Combofix fonctionne à présent :-))
ComboFix 09-08-23.01 - Administrateur 26/08/2009 16:26.1.1 - NTFSx86 MINIMAL
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.510.284 [GMT 2:00]
Running from: c:\documents and settings\Administrateur\Bureau\Delirium79.exe
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\uacinit.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_UACd.sys
-------\Service_UACd.sys
((((((((((((((((((((((((( Files Created from 2009-07-26 to 2009-08-26 )))))))))))))))))))))))))))))))
.
2009-08-26 13:43 . 2007-01-18 12:00 3968 ----a-w- c:\windows\system32\drivers\AvgArCln.sys
2009-08-25 12:38 . 2009-08-25 12:38 -------- d-----w- c:\windows\ERUNT
2009-08-25 12:33 . 2009-08-25 12:49 -------- d-----w- C:\SDFix
2009-08-25 07:23 . 2009-08-25 07:23 -------- d-----w- c:\documents and settings\Administrateur\Local Settings\Application Data\Symantec
2009-08-25 06:51 . 2009-08-25 06:51 -------- d--h--w- c:\windows\system32\GroupPolicy
2009-08-24 14:16 . 2009-08-24 14:16 -------- d-----w- C:\rsit
2009-08-24 14:16 . 2009-08-24 14:16 -------- d-----w- c:\program files\trend micro
2009-08-24 08:35 . 2009-08-24 08:35 -------- d-s---w- c:\documents and settings\Administrateur.GARAGEDUCARREFO\UserData
2009-08-24 07:25 . 2009-08-24 07:25 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Malwarebytes
2009-08-24 06:10 . 2009-08-24 06:23 -------- d-----w- C:\graph
2009-08-21 15:05 . 2009-08-21 15:05 -------- d-----w- c:\program files\Microsoft Silverlight
2009-08-21 14:49 . 2009-08-21 14:49 -------- d-----w- c:\documents and settings\GLaurent\Application Data\Malwarebytes
2009-08-21 14:48 . 2009-08-03 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-21 14:48 . 2009-08-21 14:49 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-21 14:48 . 2009-08-21 14:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-21 14:48 . 2009-08-03 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-21 11:23 . 2009-03-24 14:07 55640 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-08-21 07:35 . 2009-08-21 08:31 -------- d-----w- c:\program files\Lavasoft
2009-08-21 07:35 . 2009-08-21 08:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-08-20 14:25 . 2009-08-24 08:28 -------- d-----w- c:\program files\a-squared Free
2009-08-20 14:24 . 2009-08-26 06:22 -------- d-----w- c:\program files\CCleaner
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-26 13:45 . 2009-07-25 09:32 19968 ----a-w- c:\windows\system32\UACqvngwuflut.dll
2009-08-26 13:45 . 2009-07-25 09:32 174 ----a-w- c:\windows\system32\UACrjnkciqugq.dat
2009-08-26 13:45 . 2009-07-25 09:32 74240 ----a-w- c:\windows\system32\UACulkmotawin.dll
2009-08-25 08:39 . 2009-07-27 07:23 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-08-25 08:08 . 2006-03-10 17:00 -------- d-----w- c:\program files\Fichiers communs\Symantec Shared
2009-08-25 08:08 . 2006-03-10 17:00 -------- d-----w- c:\program files\Symantec AntiVirus
2009-08-25 07:23 . 2006-03-10 17:00 -------- d-----w- c:\program files\Symantec
2009-08-20 14:22 . 2004-08-05 12:00 80364 ----a-w- c:\windows\system32\perfc00C.dat
2009-08-20 14:22 . 2004-08-05 12:00 482304 ----a-w- c:\windows\system32\perfh00C.dat
2009-08-20 14:18 . 2005-09-24 11:49 -------- d-----w- c:\documents and settings\GLaurent\Application Data\Lavasoft
2009-07-27 07:23 . 2009-07-27 07:23 -------- d-----w- c:\program files\AVG
2009-07-25 09:32 . 2009-07-25 09:32 18432 ----a-w- c:\windows\system32\UACfspfdprbhb.dll
2009-07-25 09:32 . 2009-07-25 09:32 30208 ----a-w- c:\windows\system32\UACjkmvbvphfd.dll
2009-07-25 09:32 . 2009-07-25 09:32 26624 ----a-w- c:\windows\system32\UACpxevstyqxd.dll
2009-07-25 09:32 . 2009-07-25 09:32 54784 ----a-w- c:\windows\system32\drivers\UACeptklrxume.sy_
2009-07-25 09:32 . 2009-07-25 09:32 843776 ----a-w- c:\windows\system32\UACfvlrohjqqb.dll
2009-07-09 14:11 . 2007-03-05 15:32 -------- d--h--w- c:\program files\Okelia
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-08-12 122939]
"UpdateManager"="c:\program files\Fichiers communs\Sonic\Update Manager\sgtray.exe" [2004-01-06 110592]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-26 53248]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"Synchronization Manager"="c:\windows\system32\mobsync.exe" [2004-08-05 144384]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Microsoft Office.lnk - c:\msoffice\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"EditLevel"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"EditLevel"= 0 (0x0)
"NoCommonGroups"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\JavaSoft\\JRE\\1.3.1\\bin\\javaw.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Java\\jre1.5.0_06\\bin\\javaw.exe"=
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
Notify-avgrsstarter - avgrsstx.dll
Notify-NavLogon - (no file)
.
------- Supplementary Scan -------
.
IE: E&xporter vers Microsoft Excel - c:\msoffice\Office10\EXCEL.EXE/3000
TCP: {37C5FAE6-6662-4EDE-9E25-0FE85161F489} = 193.74.208.135,193.74.208.65
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-26 16:34
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\program files\a-squared Free\a2service.exe
c:\program files\a-squared Free\a2service.exe
c:\windows\system32\imapi.exe
.
**************************************************************************
.
Completion time: 2009-08-26 16:37 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-26 14:37
Pre-Run: 69.237.559.296 octets libres
Post-Run: 69.445.832.704 octets libres
120