Cette fois ComboFix a marché parfaitement
ComboFix 08-09-03.03 - edouard 2008-09-04 15:58:59.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.454 [GMT 2:00]
Endroit: G:\documents de edouard2\Musiques de edouard\ComboFix.exe
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\edouard\Application Data\macromedia\Flash Player\#SharedObjects\AX9LZSYZ\bin.clearspring.com
C:\Documents and Settings\edouard\Application Data\macromedia\Flash Player\#SharedObjects\AX9LZSYZ\bin.clearspring.com\clearspring.sol
C:\Documents and Settings\edouard\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com
C:\Documents and Settings\edouard\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com\settings.sol
C:\Documents and Settings\ROMANE\Application Data\macromedia\Flash Player\#SharedObjects\F4HADUSJ\bin.clearspring.com
C:\Documents and Settings\ROMANE\Application Data\macromedia\Flash Player\#SharedObjects\F4HADUSJ\bin.clearspring.com\clearspring.sol
C:\Documents and Settings\ROMANE\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com
C:\Documents and Settings\ROMANE\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#bin.clearspring.com\settings.sol
C:\Documents and Settings\ROMANE\Cookies\romane@edt02[1].txt
C:\WINDOWS\Downloaded Program Files\egdaccess.inf
C:\WINDOWS\Downloaded Program Files\egdaccess_aspiv4.inf
C:\WINDOWS\Downloaded Program Files\netslv32.inf
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\pack.epk
C:\WINDOWS\pi.exe
C:\WINDOWS\system32\ckyomis.dat
C:\WINDOWS\system32\ckyomis.exe
C:\WINDOWS\system32\ckyomis_nav.dat
C:\WINDOWS\system32\ckyomis_navps.dat
C:\WINDOWS\system32\dplcogm.dat
C:\WINDOWS\system32\dplcogm_nav.dat
C:\WINDOWS\system32\dplcogm_navps.dat
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\nvs2.inf
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\UpMedia
C:\WINDOWS\system32\wanpacket.dll
C:\WINDOWS\system32\woetjwkhvi.dat
C:\WINDOWS\system32\woetjwkhvi_nav.dat
C:\WINDOWS\system32\woetjwkhvi_navps.dat
C:\WINDOWS\system32\wpcap.dll
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Service_NPF
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-08-04 to 2008-09-04 ))))))))))))))))))))))))))))))))))))
.
2008-09-04 15:18 . 2008-09-04 15:18 <REP> d-------- C:\Documents and Settings\LocalService\Application Data\AdobeUM
2008-09-04 14:50 . 2008-09-04 14:50 <REP> d-------- C:\WINDOWS\ERUNT
2008-09-04 14:40 . 2008-09-04 15:35 <REP> d----c--- C:\SDFix
2008-09-03 17:45 . 2008-09-03 17:45 <REP> d-------- C:\Program Files\Avira
2008-09-03 17:45 . 2008-09-03 17:45 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-09-03 15:21 . 2008-09-03 17:29 <REP> d-------- C:\Program Files\Navilog1
2008-09-03 15:01 . 2008-09-03 15:01 <REP> d-------- C:\Program Files\Trend Micro
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-03 17:52 --------- d-----w C:\Program Files\24-FR
2008-09-02 14:48 --------- d-----w C:\Program Files\Java
2008-09-01 21:14 --------- d-----w C:\Documents and Settings\edouard\Application Data\uTorrent
2008-08-31 10:45 --------- d-----w C:\Program Files\MSN Messenger
2008-08-31 10:45 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-07-25 18:28 --------- d-----w C:\Program Files\Monkey's Audio
2008-07-25 17:49 --------- d-----w C:\Program Files\Winamp
2008-07-10 15:51 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-10 15:51 --------- d-----w C:\Program Files\Deep Silver
2008-07-10 14:59 --------- d-----w C:\Documents and Settings\ROMANE\Application Data\InstallShield Installation Information
2008-07-10 14:59 --------- d-----w C:\Documents and Settings\ROMANE\Application Data\Deep Silver
2008-07-10 14:56 --------- d-----w C:\Documents and Settings\ROMANE\Application Data\InstallShield
2007-10-28 16:49 91,816 -c--a-w C:\Documents and Settings\ROMANE\Application Data\GDIPFONTCACHEV1.DAT
2007-09-19 15:35 91,816 -c--a-w C:\Documents and Settings\edouard\Application Data\GDIPFONTCACHEV1.DAT
2005-12-24 19:02 774,144 -c--a-w C:\Program Files\RngInterstitial.dll
2004-10-02 16:56 8,192 -csha-w C:\WINDOWS\o2cLicStore.bin
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"EPSON Stylus Photo R200 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0H2.EXE" [2003-09-11 99840]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 15360]
"NVIEW"="nview.dll" [2002-10-01 C:\WINDOWS\system32\nview.dll]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-03 282624]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 262401]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoLogoff"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2001-12-21 00:34 24576 G:\Program Files\AlienGUIse\fastload.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= DivXa32.acm
"vidc.yv12"= yv12vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"C:\\Program Files\\Outlook Express\\msimn.exe"=
"C:\\Program Files\\Java\\j2re1.4.1_01\\bin\\javaw.exe"=
"G:\\Program Files\\Radio Fr Solo\\Radio_Fr_Solo.exe"=
"G:\\Program Files\\Web TV\\WebTV.exe"=
"C:\\WINDOWS\\GOTOCFG.EXE"=
"C:\\Program Files\\Free.fr\\iconf.exe"=
"C:\\Program Files\\i-Media\\ims.exe"=
"C:\\WINDOWS\\system32\\dpnsvr.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\EA Games\\Command and Conquer Generals\\game.dat"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"G:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
"C:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"G:\\Program Files\\Red Storm Entertainment\\RavenShield\\system\\ravenshield.exe"=
"C:\\Program Files\\WinMX\\WinMX.exe"=
"C:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"G:\\Program Files\\THQ\\Dawn Of War\\W40k.exe"=
"G:\\Program Files\\eMule\\emule.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\FrostWire\\FrostWire.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\Program Files\\uTorrent\\utorrent-1.7-beta-2248.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"7571:UDP"= 7571:UDP:kademilia(0.46c)
"7561:TCP"= 7561:TCP:emule(0.46c)
"7362:TCP"= 7362:TCP:BitComet 7362 TCP
"7362:UDP"= 7362:UDP:BitComet 7362 UDP
"61196:TCP"= 61196:TCP:utorrent
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowRedirect"= 1 (0x1)
R3 PID_0920;Logitech QuickCam Express(PID_0920);C:\WINDOWS\system32\DRIVERS\LV532AV.SYS [2003-09-04 152576]
S1 ewido security suite driver;ewido security suite driver;C:\Program Files\ewido\security suite\guard.sys [ ]
S3 Boonty Games;Boonty Games;C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe [2006-01-03 69120]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;C:\WINDOWS\system32\DRIVERS\fbxusb32.sys [2004-10-20 21344]
S3 jbridgep;jbridgep;C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp\jbridgep.sys [ ]
S3 SetupNTGLM7X;SetupNTGLM7X;E:\NTGLM7X.sys [ ]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-04 15104]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{94f701a0-12d6-11dd-9571-001109333d16}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Setup.pif
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-IncrediMail - G:\Program Files\IncrediMail\bin\IncMail.exe
HKCU-Run-updateMgr - G:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
HKCU-Run-BitTorrent - G:\Program Files\BitTorrent\bittorrent.exe
HKLM-Run-ckyomis - c:\windows\system32\ckyomis.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\edouard\Application Data\Mozilla\Firefox\Profiles\dilw1cnu.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL -
hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://google.fr/
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-04 16:21:19
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
G:\Program Files\CDBurnerXP\NMSAccess.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\SlimCam 2 Mega\ICON.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-09-04 16:35:46 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-04 14:35:39
Pre-Run: 8,304,889,856 octets libres
Post-Run: 9,591,578,624 octets libres
189