le rapport de combofix
ComboFix 09-01-21.04 - NANO 2009-01-29 20:11:17.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.895.507 [GMT 1:00]
Lancé depuis: c:\documents and settings\NANO\Bureau\marin.exe
AV: BitDefender Antivirus *On-access scanning disabled* (Updated)
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
c:\documents and settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
c:\documents and settings\NANO\Application Data\inst.exe
c:\windows\system32\FM20(2).DLL
c:\windows\system32\FM20FRA(2).DLL
c:\windows\system32\msrecr40(2).dll
c:\windows\system32\MSSTDFMT(2).DLL
c:\windows\system32\OUTLWAB(2).DLL
.
---- Exécution préalable -------
.
c:\program files\INSTALL.LOG
c:\windows\system32\AutoRun.inf
c:\windows\system32\drivers\senekaoylyaxmt.sys
c:\windows\system32\MabryObj.dll
c:\windows\system32\open.ico
c:\windows\system32\senekacjdvckor.dll
c:\windows\system32\senekacpudatva.dll
c:\windows\system32\senekarftidqbn.dat
c:\windows\system32\senekaxbwqgdae.dat
----- BITS: Il y a peut-être des sites infectés -----
hxxp://updateserver.info
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_SENEKA
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-28 au 2009-01-29 ))))))))))))))))))))))))))))))))))))
.
2009-01-29 18:41 . 2009-01-29 18:41 <REP> d-------- C:\_OTMoveIt
2009-01-29 17:37 . 2009-01-29 17:37 <REP> d-------- c:\program files\Trend Micro
2009-01-29 13:31 . 2009-01-29 13:31 61,440 --a------ c:\windows\system32\drivers\pauxcom.sys
2009-01-27 22:35 . 2009-01-27 22:35 <REP> d-------- c:\program files\Panda Security
2009-01-27 22:35 . 2008-06-19 16:24 28,544 --a------ c:\windows\system32\drivers\pavboot.sys
2009-01-27 19:26 . 2009-01-28 12:52 <REP> d-------- C:\HaxFix
2009-01-27 18:43 . 2009-01-27 18:46 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-27 18:43 . 2009-01-27 18:43 <REP> d-------- c:\documents and settings\NANO\Application Data\Malwarebytes
2009-01-27 18:43 . 2009-01-27 18:43 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-27 18:43 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-27 18:43 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-01-27 18:04 . 2009-01-27 18:04 <REP> d-------- c:\windows\system32\Kaspersky Lab
2009-01-27 16:16 . 2002-09-30 11:55 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage réseau
2009-01-27 16:16 . 2002-09-30 11:55 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage d'impression
2009-01-27 16:16 . 2002-09-30 11:55 <REP> d--h----- c:\documents and settings\Administrateur\Modèles
2009-01-27 16:16 . 2002-09-30 12:09 <REP> dr------- c:\documents and settings\Administrateur\Mes documents
2009-01-27 16:16 . 2002-09-30 11:55 <REP> dr------- c:\documents and settings\Administrateur\Menu Démarrer
2009-01-27 16:16 . 2004-07-26 08:00 <REP> dr------- c:\documents and settings\Administrateur\Favoris
2009-01-27 16:16 . 2004-07-26 07:57 <REP> dr------- c:\documents and settings\Administrateur\Bureau
2009-01-27 16:16 . 2009-01-27 16:16 <REP> d-------- c:\documents and settings\Administrateur
2009-01-27 15:56 . 2009-01-28 13:46 0 --a------ c:\windows\system32\drivers\c291fff6.sys
2009-01-27 15:22 . 2009-01-27 15:52 <REP> d-------- c:\documents and settings\NANO\Application Data\Vso
2009-01-27 15:22 . 2009-01-27 15:22 289,840 --a------ c:\windows\Promo2-Petri.png
2009-01-27 15:22 . 2009-01-27 15:22 133,254 --a------ c:\windows\Promo3-Is_it_safe.png
2009-01-27 15:22 . 2009-01-27 15:22 47,360 --a------ c:\windows\system32\drivers\pcouffin.sys
2009-01-27 15:22 . 2009-01-27 15:52 47,360 --a------ c:\documents and settings\NANO\Application Data\pcouffin.sys
2009-01-27 15:21 . 2009-01-27 15:21 298,242 --a------ c:\windows\Promo1-map.png
2009-01-27 15:20 . 2009-01-29 20:14 93,420 --a------ c:\windows\system32\drivers\44a262bd.sys
2009-01-27 15:18 . 2009-01-27 15:56 2 --a------ C:\945281028
2009-01-24 17:35 . 2009-01-24 17:35 <REP> d-------- c:\documents and settings\All Users\Application Data\Logitech
2009-01-20 16:01 . 2008-12-17 06:55 195,096 --a------ c:\windows\system32\lvci11901262.dll
2009-01-20 14:22 . 2008-12-17 07:00 768,024 --a------ c:\windows\system32\drivers\lvrs.sys
2009-01-20 14:22 . 2008-04-13 20:45 60,032 --a------ c:\windows\system32\drivers\USBAUDIO.sys
2009-01-20 14:22 . 2008-04-13 20:45 60,032 --a------ c:\windows\system32\dllcache\usbaudio.sys
2009-01-20 14:22 . 2008-12-17 06:37 29,562 --a------ c:\windows\system32\Repository.reg
2009-01-20 14:22 . 2009-01-20 14:22 0 --a------ c:\windows\system32\drivers\lvuvc.hs
2009-01-20 14:21 . 2008-12-17 07:01 6,364,440 --a------ c:\windows\system32\drivers\lvuvc.sys
2009-01-20 14:21 . 2008-07-26 16:23 195,096 -ra------ c:\windows\system32\lvci11801048.dll
2009-01-20 14:21 . 2009-01-20 14:21 127,034 -r------- c:\windows\bwUnin-8.1.1.50-8876480SL.exe
2009-01-20 14:21 . 2008-12-17 07:02 23,832 --a------ c:\windows\system32\drivers\lvuvcflt.sys
2009-01-20 14:21 . 2008-04-14 04:34 20,992 --a------ c:\windows\system32\dshowext.ax
2009-01-20 14:21 . 2008-04-14 04:34 20,992 --a------ c:\windows\system32\dllcache\dshowext.ax
2009-01-20 14:21 . 2009-01-29 19:31 0 --a------ c:\windows\system32\drivers\logiflt.iad
2009-01-20 14:17 . 2009-01-24 17:36 <REP> d-------- c:\program files\Fichiers communs\LogiShrd
2009-01-20 14:17 . 2009-01-24 17:36 <REP> d-------- c:\documents and settings\All Users\Application Data\Logishrd
2009-01-18 16:21 . 2009-01-18 16:21 268 --ah----- C:\sqmdata08.sqm
2009-01-18 16:21 . 2009-01-18 16:21 244 --ah----- C:\sqmnoopt08.sqm
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-29 18:07 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-29 12:31 396 ----a-w c:\program files\nxup.txt
2009-01-27 16:03 --------- d-----w c:\documents and settings\NANO\Application Data\Azureus
2009-01-27 15:08 --------- d-----w c:\program files\adslTV
2009-01-27 11:27 --------- d-----w c:\documents and settings\NANO\Application Data\dvdcss
2009-01-26 13:47 --------- d-----w c:\program files\Steam
2009-01-24 22:23 81,984 ----a-w c:\windows\system32\bdod.bin
2009-01-24 16:36 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-24 16:36 --------- d-----w c:\program files\Logitech
2009-01-24 16:34 --------- d-----w c:\program files\CCleaner
2009-01-24 16:34 --------- d-----w c:\documents and settings\NANO\Application Data\vlc
2009-01-24 16:16 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-01-20 11:49 --------- d-----w c:\documents and settings\All Users\Application Data\DVD Shrink
2009-01-20 11:09 242,184 ----a-w c:\windows\system32\drivers\bdfsfltr.sys
2008-12-20 16:35 16,130,060 ----a-w c:\windows\system32\ecran-veille-vdg.scr
2008-12-17 06:01 432,664 ----a-w c:\windows\system32\LVUI2RC.dll
2008-12-17 06:01 41,752 ----a-w c:\windows\system32\drivers\LVUSBSta.sys
2008-12-17 06:00 494,104 ----a-w c:\windows\system32\LVUI2.dll
2008-12-17 05:55 416,280 ----a-w c:\windows\system32\lvcodec2.dll
2008-12-16 20:58 25,624 ----a-w c:\windows\system32\drivers\LVPr2Mon.sys
2008-12-16 20:50 13,584 ----a-w c:\windows\system32\drivers\iKeyLgFT.dll
2008-12-16 20:38 85,302 ----a-w c:\windows\system32\drivers\LVFeL002.cfg
2008-12-16 20:38 69,592 ----a-w c:\windows\system32\drivers\LVFaL000.cfg
2008-12-16 20:38 227,172 ----a-w c:\windows\system32\drivers\LVFeL000.cfg
2008-12-16 20:38 146,680 ----a-w c:\windows\system32\drivers\LVFeL001.cfg
2008-12-13 06:37 3,593,216 ----a-w c:\windows\system32\dllcache\mshtml.dll
2008-12-11 10:57 333,952 ------w c:\windows\system32\drivers\srv.sys
2008-12-11 10:57 333,952 ------w c:\windows\system32\dllcache\srv.sys
2008-12-02 18:40 --------- d-----w c:\program files\Windows Live Safety Center
2008-11-29 16:27 --------- d-----w c:\program files\PhotoFiltre
2008-11-29 15:23 --------- d-----w c:\program files\Windows Desktop Search
2008-05-19 19:21 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008051920080520\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-05-15 339968]
"ACTIVBOARD"="c:\apps\ABoard\ABoard.exe" [2003-05-02 24576]
"BDAgent"="c:\program files\BitDefender\BitDefender 2009\bdagent.exe" [2009-01-29 741376]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2009\IEShow.exe" [2008-10-17 69632]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-09-30 98304]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoTrayItemsDisplay "= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=sockspy.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^NANO^Menu Démarrer^Programmes^Démarrage^Logitech . Enregistrement du produit.lnk]
path=c:\documents and settings\NANO\Menu Démarrer\Programmes\Démarrage\Logitech . Enregistrement du produit.lnk
backup=c:\windows\pss\Logitech . Enregistrement du produit.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-10-15 01:04 39792 c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Autoconfigurateur WiFi Neuf]
--a------ 2007-02-14 12:06 181752 c:\program files\Neuf\Kit\WiFi\9wifi.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
--a------ 2008-12-20 07:50 2656528 c:\program files\Logitech\QuickCam\Quickcam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2005-09-30 13:50 98304 c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2006-01-05 17:40 180269 c:\program files\Fichiers communs\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe"
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_02\bin\jusched.exe"
"LVCOMSX"=c:\windows\system32\LVCOMSX.EXE
"NeroCheck"=c:\windows\system32\NeroCheck.exe
"VCSPlayer"="c:\program files\Virtual CD v4 SDK\system\vcsplay.exe"
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
"HP Software Update"=c:\program files\HP\HP Software Update\HPWuSchd2.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Steam\\SteamApps\\day_of_defeat918\\day of defeat source\\hl2.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Azureus\\Azureus.exe"=
"c:\\Program Files\\Steam\\SteamApps\\day_of_defeat918\\day of defeat\\hl.exe"=
"c:\\Program Files\\Steam\\SteamApps\\day_of_defeat918\\counter-strike\\hl.exe"=
"c:\\Program Files\\Steam\\SteamApps\\day_of_defeat918\\condition zero\\hl.exe"=
"c:\\Program Files\\Steam\\SteamApps\\day_of_defeat918\\condition zero deleted scenes\\hl.exe"=
"c:\\Program Files\\adslTV\\adsltv.exe"=
"c:\\Program Files\\Steam\\SteamApps\\day_of_defeat918\\half-life deathmatch source\\hl2.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Steam\\SteamApps\\day_of_defeat918\\insurgency\\hl2.exe"=
"c:\\Documents and Settings\\NANO\\Mes documents\\VLC\\vlc.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
R0 atiide;atiide;c:\windows\system32\drivers\atiide.sys [2004-06-01 6016]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2009-01-27 28544]
R1 Asapi;Asapi;c:\windows\system32\drivers\asapi.sys [2004-07-26 11264]
R1 vcsmpdrv;vcsmpdrv;c:\windows\system32\drivers\vcsmpdrv.sys [2004-07-26 49024]
R3 PhTVTune;ASUS WDM TV Tuner;c:\windows\system32\drivers\PhTVTune.sys [1979-12-31 24608]
R4 VCSSecS;Virtual CD v4 Security service (SDK - Version);c:\program files\Virtual CD v4 SDK\System\vcssecs.exe [2004-07-26 139264]
S1 c291fff6;c291fff6;c:\windows\system32\drivers\c291fff6.sys [2009-01-27 0]
S3 afs_rec;afs_rec; [x]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [2008-07-17 118784]
S3 ASIOMI;ASIOMI;c:\windows\system32\drivers\ASIOMI.sys [2004-07-26 5396]
S3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [2008-09-18 111112]
S3 cnwlnkfl;cnwlnkfl; [x]
S3 gkmixern;gkmixern; [x]
S3 hql12160;hql12160; [x]
S3 MPCSYS;MPCSYS;c:\windows\system32\drivers\mpcsys.SYS [2006-10-09 15360]
S3 msonydca;msonydca; [x]
S3 NBXG7031;NB 802.11g XG703 SP1 Driver;c:\windows\system32\drivers\WlanUIG.sys [2004-09-17 381312]
S3 nfltmgr;nfltmgr; [x]
S3 uks;uks; [x]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
bdx REG_MULTI_SZ scan
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b92c54ea-2e23-11dd-ba7a-00038a000015}]
\Shell\AutoRun\command - e:\wd_windows_tools\setup.exe
.
Contenu du dossier 'Tâches planifiées'
2004-08-22 c:\windows\Tasks\Rappel d'enregistrement 1.job
- c:\windows\System32\OOBE\oobebaln.exe [2008-04-14 03:34]
2004-08-21 c:\windows\Tasks\Rappel d'enregistrement 2.job
- c:\windows\System32\OOBE\oobebaln.exe [2008-04-14 03:34]
2004-09-04 c:\windows\Tasks\Rappel d'enregistrement 3.job
- c:\windows\System32\OOBE\oobebaln.exe [2008-04-14 03:34]
2009-01-29 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDetect.exe []
.
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://www.neufportail.fr/
uInternet Settings,ProxyOverride = localhost
uSearchURL,(Default) =
hxxp://www.google.com/keyword/%s
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: DirectAnimation Java Classes
DPF: Microsoft XML Parser for Java
DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} -
hxxp://download.ewido.net/ewidoOnlineScan.cab
DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} -
hxxp://www.bobtv.fr/download/cfweb_www.bobtv.fr-download_instmodule.exe
DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} -
hxxp://www.extrafilm.fr/ImageUploader5.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -
hxxp://www.bitdefender.fr/scan8/oscan8.cab
DPF: {8731163E-77B9-4F91-9122-F112521C28AF} -
hxxp://62.201.137.56/mmawap/jsp/composer/player/mmsPlayer.cab
DPF: {87AF076E-D86D-4E87-ADDD-F05804E1F150} -
hxxps://www.virginmega.fr/DownloadManager/Release/Prod/DownMan.cab
DPF: {B79A53C0-1DAC-4636-BACE-FD086A7A79BF} -
hxxps://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-1.0.cab
DPF: {DFB5BCF1-06AE-4ABB-BFA8-1E228F41C50A} -
hxxp://www.bobtv.fr/download/cfweb_www.bobtv.fr-download_instmodule.exe
DPF: {E862C832-3A5F-4CEB-BFAA-167B22010A71} -
hxxp://support.packardbell.com/files/activex/InfosFinder2.CAB
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-29 20:14:53
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\controlset007\Services\44a262bd]
"ImagePath"="\SystemRoot\System32\drivers\44a262bd.sys"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\s-1-5-21-4063979878-1902328510-3657523918-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(620)
c:\windows\system32\Ati2evxx.dll
.
Heure de fin: 2009-01-29 20:17:42
ComboFix-quarantined-files.txt 2009-01-29 19:17:06
Avant-CF: 91,143,356,416 octets libres
Après-CF: 91,121,184,768 octets libres
Current=7 Default=7 Failed=6 LastKnownGood=8 Sets=1,2,3,4,5,6,7,8
269 --- E O F --- 2009-01-24 16:42:20