J'ai donc relancé au moins 5 ou 6 fois ELIBAGLA (dans tous les modes et tous les comptes possible), mais ensuite j'ai lancé Combofix (qui enfin à s'est lancé) qui a supprimé le InfoSat.txt
donc le compte rendu d'Elibagla ne témoigne que d'un seul scan (un ultime après ComboFix), mais j'en ai bien fait plusieurs avant.
voici le résultat de Elibagla:
Tue Aug 26 00:50:27 2008
EliBagle v11.66 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 1 de Agosto del 2008)
----------------------------------------------
Lista de Acciones (por Acción Directa):
Tue Aug 26 00:50:29 2008
EliBagle v11.66 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 1 de Agosto del 2008)
----------------------------------------------
Lista de Acciones (por Exploración):
Explorando Unidad C:\
Nº Total de Directorios: 10142
Nº Total de Ficheros: 153505
Nº de Ficheros Analizados: 13394
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0
J'ai donc exécuté comboFix 2 fois en mode sans echec (la première fois il a redémarrer en cours de travail), et je l'ai relancé une fois en mode normal
voici le résultat du 1er ComboFix en mode sans-echec:
ComboFix 08-08-24.03 - SlideHorn 2008-08-26 0:27:12.1 - NTFSx86 MINIMAL
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.891 [GMT 2:00]
Endroit: C:\MAGIC.exe
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\InfoSat.txt
C:\WINDOWS\system32\drivers\downld
C:\WINDOWS\system32\drivers\mdelk.exe
C:\WINDOWS\system32\mdm.exe
C:\WINDOWS\tmlpcert2007
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_IPRIP
-------\Legacy_SROSA
-------\Service_Iprip
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-07-25 to 2008-08-25 ))))))))))))))))))))))))))))))))))))
.
2008-08-26 00:31 . 2008-08-26 00:31 <REP> d-------- C:\WINDOWS\system32\drivers\downld
2008-08-25 15:11 . 2008-08-24 19:39 55,819 --a------ C:\SlideHorn.exe
2008-08-25 14:12 . 2008-08-25 15:01 2,830,141 -ra------ C:\MAGIC.exe
2008-08-24 20:44 . 2008-08-24 20:44 <REP> d-------- C:\Muestras
2008-08-24 19:25 . 2008-08-24 19:25 <REP> d-------- C:\Program Files\CCleaner
2008-08-24 19:12 . 2008-08-24 19:12 <REP> d-------- C:\Program Files\AVG Anti-Spyware 7.5
2008-08-24 19:12 . 2008-08-24 19:12 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-08-23 00:06 . 2003-04-24 13:00 19,456 --a--c--- C:\WINDOWS\system32\dllcache\agt0804.dll
2008-08-23 00:06 . 2003-04-24 13:00 19,456 --a--c--- C:\WINDOWS\system32\dllcache\agt0412.dll
2008-08-23 00:06 . 2003-04-24 13:00 19,456 --a--c--- C:\WINDOWS\system32\dllcache\agt0411.dll
2008-08-23 00:06 . 2003-04-24 13:00 19,456 --a--c--- C:\WINDOWS\system32\dllcache\agt040d.dll
2008-08-23 00:06 . 2001-08-17 21:52 12,800 --a--c--- C:\WINDOWS\system32\dllcache\aha154x.sys
2008-08-23 00:04 . 2001-08-23 17:46 689,216 --a--c--- C:\WINDOWS\system32\dllcache\3dfxvs.dll
2008-08-23 00:04 . 2001-08-23 17:46 462,848 --a--c--- C:\WINDOWS\system32\dllcache\a3dapi.dll
2008-08-23 00:04 . 2001-08-17 20:20 297,728 --a--c--- C:\WINDOWS\system32\dllcache\ac97sis.sys
2008-08-23 00:04 . 2004-08-03 22:32 231,552 --a--c--- C:\WINDOWS\system32\dllcache\ac97ali.sys
2008-08-23 00:04 . 2001-08-17 20:48 148,352 --a--c--- C:\WINDOWS\system32\dllcache\3dfxvsm.sys
2008-08-23 00:04 . 2001-08-17 20:20 96,256 --a--c--- C:\WINDOWS\system32\dllcache\ac97intc.sys
2008-08-23 00:04 . 2004-08-03 22:32 84,480 --a--c--- C:\WINDOWS\system32\dllcache\ac97via.sys
2008-08-23 00:04 . 2001-08-23 17:46 61,952 --a--c--- C:\WINDOWS\system32\dllcache\acerscad.dll
2008-08-23 00:04 . 2001-08-23 17:46 38,400 --a--c--- C:\WINDOWS\system32\dllcache\8514a.dll
2008-08-23 00:04 . 2001-08-17 21:52 23,552 --a--c--- C:\WINDOWS\system32\dllcache\abp480n5.sys
2008-08-23 00:04 . 2004-08-03 23:00 12,288 --a--c--- C:\WINDOWS\system32\dllcache\4mmdat.sys
2008-08-23 00:03 . 2004-08-19 16:04 2,150,400 --a--c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-08-23 00:03 . 2001-08-17 21:28 762,780 --a--c--- C:\WINDOWS\system32\dllcache\3cwmcru.sys
2008-08-23 00:03 . 2001-08-23 17:46 66,048 --a--c--- C:\WINDOWS\system32\dllcache\s3legacy.dll
2008-08-23 00:03 . 2001-08-17 22:06 11,264 --a--c--- C:\WINDOWS\system32\dllcache\1394vdbg.sys
2008-07-27 14:24 . 2008-07-27 14:24 <REP> d-------- C:\Program Files\Microsoft Money
2008-07-27 14:17 . 2008-07-27 14:17 <REP> d-------- C:\Program Files\Microsoft Works Suite 99
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-23 08:14 --------- d-----w C:\Program Files\FireFox
2008-08-22 22:34 --------- d-----w C:\Documents and Settings\SlideHorn\Application Data\Free Download Manager
2008-08-22 10:26 --------- d-----w C:\Program Files\Microsoft AntiSpyware
2008-08-22 10:07 --------- d-----w C:\Program Files\Thunderbird
2008-08-21 22:57 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-08-21 09:15 --------- d-----w C:\Program Files\Norton Internet Security
2008-08-15 22:08 --------- d-----w C:\Program Files\PhotoFiltre
2008-08-04 19:08 --------- d-----w C:\Documents and Settings\SlideHorn\Application Data\Skype
2008-08-03 10:35 --------- d-----w C:\Program Files\Paint Shop Pro 6
2008-07-29 22:41 --------- d-----w C:\Program Files\Winamp
2008-07-29 22:41 --------- d-----w C:\Program Files\Sonic Foundry ACID Music
2008-07-06 13:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\TrackMania
2008-06-26 06:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-26 06:30 --------- d-----w C:\Program Files\Ad-Aware
2008-06-26 06:28 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-06-26 06:16 --------- d-----w C:\Documents and Settings\SlideHorn\Application Data\Lavasoft
2008-06-10 18:09 6,453,676 ----a-w C:\Photos_Badminton_ELP.zip
2007-02-25 11:50 1,534,976 ----a-w C:\Program Files\SIW_Systeme-Information-for-Windows_1.66.exe
2006-08-25 04:14 47,360 ----a-w C:\Documents and Settings\SlideHorn\Application Data\pcouffin.sys
2005-11-23 23:23 3,854,863 ----a-w C:\Program Files\copiTC.exe
2003-06-25 15:05 120,832 ----a-w C:\Program Files\TweakUI.exe
2002-07-26 15:02 153,088 ----a-w C:\Program Files\UNWISE.EXE
2006-05-03 09:06 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47 31,232 --sh--r C:\WINDOWS\system32\msfDX.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 17:09 15360]
"Reminder"="C:\Program Files\Microsoft Money\System\reminder.exe" [2005-03-20 03:07 712712]
"Sensiva"="C:\Program Files\Sensiva\Sensiva.exe" [2006-06-10 09:29 626688]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-01-22 16:09 98304]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-01-22 16:08 495616]
"THotkey"="C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe" [2004-04-30 16:42 430080]
"PadTouch"="C:\Program Files\TOSHIBA\PadTouch\PadExe.exe" [2004-02-12 11:43 1019904]
"CoolSwitch"="C:\WINDOWS\System32\taskswitch.exe" [2002-03-19 18:30 45632]
"gcasServ"="C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" [2008-08-24 21:11 473928]
"\\EVO\EPSON Stylus C86 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0R2.EXE" [2003-11-25 05:00 99840]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2008-08-24 21:11 58728]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-04-09 00:27 100056]
"TPSMain"="TPSMain.exe" [2004-05-04 10:41 266240 C:\WINDOWS\system32\TPSMain.exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-09-15 11:12 37888 C:\WINDOWS\KHALMNPR.Exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 17:09 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{93994DE8-8239-4655-B1D1-5F4E91300429}"= "C:\Program Files\DVD Region\DVDShell.dll" [2004-10-09 15:18 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"msacm.l3acm"= l3codecp.acm
"vidc.xvid"= xvid.dll
"VIDC.HFYU"= huffyuv.dll
"VIDC.YV12"= yv12vfw.dll
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"vidc.3ivx"= 3ivxVfWCodec.dll
"msacm.divxa32"= divxa32.acm
"VIDC.i263"= i263_32.drv
"msacm.imc"= imc32.acm
"VIDC.MJPG"= Pvmjpg21.dll
"VIDC.PIM1"= pclepim1.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wd.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
backup=C:\WINDOWS\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
--a------ 2007-06-11 11:25 6731312 C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh]
--a------ 2003-09-26 15:43 184320 C:\Program Files\ltmoh\ltmoh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmoothView]
--a------ 2004-04-30 11:14 118784 C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
"PMCS"="C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"CloneCDElbyCDFL"="C:\Program Files\CloneCD 4.2.02\ElbyCheck.exe" /L ElbyCDFL
"AGRSMMSG"=AGRSMMSG.exe
"ATIModeChange"=Ati2mdxx.exe
"PinnacleDriverCheck"=C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\SmartFTP Client 2.0\\SmartFTP.exe"=
"C:\\Program Files\\NetSupport School\\client32.exe"=
"C:\\Program Files\\NetSupport School\\PCINSSUI.EXE"=
"C:\\Program Files\\NetSupport School\\pcinsscd.exe"=
"C:\\Program Files\\NetSupport School\\pcideply.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 atiide;atiide;C:\WINDOWS\system32\DRIVERS\atiide.sys [2004-04-14 14:52]
R0 d346bus;d346bus;C:\WINDOWS\system32\DRIVERS\d346bus.sys [2004-03-12 22:41]
R0 d346prt;d346prt;C:\WINDOWS\system32\Drivers\d346prt.sys [2004-03-12 22:41]
R2 gearsec;gearsec;C:\WINDOWS\System32\gearsec.exe [2003-01-27 18:40]
S3 iscFlash;iscFlash;C:\DOCUME~1\SlideHorn\LOCALS~1\Temp\iscCtmp\iscflash.sys []
S3 USB28xxBGA;USB 2883 Device;C:\WINDOWS\system32\DRIVERS\emBDA.sys [2006-08-09 11:10]
S3 USB28xxOEM;USB 28xx OEM Filter;C:\WINDOWS\system32\DRIVERS\emOEM.sys [2006-08-09 11:10]
S3 ZD1211U(Wireless);IEEE 802.11g USB Adapter Driver(Wireless);C:\WINDOWS\system32\DRIVERS\zd1211u.sys [2004-07-14 14:53]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e88684c8-50b1-11db-9a78-806d6172696f}]
\Shell\AutoRun\command - E:\AutoPlay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E4066320-E4AE-11CF-B1B0-00AA00BBAD66}]
rundll32.exe advpack.dll,LaunchINFSection %SystemRoot%\INF\fpxpress.inf,PerUserstub
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
2008-08-22 C:\WINDOWS\Tasks\Norton AntiVirus - Analyser mon ordinateur - SlideHorn.job
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe [2008-08-24 21:11]
2005-11-07 C:\WINDOWS\Tasks\Rappel d'enregistrement 1.job
- C:\WINDOWS\System32\OOBE\oobebaln.exe [2004-08-19 17:10]
2005-11-14 C:\WINDOWS\Tasks\Rappel d'enregistrement 2.job
- C:\WINDOWS\System32\OOBE\oobebaln.exe [2004-08-19 17:10]
2005-11-21 C:\WINDOWS\Tasks\Rappel d'enregistrement 3.job
- C:\WINDOWS\System32\OOBE\oobebaln.exe [2004-08-19 17:10]
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-PMCS - C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\SlideHorn\Application Data\Mozilla\Firefox\Profiles\mqlnu3fr.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
www.google.fr
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-26 00:31:56
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
"\\\\EVO\\EPSON Stylus C86 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_S4I0R2.EXE /P29 \"\\\\EVO\\EPSON Stylus C86 Series\" /O6 \"USB002\" /M \"Stylus C86\""
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Ad-Aware\aawservice.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\system32\tcpsvcs.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-08-26 0:37:22 - machine was rebooted [SlideHorn]
ComboFix-quarantined-files.txt 2008-08-25 22:37:19
Pre-Run: 2,330,329,088 octets libres
Post-Run: 966,025,216 octets libres
228
voici le résultat du ComboFix en mode normal:
ComboFix 08-08-24.03 - SlideHorn 2008-08-26 1:09:50.3 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.844 [GMT 2:00]
Endroit: C:\MAGIC.exe
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\drivers\downld
.
((((((((((((((((((((((((((((( Fichiers créés 2008-07-25 to 2008-08-25 ))))))))))))))))))))))))))))))))))))
.
2008-08-25 15:11 . 2008-08-24 19:39 55,819 --a------ C:\SlideHorn.exe
2008-08-25 14:12 . 2008-08-25 15:01 2,830,141 -ra------ C:\MAGIC.exe
2008-08-24 20:44 . 2008-08-24 20:44 <REP> d-------- C:\Muestras
2008-08-24 19:25 . 2008-08-24 19:25 <REP> d-------- C:\Program Files\CCleaner
2008-08-24 19:12 . 2008-08-24 19:12 <REP> d-------- C:\Program Files\AVG Anti-Spyware 7.5
2008-08-24 19:12 . 2008-08-24 19:12 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-08-23 00:06 . 2003-04-24 13:00 19,456 --a--c--- C:\WINDOWS\system32\dllcache\agt0804.dll
2008-08-23 00:06 . 2003-04-24 13:00 19,456 --a--c--- C:\WINDOWS\system32\dllcache\agt0412.dll
2008-08-23 00:06 . 2003-04-24 13:00 19,456 --a--c--- C:\WINDOWS\system32\dllcache\agt0411.dll
2008-08-23 00:06 . 2003-04-24 13:00 19,456 --a--c--- C:\WINDOWS\system32\dllcache\agt040d.dll
2008-08-23 00:06 . 2001-08-17 21:52 12,800 --a--c--- C:\WINDOWS\system32\dllcache\aha154x.sys
2008-08-23 00:04 . 2001-08-23 17:46 689,216 --a--c--- C:\WINDOWS\system32\dllcache\3dfxvs.dll
2008-08-23 00:04 . 2001-08-23 17:46 462,848 --a--c--- C:\WINDOWS\system32\dllcache\a3dapi.dll
2008-08-23 00:04 . 2001-08-17 20:20 297,728 --a--c--- C:\WINDOWS\system32\dllcache\ac97sis.sys
2008-08-23 00:04 . 2004-08-03 22:32 231,552 --a--c--- C:\WINDOWS\system32\dllcache\ac97ali.sys
2008-08-23 00:04 . 2001-08-17 20:48 148,352 --a--c--- C:\WINDOWS\system32\dllcache\3dfxvsm.sys
2008-08-23 00:04 . 2001-08-17 20:20 96,256 --a--c--- C:\WINDOWS\system32\dllcache\ac97intc.sys
2008-08-23 00:04 . 2004-08-03 22:32 84,480 --a--c--- C:\WINDOWS\system32\dllcache\ac97via.sys
2008-08-23 00:04 . 2001-08-23 17:46 61,952 --a--c--- C:\WINDOWS\system32\dllcache\acerscad.dll
2008-08-23 00:04 . 2001-08-23 17:46 38,400 --a--c--- C:\WINDOWS\system32\dllcache\8514a.dll
2008-08-23 00:04 . 2001-08-17 21:52 23,552 --a--c--- C:\WINDOWS\system32\dllcache\abp480n5.sys
2008-08-23 00:04 . 2004-08-03 23:00 12,288 --a--c--- C:\WINDOWS\system32\dllcache\4mmdat.sys
2008-08-23 00:03 . 2004-08-19 16:04 2,150,400 --a--c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-08-23 00:03 . 2001-08-17 21:28 762,780 --a--c--- C:\WINDOWS\system32\dllcache\3cwmcru.sys
2008-08-23 00:03 . 2001-08-23 17:46 66,048 --a--c--- C:\WINDOWS\system32\dllcache\s3legacy.dll
2008-08-23 00:03 . 2001-08-17 22:06 11,264 --a--c--- C:\WINDOWS\system32\dllcache\1394vdbg.sys
2008-07-27 14:24 . 2008-07-27 14:24 <REP> d-------- C:\Program Files\Microsoft Money
2008-07-27 14:17 . 2008-07-27 14:17 <REP> d-------- C:\Program Files\Microsoft Works Suite 99
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-23 08:14 --------- d-----w C:\Program Files\FireFox
2008-08-22 22:34 --------- d-----w C:\Documents and Settings\SlideHorn\Application Data\Free Download Manager
2008-08-22 10:26 --------- d-----w C:\Program Files\Microsoft AntiSpyware
2008-08-22 10:07 --------- d-----w C:\Program Files\Thunderbird
2008-08-21 22:57 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-08-21 09:15 --------- d-----w C:\Program Files\Norton Internet Security
2008-08-15 22:08 --------- d-----w C:\Program Files\PhotoFiltre
2008-08-04 19:08 --------- d-----w C:\Documents and Settings\SlideHorn\Application Data\Skype
2008-08-03 10:35 --------- d-----w C:\Program Files\Paint Shop Pro 6
2008-07-29 22:41 --------- d-----w C:\Program Files\Winamp
2008-07-29 22:41 --------- d-----w C:\Program Files\Sonic Foundry ACID Music
2008-07-06 13:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\TrackMania
2008-06-26 06:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-06-26 06:30 --------- d-----w C:\Program Files\Ad-Aware
2008-06-26 06:28 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-06-26 06:16 --------- d-----w C:\Documents and Settings\SlideHorn\Application Data\Lavasoft
2008-06-10 18:09 6,453,676 ----a-w C:\Photos_Badminton_ELP.zip
2007-02-25 11:50 1,534,976 ----a-w C:\Program Files\SIW_Systeme-Information-for-Windows_1.66.exe
2006-08-25 04:14 47,360 ----a-w C:\Documents and Settings\SlideHorn\Application Data\pcouffin.sys
2005-11-23 23:23 3,854,863 ----a-w C:\Program Files\copiTC.exe
2003-06-25 15:05 120,832 ----a-w C:\Program Files\TweakUI.exe
2002-07-26 15:02 153,088 ----a-w C:\Program Files\UNWISE.EXE
2006-05-03 09:06 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47 31,232 --sh--r C:\WINDOWS\system32\msfDX.dll
.
((((((((((((((((((((((((((((( snapshot@2008-08-26_ 0.36.51.03 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-08-25 23:06:46 16,384 ----atw C:\WINDOWS\temp\Perflib_Perfdata_dc.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 17:09 15360]
"Reminder"="C:\Program Files\Microsoft Money\System\reminder.exe" [2005-03-20 03:07 712712]
"Sensiva"="C:\Program Files\Sensiva\Sensiva.exe" [2006-06-10 09:29 626688]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-01-22 16:09 98304]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-01-22 16:08 495616]
"THotkey"="C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe" [2004-04-30 16:42 430080]
"PadTouch"="C:\Program Files\TOSHIBA\PadTouch\PadExe.exe" [2004-02-12 11:43 1019904]
"CoolSwitch"="C:\WINDOWS\System32\taskswitch.exe" [2002-03-19 18:30 45632]
"gcasServ"="C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" [2008-08-24 21:11 473928]
"\\EVO\EPSON Stylus C86 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0R2.EXE" [2003-11-25 05:00 99840]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2008-08-24 21:11 58728]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-04-09 00:27 100056]
"TPSMain"="TPSMain.exe" [2004-05-04 10:41 266240 C:\WINDOWS\system32\TPSMain.exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-09-15 11:12 37888 C:\WINDOWS\KHALMNPR.Exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 17:09 15360]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2005-11-04 20:13:10 598016]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{93994DE8-8239-4655-B1D1-5F4E91300429}"= "C:\Program Files\DVD Region\DVDShell.dll" [2004-10-09 15:18 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i420vfw.dll
"msacm.l3acm"= l3codecp.acm
"vidc.xvid"= xvid.dll
"VIDC.HFYU"= huffyuv.dll
"VIDC.YV12"= yv12vfw.dll
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"vidc.3ivx"= 3ivxVfWCodec.dll
"msacm.divxa32"= divxa32.acm
"VIDC.i263"= i263_32.drv
"msacm.imc"= imc32.acm
"VIDC.MJPG"= Pvmjpg21.dll
"VIDC.PIM1"= pclepim1.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wd.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
backup=C:\WINDOWS\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
--a------ 2007-06-11 11:25 6731312 C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh]
--a------ 2003-09-26 15:43 184320 C:\Program Files\ltmoh\ltmoh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmoothView]
--a------ 2004-04-30 11:14 118784 C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
"PMCS"="C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"CloneCDElbyCDFL"="C:\Program Files\CloneCD 4.2.02\ElbyCheck.exe" /L ElbyCDFL
"AGRSMMSG"=AGRSMMSG.exe
"ATIModeChange"=Ati2mdxx.exe
"PinnacleDriverCheck"=C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\SmartFTP Client 2.0\\SmartFTP.exe"=
"C:\\Program Files\\NetSupport School\\client32.exe"=
"C:\\Program Files\\NetSupport School\\PCINSSUI.EXE"=
"C:\\Program Files\\NetSupport School\\pcinsscd.exe"=
"C:\\Program Files\\NetSupport School\\pcideply.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 atiide;atiide;C:\WINDOWS\system32\DRIVERS\atiide.sys [2004-04-14 14:52]
R0 d346bus;d346bus;C:\WINDOWS\system32\DRIVERS\d346bus.sys [2004-03-12 22:41]
R0 d346prt;d346prt;C:\WINDOWS\system32\Drivers\d346prt.sys [2004-03-12 22:41]
S2 gearsec;gearsec;C:\WINDOWS\System32\gearsec.exe [2003-01-27 18:40]
S3 iscFlash;iscFlash;C:\DOCUME~1\SlideHorn\LOCALS~1\Temp\iscCtmp\iscflash.sys []
S3 USB28xxBGA;USB 2883 Device;C:\WINDOWS\system32\DRIVERS\emBDA.sys [2006-08-09 11:10]
S3 USB28xxOEM;USB 28xx OEM Filter;C:\WINDOWS\system32\DRIVERS\emOEM.sys [2006-08-09 11:10]
S3 ZD1211U(Wireless);IEEE 802.11g USB Adapter Driver(Wireless);C:\WINDOWS\system32\DRIVERS\zd1211u.sys [2004-07-14 14:53]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e88684c8-50b1-11db-9a78-806d6172696f}]
\Shell\AutoRun\command - E:\AutoPlay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E4066320-E4AE-11CF-B1B0-00AA00BBAD66}]
rundll32.exe advpack.dll,LaunchINFSection %SystemRoot%\INF\fpxpress.inf,PerUserstub
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
2008-08-22 C:\WINDOWS\Tasks\Norton AntiVirus - Analyser mon ordinateur - SlideHorn.job
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exe [2008-08-24 21:11]
2005-11-07 C:\WINDOWS\Tasks\Rappel d'enregistrement 1.job
- C:\WINDOWS\System32\OOBE\oobebaln.exe [2004-08-19 17:10]
2005-11-14 C:\WINDOWS\Tasks\Rappel d'enregistrement 2.job
- C:\WINDOWS\System32\OOBE\oobebaln.exe [2004-08-19 17:10]
2005-11-21 C:\WINDOWS\Tasks\Rappel d'enregistrement 3.job
- C:\WINDOWS\System32\OOBE\oobebaln.exe [2004-08-19 17:10]
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\SlideHorn\Application Data\Mozilla\Firefox\Profiles\mqlnu3fr.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
www.google.fr
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-26 01:13:54
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
"\\\\EVO\\EPSON Stylus C86 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_S4I0R2.EXE /P29 \"\\\\EVO\\EPSON Stylus C86 Series\" /O6 \"USB002\" /M \"Stylus C86\""
.
Temps d'accomplissement: 2008-08-26 1:15:38
ComboFix-quarantined-files.txt 2008-08-25 23:15:21
ComboFix2.txt 2008-08-25 23:04:52
ComboFix3.txt 2008-08-25 22:37:23
Pre-Run: 976,965,632 octets libres
Post-Run: 957,861,888 octets libres
209
seul amélioration pour l'instant: l'option des fichiers cachées est revenue, je peux donc ré-afficher mes fichiers caché
Sinon rien n'a vraiment évolué: mes antivirus et antiSpyWare ne fonctionnent toujours pas, mon wifi toujours dans les choux
Malgré que certain logiciel (antiBeagle) ne détecte rien, il s'agirait quand même d'un problème de sécurité?? donc je ne me vexerai pas si un modo transfert ce topic vers la rubrique "Sécurité"
Merci de ta patience.