voici le rapport de combofix
ComboFix 10-04-21.01 - Propriétaire 23/04/2010 22:36:45.1.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.33.1036.18.759.209 [GMT 2:00]
Lancé depuis: c:\documents and settings\Propriétaire\Bureau\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\S-1-5-21-299502267-2025429265-682003330-500
C:\Thumbs.db
c:\windows\photo album.zip
c:\windows\system32\Microsoft\backup.ftp
c:\windows\system32\Microsoft\backup.tftp
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-03-23 au 2010-04-23 ))))))))))))))))))))))))))))))))))))
.
2010-04-23 16:41 . 2010-04-23 16:56 -------- d-----w- c:\program files\RegCleaner
2010-04-23 15:59 . 2010-04-23 20:48 -------- d-----w- c:\windows\LastGood
2010-04-23 15:56 . 2007-01-18 12:00 3968 ----a-w- c:\windows\system32\drivers\AvgArCln.sys
2010-04-23 14:46 . 2004-08-05 12:00 46080 -c--a-w- c:\windows\system32\dllcache\ftp.exe
2010-04-23 14:46 . 2004-08-05 12:00 46080 ----a-w- c:\windows\system32\ftp.exe
2010-04-23 14:38 . 2004-08-05 12:00 17920 -c--a-w- c:\windows\system32\dllcache\tftp.exe
2010-04-23 14:38 . 2004-08-05 12:00 17920 ----a-w- c:\windows\system32\tftp.exe
2010-04-23 13:59 . 2010-04-23 13:59 -------- d-----w- C:\$AVG
2010-04-23 12:38 . 2010-04-23 12:38 242896 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-04-23 12:38 . 2010-04-23 12:38 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-04-23 12:38 . 2010-04-23 12:38 216200 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-04-23 12:38 . 2010-04-23 12:38 29512 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-04-23 12:38 . 2010-04-23 12:44 -------- d-----w- c:\windows\system32\drivers\Avg
2010-04-23 12:37 . 2010-04-23 12:37 -------- d-----w- c:\program files\AVG
2010-04-23 12:37 . 2010-04-23 12:37 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\avg9
2010-04-23 08:53 . 2010-02-04 15:53 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-04-23 08:45 . 2010-04-23 08:45 -------- dc-h--w- c:\documents and settings\All Users.WINDOWS\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-04-23 08:44 . 2010-04-23 08:53 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Lavasoft
2010-04-23 08:32 . 2010-04-23 08:32 -------- d-----w- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2010-04-23 08:32 . 2010-04-23 08:32 -------- d-----w- c:\program files\SDHelper (Spybot - Search & Destroy)
2010-04-23 08:32 . 2010-04-23 08:32 -------- d-----w- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2010-04-23 08:32 . 2010-04-23 08:32 -------- d-----w- c:\program files\TeaTimer (Spybot - Search & Destroy)
2010-04-22 20:10 . 2010-04-22 20:10 411368 ----a-w- c:\windows\system32\deployJava1.dll
2010-04-22 09:42 . 2010-04-22 09:42 -------- d-----w- C:\_OTM
2010-04-22 07:11 . 2010-04-22 07:13 -------- d---a-w- C:\Navilog1
2010-04-21 20:25 . 2010-04-21 22:05 -------- d-----w- C:\Ad-Remover
2010-04-21 17:36 . 2010-04-21 17:36 -------- d-----w- c:\program files\Trend Micro
2010-04-21 08:12 . 2010-04-23 11:59 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Yahoo! Companion
2010-04-21 08:11 . 2010-04-21 08:13 -------- d-----w- c:\program files\Yahoo!
2010-04-21 08:11 . 2010-04-21 08:13 -------- d-----w- c:\program files\CCleaner
2010-04-20 06:07 . 2010-04-23 20:49 755200 ----a-w- c:\windows\system32\drivers\kmixer.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-23 19:09 . 2007-09-28 06:54 -------- d-----w- c:\program files\Wanadoo
2010-04-23 10:10 . 2007-04-23 14:25 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2010-04-23 09:18 . 2007-04-23 14:25 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-04-23 08:45 . 2007-04-23 15:13 -------- d-----w- c:\program files\Lavasoft
2010-04-23 05:09 . 2007-10-01 16:15 -------- d-----w- c:\program files\Fichiers communs\Java
2010-04-23 05:09 . 2007-10-01 16:20 -------- d-----w- c:\program files\Java
2010-04-21 21:54 . 2008-12-22 22:26 -------- d-----w- c:\program files\EoRezo
2010-04-20 06:05 . 2010-04-20 06:05 12 ----a-w- c:\documents and settings\NetworkService.AUTORITE NT\Application Data\kcmdte.dat
2010-04-15 07:13 . 2009-02-07 14:25 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft Help
2010-04-12 12:49 . 2006-04-09 17:39 -------- d-----w- c:\program files\emule
2010-03-29 06:41 . 2004-08-05 12:00 80856 ----a-w- c:\windows\system32\perfc00C.dat
2010-03-29 06:41 . 2004-08-05 12:00 500814 ----a-w- c:\windows\system32\perfh00C.dat
2010-03-24 18:17 . 2010-03-24 08:04 952768 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Adobe\Reader\9.2\ARM\30118\AdobeARM.exe
2010-03-24 18:17 . 2010-03-24 08:04 70584 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Adobe\Reader\9.2\ARM\30118\AdobeExtractFiles.dll
2010-03-24 18:17 . 2010-03-24 08:04 326056 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Adobe\Reader\9.2\ARM\30118\ReaderUpdater.exe
2010-03-24 18:17 . 2010-03-24 08:04 326056 ----a-w- c:\documents and settings\All Users.WINDOWS\Application Data\Adobe\Reader\9.2\ARM\30118\AcrobatUpdater.exe
2010-03-11 12:34 . 2004-08-05 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
2010-03-11 12:34 . 2004-08-05 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-03-11 12:34 . 2004-08-05 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2010-03-10 09:01 . 2007-09-28 16:40 -------- d-----w- c:\program files\Alwil Software
2010-03-10 08:57 . 2010-03-10 08:57 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Alwil Software
2010-03-09 11:10 . 2004-08-05 12:00 430080 ----a-w- c:\windows\system32\vbscript.dll
2010-02-24 12:31 . 2004-08-05 12:00 454016 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-16 19:33 . 2004-08-05 12:00 2183424 ----a-w- c:\windows\system32\ntoskrnl.exe
2010-02-16 19:33 . 2004-08-04 00:48 2060416 ----a-w- c:\windows\system32\ntkrnlpa.exe
2010-02-12 10:03 . 2004-03-20 13:59 293376 ------w- c:\windows\system32\browserchoice.exe
2010-02-12 04:46 . 2004-08-05 12:00 100864 ----a-w- c:\windows\system32\6to4svc.dll
2010-02-11 12:01 . 2004-08-05 12:00 226880 ----a-w- c:\windows\system32\drivers\tcpip6.sys
2010-02-04 15:53 . 2010-04-23 08:45 2954656 -c--a-w- c:\documents and settings\All Users.WINDOWS\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2006-06-01 94208]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-21 126976]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2006-01-07 81920]
"ArcSoft Connection Service"="c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2007-10-11 31232]
c:\documents and settings\Administrateur\Menu D‚marrer\Programmes\D‚marrage\
D‚marrage d'Office.lnk - c:\program files\Microsoft Office\Office\OSA.EXE [1996-12-17 51984]
Microsoft Recherche acc‚l‚r‚e.lnk - c:\program files\Microsoft Office\Office\FINDFAST.EXE [1996-12-17 111376]
UMAX VistaAccess.lnk - c:\vstascan\vsaccess.exe [2005-12-2 2502656]
c:\documents and settings\Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
Lanceur.lnk - c:\program files\Micro Application\LauncherMA.exe [2009-2-10 485376]
c:\documents and settings\All Users.WINDOWS\Menu D‚marrer\Programmes\D‚marrage\
PHOTOfunSTUDIO -viewer-.lnk - c:\program files\Panasonic\PHOTOfunSTUDIO -viewer-\PhAutoRun.exe [2009-8-24 40960]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-04-23 12:38 12464 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\emule\\emule.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\Warcraft III\\War3.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"4242:TCP"= 4242:TCP:4242
"4242:UDP"= 4242:UDP:4242
"4662:TCP"= 4662:TCP:4662
"4662:UDP"= 4662:UDP:4662
"3728:TCP"= 3728:TCP:TribalWeb
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [23/04/2010 10:53 64288]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [23/04/2010 14:38 216200]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [23/04/2010 14:38 242896]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [23/04/2010 14:37 916760]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [23/04/2010 14:37 308064]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [04/02/2010 17:52 1228208]
--- Autres Services/Pilotes en mémoire ---
*NewlyCreated* - AVGARCLN
*NewlyCreated* - AVG_ANTI-ROOTKIT
.
Contenu du dossier 'Tâches planifiées'
2010-04-23 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2010-02-04 15:52]
2010-04-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
------- Examen supplémentaire -------
.
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Envoyer l'image vers la bibliothèque -
file://c:\program files\MGI\MGI PhotoSuite III SE\Temp\MGI00000.html
IE: { - c:\program files\Messenger\msmsgs.exe
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-StandardInstall - (no file)
HKLM-Run-NWEReboot - (no file)
HKLM-Run-SpiderMessenger - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-04-23 22:48
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\kmixer]
"ImagePath"="system32\drivers\kmixer.sys"
.
Heure de fin: 2010-04-23 22:57:35
ComboFix-quarantined-files.txt 2010-04-23 20:57
Avant-CF: 10 247 446 528 octets libres
Après-CF: 10 418 782 208 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /fastdetect /noexecute=optin
- - End Of File - - F88ACC6B1047D40AAFC4E969C02C0E67