re
voila le rapport:
ComboFix 08-11-13.01 - HASNAOUI 2008-11-15 16:39:09.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.193 [GMT 1:00]
Lancé depuis: c:\documents and settings\HASNAOUI\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/B/COLOR
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-15 au 2008-11-15 ))))))))))))))))))))))))))))))))))))
.
2008-11-15 15:53 . 2008-11-15 15:53 <REP> d-------- c:\documents and settings\HASNAOUI\Application Data\Malwarebytes
2008-11-15 15:53 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-15 15:53 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-15 15:52 . 2008-11-15 15:53 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-15 15:52 . 2008-11-15 15:52 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-15 15:08 . 2008-11-15 15:41 <REP> d-------- C:\Lop SD
2008-11-15 14:37 . 2008-11-15 14:37 <REP> d-------- C:\_OTMoveIt
2008-11-15 14:00 . 2008-11-15 14:07 <REP> d-------- c:\program files\UsbFix
2008-11-15 12:59 . 2008-11-15 12:59 <REP> d-------- c:\program files\Trend Micro
2008-11-15 02:51 . 2008-06-30 17:16 234,640 --a------ c:\windows\system32\drivers\afwcore.sys
2008-11-15 02:50 . 2008-06-04 17:36 1,072,722 --a------ c:\windows\system32\drivers\VBEngNT.sys
2008-11-15 02:50 . 2008-07-11 15:41 673,920 --a------ c:\windows\system32\drivers\SandBox.sys
2008-11-15 02:50 . 2008-06-30 17:16 30,864 --a------ c:\windows\system32\drivers\afw.sys
2008-11-15 02:50 . 2007-09-07 17:45 49 --a------ c:\windows\transp.gif
2008-11-15 02:49 . 2008-11-15 03:12 <REP> d-------- c:\windows\system32\Filt
2008-11-15 02:49 . 2008-11-15 02:49 <REP> d-------- c:\program files\Agnitum
2008-11-15 02:48 . 2008-11-15 02:48 <REP> d-------- c:\documents and settings\All Users\Application Data\Agnitum
2008-11-15 02:34 . 2008-11-15 02:34 <REP> d-------- c:\program files\Avira
2008-11-15 02:34 . 2008-11-15 02:34 <REP> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-11-15 01:39 . 2008-11-15 01:39 <REP> d-------- c:\documents and settings\All Users\Application Data\Avg8
2008-11-15 01:13 . 2008-11-15 01:13 <REP> d-------- c:\documents and settings\All Users\Application Data\Innovative Solutions
2008-11-15 01:11 . 2008-11-15 01:11 <REP> d-------- c:\program files\Innovative Solutions
2008-11-15 01:11 . 2006-11-22 11:35 42,496 --a------ c:\windows\system32\AdvUninstCPL.cpl
2008-11-14 21:46 . 2008-11-14 21:46 850 --a------ c:\windows\system32\ProductTweaks.xml
2008-11-14 21:46 . 2008-11-14 21:46 385 --a------ c:\windows\system32\user_gensett.xml
2008-11-14 21:30 . 2008-11-14 21:30 <REP> d-------- c:\windows\system32\logs
2008-11-14 21:25 . 2008-11-15 01:49 <REP> d-------- c:\program files\BitDefender
2008-11-14 21:17 . 2008-11-14 21:19 <REP> d-------- c:\windows\system32\URTTemp
2008-11-14 21:15 . 2008-11-15 01:49 <REP> d-------- c:\program files\Fichiers communs\BitDefender
2008-11-14 18:10 . 2008-11-14 18:10 <REP> d--h----- C:\$AVG8.VAULT$
2008-11-09 03:55 . 2008-11-09 03:55 <REP> d-------- c:\program files\VideoLAN
2008-11-08 20:34 . 2008-11-08 20:34 <REP> d-------- C:\essai2
2008-10-31 22:30 . 2008-10-31 22:30 <REP> d-------- c:\program files\ProxyWay
2008-10-29 20:09 . 2008-10-29 20:09 <REP> d-------- C:\My Downloads
2008-10-24 19:04 . 2008-10-24 19:06 <REP> d-------- C:\web
2008-10-23 22:23 . 2008-10-23 22:23 268 --ah----- C:\sqmdata04.sqm
2008-10-23 22:23 . 2008-10-23 22:23 244 --ah----- C:\sqmnoopt04.sqm
2008-10-19 19:41 . 2008-11-15 07:53 <REP> d-------- c:\documents and settings\HASNAOUI\Application Data\ProxyWay
2008-10-18 18:10 . 2007-04-09 13:23 28,040 --a------ c:\windows\system32\mdimon.dll
2008-10-18 18:10 . 2008-10-18 18:10 385 --a------ c:\windows\ODBC.INI
2008-10-18 18:07 . 2008-10-18 18:07 <REP> d-------- c:\program files\Microsoft.NET
2008-10-18 18:03 . 2008-10-18 18:06 <REP> d-------- c:\windows\SHELLNEW
2008-10-18 17:27 . 2008-10-24 18:41 <REP> d-------- c:\program files\EasyPHP1-8
2008-10-18 07:32 . 2008-10-18 07:32 236 --a------ C:\sqmdata03.sqm
2008-10-18 07:32 . 2008-10-18 07:32 200 --a------ C:\sqmnoopt03.sqm
2008-10-18 00:11 . 2008-10-18 07:32 <REP> d-------- c:\documents and settings\HASNAOUI\Tracing
2008-10-18 00:07 . 2008-10-18 00:07 <REP> d-------- c:\program files\Microsoft
2008-10-17 23:41 . 2008-10-17 23:41 <REP> d-------- c:\program files\Fichiers communs\Windows Live
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-15 13:45 --------- d-----w c:\documents and settings\HASNAOUI\Application Data\uTorrent
2008-11-14 22:58 --------- d-----w c:\program files\eMule
2008-11-14 14:20 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-11-12 21:16 --------- d-----w c:\program files\Mozilla Thunderbird
2008-11-06 12:44 --------- d-----w c:\documents and settings\HASNAOUI\Application Data\Skype
2008-11-06 09:49 --------- d-----w c:\documents and settings\HASNAOUI\Application Data\skypePM
2008-11-04 00:27 --------- d-----w c:\documents and settings\HASNAOUI\Application Data\TeamViewer
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-19 18:41 --------- d-----w c:\program files\Messenger Plus! Live
2008-10-18 10:10 --------- d-----w c:\program files\Windows Live
2008-10-18 09:51 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2008-10-02 18:49 --------- d-----w c:\program files\Fichiers communs\Macromedia
2008-10-02 18:47 --------- d-----w c:\program files\Macromedia
2008-10-02 12:27 --------- d-----w c:\program files\uTorrent
2008-10-02 10:57 --------- d-----w c:\documents and settings\HASNAOUI\Application Data\FileZilla
2008-10-02 08:14 --------- d-----w c:\program files\P2P_Energy
2008-10-02 08:14 --------- d-----w c:\program files\Conduit
2008-10-02 08:13 --------- d-----w c:\program files\EZ Boosters
2008-10-02 07:36 --------- d-----w c:\program files\FileZilla FTP Client
2008-10-01 21:34 --------- d-----w c:\program files\Windows Live Messenger Khalid Edition v5.5
2008-10-01 21:20 --------- d-----w c:\program files\Ganymede
2008-09-27 00:33 --------- d-----w c:\documents and settings\HASNAOUI\Application Data\URSoft
2008-09-22 02:29 --------- d-----w c:\documents and settings\HASNAOUI\Application Data\Thunderbird
2008-09-21 01:24 --------- d-----w c:\program files\Camfrog
2008-09-21 01:24 --------- d-----w c:\documents and settings\HASNAOUI\Application Data\Camfrog
2008-09-19 21:47 --------- d-----w c:\documents and settings\All Users\Application Data\Downloaded Installations
2008-09-19 01:42 --------- d-----w c:\program files\Alwil Software
2008-09-18 02:28 --------- d-----w c:\documents and settings\HASNAOUI\Application Data\GanymedeNet
2008-09-18 01:27 --------- d-----w c:\documents and settings\HASNAOUI\Application Data\Thinstall
2008-09-17 15:29 --------- d--h--w c:\program files\InstallShield Installation Information
2008-09-17 15:29 --------- d-----w c:\program files\NewTech Infosystems
2008-09-17 15:24 --------- d-----w c:\program files\Java
2008-09-17 13:25 --------- d-----w c:\program files\CyberLink
2008-09-17 13:17 --------- d-----w c:\program files\BitComet
2008-06-28 13:24 2,788,800 ----a-w c:\program files\FLV PlayerFCSetup.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{2bae58c2-79f9-45d1-a286-81f911301c3a}"= "c:\program files\P2P_Energy\tbP2P_.dll" [2008-09-15 1784856]
[HKEY_CLASSES_ROOT\clsid\{2bae58c2-79f9-45d1-a286-81f911301c3a}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2bae58c2-79f9-45d1-a286-81f911301c3a}]
2008-09-15 05:47 1784856 --a------ c:\program files\P2P_Energy\tbP2P_.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{2bae58c2-79f9-45d1-a286-81f911301c3a}"= "c:\program files\P2P_Energy\tbP2P_.dll" [2008-09-15 1784856]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{2BAE58C2-79F9-45D1-A286-81F911301C3A}"= "c:\program files\P2P_Energy\tbP2P_.dll" [2008-09-15 1784856]
[HKEY_CLASSES_ROOT\clsid\{2bae58c2-79f9-45d1-a286-81f911301c3a}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-05 15360]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2003-03-18 184320]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-05-07 98304]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-05-07 536576]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-05-15 339968]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"OutpostMonitor"="c:\progra~1\Agnitum\OUTPOS~1\op_mon.exe" [2008-08-22 1211224]
"OutpostFeedBack"="c:\program files\Agnitum\Outpost Security Suite Pro\feedback.exe" [2008-08-05 435544]
"SoundMan"="SOUNDMAN.EXE" [2004-06-18 c:\windows\SOUNDMAN.EXE]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-07 c:\windows\AGRSMMSG.exe]
c:\documents and settings\HASNAOUI\Menu D‚marrer\Programmes\D‚marrage\
Y'z Toolbar.lnk - c:\windows\Packs\Crystal XP\YzToolbar\YzToolbar.exe [2008-06-28 90112]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 2009\\english\\setup.exe"=
"c:\\Documents and Settings\\HASNAOUI\\Mes documents\\Log\\TeamViewer\\TeamViewer.exe"=
"c:\\Program Files\\Camfrog\\Camfrog Video Chat\\Camfrog Video Chat.exe"=
"c:\\Documents and Settings\\HASNAOUI\\Bureau\\TeamViewer.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"18125:TCP"= 18125:TCP:BitComet 18125 TCP
"18125:UDP"= 18125:UDP:BitComet 18125 UDP
R0 atiide;atiide;c:\windows\system32\DRIVERS\atiide.sys [2004-04-14 5632]
R1 SandBox;SandBox;c:\windows\system32\DRIVERS\SandBox.sys [2008-07-11 673920]
R3 afw;Agnitum firewall driver;c:\windows\system32\DRIVERS\afw.sys [2008-06-30 30864]
R3 IPN2220;acer IPN2220 Wireless LAN Card Driver;c:\windows\system32\DRIVERS\i2220ntx.sys [2004-08-16 160896]
S2 acssrv;Agnitum Client Security Service;c:\progra~1\Agnitum\OUTPOS~1\acs.exe [2008-08-05 1570136]
S3 afwcore;afwcore;c:\windows\system32\drivers\afwcore.sys [2008-06-30 234640]
S3 ASWFilt;ASWFilt;c:\windows\system32\Filt\ASWFilt.dll [2008-07-11 33408]
S3 VBEngNT;VBEngNT;c:\windows\system32\DRIVERS\VBEngNT.sys [2008-06-04 1072722]
S3 VBFilt;VBFilt;c:\windows\system32\Filt\VBFilt.dll [2008-07-11 158816]
.
Contenu du dossier 'Tâches planifiées'
2008-11-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 14:42]
.
- - - - ORPHELINS SUPPRIMES - - - -
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
HKCU-Run-Acid okay - c:\docume~1\HASNAOUI\APPLIC~1\ProxyWay\file grid.exe
HKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exe
HKLM-Run-winudp64.exe - winudp64.exe
HKLM-RunServices-winudp64.exe - winudp64.exe
.
------- Examen supplémentaire -------
.
FireFox -: Profile - c:\documents and settings\HASNAOUI\Application Data\Mozilla\Firefox\Profiles\cozl4sya.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1060933&SearchSource=3&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://funnylogo.info/engines/Google/Red/menel.aspx
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npganymedenet.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-15 16:45:58
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
PROCESSUS: c:\windows\explorer.exe
-> c:\program files\RocketDock\RocketDock.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\acer\eManager\anbmServ.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\windows\system32\fxssvc.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2008-11-15 16:59:31 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-11-15 15:59:18
Avant-CF: 13 670 785 024 octets libres
Après-CF: 13,612,048,384 octets libres
209 --- E O F --- 2008-11-15 08:02:06