Ensuite le rapport ComboFix:
ComboFix 08-06-09.7 - Maël 2008-06-10 21:36:25.1 - NTFSx86 MINIMAL
Endroit: C:\Documents and Settings\Maël\Bureau\ComboFix.exe
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
C:\WINDOWS\backinf.tab
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\session.exe
C:\WINDOWS\system32\filekan.exe
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\socksa.exe
C:\WINDOWS\ufdata2000.log
.
((((((((((((((((((((((((((((( Fichiers créés 2008-05-10 to 2008-06-10 ))))))))))))))))))))))))))))))))))))
.
2008-06-08 03:08 . 2008-06-08 03:08 <REP> d-------- C:\Program Files\Kantaris
2008-06-08 03:08 . 2008-06-08 03:10 <REP> d-------- C:\Documents and Settings\Maël\Application Data\kantaris
2008-06-07 11:15 . 2008-06-07 11:15 687 --a------ C:\WINDOWS\{0240BDFB-2995-4A3F-8C96-18D41282B716}_WiseFW.ini
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-10 19:19 --------- d-----w C:\Program Files\eMule
2008-06-10 18:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-06-09 10:22 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-06-08 00:44 --------- d-----w C:\Program Files\VideoLAN
2008-06-05 21:17 --------- d-----w C:\Documents and Settings\Maël\Application Data\uTorrent
2008-06-01 12:57 --------- d-----w C:\Program Files\Dell Network Assistant
2008-05-30 10:14 --------- d-----w C:\Program Files\dl_cats
2008-05-06 22:27 --------- d-----w C:\Program Files\Shareaza
2008-05-06 22:27 --------- d-----w C:\Documents and Settings\Maël\Application Data\Shareaza
2008-04-26 23:01 --------- d-----w C:\Program Files\UnFREEz
2008-04-26 22:58 --------- d-----w C:\Program Files\Microsoft GIF Animator
2008-04-24 20:57 --------- d-----w C:\Program Files\RAR Password Cracker
2008-04-20 21:08 --------- d-----w C:\Program Files\Google
2008-04-12 22:39 --------- d-----w C:\Program Files\DivX
2008-04-12 19:42 --------- d-----w C:\Program Files\MSN Messenger
2008-04-12 19:41 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-04-12 19:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-04-12 18:44 --------- d-----w C:\Documents and Settings\Maël\Application Data\Delivery
2008-04-12 18:37 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-04-12 18:16 --------- d-----w C:\Program Files\Native Instruments
2008-04-12 18:16 --------- d-----w C:\Program Files\Fichiers communs\ArcSoft
2008-04-12 18:16 --------- d-----w C:\Program Files\Abbyy FineReader 6.0 Sprint
2008-04-12 18:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Samsung
2008-04-12 18:11 --------- d-----w C:\Program Files\MSXML 4.0
2008-04-12 18:11 --------- d-----w C:\Program Files\Fichiers communs\McAfee
2008-04-12 18:11 --------- d-----w C:\Documents and Settings\Soph\Application Data\McAfee.com Personal Firewall
2008-04-12 18:11 --------- d-----w C:\Documents and Settings\Maël\Application Data\McAfee.com Personal Firewall
2008-04-12 18:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com Personal Firewall
2008-04-12 18:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com
2008-04-12 11:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\SingleClick Systems
2008-04-12 11:41 --------- d-----w C:\Program Files\McAfee.com
2008-04-12 11:40 --------- d-----w C:\Program Files\McAfee
2008-04-12 11:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\SiteAdvisor
2008-04-12 11:37 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-03-23 20:41 230,432 ----a-w C:\StiImg.dat
2007-01-09 11:00 168 --sh--r C:\WINDOWS\system32\1D0170AE8D.sys
2007-04-05 20:39 104 --sh--r C:\WINDOWS\system32\8DAE70011D.sys
2007-04-05 20:39 12,208 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" [2006-12-11 17:58 190024]
"Gadwin PrintScreen 3.5"="C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe" [2006-07-08 10:57 1101824]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
"eMuleAutoStart"="C:\Program Files\eMule\emule.exe" [2008-05-11 13:19 5423104]
"ModemOnHold"="C:\Program Files\NetWaiting\netWaiting.exe" [2003-09-10 04:24 20480]
"DellSupport"="C:\Program Files\Dell Support\DSAgnt.exe" [2006-08-28 23:57 395776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DLCXCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-06-07 18:17 106496]
"MCUpdateExe"="c:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 13:05 212992]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-05-11 23:33 185896]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-29 15:05 282624]
"MSKAGENTEXE"="C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe" [2005-11-09 16:01 110592]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\McAgent.exe" [2005-09-22 19:29 303104]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Dell Network Assistant.lnk - C:\WINDOWS\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2006-12-06 07:38:33 7168]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-12-06 07:32:27 24576]
DSLMON.lnk - C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2007-10-13 18:40:49 962663]
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696]
Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2008-04-20 23:04:38 124400]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Dell\\MediaDirect\\PCMService.exe"=
"C:\\WINDOWS\\system32\\dlcxcoms.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"135:TCP"= 135:TCP:TCP Port 135
"5000:TCP"= 5000:TCP:TCP Port 5000
"5001:TCP"= 5001:TCP:TCP Port 5001
"5002:TCP"= 5002:TCP:TCP Port 5002
"5003:TCP"= 5003:TCP:TCP Port 5003
"5004:TCP"= 5004:TCP:TCP Port 5004
"5005:TCP"= 5005:TCP:TCP Port 5005
"5006:TCP"= 5006:TCP:TCP Port 5006
"5007:TCP"= 5007:TCP:TCP Port 5007
"5008:TCP"= 5008:TCP:TCP Port 5008
"5009:TCP"= 5009:TCP:TCP Port 5009
"5010:TCP"= 5010:TCP:TCP Port 5010
"5011:TCP"= 5011:TCP:TCP Port 5011
"5012:TCP"= 5012:TCP:TCP Port 5012
"5013:TCP"= 5013:TCP:TCP Port 5013
"5014:TCP"= 5014:TCP:TCP Port 5014
"5015:TCP"= 5015:TCP:TCP Port 5015
"5016:TCP"= 5016:TCP:TCP Port 5016
"5017:TCP"= 5017:TCP:TCP Port 5017
"5018:TCP"= 5018:TCP:TCP Port 5018
"5019:TCP"= 5019:TCP:TCP Port 5019
"5020:TCP"= 5020:TCP:TCP Port 5020
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 00:08]
S3 dlcx_device;dlcx_device;C:\WINDOWS\system32\dlcxcoms.exe [2006-05-18 22:36]
S3 PAC207;Trust WB-1400T Webcam;C:\WINDOWS\system32\DRIVERS\pfc027.sys [2005-02-24 13:29]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 23:58]
*Newly Created Service* - ADILOADER
*Newly Created Service* - CATCHME
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-04-14 23:00:00 C:\WINDOWS\Tasks\McDefragTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe'
"2008-05-31 23:00:00 C:\WINDOWS\Tasks\McQcTask.job"
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe
"2008-06-09 19:22:20 C:\WINDOWS\Tasks\User_Feed_Synchronization-{986FE309-5351-4070-9420-C90E48E618CF}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-10 21:42:40
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DLCXCATS = rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-06-10 21:44:47
ComboFix-quarantined-files.txt 2008-06-10 19:44:29
Pre-Run: 14,036,267,008 octets libres
Post-Run: 16,310,607,872 octets libres
161 --- E O F --- 2007-12-15 14:38:26