voici le log combofix
ComboFix 08-01-23.1C - Administrateur 2008-01-26 17:31:58.2 - NTFSx86 MINIMAL
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.2801 [GMT 1:00]
Endroit: C:\Documents and Settings\Administrateur\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Administrateur\Bureau\CFScript.txt
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
FILE
C:\WINDOWS\aswmklt.dll
C:\WINDOWS\dpvtporrtf.dll
C:\WINDOWS\fvqkfsp.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\aswmklt.dll
C:\WINDOWS\dpvtporrtf.dll
C:\WINDOWS\fvqkfsp.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2007-12-26 to 2008-01-26 ))))))))))))))))))))))))))))))))))))
.
2008-01-26 16:26 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\Nircmd.exe
2008-01-25 14:28 . 2008-01-25 14:28 <REP> d-------- C:\Program Files\mysqlcc
2008-01-25 14:12 . 2008-01-25 14:12 <REP> d-------- C:\Program Files\MySQL
2008-01-23 21:11 . 2008-01-23 21:11 <REP> d-------- C:\Program Files\Lavasoft
2008-01-23 20:59 . 2008-01-23 20:59 <REP> d-------- C:\Program Files\Trend Micro
2008-01-22 18:52 . 2008-01-23 21:32 6,328 --a------ C:\WINDOWS\system32\tmp.reg
2008-01-22 13:47 . 2008-01-26 17:28 7,628,576 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-22 13:47 . 2008-01-26 17:28 143,648 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-01-22 13:47 . 2008-01-26 17:28 105,332 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-22 13:47 . 2008-01-22 13:51 91,492 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-01-22 13:47 . 2008-01-22 13:51 85,860 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-01-22 13:47 . 2008-01-26 17:28 16,580 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-01-22 13:46 . 2008-01-22 13:47 <REP> d-------- C:\Program Files\Kaspersky Lab
2008-01-22 13:46 . 2008-01-22 13:46 <REP> d-------- C:\Program Files\Fichiers communs\Kaspersky Lab
2008-01-22 13:46 . 2008-01-22 13:46 <REP> d-------- C:\Program Files\Fichiers communs\Cisco Systems
2008-01-22 09:52 . 2008-01-22 09:52 85 --a------ C:\WINDOWS\wininit.ini
2008-01-21 18:51 . 2008-01-21 19:01 <REP> d-------- C:\Program Files\FreeRIP2
2008-01-21 18:26 . 2008-01-21 18:49 840 --a------ C:\WINDOWS\cdplayer.ini
2008-01-21 18:17 . 2008-01-21 18:17 <REP> d-------- C:\Program Files\Free Audio Pack
2008-01-21 18:09 . 2008-01-21 18:09 197 --a------ C:\WINDOWS\MP32WAV.INI
2008-01-21 16:46 . 2008-01-21 16:46 25,288 --ah----- C:\WINDOWS\system32\mlfcache.dat
2008-01-14 16:32 . 2008-01-25 15:44 <REP> d-------- C:\Temp\datas
2008-01-01 12:25 . 2008-01-01 12:25 <REP> d-------- C:\Program Files\IGN Rando
2008-01-01 12:25 . 1997-01-29 17:58 462,848 --a------ C:\WINDOWS\system32\NMW3VWN.DLL
2008-01-01 12:25 . 1997-01-29 17:53 240,640 --a------ C:\WINDOWS\system32\NMOCOD.DLL
2008-01-01 12:25 . 1997-02-27 00:00 192,272 --a------ C:\WINDOWS\system32\MCI32.OCX
2008-01-01 12:25 . 1997-01-29 18:05 169,472 --a------ C:\WINDOWS\system32\HTML.OCX
2008-01-01 12:25 . 1997-02-27 00:00 94,992 --a------ C:\WINDOWS\system32\Vb5fr.dll
2008-01-01 12:25 . 1997-03-04 13:44 66,560 --a------ C:\WINDOWS\system32\NMORENU.DLL
2008-01-01 12:25 . 1997-01-29 17:46 48,128 --a------ C:\WINDOWS\system32\NMSCKN.DLL
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-25 12:55 --------- d-----w C:\Program Files\sqldeveloper
2008-01-25 09:14 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-01-22 12:53 --------- d-----w C:\Program Files\vmntoolbar
2008-01-22 11:42 --------- d-----w C:\Program Files\Google
2008-01-16 10:44 --------- d-----w C:\Program Files\AseIsql
2008-01-01 11:25 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-06 10:35 73,216 ----a-w C:\WINDOWS\ST6UNST.EXE
2007-12-05 17:26 --------- d-----w C:\Program Files\Intel Corporation
2007-12-05 13:21 --------- d-----w C:\Program Files\Windows Media Components
2007-12-03 14:37 --------- d-----w C:\Program Files\SafeNet
2007-12-03 14:37 --------- d-----w C:\Program Files\OrangeBusinessServices
2007-12-03 14:37 --------- d-----w C:\Program Files\Fichiers communs\Deterministic Networks
2007-12-03 14:34 --------- d-----w C:\Program Files\Fichiers communs\France Telecom
2007-11-27 15:56 --------- d-----w C:\Program Files\Winamp
2007-11-18 10:46 86,016 ----a-w C:\WINDOWS\system32\OpenAL32.dll
2007-11-18 10:46 262,144 ----a-w C:\WINDOWS\system32\wrap_oal.dll
2007-11-14 13:51 35,328 ----a-w C:\WINDOWS\system32\mthr110.dll
2007-11-14 13:51 3,381,239 ----a-w C:\WINDOWS\system32\WCMDDA24.dll
2007-11-14 13:51 27,136 ----a-w C:\WINDOWS\system32\mt7r110.dll
2007-11-14 13:51 23,040 ----a-w C:\WINDOWS\system32\mchelp.dll
2007-11-14 13:51 224,768 ----a-w C:\WINDOWS\system32\clbr110.dll
2007-11-14 13:51 2,029,056 ----a-w C:\WINDOWS\system32\WCMDPA24.dll
2007-11-14 13:51 124,416 ----a-w C:\WINDOWS\system32\plbr110.dll
2007-11-14 13:51 1,207,296 ----a-w C:\WINDOWS\system32\mclib.dll
2007-11-14 13:14 253,952 ------w C:\WINDOWS\Setup1.exe
2007-11-14 07:28 450,560 ----a-w C:\WINDOWS\system32\dllcache\jscript.dll
2007-11-07 09:28 728,576 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:28 728,576 ----a-w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-30 17:20 360,064 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-30 10:18 3,079,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,293,824 ------w C:\WINDOWS\system32\dllcache\quartz.dll
.
(((((((((((((((((((((((((((((
snapshot@2008-01-26_16.30.53.21 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-26 15:26:43 1,413,120 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
+ 2008-01-26 16:31:54 1,413,120 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000001\NTUSER.DAT
- 2008-01-26 15:26:43 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
+ 2008-01-26 16:31:54 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000002\UsrClass.dat
- 2008-01-26 15:26:44 3,166,208 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
+ 2008-01-26 16:31:54 3,166,208 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000003\NTUSER.DAT
- 2008-01-26 15:26:44 114,688 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
+ 2008-01-26 16:31:54 114,688 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\
00000004\UsrClass.dat
- 2008-01-26 15:15:07 67,664 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-01-26 16:33:38 67,330 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-01-26 15:15:07 81,826 ----a-w C:\WINDOWS\system32\perfc00C.dat
+ 2008-01-26 16:33:38 81,388 ----a-w C:\WINDOWS\system32\perfc00C.dat
- 2008-01-26 15:15:07 420,286 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-01-26 16:33:38 419,952 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2008-01-26 15:15:07 489,448 ----a-w C:\WINDOWS\system32\perfh00C.dat
+ 2008-01-26 16:33:38 488,792 ----a-w C:\WINDOWS\system32\perfh00C.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33}
{03DA425A-7234-425C-95A6-FB8CFB7FFD8E}
[HKEY_CLASSES_ROOT\clsid\{03da425a-7234-425c-95a6-fb8cfb7ffd8e}]
[HKEY_CLASSES_ROOT\elfwgps.ToolBar.1]
[HKEY_CLASSES_ROOT\TypeLib\{BC498E74-EE51-4A67-9D7B-75B0FD65D934}]
[HKEY_CLASSES_ROOT\elfwgps.ToolBar]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-05-25 13:07 8429568]
"nwiz"="nwiz.exe" [2007-05-25 13:07 1626112 C:\WINDOWS\system32\nwiz.exe]
"MsmqIntCert"="regsvr32 /s mqrt.dll" []
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2007-01-05 17:36 872448]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2006-07-13 06:12 729088]
"PTHOSTTR"="C:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.exe" [2007-01-09 14:52 145184]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-12 14:36 827392]
"hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 12:18 472776]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-05-02 15:17 163840]
"CognizanceTS"="C:\PROGRA~1\HEWLET~1\IAM\Bin\ASTSVCC.dll" [2003-12-22 18:12 17920]
"Recguard"="C:\WINDOWS\Sminst\Recguard.exe" [2005-12-20 15:51 1187840]
"Reminder"="C:\WINDOWS\Creator\Remind_XP.exe" [2006-03-09 16:38 806912]
"Scheduler"="C:\WINDOWS\SMINST\Scheduler.exe" [2006-10-09 10:23 697976]
"HP Software Update"="c:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 22:11 49152]
"Cpqset"="C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe" [2007-05-03 10:52 57344]
"AccelerometerSysTrayApplet"="C:\WINDOWS\system32\AccelerometerSt.exe" [2007-01-24 14:28 124928]
"atchk"="C:\Program Files\Intel\AMT\atchk.exe" [2007-05-01 17:52 404248]
"HPWWANGSAssistant"="c:\SWSetup\HPQWWAN\HPWWanGSAssistant.exe" [ ]
"Sun ONE Synchronization - iPlanet"="C:\Program Files\Fichiers communs\XCPCSync\Translators\iPlanet\iPlanetTray.exe" [ ]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"WatchDog"="C:\Program Files\InterVideo\DVD Check\DVDCheck.exe" [2007-05-23 11:00 192512]
"BEW-INTRANET-FR-30SessionManager"="C:\Program Files\OrangeBusinessServices\BEW\SessionManager\SessionManager.exe" [2007-08-21 19:07 102400]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-10-10 06:28 36352]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0 for Windows Workstations\avp.exe" [2007-10-05 16:18 230664]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 09:00 15360]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
BTTray.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-02-06 15:14:00 561213]
DVD Check.lnk - C:\Program Files\InterVideo\DVD Check\DVDCheck.exe [2007-11-12 14:45:18 192512]
HotSync Manager.lnk - C:\Program Files\palmOne\Hotsync.exe [2004-06-09 14:16:08 471040]
SoftRemote.lnk - C:\Program Files\SafeNet\SoftRemote\SafeCfg.exe [2007-12-03 15:37:43 73780]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\DeviceNP]
DeviceNP.dll 2007-04-30 07:19 49152 C:\WINDOWS\system32\DeviceNP.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=APSHook.dll,C:\PROGRA~1\KASPER~1\KASPER~1.0FO\adialhk.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\group policy\state\Machine\Scripts\Shutdown\
0\
0]
"Script"=trace.bat
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MagicRotation]
--a------ 2006-03-14 13:12 1097728 C:\Program Files\MagicRotation\MagicPvt.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2007-05-25 13:07 81920 C:\WINDOWS\system32\NvMcTray.dll
R0 SafeBoot;SafeBoot;C:\WINDOWS\system32\drivers\SafeBoot.sys [2007-04-26 18:23]
R0 SbAlg;SbAlg;C:\WINDOWS\system32\drivers\SbAlg.sys [2006-10-09 12:31]
R0 SbFsLock;SbFsLock;C:\WINDOWS\system32\drivers\SbFsLock.sys [2007-03-29 15:54]
R3 IFXTPM;IFXTPM;C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS [2007-04-04 20:16]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
S1 IPSECDRV;SafeNet IPSec Plugin;C:\WINDOWS\system32\Drivers\IPSECDRV.sys [2006-05-01 18:06]
S1 magicpvt;magicpvt;C:\WINDOWS\system32\drivers\magicpvt.sys [2005-11-14 03:26]
S1 NaturalColor;NaturalColor;C:\WINDOWS\system32\drivers\MTictwl.sys []
S1 RsvLock;RsvLock;C:\WINDOWS\system32\drivers\RsvLock.sys [2007-04-26 18:23]
S2 ASChannel;Canal de communication local;C:\WINDOWS\System32\svchost.exe [2004-08-05 09:00]
S2 atchksrv;Intel(R) Active Management Technology System Status Service;C:\Program Files\Intel\AMT\atchksrv.exe [2007-05-01 17:52]
S2 Crypto;Crypto;C:\WINDOWS\system32\Drivers\Crypto.sys [2005-08-15 09:27]
S2 HpFkCryptService;Drive Encryption Service;"c:\Program Files\Hewlett-Packard\Drive Encryption\HpFkCrypt.exe" [2007-04-27 09:58]
S2 klnagent;Kaspersky Network Agent;"C:\Program Files\Kaspersky Lab\NetworkAgent\klnagent.exe" [2007-10-02 13:50]
S2 LMS;Intel(R) Active Management Technology Local Management Service;C:\Program Files\Intel\AMT\LMS.exe [2007-05-01 17:52]
S2 SWIHPWMI;SWIHPWMI;C:\Program Files\HPQ\Shared\Sierra Wireless\Win32\Unicode\SWIHPWMI.exe [2006-12-04 16:13]
S2 UNS;Intel(R) Active Management Technology User Notification Service;C:\Program Files\Intel\AMT\UNS.exe [2007-05-01 17:52]
S3 APSINV;APSINV;C:\WINDOWS\system32\DRIVERS\APSINV.SYS [2004-11-10 19:07]
S3 DAMDrv;DAMDrv;C:\WINDOWS\system32\DRIVERS\DAMDrv.sys [2007-04-23 12:13]
S3 DniVap;SafeNet WAN Miniport (VA);C:\WINDOWS\system32\DRIVERS\vap.sys [2001-12-14 16:26]
S3 FLCDLOCK;Verrouillage des périphériques / Audition HP ProtectTools;C:\WINDOWS\system32\flcdlock.exe [2007-04-30 07:28]
S3 GTF32BUS;GT F32 BUS;C:\WINDOWS\system32\DRIVERS\gtf32bus.sys [2007-01-15 16:43]
S3 GTPTSER;GT PT SER;C:\WINDOWS\system32\DRIVERS\gtptser.sys [2007-01-15 16:43]
S3 GTSCSER;GT SC SER;C:\WINDOWS\system32\DRIVERS\gtscser.sys [2007-03-08 06:03]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-05-30 18:49]
S3 rismc32;RICOH Smart Card Reader;C:\WINDOWS\system32\DRIVERS\rismc32.sys [2006-12-20 02:08]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
Cognizance REG_MULTI_SZ ASChannel
*Newly Created Service* - MDMXSDK
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Fichiers communs\LightScribe\LSRunOnce.exe"
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-26 17:34:27
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe????????T??????????????|?M?|?????M?|&?@
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-01-26 17:34:57
ComboFix-quarantined-files.txt 2008-01-26 16:34:55
ComboFix2.txt 2008-01-26 15:31:27
.
2008-01-09 12:43:20 --- E O F ---