voici le rapport : Guigu'sss
ComboFix 08-07-29.1 - SHIFT 2008-07-30 20:08:41.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.468 [GMT 2:00]
Endroit: C:\Documents and Settings\SHIFT\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\SHIFT\Application Data\rhc7f8j0eaaa
C:\Program Files\rhc7f8j0eaaa
C:\WINDOWS\system32\6.tmp
C:\WINDOWS\system32\blphc3f8j0eaaa.scr
C:\WINDOWS\system32\lphc3f8j0eaaa.exe
C:\WINDOWS\system32\phc3f8j0eaaa.bmp
C:\WINDOWS\system32\pphc3f8j0eaaa.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SYSREST.SYS
-------\Service_sysrest.sys
((((((((((((((((((((((((((((( Fichiers cr??s 2008-06-28 to 2008-07-30 ))))))))))))))))))))))))))))))))))))
.
2008-07-25 11:07 . 2008-07-25 11:07 23,040 --a------ C:\WINDOWS\system32\sysrest32.exe
2008-07-25 11:07 . 2008-07-30 19:11 15,328 --a------ C:\WINDOWS\system32\sysrest.sys
2008-07-24 19:26 . 2008-07-24 19:26 268 --ah----- C:\sqmdata19.sqm
2008-07-24 19:26 . 2008-07-24 19:26 244 --ah----- C:\sqmnoopt19.sqm
2008-07-24 19:22 . 2008-07-24 19:22 86,016 --a------ C:\WINDOWS\system32\clahkbct.exe
2008-07-24 19:19 . 2008-07-24 19:19 268 --ah----- C:\sqmdata18.sqm
2008-07-24 19:19 . 2008-07-24 19:19 244 --ah----- C:\sqmnoopt18.sqm
2008-07-24 19:10 . 2008-07-24 19:20 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-24 19:10 . 2008-07-24 19:10 <REP> d-------- C:\Documents and Settings\SHIFT\Application Data\Malwarebytes
2008-07-24 19:10 . 2008-07-24 19:10 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-24 19:10 . 2008-07-23 20:09 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-07-24 19:10 . 2008-07-23 20:09 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-24 00:07 . 2008-07-24 00:07 268 --ah----- C:\sqmdata17.sqm
2008-07-24 00:07 . 2008-07-24 00:07 244 --ah----- C:\sqmnoopt17.sqm
2008-07-23 22:16 . 2008-07-23 22:16 90,112 --a------ C:\WINDOWS\system32\xgrylepa.exe
2008-07-23 22:13 . 2008-07-23 22:13 268 --ah----- C:\sqmdata16.sqm
2008-07-23 22:13 . 2008-07-23 22:13 244 --ah----- C:\sqmnoopt16.sqm
2008-07-23 21:34 . 2008-07-23 21:34 <REP> d-------- C:\Program Files\Trend Micro
2008-07-23 00:34 . 2008-07-23 00:34 268 --ah----- C:\sqmdata15.sqm
2008-07-23 00:34 . 2008-07-23 00:34 244 --ah----- C:\sqmnoopt15.sqm
2008-07-23 00:28 . 2008-07-23 00:28 268 --ah----- C:\sqmdata14.sqm
2008-07-23 00:28 . 2008-07-23 00:28 244 --ah----- C:\sqmnoopt14.sqm
2008-07-22 19:35 . 2008-07-22 19:35 268 --ah----- C:\sqmdata13.sqm
2008-07-22 19:35 . 2008-07-22 19:35 244 --ah----- C:\sqmnoopt13.sqm
2008-07-22 19:15 . 2008-07-22 19:15 268 --ah----- C:\sqmdata12.sqm
2008-07-22 19:15 . 2008-07-22 19:15 244 --ah----- C:\sqmnoopt12.sqm
2008-07-22 18:57 . 2008-07-22 18:57 268 --ah----- C:\sqmdata11.sqm
2008-07-22 18:57 . 2008-07-22 18:57 244 --ah----- C:\sqmnoopt11.sqm
2008-07-22 18:55 . 2008-07-22 18:55 <REP> d-------- C:\Program Files\kyuzgub
2008-07-22 18:55 . 2008-07-22 18:55 <REP> d-------- C:\Documents and Settings\All Users\Application Data\adojyvsh
2008-07-21 23:08 . 2008-07-21 23:08 268 --ah----- C:\sqmdata10.sqm
2008-07-21 23:08 . 2008-07-21 23:08 244 --ah----- C:\sqmnoopt10.sqm
2008-07-15 17:02 . 2008-07-16 11:03 <REP> d-------- C:\Program Files\Dofus
2008-06-21 11:26 . 2008-06-21 11:26 268 --ah----- C:\sqmdata09.sqm
2008-06-21 11:26 . 2008-06-21 11:26 244 --ah----- C:\sqmnoopt09.sqm
2008-06-20 23:38 . 2008-06-20 23:38 268 --ah----- C:\sqmdata08.sqm
2008-06-20 23:38 . 2008-06-20 23:38 244 --ah----- C:\sqmnoopt08.sqm
2008-06-20 23:32 . 2008-06-20 23:32 268 --ah----- C:\sqmdata07.sqm
2008-06-20 23:32 . 2008-06-20 23:32 244 --ah----- C:\sqmnoopt07.sqm
2008-06-20 19:41 . 2008-06-20 19:41 247,808 -----c--- C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 12:44 . 2008-06-20 12:44 138,368 -----c--- C:\WINDOWS\system32\dllcache\afd.sys
2008-06-11 10:34 . 2008-06-14 19:59 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 10:34 . 2008-06-14 19:59 272,768 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-05 23:17 . 2008-06-05 23:17 268 --ah----- C:\sqmdata06.sqm
2008-06-05 23:17 . 2008-06-05 23:17 244 --ah----- C:\sqmnoopt06.sqm
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-20 16:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-07-17 11:53 --------- d-----w C:\Program Files\TrackMania Nations ESWC
2008-07-14 20:55 --------- d-----w C:\Documents and Settings\SHIFT\Application Data\LimeWire
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-07 12:31 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-06-07 12:28 --------- d-----w C:\Documents and Settings\SHIFT\Application Data\AdobeUM
2008-05-31 11:24 --------- d-----w C:\Program Files\LimeWire
2008-05-31 11:22 --------- d-----w C:\Program Files\FrostWire
2008-01-08 21:47 374 ----a-w C:\Documents and Settings\SHIFT\Application Data\internaldb6334.dat
2008-01-08 21:32 555 ----a-w C:\Documents and Settings\SHIFT\Application Data\internaldb8467.dat
2008-01-08 21:32 18,432 ----a-w C:\Documents and Settings\SHIFT\Application Data\internaldb41.dat
.
((((((((((((((((((((((((((((( snapshot@2008-07-23_22.08.47.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 18:02:28 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
+ 2008-07-30 18:15:27 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_6c8.dat
+ 2008-07-30 18:18:56 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_b18.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ?l?ments vides & les ?l?ments initiaux l?gitimes ne sont pas list?s
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{0579B4B6-0293-4d73-B02D-5EBB0BA0F0A2}"= "C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL" [2008-01-20 20:23 66912]
[HKEY_CLASSES_ROOT\clsid\{0579b4b6-0293-4d73-b02d-5ebb0ba0f0a2}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2}]
2008-01-20 20:23 66912 --a------ C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLL
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-14 19:57 68856]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-04-04 00:29 165784]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 12:34 5724184]
"MSMSGS"="C:\Program Files\Messenger\MSMSGS.EXE" [2004-11-15 17:18 1670144]
"ProcMon"="C:\WINDOWS\system32\xgrylepa.exe" [2008-07-23 22:16 90112]
"WinApp"="C:\WINDOWS\system32\clahkbct.exe" [2008-07-24 19:22 86016]
"InfoShProc"="C:\WINDOWS\system32\adqvmref.exe" [2008-07-30 20:18 94208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2003-11-07 10:21 114688]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-06-09 09:56 6746112]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2005-04-29 07:56 45056]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-06-29 07:33 94208]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-06-29 07:33 77824]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2005-06-29 07:33 114688]
"SonyPowerCfg"="C:\Program Files\Sony\VAIO Power Management\SPMgr.exe" [2005-10-19 23:07 184320]
"ISBMgr.exe"="C:\Program Files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 15:12 32768]
"VAIO Update 2"="C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" [2005-10-11 22:36 151552]
"PDService.exe"="C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe" [2004-07-06 15:15 40960]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2005-03-03 21:47 483328]
"PrepareYourVAIO"="C:\Program Files\Sony\Prepare your VAIO\PYVAlert.exe" [2005-01-21 16:36 118784]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 16:17 159744]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-23 17:37 155648]
"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-05-14 18:01 644696]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 18:50 1603152]
"SSBkgdUpdate"="C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 09:03 210472]
"OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 12:02 79400]
"USB Storage Toolbox"="C:\Program Files\USB Disk Win98 Driver\Res.EXE" [2005-09-14 21:44 65536]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 02:11 132496]
"lphc3f8j0eaaa"="C:\WINDOWS\system32\lphc3f8j0eaaa.exe" [2008-07-30 20:18 110080]
"SMrhc7f8j0eaaa"="C:\Program Files\rhc7f8j0eaaa\rhc7f8j0eaaa.exe" [2008-07-30 09:41 9457664]
"RTHDCPL"="RTHDCPL.EXE" [2005-06-29 06:25 14720000 C:\WINDOWS\RTHDCPL.EXE]
"Mouse Suite 98 Daemon"="ICO.EXE" [2002-03-14 17:46 45056 C:\WINDOWS\system32\ico.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\Currentversion\policies\explorer\Run]
"eKp8XOlhXr"="C:\Documents and Settings\All Users\Application Data\adojyvsh\wdmjarqn.exe" [2008-07-22 18:55 65536]
C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\DMARRA~1\
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispBackgroundPage"= 1 (0x1)
"NoDispScrSavPage"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"SysMntUi"= {33028A21-D4D8-E4F7-EED9-03D365E75136} - C:\Program Files\kyuzgub\SysMntUi.dll [2008-07-22 18:55 131072]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2005-05-20 18:42 73728 C:\WINDOWS\system32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= C:\PROGRA~1\FICHIE~1\SONYSH~1\VideoLib\sonydv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMrhc7f8j0eaaa]
--a------ 2008-07-30 09:41 9457664 C:\Program Files\rhc7f8j0eaaa\rhc7f8j0eaaa.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Dassault Systemes\\B15\\intel_a\\code\\bin\\orbixd.exe"=
"C:\\Program Files\\Dassault Systemes\\B15\\intel_a\\code\\bin\\CNEXT.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\TrackMania Nations ESWC\\TmNationsESWC.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"18882:TCP"= 18882:TCP:NortonAV
"13669:TCP"= 13669:TCP:NortonAV
R1 LUMDriver;LUMDriver;C:\WINDOWS\system32\drivers\LUMDriver.sys [2005-04-23 10:21]
R1 PrivateDisk;PrivateDisk;C:\WINDOWS\system32\Drivers\PrivateDiskM.sys [2004-07-06 15:07]
R2 BBDemon;Backbone Service;C:\Program Files\Dassault Systemes\B15\intel_a\code\bin\CATSysDemon.exe [2005-01-29 12:12]
R2 IJPLMSVC;PIXMA Extended Survey Program;C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2007-04-13 09:20]
R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe [2002-12-17 17:55]
R3 sysrest.sys;sysrest.sys;C:\WINDOWS\system32\sysrest.sys [2008-07-30 20:18]
S2 aawc6iua1dohi8k;Print Spooler Service;C:\WINDOWS\system32\t.exe []
S3 Image Converter video recording monitor for VAIO Entertainment;Image Converter video recording monitor for VAIO Entertainment;C:\Program Files\Sony\Image Converter 2\IcVzMon.exe [2005-07-14 19:10]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE [2002-12-17 17:23]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
*Newly Created Service* - SYSREST.SYS
.
Contenu du dossier 'Scheduled Tasks/T?ches planifi?es'
2008-07-28 C:\WINDOWS\Tasks\Symantec NetDetect.job
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE [2005-01-27 16:59]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-InfoMon - C:\WINDOWS\system32\oxqvupgh.exe
HKLM-Run-sysrest32.exe - C:\WINDOWS\system32\sysrest32.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page =
www.ask.com...
R0 -: HKCU-Main,Search Page =
www.google.com...
R0 -: HKCU-Main,Default_Search_URL =
www.google.com...
R0 -: HKCU-Main,Search Bar =
www.google.com...
R0 -: HKLM-Main,Default_Search_URL =
www.google.com...
R0 -: HKCU-Search,SearchAssistant =
www.google.com...
R1 -: HKCU-SearchURL,(Default) =
www.google.com...
R0 -: HKLM-Search,SearchAssistant =
www.google.com...
O8 -: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O15 -: Trusted Zone: *.sony-europe.com
O15 -: Trusted Zone: *.sonystyle-europe.com
O15 -: Trusted Zone: *.vaio-link.com
O16 -: {91D4B4D5-E368-40AB-8F53-A37FA634B471} -
www.tellmemorecampus.com...
C:\WINDOWS\Downloaded Program Files\Tol9Inst.inf
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
www.gmer.net...
Rootkit scan 2008-07-30 20:15:46
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach?s ...
Balayage cach? autostart entries ...
Balayage des fichiers cach?s ...
C:\WINDOWS\system32\adqvmref.exe 94208 bytes executable
C:\WINDOWS\system32\pphc3f8j0eaaa.exe 94208 bytes executable
Scan termin? avec succ?s
Les fichiers cach?s: 2
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\WINDOWS\system32\CNAC4RPK.EXE
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\Apoint\ApntEx.exe
C:\Program Files\Fichiers communs\Teleca Shared\CapabilityManager.exe
C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe
C:\WINDOWS\system32\lphc3f8j0eaaa.exepplication Data\
C:\WINDOWS\system32\wscript.exe
C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\WINDOWS\system32\pphc3f8j0eaaa.exe
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-07-30 20:24:51 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-30 18:24:47
ComboFix2.txt 2008-07-23 20:10:01
Pre-Run: 21,368,426,496 octets libres
Post-Run: 21,422,780,416 octets libres
249 --- E O F --- 2008-07-20 16:22:41