rapport combofix =
ComboFix 09-04-15.08 - Administrateur 15/04/2009 9:33.4 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.639.397 [GMT 2:00]
Lancé depuis: c:\documents and settings\Administrateur.TITANIUM.000\Bureau\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrateur\Cookies\hpothb07.dat
c:\documents and settings\Administrateur\Cookies\hpothb07.tif
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-03-15 au 2009-04-15 ))))))))))))))))))))))))))))))))))))
.
2009-04-09 14:52 . 2009-04-09 14:52 -------- d-----w C:\VundoFix Backups
2009-04-09 07:27 . 2009-04-09 07:27 -------- d-----w c:\program files\Trend Micro
2009-04-07 16:46 . 2009-04-07 16:46 -------- d-----w c:\windows\system32\Kaspersky Lab
2009-04-07 15:21 . 2009-04-08 07:03 -------- d-----w c:\windows\SxsCaPendDel
2009-04-07 08:30 . 2009-04-07 08:30 -------- d-sh--w c:\documents and settings\Administrateur.TITANIUM.000\IECompatCache
2009-04-06 19:33 . 2009-04-06 19:33 -------- d-sh--w c:\documents and settings\Administrateur.TITANIUM.000\PrivacIE
2009-04-06 19:30 . 2009-04-06 19:30 -------- d-sh--w c:\documents and settings\Administrateur.TITANIUM.000\IETldCache
2009-04-06 18:38 . 2009-04-06 18:38 -------- d-----w c:\windows\ie8updates
2009-04-06 18:31 . 2009-04-06 18:35 -------- dc-h--w c:\windows\ie8
2009-04-06 18:20 . 2009-02-28 04:55 105984 -c----w c:\windows\system32\dllcache\iecompat.dll
2009-04-06 18:14 . 2009-04-06 18:15 17001840 ----a-w c:\program files\IE8-WindowsXP-x86-FRA.exe
2009-03-29 13:29 . 2009-03-29 13:29 -------- d-----w c:\program files\SFR
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-15 06:40 . 2001-08-24 14:00 368076 ----a-w c:\windows\system32\perfh00C.dat
2009-04-15 06:40 . 2001-08-24 14:00 48856 ----a-w c:\windows\system32\perfc00C.dat
2009-04-14 23:09 . 2008-04-13 16:40 2683 ----a-w C:\Saved.game
2009-04-09 16:12 . 2009-04-09 14:52 159 ----a-w C:\VundoFix.txt
2009-04-07 16:40 . 2008-05-14 06:54 -------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2009-04-07 15:22 . 2005-06-28 14:10 -------- d-----w c:\program files\Fichiers communs\Adobe
2009-04-07 07:12 . 2008-05-14 06:54 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-09 18:46 . 2008-11-24 19:52 0 ---ha-w c:\documents and settings\Administrateur.TITANIUM\hpothb07.dat
2009-03-08 02:34 . 2004-08-04 00:54 914944 ----a-w c:\windows\system32\wininet.dll
2009-03-08 02:34 . 2004-08-04 00:54 43008 ----a-w c:\windows\system32\licmgr10.dll
2009-03-08 02:33 . 2004-08-04 00:54 18944 ----a-w c:\windows\system32\corpol.dll
2009-03-08 02:33 . 2004-08-04 00:54 420352 ----a-w c:\windows\system32\vbscript.dll
2009-03-08 02:32 . 2004-08-04 00:54 72704 ----a-w c:\windows\system32\admparse.dll
2009-03-08 02:32 . 2004-08-04 00:54 71680 ----a-w c:\windows\system32\iesetup.dll
2009-03-08 02:31 . 2004-08-04 00:54 34816 ----a-w c:\windows\system32\imgutil.dll
2009-03-08 02:31 . 2004-08-04 00:53 48128 ----a-w c:\windows\system32\mshtmler.dll
2009-03-08 02:31 . 2004-08-04 00:54 45568 ----a-w c:\windows\system32\mshta.exe
2009-03-08 02:22 . 2001-08-24 14:00 156160 ----a-w c:\windows\system32\msls31.dll
2009-02-09 14:17 . 2004-08-04 00:45 1846400 ----a-w c:\windows\system32\win32k.sys
2008-11-24 19:49 . 2008-11-24 19:49 383 ---ha-w c:\documents and settings\Administrateur\Application Data\hpothb07.dat
2008-11-24 19:49 . 2008-11-24 19:49 526 ---ha-w c:\documents and settings\Administrateur\hpothb07.dat
2008-09-21 13:41 . 2008-05-05 17:51 25085704 ----a-w c:\program files\antivir_workstation_winu_en_h.exe
2008-07-06 16:26 . 2008-07-06 16:26 2919360 ----a-w c:\program files\ccsetup209.exe
2008-06-06 17:51 . 2008-06-06 17:51 2914296 ----a-w c:\program files\ccsetup208.exe
2008-05-14 12:51 . 2008-05-14 12:50 4004400 ----a-w c:\program files\a2AntiDialerSetup.exe
2008-05-14 07:12 . 2008-05-14 07:12 2897456 ----a-w c:\program files\ccsetup207.exe
2008-05-14 06:52 . 2008-05-14 06:52 9722720 ----a-w c:\program files\spybotsd152.exe
2008-04-14 16:18 . 2008-04-14 16:18 210098 ----a-w c:\program files\icscreensaver.exe
2008-04-02 19:09 . 2008-04-02 19:09 2317280 ----a-w c:\program files\zipit3.exe
2008-04-02 18:32 . 2008-04-02 18:32 4399029 ----a-w c:\program files\quickzip.exe
2008-03-31 16:42 . 2008-03-31 16:42 21907616 ----a-w c:\program files\setupfre.exe
2008-03-31 16:38 . 2008-03-31 16:38 1264022 ----a-w c:\program files\pcsecuritytest.zip
2008-03-30 18:09 . 2008-03-30 18:09 14163419 ----a-w c:\program files\klcodec370f.exe
2008-03-07 19:14 . 2008-03-07 19:14 164 ---ha-w c:\documents and settings\All Users\hpothb07.dat
2008-03-04 11:42 . 2007-11-18 11:54 20864 ----a-w c:\documents and settings\Administrateur.TITANIUM.000\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2007-12-03 08:35 . 2007-12-03 08:34 11170003 ----a-w c:\program files\vlc-0.8.6d.tar.bz2
2007-12-03 08:34 . 2007-12-03 08:34 1501 ----a-w c:\program files\vlc-0.8.6d-announce
2007-12-03 08:34 . 2007-12-03 08:33 14285681 ----a-w c:\program files\vlc-0.8.6d-win32.zip
2006-09-14 20:05 . 2005-06-28 09:39 51096 -c--a-w c:\documents and settings\Administrateur\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2006-06-15 09:29 . 2005-08-28 12:26 49936 -c--a-w c:\documents and settings\Administrateur\Application Data\GDIPFONTCACHEV1.DAT
2005-10-31 15:18 . 2005-10-12 16:36 278528 -c--a-w c:\program files\Fichiers communs\FDEUnInstaller.exe
2005-06-29 01:31 . 2005-06-29 01:31 137 -c--a-w c:\documents and settings\Administrateur\Local Settings\Application Data\fusioncache.dat
2002-07-26 16:02 . 2005-09-14 13:54 153088 ----a-w c:\program files\UNWISE.EXE
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}"= "c:\program files\Yahoo!\Companion\Installs\cpn\yt.dll" [2006-10-26 440384]
[HKEY_CLASSES_ROOT\clsid\{ef99bd32-c1fb-11d2-892f-0090271d4f88}]
[HKEY_CLASSES_ROOT\yt.YToolbarBand.1]
[HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}]
[HKEY_CLASSES_ROOT\yt.YToolbarBand]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\program files\Java\j2re1.4.2_05\bin\jusched.exe" [2004-06-03 32881]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-11 69632]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-11-07 8523776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-11-07 81920]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-19 266497]
"a-squared"="c:\program files\a-squared Anti-Dialer\a2adguard.exe" [2008-06-06 1497744]
"Autoconfigurateur WiFi SFR"="c:\program files\SFR\Kit\WiFi\9wifi.exe" [2008-09-01 287984]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-11-07 1626112]
c:\documents and settings\All Users.WINDOWS\Menu D‚marrer\Programmes\D‚marrage\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"WebCheck"= {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - c:\windows\system32\webcheck.dll [2009-03-08 236544]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
R3 ALS4KMF;ALS4KMF;c:\windows\system32\drivers\mf.sys [2004-08-04 63744]
R3 MBAMCatchMe;MBAMCatchMe; [x]
S2 a2AntiDialer;a-squared Anti-Dialer Service;c:\program files\a-squared Anti-Dialer\a2service.exe [2008-10-05 418936]
S3 als4k;Avance Audio Miniport Driver (WDM);c:\windows\system32\drivers\als4000.sys [2001-10-22 28919]
S3 NBXG7031;NB 802.11g XG703 SP1 Driver;c:\windows\system32\DRIVERS\WlanUIG.sys [2004-09-17 381312]
--- Autres Services/Pilotes en mémoire ---
*NewlyCreated* - HTTPFILTER
*Deregistered* - mchInjDrv
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contenu du dossier 'Tâches planifiées'
2009-04-15 c:\windows\Tasks\User_Feed_Synchronization-{914984A3-F0B5-4924-940B-999EB165918E}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 02:31]
.
- - - - ORPHELINS SUPPRIMES - - - -
Toolbar-Locked - (no file)
HKCU-Run-eniwhdml - c:\windows\system32\zcvuxypu.exe
SSODL-CDBurn-{fbeb8a05-beee-4442-804e-409d6c4515e9} - %SystemRoot%\system32\SHELL32.dll
Notify-WgaLogon - (no file)
.
------- Examen supplémentaire -------
.
IE: {{e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
Handler: http\
0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\FICHIE~1\System\OLEDB~1\MSDAIPP.DLL
Handler: http\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\FICHIE~1\System\OLEDB~1\MSDAIPP.DLL
Handler: https\
0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\FICHIE~1\System\OLEDB~1\MSDAIPP.DLL
Handler: https\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\FICHIE~1\System\OLEDB~1\MSDAIPP.DLL
Handler: ipp\
0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\FICHIE~1\System\OLEDB~1\MSDAIPP.DLL
Handler: msdaipp\
0x00000001 - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\FICHIE~1\System\OLEDB~1\MSDAIPP.DLL
Handler: msdaipp\oledb - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - c:\progra~1\FICHIE~1\System\OLEDB~1\MSDAIPP.DLL
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -
hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} -
hxxp://www.mypix.com/fr/fr/importer/ImageUploader4.cab
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-15 09:38
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-1409082233-1202660629-1957994488-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,9c,6b,ae,08,14,43,b8,42,b7,18,60,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,9c,6b,ae,08,14,43,b8,42,b7,18,60,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,9c,6b,ae,08,14,43,b8,42,b7,18,60,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,9c,6b,ae,08,14,43,b8,42,b7,18,60,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,9c,6b,ae,08,14,43,b8,42,b7,18,60,\
.
Heure de fin: 2009-04-15 9:42
ComboFix-quarantined-files.txt 2009-04-15 07:42
Avant-CF: 3 811 876 864 octets libres
Après-CF: 3 872 903 168 octets libres
171 --- E O F --- 2009-03-11 15:24