voici le rapport :
ComboFix 08-09-05.12 - Claude 2008-09-09 17:38:47.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.233 [GMT 2:00]Endroit: C:\Documents and Settings\Claude\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Claude\Bureau\CFScript.txt
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Claude\real.txt
C:\Documents and Settings\Marion\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\WINDOWS\system32\^^^^^^.exe
C:\WINDOWS\system32\real.txt
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-08-09 to 2008-09-09 ))))))))))))))))))))))))))))))))))))
.
2008-09-09 16:25 . 2008-09-09 16:25 <REP> d-------- C:\_OTMoveIt
2008-09-09 10:44 . 2008-09-09 10:44 <REP> d-------- C:\Documents and Settings\Claude\Application Data\Malwarebytes
2008-09-09 10:44 . 2008-09-08 00:11 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-09 10:44 . 2008-09-08 00:11 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-09 10:43 . 2008-09-09 10:44 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-09 10:43 . 2008-09-09 10:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-09 10:32 . 2008-09-09 16:24 <REP> d-------- C:\Regsearch
2008-09-09 09:45 . 2008-09-09 09:47 <REP> d-------- C:\Program Files\Unlocker
2008-09-09 09:45 . 2008-09-09 15:58 <REP> d-------- C:\Documents and Settings\Claude\Application Data\Desktopicon
2008-09-09 09:38 . 2008-09-09 09:38 <REP> d-------- C:\Program Files\Zylom Games
2008-09-09 09:38 . 2008-09-09 09:38 <REP> d-------- C:\Documents and Settings\Claude\Application Data\Zylom
2008-09-09 09:32 . 2008-09-09 09:32 <REP> d--hs---- C:\WINDOWS\ftpcache
2008-09-09 09:32 . 2008-09-09 09:32 <REP> dr-h----- C:\Documents and Settings\Claude\Application Data\SecuROM
2008-09-09 09:32 . 2008-09-09 09:32 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-09-09 08:51 . 2008-09-09 09:42 <REP> d-------- C:\Hjt
2008-09-05 18:15 . 2008-09-05 18:15 <REP> d-------- C:\Program Files\iPod
2008-09-05 16:31 . 2008-09-05 16:31 <REP> d-------- C:\Program Files\NOS
2008-09-05 16:31 . 2008-09-05 16:31 <REP> d-------- C:\Documents and Settings\All Users\Application Data\NOS
2008-09-04 14:20 . 2008-09-04 14:21 <REP> d-------- C:\Program Files\OptGeo
2008-08-24 21:04 . 2008-08-24 21:04 <REP> d-------- C:\Program Files\Limewire
2008-08-24 21:04 . 2008-09-07 10:21 <REP> d-------- C:\Documents and Settings\Claude\Application Data\LimeWire
2008-08-19 19:14 . 2008-08-19 19:14 74,752 --a------ C:\WINDOWS\taskkill.exe
2008-08-11 09:59 . 2008-08-11 09:59 2,560 --a------ C:\Documents and Settings\Claude\shoixt.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-09 14:30 --------- d-----w C:\Program Files\Mozilla Firefox 2 Beta 1
2008-09-09 07:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-09 07:38 --------- d-----w C:\Documents and Settings\Claude\Application Data\PlayFirst
2008-09-09 07:38 --------- d-----w C:\Documents and Settings\All Users\Application Data\PlayFirst
2008-09-09 07:34 --------- d-----w C:\Program Files\Pochette Express 2
2008-09-09 07:34 --------- d-----w C:\Program Files\DivX
2008-09-09 06:19 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-09-07 08:27 --------- d-----w C:\Documents and Settings\Claude\Application Data\Apple Computer
2008-09-05 20:05 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-09-05 20:03 --------- d-----w C:\Documents and Settings\Claude\Application Data\AdobeUM
2008-09-05 16:17 --------- d-----w C:\Program Files\Apple Software Update
2008-09-05 16:16 --------- d-----w C:\Program Files\iTunes
2008-09-05 16:12 --------- d-----w C:\Program Files\QuickTime
2008-09-04 12:32 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-19 17:46 --------- d-----w C:\Program Files\Microsoft Works
2008-08-11 16:24 21,840 ----atw C:\WINDOWS\system32\SIntfNT.dll
2008-08-11 16:24 17,212 ----atw C:\WINDOWS\system32\SIntf32.dll
2008-08-11 16:24 12,067 ----atw C:\WINDOWS\system32\SIntf16.dll
2008-08-06 19:31 2,560 ----a-w C:\Documents and Settings\Claude\xfskzn.exe
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-14 10:47 --------- d-----w C:\Program Files\Java
2008-07-07 20:31 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 15:40 663,552 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\SET34.tmp
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\SET35.tmp
2006-08-29 17:29 56 --sh--r C:\WINDOWS\system32\FF1EB3E78A.sys
2006-08-29 17:29 1,890 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 15360]
"ccleaner"="C:\Program Files\CCleaner\ccleaner.exe" [2008-08-22 1234160]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2003-03-09 188416]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-14 266497]
"AppleSyncNotifier"="C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 116040]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2008-05-02 15872]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
"VIDC.HFYU"= huffyuv.dll
"vidc.ffds"= C:\Program Files\ffdshow\ffdshow.ax
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\fxsclnt.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Limewire\\LimeWire.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
S3 3593c490-a9f7-44df-87a2-127e99faaea3;3593c490-a9f7-44df-87a2-127e99faaea3;D:\Player\cds300.dll [ ]
S3 getPlus(R) Helper;getPlus(R) Helper;C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2008-08-29 33752]
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-Flash Media - C:\WINDOWS\system32\^^^^^^.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-09 17:47:12
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
--------------------- DLLs a charg‚ sous des processus courants ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\Unlocker\UnlockerHook.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hposts08.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-09-09 17:58:11 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-09 15:57:22
Pre-Run: 60,054,867,968 octets libres
Post-Run: 60,116,242,432 octets libres
157 --- E O F --- 2008-08-21 01:08:11