Voili voilou !
ComboFix 09-02-10.01 - Admin 2009-02-10 19:30:39.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.3327.2636 [GMT 1:00]
Lancé depuis: c:\documents and settings\Admin\Bureau\ComboFix.exe
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\documents and settings\Admin\Application Data\.#
c:\documents and settings\Admin\Application Data\.#\MBX@DC0@A141A8.###
c:\documents and settings\Admin\Application Data\.#\MBX@DC0@A141D8.###
c:\documents and settings\Admin\Application Data\.#\MBX@DC0@A14208.###
c:\documents and settings\Admin\Local Settings\Application Data\vwgfgo.dat
c:\documents and settings\Admin\Local Settings\Application Data\vwgfgo_nav.dat
c:\documents and settings\Admin\Local Settings\Application Data\vwgfgo_navps.dat
c:\program files\Mozilla Firefox\components\iamfamous.dll
c:\windows\system32\test.ttt
D:\Autorun.inf
D:\resycled
d:\resycled\boot.com
E:\Autorun.inf
E:\resycled
e:\resycled\boot.com
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-01-10 au 2009-02-10 ))))))))))))))))))))))))))))))))))))
.
2009-02-10 19:27 . 2009-02-10 19:27 0 --a------ c:\windows\LCDMedia.INI
2009-02-10 17:47 . 2009-02-10 18:28 185 --a------ c:\windows\wininit.ini
2009-02-05 06:37 . 2009-02-05 06:37 46,605 --a------ C:\fraglist.luar
2009-02-01 21:30 . 2009-02-01 21:31 8 --a------ c:\windows\system32\nvModes.dat
2009-02-01 21:27 . 2009-01-15 08:19 453,152 --a------ c:\windows\system32\nvudisp.exe
2009-02-01 21:27 . 2009-02-07 10:47 206,530 --a------ c:\windows\system32\nvapps.xml
2009-02-01 21:27 . 2009-01-15 08:19 18,725 --a------ c:\windows\system32\nvdisp.nvu
2009-02-01 21:26 . 2009-01-07 11:28 453,152 --a------ c:\windows\system32\NVUNINST.EXE
2009-02-01 21:23 . 2009-02-01 21:23 <REP> d-------- c:\program files\SystemRequirementsLab
2009-02-01 21:23 . 2009-02-01 21:23 <REP> d-------- c:\documents and settings\Admin\Application Data\SystemRequirementsLab
2009-02-01 21:23 . 2009-02-01 21:23 552 --a------ c:\windows\system32\d3d8caps.dat
2009-02-01 21:22 . 2009-02-01 21:23 664 --a------ c:\windows\system32\d3d9caps.dat
2009-02-01 21:08 . 2009-02-01 21:08 <REP> d-------- c:\program files\Spybot - Search & Destroy
2009-02-01 21:08 . 2009-02-10 18:29 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-01 21:05 . 2009-02-01 21:05 <REP> d--h----- c:\windows\system32\GroupPolicy
2009-02-01 20:43 . 2009-02-01 20:59 <REP> d-------- c:\program files\Spyware Terminator
2009-02-01 20:43 . 2009-02-01 20:50 <REP> d-------- c:\documents and settings\All Users\Application Data\Spyware Terminator
2009-02-01 20:43 . 2009-02-10 17:23 <REP> d-------- c:\documents and settings\Admin\Application Data\Spyware Terminator
2009-02-01 20:43 . 2009-02-01 20:43 142,592 --a------ c:\windows\system32\drivers\sp_rsdrv2.sys
2009-01-31 13:38 . 2003-07-16 07:17 5,174 --a------ c:\windows\system32\nppt9x.vxd
2009-01-31 13:38 . 2004-12-30 22:43 4,682 --a------ c:\windows\system32\npptNT2.sys
2009-01-31 13:37 . 2009-01-31 13:37 <REP> d-------- c:\program files\Common Files
2009-01-31 13:13 . 2009-01-31 13:13 <REP> d-------- c:\documents and settings\All Users\Application Data\InstallShield
2009-01-30 15:07 . 2009-01-30 15:07 <REP> d-------- c:\documents and settings\All Users\Application Data\Ubisoft
2009-01-30 15:07 . 2009-01-30 15:06 22,328 --a------ c:\windows\system32\drivers\PnkBstrK.sys
2009-01-30 15:06 . 2009-01-30 15:06 <REP> d-------- c:\windows\system32\LogFiles
2009-01-30 15:06 . 2009-01-30 15:06 2,337,865 --a------ c:\windows\system32\pbsvc.exe
2009-01-30 15:06 . 2009-01-30 15:06 107,832 --a------ c:\windows\system32\PnkBstrB.exe
2009-01-30 15:06 . 2009-01-30 15:06 66,872 --a------ c:\windows\system32\PnkBstrA.exe
2009-01-30 15:06 . 2009-01-30 15:06 22,328 --a------ c:\documents and settings\Admin\Application Data\PnkBstrK.sys
2009-01-30 14:47 . 2009-01-30 14:47 107,888 --a------ c:\windows\system32\CmdLineExt.dll
2009-01-30 14:35 . 2009-01-30 14:35 <REP> dr-h----- c:\documents and settings\Admin\Application Data\SecuROM
2009-01-30 14:35 . 2009-01-30 14:35 98,304 --a------ c:\windows\system32CmdLineExt.dll
2009-01-30 14:23 . 2009-01-30 14:23 <REP> d-------- c:\documents and settings\Admin\Application Data\DAEMON Tools Pro
2009-01-30 14:23 . 2009-01-30 14:23 <REP> d-------- c:\documents and settings\Admin\Application Data\DAEMON Tools
2009-01-30 14:22 . 2009-01-30 14:22 <REP> d-------- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-01-30 14:20 . 2009-01-30 14:23 <REP> d-------- c:\documents and settings\Admin\Application Data\DAEMON Tools Lite
2009-01-30 14:20 . 2009-01-30 14:20 717,296 --a------ c:\windows\system32\drivers\sptd.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-08 07:28 --------- d-----w c:\documents and settings\Admin\Application Data\dvdcss
2009-02-07 08:25 --------- d-----w c:\program files\AMD
2009-02-02 19:45 --------- d-----w c:\documents and settings\Admin\Application Data\vlc
2009-02-01 20:27 --------- d-----w c:\program files\Fichiers communs\Wise Installation Wizard
2009-02-01 20:27 --------- d-----w c:\program files\AGEIA Technologies
2009-01-31 19:02 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-31 12:08 --------- d-----w c:\program files\Fichiers communs\InstallShield
2009-01-19 19:45 --------- d-----w c:\documents and settings\Admin\Application Data\teamspeak2
2009-01-05 10:58 --------- d-----w c:\program files\CCleaner
2009-01-03 15:06 410,984 ----a-w c:\windows\system32\deploytk.dll
2009-01-03 15:06 --------- d-----w c:\program files\Java
2008-12-29 01:58 21,840 ----a-w c:\windows\system32\SIntfNT.dll
2008-12-29 01:58 17,212 ----a-w c:\windows\system32\SIntf32.dll
2008-12-29 01:58 12,067 ----a-w c:\windows\system32\SIntf16.dll
2008-12-22 18:53 --------- d-----w c:\program files\Fichiers communs\Ahead
2008-12-22 18:53 --------- d-----w c:\program files\Ahead
2008-12-20 19:34 --------- d-----w c:\documents and settings\Admin\Application Data\Ahead
2008-12-12 19:20 --------- d-----w c:\program files\Teamspeak2_RC2
2008-12-10 08:45 70,936 ----a-w c:\windows\system32\PhysXLoader.dll
2008-12-04 08:28 24,344 ----a-w c:\windows\system32\PhysXDevice.dll
2008-11-26 07:55 288,024 ----a-w c:\windows\system32\PhysXCplUI.exe
2008-11-25 07:38 288,024 ----a-w c:\windows\system32\PhysXCompatCplUI.exe
2008-11-13 09:52 91,648 ----a-w c:\windows\system32\lua5.1a.dll
2008-11-13 09:52 9,728 ----a-w c:\windows\system32\udefrag.dll
2008-11-13 09:52 9,728 ----a-w c:\windows\system32\lua5.1a.exe
2008-11-13 09:52 9,728 ----a-w c:\windows\system32\defrag_native.exe
2008-11-13 09:52 86,016 ----a-w c:\windows\system32\ultradefrag.exe
2008-11-13 09:52 7,680 ----a-w c:\windows\system32\udefrag.exe
2008-11-13 09:52 6,656 ----a-w c:\windows\system32\udefrag-gui.exe
2008-11-13 09:52 6,656 ----a-w c:\windows\system32\bootexctrl.exe
2008-11-13 09:52 17,408 ----a-w c:\windows\system32\zenwinx.dll
2008-11-13 09:52 13,824 ----a-w c:\windows\system32\lua5.1a_gui.exe
.
------- Sigcheck -------
2005-07-26 14:01 578048 0df75fb73f705b011630159a43d7c354 c:\windows\system32\user32.dll
2005-12-14 12:12 662528 e41e8fdf62cf20f2e2b16d800d96eb51 c:\windows\system32\wininet.dll
2005-09-18 11:29 359936 0df628756fb71111955be60bac216a70 c:\windows\system32\drivers\tcpip.sys
2005-10-12 09:33 2017280 50b3a210b6fa8d3089a36a32e7d8b21f c:\windows\system32\ntkrnlpa.exe
2005-07-26 14:01 2137600 e75f7aa5a33479f29c636fd0890f5762 c:\windows\system32\ntoskrnl.exe
2005-07-26 14:01 1036288 0bee3b07ace3303ee57698808e1d2de3 c:\windows\explorer.exe
2005-08-10 11:15 57856 da81ec57acd4cdc3d4c51cf3d409af9f c:\windows\system32\spoolsv.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-11-17 1805552]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"SpybotDeletingD8748"="del" [X]
"SpybotDeletingD8969"="del" [X]
"SpybotDeletingD4405"="del" [X]
"SpybotDeletingB2022"="command.com" [2001-10-02 c:\windows\system32\command.com]
"SpybotDeletingB9354"="command.com" [2001-10-02 c:\windows\system32\command.com]
"SpybotDeletingB9040"="command.com" [2001-10-02 c:\windows\system32\command.com]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"Launch LGDCore"="c:\program files\Logitech\G-series Software\LGDCore.exe" [2005-11-02 1110079]
"Launch LCDMon"="c:\program files\Logitech\G-series Software\LCDMon.exe" [2005-11-02 188928]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-03 136600]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-01-15 13680640]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-01-15 86016]
"AODAssist.exe"="c:\program files\AMD\AMD OverDrive\AODAssist.exe" [2007-11-06 69632]
"nwiz"="nwiz.exe" [2009-01-15 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="move" [X]
"Config"="c:\windows\system32\run.cmd" [2005-08-23 341]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-19 44544]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoAutoUpdate"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoAutoUpdate"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 15:28 352256 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"e:\\Rainbow 6 vegas 1\\Binaries\\R6Vegas_Game.exe"=
"e:\\Rainbow 6 vegas 1\\Binaries\\R6Vegas_Launcher.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"e:\\Rainbow 6 vegas 2\\Binaries\\R6Vegas2_Game.exe"=
"e:\\Rainbow 6 vegas 2\\Binaries\\R6Vegas2_Launcher.exe"=
"e:\\NWN\\nwn2main.exe"=
"e:\\NWN\\nwn2main_amdxp.exe"=
"e:\\NWN\\nwupdate.exe"=
"e:\\NWN\\nwn2server.exe"=
R0 mv61xx;mv61xx;c:\windows\system32\drivers\mv61xx.sys [2007-06-15 143256]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2008-11-17 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2008-11-17 55024]
R2 MRUWebService;MRU Web Service;c:\program files\Marvell\61xx\Apache2\bin\Apache.exe [2007-05-23 20539]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-11-17 7408]
S3 Marvell RAID;Marvell RAID Event Agent;c:\program files\Marvell\61xx\svc\mvraidsvc.exe [2007-06-12 61440]
S3 ultradfg;ultradfg;c:\windows\system32\drivers\ultradfg.sys [2008-11-13 24576]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c63d9079-b7f2-11dd-be9c-0022157f732e}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com g:
\Shell\Open\command - g:\resycled\boot.com g:
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cf330a47-b7ed-11dd-8983-806d6172696f}]
\Shell\AutoRun\command - F:\autorun.exe
\Shell\install\command - F:\setup.exe
.
Contenu du dossier 'Tâches planifiées'
2009-01-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.wanadoo.fr
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.fr/keyword/%s
FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\cdd6lxls.default\
---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-10 19:31:17
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-1220945662-1614895754-839522115-1003\SOFTWARE\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:87,73,f0,28,96,76,bc,ce,28,96,8b,08,e9,54,41,1a,91,73,7a,ab,18,a1,5e,
77,7b,70,84,0f,da,56,dd,26,b4,01,b4,3b,f0,4b,53,c8,2b,57,89,75,28,6c,36,fa,\
"??"=hex:3a,bb,a1,e3,ab,56,3f,f9,d7,c7,4b,f2,d4,5a,36,8d
[HKEY_USERS\S-1-5-21-1220945662-1614895754-839522115-1003\SOFTWARE\SecuROM\License information*]
"datasecu"=hex:98,08,4f,03,8a,87,cd,93,e6,9a,8d,7d,3d,f7,93,56,a5,64,7f,e1,a3,
a3,2b,34,cb,e5,bc,73,ec,8e,26,ac,42,33,85,04,bc,1f,18,83,50,ab,0b,e3,f8,86,\
"rkeysecu"=hex:0c,bb,f8,93,3c,84,d9,7e,0c,9f,22,12,4b,32,b7,ac
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(712)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
Heure de fin: 2009-02-10 19:31:52
ComboFix-quarantined-files.txt 2009-02-10 18:31:51
Avant-CF: 24,057,016,320 octets libres
Après-CF: 24,051,912,704 octets libres
233