voici le rapport de combofix
-> tout d'abord dans C:\ComboFix-quarantined-files
[code]
2006-06-02 18:52 1120 --a------ C:\Qoobox\Quarantine\C\INSTALL.LOG.vir
2007-05-31 08:17 37423 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\evenain.dll.vir
2007-06-10 17:34 53 --a------ C:\Qoobox\Quarantine\catchme.log
Structure du dossier
Le num‚ro de s‚rie du volume est 8C7E-E767
C:\QOOBOX
\---Quarantine
| catchme.log
|
+---C
| | INSTALL.LOG.vir
| |
| \---WINDOWS
| \---system32
| evenain.dll.vir
|
\---Registry_backups
[/code]
-> puis le log:
ComboFix 07-06-09.5
"ADMIN" - 2007-06-10 17:28:45 - Service Pack 2 NTFS
(((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))
C:\WINDOWS\system32\evenain.dll
* * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\install.log
((((((((((((((((((((((((( Files Created from 2007-05-10 to 2007-06-10 )))))))))))))))))))))))))))))))
2007-06-10 17:38 47,899 --a------ C:\WINDOWS\system32\ddabx.exe
2007-06-10 17:38 37,437 --a------ C:\WINDOWS\system32\asybug.dll
2007-06-10 17:27 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-09 18:53 <REP> d-------- C:\Program Files\a-squared Free
2007-06-09 16:57 <REP> d-------- C:\Program Files\RogueRemover PRO
2007-06-09 16:34 933 --a------ C:\DOCUME~1\ADMIN\APPLIC~1\tmp9D4.tmp.exe
2007-06-09 16:34 933 --a------ C:\DOCUME~1\ADMIN\APPLIC~1\tmp9C9.tmp.exe
2007-06-08 17:34 120,952 --a------ C:\WINDOWS\system32\PandoraCtrl2.dll
2007-06-08 17:34 102,400 --a------ C:\WINDOWS\system32\PandoraCtrl.dll
2007-06-08 17:34 <REP> d-------- C:\Program Files\Boonty
2007-06-07 10:02 659 --a------ C:\WINDOWS\mozver.dat
2007-06-06 13:48 <REP> d-------- C:\Program Files\Fichiers communs\xing shared
2007-06-06 03:01 933 --a------ C:\DOCUME~1\ADMIN\APPLIC~1\tmp13F.tmp.exe
2007-06-06 02:36 933 --a------ C:\DOCUME~1\ADMIN\APPLIC~1\tmp13B.tmp.exe
2007-06-06 02:02 933 --a------ C:\DOCUME~1\ADMIN\APPLIC~1\tmp12B.tmp.exe
2007-06-05 23:29 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
2007-06-05 23:02 <REP> d-------- C:\WINDOWS\system32\glvLog
2007-06-05 18:47 <REP> d-------- C:\DOCUME~1\ADMIN\Contacts
2007-06-05 18:46 <REP> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-06-05 18:46 <REP> d-------- C:\Program Files\MSN Messenger
2007-06-05 18:20 131,072 --a------ C:\WINDOWS\system32\datestamp.dll
2007-06-05 18:20 <REP> d-------- C:\WINDOWS\system32\ZeroSpyware
2007-06-05 18:08 <REP> d-------- C:\Program Files\FBM Software
2007-06-05 12:44 933 --a------ C:\DOCUME~1\ADMIN\APPLIC~1\tmp56A.tmp.exe
2007-06-05 12:43 933 --a------ C:\DOCUME~1\ADMIN\APPLIC~1\tmp566.tmp.exe
2007-06-05 12:37 933 --a------ C:\DOCUME~1\ADMIN\APPLIC~1\tmp4B.tmp.exe
2007-06-05 08:55 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-06-05 08:53 <REP> d-------- C:\Program Files\Navilog1
2007-06-04 17:47 933 --a------ C:\DOCUME~1\ADMIN\APPLIC~1\tmp1A9.tmp.exe
2007-06-04 17:37 232,862 --a------ C:\DOCUME~1\ADMIN\APPLIC~1\tmp191.tmp.exe
2007-06-04 17:31 <REP> d-------- C:\VundoFix Backups
2007-06-04 17:23 <REP> d-------- C:\Program Files\CCleaner
2007-06-04 17:21 933 --a------ C:\DOCUME~1\ADMIN\APPLIC~1\tmp17D.tmp.exe
2007-06-04 17:15 <REP> d-------- C:\Program Files\Hijackthis Version Fran‡aise
2007-06-03 09:52 233,689 --a------ C:\DOCUME~1\ADMIN\APPLIC~1\tmp5B.tmp.exe
2007-06-02 18:37 933 --a------ C:\DOCUME~1\ADMIN\APPLIC~1\tmp4C.tmp.exe
2007-06-02 18:37 233,385 --a------ C:\DOCUME~1\ADMIN\APPLIC~1\tmp52.tmp.exe
2007-06-02 18:36 933 --a------ C:\DOCUME~1\ADMIN\APPLIC~1\tmp48.tmp.exe
2007-06-02 13:25 233,515 --a------ C:\DOCUME~1\ADMIN\APPLIC~1\tmp57F.tmp.exe
2007-06-02 13:24 933 --a------ C:\DOCUME~1\ADMIN\APPLIC~1\tmp57A.tmp.exe
2007-06-02 13:24 933 --a------ C:\DOCUME~1\ADMIN\APPLIC~1\tmp574.tmp.exe
2007-06-02 12:06 233,301 --a------ C:\DOCUME~1\ADMIN\APPLIC~1\tmp34.tmp.exe
2007-06-01 17:28 233,421 --a------ C:\DOCUME~1\ADMIN\APPLIC~1\tmp1C7.tmp.exe
2007-05-31 08:17 47,948 --a------ C:\WINDOWS\system32\ddabc.exe
2007-05-31 08:12 12,494 --a------ C:\WINDOWS\system32\geebbyy.dll
2007-05-25 09:15 <REP> d-------- C:\Program Files\FairUse Wizard 2
2007-05-23 12:54 <REP> d-------- C:\DOCUME~1\ADMIN\APPLIC~1\ItsLabel
2007-05-23 12:50 <REP> d-------- C:\DOCUME~1\ADMIN\APPLIC~1\EoRezo
2007-05-13 09:43 78,848 --a------ C:\WINDOWS\system32\INLOADER.DLL
2007-05-13 09:43 <REP> d-------- C:\Program Files\PCFriendly
2007-05-13 00:27 <REP> d-------- C:\DOCUME~1\ADMIN\APPLIC~1\dvdcss
2007-05-12 11:55 <REP> d-------- C:\Program Files\DVD Decrypter
2007-05-11 09:26 29,696 --a------ C:\WINDOWS\mickey32.dll
2007-05-11 09:26 232,784 --a------ C:\WINDOWS\Matrix Code.scr
2007-05-11 09:26 2,285,222 --a------ C:\WINDOWS\Matrix Code.exe
2007-05-10 16:31 32,768 --a------ C:\WINDOWS\system32\WooDial2000.dll
2007-05-10 16:31 <REP> d-------- C:\WINDOWS\system32\AlertModule
2007-05-10 16:30 40,960 --a------ C:\WINDOWS\system32\FTRTSVC.exe
2007-05-10 16:29 <REP> d-------- C:\Program Files\Wanadoo
2007-05-10 16:22 <REP> d-------- C:\Program Files\Securitoo
2007-05-10 16:22 <REP> d-------- C:\Program Files\Inventel
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-06-10 15:35:54 81,984 ----a-w C:\WINDOWS\system32\bdod.bin
2007-06-09 22:54:38 -------- d-----w C:\Program Files\Hijackthis Version Française
2007-06-09 16:09:04 -------- d-----w C:\Program Files\PROMT98
2007-06-09 10:36:50 -------- d-----w C:\Program Files\BoontyGames
2007-06-07 08:15:33 -------- d-----w C:\Program Files\QuickTime
2007-06-06 11:47:43 -------- d-----w C:\Program Files\Fichiers communs\Real
2007-06-06 11:37:45 -------- d-----w C:\Program Files\VideoLAN
2007-06-05 21:21:31 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-06-05 20:56:17 -------- d-----w C:\Program Files\MessengerPlus! 3
2007-06-01 16:27:31 10 ----a-w C:\WINDOWS\popcinfo.dat
2007-05-17 03:54:27 -------- d-----w C:\Program Files\eMule
2007-05-17 03:44:33 -------- d-----w C:\Program Files\DivX
2007-05-13 23:49:35 -------- d-----w C:\DOCUME~1\ADMIN\APPLIC~1\Real
2007-05-11 14:08:33 -------- d-----w C:\Program Files\Fichiers communs\AVSMedia
2007-05-09 05:54:41 -------- d-----w C:\DOCUME~1\ADMIN\APPLIC~1\Media Player Classic
2007-05-07 14:28:00 -------- d-----w C:\Program Files\Red Storm Entertainment
2007-05-07 10:31:23 -------- d-----w C:\Program Files\ahead
2007-04-28 07:53:45 -------- d-----w C:\Program Files\K-Lite Codec Pack
2007-04-27 14:44:10 -------- d-----w C:\DOCUME~1\ADMIN\APPLIC~1\vlc
2007-04-27 10:41:54 -------- d-----w C:\Program Files\SLD Codec Pack
2007-04-27 10:41:44 0 ----a-w C:\WINDOWS\nsreg.dat
2007-04-27 10:28:08 49,494 ----a-w C:\WINDOWS\system32\perfc00C.dat
2007-04-27 10:28:08 370,414 ----a-w C:\WINDOWS\system32\perfh00C.dat
2007-04-27 10:24:41 81,920 ----a-w C:\WINDOWS\system32\W32N50.dll
2007-04-27 10:24:41 17,134 ----a-w C:\WINDOWS\system32\PCANDIS5.sys
2007-04-18 16:14:18 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-16 20:47:36 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-04-16 20:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 20:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 20:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 20:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 20:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 20:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 20:45:20 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-04-10 11:12:38 -------- d-----w C:\Program Files\Fichiers communs\BOONTY Shared
2007-04-08 16:01:05 913,408 ----a-w C:\WINDOWS\system32\xreglib.dll
2007-03-17 13:44:47 293,376 ----a-w C:\WINDOWS\system32\winsrv.dll
2004-08-05 12:00:00 94,864 --sh--w C:\WINDOWS\twain.dll
2004-08-05 12:00:00 50,688 --sh--w C:\WINDOWS\twain_32.dll
2004-08-05 12:00:00 65,024 --sha-w C:\WINDOWS\system32\asycfilt.dll
2004-08-05 12:00:00 1,028,096 --sha-w C:\WINDOWS\system32\mfc42.dll
2004-08-05 12:00:00 57,344 --sha-w C:\WINDOWS\system32\mfc42loc.dll
2004-08-05 12:00:00 54,784 --sh--w C:\WINDOWS\system32\msvcirt.dll
2004-08-05 12:00:00 413,696 --sha-w C:\WINDOWS\system32\msvcp60.dll
2004-08-05 12:00:00 343,040 --sha-w C:\WINDOWS\system32\msvcrt.dll
2004-08-05 12:00:00 253,952 --sha-w C:\WINDOWS\system32\msvcrt20.dll
2004-08-05 12:00:00 553,472 --sha-w C:\WINDOWS\system32\oleaut32.dll
2004-08-05 12:00:00 83,456 --sha-w C:\WINDOWS\system32\olepro32.dll
2004-08-05 12:00:00 12,288 --sh--w C:\WINDOWS\system32\regsvr32.exe
2004-08-05 12:00:00 30,749 --sha-w C:\WINDOWS\system32\vbajet32.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{53707962-6F74-2D53-2644-206D7942484F}=C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2005-05-31 01:04]
{64F56FC1-1272-44CD-BA6E-39723696E350}=C:\Program Files\eoRezo\EoAdv\EoRezoBHO.dll []
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll [2006-12-15 03:23]
{bedfb04c-92a3-4388-85d6-0a9a61f1f506}=C:\WINDOWS\system32\asybug.dll [2007-06-10 17:38]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EoEngine"="" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"BDMCon"="C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe" [2007-04-17 13:42]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-06-06 13:46]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-06-09 18:49]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-02-13 12:22]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00]
"WOOKIT"="C:\PROGRA~1\Wanadoo\Shell.exe" [2004-08-23 14:50]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\asybug]
asybug.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=c:\windows\system32\geebbyy.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
Contents of the 'Scheduled Tasks' folder
2007-06-04 07:17:08 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
**************************************************************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-06-10 17:37:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-06-10 17:40:51 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-06-10 17:40
--- E O F ---