:22 <REP> d-------- c:\program files\Free Download Manager
2008-10-28 17:21 . 2008-10-28 17:21 <REP> d-------- c:\documents and settings\All Users\Application Data\FreeDownloadManager.ORG
2008-10-28 16:12 . 2008-10-28 16:43 <REP> d-------- c:\program files\Google
2008-10-28 11:52 . 2008-11-01 10:01 <REP> d-------- c:\documents and settings\CHERIF_HUGUES\Application Data\dvdcss
2008-10-28 10:51 . 2008-10-28 11:16 <REP> d-------- c:\documents and settings\CHERIF_HUGUES\Application Data\uTorrent
2008-10-28 09:45 . 2004-09-13 13:17 2,146,304 --------- c:\windows\UNNMP.exe
2008-10-28 09:45 . 2004-09-29 09:18 52,536 --------- c:\windows\UNNMP.cfg
2008-10-28 09:39 . 2001-07-09 11:50 155,648 --a------ c:\windows\system32\NeroCheck.exe
2008-10-28 09:36 . 2004-07-26 18:09 2,023,424 --------- c:\windows\UNNeroVision.exe
2008-10-28 09:36 . 2004-09-29 09:18 110,833 --------- c:\windows\UNNeroVision.cfg
2008-10-28 09:36 . 2001-03-08 19:30 24,064 --------- c:\windows\system32\msxml3a.dll
2008-10-28 09:35 . 2008-10-28 09:38 <REP> d-------- c:\program files\Fichiers communs\Ahead
2008-10-28 09:35 . 2008-10-28 09:45 <REP> d-------- c:\program files\Ahead
2008-10-28 09:35 . 2008-10-28 09:35 <REP> d-------- c:\documents and settings\All Users\Application Data\Ahead
2008-10-28 09:35 . 2004-07-20 17:24 1,568,768 --------- c:\windows\system32\ImagX7.dll
2008-10-28 09:35 . 2004-07-20 17:24 476,320 --------- c:\windows\system32\ImagXpr7.dll
2008-10-28 09:35 . 2004-07-20 17:24 471,040 --------- c:\windows\system32\ImagXRA7.dll
2008-10-28 09:35 . 2004-07-09 09:43 364,544 --------- c:\windows\system32\TwnLib4.dll
2008-10-28 09:35 . 2004-07-20 17:24 262,144 --------- c:\windows\system32\ImagXR7.dll
2008-10-28 09:35 . 2000-06-26 11:45 106,496 --a------ c:\windows\system32\TwnLib20.dll
2008-10-28 09:35 . 2001-06-26 08:15 38,912 --------- c:\windows\system32\picn20.dll
2008-10-27 21:11 . 2008-10-27 21:11 <REP> d-------- c:\program files\ZikiTranslator
2008-10-27 12:25 . 2008-10-27 12:25 <REP> d-------- c:\documents and settings\All Users\Application Data\WEBREG
2008-10-27 12:23 . 2008-10-27 12:23 <REP> d-------- c:\documents and settings\All Users\Application Data\Hewlett-Packard
2008-10-27 12:23 . 2007-03-30 16:11 267,864 -ra------ c:\windows\system32\hpzids01.dll
2008-10-27 12:23 . 2007-03-28 14:01 117,760 --a------ c:\windows\system32\hpzll5ha.dll
2008-10-27 11:40 . 2008-10-27 11:40 <REP> d-------- c:\documents and settings\CHERIF_HUGUES\Application Data\HPAppData
2008-10-27 11:37 . 2008-10-27 11:37 <REP> d-------- c:\documents and settings\All Users\Application Data\HP Product Assistant
2008-10-27 11:37 . 2008-10-27 11:40 <REP> d-------- c:\documents and settings\All Users\Application Data\HP
2008-10-27 11:35 . 2008-10-27 11:35 <REP> d-------- c:\program files\Fichiers communs\HP
2008-10-27 11:33 . 2008-10-28 16:44 <REP> d-------- c:\program files\HP
2008-10-27 11:33 . 2004-08-03 23:08 31,616 --a------ c:\windows\system32\drivers\usbccgp.sys
2008-10-27 11:33 . 2004-08-03 23:08 31,616 --a--c--- c:\windows\system32\dllcache\usbccgp.sys
2008-10-27 11:31 . 2008-10-27 12:25 156,056 --a------ c:\windows\HPHins15.dat
2008-10-27 11:31 . 2007-08-28 07:45 2,828 --------- c:\windows\hphmdl15.dat
2008-10-27 11:29 . 2004-08-03 23:01 25,856 --a------ c:\windows\system32\drivers\usbprint.sys
2008-10-27 11:29 . 2004-08-03 23:01 25,856 --a--c--- c:\windows\system32\dllcache\usbprint.sys
2008-10-26 22:39 . 2008-11-01 08:47 <REP> d-------- c:\documents and settings\CHERIF_HUGUES\Application Data\vlc
2008-10-26 22:35 . 2008-10-26 22:35 <REP> d-------- c:\program files\VideoLAN
2008-10-26 22:25 . 2008-10-26 22:25 <REP> d-------- c:\program files\MSBuild
2008-10-26 22:25 . 2008-10-26 22:25 <REP> d-------- c:\program files\Microsoft Works
2008-10-26 22:23 . 2008-10-26 22:23 <REP> d-------- c:\program files\Microsoft.NET
2008-10-26 22:19 . 2008-10-26 22:19 <REP> d-------- c:\program files\Microsoft Visual Studio 8
2008-10-26 22:14 . 2008-10-26 22:24 <REP> d-------- c:\windows\SHELLNEW
2008-10-26 22:11 . 2008-10-26 22:11 <REP> dr-h----- C:\MSOCache
2008-10-26 21:25 . 2008-10-26 22:28 <REP> d-------- c:\documents and settings\All Users\Application Data\Microsoft Help
2008-10-25 19:01 . 2008-10-25 19:01 <REP> d-------- c:\program files\Fichiers communs\Adobe
2008-10-25 13:22 . 2008-10-25 13:22 <REP> d---s---- c:\documents and settings\CHERIF_HUGUES\UserData
2008-10-25 12:37 . 2008-10-25 12:37 <REP> d-------- c:\program files\SuperCopier2
2008-10-25 12:05 . 2008-10-25 12:05 <REP> d-------- c:\windows\system32\LogFiles
2008-10-25 11:27 . 2008-10-30 17:16 <REP> d-------- c:\documents and settings\CHERIF_HUGUES\Contacts
2008-10-25 11:14 . 2008-10-27 11:33 <REP> d----c--- c:\windows\system32\DRVSTORE
2008-10-25 11:13 . 2008-10-25 11:13 <REP> d-------- c:\program files\MSN Messenger
2008-10-25 07:22 . 2008-10-25 07:22 <REP> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-10-25 07:20 . 2004-08-03 22:08 26,496 --a--c--- c:\windows\system32\dllcache\usbstor.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-06 13:50 2,404 --sh--w c:\windows\system32\ul.dll
2008-10-24 22:49 --------- d-----w c:\program files\microsoft frontpage
2008-10-24 22:46 --------- d-----w c:\program files\Services en ligne
2008-09-24 19:33 484,352 ----a-w c:\windows\system32\lame_enc.dll
2008-09-15 15:39 1,846,144 ----a-w c:\windows\system32\win32k.sys
2008-08-20 05:37 663,552 ----a-w c:\windows\system32\wininet.dll
2008-08-20 05:37 617,984 ----a-w c:\windows\system32\sssurl.dll
2008-08-14 13:39 2,188,032 ----a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 13:39 2,065,024 ----a-w c:\windows\system32\ntkrnlpa.exe
2006-05-03 09:06 163,328 --sh--r c:\windows\system32\flvDX.dll
2007-02-21 10:47 31,232 --sh--r c:\windows\system32\msfDX.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3711EEB0-1851-42C2-9ABD-C29470A5035C}]
2002-11-07 11:32 34304 --a------ c:\windows\system32\jkkLcDuu.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-05 15360]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"SuperCopier2.exe"="c:\program files\SuperCopier2\SuperCopier2.exe" [2006-07-07 1052672]
"swg"="c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-10-28 171448]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-10-16 4347120]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-05 15360]
c:\documents and settings\CHERIF_HUGUES\Menu D‚marrer\Programmes\D‚marrage\
.lnk - c:\windows\system32\XP-F51F8CDD.EXE [2002-11-07 1501856]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]
Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{3711EEB0-1851-42C2-9ABD-C29470A5035C}"= "c:\windows\system32\jkkLcDuu.dll" [2002-11-07 34304]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkLcDuu]
2002-11-07 11:32 34304 c:\windows\system32\jkkLcDuu.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\WinRAR\\WinRAR.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Free Download Manager\\fdm.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\Polish\\setup.exe"=
"c:\\Program Files\\A4Proxy\\A4Proxy.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-03-29 75856]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-03-29 20560]
R2 UxTuneUp;TuneUp Extension de thème;c:\windows\System32\svchost.exe [2004-08-05 14336]
R3 ati2mtaa;ati2mtaa;c:\windows\system32\DRIVERS\ati2mtaa.sys [2004-08-04 327168]
R3 USBSTOR;Pilote de stockage de masse USB;c:\windows\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 AVPsys;AVPsys;c:\windows\system32\drivers\tdi.sys [2004-08-05 18560]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;c:\windows\System32\TuneUpDefragService.exe [2008-11-02 354560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{00e1a076-f093-11d6-9bd4-00065bac0528}]
\Shell\AutoRun\command - xih9.cmd
\Shell\explore\Command - xih9.cmd
\Shell\open\Command - xih9.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{30e7fc31-a978-11dd-9bcc-00065bac0528}]
\Shell\AutoRun\command - E:\yew.bat
\Shell\explore\Command - E:\yew.bat
\Shell\open\Command - E:\yew.bat
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{86391627-f1ae-11d6-9bd6-00065bac0528}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{86391628-f1ae-11d6-9bd6-00065bac0528}]
\Shell\AutoRun\command - F:\b.exe
\Shell\explore\Command - F:\b.exe
\Shell\open\Command - F:\b.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b9db7232-a4c9-11dd-9baa-00065bac0528}]
\Shell\AutoRun\command - E:\68.exe
\Shell\explore\Command - E:\68.exe
\Shell\open\Command - E:\68.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f9a5e853-f089-11d6-9bd2-00065bac0528}]
\Shell\AutoRun\command - E:\nq0cq.cmd
\Shell\explore\Command - E:\nq0cq.cmd
\Shell\open\Command - E:\nq0cq.cmd
.
Contenu du dossier 'Tâches planifiées'
2008-11-06 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2008\OneClickStarter.exe [2008-04-22 14:17]
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{FF423F09-C67A-4E69-91CB-FEAF8C888670} - c:\windows\system32\rqRKASkh.dll
HKLM-Run-8c9b10ca - c:\windows\system32\cxmutkib.dll
.
------- Examen supplémentaire -------
.
FireFox -: Profile - c:\documents and settings\CHERIF_HUGUES\Application Data\Mozilla\Firefox\Profiles\[u]0/ueiyc1rt.default\
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-06 14:52:22
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\mchInjDrv]
"ImagePath"="\??\c:\docume~1\CHERIF~1\LOCALS~1\Temp\mc21.tmp"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
PROCESSUS: c:\windows\system32\winlogon.exe
-> c:\windows\system32\jkkLcDuu.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\SoftwareDistribution\Download\[u]0/u849907f95a74b12c1123c5ac1e377a8\update\update.exe
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
.
**************************************************************************
.
Heure de fin: 2008-11-06 14:59:49 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-11-06 13:59:27
Avant-CF: 68 137 807 872 octets libres
Après-CF: 68,418,478,080 octets libres
260 --- E O F --- 2008-11-02 21:17:50