Hi deltalima,
Here is the ComboFix log file:
ComboFix 10-09-03.02 - Administrateur 04/09/2010 21:36:49.1.2 - x86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.32.1036.18.2047.1568 [GMT 2:00]
Lancé depuis: c:\documents and settings\Administrateur\Bureau\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrateur\Local Settings\Application Data\Windows Server
c:\documents and settings\Administrateur\Local Settings\Application Data\Windows Server\flags.ini
c:\documents and settings\Administrateur\Local Settings\Application Data\Windows Server\server.dat
c:\documents and settings\Administrateur\Local Settings\Application Data\Windows Server\uses32.dat
c:\windows\system32\adgxpfi.dll
c:\windows\system32\drivers\mbwoxlmf.sys
c:\windows\system32\drivers\yfnalnya.sys
c:\windows\system32\explorer.exe
c:\windows\system32\kmjffbl.dll
c:\windows\system32\msconfig.exe
c:\windows\system32\scrrnfr.dll
c:\windows\system32\spool\prtprocs\w32x86\GRO1.tmp
c:\windows\system32\Thumbs.db
c:\windows\system32\winlogon.exe . . . est infecté!!
c:\windows\explorer.exe . . . est infecté!!
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ATAPIDRV
-------\Legacy_TUYVHACD
-------\Legacy_YFNALNYA
-------\Service_tuyvhacd
-------\Service_yfnalnya
((((((((((((((((((((((((((((( Fichiers créés du 2010-08-04 au 2010-09-04 ))))))))))))))))))))))))))))))))))))
.
2010-09-04 19:42 . 2010-09-04 19:42 -------- d-sh--w- c:\windows\system32\dllcache
2010-09-04 19:42 . 2010-09-04 19:42 -------- d-----w- c:\windows\system32\xircom
2010-09-04 19:42 . 2010-09-04 19:42 -------- d-----w- c:\windows\system32\wbem\snmp
2010-09-04 19:42 . 2010-09-04 19:42 -------- d-----w- c:\windows\srchasst
2010-09-03 22:08 . 2010-09-03 22:08 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Malwarebytes
2010-09-03 22:07 . 2010-09-03 22:07 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-09-03 22:07 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-09-03 22:07 . 2010-09-03 22:07 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-09-03 22:07 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-09-02 11:08 . 2010-09-02 11:08 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-09-02 11:08 . 2010-09-02 11:08 -------- d-----w- c:\documents and settings\Administrateur\Application Data\SUPERAntiSpyware.com
2010-09-01 20:47 . 2010-09-01 20:47 -------- d-----w- C:\_OTL
2010-08-30 22:24 . 2010-08-30 22:24 -------- d-----w- c:\documents and settings\Administrateur\Application Data\InstallShield
2010-08-26 20:24 . 2010-08-26 20:24 -------- d-s---w- c:\documents and settings\NetworkService\UserData
2010-08-26 19:27 . 2010-08-26 19:27 131 ----a-w- c:\windows\system32\file.bat
2010-08-26 19:27 . 2010-08-26 19:27 -------- d-----w- c:\documents and settings\Administrateur\Application Data\878E3BB16E0E9CA70630B7733CB1EE6D
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-04 19:45 . 2009-02-18 17:42 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Skype
2010-09-04 19:42 . 2010-09-04 19:42 -------- d-----w- c:\program files\microsoft frontpage
2010-09-04 14:02 . 2009-02-18 17:44 -------- d-----w- c:\documents and settings\Administrateur\Application Data\skypePM
2010-09-03 22:10 . 2010-04-29 10:25 0 ----a-w- c:\documents and settings\Administrateur\Local Settings\Application Data\prvlcl.dat
2010-09-01 20:44 . 2009-02-18 15:47 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2010-09-01 13:29 . 2001-09-28 17:00 76606 ----a-w- c:\windows\system32\perfc00C.dat
2010-09-01 13:29 . 2001-09-28 17:00 469824 ----a-w- c:\windows\system32\perfh00C.dat
2010-08-26 20:41 . 2009-02-23 14:32 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Azureus
2010-08-26 19:27 . 2010-08-26 19:27 720896 ----a-w- c:\documents and settings\Administrateur\Application Data\878E3BB16E0E9CA70630B7733CB1EE6D\newsecureapp70700.exe
2010-08-09 12:34 . 2010-08-26 20:15 14336 ----a-w- c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\iop5lzfh.default\extensions\radiobar@toolbar\components\toolbarhomewmp.dll
2010-07-17 11:08 . 2010-07-17 11:08 -------- d-----w- c:\documents and settings\Administrateur\Application Data\iWin
2010-07-17 09:22 . 2010-07-17 09:22 -------- d-----w- c:\program files\Fichiers communs\Skype
2010-07-16 22:13 . 2009-09-10 20:27 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-07-15 16:45 . 2009-02-05 21:11 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-07-15 16:45 . 2010-07-15 16:45 -------- d-----w- c:\program files\SmartSound Software
2010-07-15 16:45 . 2010-07-15 16:45 -------- d-----w- c:\documents and settings\All Users\Application Data\SmartSound Software Inc
2010-07-15 16:44 . 2010-07-15 16:44 1100 ----a-w- c:\program files\uninstal.log
2010-07-15 13:17 . 2009-02-05 21:54 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-15 13:17 . 2010-07-15 13:17 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-06-09 14:20 . 2010-06-09 14:20 15781 ----a-w- c:\windows\system32\drivers\mdc8021x.sys
2009-02-05 21:06 . 2009-02-05 21:06 56 --sh--r- c:\windows\system32\E7F5CFDA1E.sys
2009-02-05 21:06 . 2009-02-05 21:06 1890 --sha-w- c:\windows\system32\KGyGaAvL.sys
.
------- Sigcheck -------
[-] 2005-09-18 . DBC20C4332FE84B826530C49AE09721E . 359936 . . [5.1.2600.2685] . . c:\windows\system32\drivers\tcpip.sys
[-] 2004-08-04 . 9AD94F96BBBE3F2F85ADE0A7950FBD67 . 506368 . . [5.1.2600.2180] . . c:\windows\system32\winlogon.exe
[-] 2005-09-17 . 5D35335E7B6DE0C2F632CFC2DEC7C9E6 . 2120704 . . [6.00.2900.2649] . . c:\windows\explorer.exe
[-] 2005-09-18 . BF786B9F0DB745C5E8DFEDF1F9A4DBDC . 1548288 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll
c:\windows\System32\drivers\beep.sys ... manque !!
c:\windows\System32\regsvc.dll ... manque !!
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-19 68856]
"Skype"="c:\program files\Skype\\Phone\Skype.exe" [2010-05-13 26192168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-04 8523776]
"nwiz"="nwiz.exe" [2007-12-04 1626112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-04 81920]
"RTHDCPL"="RTHDCPL.EXE" [2007-02-03 16116224]
"SkyTel"="SkyTel.EXE" [2006-05-20 2879488]
"BootSkin Startup Jobs"="c:\program files\Stardock\WinCustomize\BootSkin\BootSkin.exe" [2004-04-26 270336]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-10 624248]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-12 342312]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-07-15 2065760]
"Control Center"="c:\program files\ASUS\WLAN Card Utilities\Center.exe" [2004-11-04 1569280]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-04 44544]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"ForceClassicControlPanel"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\policies\microsoft\windows\windowsupdate\au]
"NoAutoUpdate"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"=hex(2):6c,6f,67,6f,6e,75,69,32,2e,65,78,65,00
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-07-15 13:17 12536 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Fichiers communs\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/02/2009 23:54 243024]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [15/07/2010 15:17 308136]
S1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys --> c:\windows\system32\Drivers\avgldx86.sys [?]
S1 SASDIFSV;SASDIFSV;\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS --> c:\docume~1\ADMINI~1\LOCALS~1\Temp\SAS_SelfExtract\SASDIFSV.SYS [?]
S1 SASKUTIL;SASKUTIL;\??\c:\docume~1\ADMINI~1\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.SYS --> c:\docume~1\ADMINI~1\LOCALS~1\Temp\SAS_SelfExtract\SASKUTIL.SYS [?]
S2 avg9emc;AVG Free E-mail Scanner;c:\program files\AVG\AVG9\avgemc.exe [15/07/2010 15:16 921952]
S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [28/01/2010 12:52 135664]
S3 cxbu0wdm;CardMan 3x21;c:\windows\system32\drivers\cxbu0wdm.sys [15/01/2008 12:39 97792]
--- Autres Services/Pilotes en mémoire ---
*NewlyCreated* - HELPSVC
*NewlyCreated* - YFNALNYA
*Deregistered* - yfnalnya
.
Contenu du dossier 'Tâches planifiées'
2010-07-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2010-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-28 10:51]
2010-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-28 10:51]
.
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://start.gametop.com/?utm_source=Cr ... dium=startuSearch Page =
hxxp://www.google.comuSearch Bar =
hxxp://www.google.com/iemDefault_Search_URL =
hxxp://www.google.com/ieuInternet Settings,ProxyOverride = *.local
uSearchAssistant =
hxxp://www.google.com/ieuSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
mSearchAssistant =
hxxp://www.google.com/ieIE: Ajouter au fichier PDF existant - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir en Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir en un fichier PDF existant - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir la cible du lien en Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir la cible du lien en un fichier PDF existant - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir la sélection en Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convertir la sélection en un fichier PDF existant - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convertir les liens sélectionnés en fichier Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convertir les liens sélectionnés en un fichier PDF existant - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~1\Office10\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
FF - ProfilePath - c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\iop5lzfh.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo! Search
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.be/FF - component: c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\iop5lzfh.default\extensions\radiobar@toolbar\components\toolbarhomewmp.dll
FF - component: c:\program files\AVG\AVG9\Firefox\components\avgssff.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}\components\SkypeFfComponent.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
.
- - - - ORPHELINS SUPPRIMES - - - -
WebBrowser-{CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
AddRemove-HijackThis - c:\program files\hijackthis\HijackThis.exe
AddRemove-Octoshape add-in for Adobe Flash Player - c:\documents and settings\Administrateur\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-09-04 21:42
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:56,04,fd,68,f3,9d,cc,f3,a2,ab,0d,b3,c3,c8,30,57,02,8b,8e,32,4c,
3b,d8,cc,c6,39,d0,9f,c5,1b,b4,95,8c,3e,6b,37,a5,25,a5,3f,9e,a8,a7,8b,66,ae,\
[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:56,04,fd,68,f3,9d,cc,f3,a2,ab,0d,b3,c3,c8,30,57,02,8b,8e,32,4c,
3b,d8,cc,c6,39,d0,9f,c5,1b,b4,95,8c,3e,6b,37,a5,25,a5,3f,9e,a8,a7,8b,66,ae,\
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(2108)
c:\windows\system32\msi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\windows\System32\SCardSvr.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wdfmgr.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\RUNDLL32.EXE
c:\windows\RTHDCPL.EXE
c:\program files\Skype\Phone\Skype.exe
c:\program files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Heure de fin: 2010-09-04 21:50:19 - La machine a redémarré
ComboFix-quarantined-files.txt 2010-09-04 19:50
Avant-CF: 54.826.774.528 octets libres
Après-CF: 54.887.804.928 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect /usepmtimer
- - End Of File - - B881B62EC96405EF97565F45CB53F0F5