Voilà, j'y suis. J'attends tes nouvelles instructions. Elios1
ComboFix 09-01-17.04 - utilisateur 2009-01-18 21:09:16.2 -
FAT32x86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.502.152 [GMT 1:00]
Lancé depuis: c:\documents and settings\utilisateur\Bureau\Elios.exe
Commutateurs utilisés :: c:\documents and settings\utilisateur\Bureau\CFScript.txt
AV: Norton AntiVirus 2006 *On-access scanning disabled* (Outdated)
FW: Norton Internet Worm Protection *disabled*
* Un nouveau point de restauration a été créé
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
FILE ::
c:\windows\system32\5963e6d5639ab34386deb5057c4c155a.TMP
c:\windows\system32\aeeccddab.dll
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\5963e6d5639ab34386deb5057c4c155a.TMP
c:\windows\system32\aeeccddab.dll . . . . impossible à supprimer
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-18 au 2009-01-18 ))))))))))))))))))))))))))))))))))))
.
2009-01-18 19:59 . 2009-01-18 19:59 3,042,839 -ra------ C:\Elios.exe
2009-01-18 19:03 . 2009-01-18 19:03 2,737,808 --a------ C:\mbam-setup.exe
2009-01-18 18:41 . 2009-01-18 18:42 22,148,280 --a------ C:\antivir_workstation_winu_fr_h.exe
2009-01-18 17:10 . 2009-01-18 17:08 792,618 --a------ C:\MSNFix.zip
2009-01-18 16:49 . 2009-01-18 16:49 <REP> d-------- C:\GenProc
2009-01-18 16:48 . 2009-01-18 16:41 2,022,787 --a------ C:\GenProc.zip
2009-01-18 14:41 . 2009-01-18 14:41 <REP> d-------- c:\program files\Navilog1
2009-01-18 14:05 . 2009-01-18 14:05 <REP> d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-01-18 13:46 . 2009-01-18 13:46 <REP> d-------- c:\windows\system32\Kaspersky Lab
2009-01-18 13:05 . 2009-01-18 13:05 <REP> d-------- c:\documents and settings\Administrateur\Application Data\Yahoo!
2009-01-18 13:02 . 2009-01-18 13:02 <REP> d-------- c:\documents and settings\Administrateur\Application Data\Symantec
2009-01-18 12:36 . 2009-01-18 12:36 <REP> d-------- c:\program files\UsbFix
2009-01-18 12:19 . 2009-01-18 12:19 <REP> d-------- C:\rsit
2009-01-18 12:19 . 2009-01-18 12:19 <REP> d-------- c:\program files\trend micro
2009-01-14 21:53 . 2009-01-14 21:53 <REP> d-------- c:\program files\Yahoo!
2009-01-14 21:53 . 2009-01-14 21:53 <REP> d-------- c:\program files\CCleaner
2009-01-14 21:53 . 2009-01-14 21:53 <REP> d-------- c:\documents and settings\utilisateur\Application Data\Yahoo!
2009-01-14 21:53 . 2009-01-14 21:53 <REP> d-------- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-01-14 21:51 . 2009-01-14 21:51 3,165,824 --a------ C:\ccsetup215.exe
2009-01-14 21:42 . 2009-01-14 21:42 455,168 --a------ C:\ToolsCleaner2.exe
2009-01-14 20:57 . 2009-01-14 20:57 <REP> d-------- c:\program files\FindyKill
2009-01-14 20:54 . 2009-01-14 20:54 528,333 --a------ C:\FindyKill.exe
2009-01-13 22:22 . 2009-01-13 22:22 <REP> d-------- c:\documents and settings\All Users\Application Data\TEMP
2009-01-13 20:51 . 2009-01-13 20:51 <REP> d-------- c:\program files\Lavasoft
2009-01-13 20:51 . 2009-01-13 20:51 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2009-01-13 20:50 . 2009-01-13 20:50 <REP> d-------- c:\program files\Fichiers communs\Wise Installation Wizard
2009-01-13 19:01 . 2009-01-13 19:01 39,936 --a------ c:\windows\system32\f59a60a9e4e776062ff32510b120d7d4.sys
2009-01-12 21:26 . 2009-01-12 21:26 <REP> d-------- c:\documents and settings\All Users\Application Data\1074857305
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-18 20:14 277,519 ----a-w c:\windows\system32\aeeccddab.dll
2009-01-18 20:14 277,519 ------w c:\windows\system32\9f01c8c5ba239031d7e3fbafe28e26d7.TMP
2009-01-06 06:22 806 ----a-w c:\windows\system32\drivers\SYMEVENT.INF
2009-01-06 06:22 60,808 ----a-w c:\windows\system32\S32EVNT1.DLL
2009-01-06 06:22 124,464 ----a-w c:\windows\system32\drivers\SYMEVENT.SYS
2009-01-06 06:22 10,635 ----a-w c:\windows\system32\drivers\SYMEVENT.CAT
2008-12-12 17:02 3,088,896 ------w c:\windows\system32\dllcache\mshtml.dll
2008-12-12 10:59 --------- d-----w c:\documents and settings\All Users\Application Data\CyberLink
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-11 10:57 333,952 ------w c:\windows\system32\dllcache\srv.sys
2008-11-07 15:45 2,174,976 ----a-w c:\windows\system32\dllcache\WMVCore.dll
2008-10-24 11:21 455,296 ------w c:\windows\system32\dllcache\mrxsmb.sys
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-23 12:36 286,720 ------w c:\windows\system32\dllcache\gdi32.dll
2008-02-18 22:13 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2006-08-17 20:57 278,528 ----a-w c:\program files\Fichiers communs\FDEUnInstaller.exe
2006-05-24 21:00 2,378,037 ----a-w c:\program files\wsbeta.zip
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- c:\windows\system32\f59a60a9e4e776062ff32510b120d7d4.sys ----
Company: Noves Inc
File Description: ckmd
File Version: 3, 35, 52, 123
Product Name: Noves ckmd
Copyright: Noves Inc ¸ 2007
Original file name: ckmd
MD5: 6c7234ec1cc778d45ffb265d026934a7
---- Directory of c:\documents and settings\All Users\Application Data\1074857305 ----
2009-01-14 18:34 97 --a------ c:\documents and settings\All Users\Application Data\1074857305\config.udb
2009-01-12 21:26 241 --a------ c:\documents and settings\All Users\Application Data\1074857305\init.udb
2009-01-12 21:26 12930 --a------ c:\documents and settings\All Users\Application Data\1074857305\Langs.udb
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-09-28 443968]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-05-30 21718312]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-13 68856]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" [2006-03-30 313472]
"WebCallDirect"="c:\program files\WebCallDirect.com\WebCallDirect\WebCallDirect.exe" [2008-12-10 9118008]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-08 2828184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2005-06-11 53248]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-08 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-08 688218]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-07-18 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-07-18 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-07-18 114688]
"EPM-DM"="c:\acer\epm\epm-dm.exe" [2005-08-11 200704]
"ePowerManagement"="c:\acer\ePM\ePM.exe" [2005-03-15 2893824]
"LManager"="c:\progra~1\LAUNCH~1\QtZgAcer.EXE" [2005-08-19 462848]
"eRecoveryService"="c:\program files\Acer\eRecovery\Monitor.exe" [2005-08-18 352256]
"WinVNC"="c:\program files\UltraVNC\WinVNC.exe" [2005-08-06 974848]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2006-01-12 483328]
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2008-03-07 53096]
"SSBkgdUpdate"="c:\program files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-17 57393]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-17 40960]
"ControlCenter2.0"="c:\program files\SP\ControlCenter2\brctrcen.exe" [2006-09-07 933888]
"SunJavaUpdateSched"="c:\program files\Java\j2re1.4.2_15\bin\jusched.exe" [2007-05-22 32881]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-12 413696]
"Symantec PIF AlertEng"="c:\program files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 c:\windows\system32\HdAShCut.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 c:\windows\system32\bthprops.cpl]
"RTHDCPL"="RTHDCPL.EXE" [2005-08-09 c:\windows\RTHDCPL.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-09-28 443968]
c:\documents and settings\utilisateur\Menu D‚marrer\Programmes\D‚marrage\
Pervasive.SQL Workgroup Engine.lnk - c:\pvsw\Bin\w3dbsmgr.exe [2004-07-22 106546]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Lancement rapide d'Adobe Acrobat.lnk - c:\windows\Installer\{AC76BA86-1033-F400-BA7E-000000000002}\SC_Acrobat.exe [2006-02-26 25214]
SoftRemoteLT.lnk - c:\program files\SafeNet\SoftRemoteLT\SafeCfg.exe [2006-02-26 53300]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\aeeccddab]
2009-01-18 21:14 277519 c:\windows\system32\aeeccddab.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux2"= wdmaud.sys
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Acrobat.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Acrobat.lnk
backup=c:\windows\pss\Lancement rapide d'Adobe Acrobat.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
--a------ 2006-01-12 20:52 483328 c:\program files\Adobe\Acrobat 7.0\Distillr\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\PVSW\\Bin\\w3dbsmgr.exe"=
"c:\\Program Files\\WebCallDirect.com\\WebCallDirect\\WebCallDirect.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
R3 DniVap;SafeNet WAN Miniport (VA);c:\windows\system32\drivers\vap.sys [2006-02-26 36188]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Fichiers communs\Symantec Shared\eengine\EraserUtilRebootDrv.sys [2006-08-16 99376]
R4 Crypto;Crypto;c:\windows\system32\drivers\Crypto.sys [2006-02-26 454202]
R4 EpmPsd;Acer EPM Power Scheme Driver;c:\windows\system32\drivers\epm-psd.sys [2006-02-06 4096]
R4 EpmShd;Acer EPM System Hardware Driver;c:\windows\system32\drivers\epm-shd.sys [2006-02-06 78208]
R4 IPSECDRV;SafeNet IPSec Plugin;c:\windows\system32\drivers\IpSecDrv.sys [2006-02-26 117304]
R4 osaio;osaio;c:\windows\system32\drivers\osaio.sys [2006-02-06 7296]
R4 osanbm;osanbm;c:\windows\system32\drivers\osanbm.sys [2006-02-06 4010]
S0 f59a60a9e4e776062ff32510b120d7d4;f59a60a9e4e776062ff32510b120d7d4;c:\windows\system32\f59a60a9e4e776062ff32510b120d7d4.sys [2009-01-13 39936]
S3 PLCMPR5;PLCMPR5 NDIS Protocol Driver;\??\c:\windows\system32\PLCMPR5.SYS --> c:\windows\system32\PLCMPR5.SYS [?]
S4 WinDefend;Windows Defender Service;c:\program files\Windows Defender\MsMpEng.exe [2006-02-10 45840]
.
Contenu du dossier 'Tâches planifiées'
2009-01-15 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-02-10 16:27]
2009-01-16 c:\windows\Tasks\Norton AntiVirus - Effectuer une analyse complète du système - utilisateur.job
- c:\progra~1\NORTON~1\Navw32.exe [2007-05-28 12:00]
.
.
------- Examen supplémentaire -------
.
uSearch Page =
hxxp://www.google.com
uDefault_Search_URL =
hxxp://www.google.com/ie
uSearch Bar =
hxxp://www.google.com/ie
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
IE: Convertir en Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir en un fichier PDF existant - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir la cible du lien en Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir la cible du lien en un fichier PDF existant - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir la sélection en Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir la sélection en un fichier PDF existant - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir les liens sélectionnés en fichier Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convertir les liens sélectionnés en un fichier PDF existant - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
c:\windows\Downloaded Program Files\oscan81.ocx_x - c:\windows\bdoscandellang.ini
c:\windows\bdoscandel.exe
c:\windows\Downloaded Program Files\live.ini
c:\windows\Downloaded Program Files\scanoptions.tsi
c:\windows\Downloaded Program Files\lang.ini
c:\windows\Downloaded Program Files\ipsupd.dll
c:\windows\Downloaded Program Files\bdupd.dll
c:\windows\Downloaded Program Files\libfn.dll
c:\windows\Downloaded Program Files\bdcore.dll
c:\windows\Downloaded Program Files\oscan8.ocx
O16 -: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}
hxxp://www.bitdefender.fr/scan8/oscan8.cab
c:\windows\Downloaded Program Files\oscan8.inf
FF - ProfilePath - c:\documents and settings\utilisateur\Application Data\Mozilla\Firefox\Profiles\mmzkitrm.default\
FF - plugin: c:\program files\Java\j2re1.4.2_15\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_15\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_15\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_15\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_15\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_15\bin\NPJPI142_15.dll
FF - plugin: c:\program files\Java\j2re1.4.2_15\bin\NPOJI610.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-18 21:16:15
Windows 5.1.2600 Service Pack 3 FAT NTAPI
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(1080)
c:\windows\system32\aeeccddab.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\SAFENET\SOFTREMOTELT\IREIKE.EXE
c:\program files\FICHIERS COMMUNS\SYMANTEC SHARED\CCSETMGR.EXE
c:\program files\FICHIERS COMMUNS\SYMANTEC SHARED\CCEVTMGR.EXE
c:\program files\FICHIERS COMMUNS\SYMANTEC SHARED\SNDSRVC.EXE
c:\program files\FICHIERS COMMUNS\SYMANTEC SHARED\SPBBC\SPBBCSVC.EXE
c:\program files\FICHIERS COMMUNS\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
c:\program files\LAVASOFT\AD-AWARE\AAWSERVICE.EXE
c:\windows\SYSTEM32\BRSVC01A.EXE
c:\windows\SYSTEM32\BRSS01A.EXE
c:\windows\SYSTEM32\RUNDLL32.EXE
c:\program files\LAUNCH MANAGER\QTZGACER.EXE
c:\acer\EMANAGER\ANBMSERV.EXE
c:\program files\SAFENET\SOFTREMOTELT\IPSECMON.EXE
c:\program files\FICHIERS COMMUNS\MICROSOFT SHARED\VS7DEBUG\MDM.EXE
c:\program files\Norton AntiVirus\navapsvc.exe
c:\program files\NORTON ANTIVIRUS\IWP\NPFMNTOR.EXE
c:\program files\SYMANTEC\LIVEUPDATE\ALUSCHEDULERSVC.EXE
c:\program files\Skype\Plugin Manager\skypePM.exe
c:\program files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Heure de fin: 2009-01-18 21:22:11 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-01-18 20:22:06
ComboFix2.txt 2009-01-18 19:23:48
Avant-CF: 6 500 925 440 octets libres
Après-CF: 6,487,228,416 octets libres
263 --- E O F --- 2009-01-15 02:07:43