voici le rapport combofix :
ComboFix 10-03-21.05 - ams dane 22/03/2010 17:43:38.1.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.959.579 [GMT 1:00]
Lancé depuis: f:\documents and settings\ams dane\Mes documents\Téléchargements\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Uninstall.exe
C:\WinRAR.exe
f:\recycler\S-1-5-21-1078081533-329068152-1417001333-1004
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-02-22 au 2010-03-22 ))))))))))))))))))))))))))))))))))))
.
2010-03-22 13:40 . 2010-03-22 13:43 -------- d-----w- f:\program files\navilog1
2010-03-22 13:35 . 2010-03-22 13:43 -------- d---a-w- F:\Navilog1
2010-03-22 13:28 . 2010-03-22 13:28 -------- d-----w- f:\program files\Trend Micro
2010-03-16 17:13 . 2010-03-16 17:13 -------- d-----w- f:\documents and settings\ams dane\Application Data\Malwarebytes
2010-03-16 17:13 . 2010-01-07 15:07 38224 ----a-w- f:\windows\system32\drivers\mbamswissarmy.sys
2010-03-16 17:13 . 2010-03-16 17:29 -------- d-----w- f:\program files\Malwarebytes' Anti-Malware
2010-03-16 17:13 . 2010-03-16 17:13 -------- d-----w- f:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-16 17:13 . 2010-01-07 15:07 19160 ----a-w- f:\windows\system32\drivers\mbam.sys
2010-03-16 17:12 . 2004-02-23 00:00 1386496 ----a-w- f:\windows\system32\msvbvm60.dll
2010-03-16 14:27 . 2010-03-16 14:27 -------- d-----w- f:\windows\system32\wbem\Repository
2010-03-15 20:25 . 2010-03-15 20:25 -------- d-----w- f:\program files\Winamp Detect
2010-03-15 20:24 . 2009-11-01 21:12 -------- d-----w- f:\program files\Winamp
2010-03-15 15:56 . 2010-03-15 15:56 -------- d-----w- f:\program files\SpacialAudio
2010-03-15 15:56 . 2009-07-22 16:46 450560 ----a-w- f:\windows\system32\GDS32.DLL
2010-03-15 15:56 . 2010-03-15 15:56 -------- d-----w- f:\program files\Firebird
2010-03-15 13:48 . 2010-03-15 13:50 -------- d-----w- f:\documents and settings\All Users\Application Data\OrbNetworks
2010-03-15 13:48 . 2010-03-15 13:48 -------- d-----w- f:\program files\Orb Networks
2010-03-15 00:23 . 2010-03-15 20:21 -------- d-----w- f:\program files\StationPlaylist
2010-03-13 23:29 . 2009-11-01 22:09 -------- d-----w- f:\documents and settings\ams dane\Application Data\vlc
2010-03-12 22:51 . 2010-03-12 22:51 -------- d-----w- f:\program files\Google
2010-03-06 23:43 . 2010-03-06 23:43 -------- d-----w- f:\documents and settings\ams dane\Application Data\DivX
2010-03-06 23:43 . 2009-11-14 00:49 120056 ------w- f:\windows\system32\pxcpyi64.exe
2010-03-06 23:43 . 2009-11-14 00:49 118520 ------w- f:\windows\system32\pxinsi64.exe
2010-03-06 23:33 . 2010-03-08 09:02 -------- d-----w- f:\program files\DivX
2010-02-25 03:19 . 2009-11-01 21:00 -------- d-----w- f:\program files\NewTek
2010-02-24 03:48 . 2010-02-24 04:36 -------- d-----w- f:\documents and settings\ams dane\Application Data\Inbox2
2010-02-23 16:53 . 2010-03-19 02:03 -------- d-----w- f:\documents and settings\ams dane\Local Settings\Application Data\Temp
2010-02-23 16:53 . 2010-03-12 22:54 -------- d-----w- f:\documents and settings\ams dane\Local Settings\Application Data\Google
2010-02-22 03:12 . 2010-02-22 03:12 -------- d-----w- f:\documents and settings\ams dane\Application Data\Xtranormal
2010-02-21 07:46 . 2010-02-23 01:34 -------- d-----w- f:\documents and settings\ams dane\Application Data\SWiSH miniMax3
2010-02-21 07:38 . 2009-11-01 21:03 -------- d-----w- f:\program files\SWiSH miniMax3
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-21 00:00 . 2009-11-02 08:05 -------- d-----w- f:\program files\TO@NE-Radio
2010-03-16 13:45 . 2010-03-16 13:45 16 ----a-w- f:\documents and settings\ams dane\Application Data\zxcdyt.dat
2010-03-12 19:38 . 2009-10-18 19:44 -------- d-----w- f:\documents and settings\ams dane\Application Data\dvdcss
2010-03-09 21:15 . 2009-11-01 00:02 -------- d-----w- f:\program files\Replay Video Capture
2010-03-01 12:19 . 2010-01-13 11:53 1 ----a-w- f:\documents and settings\ams dane\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-02-24 04:50 . 2009-11-01 23:10 1558168 ----a-w- f:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-02-19 23:47 . 2010-02-19 23:47 3604480 ----a-w- f:\windows\system32\GPhotos.scr
2010-02-17 11:22 . 2010-02-17 11:22 57344 ----a-r- f:\documents and settings\ams dane\Application Data\Microsoft\Installer\{3705A9AD-4506-4BE3-B29D-89A79A5138E9}\NewShortcut7_B56E5B51EA954C948003CC703E2AFAD5.exe
2010-02-17 11:22 . 2010-02-17 11:22 57344 ----a-r- f:\documents and settings\ams dane\Application Data\Microsoft\Installer\{3705A9AD-4506-4BE3-B29D-89A79A5138E9}\NewShortcut1_B56E5B51EA954C948003CC703E2AFAD5.exe
2010-02-17 11:22 . 2010-02-17 11:22 -------- d-----w- f:\program files\Serato
2010-02-16 11:24 . 2010-02-16 11:24 -------- d-----w- f:\program files\Seesmic Desktop
2010-02-14 15:16 . 2010-02-14 15:16 552 ----a-w- f:\windows\system32\d3d8caps.dat
2010-01-28 18:58 . 2010-01-25 16:04 -------- d-----w- f:\program files\SopCast
2009-12-22 18:39 . 2009-12-22 18:39 922112 ------w- f:\windows\system32\imapi2fs.dll
2009-12-22 18:39 . 2009-12-22 18:39 426496 ------w- f:\windows\system32\imapi2.dll
.
------- Sigcheck -------
[-] 2008-05-14 . 33578A738C564B4F84D906EFD91025E5 . 1571840 . . [5.1.2600.5512] . . f:\windows\system32\sfcfiles.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-8287-79A187E26987}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="f:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Google Update"="f:\documents and settings\ams dane\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-02-23 135664]
"Orb"="f:\program files\Orb Networks\Orb\bin\OrbTray.exe" [2009-03-17 510416]
f:\documents and settings\ams dane\Menu D‚marrer\Programmes\D‚marrage\
Seesmic Desktop.lnk - f:\program files\Seesmic Desktop\Seesmic Desktop.exe [2010-2-16 95232]
f:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Logitech Desktop Messenger.lnk - f:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2009-10-18 67128]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"f:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"f:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"f:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"f:\\Program Files\\iTunes\\iTunes.exe"=
"f:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"f:\\Program Files\\SopCast\\SopCast.exe"=
"f:\\Program Files\\SopCast\\sopvod.exe"=
"f:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"f:\\Documents and Settings\\ams dane\\Bureau\\ftpxpert3.exe"=
"f:\\WINDOWS\\system32\\sessmgr.exe"=
"f:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"f:\\Program Files\\Orb Networks\\Orb\\bin\\Orb.exe"=
"f:\\Program Files\\Orb Networks\\Orb\\bin\\OrbStreamerClient.exe"=
"f:\\Program Files\\Orb Networks\\Orb\\bin\\OrbChannelScan.exe"=
"f:\\Program Files\\Orb Networks\\Orb\\bin\\OrbTray.exe"=
"f:\\Program Files\\Orb Networks\\Orb\\bin\\xmltv.exe"=
"f:\\Program Files\\SpacialAudio\\SAMBC\\SAMBC.exe"=
"f:\\Program Files\\Winamp\\winamp.exe"=
"f:\\Documents and Settings\\ams dane\\Bureau\\sc_serv.exe"=
"f:\\Program Files\\SpacialAudio\\SAMBC\\SAMReporter\\SAMReporter.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"7170:TCP"= 7170:TCP:streaming
"7170:UDP"= 7170:UDP:streaming2
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;f:\program files\Avira\AntiVir Desktop\sched.exe [18/10/2009 19:39 108289]
R2 MSSQL$RADIONOMY536765;SQL Server (RADIONOMY536765);f:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [24/11/2008 21:31 29263712]
R3 COMMONFX.SYS;COMMONFX.SYS;f:\windows\system32\drivers\COMMONFX.sys [23/06/2009 12:34 99352]
R3 CTAUDFX.SYS;CTAUDFX.SYS;f:\windows\system32\drivers\CTAUDFX.sys [23/06/2009 12:34 555032]
R3 CTSBLFX.SYS;CTSBLFX.SYS;f:\windows\system32\drivers\CTSBLFX.sys [23/06/2009 12:34 566296]
S2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance;f:\program files\Firebird\Firebird_2_1\bin\fbguard.exe [15/03/2010 16:56 81920]
S3 COMMONFX;COMMONFX;f:\windows\system32\drivers\COMMONFX.sys [23/06/2009 12:34 99352]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;f:\program files\Fichiers communs\Creative Labs Shared\Service\CTAELicensing.exe [18/10/2009 20:32 79360]
S3 CTAUDFX;CTAUDFX;f:\windows\system32\drivers\CTAUDFX.sys [23/06/2009 12:34 555032]
S3 CTERFXFX.SYS;CTERFXFX.SYS;f:\windows\system32\drivers\CTERFXFX.sys [23/06/2009 12:35 100888]
S3 CTERFXFX;CTERFXFX;f:\windows\system32\drivers\CTERFXFX.sys [23/06/2009 12:35 100888]
S3 CTSBLFX;CTSBLFX;f:\windows\system32\drivers\CTSBLFX.sys [23/06/2009 12:34 566296]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;f:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt [17/08/2005 23:00 7168]
S3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance;f:\program files\Firebird\Firebird_2_1\bin\fbserver.exe [15/03/2010 16:56 2736128]
S3 SL3Usb;SL3 driver;f:\windows\system32\drivers\Sl3.sys [03/11/2009 12:37 36352]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
vvdsvc REG_MULTI_SZ vvdsvc
.
Contenu du dossier 'Tâches planifiées'
2010-03-22 f:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-1770027372-1417001333-1004Core.job
- f:\documents and settings\ams dane\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-23 16:53]
2010-03-22 f:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1547161642-1770027372-1417001333-1004UA.job
- f:\documents and settings\ams dane\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-02-23 16:53]
.
.
------- Examen supplémentaire -------
.
uInternet Settings,ProxyOverride = *.local
IE: Add to Google Photos Screensa&ver - f:\windows\system32\GPhotos.scr/200
TCP: {B7E9288D-C807-435D-9484-4339A3FB9D5F} = 80.118.192.100,80.118.196.36
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - f:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: {50DC58D0-C870-4BE6-BC41-971ED2D5F022} -
hxxp://www.super-messenger.fr/tab/HookWlmEx.cabFF - ProfilePath - f:\documents and settings\ams dane\Application Data\Mozilla\Firefox\Profiles\j9vq4j4m.default\
FF - prefs.js: browser.search.defaulturl -
hxxp://slirsredirect.search.aol.com/sli ... -us&query=FF - prefs.js: browser.search.selectedEngine - Wikipédia (fr)
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.comFF - prefs.js: keyword.URL -
hxxp://slirsredirect.search.aol.com/sli ... -us&query=FF - plugin: f:\documents and settings\ams dane\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: f:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: f:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: f:\program files\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: f:\program files\Virtools\3D Life Player\npvirtools.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-03-22 17:49
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\f:\program files\Lavalys\EVEREST Home Edition\kerneld.wnt"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-1547161642-1770027372-1417001333-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5D8F075C-F4D3-958F-221A-CDFF30B56A23}*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"ialfbcdjmkpaolfhmo"=hex:6a,61,65,70,66,6e,67,6f,66,62,68,6b,6d,64,6b,67,61,61,
64,70,00,fe
"habflacddnglljea"=hex:6b,61,65,70,66,6e,67,6f,6c,62,6d,68,62,70,6c,6f,6b,6a,
63,69,61,68,00,00
"iahgjonoadlhlffngp"=hex:63,61,69,61,6f,61,00,7c
.
Heure de fin: 2010-03-22 17:51:17
ComboFix-quarantined-files.txt 2010-03-22 16:51
Avant-CF: 34 926 284 800 octets libres
Après-CF: 38 833 082 368 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(4)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(4)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
- - End Of File - - 7E4C834A964BDA2CBF5D255403D340BA