C'est fait :
ComboFix 07-11-19.4C - Dean_Keaton 2007-11-30 13:37:49.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.587 [GMT 1:00]
Running from: C:\Documents and Settings\Dean_Keaton\Bureau\ComboFix.exe
* Created a new restore point
.
ADS - svchost.exe: deleted 68 bytes in 1 streams.
ADS - ntoskrnl.exe: deleted 68 bytes in 1 streams.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users.\documents\settings\config.ini
C:\Documents and Settings\All Users.\documents\settings\ivn4.dll
C:\Documents and Settings\All Users\Menu Démarrer\Live Safety Center.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Online Security Guide.lnk
C:\Documents and Settings\Dean_Keaton\Bureau\Live Safety Center.lnk
C:\Documents and Settings\Dean_Keaton\Bureau\Online Security Guide.lnk
C:\WINDOWS\system32\nqstv.ini
C:\WINDOWS\system32\nqstv.ini2
C:\WINDOWS\system32\vtsqn.dll
C:\WINDOWS\system32\xpdx.sys
C:\Documents and Settings\All Users.\documents\settings
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\LEGACY_NTMLSVC
-------\LEGACY_SYMAVC32
-------\DomainService
-------\NtmlSvc
-------\symavc32
-------\xpdx
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-10-28 to 2007-11-30 ))))))))))))))))))))))))))))))))))))
.
2007-11-30 12:41 5,126 --a------ C:\WINDOWS\system32\tmp.reg
2007-11-30 12:40 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2007-11-30 12:40 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2007-11-30 12:35 78,912 --a------ C:\WINDOWS\system32\caftnxek.dll
2007-11-30 12:32 792,726 ---hs---- C:\WINDOWS\system32\ygbmkvrs.ini
2007-11-30 12:32 85,056 --a------ C:\WINDOWS\system32\srvkmbgy.dll
2007-11-30 11:42 <REP> d-------- C:\VundoFix Backups
2007-11-30 10:45 <REP> d-------- C:\Program Files\Panda Security
2007-11-30 10:11 790,097 ---hs---- C:\WINDOWS\system32\xmnvtbxx.ini
2007-11-29 12:18 <REP> d-------- C:\WINDOWS\system32\ActiveScan
2007-11-29 12:18 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2007-11-29 01:14 <REP> d-------- C:\Documents and Settings\Dean_Keaton\Application Data\Grisoft
2007-11-29 01:14 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-28 23:41 18,688 --a--c--- C:\WINDOWS\system32\dllcache\cdaudio.sys
2007-11-28 23:41 8,192 --a--c--- C:\WINDOWS\system32\dllcache\changer.sys
2007-11-28 23:14 37,376 --a------ C:\WINDOWS\system32\tuvssqo.dll
2007-11-25 18:20 <REP> d-------- C:\Program Files\Fichiers communs\Skype
2007-11-21 18:48 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-11-20 18:47 <REP> d-------- C:\Documents and Settings\Dean_Keaton\Application Data\Motive
2007-11-19 19:10 <REP> d-------- C:\Documents and Settings\All Users\Application Data\MotiveSysIDs
2007-11-19 18:54 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-11-19 18:30 <REP> d-------- C:\WINDOWS\Motive
2007-11-19 18:30 81,920 --a------ C:\WINDOWS\system32\W32n50.dll
2007-11-19 18:29 <REP> d-------- C:\Program Files\Motive
2007-11-19 18:29 <REP> d-------- C:\Program Files\Fichiers communs\Motive
2007-11-19 18:29 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Motive
2007-11-19 18:28 <REP> d-------- C:\Program Files\BroadJump
2007-11-19 18:28 532,594 --a------ C:\WINDOWS\system32\xerces-c_1_40_0_DDR.dll
2007-11-19 18:28 524,377 --a------ C:\WINDOWS\system32\stlport_4_0_0_DDR.dll
2007-11-19 18:28 307,329 --a------ C:\WINDOWS\system32\BJBase_2-2-2_DDR.dll
2007-11-19 18:28 159,744 --a------ C:\WINDOWS\system32\ssleay32_1-1-0_DDR.dll
2007-11-19 18:26 <REP> d-------- C:\Program Files\Club-Internet
2007-11-19 18:26 6,345 -ra------ C:\WINDOWS\system32\DevMngr.vxd
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-30 09:07 78,912 ----a-w C:\WINDOWS\system32\odmqplim.dll
2007-11-29 14:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-29 11:38 --------- d-----w C:\Program Files\QuickTime
2007-11-29 11:38 --------- d-----w C:\Program Files\Google
2007-11-28 22:07 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-25 17:26 --------- d-----w C:\Documents and Settings\Dean_Keaton\Application Data\Skype
2007-11-25 17:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2007-11-20 21:29 359,808 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS.ORIGINAL
2007-11-20 21:29 359,808 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS
2007-11-19 17:29 --------- d-----w C:\Program Files\Common Files
2007-10-25 17:05 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-10-25 17:05 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-10-25 16:24 815,480 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-10-25 16:14 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
2007-08-22 13:13 617,472 ----a-w C:\WINDOWS\system32\urlmon(2).dll
2007-08-21 06:17 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-17 20:11 22,872 ----a-w C:\Documents and Settings\Dean_Keaton\Application Data\GDIPFONTCACHEV1.DAT
2003-06-03 15:49 448,256 ----a-w C:\WINDOWS\inf\EL2K_N64.sys
2003-06-03 15:48 147,328 ----a-w C:\WINDOWS\inf\EL2K_XP.sys
2003-06-03 15:47 147,328 ----a-w C:\WINDOWS\inf\EL2K_2K.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{14edc8f7-9c6e-41a2-a82e-94192eb31753}]
2007-11-30 12:35 78912 --a------ C:\WINDOWS\system32\caftnxek.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8E3FBDE2-7DBD-4040-85D9-29BBC559C129}]
2007-11-28 23:14 37376 --a------ C:\WINDOWS\system32\tuvssqo.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WebCamRT.exe"="" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 00:09]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-31 16:08]
"PMCS"="F:\Program Files\Pinnacle\Shared Files\\Programs\MediaCenterService\PMC.Service.Main.exe" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2003-05-29 16:28]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2003-05-30 09:42]
"LiveNote"="livenote.exe" [2002-07-11 14:31 C:\WINDOWS\livenote.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"WinampAgent"="F:\Program Files\Winamp\Winampa.exe" [2003-04-02 03:20]
"LVCOMS"="C:\Program Files\Fichiers communs\Logitech\QCDriver\LVCOMS.EXE" [2001-09-24 09:39]
"Syslog"="" []
"tercv"="C:\WINDOWS\tercv.exe" []
"QuickTime Task"="C:\program files\quicktime\qttask.exe" [2004-06-06 18:48]
"Ulead Memory Card Detector"="F:\Program Files\Ulead Systems\Ulead Photo Explorer 7.0\Monitor.exe" [2002-09-11 14:00]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-20 00:10 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2005-02-24 00:32 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-20 00:10 C:\WINDOWS\system32\rundll32.exe]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-02-16 21:28]
"Sony Ericsson PC Suite"="F:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 15:17]
"PinnacleDriverCheck"="C:\WINDOWS\system32\PSDrvCheck.exe" []
"Pinnacle WebUpdater"="F:\Program Files\Pinnacle\Shared Files\\Programs\WebUpdater\WebUpdater.exe" []
"PMCRemote"="F:\Program Files\Pinnacle\Shared Files\\Programs\Remote\Remoterm.exe" []
"BJCFD"="C:\Program Files\BroadJump\Client Foundation\CFD.exe" [2003-01-27 17:16]
"Motive SmartBridge"="C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe" [2006-04-21 15:41]
"StandardInstall"="" []
"avast!"="F:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-10-25 17:20]
"UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" []
"!AVG Anti-Spyware"="F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"f40c2de4"="C:\WINDOWS\system32\srvkmbgy.dll" [2007-11-30 12:32]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-20 00:09]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2003-08-19 19:03]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[hklm\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{8E3FBDE2-7DBD-4040-85D9-29BBC559C129}"= C:\WINDOWS\system32\tuvssqo.dll [2007-11-28 23:14 37376]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ivn4reg]
C:\Documents and Settings\All Users\Documents\Settings\ivn4.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tuvssqo]
tuvssqo.dll 2007-11-28 23:14 37376 C:\WINDOWS\system32\tuvssqo.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\vtsqn.dll
R0 PzWDM;PzWDM;C:\WINDOWS\system32\Drivers\PzWDM.sys
R1 SSHDRV85;SSHDRV85;\??\C:\WINDOWS\system32\drivers\SSHDRV85.sys
R3 PhilCam8116;Logitech QuickCam Pro 3000(PID_08B0);C:\WINDOWS\system32\DRIVERS\CamDrL21.sys
S3 jgameenp;jgameenp;\??\C:\DOCUME~1\DEAN_K~1\LOCALS~1\Temp\jgameenp.sys
S3 USB28xxBGA;USB 2870 Device;C:\WINDOWS\system32\DRIVERS\emBDA.sys
S3 USB28xxOEM;USB 28xx OEM Filter;C:\WINDOWS\system32\DRIVERS\emOEM.sys
S3 w200bus;Sony Ericsson W200 driver (WDM);C:\WINDOWS\system32\DRIVERS\w200bus.sys
S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w200mdfl.sys
S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w200mdm.sys
S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w200mgmt.sys
S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w200obex.sys
*Newly Created Service* - SHAREDACCESS
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2007-11-30 12:44:12 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-30 13:44:51
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-30 13:48:30 - machine was rebooted
.
--- E O F ---
----
Entre tps j'ai eu un Adware "Win32: SecBar-B [Adw]" dans C:\Docume~1\Dean_K~1\Local~1\Temp\arhidgji.dll
Euh et là j'ai plus rien sur mon bureau tout à disparu... ainsi que le bouton Démarrer la barre de tache, bref j'ai plus rien oO
-->Message édité par Decay le 30/11/2007 14:18:54<--