Voici le Rapport ... Y a-t-il une suite à faire??
Merci du suivi hyper rapide.
ComboFix 08-11-27.03 - ALEXANDRE 2008-11-27 22:30:09.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.504 [GMT 1:00]
Lancé depuis: c:\documents and settings\ALEXANDRE\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\ALEXANDRE\Application Data\Rapid Antivirus
c:\documents and settings\ALEXANDRE\Application Data\Rapid Antivirus\Rapid Antivirus.ini
c:\documents and settings\ALEXANDRE\Bureau\Rapid Antivirus.lnk
c:\documents and settings\All Users\Menu Démarrer\Programmes\Rapid Antivirus
c:\documents and settings\All Users\Menu Démarrer\Programmes\Rapid Antivirus\Purchase License.lnk
c:\documents and settings\All Users\Menu Démarrer\Programmes\Rapid Antivirus\Start Rapid Antivirus.lnk
c:\documents and settings\All Users\Menu Démarrer\Programmes\Rapid Antivirus\Support Page.lnk
c:\documents and settings\All Users\Menu Démarrer\Programmes\Rapid Antivirus\Uninstall.lnk
c:\program files\Rapid Antivirus
c:\program files\Rapid Antivirus\Buy.url
c:\program files\Rapid Antivirus\Help.url
c:\program files\Rapid Antivirus\HowToBuy.txt
c:\program files\Rapid Antivirus\ID.dat
c:\program files\Rapid Antivirus\License.txt
c:\program files\Rapid Antivirus\Rapid Antivirus.exe
c:\program files\Rapid Antivirus\Uninstall.exe
c:\windows\fxstaller.exe
c:\windows\IE4 Error Log.txt
c:\windows\system32\cbXQhHby.dll
c:\windows\system32\chphxivm.dll
c:\windows\system32\CMopYcdd.ini
c:\windows\system32\CMopYcdd.ini2
c:\windows\system32\ddcYpoMC.dll
c:\windows\system32\djxgfovx.ini
c:\windows\system32\nnnmlJyX.dll
c:\windows\system32\xebwhd.dll
c:\windows\system32\xvofgxjd.dll
c:\windows\Tasks\gqhcdnxg.job
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_PACKET
-------\Service_Packet
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-27 au 2008-11-27 ))))))))))))))))))))))))))))))))))))
.
2008-11-27 20:39 . 2008-11-27 20:54 <REP> d-------- c:\program files\Navilog1
2008-11-27 20:25 . 2008-11-27 20:26 <REP> d-------- C:\rsit
2008-11-27 20:25 . 2008-11-27 20:26 <REP> d-------- c:\program files\trend micro
2008-11-27 15:07 . 2008-11-27 15:07 <REP> d-------- c:\documents and settings\ALEXANDRE\Application Data\install_4848_MHwzNXwxMDAwMDAwMDAwfHwyNTA0fHx8fHx8_[1]
2008-11-20 16:32 . 2008-11-20 16:33 <REP> d-------- c:\program files\InterActual
2008-11-19 20:46 . 2008-11-19 20:46 126,976 --a------ c:\windows\War3Unin.exe
2008-11-19 20:46 . 2008-11-19 20:46 18,051 --a------ c:\windows\War3Unin.dat
2008-11-19 20:46 . 2008-11-19 20:46 2,829 --a------ c:\windows\War3Unin.pif
2008-11-19 20:41 . 2008-11-19 21:14 <REP> d-------- c:\program files\Warcraft III
2008-11-19 20:22 . 1999-01-25 12:00 143,872 --------- c:\windows\system32\iacenc.dll
2008-11-19 20:22 . 1999-01-25 12:00 56,832 --------- c:\windows\system32\iyvu9_32.dll
2008-11-19 20:21 . 2008-11-19 20:21 <REP> d-------- c:\program files\Microsoft Games
2008-11-12 08:28 . 2008-10-24 12:21 455,296 --------- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-12 08:27 . 2008-09-04 18:16 1,106,944 --------- c:\windows\system32\dllcache\msxml3.dll
2008-11-03 20:55 . 2008-11-03 20:55 <REP> d-------- c:\program files\Uniblue
2008-11-03 20:55 . 2008-11-03 20:55 <REP> d-------- c:\documents and settings\ALEXANDRE\Application Data\Uniblue
2008-11-03 20:54 . 2008-11-03 20:55 <REP> d--h-c--- c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-27 21:10 --------- d-----w c:\documents and settings\ALEXANDRE\Application Data\Skype
2008-11-27 15:01 --------- d-----w c:\documents and settings\ALEXANDRE\Application Data\skypePM
2008-11-27 06:51 0 ----a-w c:\windows\system32\drivers\lvuvc.hs
2008-11-27 06:51 --------- d-----w c:\program files\LogMeIn
2008-11-12 21:13 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-22 06:06 --------- d-----w c:\program files\Microsoft Silverlight
2008-10-21 10:09 --------- d-----w c:\program files\Java
2008-10-19 18:53 --------- d-----w c:\documents and settings\ALEXANDRE\Application Data\U3
2008-10-07 13:04 --------- d-----w c:\program files\iTunes
2008-10-07 13:04 --------- d-----w c:\program files\iPod
2008-10-07 13:04 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-04 12:28 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-01 11:01 32,000 ----a-w c:\windows\system32\drivers\usbaapl.sys
2008-01-13 19:42 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2006-09-27 07:21 56,621,155 ----a-w c:\program files\openofficeorg3.cab
2006-09-27 07:21 2,625,269 ----a-w c:\program files\openofficeorg4.cab
2006-09-27 07:17 15,301,576 ----a-w c:\program files\openofficeorg2.cab
2006-09-27 07:16 18,114,541 ----a-w c:\program files\openofficeorg1.cab
2006-09-27 07:15 5,294,592 ----a-w c:\program files\openofficeorg20.msi
2006-09-27 07:15 217 ----a-w c:\program files\setup.ini
2006-09-01 18:05 299,008 ----a-w c:\program files\setup.exe
2006-08-31 22:12 0 ----a-w c:\documents and settings\ALEXANDRE\Application Data\wklnhst.dat
2002-03-11 08:06 1,822,520 ----a-w c:\program files\instmsiw.exe
2002-03-11 07:45 1,708,856 ----a-w c:\program files\instmsia.exe
2007-05-22 17:14 8,784 ----a-w c:\program files\mozilla firefox\plugins\ractrlkeyhook.dll
2007-05-22 17:17 245,408 ----a-w c:\program files\mozilla firefox\plugins\unicows.dll
2006-12-25 22:11 88 --sh--r c:\windows\system32\1748541FED.sys
2006-11-30 19:25 56 --sh--r c:\windows\system32\ED1F544817.sys
2006-12-25 22:11 6,580 --sha-w c:\windows\system32\KGyGaAvL.sys
2008-08-26 15:08 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008082620080827\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Uniblue RegistryBooster 2009"="c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe" [2008-08-26 2019624]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-05-01 667718]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-05-01 602182]
"ISUSPM Startup"="c:\program files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2005-05-31 122941]
"LogitechCommunicationsManager"="c:\program files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 563984]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-07-25 2027792]
"fssui"="c:\program files\Windows Live\Contrôle parental\fssui.exe" [2007-12-17 243240]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"AppleSyncNotifier"="c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 c:\windows\stsystra.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-09-28 443968]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2007-11-15 18:46 87352 c:\windows\system32\LMIinit.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=xebwhd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
[HKLM\~\startupfolder\C:^Documents and Settings^ALEXANDRE^Menu Démarrer^Programmes^Démarrage^Rapid Antivirus.lnk]
path=c:\documents and settings\ALEXANDRE\Menu Démarrer\Programmes\Démarrage\Rapid Antivirus.lnk
backup=c:\windows\pss\Rapid Antivirus.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AnyDVD]
--a------ 2007-10-14 20:40 468480 c:\program files\SlySoft\AnyDVD\AnyDVD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2006-10-09 10:28 139264 c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
--a------ 2005-05-19 14:47 57344 c:\program files\SlySoft\CloneCD\CloneCDTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSVolFE.exe]
--------- 2005-02-23 15:57 57344 c:\program files\Creative\Mixer\CTSVolFE.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
--a------ 2006-04-06 14:58 1032192 c:\program files\Dell\QuickSet\quickset.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
--a------ 2005-01-27 01:02 86016 c:\program files\Dell\Media Experience\DMXLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
--------- 2005-12-09 20:29 49152 c:\program files\CyberLink\PowerDVD\DVDLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JobHisInit]
--a------ 2005-11-01 10:52 151552 c:\program files\RDS\RMClient\JobHisInit.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn GUI]
--a------ 2007-09-12 09:20 63048 c:\program files\LogMeIn\x86\LogMeInSystray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ModemOnHold]
--------- 2003-09-10 02:24 20480 c:\program files\NetWaiting\netwaiting.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MplSetUp]
--a------ 2005-06-01 01:59 40960 c:\program files\RDS\RMClient\MplSetUp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2006-01-12 15:40 155648 c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-02-03 16:05 185896 c:\program files\Fichiers communs\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Bonjour Service"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\ftp.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-04-05 78416]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-04-05 20560]
R2 fssfltr;FssFltr;c:\windows\system32\DRIVERS\fssfltr.sys [2008-02-27 43816]
R2 fsssvc;Windows Live OneCare Contrôle parental;"c:\program files\Windows Live\Contrôle parental\fsssvc.exe" [2007-12-17 523816]
R2 LMIInfo;LogMeIn Kernel Information Provider;\??\c:\program files\LogMeIn\x86\RaInfo.sys [2007-09-12 12992]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;\??\c:\windows\system32\drivers\LMIRfsDriver.sys [2007-10-14 46112]
S3 ovt530;Webcam Classic;c:\windows\system32\Drivers\ov530vid.sys [2006-09-19 161792]
S4 LMIRfsClientNP;LMIRfsClientNP; []
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c3da85b8-7a39-11dc-ab01-0015c53f9611}]
\Shell\AutoRun\command - Copie de RavMon.exe
.
Contenu du dossier 'Tâches planifiées'
2008-11-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2008-11-21 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2007-08-02 18:18]
2008-11-27 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{3e191e34-b704-45f7-95f1-f46703fdfceb} - c:\windows\system32\xebwhd.dll
BHO-{ACD587D8-F0EB-4533-9667-89FC52ABFDEA} - c:\windows\system32\ddcYpoMC.dll
.
------- Examen supplémentaire -------
.
FireFox -: Profile - c:\documents and settings\ALEXANDRE\Application Data\Mozilla\Firefox\Profiles\44a99aen.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.be/
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-27 22:36:42
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(712)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\LMIinit.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Intel\Wireless\Bin\WLKEEPER.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
c:\program files\a-squared Free\a2service.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\Fichiers communs\Creative Labs Shared\Service\CreativeLicensing.exe
c:\program files\Dell Network Assistant\hnm_svc.exe
c:\program files\LogMeIn\x86\ramaint.exe
c:\program files\LogMeIn\x86\LogMeIn.exe
c:\program files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files\Dell\QuickSet\NicConfigSvc.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\ati2evxx.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Fichiers communs\LogiShrd\LQCVFX\COCIManager.exe
.
**************************************************************************
.
Heure de fin: 2008-11-27 22:43:51 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-11-27 21:43:38
Avant-CF: 37 223 735 296 octets libres
Après-CF: 37,611,454,464 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
270 --- E O F --- 2008-11-18 18:36:01