Voici le rapport COMBOFIX
ComboFix 08-11-04.02 - N&R Tayeb 2008-11-05 13:43:22.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.171 [GMT 1:00]
Lancé depuis: c:\documents and settings\N&R Tayeb\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\N&R Tayeb\Bureau\CFScript.txt
* Un nouveau point de restauration a été créé
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-05 au 2008-11-05 ))))))))))))))))))))))))))))))))))))
.
2008-11-05 13:38 . 2008-11-05 13:38 <REP> d-------- c:\program files\Trend Micro
2008-11-05 10:40 . 2008-11-05 10:40 <REP> d-------- c:\program files\Avira
2008-11-05 10:40 . 2008-11-05 10:40 <REP> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-11-01 19:35 . 2008-11-01 19:35 <REP> d-------- c:\documents and settings\N&R Tayeb\Application Data\Mostick
2008-11-01 13:08 . 2008-11-01 13:08 <REP> d-------- c:\windows\Internet Logs
2008-11-01 13:08 . 2008-11-01 13:08 <REP> d-------- c:\program files\Zone Labs
2008-10-30 16:26 . 2008-10-30 16:26 <REP> d-------- c:\program files\Boonty
2008-10-25 19:55 . 2008-10-25 19:58 <REP> d-------- c:\program files\Internet Download Manager
2008-10-25 15:42 . 2008-10-25 16:02 <REP> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2008-10-25 15:10 . 2008-10-25 15:10 <REP> d-------- c:\documents and settings\N&R Tayeb\Application Data\Malwarebytes
2008-10-25 15:10 . 2008-10-25 15:10 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-10-25 15:08 . 2008-10-25 15:10 <REP> d-------- c:\program files\The Cleaner Demo
2008-10-25 15:08 . 2008-10-25 15:08 5,376 --a------ c:\windows\system32\drivers\MS1000.sys
2008-10-25 15:05 . 2008-10-25 15:06 <REP> d-------- c:\documents and settings\N&R Tayeb\DoctorWeb
2008-10-25 15:02 . 2008-10-25 15:02 77,824 --a----t- c:\windows\system32\DRWEBSP.DLL
2008-10-25 15:01 . 2008-10-25 15:27 <REP> d-------- c:\program files\DrWeb
2008-10-25 14:49 . 2008-10-25 14:49 <REP> d-------- c:\program files\ToniArts
2008-10-24 08:24 . 2008-10-15 17:35 337,408 --------- c:\windows\system32\dllcache\netapi32.dll
2008-10-23 17:00 . 2008-10-30 22:46 69 --a------ c:\windows\NeroDigital.ini
2008-10-15 22:27 . 2008-09-08 11:41 333,824 --------- c:\windows\system32\dllcache\srv.sys
2008-10-15 22:24 . 2008-08-14 14:23 2,191,232 --------- c:\windows\system32\dllcache\ntoskrnl.exe
2008-10-15 22:24 . 2008-08-14 14:23 2,147,328 --------- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-10-15 22:24 . 2008-08-14 14:23 2,068,096 --------- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-15 22:24 . 2008-08-14 14:23 2,025,984 --------- c:\windows\system32\dllcache\ntkrpamp.exe
2008-10-15 22:24 . 2008-09-15 16:26 1,846,528 --------- c:\windows\system32\dllcache\win32k.sys
2008-10-08 19:16 . 2008-10-08 19:23 <REP> d-------- c:\program files\AtomixMP3
2008-10-07 13:05 . 2008-10-07 13:10 <REP> d-------- c:\program files\SopCast
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-31 19:02 --------- d-----w c:\documents and settings\N&R Tayeb\Application Data\uTorrent
2008-10-28 14:31 --------- d-----w c:\program files\Google
2008-10-25 18:56 --------- d-----w c:\documents and settings\N&R Tayeb\Application Data\DMCache
2008-10-25 15:03 --------- d-----w c:\program files\Windows Live Safety Center
2008-10-25 14:01 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-25 13:57 --------- d-----w c:\program files\Fichiers communs\snpstd3
2008-10-25 13:57 --------- d-----w c:\documents and settings\N&R Tayeb\Application Data\LimeWire
2008-10-25 11:38 --------- d-----w c:\documents and settings\N&R Tayeb\Application Data\IDM
2008-10-24 19:38 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-07 17:49 --------- d-----w c:\documents and settings\N&R Tayeb\Application Data\Samsung
2008-10-03 17:12 6,066,176 ----a-w c:\windows\system32\dllcache\ieframe.dll
2008-10-02 18:33 --------- d-----w c:\documents and settings\N&R Tayeb\Application Data\GetRightToGo
2008-10-01 17:34 --------- d-----w c:\program files\Free Download Manager
2008-10-01 12:09 --------- d-----w c:\program files\Fichiers communs\AVSMedia
2008-10-01 12:06 --------- d-----w c:\documents and settings\All Users\Application Data\AVS4YOU
2008-10-01 10:40 --------- d-----w c:\program files\Fichiers communs\Adobe
2008-09-29 10:09 --------- d-----w c:\documents and settings\All Users\Application Data\Yahoo!
2008-09-23 16:46 245,408 ----a-w c:\windows\system32\unicows.dll
2008-09-22 10:43 --------- d-----w c:\documents and settings\N&R Tayeb\Application Data\vlc
2008-09-20 14:08 --------- d-----w c:\documents and settings\N&R Tayeb\Application Data\AdobeUM
2008-09-20 11:02 --------- d-----w c:\program files\Java
2008-09-20 10:59 --------- d-----w c:\program files\Fichiers communs\Java
2008-09-20 09:32 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-09-20 09:00 --------- d-----w c:\documents and settings\Invité\Application Data\Yahoo!
2008-09-19 15:46 --------- d-----w c:\documents and settings\Invité\Application Data\vlc
2008-09-18 15:40 --------- d-----w c:\documents and settings\N&R Tayeb\Application Data\Yahoo!
2008-09-18 11:46 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2008-09-18 11:26 --------- d-----w c:\documents and settings\N&R Tayeb\Application Data\Logitech
2008-09-18 11:20 --------- d-----w c:\documents and settings\Invité\Application Data\Logitech
2008-09-17 17:22 --------- d-----w c:\documents and settings\All Users\Application Data\NCH Software
2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
2008-09-14 14:46 --------- d-----w c:\documents and settings\JP Bernard\Application Data\Skype
2008-09-14 14:32 --------- d-----w c:\documents and settings\JP Bernard\Application Data\skypePM
2008-09-08 11:52 --------- d-----w c:\documents and settings\JP Bernard\Application Data\InstallShield
2008-09-08 10:41 333,824 ----a-w c:\windows\system32\drivers\srv.sys
2008-08-27 09:11 3,593,216 ----a-w c:\windows\system32\dllcache\mshtml.dll
2008-08-25 08:39 70,656 ----a-w c:\windows\system32\dllcache\ie4uinit.exe
2008-08-25 08:38 13,824 ----a-w c:\windows\system32\dllcache\ieudinit.exe
2008-08-23 05:56 635,848 ----a-w c:\windows\system32\dllcache\iexplore.exe
2008-08-23 05:54 161,792 ----a-w c:\windows\system32\dllcache\ieakui.dll
2008-08-14 13:23 2,191,232 ----a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 13:23 2,068,096 ----a-w c:\windows\system32\ntkrnlpa.exe
2008-08-14 10:04 138,496 ------w c:\windows\system32\dllcache\afd.sys
.
(((((((((((((((((((((((((((((
snapshot@2008-11-04_13.44.30.84 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-10-16 13:08:58 34,328 ----a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.2.6001.788\wups.dll
+ 2008-10-16 13:09:44 43,544 ----a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.2.6001.788\wups2.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2008-09-19 4347120]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiS Windows KeyHook"="c:\windows\system32\keyhook.exe" [2004-09-02 249856]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb11.exe" [2004-04-06 172032]
"HPHUPD06"="c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"HPHmon06"="c:\windows\system32\hphmon06.exe" [2004-06-07 659456]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 49152]
"FixCamera"="c:\windows\FixCamera.exe" [2007-07-11 20480]
"snpstd3"="c:\windows\vsnpstd3.exe" [2007-05-10 835584]
"tsnpstd3"="c:\windows\tsnpstd3.exe" [2007-04-21 270336]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SiSPower"="SiSPower.dll" [2004-09-02 c:\windows\system32\SiSPower.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\kem.exe [2004-01-11 561152]
Utility Tray.lnk - c:\windows\system32\sistray.exe [2004-09-14 331776]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecycleFiles"= 1 (0x1)
"NoResolveSearch"= 1 (0x1)
"NoLogOff"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"86:TCP"= 86:TCP:BroadCam Web Server
R3 CONAN;CONAN;c:\windows\system32\drivers\o2mmb.sys [2004-02-12 191092]
R3 MbxStby;MbxStby;c:\windows\system32\drivers\MbxStby.sys [2004-01-27 6100]
S3 iatmunin;iatmunin;c:\docume~1\JPBERN~1\LOCALS~1\Temp\iatmunin.sys [ ]
S3 PCASp50;PCASp50 NDIS Protocol Driver;c:\windows\system32\Drivers\PCASp50.sys [2005-11-19 20096]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d339a476-a841-11dd-a0da-00030d184902}]
\Shell\AutoRun\command - F:\start.exe
\Shell\iledefrance\command - F:\start.exe
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-05 13:46:09
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-11-05 13:49:37
ComboFix-quarantined-files.txt 2008-11-05 12:49:22
ComboFix2.txt 2008-11-04 12:45:33
Avant-CF: 29,228,847,104 octets libres
Après-CF: 29,234,036,736 octets libres
172 --- E O F --- 2008-10-24 08:39:25