Bonjour,
Bon sauf omission de ma part, ci-joint le rapport combofix :
moi rien comprendre... lol
ComboFix 08-11-03.06 - Propriétaire 2008-11-04 17:10:58.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.635 [GMT 1:00]
Lancé depuis: c:\documents and settings\Propriétaire\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Downloaded Program Files\rave
c:\windows\Downloaded Program Files\rave\avirexe.vdm
c:\windows\Downloaded Program Files\rave\avirscr.vdm
c:\windows\Downloaded Program Files\rave\base.vdm
c:\windows\Downloaded Program Files\rave\daily.vdm
c:\windows\Downloaded Program Files\rave\daily.vdt
c:\windows\Downloaded Program Files\rave\filters.vdm
c:\windows\Downloaded Program Files\rave\kernel.vdk
c:\windows\Downloaded Program Files\rave\keyring.vdk
c:\windows\Downloaded Program Files\rave\mapi_vdm.vdm
c:\windows\Downloaded Program Files\rave\modules.vdk
c:\windows\Downloaded Program Files\rave\rav8def.vdm
c:\windows\Downloaded Program Files\rave\rufs.vdm
c:\windows\Downloaded Program Files\rave\rufsplg.vdm
c:\windows\Downloaded Program Files\rave\unarch.vdm
c:\windows\Downloaded Program Files\rave\unmail.vdm
c:\windows\Downloaded Program Files\rave\unpack.vdm
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-04 au 2008-11-04 ))))))))))))))))))))))))))))))))))))
.
2008-11-03 18:43 . 2008-11-03 18:43 <REP> d-------- c:\documents and settings\Administrateur\Application Data\Malwarebytes
2008-11-03 18:24 . 2008-11-03 18:26 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-03 18:24 . 2008-11-03 18:24 <REP> d-------- c:\documents and settings\Propriétaire\Application Data\Malwarebytes
2008-11-03 18:24 . 2008-11-03 18:24 <REP> d-------- c:\documents and settings\Propriétaire\Application Data\Malwarebytes
2008-11-03 18:24 . 2008-11-03 18:24 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-03 18:24 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-03 18:24 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-02 18:52 . 2008-11-02 20:06 <REP> d-------- c:\documents and settings\Propriétaire\.homeplayer
2008-11-02 18:52 . 2008-11-02 20:06 <REP> d-------- c:\documents and settings\Propriétaire\.homeplayer
2008-11-02 18:51 . 2008-11-02 20:05 <REP> d-------- c:\program files\HomePlayer
2008-10-30 22:19 . 2008-10-30 22:20 <REP> d-------- c:\program files\Freeplayer
2008-10-29 18:59 . 2008-10-29 19:05 <REP> d-------- c:\program files\Spybot - Search & Destroy
2008-10-24 11:12 . 2008-10-15 17:35 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-10-15 16:41 . 2008-09-08 11:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
2008-10-15 16:40 . 2008-08-14 14:23 2,191,232 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-10-15 16:40 . 2008-08-14 14:23 2,147,328 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-10-15 16:40 . 2008-08-14 14:23 2,068,096 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-15 16:40 . 2008-08-14 14:23 2,025,984 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-10-15 16:40 . 2008-09-15 16:26 1,846,528 -----c--- c:\windows\system32\dllcache\win32k.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-04 16:31 23,921,440 --sha-w c:\windows\system32\drivers\fidbox.dat
2008-11-04 16:26 783,136 --sha-w c:\windows\system32\drivers\fidbox2.dat
2008-11-04 16:26 --------- d-----w c:\program files\Lx_cats
2008-11-04 16:21 78,572 --sha-w c:\windows\system32\drivers\fidbox2.idx
2008-11-04 16:21 325,460 --sha-w c:\windows\system32\drivers\fidbox.idx
2008-11-04 15:15 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-11-02 22:01 --------- d-----w c:\program files\eMule
2008-10-30 21:20 --------- d-----w c:\documents and settings\Propriétaire\Application Data\vlc
2008-10-30 21:20 --------- d-----w c:\documents and settings\Propriétaire\Application Data\vlc
2008-10-30 16:41 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-29 21:05 --------- d-----w c:\program files\Apple Software Update
2008-09-25 10:00 --------- d--h--w c:\program files\InstallShield Installation Information
2008-09-25 10:00 --------- d-----w c:\program files\e-Carte Bleue Banque Populaire
2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
2008-09-13 18:39 --------- d-----w c:\documents and settings\Propriétaire\Application Data\FaxCtr
2008-09-13 18:39 --------- d-----w c:\documents and settings\Propriétaire\Application Data\FaxCtr
2008-09-12 19:31 --------- d-----w c:\documents and settings\Propriétaire\Application Data\Lexmark Imaging Studio
2008-09-12 19:31 --------- d-----w c:\documents and settings\Propriétaire\Application Data\Lexmark Imaging Studio
2008-09-12 19:22 --------- d-----w c:\program files\Lexmark Fax Solutions
2008-09-12 19:22 --------- d-----w c:\program files\Lexmark 2500 Series
2008-09-12 19:21 --------- d-----w c:\documents and settings\All Users\Application Data\FaxCtr
2008-09-12 19:20 --------- d-----w c:\program files\Lexmark Toolbar
2008-09-12 19:20 --------- d-----w c:\program files\Abbyy FineReader 6.0 Sprint
2008-09-08 10:41 333,824 ----a-w c:\windows\system32\drivers\srv.sys
2008-09-05 23:37 --------- d-----w c:\program files\MSN Messenger
2008-08-26 08:11 826,368 ----a-w c:\windows\system32\wininet.dll
2008-08-14 13:23 2,191,232 ----a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 13:23 2,068,096 ----a-w c:\windows\system32\ntkrnlpa.exe
2006-07-24 17:14 278,528 ----a-w c:\program files\Fichiers communs\FDEUnInstaller.exe
2006-10-23 09:33 12,208 --sha-w c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AtiPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-03-22 335872]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"UMonit"="c:\windows\system32\UMonit.exe" [2007-06-18 200704]
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" [2007-02-13 312240]
"LXDDCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXDDtime.dll" [2007-01-22 102400]
"AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2008-02-08 227856]
"nForce Tray Options"="sstray.exe" [2003-08-13 c:\windows\system32\sstray.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Wireless Configuration Utility HW.32.lnk - c:\windows\Installer\{BDC88E5A-F47B-4314-AB38-994592E32C95}\NewShortcut1.exe [2006-07-24 40960]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxddamon]
--a------ 2007-02-06 00:32 20480 c:\program files\Lexmark 2500 Series\lxddamon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\lxddmon.exe]
--a------ 2007-02-13 00:58 291760 c:\program files\Lexmark 2500 Series\lxddmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:55 5674352 c:\program files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Kazaa Lite K++\\Kazaa.kpp"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Lexmark 2500 Series\\lxddamon.exe"=
"c:\\Program Files\\Lexmark 2500 Series\\App4R.exe"=
"c:\\WINDOWS\\system32\\lxddcoms.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8080:TCP"= 8080:TCP:freeplayer
"1234:UDP"= 1234:UDP:freeplayer2
"80:TCP"= 80:TCP:free mon site
"80:UDP"= 80:UDP:free mon site
R0 SI3112r;Silicon Image SiI 3112 SATARaid Controller;c:\windows\system32\DRIVERS\SI3112r.sys [2006-01-12 102528]
R0 tffsport;M-Systems DiskOnChip 2000;c:\windows\system32\DRIVERS\tffsport.sys [2008-04-13 149376]
R2 lxdd_device;lxdd_device;c:\windows\system32\lxddcoms.exe [2007-02-13 537520]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\DRIVERS\klim5.sys [2007-12-13 24592]
S3 CA500AI;ePhoto CL20 Still Image Capture Version 1.00;c:\windows\system32\Drivers\CL20.sys [2000-11-14 10075]
S3 CA500AV;ePhoto CL20 WDM Video Capture;c:\windows\system32\DRIVERS\Cl20AV.SYS [2000-11-14 174743]
S3 ids00026;ids00026;c:\documents and settings\All Users\Application Data\Kaspersky Anti-Virus Personal\5.0\bases\ids00026.sys [ ]
S3 ids0005c;ids0005c;c:\documents and settings\All Users\Application Data\Kaspersky Anti-Virus Personal\5.0\bases\ids0005c.sys [ ]
S3 SIS163u;SiS 163 usb Wireless LAN Adapter Driver;c:\windows\system32\DRIVERS\sis163u.sys [2004-12-31 167424]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eab1ba63-f988-11dc-bbfb-93a48157d41a}]
\Shell\AutoRun\command - G:\LaunchU3.exe -a
.
- - - - ORPHELINS SUPPRIMES - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
HKCU-Run-StopClope - c:\program files\StopClope\bin\StopClope.exe
HKLM-Run-AQ3HelperStartUp - c:\progra~1\AQUATI~1\AQ3HEL~1.EXE
.
------- Examen supplémentaire -------
.
FireFox -: Profile - c:\documents and settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\hdtw58jr.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL -
hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://www.yahoo.fr/
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npmidas.dll
FF -: plugin - c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-04 17:23:02
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\ati2evxx.exe
c:\program files\IVT Corporation\BlueSoleil\BTNtService.exe
c:\windows\system32\drivers\CDAC11BA.EXE
c:\program files\802.11 Wireless LAN\802.11g Pen Size Wireless USB 2.0 Adapter HW.32 V1.10\WlanCU.exe
c:\program files\802.11 Wireless LAN\802.11g Pen Size Wireless USB 2.0 Adapter HW.32 V1.10\SiSWLSvc.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2008-11-04 17:36:02 - La machine a redémarré [Propriétaire]
ComboFix-quarantined-files.txt 2008-11-04 16:35:50
Avant-CF: 8,844,775,424 octets libres
Après-CF: 9,540,337,664 octets libres
191 --- E O F --- 2008-10-19 18:29:27