XP antispyware 2010

ces -  
 cosmido -
Bonjour,

j'ai eu hier un virus XP ANTISPYWARE 2010 .
J'ai lancer deux logiciels: Malwarebytes'et Combofix.
Voici le log:


ComboFix 10-02-12.01 - XXXX 14/02/2010 14:17:18.1.1 - FAT32x86 MINIMAL
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.33.1036.18.446.300 [GMT 1:00]
Lancé depuis: c:\documents and settings\XXXX\Bureau\ComboFix.exe
FW: ZoneAlarm Pro Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}

AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\1mteolu9.com
c:\documents and settings\XXXX\Local Settings\Temporary Internet Files\7577MA8M.jpg
c:\documents and settings\XXXX\Local Settings\Temporary Internet Files\M6abX.jpg
c:\documents and settings\XXXX\Local Settings\Temporary Internet Files\mxLJB.jpg
c:\documents and settings\XXXX\Local Settings\Temporary Internet Files\N3XXk.jpg
c:\documents and settings\XXXX\RavMonLog
C:\p3vwxx.exe
c:\program files\Internet Explorer\iekey.dll
C:\qkm.exe
c:\recycler\S-1-5-21-3622181106-6803858438-607290675-9468
c:\recycler\S-1-5-21-3771870668-2264318659-989268345-3924
c:\recycler\S-1-5-21-6565493598-8913134836-934001162-5770
c:\recycler\S-1-5-21-7957720310-7038851006-048897260-3090
c:\recycler\S-1-5-21-8101872085-9521594394-289309836-6570
C:\uo10sn.cmd
c:\windows\system32\COMCTL32.OCA
c:\windows\Uninstall.ini
C:\ws.exe
C:\y.bat
D:\1mteolu9.com
D:\8rcahp.exe
D:\Autorun.inf
D:\p3vwxx.exe
D:\q8e6.bat
D:\q93fi6kf.exe
D:\qkm.exe
D:\rcukd.cmd
D:\uo10sn.cmd
D:\ws.exe
D:\y.bat

.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Service_AVPsys


((((((((((((((((((((((((((((( Fichiers créés du 2010-01-14 au 2010-02-14 ))))))))))))))))))))))))))))))))))))
.

2010-02-14 12:37 . 2010-02-14 12:37 -------- d-----w- c:\documents and settings\XXXX\Application Data\Malwarebytes
2010-02-14 12:36 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-14 12:36 . 2010-02-14 12:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-14 12:36 . 2010-02-14 12:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-02-14 12:36 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-12 68856]
"msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
"PcSync"="c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2005-11-30 1306624]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-07 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-07 688218]
"SoundMan"="SOUNDMAN.EXE" [2005-02-23 77824]
"AGRSMMSG"="AGRSMMSG.exe" [2004-10-07 88363]
"SiSPower"="SiSPower.dll" [2005-02-25 49152]
"SiS Windows KeyHook"="c:\windows\system32\keyhook.exe" [2005-03-04 32768]
"PCMService"="c:\program files\Arcade\PCMService.exe" [2005-03-09 49152]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"LManager"="c:\program files\Launch Manager\QtZgAcer.EXE" [2005-03-28 315392]
"eRecoveryService"="c:\windows\System32\Check.exe" [2005-03-23 245760]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2005-06-24 278528]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-10-01 98304]
"LVCOMS"="c:\program files\Fichiers communs\Logitech\QCDriver2\LVCOMS.EXE" [2003-09-04 135214]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2005-10-02 20480]
"REGSHAVE"="c:\program files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 53248]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-05 15360]

c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Utility Tray.lnk - c:\windows\system32\sistray.exe [2005-3-7 331776]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-1-21 65588]
Exif Launcher.lnk - c:\program files\FinePixViewer\QuickDCF.exe [2002-1-9 200704]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Real\\RealPlayer\\REALPLAY.EXE"=
"c:\\WINDOWS\\System32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\eMule\\emule.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"12961:TCP"= 12961:TCP:NortonAV
"13725:TCP"= 13725:TCP:NortonAV
"14534:TCP"= 14534:TCP:NortonAV
"15310:TCP"= 15310:TCP:NortonAV
"17415:TCP"= 17415:TCP:NortonAV
"14327:TCP"= 14327:TCP:NortonAV
"15444:TCP"= 15444:TCP:NortonAV
"18456:TCP"= 18456:TCP:NortonAV
"16069:TCP"= 16069:TCP:NortonAV
"17101:TCP"= 17101:TCP:NortonAV
"12809:TCP"= 12809:TCP:NortonAV
"15233:TCP"= 15233:TCP:NortonAV
"12137:TCP"= 12137:TCP:NortonAV
"14715:TCP"= 14715:TCP:NortonAV
"14637:TCP"= 14637:TCP:NortonAV
"18768:TCP"= 18768:TCP:NortonAV
"18602:TCP"= 18602:TCP:NortonAV
"12011:TCP"= 12011:TCP:NortonAV
"15253:TCP"= 15253:TCP:NortonAV
"16683:TCP"= 16683:TCP:NortonAV
"17568:TCP"= 17568:TCP:NortonAV
"17003:TCP"= 17003:TCP:NortonAV
"14850:TCP"= 14850:TCP:NortonAV
"12806:TCP"= 12806:TCP:NortonAV
"13984:TCP"= 13984:TCP:NortonAV
"15151:TCP"= 15151:TCP:NortonAV
"13715:TCP"= 13715:TCP:NortonAV
"18007:TCP"= 18007:TCP:NortonAV

S3 PID_0920;Logitech QuickCam Express(PID_0920);c:\windows\system32\drivers\LV532AV.SYS [02/10/2005 14:58 152576]
.
.
------- Examen supplémentaire -------
.
uSearch Page = hxxp://www.google.com
uStart Page = hxxp://www.google.fr/
uSearch Bar = hxxp://www.google.com/ie
mDefault_Search_URL = hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = hxxp://global.acer.com/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
Trusted Zone: getmirar.com\click
Trusted Zone: mirarsearch.com\click
Trusted Zone: mirarsearch.com\redirect
.
- - - - ORPHELINS SUPPRIMES - - - -

HKCU-Run-WOOKIT - c:\progra~1\WANADOO\GestMaj.exe
AddRemove-mIRC - c:\windows\system32\dk\calling.com



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-02-14 14:23
Windows 5.1.2600 Service Pack 2 FAT NTAPI

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------

- - - - - - - > 'explorer.exe'(1888)
c:\program files\CyberLink\Shared Files\CLRCEngine.dll
c:\windows\system32\msi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\acer\eManager\anbmServ.exe
c:\windows\system32\wscntfy.exe
c:\windows\SOUNDMAN.EXE
c:\windows\AGRSMMSG.exe
c:\windows\system32\Rundll32.exe
c:\progra~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
c:\program files\iPod\bin\iPodService.exe
c:\progra~1\FICHIE~1\PCSuite\Services\SERVIC~1.EXE
c:\progra~1\FICHIE~1\Nokia\MPAPI\MPAPI3s.exe
c:\program files\acer\eRecovery\Monitor.exe
.
**************************************************************************
.
Heure de fin: 2010-02-14 14:25:30 - La machine a redémarré
ComboFix-quarantined-files.txt 2010-02-14 13:25

Avant-CF: 13 811 941 376 octets libres
Après-CF: 15 728 377 856 octets libres

- - End Of File - - 1AE9576DE05F11EDE7763DA307F453A6




Est ce que je dois faire une autre manipulation?
Merci pour votre aide
A voir également:

1 réponse

cosmido
 
bonjour,

hein ..
Trusted Zone: getmirar.com\click
Trusted Zone: mirarsearch.com\click
..
0