Voici Combo Fix
ComboFix 08-11-12.01 - Easy Home 2008-11-13 10:57:25.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.532 [GMT -5:00]
Lancé depuis: c:\documents and settings\Easy Home\Mes documents\Setup files\ComboFix.exe
* Un nouveau point de restauration a été créé
[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/B/COLOR
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\174125.dll
c:\windows\system32\MSINET.oca
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-13 au 2008-11-13 ))))))))))))))))))))))))))))))))))))
.
2008-11-13 10:37 . 2008-11-13 10:37 <REP> d-------- c:\program files\Trend Micro
2008-11-13 04:18 . 2008-11-13 04:18 <REP> d-------- C:\logs
2008-11-11 23:07 . 2007-01-24 12:47 <REP> d-------- c:\documents and settings\Administrateur\WINDOWS
2008-11-11 23:07 . 2005-06-10 15:17 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage réseau
2008-11-11 23:07 . 2005-06-10 15:17 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage d'impression
2008-11-11 23:07 . 2007-01-24 12:47 <REP> d--h----- c:\documents and settings\Administrateur\Modèles
2008-11-11 23:07 . 2007-01-24 12:47 <REP> dr------- c:\documents and settings\Administrateur\Mes documents
2008-11-11 23:07 . 2007-01-24 12:47 <REP> dr------- c:\documents and settings\Administrateur\Menu Démarrer
2008-11-11 23:07 . 2007-01-24 12:47 <REP> dr------- c:\documents and settings\Administrateur\Favoris
2008-11-11 23:07 . 2007-01-24 09:58 <REP> d-------- c:\documents and settings\Administrateur\Bureau
2008-11-11 23:07 . 2008-11-11 23:07 <REP> d-------- c:\documents and settings\Administrateur
2008-11-11 23:05 . 2008-11-12 15:22 2,540 --a------ c:\windows\system32\oodbs.lor
2008-11-11 23:04 . 2008-11-11 23:04 <REP> d-------- c:\windows\system32\oodag
2008-11-11 23:02 . 2008-11-11 23:02 0 --a------ c:\windows\oodcnt.INI
2008-11-11 22:37 . 2008-11-11 22:37 <REP> d-------- c:\program files\OO Software
2008-11-10 19:12 . 2008-11-10 19:24 <REP> d-------- c:\program files\1 - Pograme Shortcuts
2008-10-31 00:32 . 2008-11-03 13:24 <REP> d-------- c:\program files\Picasa2
2008-10-28 22:16 . 2008-10-28 22:16 4,128 --a------ C:\INFCACHE.1
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-13 11:52 --------- d-----w c:\program files\Mcafee Rootkit
2008-11-13 09:21 --------- d-----w c:\program files\Lx_cats
2008-11-13 07:58 --------- d-----r c:\documents and settings\Easy Home\Application Data\uTorrent
2008-11-12 04:04 48,416 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-12 04:04 4,354,080 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-11-12 02:50 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-11 00:23 --------- d-----w c:\program files\MagicISO
2008-11-11 00:23 --------- d-----w c:\program files\Lupas Rename 2000
2008-11-11 00:23 --------- d-----w c:\program files\LogonStudio
2008-11-11 00:22 --------- d-----w c:\program files\LimeWire
2008-11-11 00:22 --------- d-----w c:\program files\Lexmark 1300 Series
2008-11-11 00:20 --------- d-----w c:\program files\IZArc
2008-11-11 00:20 --------- d-----w c:\program files\IVCsoft
2008-11-11 00:20 --------- d-----w c:\program files\Iso-burner
2008-11-11 00:19 --------- d-----w c:\program files\IcoFX 1.5
2008-11-11 00:19 --------- d-----w c:\program files\Folder 2 Iso
2008-11-11 00:18 --------- d-----w c:\program files\FileZilla
2008-11-11 00:18 --------- d-----w c:\program files\Easy SpyRemover
2008-11-11 00:17 --------- d-----w c:\program files\DDS Converter 2
2008-11-11 00:17 --------- d-----w c:\program files\DAEMON Tools
2008-11-11 00:17 --------- d-----w c:\program files\CCleaner
2008-11-11 00:16 --------- d-----w c:\program files\BootSkin
2008-11-11 00:14 --------- d-----w c:\program files\ActiveMultiwallpaper
2008-11-11 00:13 --------- d-----w c:\program files\Acoustica MP3 CD Burner
2008-11-11 00:13 --------- d-----w c:\program files\7-Zip
2008-10-28 07:13 --------- d-----r c:\documents and settings\Easy Home\Application Data\ActiveMultiWallpaper
2008-10-27 16:55 --------- d-----w c:\documents and settings\Easy Home\Application Data\IcoFX
2008-10-27 16:08 --------- d-----w c:\program files\VirtualDJ
2008-10-27 16:03 409,600 ----a-w c:\windows\system32\wrap_oal.dll
2008-10-27 16:03 114,688 ----a-w c:\windows\system32\OpenAL32.dll
2008-10-27 15:42 --------- d-----w c:\program files\Acoustica MP3 CD Burner 4.5
2008-10-27 15:40 5,650,944 ----a-w c:\windows\system32\logonuiX.exe
2008-10-27 15:24 163,712 ----a-w c:\windows\system32\drivers\vidstub.sys
2008-10-27 15:15 --------- d-----w c:\program files\AbiSuite2
2008-10-16 19:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-15 10:38 --------- d-----w c:\documents and settings\Easy Home\Application Data\XnView
2008-10-12 21:05 22,811,137 ----a-w c:\windows\Internet Logs\tvDebug.zip
2008-10-11 08:29 --------- d-----w c:\program files\sixteen tons entertainment
2008-10-09 22:39 --------- d-----w c:\program files\Xbox-Hq PC Essentials
2008-10-04 02:40 --------- d-----w c:\documents and settings\Easy Home\Application Data\Lexmark Imaging Studio
2008-10-04 02:34 --------- d-----w c:\program files\Lexmark Toolbar
2008-10-03 05:31 --------- d--h--w c:\program files\InstallShield Installation Information
2008-09-23 00:47 --------- d-----r c:\documents and settings\Easy Home\Application Data\Logitech
2008-09-23 00:45 --------- d-----w c:\program files\Fichiers communs\Logitech
2008-09-23 00:44 --------- d-----w c:\program files\Logitech
2008-09-21 04:12 --------- d-----w c:\program files\uTorrent
2008-09-15 15:39 1,846,144 ----a-w c:\windows\system32\win32k.sys
2008-09-15 06:28 --------- d-----w c:\program files\Avira
2008-09-15 06:28 --------- d-----w c:\documents and settings\All Users\Application Data\Avira
2008-09-15 05:46 0 ----a-w c:\documents and settings\Easy Home\Application Data\wklnhst.dat
2008-09-14 19:37 54,624 ----a-w c:\windows\system32\8d16C.sys
2008-09-14 19:09 2,982,912 ----a-w c:\windows\Internet Logs\xDB55.tmp
2008-09-14 19:09 2,705,920 ----a-w c:\windows\Internet Logs\xDB56.tmp
2008-09-14 19:02 54,624 ----a-w c:\windows\system32\a8c2.sys
2008-09-14 19:02 128,352 ----a-w c:\windows\system32\a8c2.dll
2008-09-14 18:15 54,624 ----a-w c:\windows\system32\174125.sys
2008-09-10 08:06 4,135,424 ----a-w c:\windows\Internet Logs\xDB53.tmp
2008-09-10 08:06 2,704,896 ----a-w c:\windows\Internet Logs\xDB54.tmp
2008-09-04 11:02 730,368 ----a-w c:\windows\system32\oodsvct.exe
2008-09-04 11:02 1,295,616 ----a-w c:\windows\system32\oodag.exe
2008-09-04 11:01 2,524,416 ----a-w c:\windows\system32\oodtray.exe
2008-09-04 11:01 194,816 ----a-w c:\windows\system32\oodbs.exe
2008-09-04 10:58 9,984 ----a-w c:\windows\system32\oodbsrs.dll
2008-09-04 10:58 894,208 ----a-w c:\windows\system32\oodtrrs.dll
2008-09-04 10:58 8,448 ----a-w c:\windows\system32\oodagrs.dll
2008-09-04 10:58 15,616 ----a-w c:\windows\system32\oodagmg.dll
2008-08-30 10:20 15,104 ----a-w c:\windows\system32\ootmapi.dll
2008-08-25 02:39 3,002,368 ----a-w c:\windows\Internet Logs\xDB51.tmp
2008-08-25 02:39 2,680,832 ----a-w c:\windows\Internet Logs\xDB52.tmp
2008-08-24 01:22 4,193,792 ----a-w c:\windows\Internet Logs\xDB4F.tmp
2008-08-24 01:22 2,680,320 ----a-w c:\windows\Internet Logs\xDB50.tmp
2008-08-24 00:46 21,840 ----a-w c:\windows\system32\SIntfNT.dll
2008-08-24 00:46 17,212 ----a-w c:\windows\system32\SIntf32.dll
2008-08-24 00:46 12,067 ----a-w c:\windows\system32\SIntf16.dll
2008-08-20 05:33 671,744 ----a-w c:\windows\system32\wininet.dll
2008-08-14 13:44 2,138,112 ----a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 13:44 2,017,792 ----a-w c:\windows\system32\ntkrnlpa.exe
2007-12-27 22:05 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2007-08-25 15:27 119 --sh--w c:\program files\desktop.ini
2007-07-30 13:18 24,192 ----a-w c:\documents and settings\Easy Home\usbsermptxp.sys
2007-07-30 13:18 22,768 ----a-w c:\documents and settings\Easy Home\usbsermpt.sys
2007-07-22 16:04 47,360 ----a-w c:\documents and settings\Easy Home\Application Data\pcouffin.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-19 68856]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-30 1829712]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-10-19 286720]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-09-14 344064]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"LXSUPMON"="c:\windows\system32\LXSUPMON.EXE" [2002-02-09 886272]
"BootSkin Startup Jobs"="c:\program files\BootSkin\BootSkin.exe" [2004-04-26 270336]
"LogonStudio"="c:\program files\LogonStudio\logonstudio.exe" [2002-09-03 987187]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-12-13 919016]
"lxdcamon"="c:\program files\Lexmark 1300 Series\lxdcamon.exe" [2007-02-05 20480]
"LXDCCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll" [2007-01-22 102400]
"OODefragTray"="c:\windows\system32\oodtray.exe" [2008-09-04 2524416]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-03 160768]
"SoundMan"="SOUNDMAN.EXE" [2005-07-22 c:\windows\SOUNDMAN.EXE]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-05-20 c:\windows\KHALMNPR.Exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\Easy Home\Menu D‚marrer\Programmes\D‚marrage\
PowerReg Scheduler V3.exe [2008-08-04 225280]
PowerReg Scheduler.exe [2008-08-04 256000]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-09-22 450560]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\\WINDOWS\\system32\\logonuiX.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Cakewalk\\Kinetic\\Kinetic.EXE"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\WINDOWS\\system32\\lxdccoms.exe"=
"c:\\Program Files\\Lexmark 1300 Series\\lxdcamon.exe"=
"c:\\Program Files\\Lexmark 1300 Series\\App4R.exe"=
R2 lxdc_device;lxdc_device;c:\windows\system32\lxdccoms.exe [2007-02-12 537520]
S3 174125;174125;c:\windows\system32\174125.sys [2008-09-14 54624]
S3 8d16C;8d16C;c:\windows\system32\8d16C.sys [2008-09-14 54624]
S3 a8c2;a8c2;c:\windows\system32\a8c2.sys [2008-09-14 54624]
S3 SNPP106;PC Camera (6029 CIF);c:\windows\system32\DRIVERS\snpp106.sys [2003-04-09 227200]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\Z]
\Shell\AutoRun\command - Z:\Info.exe folder.htt 480 480
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Tâches planifiées'
2008-11-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
2008-11-13 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE []
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-VoipStunt - c:\program files\VoipStunt.com\VoipStunt\VoipStunt.exe
HKLM-Run-lxdcmon.exe - c:\program files\Lexmark 1300 Series\lxdcmon.exe
.
------- Examen supplémentaire -------
.
FireFox -: Profile - c:\documents and settings\Easy Home\Application Data\Mozilla\Firefox\Profiles\bqi8cqdn.Mich\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.ca/
FF -: plugin - c:\program files\Picasa2\npPicasa2.dll
FF -: plugin - c:\program files\Yahoo!\Shared\npYState.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-13 11:01:07
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXDCCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXDCtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-11-13 11:08:46
ComboFix-quarantined-files.txt 2008-11-13 16:08:41
Avant-CF: 25 401 901 056 octets libres
Après-CF: 25,416,802,304 octets libres
221 --- E O F --- 2008-11-11 10:45:00