Salut Dede
Voici le rapport combofix. J'ai du le rouler 2 fois. je n,ai pas trouve le premier rapport. Voici
ComboFix 09-08-25.02 - Eric 2009-08-25 23:04.6.1 - NTFSx86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.2.1033.18.255.110 [GMT -4:00]
Running from: c:\documents and settings\Eric\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
c:\documents and settings\All Users\Application Data\96609216.ini
c:\documents and settings\Eric\Start Menu\Programs\Windows Antivirus Pro
c:\documents and settings\Eric\Start Menu\Programs\Windows Antivirus Pro\Windows Antivirus Pro.lnk
c:\program files\Windows Antivirus Pro
c:\program files\Windows Antivirus Pro\msvcm80.dll
c:\program files\Windows Antivirus Pro\msvcp80.dll
c:\program files\Windows Antivirus Pro\msvcr80.dll
c:\program files\Windows Antivirus Pro\Windows Antivirus Pro.exe
c:\windows\Installer\32e6e.msi
c:\windows\ppp3.dat
c:\windows\ppp4.dat
c:\windows\svchast.exe
c:\windows\system32\3971510106.dat
c:\windows\system32\bennuar.old
c:\windows\system32\bincd32.dat
c:\windows\system32\dddesot.dll
c:\windows\system32\desot.exe
c:\windows\system32\drivers\Sonyhcp.dll
c:\windows\system32\images
c:\windows\system32\images\i1.gif
c:\windows\system32\images\i2.gif
c:\windows\system32\images\i3.gif
c:\windows\system32\images\j1.gif
c:\windows\system32\images\j2.gif
c:\windows\system32\images\j3.gif
c:\windows\system32\images\jj1.gif
c:\windows\system32\images\jj2.gif
c:\windows\system32\images\jj3.gif
c:\windows\system32\images\l1.gif
c:\windows\system32\images\l2.gif
c:\windows\system32\images\l3.gif
c:\windows\system32\images\pix.gif
c:\windows\system32\images\t1.gif
c:\windows\system32\images\t2.gif
c:\windows\system32\images\up1.gif
c:\windows\system32\images\up2.gif
c:\windows\system32\images\w1.gif
c:\windows\system32\images\w11.gif
c:\windows\system32\images\w2.gif
c:\windows\system32\images\w3.gif
c:\windows\system32\images\w3.jpg
c:\windows\system32\images\wt1.gif
c:\windows\system32\images\wt2.gif
c:\windows\system32\images\wt3.gif
c:\windows\system32\nerocheck.exe
c:\windows\system32\sonhelp.htm
c:\windows\system32\sysnet.dat
c:\windows\system32\tapi.nfo
c:\windows\system32\wispex.html
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_AntipPro2009_100
-------\Service_AntipPro2009_100
((((((((((((((((((((((((( Files Created from 2009-07-26 to 2009-08-26 )))))))))))))))))))))))))))))))
.
2009-08-26 02:26 . 2009-08-26 02:26 -------- dc----w- C:\rsit
2009-08-24 23:18 . 2009-08-24 17:35 145920 ----a-w- c:\windows\msb.exe
2009-08-24 22:34 . 2009-08-24 22:34 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-08-14 19:30 . 2009-06-25 08:25 54272 -c----w- c:\windows\system32\dllcache\wdigest.dll
2009-08-14 19:30 . 2009-06-25 08:25 136192 -c----w- c:\windows\system32\dllcache\msv1_0.dll
2009-08-14 19:30 . 2009-06-24 11:18 92928 -c----w- c:\windows\system32\dllcache\ksecdd.sys
2009-08-14 19:30 . 2009-06-25 08:25 301568 -c----w- c:\windows\system32\dllcache\kerberos.dll
2009-08-13 10:08 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-08-05 09:01 . 2009-08-05 09:01 204800 -c----w- c:\windows\system32\dllcache\mswebdvd.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-26 02:26 . 2009-05-25 23:01 -------- d-----w- c:\program files\trend micro
2009-08-18 21:12 . 2009-05-31 17:02 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-08-14 21:43 . 2004-01-17 23:41 -------- d-----w- c:\documents and settings\Eric\Application Data\MSN6
2009-08-05 09:01 . 2004-02-01 20:58 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-27 03:00 . 2009-07-27 03:00 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-27 02:59 . 2005-06-06 00:59 -------- d-----w- c:\program files\Java
2009-07-27 02:59 . 2009-06-01 01:12 152576 ----a-w- c:\documents and settings\Eric\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-07-21 04:42 . 2006-01-01 15:28 -------- d-----w- c:\program files\LimeWire
2009-07-17 19:01 . 2003-05-27 15:41 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 14:08 . 2003-05-27 15:51 286720 ----a-w- c:\windows\system32\wmpdxm.dll
2009-07-03 17:09 . 2004-02-06 23:05 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-30 00:48 . 2009-06-30 00:47 -------- d-----w- c:\program files\PartyGaming
2009-06-25 08:25 . 2003-05-27 15:42 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2003-05-27 15:42 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2003-05-27 15:42 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2003-05-27 15:42 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-25 08:25 . 2003-05-27 15:42 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2003-05-27 15:42 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-24 11:18 . 2003-05-27 15:42 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-22 23:50 . 2009-06-22 23:50 2967799 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
2009-06-16 14:36 . 2003-05-27 15:42 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2003-05-27 15:42 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-13 14:19 . 2004-10-09 17:36 64920 ----a-w- c:\documents and settings\Eric\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-12 12:31 . 2003-05-27 15:42 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2003-05-27 15:41 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2003-05-27 15:52 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2003-05-27 15:42 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-03 19:09 . 2003-05-30 16:00 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-05-30 17:49 . 2009-05-30 17:54 227 ----a-w- c:\windows\system.tmp
2004-07-13 02:59 . 2004-07-13 02:58 16706160 ----a-w- c:\program files\AdbeRdr60_enu_full.exe
.
------- Sigcheck -------
[-] 2005-05-25 19:07 359936 63FDFEA54EB53DE2D863EE454937CE1E c:\windows\$hf_mig$\KB893066\SP2QFE\tcpip.sys
[-] 2006-01-13 17:07 360448 5562CC0A47B2AEF06D3417B733F3C195 c:\windows\$hf_mig$\KB913446\SP2QFE\tcpip.sys
[-] 2006-04-20 12:18 360576 B2220C618B42A2212A59D91EBD6FC4B4 c:\windows\$hf_mig$\KB917953\SP2QFE\tcpip.sys
[-] 2007-10-30 16:53 360832 64798ECFA43D78C7178375FCDD16D8C8 c:\windows\$hf_mig$\KB941644\SP2QFE\tcpip.sys
[7] 2008-06-20 10:44 360960 744E57C99232201AE98C49168B918F48 c:\windows\$hf_mig$\KB951748\SP2QFE\tcpip.sys
[7] 2008-06-20 11:51 361600 9AEFA14BD6B182D61E3119FA5F436D3D c:\windows\$hf_mig$\KB951748\SP3GDR\tcpip.sys
[7] 2008-06-20 11:59 361600 AD978A1B783B5719720CFF204B666C8E c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys
[7] 2008-06-20 10:45 360320 2A5554FC5B1E04E131230E3CE035C3F9 c:\windows\$NtServicePackUninstall$\tcpip.sys
[7] 2004-08-04 06:14 359040 9F4B36614A0FC234525BA224957DE55C c:\windows\$NtUninstallKB893066$\tcpip.sys
[-] 2005-05-25 19:04 359808 88763A98A4C26C409741B4AA162720C9 c:\windows\$NtUninstallKB913446$\tcpip.sys
[-] 2006-01-13 02:28 359808 583E063FDC888CA30D05C2724B0D7EF4 c:\windows\$NtUninstallKB917953$\tcpip.sys
[-] 2006-04-20 11:51 359808 1DBF125862891817F374F407626967F4 c:\windows\$NtUninstallKB941644$\tcpip.sys
[7] 2008-04-13 19:20 361344 93EA8D04EC73A85DB02EB8805988F733 c:\windows\$NtUninstallKB951748$\tcpip.sys
[-] 2007-10-30 17:20 360064 90CAFF4B094573449A0872A0F919B178 c:\windows\$NtUninstallKB951748_0$\tcpip.sys
[-] 2008-04-13 19:20 361344 ACCF5A9A1FFAA490F33DBA1C632B95E1 c:\windows\ServicePackFiles\i386\tcpip.sys
[-] 2008-06-20 11:51 361600 9425B72F40257B45D45D24773273DAD0 c:\windows\system32\dllcache\tcpip.sys
[-] 2008-06-20 11:51 361600 9425B72F40257B45D45D24773273DAD0 c:\windows\system32\drivers\tcpip.sys
.
(((((((((((((((((((((((((((((
SnapShot@2009-08-26_00.05.34 )))))))))))))))))))))))))))))))))))))))))
.
+ 2003-05-27 15:41 . 2002-08-29 12:00 67584 c:\windows\I386\WINNT32.MSI
+ 2003-05-27 18:05 . 2002-08-29 12:00 793088 c:\windows\VALUEADD\MSFT\NTBACKUP\NTBACKUP.MSI
+ 2003-05-27 18:05 . 2002-08-29 12:00 185856 c:\windows\VALUEADD\MSFT\MGMT\WBEMODBC\WBEMODBC.MSI
+ 2008-09-12 22:22 . 2007-04-02 18:34 366080 c:\windows\ServicePackFiles\i386\digreqex.msi
+ 2008-09-12 22:22 . 2007-04-02 18:34 863232 c:\windows\ServicePackFiles\i386\digopt.msi
+ 2007-09-03 03:22 . 2007-09-03 03:22 282624 c:\windows\Installer\fa7952e.msi
+ 2005-06-06 00:59 . 2005-06-06 00:59 621056 c:\windows\Installer\b90f72.msi
+ 2004-12-27 04:33 . 2004-12-27 04:33 195584 c:\windows\Installer\65a4c7f.msi
+ 2009-06-01 02:05 . 2009-06-01 02:05 355328 c:\windows\Installer\5a0a4.msi
+ 2009-05-31 17:01 . 2009-05-31 17:01 228352 c:\windows\Installer\28136.msi
+ 2006-07-19 15:35 . 2006-07-19 15:35 115712 c:\windows\Installer\11a95c1b.msi
+ 2009-07-27 02:59 . 2009-07-27 02:59 598016 c:\windows\Installer\114d99.msi
+ 2003-05-27 16:07 . 2003-05-27 16:07 666624 c:\windows\Installer\1092b.msi
+ 2003-05-27 16:00 . 2003-05-27 16:00 264704 c:\windows\Installer\10927.msi
+ 2003-05-27 15:42 . 2004-07-17 18:35 1326080 c:\windows\system32\webfldrs.msi
+ 2004-07-17 18:35 . 2004-07-17 18:35 1326080 c:\windows\ServicePackFiles\i386\webfldrs.msi
+ 2008-09-12 22:23 . 2007-04-02 18:42 5080576 c:\windows\ServicePackFiles\i386\msnmsgs.msi
+ 2009-06-20 03:35 . 2009-06-20 03:35 1021952 c:\windows\Installer\fa3861.msi
+ 2008-02-11 19:11 . 2008-02-11 19:11 7423488 c:\windows\Installer\388e44c.msi
+ 2008-02-11 19:10 . 2008-02-11 19:10 1527808 c:\windows\Installer\388e419.msi
+ 2007-09-10 00:33 . 2007-09-10 00:33 3200000 c:\windows\Installer\331896d8.msi
+ 2004-01-06 06:32 . 2004-01-06 06:32 2255360 c:\windows\Installer\2dc74.msi
+ 2004-01-06 06:28 . 2004-01-06 06:28 2369024 c:\windows\Installer\2dba7.msi
+ 2005-12-27 13:13 . 2005-12-27 13:13 1239552 c:\windows\Installer\18c9834.msi
+ 2006-07-19 15:34 . 2006-07-19 15:34 1002496 c:\windows\Installer\11a95c12.msi
+ 2004-05-06 12:07 . 2004-05-06 12:06 6369280 c:\windows\Downloaded Installations\{FB590DCB-74FE-4352-A2C5-1BEAAC216F7E}\Adobe Photoshop Album 2 ED.msi
+ 2005-07-04 00:53 . 2005-07-04 00:53 6076928 c:\windows\Downloaded Installations\{DF2E8A41-7E98-427D-9582-7D2EAF44F827}\Microsoft AntiSpyware.msi
+ 2005-12-20 02:43 . 2005-12-20 02:42 6170112 c:\windows\Downloaded Installations\{C0FA7138-477B-4FEC-8F23-640C21C2287B}\Microsoft AntiSpyware.msi
+ 2005-02-06 00:50 . 2005-02-06 00:50 5791744 c:\windows\Downloaded Installations\{80198C48-0633-46B5-A2A4-EB62DAA02D78}\Microsoft AntiSpyware.msi
+ 2005-07-25 01:42 . 2005-07-25 01:42 6120448 c:\windows\Downloaded Installations\{78CB0701-6520-4FAE-99CE-20DE50BEF25C}\Microsoft AntiSpyware.msi
+ 2004-07-13 02:59 . 2003-11-03 23:06 2250100 c:\windows\Cache\Adobe Reader 6.0.1\ENUBIG\Adobe Reader 6.0.1.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2005-05-19 1957888]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"iIWiper"="c:\program files\iISystem Wiper\SystemWiper.exe" [2005-09-11 258048]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QAGENT"="c:\program files\QUICKENW\QAGENT.EXE" [2001-11-14 94208]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2005-06-03 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-27 148888]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-02-16 282624]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"ALUAlert"="c:\program files\Symantec\LiveUpdate\ALUNotify.exe" [BU]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
Assistant Internet.lnk - c:\program files\NetAssistant\bin\matcli.exe [2005-6-5 217088]
[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
Source= c:\windows\system32\onhelp.htm
FriendlyName= tets
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"IncrediMail"=c:\program files\IncrediMail\bin\IncMail.exe /c
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NeroCheck"=c:\windows\system32\NeroCheck.exe
"ATIPTA"=c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
"IPInSightMonitor 01"="c:\program files\Visual Networks\Visual IP InSight\Sympatico Consumer\IPMon32.exe"
"IPInSightLAN 01"="c:\program files\Visual Networks\Visual IP InSight\Sympatico Consumer\IPClient.exe" -l
"SoundMan"=SOUNDMAN.EXE
"Symantec NetDriver Monitor"=c:\progra~1\SYMNET~1\SNDMon.exe /Consumer
"Motive SmartBridge"=c:\progra~1\NETASS~1\SMARTB~1\MotiveSB.exe
"SsAAD.exe"=c:\progra~1\Sony\SONICS~1\SsAAD.exe
"QAGENT"=c:\program files\QUICKENW\QAGENT.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\WINDOWS\\system32\\dxdiag.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
S2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-05-31 108289]
S2 mrtRate;mrtRate;c:\windows\system32\drivers\MrtRate.sys [2004-01-04 34712]
S4 WinDefend;Windows Defender Service;c:\program files\Windows Defender\MsMpEng.exe [2006-04-03 14032]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-08-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 20:42]
2009-08-24 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-04-03 22:12]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-NeroFilterCheck - c:\windows\system32\NeroCheck.exe
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = 127.0.0.1
DPF: DirectAnimation Java Classes -
file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
DPF: {18CD2FD8-81CE-44C3-99E1-0822E1C7116C} -
hxxp://files.ea.com/downloads/rtpatch/v4/EARTP8X.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} -
hxxp://download.eset.com/special/eos/OnlineScanner.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-08-25 23:11
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-3277439761-2136417557-3852222622-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(436)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(988)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
.
Completion time: 2009-08-26 23:15
ComboFix-quarantined-files.txt 2009-08-26 03:15
ComboFix2.txt 2009-08-26 00:10
ComboFix3.txt 2009-08-25 23:57
Pre-Run: 28 634 664 960 bytes free
Post-Run: 28 616 310 784 bytes free
267 --- E O F --- 2009-08-19 01:01