Bon alors c'est de pire en pire...
J'ai du redémarrer plusieurs fois l'ordi pour réussir à démarrer en mode normal (pas rester planté sur l'écran noir), mais maintenant le virus/trojan m'empêche de démarrer tous les programmes antivirus/antispyware quand ils ne sont pas renommés, et même certains comme Hijackthis quand ils sont renommés (donc plus de Hijackthis possible). Je ne peux pas démarrer Antivir car apparemment il est fermé direct (il n'apparait pas dans les processus), tout comme Hijackthis. Je suis aussi censuré sur internet, il suffit que j'aille sur une page internet qui contient un mot qui ne lui plait pas (comme hijackthis) et la page est fermée directement.
J'ai ensuite essayé en mode sans échec. Dans ce mode c'est pareil sauf que j'ai pu démarrer combofix en renommé. J'ai tout fait en sans échec et il a supprimé pas mal de fichiers. Après j'ai fais la totale: SDfix, Malwarebyte, antivir (je peux pas le lancer mais quand je fais clic droit puis "scan selected files with Antivir" ça fonctionne), FindyKill, CCleaner, réparateur de registre. Ca a bien nettoyé, mais je suis toujours censuré et je ne peux toujours pas lancer Hijackthis.
Voila donc je ne sais plus quoi faire maintenant... Je vais mettre le rapport de combofix et le dernier de SDfix que j'ai fais (je ne sais pas où est enregistré celui de antivir et les autres n'ont rien trouvé de plus), en espérant que vous pourrez m'aider:
ComboFix 08-11-29.03 - Chris 2008-11-30 12:40:32.1 - NTFSx86 MINIMAL
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\InfoSat.txt
c:\program files\Internet Explorer\fxavx.ini
C:\userinit.exe
c:\windows\Downloaded Program Files\setup.inf
c:\windows\system32\drivers\services.exe
c:\windows\system32\drivers\TDSSmaxt.sys
c:\windows\system32\dyfilqsd.dll
c:\windows\system32\ernjia.dll
c:\windows\system32\fxggpdai.ini
c:\windows\system32\hxbkvl.dll
c:\windows\system32\jcqfqy.dll
c:\windows\system32\nthybj.dll
c:\windows\system32\rrfghuoc.dll
c:\windows\system32\slrflxpt.ini
c:\windows\system32\swmpkowm.dll
c:\windows\system32\TDSScfum.dll
c:\windows\system32\TDSSlxwp.dll
c:\windows\system32\TDSSmhct.log
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSnrsr.dll
c:\windows\system32\TDSSofxh.dll
c:\windows\system32\TDSSofxh.log
c:\windows\system32\TDSSosvd.dat
c:\windows\system32\TDSSriqp.dll
c:\windows\system32\TDSSsihc.dll
c:\windows\system32\udhmtjxi.dll
c:\windows\system32\vbadkhcx.dll
c:\windows\system32\whsshm.dll
c:\windows\system32\xgxcmhnu.ini
c:\windows\system32\yxmiiwwj.ini
d:\documents and settings\Chris\Menu Démarrer\Programmes\Démarrage\userinit.exe
d:\documents and settings\Chris\svchost.exe
d:\documents and settings\LocalService\svchost.exe
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_TDSSSERV.SYS
-------\Legacy_TDSSSERV.SYS
-------\Legacy_FCI
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-28 au 2008-11-30 ))))))))))))))))))))))))))))))))))))
.
2008-11-30 02:33 . 2008-11-30 02:33 114,688 --a------ c:\windows\~DF98C4.tmp
2008-11-30 01:26 . 2008-11-30 01:26 <REP> d-------- d:\documents and settings\Chris\Application Data\Malwarebytes
2008-11-30 01:24 . 2008-11-30 01:24 <REP> d-------- d:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-30 01:24 . 2008-09-08 00:16 38,528 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-30 01:24 . 2008-09-08 00:16 17,200 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-29 21:34 . 2008-11-29 21:34 <REP> d-------- c:\windows\ERUNT
2008-11-29 20:57 . 2008-11-29 21:15 <REP> d-------- C:\azerty
2008-11-29 20:49 . 2008-11-29 23:39 <REP> d-------- C:\SDFix
2008-11-29 19:19 . 2001-08-17 22:01 241,664 --a------ c:\windows\system32\dllcache\OLDF0B.tmp
2008-11-29 19:19 . 2001-08-17 22:02 230,912 --a------ c:\windows\system32\dllcache\OLDF11.tmp
2008-11-29 19:19 . 2008-04-14 04:34 82,944 --a------ c:\windows\system32\dllcache\OLDF1E.tmp
2008-11-29 19:19 . 2001-08-23 17:46 43,520 --a------ c:\windows\system32\dllcache\OLDF24.tmp
2008-11-29 19:19 . 2001-08-23 17:47 31,744 --a------ c:\windows\system32\dllcache\OLDF19.tmp
2008-11-29 19:11 . 2001-08-23 17:20 16,768 --a------ c:\windows\system32\dllcache\OLDD10.tmp
2008-11-29 19:02 . 2001-08-17 20:50 39,264 --a------ c:\windows\system32\dllcache\OLDAC9.tmp
2008-11-29 19:01 . 2001-08-23 17:46 60,480 --a------ c:\windows\system32\dllcache\OLDAC3.tmp
2008-11-29 18:53 . 2001-08-23 17:47 126,976 --a------ c:\windows\system32\dllcache\OLD834.tmp
2008-11-29 18:53 . 2001-08-23 17:47 93,696 --a------ c:\windows\system32\dllcache\OLD83A.tmp
2008-11-29 18:52 . 2001-08-23 17:47 101,376 --a------ c:\windows\system32\dllcache\OLD82F.tmp
2008-11-29 18:42 . 2001-08-23 17:08 50,944 --a------ c:\windows\system32\dllcache\OLD53B.tmp
2008-11-29 18:42 . 2001-08-23 17:47 29,184 --a------ c:\windows\system32\dllcache\OLD537.tmp
2008-11-29 18:42 . 2001-08-23 17:08 17,536 --a------ c:\windows\system32\dllcache\OLD52E.tmp
2008-11-29 18:42 . 2001-08-23 17:08 15,104 --a------ c:\windows\system32\dllcache\OLD532.tmp
2008-11-29 17:58 . 2008-11-29 17:58 185,360 --a------ c:\windows\C9D4E587C0C6B8DE93022409C758FE.exe
2008-11-29 17:54 . 2008-11-29 18:05 <REP> d-------- d:\documents and settings\All Users\Application Data\comodo
2008-11-29 17:54 . 2008-11-29 17:54 <REP> d-------- c:\program files\COMODO
2008-11-29 17:54 . 2008-11-29 17:54 143,096 --a------ c:\windows\system32\guard32.dll
2008-11-29 17:54 . 2008-11-29 17:54 99,216 --a------ c:\windows\system32\drivers\cmdguard.sys
2008-11-29 17:54 . 2008-11-29 17:54 31,504 --a------ c:\windows\system32\drivers\cmdhlp.sys
2008-11-29 17:13 . 2008-11-29 17:49 120 --a------ c:\windows\CIS_Setup_3.5.55810.432_XP_Vista_x32.INI
2008-11-29 15:55 . 2008-11-29 15:55 <REP> d-------- c:\program files\PrevxCSI
2008-11-29 15:55 . 2008-11-29 15:55 26,680 --a------ c:\windows\system32\drivers\pxark.sys
2008-11-29 15:54 . 2008-11-29 15:56 <REP> d-------- d:\documents and settings\All Users\Application Data\PrevxCSI
2008-11-29 15:53 . 2008-11-29 18:10 336 --a------ C:\log.udt
2008-11-27 19:39 . 2008-11-27 19:39 197,632 --a------ c:\windows\system32\drivers\NNRZNFZZ.sys
2008-11-27 19:39 . 2008-11-29 16:40 184,848 --a------ C:\jfjsipw.exe
2008-11-27 19:39 . 2008-11-29 16:40 167,936 --a------ C:\lurjlnps.exe
2008-11-27 19:39 . 2008-11-29 16:40 104,448 --a------ C:\dtqlv.exe
2008-11-25 00:24 . 2007-03-01 19:54 21,056 --a------ c:\windows\system32\drivers\sskbfd.sys
2008-11-24 00:08 . 2008-11-24 00:12 <REP> d-------- c:\program files\UsbFix
2008-11-23 23:10 . 2008-11-23 23:47 <REP> d-------- c:\program files\FindyKill
2008-11-23 22:28 . 2008-11-30 01:25 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-23 22:01 . 2007-09-05 23:22 289,144 --a------ c:\windows\system32\VCCLSID.exe
2008-11-23 22:01 . 2006-04-27 16:49 288,417 --a------ c:\windows\system32\SrchSTS.exe
2008-11-23 22:01 . 2008-10-01 14:51 87,552 --a------ c:\windows\system32\VACFix.exe
2008-11-23 22:01 . 2008-10-10 07:58 82,944 --a------ c:\windows\system32\o4Patch.exe
2008-11-23 22:01 . 2008-05-18 20:40 82,944 --a------ c:\windows\system32\IEDFix.exe
2008-11-23 22:01 . 2008-10-10 07:58 82,944 --a------ c:\windows\system32\IEDFix.C.exe
2008-11-23 22:01 . 2008-08-18 11:19 82,432 --a------ c:\windows\system32\404Fix.exe
2008-11-23 22:01 . 2003-06-05 20:13 53,248 --a------ c:\windows\system32\Process.exe
2008-11-23 22:01 . 2004-07-31 17:50 51,200 --a------ c:\windows\system32\dumphive.exe
2008-11-23 22:01 . 2007-10-03 23:36 25,600 --a------ c:\windows\system32\WS2Fix.exe
2008-11-23 16:39 . 2008-11-23 16:39 2,560 --a------ c:\windows\_MSRSTRT.EXE
2008-11-23 01:40 . 2008-11-23 01:58 <REP> d-------- c:\program files\a-squared Free
2008-11-23 01:12 . 2008-11-23 01:12 <REP> d-------- c:\program files\Avira
2008-11-22 23:58 . 2008-11-27 00:50 392 --a------ c:\windows\pdf2word.INI
2008-11-22 23:57 . 2008-11-26 14:07 <REP> d-------- c:\program files\PDF2Word v3.0
2008-11-22 16:38 . 2008-11-22 16:38 <REP> d-------- d:\documents and settings\Chris\Application Data\Avira
2008-11-22 16:12 . 2008-11-23 01:12 <REP> d-------- d:\documents and settings\All Users\Application Data\Avira
2008-11-20 00:40 . 2008-04-14 04:33 116,736 --a------ c:\windows\system32\dllcache\xrxwiadr.dll
2008-11-20 00:40 . 2001-08-23 17:47 27,648 --a------ c:\windows\system32\dllcache\xrxftplt.exe
2008-11-20 00:40 . 2001-08-23 17:47 23,040 --a------ c:\windows\system32\dllcache\xrxwbtmp.dll
2008-11-20 00:40 . 2008-04-14 04:33 18,944 --a------ c:\windows\system32\dllcache\xrxscnui.dll
2008-11-20 00:38 . 2001-08-17 21:28 794,654 --a------ c:\windows\system32\dllcache\usr1801.sys
2008-11-20 00:37 . 2001-08-23 17:47 525,568 --a------ c:\windows\system32\dllcache\tridxp.dll
2008-11-20 00:36 . 2001-08-17 22:01 241,664 --a------ c:\windows\system32\dllcache\tosdvd02.sys
2008-11-20 00:35 . 2001-08-23 16:57 286,848 --a------ c:\windows\system32\dllcache\stlnata.sys
2008-11-20 00:34 . 2001-08-23 17:47 238,592 --a------ c:\windows\system32\dllcache\sisgrv.dll
2008-11-20 00:33 . 2001-08-23 17:46 386,560 --a------ c:\windows\system32\dllcache\sgiul50.dll
2008-11-20 00:32 . 2001-08-23 17:47 495,616 --a------ c:\windows\system32\dllcache\sblfx.dll
2008-11-20 00:31 . 2001-08-23 17:18 899,914 --a------ c:\windows\system32\dllcache\r2mdkxga.sys
2008-11-20 00:30 . 2001-08-17 22:05 351,616 --a------ c:\windows\system32\dllcache\ovcodek2.sys
2008-11-20 00:29 . 2001-08-17 20:50 198,144 --a------ c:\windows\system32\dllcache\nv3.sys
2008-11-20 00:28 . 2001-08-23 17:09 131,072 --a------ c:\windows\system32\dllcache\n100325.sys
2008-11-20 00:27 . 2001-08-17 21:28 802,683 --a------ c:\windows\system32\dllcache\ltsm.sys
2008-11-20 00:26 . 2001-08-23 17:47 372,824 --a------ c:\windows\system32\dllcache\iconf32.dll
2008-11-20 00:25 . 2008-04-14 04:33 702,845 --a------ c:\windows\system32\dllcache\i81xdnt5.dll
2008-11-20 00:24 . 2001-08-23 17:46 1,733,120 --a------ c:\windows\system32\dllcache\g400d.dll
2008-11-20 00:23 . 2001-08-23 17:16 596,319 --a------ c:\windows\system32\dllcache\es56cvmp.sys
2008-11-20 00:22 . 2001-08-17 20:14 952,007 --a------ c:\windows\system32\dllcache\diwan.sys
2008-11-20 00:21 . 2001-08-23 17:47 622,621 --a------ c:\windows\system32\dllcache\digiview.exe
2008-11-20 00:20 . 2001-08-23 17:04 980,034 --a------ c:\windows\system32\dllcache\cicap.sys
2008-11-20 00:19 . 2001-08-17 21:28 762,780 --a------ c:\windows\system32\dllcache\3cwmcru.sys
2008-11-18 21:55 . 2008-11-18 21:58 <REP> d-------- c:\windows\avxoscan
2008-11-13 22:43 . 2008-11-13 22:53 <REP> d-------- d:\documents and settings\Chris\Application Data\Red Alert 3
2008-11-13 22:34 . 2006-03-23 14:23 454,656 --a------ c:\windows\system32\snapapi32.dll
2008-11-13 22:02 . 2008-11-13 22:02 <REP> d-------- c:\windows\Logs
2008-11-13 22:02 . 2008-11-13 22:02 <REP> d-------- c:\program files\Electronic Arts
2008-11-13 22:02 . 2008-05-30 14:11 3,850,760 --a------ c:\windows\system32\D3DX9_38.dll
2008-11-13 22:02 . 2007-07-19 18:14 3,727,720 --a------ c:\windows\system32\d3dx9_35.dll
2008-11-13 22:02 . 2008-05-30 14:11 1,491,992 --a------ c:\windows\system32\D3DCompiler_38.dll
2008-11-13 22:02 . 2007-07-19 18:14 1,358,192 --a------ c:\windows\system32\D3DCompiler_35.dll
2008-11-13 22:02 . 2008-05-30 14:11 467,984 --a------ c:\windows\system32\d3dx10_38.dll
2008-11-13 22:02 . 2007-07-19 18:14 444,776 --a------ c:\windows\system32\d3dx10_35.dll
2008-11-13 07:04 . 2008-04-13 20:47 25,856 --a------ c:\windows\system32\drivers\usbprint.sys
2008-11-13 07:04 . 2008-04-13 20:47 25,856 --a------ c:\windows\system32\dllcache\usbprint.sys
2008-11-05 04:21 . 2008-11-05 04:21 <REP> d-------- c:\program files\Fichiers communs\Adobe AIR
2008-10-30 18:48 . 2008-10-30 18:48 0 --a------ c:\windows\ativpsrm.bin
2008-10-30 18:40 . 2008-10-30 18:43 1,877 --a------ c:\windows\ATICIM.INI
2008-10-30 18:20 . 2008-10-30 18:39 <REP> d-------- C:\ATI
2008-10-30 17:57 . 2008-10-30 18:32 <REP> d-------- d:\documents and settings\All Users\Application Data\ma-config.com
2008-10-28 23:36 . 2008-10-28 23:36 823,296 --a------ c:\windows\system32\divx_xx0c.dll
2008-10-28 23:36 . 2008-10-28 23:36 823,296 --a------ c:\windows\system32\divx_xx07.dll
2008-10-28 23:35 . 2008-10-28 23:35 815,104 --a------ c:\windows\system32\divx_xx0a.dll
2008-10-28 23:35 . 2008-10-28 23:35 802,816 --a------ c:\windows\system32\divx_xx11.dll
2008-10-28 23:35 . 2008-10-28 23:35 684,032 --a------ c:\windows\system32\DivX.dll
2008-10-16 00:04 . 2008-08-14 14:23 2,191,232 --a------ c:\windows\system32\dllcache\ntoskrnl.exe
2008-10-16 00:04 . 2008-08-14 14:23 2,068,096 --a------ c:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-10 21:38 . 2008-10-10 21:38 <REP> d-------- c:\windows\system32\fr
2008-10-10 21:38 . 2008-10-10 21:38 <REP> d-------- c:\windows\system32\bits
2008-10-10 21:38 . 2008-10-10 21:38 <REP> d-------- c:\windows\l2schemas
2008-10-10 21:36 . 2008-10-10 21:38 <REP> d-------- c:\windows\ServicePackFiles
2008-10-10 21:27 . 2008-10-10 21:27 <REP> d-------- c:\windows\EHome
2008-10-08 19:38 . 2004-08-03 23:38 327,168 --------- c:\windows\system32\drivers\ati2mtaa.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-30 01:30 --------- d-----w c:\program files\Spybot - Search & Destroy
2008-11-30 00:52 --------- d---a-w d:\documents and settings\All Users\Application Data\TEMP
2008-11-29 16:52 --------- d-----w d:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-29 00:05 --------- d-----w d:\documents and settings\Chris\Application Data\Hamachi
2008-11-27 23:44 --------- d-----w d:\documents and settings\Chris\Application Data\OpenOffice.org2
2008-11-22 23:01 --------- d-----w d:\documents and settings\Chris\Application Data\uTorrent
2008-11-19 15:13 --------- d-----w c:\program files\Assistant Dartybox
2008-11-11 18:31 --------- d-----w c:\program files\DivX
2008-11-11 17:08 --------- d-----w c:\program files\Messenger Plus! Live
2008-11-05 03:20 --------- d-----w c:\program files\Fichiers communs\Adobe
2008-11-03 03:15 --------- d-----w d:\documents and settings\Chris\Application Data\codeblocks
2008-10-30 17:45 --------- d-----w c:\program files\ATI Technologies
2008-10-30 17:42 --------- d-----w d:\documents and settings\Chris\Application Data\ATI
2008-10-30 17:20 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-26 02:11 --------- d-----w c:\program files\CodeBlocks
2008-10-24 19:59 --------- d-----w c:\program files\Valve
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2007-08-16 00:01 357 ----a-w d:\documents and settings\Chris\.cb_layout.bin
2006-05-03 09:06 163,328 --sh--r c:\windows\system32\flvDX.dll
2007-02-21 10:47 31,232 --sh--r c:\windows\system32\msfDX.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SmpcSys"="c:\apps\SMP\SmpSys.exe" [2005-11-17 975360]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Ulead AutoDetector v2"="c:\program files\Fichiers communs\Ulead Systems\AutoDetector\monitor.exe" [2004-11-26 90112]
"ACTIVBOARD"="c:\apps\ABoard\ABoard.exe" [2003-05-02 24576]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-05-16 180269]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2008-11-29 1796856]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 c:\windows\system32\HdAShCut.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-11-30 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\aaacddfbc]
2001-09-16 12:29 313871 c:\windows\system32\aaacddfbc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\eccceaaccfeebcf]
2008-11-30 12:41 312847 c:\windows\system32\eccceaaccfeebcf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"msacm.dvacm"= c:\progra~1\FICHIE~1\ULEADS~1\Vio\Dvacm.acm
"msacm.ulmp3acm"= c:\progra~1\FICHIE~1\ULEADS~1\MPEG\ulmp3acm.acm
"msacm.mpegacm"= c:\progra~1\FICHIE~1\ULEADS~1\MPEG\mpegacm.acm
"vidc.VP31"= vp31vfw.dll
"vidc.VP40"= vp4vfw.dll
"vidc.VP50"= vp5vfw.dll
"VIDC.HFYU"= huffyuv.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, snapapi32.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati3xnxx.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winka33.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winkf41.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winqq63.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winvb06.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winwc03.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winxs14.sys]
@="Driver"
[HKLM\~\startupfolder\D:^Documents and Settings^Chris^Menu Démarrer^Programmes^Démarrage^Adobe Gamma.lnk]
backup=c:\windows\pss\Adobe Gamma.lnkStartup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlayerKiosquePlus
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\L'Assistant DartyBox]
--a------ 2007-06-05 21:15 151552 c:\program files\Assistant Dartybox\upgrade_manager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService]
--a------ 2005-11-16 13:11 143360 c:\apps\Powercinema\PCMService.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-05-16 21:40 98304 c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
-rahs---- 2008-01-28 11:43 2097488 c:\program files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Vade Retro Outlook Express]
--a------ 2004-10-04 12:03 310272 c:\progra~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Lecteur CANALPLAY\\CanalPlayer.exe"=
"c:\\Program Files\\Lecteur CANALPLAY\\CanalPlayerHelper.exe"=
"c:\\APPS\\skype\\phone\\Skype.exe"=
"c:\\Program Files\\FlashGet\\FlashGet.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R0 pxark;pxark;c:\windows\system32\drivers\pxark.sys [2008-11-29 26680]
S0 ati3xnxx;ati3xnxx;c:\windows\system32\Drivers\ati3xnxx.sys []
S0 diuf;diuf;c:\windows\system32\drivers\thajfhIz.sys []
S0 e03ae563ff6792eb14aec79a7a2ebd53;e03ae563ff6792eb14aec79a7a2ebd53;c:\windows\system32\e03ae563ff6792eb14aec79a7a2ebd53.sys []
S0 lzum;lzum;c:\windows\system32\drivers\cjmqbd.sys []
S1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\DRIVERS\cmdguard.sys [2008-11-29 99216]
S1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\DRIVERS\cmdhlp.sys [2008-11-29 31504]
S2 CSIScanner;CSIScanner;"c:\program files\PrevxCSI\prevxcsi.exe" /service [2008-11-29 920632]
S3 3xHybrid;3xHybrid service;c:\windows\system32\DRIVERS\3xHybrid.sys [2006-05-16 799744]
S3 Winka33;Winka33;\??\c:\windows\System32\drivers\Winka33.sys []
S3 Winkf41;Winkf41;\??\c:\windows\System32\drivers\Winkf41.sys []
S3 Winqq63;Winqq63;\??\c:\windows\System32\drivers\Winqq63.sys []
S3 Winvb06;Winvb06;\??\c:\windows\System32\drivers\Winvb06.sys []
S3 Winwc03;Winwc03;\??\c:\windows\System32\drivers\Winwc03.sys []
S3 Winxs14;Winxs14;\??\c:\windows\System32\drivers\Winxs14.sys []
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{934771FA-7BB2-4917-8AA0-A7C6358987A3} - c:\windows\system32\rqRJywtr.dll
BHO-{E75C7274-429B-41E8-9E7A-B35D55EEEA76} - (no file)
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
HKCU-Run-rs32net - c:\windows\System32\rs32net.exe
HKLM-Run-Malwarebytes Anti-Malware (reboot) - c:\program files\Malwarebytes' Anti-Malware\mbam.exe
HKU-Default-Run-[system] - c:\windows\system32\drivers\services.exe
HKU-Default-Run-winlogon - d:\documents and settings\LocalService\svchost.exe
Notify-zacoqh - zacoqh.dll
.
------- Examen supplémentaire -------
.
FireFox -: Profile - d:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\r5isbyiz.default\
FF -: plugin - c:\program files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-30 12:51:39
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(268)
c:\windows\system32\aaacddfbc.dll
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\eccceaaccfeebcf.dll
.
Heure de fin: 2008-11-30 12:56:57 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-11-30 11:56:53
Avant-CF: 6,213,906,432 octets libres
Après-CF: 6,105,206,784 octets libres
322 --- E O F --- 2008-11-13 02:02:37
[b]SDFix: Version 1.240
/b
Run by Chris on 30/11/2008 at 13:08
Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix
[b]Checking Services
/b:
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
[b]Checking Files
/b:
Trojan Files Found:
C:\WINDOWS\SYSTEM32\TDSSTKDV.log - Deleted
Removing Temp Files
[b]ADS Check
/b:
[b]Final Check
/b:
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-30 13:18:25
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"h0"=dword:00000001
"hdf12"=hex:ba,f8,8e,a2,99,e0,94,0d,4c,fc,8b,fb,53,ed,c5,aa,66,1c,09,06,4d,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:28,6f,2a,25,a6,8d,ef,33,e7,7f,fd,17,22,5f,94,d4,a6,5a,9f,41,d5,..
"p0"="D:\Documents and Settings\Chris\Mes documents\Programmes\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,24,78,78,27,85,e3,80,75,c4,09,69,bc,18,29,5e,62,ea,..
"khjeh"=hex:13,d4,04,c2,f4,17,8e,1c,e8,77,28,fa,7c,76,d7,b6,86,41,10,c2,e9,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:87,bc,b6,cd,c6,dd,94,06,c2,9d,f2,7e,6d,98,7a,5e,34,b1,0e,7a,7e,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"h0"=dword:00000001
"hdf12"=hex:ba,f8,8e,a2,99,e0,94,0d,4c,fc,8b,fb,53,ed,c5,aa,66,1c,09,06,4d,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:28,6f,2a,25,a6,8d,ef,33,e7,7f,fd,17,22,5f,94,d4,a6,5a,9f,41,d5,..
"p0"="D:\Documents and Settings\Chris\Mes documents\Programmes\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,24,78,78,27,85,e3,80,75,c4,09,69,bc,18,29,5e,62,ea,..
"khjeh"=hex:13,d4,04,c2,f4,17,8e,1c,e8,77,28,fa,7c,76,d7,b6,86,41,10,c2,e9,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:c0,2e,1b,3c,c6,e5,63,ec,f3,c0,37,1a,70,2e,87,1b,91,95,0b,76,9d,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"h0"=dword:00000001
"hdf12"=hex:ba,f8,8e,a2,99,e0,94,0d,4c,fc,8b,fb,53,ed,c5,aa,66,1c,09,06,4d,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:28,6f,2a,25,a6,8d,ef,33,e7,7f,fd,17,22,5f,94,d4,a6,5a,9f,41,d5,..
"p0"="D:\Documents and Settings\Chris\Mes documents\Programmes\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,24,78,78,27,85,e3,80,75,c4,09,69,bc,18,29,5e,62,ea,..
"khjeh"=hex:13,d4,04,c2,f4,17,8e,1c,e8,77,28,fa,7c,76,d7,b6,86,41,10,c2,e9,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:87,bc,b6,cd,c6,dd,94,06,c2,9d,f2,7e,6d,98,7a,5e,34,b1,0e,7a,7e,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:197cdda4
"s2"=dword:9a6d0e03
"h0"=dword:00000002
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"h0"=dword:00000001
"hdf12"=hex:ba,f8,8e,a2,99,e0,94,0d,4c,fc,8b,fb,53,ed,c5,aa,66,1c,09,06,4d,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:28,6f,2a,25,a6,8d,ef,33,e7,7f,fd,17,22,5f,94,d4,a6,5a,9f,41,d5,..
"p0"="D:\Documents and Settings\Chris\Mes documents\Programmes\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,24,78,78,27,85,e3,80,75,c4,09,69,bc,18,29,5e,62,ea,..
"khjeh"=hex:13,d4,04,c2,f4,17,8e,1c,e8,77,28,fa,7c,76,d7,b6,86,41,10,c2,e9,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:87,bc,b6,cd,c6,dd,94,06,c2,9d,f2,7e,6d,98,7a,5e,34,b1,0e,7a,7e,..
scanning hidden registry entries ...
scanning hidden files ...
folder error: D:\Documents and Settings\Chris
[b]Remaining Services
/b:
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%ProgramFiles%\\AOL 9.0\\aol.exe"="%ProgramFiles%\\AOL 9.0\\aol.exe:*:Enabled:AOL"
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"="%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe:*:Enabled:SPLINTER CELL PANDORA"
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"="%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe:*:Enabled:PANDORA"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Lecteur CANALPLAY\\CanalPlayer.exe"="C:\\Program Files\\Lecteur CANALPLAY\\CanalPlayer.exe:*:Enabled:Lecteur CANALPLAY"
"C:\\Program Files\\Lecteur CANALPLAY\\CanalPlayerHelper.exe"="C:\\Program Files\\Lecteur CANALPLAY\\CanalPlayerHelper.exe:*:Enabled:Lecteur CANALPLAY Helper"
"C:\\APPS\\skype\\phone\\Skype.exe"="C:\\APPS\\skype\\phone\\Skype.exe:*:Enabled:Skype"
"D:\\Documents and Settings\\Chris\\Mes documents\\Programmes\\Torrents\\utorrent\\utorrent.exe"="D:\\Documents and Settings\\Chris\\Mes documents\\Programmes\\Torrents\\utorrent\\utorrent.exe:*:Enabled:æTorrent"
"C:\\Program Files\\FlashGet\\FlashGet.exe"="C:\\Program Files\\FlashGet\\FlashGet.exe:*:Enabled:Flashget"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\AOL 9.0\\waol.exe"="C:\\Program Files\\AOL 9.0\\waol.exe:*:Enabled:AOL 9.0"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[b]Remaining Files
/b:
File Backups: - C:\SDFix\backups\backups.zip
[b]Files with Hidden Attributes
/b:
Tue 16 May 2006 215 A.SHR --- "C:\BOOT.BAK"
Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Wed 3 May 2006 163,328 ..SHR --- "C:\WINDOWS\system32\flvDX.dll"
Wed 21 Feb 2007 31,232 ..SHR --- "C:\WINDOWS\system32\msfDX.dll"
Wed 23 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\523d056929e13eacf8392044f602e53e\BIT3.tmp"
Wed 27 Aug 2008 6,321,327 ...H. --- "C:\WINDOWS\SoftwareDistribution\Download\83e78f78de649dcc1fe8dd492dc7d60b\BIT4.tmp"
Fri 14 Sep 2007 38,982 ...H. --- "C:\WINDOWS\SoftwareDistribution\Download\ac67bfa420e16e3ec2485fdb23d07a09\BIT2.tmp"
Wed 23 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\afa5528a2269b5106016bdbc1ea3037f\BIT2.tmp"
Fri 14 Sep 2007 12,762,810 ...H. --- "C:\WINDOWS\SoftwareDistribution\Download\d2e4eab6f85e4a42f68820cdfc5cf099\BIT3.tmp"
Wed 7 May 2008 3,534,838 ...H. --- "C:\WINDOWS\SoftwareDistribution\Download\dfdb2f77c38f570ae606ca40a868b7fd\BIT8.tmp"
Fri 10 Nov 2006 74,929 ...H. --- "C:\WINDOWS\SoftwareDistribution\Download\eb9936ed2cd1d6377771752504085123\BIT7.tmp"
Tue 31 May 2005 106,496 A..H. --- "C:\Program Files\Fichiers communs\aolshare\shell\fr\shellext.dll"
[b]Finished!
/b