Bonjour naheulbeul,
Voilà le Log de ComboFix:
ComboFix 08-11-19.08 - Bigblue 2008-11-20 16:26:22.1 - NTFSx86 MINIMAL
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3075 [GMT -5:00]
Running from: C:\ComboFix.exe
[B]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/B]
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\khfGxvWp.dll
c:\windows\system32\mdm.exe
.
((((((((((((((((((((((((( Files Created from 2008-10-20 to 2008-11-20 )))))))))))))))))))))))))))))))
.
2008-11-20 16:29 . 2008-11-20 16:29 0 --a------ c:\windows\LCDMedia.INI
2008-11-20 15:40 . 2008-11-20 15:40 3,051,198 -ra------ C:\ComboFix.exe
2008-10-28 17:36 . 2008-10-28 17:36 823,296 --a------ c:\windows\system32\divx_xx0c.dll
2008-10-28 17:36 . 2008-10-28 17:36 823,296 --a------ c:\windows\system32\divx_xx07.dll
2008-10-28 17:35 . 2008-10-28 17:35 815,104 --a------ c:\windows\system32\divx_xx0a.dll
2008-10-28 17:35 . 2008-10-28 17:35 802,816 --a------ c:\windows\system32\divx_xx11.dll
2008-10-28 17:35 . 2008-10-28 17:35 729,088 --a------ c:\windows\system32\divxdec.ax
2008-10-28 17:35 . 2008-10-28 17:35 684,032 --a------ c:\windows\system32\DivX.dll
2008-10-20 12:22 . 2004-08-03 22:08 26,496 --a------ c:\windows\system32\dllcache\usbstor.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-20 13:17 --------- d-----w c:\program files\Easy Video Joiner
2008-11-19 15:35 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2008-11-03 21:01 --------- d-----w c:\program files\DivX
2008-10-12 20:31 --------- d-----w c:\documents and settings\Bigblue\Application Data\Bioshock
2008-10-09 14:25 --------- d-----w c:\program files\DAP
2008-10-09 14:25 --------- d-----w c:\documents and settings\All Users\Application Data\SpeedBit
2008-10-05 18:06 --------- d-----w c:\program files\Common Files\Wise Installation Wizard
2008-10-05 18:06 --------- d-----w c:\program files\AGEIA Technologies
2008-10-02 17:57 22,328 ----a-w c:\documents and settings\Bigblue\Application Data\PnkBstrK.sys
2008-10-02 12:59 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-02 12:53 --------- d-----w c:\program files\VirtualDub
2008-09-21 12:29 --------- d-----w c:\program files\Common Files\Logitech
2008-09-21 12:27 --------- d-----w c:\documents and settings\Bigblue\Application Data\Logitech
2008-09-21 12:25 --------- d-----w c:\program files\Logitech
2008-09-21 12:19 --------- d-----w c:\program files\Common Files\Logishrd
2008-09-21 12:07 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-09-21 12:07 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_LUsbFilt_01005.Wdf
2008-09-21 12:07 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2008-09-21 12:07 --------- d-----w c:\documents and settings\All Users\Application Data\LogiShrd
.
------- Sigcheck -------
2006-10-11 10:17 359040 80082776f5f39852ee40c521806e1135 c:\windows\system32\drivers\tcpip.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTSysVol"="c:\program files\Creative\SBAudigy4\Surround Mixer\CTSysVol.exe" [2005-02-15 57344]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-18 81000]
"Launch LCDMon"="c:\program files\Logitech\G-series Software\LCDMon.exe" [2006-03-06 497152]
"Look 'n' Stop"="c:\program files\Soft4Ever\looknstop\looknstop.exe" [2007-11-02 516164]
"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2007-09-25 93208]
"Logitech Hardware Abstraction Layer"="c:\program files\Common Files\Logitech\khalshared\KHALMNPR.EXE" [2006-07-19 94208]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 86016]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-07-19 c:\windows\KHALMNPR.Exe]
"nwiz"="nwiz.exe" [2008-09-17 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\Bigblue\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - c:\program files\Stardock\ObjectDock\ObjectDock.exe [2006-10-27 3450608]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2008-09-21 671744]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMMyDocs"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{93994DE8-8239-4655-B1D1-5F4E91300429}"= "c:\progra~1\DVDREG~1\DVDShell.dll" [2004-10-09 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadAccelerator]
--a------ 2008-10-09 09:25 3061248 c:\program files\DAP\DAP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a--c--- 2007-06-29 05:24 286720 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
--a--c--- 2006-08-11 13:56 17920 c:\windows\CTHELPER.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-03-31 110160]
R1 lnsfw1;lnsfw1;c:\windows\system32\drivers\lnsfw1.sys [2007-11-02 77184]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-03-31 20560]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{03ffa182-6564-11db-8870-806d6172696f}]
\Shell\AutoRun\command - F:\setup.exe
*Newly Created Service* - WUAUSERV
.
Contents of the 'Scheduled Tasks' folder
2007-10-27 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 14:42]
.
- - - - ORPHANS REMOVED - - - -
BHO-{B1629D92-AFE4-4B23-A39D-B092F1D1BCBF} - c:\windows\system32\khfGxvWp.dll
ShellExecuteHooks-{B1629D92-AFE4-4B23-A39D-B092F1D1BCBF} - c:\windows\system32\khfGxvWp.dll
Notify-khfGxvWp - khfGxvWp.dll
.
------- Supplementary Scan -------
.
FireFox -: Profile - c:\documents and settings\Bigblue\Application Data\Mozilla\Firefox\Profiles\k9lsj2wu.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://www.radio-canada.ca/index.shtml
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-20 16:29:07
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wscntfy.exe
c:\program files\Logitech\G-series Software\Applets\LCDClock.exe
c:\windows\system32\rundll32.exe
.
**************************************************************************
.
Completion time: 2008-11-20 16:30:20 - machine was rebooted
ComboFix-quarantined-files.txt 2008-11-20 21:30:17
Pre-Run: 13,730,709,504 bytes free
Post-Run: 13,686,743,040 bytes free
132
Il semble que le fichier khfGxvWp.dll dans system32 ai été suprimé
Merci! y a t-il autre chose ?