voici ce que j ai eu comme rapport
** Rapport MyHosts.txt **
MyHosts V.1.0.0.2 de jeanmimigab
Merci à la team MH, W-T ,C_XX, Laddy et à Batch_man pour leurs aides
Résultat de l'opération:restauration du fichier hosts réussi...
** Fin du rapport **
et
ComboFix 10-04-02.01 - MALEK 03/04/2010 18:06:56.1.2 - x86
Microsoft Windows XP Professionnel 5.1.2600.3.1256.213.1036.18.2042.1524 [GMT 2:00]
Running from: D:\ComboFix.exe
AV: avast! antivirus 4.8.1296 [VPS 081219-0] *On-access scanning disabled* (Outdated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\MALEK\Application Data\avdrn.dat
c:\documents and settings\MALEK\Application Data\wiaservg.log
c:\progra~1\MAWSOA~1\MAWSoa~1.exe
c:\recycler\S-1-5-21-0243936033-3052116371-381863308-1811
c:\recycler\S-1-5-21-1070972115-6058489422-658035354-9397
c:\recycler\S-1-5-21-1973775008-6522796968-005040316-7566
c:\recycler\S-1-5-21-2395995132-6931831237-181910818-8697
c:\recycler\S-1-5-21-3147640654-1635475592-597360052-1078
c:\recycler\S-1-5-21-5907251128-4105741676-614152275-8085
c:\recycler\S-1-5-21-7829472605-0074430111-185447458-4332
c:\recycler\S-1-5-21-8203559153-2590513075-330188238-6187
c:\recycler\S-1-5-21-9694202095-1591496987-448258944-5978
c:\windows\AppPatch\AcAdProc.dll
c:\windows\system32\Cache
c:\windows\system32\setting.ini
c:\windows\system32\sshnas21.dll
c:\windows\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
c:\windows\Tasks\{66BA574B-1E11-49b8-909C-8CC9E0E8E015}.job
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SSHNAS
-------\Service_SSHNAS
((((((((((((((((((((((((( Files Created from 2010-03-03 to 2010-04-03 )))))))))))))))))))))))))))))))
.
2010-04-03 16:12 . 2010-04-03 16:12 -------- d-----w- c:\windows\system32\xircom
2010-04-03 16:12 . 2010-04-03 16:12 -------- d-----w- c:\windows\system32\wbem\snmp
2010-04-03 16:12 . 2010-04-03 16:12 -------- d-----w- c:\windows\srchasst
2010-04-03 15:20 . 2010-04-03 15:20 -------- d-----w- C:\MyHosts
2010-04-03 13:53 . 2010-04-03 16:09 -------- d-----w- c:\program files\Mawsoaat Hadeeth
2010-04-03 13:13 . 2008-11-26 16:16 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2010-04-03 13:13 . 2008-11-26 16:16 50864 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2010-04-03 13:13 . 2008-11-26 16:15 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2010-04-03 13:13 . 2008-11-26 16:17 111184 ----a-w- c:\windows\system32\drivers\aswSP.sys
2010-04-03 13:13 . 2008-11-26 16:17 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2010-04-03 13:13 . 2008-11-26 16:15 97480 ----a-w- c:\windows\system32\AvastSS.scr
2010-04-03 13:13 . 2008-11-26 16:18 93296 ----a-w- c:\windows\system32\drivers\aswmon.sys
2010-04-03 13:13 . 2008-11-26 16:18 94032 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2010-04-03 13:13 . 2008-11-26 16:21 1236208 ----a-w- c:\windows\system32\aswBoot.exe
2010-04-03 11:55 . 2010-04-03 11:55 10752 ----a-w- c:\windows\DCEBoot.exe
2010-04-03 11:48 . 2009-05-07 07:04 157712 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2010-04-03 11:32 . 2010-04-03 11:32 -------- d-----w- c:\program files\Trend Micro
2010-04-03 11:18 . 2008-04-14 11:00 26624 ----a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2010-04-03 11:12 . 2010-04-03 11:12 -------- d-----w- c:\program files\ATI
2010-04-03 03:15 . 2010-04-03 12:49 -------- d-----w- c:\windows\AntiWPA
2010-04-03 02:32 . 2010-04-03 02:32 -------- d-sh--w- c:\documents and settings\MALEK\IECompatCache
2010-04-03 02:31 . 2010-04-03 02:31 -------- d-sh--w- c:\documents and settings\MALEK\PrivacIE
2010-04-03 02:30 . 2010-04-03 02:30 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2010-04-03 02:30 . 2010-04-03 02:30 -------- d-sh--w- c:\documents and settings\MALEK\IETldCache
2010-04-03 02:27 . 2010-04-03 02:27 -------- d-----w- c:\windows\IIS Temporary Compressed Files
2010-04-03 02:27 . 2001-08-23 13:17 23040 ----a-w- c:\windows\system32\regtrace.exe
2010-04-03 02:27 . 2001-08-23 13:17 7168 ----a-w- c:\windows\system32\snprfdll.dll
2010-04-03 02:27 . 2001-08-23 13:17 12800 ----a-w- c:\windows\system32\smtpctrs.dll
2010-04-03 02:27 . 2001-08-23 13:17 43520 ----a-w- c:\windows\system32\fcachdll.dll
2010-04-03 02:27 . 2001-08-23 13:16 5632 ----a-w- c:\windows\system32\adsiisex.dll
2010-04-03 02:27 . 2010-04-03 02:27 -------- d--h--w- c:\windows\msdownld.tmp
2010-04-03 02:27 . 2008-04-14 11:00 5632 ----a-w- c:\windows\system32\write.exe
2010-04-03 02:22 . 2010-02-25 06:17 247808 ------w- c:\windows\system32\dllcache\ieproxy.dll
2010-04-03 02:22 . 2010-02-25 06:17 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2010-04-03 02:20 . 2010-02-16 04:50 64000 ------w- c:\windows\system32\dllcache\iecompat.dll
2010-04-03 02:09 . 2010-04-03 02:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2010-04-03 01:47 . 2009-08-06 14:54 44768 ----a-w- c:\windows\system32\wups2.dll
2010-04-03 01:37 . 2009-03-08 00:03 759296 ----a-w- c:\windows\system32\dllcache\VGX.dll
2010-04-03 01:21 . 2008-04-14 11:00 13312 ----a-w- c:\windows\system32\irclass.dll
2010-04-03 01:21 . 2008-04-14 11:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2010-04-02 23:44 . 2010-04-02 23:26 179200 ----a-w- c:\windows\Tnygob.exe
2010-04-02 23:33 . 2010-04-02 23:33 -------- d-----w- c:\program files\Fichiers communs\xing shared
2010-04-02 23:26 . 2010-04-03 16:12 823808 ----a-w- c:\windows\system32\drivers\kuhaqb.sys
2010-04-02 23:25 . 2010-04-02 23:26 135168 ----a-w- c:\windows\ndll.exe
2010-04-02 23:25 . 2010-04-03 11:55 -------- d-----w- c:\documents and settings\MALEK\Application Data\vlc
2010-04-02 23:24 . 2010-04-02 23:24 179200 ----a-w- c:\windows\Tnygoa.exe
2010-04-02 23:24 . 2010-04-02 23:33 -------- d-----w- c:\program files\Fichiers communs\Real
2010-04-02 23:24 . 2010-04-02 23:24 -------- d-----w- c:\program files\Real
2010-04-02 23:20 . 2010-04-02 23:20 -------- d-----w- c:\program files\VideoLAN
2010-04-02 23:14 . 2010-04-02 23:14 737280 ----a-w- c:\windows\iun6002.exe
2010-04-02 23:14 . 2010-04-02 23:14 -------- d-----w- c:\windows\system32\athan
2010-04-02 23:14 . 2010-04-02 23:14 -------- d-----w- c:\program files\Athan
2010-04-02 23:04 . 2008-04-13 10:39 5504 ----a-w- c:\windows\system32\drivers\MSTEE.sys
2010-04-02 23:04 . 2008-04-13 10:46 85248 ----a-w- c:\windows\system32\drivers\NABTSFEC.sys
2010-04-02 23:04 . 2008-04-13 10:46 17024 ----a-w- c:\windows\system32\drivers\CCDECODE.sys
2010-04-02 23:04 . 2008-04-13 10:46 19200 ----a-w- c:\windows\system32\drivers\WSTCODEC.SYS
2010-04-02 23:04 . 2001-08-17 20:59 3072 ----a-w- c:\windows\system32\drivers\audstub.sys
2010-04-02 23:03 . 2008-04-13 16:33 54784 ----a-w- c:\windows\system32\vfwwdm32.dll
2010-04-02 23:03 . 2008-04-13 16:33 4096 ----a-w- c:\windows\system32\ksuser.dll
2010-04-02 23:03 . 2008-04-13 10:46 121984 ----a-w- c:\windows\system32\drivers\usbvideo.sys
2010-04-02 23:03 . 2008-04-13 17:57 58752 ----a-w- c:\windows\system32\drivers\redbook.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-03 16:12 . 2010-04-03 16:12 -------- d-----w- c:\program files\microsoft frontpage
2010-04-03 12:47 . 2010-04-02 21:24 -------- d-----w- c:\program files\FileZilla FTP Client
2010-04-03 11:13 . 2010-04-02 21:49 83400 ----a-w- c:\documents and settings\MALEK\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-04-03 02:28 . 2008-04-14 11:00 567752 ----a-w- c:\windows\system32\perfh00C.dat
2010-04-03 02:28 . 2008-04-14 11:00 107092 ----a-w- c:\windows\system32\perfc00C.dat
2010-04-03 01:42 . 2010-04-03 01:42 8 ----a-w- c:\documents and settings\NetworkService\Application Data\zcbmvn.dat
2010-04-03 01:33 . 2010-04-02 21:07 23660 ----a-w- c:\windows\system32\emptyregdb.dat
2010-04-03 01:32 . 2010-04-02 21:07 -------- d-----w- c:\program files\Windows Media Connect 2
2010-04-02 23:33 . 2010-04-02 21:24 499712 ----a-w- c:\windows\system32\msvcp71.dll
2010-04-02 23:02 . 2010-04-02 22:55 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-04-02 22:59 . 2010-04-02 22:58 -------- d-----w- c:\program files\Microsoft Works
2010-04-02 22:58 . 2010-04-02 21:21 -------- d-----w- c:\program files\MSBuild
2010-04-02 22:57 . 2010-04-02 22:57 -------- d-----w- c:\program files\Microsoft.NET
2010-04-02 22:56 . 2010-04-02 22:56 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2010-04-02 22:54 . 2010-04-02 22:54 -------- d-----w- c:\program files\Alwil Software
2010-04-02 22:29 . 2010-04-02 22:29 -------- d-----w- c:\documents and settings\MALEK\Application Data\Intel
2010-04-02 22:28 . 2010-04-02 22:28 -------- d-----w- c:\program files\Fichiers communs\Intel
2010-04-02 22:28 . 2010-04-02 22:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Intel
2010-04-02 22:28 . 2010-04-02 21:31 -------- d-----w- c:\program files\Intel
2010-04-02 22:01 . 2010-04-02 22:01 -------- d-----w- c:\program files\ma-config.com
2010-04-02 22:01 . 2010-04-02 22:01 -------- d-----w- c:\documents and settings\All Users\Application Data\ma-config.com
2010-04-02 21:49 . 2010-04-02 21:49 -------- d-----w- c:\program files\DIFX
2010-04-02 21:49 . 2010-04-02 21:49 -------- d-----w- c:\documents and settings\MALEK\Application Data\ATI
2010-04-02 21:49 . 2010-04-02 21:49 -------- d-----w- c:\documents and settings\All Users\Application Data\ATI
2010-04-02 21:47 . 2010-04-02 21:47 0 ----a-w- c:\windows\ativpsrm.bin
2010-04-02 21:46 . 2010-04-02 21:44 -------- d-----w- c:\program files\ATI Technologies
2010-04-02 21:45 . 2010-04-02 21:35 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-04-02 21:44 . 2010-04-02 21:37 -------- d-----w- c:\program files\Fichiers communs\InstallShield
2010-04-02 21:37 . 2010-04-02 21:37 -------- d-----w- c:\program files\Analog Devices
2010-04-02 21:37 . 2010-04-02 21:37 -------- d-----w- c:\program files\Hewlett-Packard
2010-04-02 21:35 . 2010-04-02 21:35 -------- d-----w- c:\program files\Fichiers communs\SNP2UVC
2010-04-02 21:35 . 2010-04-02 21:35 -------- d-----w- c:\documents and settings\MALEK\Application Data\InstallShield
2010-04-02 21:27 . 2010-04-02 21:27 -------- d-----w- c:\program files\Marvell
2010-04-02 21:25 . 2010-04-02 21:25 -------- d-----w- c:\program files\Windows Live
2010-04-02 21:25 . 2010-04-02 21:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2010-04-02 21:25 . 2010-04-02 21:25 -------- d-----w- c:\program files\QT Lite
2010-04-02 21:24 . 2010-04-02 21:24 -------- d-----w- c:\program files\Real Alternative
2010-04-02 21:24 . 2010-04-02 21:24 -------- d-----w- c:\program files\K-Lite Codec Pack
2010-04-02 21:24 . 2010-04-02 21:24 -------- d-----w- c:\program files\Foxit Reader
2010-04-02 21:24 . 2010-04-02 21:24 -------- d-----w- c:\program files\7-Zip
2010-04-02 21:24 . 2010-04-02 21:24 -------- d-----w- c:\program files\SuperCopier2
2010-04-02 21:23 . 2010-04-02 21:23 410976 ----a-w- c:\windows\system32\deploytk.dll
2010-04-02 21:23 . 2010-04-02 21:23 -------- d-----w- c:\program files\Java
2010-04-02 21:21 . 2010-04-02 21:21 65800 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-04-02 21:21 . 2010-04-02 21:21 -------- d-----w- c:\program files\Reference Assemblies
2010-04-02 21:10 . 2010-04-02 21:09 86331 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-04-02 21:09 . 2010-04-02 21:09 -------- d-----w- c:\program files\Services en ligne
2010-02-25 06:17 . 2008-08-26 07:11 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-28 14:12 . 2009-04-01 05:28 95232 ----a-w- c:\windows\system32\drivers\AtiHdmi.sys
2010-01-19 14:43 . 2010-01-19 14:43 204800 ----a-w- c:\windows\system32\NetProvCredMan.dll
2010-01-19 14:34 . 2010-01-19 14:34 16896 ----a-w- c:\windows\system32\S24NCfg.dll
2010-01-13 06:24 . 2010-04-02 22:29 6598656 ----a-w- c:\windows\system32\drivers\NETw5x32.sys
2010-01-08 10:23 . 2010-01-08 10:23 364544 ----a-w- c:\windows\system32\yk51x86.dll
2010-01-08 10:23 . 2010-01-08 10:23 299008 ----a-w- c:\windows\system32\drivers\yk51x86.sys
.
------- Sigcheck -------
[-] 2008-10-30 . E248A8391D7388A0A3679D1FB33E003D . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
[-] 2008-10-01 . 33578A738C564B4F84D906EFD91025E5 . 1571840 . . [5.1.2600.5512] . . c:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_2"="shell32" [X]
"_nltide_3"="advpack.dll" [2009-03-08 128512]
c:\documents and settings\MALEK\Menu D‚marrer\Programmes\D‚marrage\
zipdkg32.exe [2008-4-14 36864]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
"NoSMMyDocs"= 1 (0x1)
"NoSMMyPictures"= 1 (0x1)
"NoStartMenuMyMusic"= 1 (0x1)
"NoNetworkConnections"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
R0 SFAUDIO;Sonic Focus DSP Driver;c:\windows\system32\drivers\sfaudio.sys [28/03/2008 11:14 24064]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [03/04/2010 15:13 111184]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [03/04/2010 15:13 20560]
--- Other Services/Drivers In Memory ---
*Deregistered* - kuhaqb
.
- - - - ORPHANS REMOVED - - - -
HKU-Default-RunOnce-tscuninstall - c:\windows\system32\tscupgrd.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-04-03 18:12
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\kuhaqb]
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(548)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\netprovcredman.dll
- - - - - - - > 'explorer.exe'(3240)
c:\windows\system32\webcheck.dll
c:\windows\system32\wpdshserviceobj.dll
c:\windows\system32\portabledevicetypes.dll
c:\windows\system32\portabledeviceapi.dll
c:\windows\system32\eappprxy.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Intel\WiFi\bin\S24EvMon.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Intel\WiFi\bin\EvtEng.exe
c:\windows\system32\inetsrv\inetinfo.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Fichiers communs\Intel\WirelessCommon\RegSrvc.exe
c:\windows\system32\wbem\unsecapp.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\Alwil Software\Avast4\setup\avast.setup
c:\windows\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2010-04-03 18:14:46 - machine was rebooted
ComboFix-quarantined-files.txt 2010-04-03 16:14
Pre-Run: 45 293 228 032 octets libres
Post-Run: 45 436 526 592 octets libres
Current=2 Default=2 Failed=0 LastKnownGood=4 Sets=1,2,3,4
- - End Of File - - 2097C2ED95810797F58CC6545AD8A982
apparamment le probleme est reglé..............