

RobTheMob
Membres-
Compteur de contenus
3 -
Inscription
-
Dernière visite
Type de contenu
Profils
Forums
Blogs
Tout ce qui a été posté par RobTheMob
-
Analyse rapport ComboFix et HijackThis
RobTheMob a répondu à un(e) sujet de RobTheMob dans Analyses et éradication malwares
Ok c'est tout ce que je voulais savoir, merci ! -
Analyse rapport ComboFix et HijackThis
RobTheMob a répondu à un(e) sujet de RobTheMob dans Analyses et éradication malwares
Personne ne veut m'aider ? -
Analyse rapport ComboFix et HijackThis
RobTheMob a posté un sujet dans Analyses et éradication malwares
Bonjour à tous, depuis quelques temps mon ordinateur a un fonctionnement étrange, le bureau disparaît et revient, la navigation sur internet est par moments très très lente bref je me demande si mon ordinateur est infecté. J'ai téléchargé ComBofix et HijackThis après en avoir entendu parler sur un forum, je joins les rapports ci-dessous que jje suis absolument incapable de déchiffrer, si quelqu'un peut me dire si tout va bien... Merci d'avance ! Rapport ComBofix : ComboFix 08-05-28.4 - samuel 2008-05-29 16:09:42.8 - NTFSx86 Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.261 [GMT 2:00]Endroit: C:\Documents and Settings\samuel\Bureau\ComboFix.exe * Création d'un nouveau point de restauration AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !! . ((((((((((((((((((((((((((((( Fichiers créés 2008-04-28 to 2008-05-29 )))))))))))))))))))))))))))))))))))) . 2008-05-22 16:58 . 2008-05-22 16:58 54,156 --ah----- C:\WINDOWS\QTFont.qfn 2008-05-22 16:58 . 2008-05-22 16:58 1,409 --a------ C:\WINDOWS\QTFont.for . (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M )))))))))))))))))))))))))))))))))))))))))))))))) . 2008-05-28 19:31 207,487 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err 2008-05-26 19:26 --------- d-----w C:\Program Files\Windows Live 2008-05-26 12:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller 2008-05-15 15:48 --------- d-----w C:\Program Files\eMule 2008-04-24 15:53 --------- d-----w C:\Program Files\K-Lite Codec Pack 2008-04-20 18:45 --------- d-----w C:\Program Files\Avira 2008-04-20 18:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira 2008-04-20 09:29 --------- d-----w C:\Program Files\VideoLAN 2008-04-20 08:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater 2008-04-17 17:54 --------- d-----w C:\Program Files\Google 2008-04-17 10:45 --------- d-----w C:\Program Files\Messenger Plus! Live 2008-04-11 15:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink 2008-04-11 15:01 --------- d-----w C:\Program Files\VirtualDubMOD 2008-04-11 14:22 --------- d-----w C:\Program Files\WinASPI 2008-04-11 14:22 --------- d-----w C:\Program Files\AviSynth 2.5 2008-04-03 17:26 --------- d-----w C:\Documents and Settings\samuel\Application Data\LimeWire 2008-03-31 21:25 682,496 ----a-w C:\WINDOWS\system32\divx.dll 2008-03-28 17:41 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll 2008-03-21 20:30 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll 2008-03-21 20:28 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll 2008-03-17 20:01 65,512 ----a-w C:\Documents and Settings\samuel\Application Data\GDIPFONTCACHEV1.DAT 2008-02-19 12:16 924 ----a-w C:\Program Files\Mathilde.txt 2008-02-12 17:49 9 ----a-w C:\Program Files\nomutil.txt 2008-01-21 12:37 12,413,440 ----a-w C:\Program Files\avgas-setup-7.5.1.43.exe 2007-06-30 17:46 278,528 -c--a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe 2007-03-25 12:59 262,032 -c--a-w C:\Program Files\emoticones.exe 2007-03-25 11:43 25,839,688 -c--a-w C:\Program Files\wmp11-windowsxp-x86-fr-fr.exe 2007-03-24 16:40 22,845,992 -c--a-w C:\Program Files\AdbeRdr80_fr_FR.exe 2007-02-10 18:09 13,446,648 -c--a-w C:\Program Files\avast_avast_4.7.942_francais_anglais_11113.exe 2007-02-04 20:05 1,410,680 -c--a-w C:\Program Files\install_flash_player.exe 2006-11-11 11:11 824 -c--a-w C:\Program Files\mpc5.reg 2006-11-11 11:11 800 -c--a-w C:\Program Files\ffdssetts.reg 2006-11-11 11:11 778 -c--a-w C:\Program Files\ffdsasetts.reg 2006-11-11 11:08 4,548 -c--a-w C:\Program Files\satsukidecodersettings.ini . ((((((((((((((((((((((((((((( snapshot@2008-04-25_14.50.28,42 ))))))))))))))))))))))))))))))))))))))))) . - 2008-04-25 12:27:37 2,048 --s-a-w C:\WINDOWS\bootstat.dat + 2008-05-29 12:05:16 2,048 --s-a-w C:\WINDOWS\bootstat.dat - 2000-08-31 06:00:00 73,728 ----a-w C:\WINDOWS\fdsv.exe + 2000-08-31 06:00:00 89,504 ----a-w C:\WINDOWS\fdsv.exe - 2007-12-07 17:50:32 18,718 ----a-r C:\WINDOWS\Installer\{BFD080F6-3BF0-40E1-9507-9CA969C35870}\ARPPRODUCTICON.exe + 2008-05-27 08:55:53 18,718 ----a-r C:\WINDOWS\Installer\{BFD080F6-3BF0-40E1-9507-9CA969C35870}\ARPPRODUCTICON.exe - 2007-12-07 17:50:32 18,718 ----a-r C:\WINDOWS\Installer\{BFD080F6-3BF0-40E1-9507-9CA969C35870}\NewShortcut1_E659E0EE10E649B7869660F38D0EB174.exe + 2008-05-27 08:55:53 18,718 ----a-r C:\WINDOWS\Installer\{BFD080F6-3BF0-40E1-9507-9CA969C35870}\NewShortcut1_E659E0EE10E649B7869660F38D0EB174.exe - 2007-12-07 17:50:32 18,718 ----a-r C:\WINDOWS\Installer\{BFD080F6-3BF0-40E1-9507-9CA969C35870}\NewShortcut2_8315396A5EA1419DBEC4978284BDF556.exe + 2008-05-27 08:55:53 18,718 ----a-r C:\WINDOWS\Installer\{BFD080F6-3BF0-40E1-9507-9CA969C35870}\NewShortcut2_8315396A5EA1419DBEC4978284BDF556.exe + 2008-05-26 12:06:32 2,480 ----a-w C:\WINDOWS\SoftwareDistribution\EventCache\{4461FEEA-CF55-4B4F-B5AC-528C487CC23D}.bin - 2007-04-26 09:21:30 302,000 ----a-w C:\WINDOWS\system32\drivers\fwdrv.sys + 2007-04-26 08:21:30 302,000 ----a-w C:\WINDOWS\system32\drivers\fwdrv.sys - 2007-04-26 09:21:34 72,624 ----a-w C:\WINDOWS\system32\drivers\khips.sys + 2007-04-26 08:21:34 72,624 ----a-w C:\WINDOWS\system32\drivers\khips.sys + 2008-03-25 03:21:18 2,889,088 ----a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll + 2008-03-25 03:21:20 218,496 ----a-w C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe + 2008-05-04 12:18:17 70,264 ----a-w C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe - 2008-04-20 09:08:44 78,020 ----a-w C:\WINDOWS\system32\Restore\rstrlog.dat + 2008-05-26 19:27:28 1,861,132 ----a-w C:\WINDOWS\system32\Restore\rstrlog.dat . ((((((((((((((((((((((((((((((((( Point de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 01:09 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Cmaudio"="cmicnfg.cpl" [] "igfxtray"="C:\WINDOWS\System32\igfxtray.exe" [2005-09-20 04:35 94208] "igfxhkcmd"="C:\WINDOWS\System32\hkcmd.exe" [2005-09-20 04:32 77824] "igfxpers"="C:\WINDOWS\System32\igfxpers.exe" [2005-09-20 04:36 114688] "AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe" [2006-11-11 12:11 462848] "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312] "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-20 21:42 262401] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-20 01:09 15360] C:\Documents and Settings\samuel\Menu D‚marrer\Programmes\D‚marrage\ MSN Pictures Displayer.lnk - C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe [2007-05-31 21:58:13 4571136] C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\ Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 22:05:56 65588] Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2007-02-05 15:40:46 118784] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2007-02-05 15:39 294400] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "vidc.I420"= i420vfw.dll "vidc.yv12"= yv12vfw.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "C:\\Program Files\\Lavasoft\\Ad-Aware 2007\\Ad-Aware2007.exe"= R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-04-26 10:21] R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-04-26 10:21] R2 SPF4;Sunbelt Personal Firewall 4;"C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe" [2007-04-26 10:21] S3 SIS163u;SiS163 USB Wireless LAN Adapter Driver;C:\WINDOWS\system32\DRIVERS\sis163u.sys [2005-11-02 12:53] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7f34f107-c120-11dc-8e92-00032f4750f0}] \Shell\AutoRun\command - F:\LaunchU3.exe -a [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e7d64aa4-5c8b-11dc-8d22-00032f3dc853}] \Shell\AutoRun\command - setupSNK.exe . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-05-29 16:13:29 Windows 5.1.2600 Service Pack 2 NTFS Balayage processus cachés ... Balayage caché autostart entries ... Balayage des fichiers cachés ... Scan terminé avec succès Les fichiers cachés: 0 ************************************************************************** . Temps d'accomplissement: 2008-05-29 16:19:52 ComboFix-quarantined-files.txt 2008-05-29 14:19:46 ComboFix2.txt 2008-04-25 12:52:17 ComboFix3.txt 2007-12-16 17:25:33 Pre-Run: 13,497,401,344 octets libres Post-Run: 13,441,138,688 octets libres 128 --- E O F --- 2008-04-21 15:27:09 Rapport HijackThis : Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 16:22:09, on 29/05/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\WINDOWS\System32\hkcmd.exe C:\WINDOWS\System32\igfxpers.exe C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Windows Desktop Search\WindowsSearch.exe C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\SearchIndexer.exe C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\SearchProtocolHost.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Startup: MSN Pictures Displayer.lnk = C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://webscanner.kaspersky.fr/kavwebscan_unicode.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{2C108A0A-6A00-4469-93B0-E52B85BE1DDB}: NameServer = 192.168.1.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{6622A1D4-3770-4534-B3DA-85181B9D46A6}: NameServer = 192.168.1.1 O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe -- End of file - 5487 bytes