Voici le rapport Combofix
Merci pour l'aide
ComboFix 09-09-23.02 - Gerard 24/09/2009 10:25.1.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.2046.1390 [GMT 2:00]
Lancé depuis: c:\documents and settings\Gerard\Bureau\ComboFix.exe
AV: avast! antivirus 4.8.1351 [VPS 090923-0] *On-access scanning enabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
FW: Norton Internet Worm Protection *disabled* {990F9400-4CEE-43EA-A83A-D013ADD8EA6E}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Installer\34758ff.msp
c:\windows\Installer\3490f86.msp
c:\windows\jestertb.dll
c:\windows\UA000023.DLL
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_GB
((((((((((((((((((((((((((((( Fichiers créés du 2009-08-24 au 2009-09-24 ))))))))))))))))))))))))))))))))))))
.
2009-09-24 07:00 . 2009-09-24 07:04 -------- d-----w- C:\ToolBar SD
2009-09-24 05:56 . 2009-09-24 05:56 -------- d-----w- c:\program files\Trend Micro
2009-09-23 14:50 . 2009-09-23 14:50 -------- d-----w- c:\documents and settings\Gerard\Local Settings\Application Data\Yahoo!
2009-09-16 20:47 . 2009-09-16 20:47 221664 ---ha-w- c:\windows\system32\mlfcache.dat
2009-09-16 05:44 . 2009-09-24 06:40 -------- d-----w- c:\documents and settings\Gerard\Tracing
2009-09-16 05:42 . 2009-09-16 05:42 -------- d-----w- c:\program files\Microsoft
2009-09-16 05:42 . 2009-09-16 05:42 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-09-16 05:38 . 2009-09-16 05:38 -------- d-----w- c:\program files\Fichiers communs\Windows Live
2009-09-12 08:10 . 2009-09-12 08:10 -------- d-----w- c:\program files\Utilitaire de configuration iPhone
2009-09-12 08:09 . 2009-09-12 08:09 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-09-12 08:08 . 2009-09-12 08:08 -------- d-----w- c:\program files\Bonjour
2009-09-09 06:03 . 2009-06-21 21:47 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-24 08:06 . 2007-04-20 12:33 -------- d-----w- c:\program files\Lx_cats
2009-09-22 20:04 . 2008-09-16 10:52 952 --sha-w- c:\documents and settings\All Users\Application Data\KGyGaAvL.sys
2009-09-16 20:47 . 2009-01-23 07:37 -------- d-----w- c:\documents and settings\Gerard\Application Data\Apple Computer
2009-09-16 05:43 . 2007-09-28 16:58 -------- d-----w- c:\program files\Windows Live
2009-09-16 05:43 . 2007-04-20 20:34 -------- d-----w- c:\program files\MSN Messenger
2009-09-12 08:11 . 2009-06-13 08:27 -------- d-----w- c:\program files\QuickTime
2009-09-12 08:09 . 2009-01-24 08:59 -------- d-----w- c:\program files\iTunes
2009-09-12 08:09 . 2009-01-24 08:59 -------- d-----w- c:\program files\iPod
2009-09-12 08:09 . 2009-01-24 09:28 -------- d-----w- c:\program files\Fichiers communs\Apple
2009-09-12 08:09 . 2009-01-24 09:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
2009-09-11 07:17 . 2009-04-04 08:16 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-10 12:54 . 2008-07-20 07:22 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 12:53 . 2008-06-28 18:30 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-09 20:08 . 2009-08-04 13:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-09-05 12:49 . 2007-04-21 08:39 -------- d-----w- c:\program files\Messenger Plus! Live
2009-08-23 04:02 . 2009-08-23 04:02 -------- d-----w- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2009-08-17 16:10 . 2007-05-24 09:09 1279456 ----a-w- c:\windows\system32\aswBoot.exe
2009-08-17 16:06 . 2007-05-24 09:09 93392 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-08-17 16:06 . 2007-05-24 09:09 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-08-17 16:05 . 2008-04-01 19:09 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-08-17 16:05 . 2008-04-01 19:09 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-08-17 16:04 . 2007-05-24 09:09 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-08-17 16:04 . 2007-05-24 09:09 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-08-17 16:03 . 2007-05-24 09:09 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-08-17 16:02 . 2007-05-24 09:09 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-08-13 08:12 . 2009-08-13 08:12 -------- d-----w- c:\program files\HD Tune
2009-08-05 09:00 . 2004-08-05 12:00 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-05 05:05 . 2007-06-05 20:07 -------- d-----w- c:\program files\Java
2009-08-04 15:12 . 2007-04-20 12:59 365968 ----a-w- c:\documents and settings\Gerard\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-04 14:14 . 2004-08-05 12:00 85404 ----a-w- c:\windows\system32\perfc00C.dat
2009-08-04 14:14 . 2004-08-05 12:00 513080 ----a-w- c:\windows\system32\perfh00C.dat
2009-08-04 13:18 . 2009-08-04 13:18 -------- d-----w- c:\program files\Microsoft Works
2009-08-04 13:18 . 2009-07-26 20:28 -------- d-----w- c:\program files\MSBuild
2009-08-04 13:17 . 2009-08-04 13:17 -------- d-----w- c:\program files\Microsoft.NET
2009-08-04 13:15 . 2009-08-04 13:15 -------- d-----w- c:\program files\Microsoft Visual Studio 8
2009-08-04 12:50 . 2007-04-25 08:49 -------- d-----w- c:\program files\CCleaner
2009-07-26 20:28 . 2009-07-26 20:28 -------- d-----w- c:\program files\Reference Assemblies
2009-07-26 14:44 . 2009-07-26 14:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
2009-07-25 03:23 . 2008-12-05 06:58 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-17 19:03 . 2004-08-05 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 21:43 . 2004-08-05 12:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-06-29 15:57 . 2004-08-05 12:00 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 15:57 . 2009-08-04 13:28 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 15:57 . 2004-08-05 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2007-04-21 11:03 . 2007-04-21 11:03 17929072 ----a-w- c:\program files\Install_Messenger.exe
2004-10-01 13:00 . 2007-04-19 16:52 40960 ----a-w- c:\program files\Uninstall_CDS.exe
2007-09-25 07:22 . 2007-05-03 10:49 168 --sh--r- c:\windows\system32\F44B1AC34A.sys
2008-12-08 19:55 . 2007-04-20 14:38 10332 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-25 68856]
"Pando"="c:\program files\Pando Networks\Pando\Pando.exe" [2009-02-05 3891016]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"Netlog Music Tool"="c:\program files\Netlog Music Tool\NetlogMusicTool.exe" [2009-02-12 1728456]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EM_EXEC"="c:\progra~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE" [2002-07-09 28672]
"MMTray"="c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe" [2002-05-20 90112]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-08-17 81000]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-06-07 180269]
"!AVG Anti-Spyware"="c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
"Corel Photo Downloader"="c:\program files\Fichiers communs\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe" [2008-08-08 532808]
"Corel File Shell Monitor"="c:\program files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exe" [2008-08-08 16712]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-02-21 366400]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-04 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-08 305440]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"SDFix"="g:\disque c\SdFix\SDFix\RunThis.bat" [2008-08-29 763431]
"LXDBCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXDBtime.dll" [2006-03-02 73728]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2008-01-08 1626112]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2007-9-10 110592]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImLc.exe"=
"c:\\Program Files\\Namo\\WebEditor 5 Trial\\bin\\WebEditor.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImPackr.exe"=
"c:\\Program Files\\Pando Networks\\Pando\\pando.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [01/04/2008 21:09 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [01/04/2008 21:09 20560]
S3 Ar10ais;Ar10ais; [x]
S3 lxdb_device;lxdb_device;c:\windows\system32\lxdbcoms.exe -service --> c:\windows\system32\lxdbcoms.exe -service [?]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenu du dossier 'Tâches planifiées'
2009-09-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-09-18 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2007\SystemOptimizer.exe [2007-01-17 12:47]
2009-09-24 c:\windows\Tasks\User_Feed_Synchronization-{DFEC7D64-7592-45CA-8FFC-58DCB6F66CD7}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 09:58]
.
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://orange.fr/
uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = localhost;*.local
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
IE: &Add animation to IncrediMail Style Box - c:\progra~1\INCRED~1\bin\resources\WebMenuImg.htm
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspx
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} -
hxxp://download.eset.com/special/eos/OnlineScanner.cab
.
- - - - ORPHELINS SUPPRIMES - - - -
URLSearchHooks-{06663B56-0D73-4f9f-BCC5-4AA941470AFD} - (no file)
SafeBoot-AVG Anti-Spyware Driver
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-24 10:31
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
MMTray = c:\program files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe?w???gx???V??gx???SOFTWARE\MusicMatch\MusicMatch Jukebox\4.0\TrayApp??????? ?w?????????????\?wp ?w???????w???g???????????g?RY??QY????????gz???2???????d???8???? @??%X??%X?????????????????x?Y?????^?Q?????
LXDBCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXDBtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
Recherche de fichiers cachés ...
c:\windows\TEMP\_av_proI.tm~a02044
c:\windows\TEMP\_av_proI.tm~a02044\setup.lok 0 bytes
Scan terminé avec succès
Fichiers cachés: 2
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(888)
c:\program files\Fichiers communs\Adobe\Adobe Drive CS4\AdobeDriveCS4_NP.dll
- - - - - - - > 'explorer.exe'(2184)
c:\program files\Windows Media Player\wmpband.dll
c:\progra~1\Logitech\MOUSEW~1\SYSTEM\LGMOUSHK.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PSIService.exe
c:\program files\Fichiers communs\Protexis\License Service\PsiService_2.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2009-09-24 10:34 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-09-24 08:34
Avant-CF: 76 344 274 944 octets libres
Après-CF: 76 636 065 792 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
228 --- E O F --- 2009-09-17 21:02