J'ai laissé le soin à ma fille de faire le processus car j'étais occupé avec autre chose... Alors c'est bon ?
ComboFix 09-10-05.01 - Thierry 06/10/2009 22:59.1.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.3006.2516 [GMT 2:00]
Lancé depuis: c:\documents and settings\Thierry.THIERRY-8B0DD18\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
c:\recycled\Recycled
c:\recycler\S-1-5-21-3592669358-3213677074-2582337979-1005
c:\recycler\S-1-5-21-527237240-1214440339-725345543-1003
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASC3550P
((((((((((((((((((((((((((((( Fichiers créés du 2009-09-06 au 2009-10-06 ))))))))))))))))))))))))))))))))))))
.
2009-10-06 19:33 . 2009-10-06 19:33 -------- d-----w- c:\program files\Fichiers communs\Winferno
2009-10-06 19:33 . 2009-10-06 19:33 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Winferno
2009-10-05 17:21 . 2009-10-05 17:21 -------- d-----w- c:\documents and settings\Thierry.THIERRY-8B0DD18\Application Data\Titanium Gears
2009-10-05 17:11 . 2006-10-09 11:06 495616 ----a-w- c:\windows\system32\WINUTIL5.DLL
2009-10-05 17:11 . 2006-05-17 06:40 393216 ----a-w- c:\windows\system32\WINLCTL5.DLL
2009-10-05 17:09 . 2009-10-05 17:09 -------- d-----w- c:\program files\PriceGong
2009-10-05 17:09 . 2009-10-05 17:09 -------- d-----w- c:\documents and settings\Thierry.THIERRY-8B0DD18\Application Data\PriceGong
2009-10-05 17:09 . 2009-10-05 17:09 -------- d-----w- c:\documents and settings\Thierry.THIERRY-8B0DD18\Application Data\Yahoo!
2009-10-05 17:09 . 2009-10-05 17:54 -------- d-----w- c:\program files\Yahoo!
2009-09-23 10:46 . 2009-09-23 10:46 -------- d-----w- c:\documents and settings\Thierry.THIERRY-8B0DD18\Application Data\Malwarebytes
2009-09-23 10:46 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-23 10:46 . 2009-09-23 10:46 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-23 10:46 . 2009-09-23 10:46 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2009-09-23 10:46 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-23 10:25 . 2009-09-23 10:25 -------- d-----w- c:\program files\CCleaner
2009-09-22 18:03 . 2009-09-22 18:03 -------- d-----w- c:\documents and settings\Thierry.THIERRY-8B0DD18\Documents
2009-09-22 18:01 . 2009-09-22 18:03 -------- d-----w- c:\documents and settings\Thierry.THIERRY-8B0DD18\.easyBook
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-06 20:08 . 2009-08-26 17:53 -------- d-----w- c:\program files\Bonjour
2009-10-06 19:36 . 2007-02-28 19:32 -------- d-----w- c:\program files\Common Files
2009-10-05 17:11 . 2007-03-21 09:14 -------- d-----w- c:\program files\eMule
2009-09-23 10:39 . 2009-01-21 08:25 -------- d-----w- c:\program files\rFactor
2009-09-23 10:38 . 2008-01-09 10:11 -------- d-----w- c:\program files\Fichiers communs\KnifeEdge
2009-09-23 10:36 . 2008-03-24 10:54 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\close poke frag ooze
2009-09-22 08:08 . 2009-02-21 07:28 -------- d-----w- c:\documents and settings\Thierry.THIERRY-8B0DD18\Application Data\FileZilla
2009-09-12 07:54 . 2008-11-24 11:30 -------- d-----w- c:\program files\CyberMUT
2009-08-26 18:06 . 2009-06-04 16:58 -------- d-----w- c:\documents and settings\Thierry.THIERRY-8B0DD18\Application Data\Apple Computer
2009-08-26 18:00 . 2009-05-24 11:25 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple
2009-08-26 17:54 . 2009-08-26 17:53 -------- d-----w- c:\program files\iTunes
2009-08-26 17:54 . 2009-08-26 17:53 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-08-26 17:53 . 2009-08-26 17:53 -------- d-----w- c:\program files\iPod
2009-08-26 17:53 . 2009-08-26 17:53 -------- d-----w- c:\program files\Fichiers communs\Apple
2009-08-26 17:53 . 2009-05-24 11:26 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Apple Computer
2009-08-22 15:18 . 2008-03-24 10:53 -------- d-----w- c:\program files\BitTorrent Fastest Tool
2009-08-17 11:19 . 2007-12-15 10:18 -------- d-----w- c:\documents and settings\Thierry.THIERRY-8B0DD18\Application Data\U3
2009-08-15 10:02 . 2009-08-15 09:37 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft
2009-08-15 10:02 . 2009-08-15 10:25 15688 ----a-w- c:\windows\system32\lsdelete.exe
2009-08-15 10:01 . 2009-08-15 10:02 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-08-15 09:37 . 2009-08-15 09:37 -------- dc-h--w- c:\documents and settings\All Users.WINDOWS\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
2009-08-15 09:37 . 2009-08-15 09:37 -------- d-----w- c:\program files\Lavasoft
2009-08-15 09:04 . 2007-01-01 15:03 -------- d-----w- c:\program files\Fichiers communs\Nikon
2009-08-15 09:04 . 2009-02-06 21:11 20 ---h--w- c:\documents and settings\All Users.WINDOWS\Application Data\PKP_DLeh.DAT
2009-08-13 18:08 . 2006-12-07 20:26 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-05 16:39 . 2008-03-06 18:58 62288 ----a-w- c:\documents and settings\Thierry.THIERRY-8B0DD18\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-28 10:57 . 2002-08-30 12:00 71488 ----a-w- c:\windows\system32\perfc00C.dat
2009-07-28 10:57 . 2002-08-30 12:00 458648 ----a-w- c:\windows\system32\perfh00C.dat
2009-07-28 10:53 . 2009-01-20 21:56 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-07-28 10:53 . 2009-01-20 21:56 22328 ----a-w- c:\documents and settings\Thierry.THIERRY-8B0DD18\Application Data\PnkBstrK.sys
2009-07-28 10:53 . 2009-01-20 21:56 107832 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-07-28 10:53 . 2009-01-20 21:56 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-07-28 10:53 . 2009-01-20 21:56 2250024 ----a-w- c:\windows\system32\pbsvc.exe
2009-07-09 10:16 . 2009-08-26 17:53 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-07-09 10:16 . 2009-08-26 17:53 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2002-04-25 01:00 . 2007-03-11 17:58 266240 ----a-w- c:\program files\internet explorer\plugins\PanoViewer.dll
1999-04-30 15:00 . 2007-03-11 17:58 98304 ----a-w- c:\program files\internet explorer\plugins\UPjpeg.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D2A2595C-4FE4-4315-AA9B-19DBD6271B71}]
2009-08-10 22:48 288056 ----a-w- c:\program files\PriceGong\1.5.0\PriceGongIE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"Easy-PrintToolBox"="c:\program files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE" [2006-10-17 398944]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-07-25 188416]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"EasyPHP"="c:\program files\EasyPHP 3.0\EasyPHP.exe" [2006-11-19 176128]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-09-21 520024]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-08-14 16050176]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\Thierry\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
c:\documents and settings\Thierry.THIERRY-8B0DD18\Menu D‚marrer\Programmes\D‚marrage\
ctfmon.exe [2006-11-20 20480]
c:\documents and settings\All Users.WINDOWS\Menu D‚marrer\Programmes\D‚marrage\
Lancement rapide d'Adobe Acrobat.lnk - c:\windows\Installer\{AC76BA86-1033-F400-7760-000000000002}\SC_Acrobat.exe [2009-3-18 25214]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver 8\\Dreamweaver.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Lauyan\\TOWeb V1\\TOWeb.exe"=
"c:\\Program Files\\EasyPHP 3.0\\mysql\\bin\\mysqld.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [15/08/2009 12:02 64160]
R0 xfilt;VIA SATA IDE Hot-plug Driver;c:\windows\system32\drivers\xfilt.sys [01/12/2007 11:22 11264]
R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [16/09/2008 12:03 169312]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [18/01/2009 23:34 1028432]
S3 Winferno Subscription Service;Winferno Subscription Service;c:\program files\Fichiers communs\Winferno\WSS\WSS.exe [06/10/2009 21:33 126976]
.
Contenu du dossier 'Tâches planifiées'
2009-10-05 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-01-18 10:02]
2009-09-25 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2009-10-06 c:\windows\Tasks\WSSHelper.job
- c:\program files\Fichiers communs\Winferno\WSS\WSSHelper.exe [2009-10-06 10:49]
.
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://www.google.fr/ig?hl=fr&source=iglkmStart Page =
hxxp://www.tropal.net/uInternet Settings,ProxyOverride = *.local
IE: Convertir en Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir en un fichier PDF existant - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir la cible du lien en Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir la cible du lien en un fichier PDF existant - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir la sélection en Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir la sélection en un fichier PDF existant - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir les liens sélectionnés en fichier Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convertir les liens sélectionnés en un fichier PDF existant - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
DPF: {EAC139A9-D22D-4C29-8D1C-252BE63750F9} -
hxxp://www.cooliris.com/shared/plinstll.cabFF - ProfilePath - c:\documents and settings\Thierry.THIERRY-8B0DD18\Application Data\Mozilla\Firefox\Profiles\fcd2jhq4.default\
FF - prefs.js: browser.search.selectedEngine - Live Search
FF - prefs.js: browser.startup.homepage -
hxxp://fr.msn.com/FF - prefs.js: keyword.URL -
hxxp://search.live.com/results.aspx?mkt ... =MIMWA2&q=FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
- - - - ORPHELINS SUPPRIMES - - - -
AddRemove-HijackThis - G:\HijackThis.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-06 23:15
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-746137067-1417001333-1801674531-1003\Software\SecuROM\License information*]
"datasecu"=hex:e1,de,30,f9,d0,a9,a7,50,f0,54,f8,8b,f3,fe,66,f6,1e,f1,83,65,41,
13,f9,b8,67,c9,59,06,93,f3,4c,e1,1c,76,cf,75,96,14,7c,9a,d6,c6,2b,fd,a2,4b,\
"rkeysecu"=hex:9b,c7,9a,90,0b,71,ee,de,8a,01,5e,6d,78,a2,76,71
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:ae,55,a9,de,89,c3,ec,a2,eb,2a,45,dd,1b,e9,e0,8f,9a,99,2b,84,12,
e4,9c,62,79,a2,aa,60,7e,66,12,1c,7d,a8,6e,47,0a,2b,8f,84,64,4f,5c,9e,50,67,\
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:ae,55,a9,de,89,c3,ec,a2,eb,2a,45,dd,1b,e9,e0,8f,9a,99,2b,84,12,
e4,9c,62,79,a2,aa,60,7e,66,12,1c,7d,a8,6e,47,0a,2b,8f,84,64,4f,5c,9e,50,67,\
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(568)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3980)
c:\windows\system32\msi.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\rundll32.exe
c:\documents and settings\Thierry.THIERRY-8B0DD18\Menu Démarrer\Programmes\Démarrage\ctfmon.exe
c:\progra~1\EASYPH~1.0\apache\bin\apache.exe
c:\progra~1\EASYPH~1.0\apache\bin\apache.exe
c:\progra~1\EASYPH~1.0\mysql\bin\mysqld.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Windows Live\Contacts\wlcomm.exe
.
**************************************************************************
.
Heure de fin: 2009-10-06 23:23 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-10-06 21:23
Avant-CF: 103 901 376 512 octets libres
Après-CF: 105 105 522 688 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /fastdetect /NoExecute=OptOut
245