J'ai fais une erreur de procédure , j'ai lancé combofix et j'ai oublier de copier les fichiers :
File::
C:\WINDOWS\system32\sysmgr.exe
C:\WINDOWS\TEMP\winlagon.exe
C:\WINDOWS\system32\drivers\spools.exe
C:\WINDOWS\system32\iSecurity.cpl
Folder::
C:\Program Files\cjb\
C:\Program Files\WinIFixer\
dans combofix
J'ai néanmoins un rapport que voici :
ComboFix 08-04-29.3 - Admin 2008-04-30 10:33:06.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.198 [GMT 2:00]
Endroit: C:\Documents and Settings\Admin\Bureau\COMBOFIX\ComboFix.exe
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-03-28 to 2008-04-30 ))))))))))))))))))))))))))))))))))))
.
2008-04-29 14:57 . 2008-04-29 14:57 <REP> d-------- C:\Program Files\Avira
2008-04-29 14:57 . 2008-04-29 14:57 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-04-29 10:22 . 2008-04-29 10:22 <REP> d-------- C:\WINDOWS\ERUNT
2008-04-29 10:20 . 2008-04-29 10:39 <REP> d-------- C:\SDFix
2008-04-28 16:09 . 1996-08-20 20:37 15,840 --a------ C:\WINDOWS\system32\Machnm1.exe
2008-04-28 16:09 . 2005-09-25 16:37 5,632 --a------ C:\WINDOWS\system32\Machnm64.sys
2008-04-28 16:09 . 2008-04-28 16:09 3,120 --a------ C:\WINDOWS\system32\118290.54
2008-04-28 16:09 . 2008-04-28 16:09 3,120 --a------ C:\WINDOWS\118294.78
2008-04-28 16:09 . 2003-08-13 00:27 2,304 --a------ C:\WINDOWS\system32\Machnm32.sys
2008-04-28 13:39 . 2008-04-28 13:39 <REP> d-------- C:\Program Files\Trend Micro
2008-04-22 15:10 . 2006-09-18 16:55 109,744 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-04-22 15:10 . 2006-09-18 16:55 48,816 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-04-18 10:31 . 2008-04-18 10:31 <REP> d-------- C:\Documents and Settings\Admin\Application Data\Lavasoft
2008-04-18 10:30 . 2008-04-18 10:30 <REP> d-------- C:\Program Files\Lavasoft
2008-04-17 16:19 . 2008-04-17 16:19 45,768 --a------ C:\WINDOWS\system32\drivers\MiniIcpt.sys
2008-04-17 16:18 . 2008-04-17 16:18 <REP> d-------- C:\WINDOWS\l2schemas
2008-04-17 16:18 . 2005-04-20 21:31 1,721,344 -----c--- C:\WINDOWS\system32\dllcache\netshell.dll
2008-04-17 16:18 . 2005-04-20 21:31 474,624 -----c--- C:\WINDOWS\system32\dllcache\wzcsvc.dll
2008-04-17 16:18 . 2005-04-20 21:31 381,952 -----c--- C:\WINDOWS\system32\dllcache\wzcdlg.dll
2008-04-17 16:18 . 2006-11-01 09:16 69,120 --------- C:\WINDOWS\system32\wlanapi.dll
2008-04-17 16:18 . 2005-04-20 21:31 52,736 -----c--- C:\WINDOWS\system32\dllcache\wzcsapi.dll
2008-04-17 16:18 . 2005-04-20 01:54 14,592 -----c--- C:\WINDOWS\system32\dllcache\ndisuio.sys
2008-04-17 14:41 . 2008-04-17 14:41 <REP> d-------- C:\Program Files\CCleaner
2008-04-17 13:59 . 2008-04-17 13:59 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Malwarebytes
2008-04-17 13:19 . 2008-04-17 13:19 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-17 13:19 . 2008-04-17 13:19 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-17 13:19 . 2008-04-17 13:19 <REP> d-------- C:\Documents and Settings\Admin\Application Data\Malwarebytes
2008-04-17 13:00 . 2008-04-17 13:30 2,880 --a------ C:\WINDOWS\system32\wezo532.exe
2008-04-16 17:32 . 2008-04-17 13:44 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-04-16 17:32 . 2008-04-17 13:39 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-04-14 13:11 . 2008-04-14 13:11 <REP> dr------- C:\Documents and Settings\LocalService\Mes documents
2008-04-13 16:13 . 2008-04-17 13:29 463 --a------ C:\WINDOWS\system32\ongldd.tmp
2008-04-13 14:14 . 2008-04-13 14:14 <REP> d-------- C:\WINDOWS\report
2008-04-13 14:14 . 2008-04-13 14:14 <REP> d-------- C:\WINDOWS\AU_Backup
2008-04-13 14:14 . 2008-04-13 14:14 36,571,669 --a------ C:\WINDOWS\VPTNFILE.211
2008-04-13 14:14 . 2008-04-13 14:14 36,571,669 --a------ C:\WINDOWS\LPT$VPN.211
2008-04-13 14:14 . 2008-04-13 14:14 1,947,387 --a------ C:\WINDOWS\tsc.ptn
2008-04-13 14:14 . 2008-04-13 14:14 1,163,344 --a------ C:\WINDOWS\vsapi32.dll
2008-04-13 14:14 . 2008-04-13 14:14 333,576 --a------ C:\WINDOWS\TSC.exe
2008-04-13 14:14 . 2008-04-13 14:14 86,094 --a------ C:\WINDOWS\BPMNT.dll
2008-04-13 14:14 . 2008-04-13 14:14 71,749 --a------ C:\WINDOWS\hcextoutput.dll
2008-04-13 14:14 . 2008-04-13 15:49 823 --a------ C:\WINDOWS\tsc.ini
2008-04-13 14:10 . 2008-04-13 14:14 <REP> d-------- C:\WINDOWS\AU_Temp
2008-04-13 14:10 . 2008-04-13 14:10 <REP> d-------- C:\WINDOWS\AU_Log
2008-04-13 14:10 . 2008-04-13 14:10 170 --a------ C:\WINDOWS\GetServer.ini
2008-04-13 14:09 . 2008-04-13 14:09 507,904 --a------ C:\WINDOWS\TMUPDATE.DLL
2008-04-13 14:09 . 2008-04-13 14:09 286,720 --a------ C:\WINDOWS\PATCH.EXE
2008-04-13 14:09 . 2008-04-13 14:09 69,689 --a------ C:\WINDOWS\UNZIP.DLL
2008-03-24 14:07 . 2008-03-24 14:07 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TomTom
2008-03-24 14:06 . 2008-03-24 14:07 <REP> d-------- C:\Program Files\TomTom HOME
2008-03-24 14:04 . 2008-03-24 14:04 <REP> d-------- C:\Documents and Settings\Admin\Application Data\InstallShield
2008-03-17 14:42 . 2008-03-17 14:42 57 --a------ C:\WINDOWS\DcmLtbox-WS.ini
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-30 08:36 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-04-28 14:09 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-28 11:18 --------- d-----w C:\Program Files\Yahoo!
2008-04-28 11:17 --------- d-----w C:\Program Files\Common Files
2008-04-22 13:11 --------- d-----w C:\Program Files\Symantec
2008-04-22 13:11 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-04-22 13:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-04-22 08:05 --------- d-----w C:\Program Files\BELCompta
2008-04-17 11:40 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-04-14 13:49 --------- d-----w C:\Program Files\Fichiers communs\Real
2008-04-14 12:15 --------- d-----w C:\Program Files\Picasa2
2008-04-04 11:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-03-10 08:35 --------- d-----w C:\Program Files\Java
.
------- Sigcheck -------
2005-07-26 17:01 578048 0df75fb73f705b011630159a43d7c354 C:\WINDOWS\system32\user32.dll
2005-10-12 12:25 662528 a2dd7ec3ac1ead13f65e2898fcabbd1a C:\WINDOWS\system32\wininet.dll
2005-09-18 14:29 359936 0df628756fb71111955be60bac216a70 C:\WINDOWS\system32\drivers\tcpip.sys
2005-10-12 12:33 2058880 73fa9c95d235844a36968c7852c7dbdd C:\WINDOWS\system32\ntkrnlpa.exe
2005-07-26 17:01 2181376 63729dd0f2aae36cc52b89c05505146c C:\WINDOWS\system32\ntoskrnl.exe
2005-07-26 17:01 1036288 0bee3b07ace3303ee57698808e1d2de3 C:\WINDOWS\explorer.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 18:09 15360]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 14:07 1289000]
"L07FXLRD_2746765"="C:\Program Files\Microsoft Etudes\Microsoft Encarta 2007 - Études DVD\EDICT.exe" [ ]
"SpyEmergency"="C:\Program Files\Netgate\Spy Emergency 2006\SpyEmergency.exe" [ ]
"ntuser"="C:\WINDOWS\system32\drivers\spools.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cmaudio"="cmicnfg.cpl" []
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2007-09-06 10:35 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"SSBkgdUpdate"="C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 10:22 155648]
"IndexSearch"="C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [2007-09-06 11:37 40960]
"SetDefPrt"="C:\Program Files\Brother\Brmfl04g\BrStDvPt.exe" [2007-09-06 10:35 49152]
"ControlCenter2.0"="C:\Program Files\Brother\ControlCenter2\brctrcen.exe" [2005-01-07 17:30 864256]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 00:47 31016]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"AWMON"="C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" [2004-08-12 19:43 537088]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2006-07-19 19:26 52896]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-11-14 15:51 125536]
"GDFirewallTray"="C:\Program Files\G DATA AntiVirus plus Firewall\Firewall\GDFirewallTray.exe" [ ]
"AVKTray"="C:\Program Files\G DATA AntiVirus plus Firewall\AVKTray\AVKTray.exe" [ ]
"Microsoft(R) System Manager"="C:\WINDOWS\system32\sysmgr.exe" [ ]
"cjb"="C:\Program Files\cjb\cjb8.exe" [ ]
"WinIFixer"="C:\Program Files\WinIFixer\WinIFixer.exe" [ ]
"Hhjg5jfd93dftdf"="C:\WINDOWS\TEMP\winlagon.exe" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2008-02-26 03:23 443968]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="cmd.exe" [2004-08-19 18:09 400896 C:\WINDOWS\system32\cmd.exe]
"tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-19 17:52 44544]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoDesktopCleanupWizard"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoAutoUpdate"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoDesktopCleanupWizard"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoAutoUpdate"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"2500:TCP"= 2500:TCP:Lecteur de carte
"32531:TCP"= 32531:TCP:@xpsp2res.dll,-22005
"10982:TCP"= 10982:TCP:@xpsp2res.dll,-22005
"7877:TCP"= 7877:TCP:@xpsp2res.dll,-22005
"19248:TCP"= 19248:TCP:@xpsp2res.dll,-22005
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 PwrSataR;PwrSataR;C:\WINDOWS\system32\DRIVERS\PwrSataR.sys [2004-10-25 11:25]
R2 eID CRL Service;eID CRL Service;C:\WINDOWS\system32\beidservicecrl.exe [2006-06-20 13:38]
R3 ACSSCR;ACR38 Smart Card Reader;C:\WINDOWS\system32\DRIVERS\a38usb.sys [2006-03-24 19:14]
S1 SpyEmrg;Spy Emergency Driver;C:\WINDOWS\system32\Drivers\spyemrg.sys []
S3 AX88172;USB2.0 to Fast Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\UC210T.sys [2003-06-13 15:13]
S3 BrScnUsb;Brother USB Still Image driver;C:\WINDOWS\system32\Drivers\BrScnUsb.sys [2004-10-15 12:50]
S3 eID Privacy Service;eID Privacy Service;C:\WINDOWS\system32\beidservicepcsc.exe [2006-06-21 09:47]
S3 PavSRK.sys;PavSRK.sys;C:\WINDOWS\system32\PavSRK.sys []
S3 PavTPK.sys;PavTPK.sys;C:\WINDOWS\system32\PavTPK.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5eb1a5b6-56d2-11dc-81b0-0015f29969ce}]
\Shell\AutoRun\command - H:\setup.exe -q
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2007-10-10 22:00:00 C:\WINDOWS\Tasks\At1.job"
- C:\WINDOWS\system32\3iH6G213.exe
"2008-04-13 07:00:02 C:\WINDOWS\Tasks\At10.job"
- C:\WINDOWS\system32\3iH6G213.exe
"2008-04-13 08:00:00 C:\WINDOWS\Tasks\At11.job"
- C:\WINDOWS\system32\3iH6G213.exe
"2008-04-13 09:00:00 C:\WINDOWS\Tasks\At12.job"
- C:\WINDOWS\system32\3iH6G213.exe
"2008-04-13 10:00:00 C:\WINDOWS\Tasks\At13.job"
- C:\WINDOWS\system32\3iH6G213.exe
"2008-04-13 11:00:00 C:\WINDOWS\Tasks\At14.job"
- C:\WINDOWS\system32\3iH6G213.exe
"2008-04-13 12:00:00 C:\WINDOWS\Tasks\At15.job"
- C:\WINDOWS\system32\3iH6G213.exe
"2008-04-13 13:00:01 C:\WINDOWS\Tasks\At16.job"
- C:\WINDOWS\system32\3iH6G213.exe
"2008-04-13 14:00:00 C:\WINDOWS\Tasks\At17.job"
- C:\WINDOWS\system32\3iH6G213.exe
"2008-04-12 15:00:00 C:\WINDOWS\Tasks\At18.job"
- C:\WINDOWS\system32\3iH6G213.exe
"2008-04-12 16:00:02 C:\WINDOWS\Tasks\At19.job"
- C:\WINDOWS\system32\3iH6G213.exe
"2007-10-10 23:00:00 C:\WINDOWS\Tasks\At2.job"
- C:\WINDOWS\system32\3iH6G213.exe
"2008-04-12 17:00:00 C:\WINDOWS\Tasks\At20.job"
- C:\WINDOWS\system32\3iH6G213.exe
"2008-03-28 19:00:00 C:\WINDOWS\Tasks\At21.job"
- C:\WINDOWS\system32\3iH6G213.exe
"2007-10-10 19:00:00 C:\WINDOWS\Tasks\At22.job"
- C:\WINDOWS\system32\3iH6G213.exe
"2007-10-10 20:00:00 C:\WINDOWS\Tasks\At23.job"
- C:\WINDOWS\system32\3iH6G213.exe
"2007-10-10 21:00:00 C:\WINDOWS\Tasks\At24.job"
- C:\WINDOWS\system32\3iH6G213.exe
"2007-10-10 22:00:00 C:\WINDOWS\Tasks\At25.job"
- C:\WINDOWS\system32\jyu1gJEF.exe
"2007-10-10 23:00:00 C:\WINDOWS\Tasks\At26.job"
- C:\WINDOWS\system32\jyu1gJEF.exe
"2007-10-11 00:00:00 C:\WINDOWS\Tasks\At27.job"
- C:\WINDOWS\system32\jyu1gJEF.exe
"2007-10-11 01:00:00 C:\WINDOWS\Tasks\At28.job"
- C:\WINDOWS\system32\jyu1gJEF.exe
"2007-10-11 02:00:00 C:\WINDOWS\Tasks\At29.job"
- C:\WINDOWS\system32\jyu1gJEF.exe
"2007-10-11 00:00:00 C:\WINDOWS\Tasks\At3.job"
- C:\WINDOWS\system32\3iH6G213.exe
"2007-10-11 03:00:00 C:\WINDOWS\Tasks\At30.job"
- C:\WINDOWS\system32\jyu1gJEF.exe
"2008-03-27 05:00:00 C:\WINDOWS\Tasks\At31.job"
- C:\WINDOWS\system32\jyu1gJEF.exe
"2007-10-11 05:00:00 C:\WINDOWS\Tasks\At32.job"
- C:\WINDOWS\system32\jyu1gJEF.exe
"2008-04-09 06:00:00 C:\WINDOWS\Tasks\At33.job"
- C:\WINDOWS\system32\jyu1gJEF.exe
"2008-04-13 07:00:03 C:\WINDOWS\Tasks\At34.job"
- C:\WINDOWS\system32\jyu1gJEF.exe
"2008-04-13 08:00:00 C:\WINDOWS\Tasks\At35.job"
- C:\WINDOWS\system32\jyu1gJEF.exe
"2008-04-13 09:00:00 C:\WINDOWS\Tasks\At36.job"
- C:\WINDOWS\system32\jyu1gJEF.exe
"2008-04-13 10:00:01 C:\WINDOWS\Tasks\At37.job"
- C:\WINDOWS\system32\jyu1gJEF.exe
"2008-04-13 11:00:00 C:\WINDOWS\Tasks\At38.job"
- C:\WINDOWS\system32\jyu1gJEF.exe
"2008-04-13 12:00:00 C:\WINDOWS\Tasks\At39.job"
- C:\WINDOWS\system32\jyu1gJEF.exe
"2007-10-11 01:00:00 C:\WINDOWS\Tasks\At4.job"
- C:\WINDOWS\system32\3iH6G213.exe
"2008-04-13 13:00:01 C:\WINDOWS\Tasks\At40.job"
- C:\WINDOWS\system32\jyu1gJEF.exe
"2008-04-13 14:00:00 C:\WINDOWS\Tasks\At41.job"
- C:\WINDOWS\system32\jyu1gJEF.exe
"2008-04-12 15:00:00 C:\WINDOWS\Tasks\At42.job"
- C:\WINDOWS\system32\jyu1gJEF.exe
"2008-04-12 16:00:02 C:\WINDOWS\Tasks\At43.job"
- C:\WINDOWS\system32\jyu1gJEF.exe
"2008-04-12 17:00:00 C:\WINDOWS\Tasks\At44.job"
- C:\WINDOWS\system32\jyu1gJEF.exe
"2008-03-28 19:00:00 C:\WINDOWS\Tasks\At45.job"
- C:\WINDOWS\system32\jyu1gJEF.exe
"2007-10-10 19:00:00 C:\WINDOWS\Tasks\At46.job"
- C:\WINDOWS\system32\jyu1gJEF.exe
"2007-10-10 20:00:00 C:\WINDOWS\Tasks\At47.job"
- C:\WINDOWS\system32\jyu1gJEF.exe
"2007-10-10 21:00:00 C:\WINDOWS\Tasks\At48.job"
- C:\WINDOWS\system32\jyu1gJEF.exe
"2007-10-11 02:00:00 C:\WINDOWS\Tasks\At5.job"
- C:\WINDOWS\system32\3iH6G213.exe
"2007-10-11 03:00:00 C:\WINDOWS\Tasks\At6.job"
- C:\WINDOWS\system32\3iH6G213.exe
"2008-03-27 05:00:00 C:\WINDOWS\Tasks\At7.job"
- C:\WINDOWS\system32\3iH6G213.exe
"2007-10-11 05:00:00 C:\WINDOWS\Tasks\At8.job"
- C:\WINDOWS\system32\3iH6G213.exe
"2008-04-09 06:00:00 C:\WINDOWS\Tasks\At9.job"
- C:\WINDOWS\system32\3iH6G213.exe
"2008-04-14 12:05:45 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-30 10:37:53
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\scardsvr.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\RAXCO\PerfectDisk\PDAgent.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\RAXCO\PerfectDisk\PDEngine.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Symantec AntiVirus\DoScan.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-04-30 10:42:48 - machine was rebooted [Admin]
ComboFix-quarantined-files.txt 2008-04-30 08:42:35
Pre-Run: 13,781,487,616 octets libres
Post-Run: 13,688,434,688 octets libres
304