Voici le rapport de ComboFix :
ComboFix 08-10-25.01 - DEFAULT 2008-10-26 18:40:33.2 -
FAT32x86
Lancé depuis: C:\Documents and Settings\DEFAULT\Bureau\ComboFix.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-26 au 2008-10-26 ))))))))))))))))))))))))))))))))))))
.
2008-10-26 15:32 . 2008-10-26 15:32 <REP> d--h----- C:\$AVG8.VAULT$
2008-10-26 14:55 . 2008-10-26 14:55 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-10-26 14:54 . 2008-10-26 14:54 <REP> d-------- C:\WINDOWS\system32\drivers\Avg
2008-10-26 14:54 . 2008-10-26 14:54 <REP> d-------- C:\Program Files\AVG
2008-10-26 14:54 . 2008-10-26 14:54 <REP> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-10-26 14:54 . 2008-10-26 14:54 97,928 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-10-26 14:51 . 2008-10-26 14:51 <REP> d-------- C:\Program Files\iTunes
2008-10-26 14:51 . 2008-10-26 14:51 <REP> d-------- C:\Program Files\iPod
2008-10-26 14:48 . 2008-10-26 14:48 <REP> d-------- C:\Program Files\CCleaner
2008-10-26 03:07 . 2008-10-26 03:07 249,592 --a------ C:\WINDOWS\system32\cssdll32.dll
2008-10-26 03:06 . 2008-10-26 03:06 <REP> d-------- C:\Program Files\COMODO
2008-10-26 02:09 . 2008-10-26 02:09 <REP> d-------- C:\Program Files\Eraser
2008-10-26 02:09 . 2008-10-26 02:09 <REP> d--h----- C:\Documents and Settings\All Users\Application Data\{74D61F17-FFC2-41AF-96E5-1DCB0631B6D1}
2008-10-25 00:53 . 2008-10-15 12:35 337,408 --------- C:\WINDOWS\system32\dllcache\netapi32.dll
2008-10-25 00:35 . 2008-10-25 00:35 <REP> d-------- C:\Program Files\Enigma Software Group
2008-10-23 04:00 . 2008-10-23 04:00 410,976 --a------ C:\WINDOWS\system32\deploytk.dll
2008-10-23 02:26 . 2008-10-23 02:26 579,584 --a------ C:\WINDOWS\system32\dllcache\user32.dll
2008-10-23 02:23 . 2008-10-22 02:19 <REP> d-------- C:\SDFix
2008-10-23 02:04 . 2008-10-23 02:04 <REP> d-------- C:\WINDOWS\ERUNT
2008-10-23 01:59 . 2008-10-23 02:00 <REP> d-------- C:\Program Files\Trend Micro
2008-10-23 01:37 . 2008-10-23 01:37 <REP> d-------- C:\Program Files\Fichiers communs\Kodak
2008-10-22 02:54 . 2008-10-22 02:54 <REP> d-------- C:\Documents and Settings\DEFAULT\Application Data\Malwarebytes
2008-10-22 02:54 . 2008-10-22 16:10 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-22 02:54 . 2008-10-22 16:10 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-22 02:53 . 2008-10-22 02:53 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-22 02:53 . 2008-10-22 02:54 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-22 02:09 . 2008-10-22 02:09 19,426 --a------ C:\WINDOWS\tywonyza.bin
2008-10-22 02:09 . 2008-10-22 02:09 19,255 --a------ C:\Documents and Settings\All Users\Application Data\motet.bin
2008-10-22 02:09 . 2008-10-22 02:09 18,900 --a------ C:\WINDOWS\cofysupa._sy
2008-10-22 02:09 . 2008-10-22 02:09 18,149 --a------ C:\WINDOWS\system32\bicyd._sy
2008-10-22 02:09 . 2008-10-22 02:09 17,550 --a------ C:\WINDOWS\qovixytyry.ban
2008-10-22 02:09 . 2008-10-22 02:09 17,345 --a------ C:\WINDOWS\system32\lopone.exe
2008-10-22 02:09 . 2008-10-22 02:09 16,743 --a------ C:\WINDOWS\lekabycewe.bat
2008-10-22 02:09 . 2008-10-22 02:09 16,506 --a------ C:\Documents and Settings\DEFAULT\Application Data\puhujagu.com
2008-10-22 02:09 . 2008-10-22 02:09 15,757 --a------ C:\WINDOWS\pawotelil.lib
2008-10-22 02:09 . 2008-10-22 02:09 14,580 --a------ C:\Documents and Settings\DEFAULT\Application Data\lenysukik.bin
2008-10-22 02:09 . 2008-10-22 02:09 14,010 --a------ C:\WINDOWS\system32\mywydunu._sy
2008-10-22 02:09 . 2008-10-22 02:09 12,224 --a------ C:\Documents and Settings\DEFAULT\Application Data\yloliqyxaq.bat
2008-10-22 02:09 . 2008-10-22 02:09 12,097 --a------ C:\WINDOWS\system32\urorolypob.pif
2008-10-22 02:09 . 2008-10-22 02:09 10,778 --a------ C:\WINDOWS\ceziwiqe.sys
2008-10-22 01:14 . 2008-10-22 01:36 10,240 --a------ C:\WINDOWS\system32\brastk.ex_
2008-10-20 21:08 . 2008-10-20 21:08 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-10-20 21:08 . 2008-10-20 21:08 1,409 --a------ C:\WINDOWS\QTFont.for
2008-10-14 13:49 . 2008-09-08 06:41 333,824 --------- C:\WINDOWS\system32\dllcache\srv.sys
2008-10-14 13:48 . 2008-08-14 09:23 2,191,232 --------- C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-14 13:48 . 2008-08-14 09:23 2,147,328 --------- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-14 13:48 . 2008-08-14 09:23 2,068,096 --------- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-14 13:48 . 2008-08-14 09:23 2,025,984 --------- C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-14 13:48 . 2008-09-15 11:26 1,846,528 --------- C:\WINDOWS\system32\dllcache\win32k.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-03 17:12 6,066,176 ------w C:\WINDOWS\system32\dllcache\ieframe.dll
2008-09-15 15:26 1,846,528 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-08 10:41 333,824 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-27 09:11 3,593,216 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-08-25 08:39 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-08-25 08:38 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-08-23 05:56 635,848 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-08-23 05:54 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-08-14 13:23 2,191,232 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:23 2,068,096 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-08-14 10:04 138,496 ------w C:\WINDOWS\system32\dllcache\afd.sys
2003-10-29 23:33 55,816 ----a-w C:\Documents and Settings\DEFAULT\Application Data\GDIPFONTCACHEV1.DAT
2008-07-17 19:00 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008071720080718\index.dat
.
(((((((((((((((((((((((((((((
snapshot@2008-10-26_14.29.54.50 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-08-14 17:00:04 102,400 ----a-r C:\WINDOWS\Installer\{E0219810-16E4-437D-9165-93D7B22524F9}\iTunesIco.exe
+ 2008-10-26 18:51:56 102,400 ----a-r C:\WINDOWS\Installer\{E0219810-16E4-437D-9165-93D7B22524F9}\iTunesIco.exe
+ 2008-10-26 18:54:56 26,824 ----a-w C:\WINDOWS\system32\drivers\avgmfx86.sys
- 2008-10-22 09:10:40 6,428,320 ----a-w C:\WINDOWS\system32\Restore\rstrlog.dat
+ 2008-10-26 22:27:06 11,984 ----a-w C:\WINDOWS\system32\Restore\rstrlog.dat
+ 2008-10-26 22:28:32 16,384 ----a-w C:\WINDOWS\Temp\Perflib_Perfdata_7dc.dat
+ 2006-12-02 02:56:00 96,256 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.dll
+ 2006-12-02 02:54:32 479,232 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll
+ 2006-12-02 02:54:34 548,864 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
+ 2006-12-02 02:54:32 626,688 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
+ 2006-12-02 04:25:52 1,101,824 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80.dll
+ 2006-12-02 04:25:56 1,093,120 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80u.dll
+ 2006-12-02 04:25:58 69,632 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80.dll
+ 2006-12-02 04:26:00 57,856 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80u.dll
+ 2006-12-02 04:08:00 40,960 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHS.dll
+ 2006-12-02 04:08:00 45,056 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHT.dll
+ 2006-12-02 04:08:00 65,536 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80DEU.dll
+ 2006-12-02 04:08:00 57,344 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ENU.dll
+ 2006-12-02 04:08:00 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ESP.dll
+ 2006-12-02 04:08:00 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80FRA.dll
+ 2006-12-02 04:08:00 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ITA.dll
+ 2006-12-02 04:08:00 49,152 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80JPN.dll
+ 2006-12-02 04:08:00 49,152 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80KOR.dll
+ 2006-12-02 04:46:44 65,536 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.OpenMP_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6c18549a\vcomp.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2003-03-11 155648]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2003-03-11 114688]
"VX3000"="C:\WINDOWS\vVX3000.exe" [2006-06-29 707376]
"SunJavaUpdateSched"="C:\Program Files\Java\jre6\bin\jusched.exe" [2008-10-23 136600]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-07-31 271672]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-10-26 1234712]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-13 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoLogOff"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.xvid"= xvid.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\System32\\LEXPPS.EXE"=
"C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
R0 Si3112r;Silicon Image SiI 3112 SATARaid Controller;C:\WINDOWS\system32\DRIVERS\si3112r.sys [2002-10-10 84529]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-10-26 97928]
R2 avg8wd;AVG Free8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-10-26 231704]
R2 JavaQuickStarterService;Java Quick Starter;C:\Program Files\Java\jre6\bin\jqs.exe [2008-10-23 152984]
R2 MSCamSvc;MSCamSvc;C:\Program Files\Microsoft LifeCam\MSCamSvc.exe [2006-06-29 187184]
*Newly Created Service* - CATCHME
.
Contenu du dossier 'Tâches planifiées'
2008-10-26 C:\WINDOWS\Tasks\Symantec NetDetect.job
- C:\Program Files\Symantec\LiveUpdate\NDetect.exe []
2008-10-26 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe []
.
.
------- Examen supplémentaire -------
.
FireFox -: Profile - C:\Documents and Settings\DEFAULT\Application Data\Mozilla\Firefox\Profiles\l3gh9i0g.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://login.live.com/login.srf?id=2&svc=mail&cbid=24325&msppjph=(...)
FF -: plugin - C:\Program Files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - C:\Program Files\Real\RealOne Player\Netscape6\nppl3260.dll
FF -: plugin - C:\Program Files\Real\RealOne Player\Netscape6\nprjplug.dll
FF -: plugin - C:\Program Files\Real\RealOne Player\Netscape6\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-26 18:44:10
Windows 5.1.2600 Service Pack 3 FAT NTAPI
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-10-26 18:45:48
ComboFix-quarantined-files.txt 2008-10-26 22:45:42
ComboFix2.txt 2008-10-26 18:30:46
Avant-CF: 17 429 594 112 octets libres
Après-CF: 17,413,570,560 octets libres
170 --- E O F --- 2008-10-25 16:59:32