Voilà le rapport (quel "charabia", tu t'y retrouves?)
ComboFix 07-06-09.5 - C:\Documents and Settings\noel\Bureau\ComboFix.exe
"noel" - 2007-06-10 19:32:07 - Service Pack 2 NTFS
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\noel\Bureau\internet.lnk
C:\U.exe
C:\WINDOWS\system32\2_exception.nls
C:\WINDOWS\system32\drivers\ip6fw.sys
C:\WINDOWS\system32\drivers\runtime2.sys
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
-------\LEGACY_RUNTIME
-------\LEGACY_RUNTIME2
-------\runtime
((((((((((((((((((((((((( Files Created from 2007-05-10 to 2007-06-10 )))))))))))))))))))))))))))))))
2007-06-10 19:31 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-10 16:15 <REP> d-------- C:\Program Files\CCleaner
2007-06-10 15:35 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-06-10 15:34 <REP> d-------- C:\Program Files\AVG Anti-Spyware 7.5
2007-06-10 09:43 <REP> d-------- C:\Program Files\Hijackthis Version Fran‡aise
2007-06-10 09:38 <REP> d-------- C:\Hijackthis
2007-06-10 09:01 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-06-10 09:00 <REP> d-------- C:\Program Files\Navilog1
2007-06-09 22:41 <REP> d-------- C:\DOCUME~1\noel\APPLIC~1\Uniblue
2007-06-09 21:07 <REP> d-------- C:\DOCUME~1\noel\.housecall6.6
2007-06-09 21:02 <REP> d-------- C:\WINDOWS\avxoscan
2007-06-09 10:23 <REP> d-------- C:\Program Files\RegCleaner
2007-06-06 22:34 719,872 --a------ C:\WINDOWS\system32\devil.dll
2007-06-06 22:34 70,656 --a------ C:\WINDOWS\system32\i420vfw.dll
2007-06-06 22:34 66,560 --a------ C:\WINDOWS\MOTA113.exe
2007-06-06 22:34 502,784 --a------ C:\WINDOWS\x2.64.exe
2007-06-06 22:34 471,552 --a------ C:\WINDOWS\system32\Smab.dll
2007-06-06 22:34 306,688 --a------ C:\WINDOWS\system32\avisynth.dll
2007-06-06 22:34 27,648 --a------ C:\WINDOWS\system32\AVSredirect.dll
2007-06-06 22:34 240,128 --a------ C:\WINDOWS\system32\x.264.exe
2007-06-06 22:34 217,073 --a------ C:\WINDOWS\meta4.exe
2007-06-06 22:34 <REP> d-------- C:\Program Files\AviSynth 2.5
2007-06-06 20:59 31,744 -r-hs---- C:\WINDOWS\system32\msfDX.dll
2007-06-06 20:59 163,328 -r-hs---- C:\WINDOWS\system32\flvDX.dll
2007-06-06 20:56 <REP> d-------- C:\Program Files\eRightSoft
2007-06-06 20:43 <REP> d--h----- C:\WINDOWS\PIF
2007-06-01 18:48 22,315 --a------ C:\DOCUME~1\noel\APPLIC~1\mdb.bin
2007-06-01 18:21 <REP> d-------- C:\Program Files\Fastlab Print Service
2007-05-30 19:31 <REP> d-------- C:\Program Files\DVD Decrypter
2007-05-30 19:09 86,016 --a------ C:\WINDOWS\unvise32qt.exe
2007-05-30 19:08 <REP> d-------- C:\WINDOWS\system32\QuickTime
2007-05-30 19:08 <REP> d-------- C:\Program Files\QuickTime
2007-05-30 19:07 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\QuickTime
2007-05-30 19:05 96,256 --------- C:\WINDOWS\system32\SMACKW32.DLL
2007-05-30 19:05 929,844 --------- C:\WINDOWS\system32\MFC42D.DLL
2007-05-30 19:05 798,773 --------- C:\WINDOWS\system32\MFCO42D.DLL
2007-05-30 19:05 77,824 --------- C:\WINDOWS\system32\asr32312.dll
2007-05-30 19:05 41,013 --------- C:\WINDOWS\system32\MFCN42D.DLL
2007-05-30 19:05 401,484 --------- C:\WINDOWS\system32\MSVCRTD.DLL
2007-05-30 19:05 <REP> d-------- C:\WINDOWS\LHSP
2007-05-30 19:05 <REP> d-------- C:\Program Files\Mindscape
2007-05-25 20:57 <REP> d-------- C:\Program Files\NetTransport 2
2007-05-25 20:03 <REP> d-------- C:\Program Files\Fichiers communs\xing shared
2007-05-25 20:02 <REP> d-------- C:\Program Files\Real
2007-05-25 20:02 <REP> d-------- C:\Program Files\Fichiers communs\Real
2007-05-25 20:00 <REP> d-------- C:\DOCUME~1\noel\APPLIC~1\Real
2007-05-22 19:16 <REP> d-------- C:\Program Files\Replay Music
2007-05-20 21:40 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2007-05-20 21:40 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2007-05-18 10:13 737,280 --a------ C:\WINDOWS\iun6002.exe
2007-05-18 10:13 41,984 --a------ C:\WINDOWS\system32\APTRRNTm.dll
2007-05-18 10:13 36,864 --a------ C:\WINDOWS\system32\APTRRNTl.dll
2007-05-18 10:13 <REP> d-------- C:\Program Files\Replay Music 2
2007-05-13 16:50 <REP> d-------- C:\DOCUME~1\noel\APPLIC~1\MAGIX
2007-05-13 16:49 <REP> d-------- C:\DOCUME~1\noel\APPLIC~1\Help
2007-05-12 23:07 <REP> d-------- C:\Program Files\Google
2007-05-12 23:07 <REP> d-------- C:\DOCUME~1\noel\APPLIC~1\Google
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-06-10 14:20:17 -------- d-----w C:\Program Files\Hijackthis Version Française
2007-06-09 14:19:49 -------- d-----w C:\Program Files\eMule
2007-06-09 13:54:26 -------- d-----w C:\Program Files\Heredis 9
2007-05-30 17:05:11 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-05-28 15:36:36 -------- d-----w C:\Program Files\Winamp
2007-05-25 17:02:34 1,080 ----a-w C:\WINDOWS\AUTOLNCH.REG
2007-05-20 06:42:10 1,416 ----a-w C:\WINDOWS\mozver.dat
2007-05-08 14:47:50 -------- d-----w C:\Program Files\BitComet
2007-05-07 15:18:00 -------- d-----w C:\Program Files\Mon Livre Photo by CeWe
2007-05-07 13:54:13 -------- d-----w C:\Program Files\Canon
2007-05-07 13:00:49 30,880 ----a-w C:\DOCUME~1\noel\APPLIC~1\GDIPFONTCACHEV1.DAT
2007-05-06 20:25:24 -------- d-----w C:\Program Files\Luxor
2007-05-06 20:03:52 -------- d-----w C:\DOCUME~1\noel\APPLIC~1\DivX
2007-05-06 09:03:36 -------- d-----w C:\Program Files\Luxor2
2007-05-06 08:29:57 -------- d-----w C:\Program Files\ASUS
2007-05-06 08:20:34 -------- d-----w C:\Program Files\MSXML 4.0
2007-05-06 08:18:18 83,286 ----a-w C:\WINDOWS\system32\perfc00C.dat
2007-05-06 08:18:18 504,910 ----a-w C:\WINDOWS\system32\perfh00C.dat
2007-05-05 16:03:19 -------- d-----w C:\Program Files\ReflexiveArcade
2007-05-05 15:58:12 -------- d-----w C:\Program Files\DivX
2007-05-05 15:58:02 -------- d-----w C:\Program Files\Mozilla Thunderbird
2007-05-05 13:08:41 -------- d-----w C:\Program Files\CDex_170b2
2007-05-05 10:41:53 -------- d-----w C:\Program Files\novaPDF Professional Desktop 5
2007-05-05 10:18:26 -------- d-----w C:\Program Files\doPDF 5
2007-05-05 09:48:45 -------- d-----w C:\Program Files\MSN Toolbar Suite
2007-05-05 09:22:24 -------- d-----w C:\Program Files\Movie Maker
2007-05-04 19:52:15 -------- d-----w C:\Program Files\BSD Concept
2007-05-04 19:18:20 -------- d-----w C:\Program Files\Fichiers communs\MAGIX Shared
2007-05-04 16:44:54 -------- d-----w C:\DOCUME~1\noel\APPLIC~1\Media Player Classic
2007-05-02 18:04:23 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
2007-05-02 18:04:19 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2007-05-02 18:04:15 2,560 ------w C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-05-02 18:04:15 2,432 ------w C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-05-02 18:04:14 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
2007-05-02 18:04:14 116,472 ------w C:\WINDOWS\system32\pxcpyi64.exe
2007-05-02 18:04:06 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
2007-05-02 18:04:05 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
2007-05-02 18:02:06 73,728 ----a-w C:\WINDOWS\system32\dpl100.dll
2007-05-02 18:02:06 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
2007-05-02 18:02:04 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-05-02 18:02:02 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-05-02 18:02:02 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
2007-05-02 18:02:02 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
2007-05-02 18:02:02 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
2007-05-02 18:02:02 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
2007-05-02 18:01:56 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-05-02 18:01:56 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
2007-05-02 18:01:56 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
2007-05-02 18:01:56 740,442 ----a-w C:\WINDOWS\system32\DivX.dll
2007-05-02 02:33:57 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
2007-05-02 02:33:56 124,472 ----a-w C:\WINDOWS\system32\DivXCodecUpdateChecker.exe
2007-04-27 08:47:40 21,656 ----a-w C:\WINDOWS\system32\novamnp5.dll
2007-04-27 08:47:38 18,072 ----a-w C:\WINDOWS\system32\novamip5.dll
2007-04-25 15:37:26 -------- d-----w C:\Program Files\HardwareDetection
2007-04-24 17:56:30 -------- d-----w C:\Program Files\GameHouse
2007-04-23 17:50:24 -------- d-----w C:\Program Files\Hewlett-Packard
2007-04-22 10:05:04 -------- d-----w C:\Program Files\Microsoft Money
2007-04-22 07:23:57 -------- d-----w C:\DOCUME~1\noel\APPLIC~1\Ahead
2007-04-22 07:21:56 -------- d-----w C:\Program Files\Fichiers communs\Ahead
2007-04-22 07:21:55 -------- d-----w C:\Program Files\Nero
2007-04-22 06:19:30 -------- d-----w C:\DOCUME~1\noel\APPLIC~1\BSDh9
2007-04-21 21:18:58 -------- d-----w C:\Program Files\7-Zip
2007-04-21 19:39:17 2,560 ----a-w C:\WINDOWS\system32\BitCometRes.dll
2007-04-21 17:12:50 -------- d-----w C:\Program Files\Realtek
2007-04-21 17:00:47 -------- d-----w C:\Program Files\Jasc Software Inc
2007-04-21 17:00:23 -------- d-----w C:\Program Files\Fichiers communs\InstallShield
2007-04-21 16:46:20 -------- d-----w C:\Program Files\K-Lite Codec Pack
2007-04-21 16:15:01 -------- d-----w C:\DOCUME~1\noel\APPLIC~1\Thunderbird
2007-04-21 16:11:59 0 ----a-w C:\WINDOWS\nsreg.dat
2007-04-21 15:25:08 -------- d-----w C:\Program Files\MSBuild
2007-04-21 15:21:27 -------- d-----w C:\Program Files\Reference Assemblies
2007-04-21 15:19:47 -------- d-----w C:\Program Files\Windows Media Connect 2
2007-04-21 15:17:49 -------- d-----w C:\Program Files\CONEXANT
2007-04-21 14:31:06 -------- d-----w C:\Program Files\Messenger
2007-04-21 13:58:08 502,208 ----a-w C:\WINDOWS\system32\drivers\amon.sys
2007-04-21 13:58:08 270,336 ----a-w C:\WINDOWS\system32\imon.dll
2007-04-19 17:37:50 -------- d-----w C:\Program Files\Fichiers communs\ODBC
2007-04-19 17:37:47 -------- d-----w C:\Program Files\Fichiers communs\SpeechEngines
2007-04-19 16:04:24 -------- d-----w C:\Program Files\S3
2007-04-19 16:00:43 -------- d-----w C:\Program Files\VIA
2007-04-19 16:00:16 -------- d-----w C:\Program Files\AMD
2007-04-19 15:54:17 -------- d-----w C:\Program Files\microsoft frontpage
2007-04-19 15:53:55 0 --sha-r C:\MSDOS.SYS
2007-04-19 15:53:55 0 --sha-r C:\IO.SYS
2007-04-19 15:53:55 0 ----a-w C:\CONFIG.SYS
2007-04-19 15:53:55 0 ----a-w C:\AUTOEXEC.BAT
2007-04-19 15:52:31 -------- d--h--w C:\Program Files\WindowsUpdate
2007-04-19 15:52:27 -------- d-----w C:\Program Files\Services en ligne
2007-04-19 15:51:38 -------- d-----w C:\Program Files\Fichiers communs\MSSoap
2007-04-19 15:50:58 21,892 ----a-w C:\WINDOWS\system32\emptyregdb.dat
2007-04-19 15:50:14 -------- d-----w C:\Program Files\Online Services
2007-04-19 15:50:06 -------- d-----w C:\Program Files\MSN Gaming Zone
2007-04-19 15:49:58 -------- d-----w C:\Program Files\Windows NT
2007-04-18 16:14:18 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-18 09:47:20 21,656 ----a-w C:\WINDOWS\system32\dopdfmn5.dll
2007-04-18 09:47:20 17,048 ----a-w C:\WINDOWS\system32\dopdfmi5.dll
2007-03-23 04:07:56 1,683,280 ------w C:\WINDOWS\system32\XpsSvcs.dll
2007-03-23 04:07:54 583,504 ------w C:\WINDOWS\system32\XPSSHHDR.dll
2007-03-22 18:25:02 124,928 ------w C:\WINDOWS\system32\prntvpt.dll
2007-03-17 13:44:47 293,376 ----a-w C:\WINDOWS\system32\winsrv.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}=C:\Program Files\BitComet\tools\BitCometBHO_1.1.3.28.dll [2007-03-29 16:31]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}=C:\Program Files\MSN Toolbar Suite\TB\02.05.0000.1105\fr-fr\msntb.dll [2005-07-07 16:21]
{C56CB6B0-0D96-11D6-8C65-B2868B609932}=C:\Program Files\NetTransport 2\NTIEHelper.dll [2005-09-08 20:48]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2005-03-08 05:33 C:\WINDOWS\system32\VTTimer.exe]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2007-04-21 15:58]
"S3Trayp"="S3trayp.exe" [2005-04-05 07:49 C:\WINDOWS\system32\S3Trayp.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"!AVG Anti-Spyware"="C:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" [2007-05-30 14:30]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 14:00]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 14:29]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWEReboot]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
SkyTel.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
**************************************************************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-06-10 19:37:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-06-10 19:39:18 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-06-10 19:39
--- E O F ---
********** j'ai également çà (combofix quarantined files:
[code]
2006-03-02 14:00 29056 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\ip6fw.sys.vir
2007-04-21 17:47 803 --a------ C:\Qoobox\Quarantine\C\DOCUME~1\noel\Bureau\Internet.lnk.vir
2007-06-06 17:37 19968 --a------ C:\Qoobox\Quarantine\C\U.exe.vir
2007-06-06 17:38 0 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\2_exception.nls.vir
2007-06-10 18:39 33408 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\runtime2.sys.vir
2007-06-10 19:33 1262 --a------ C:\Qoobox\Quarantine\Registry_backups\LEGACY_RUNTIME.reg.cf
2007-06-10 19:33 1276 --a------ C:\Qoobox\Quarantine\Registry_backups\LEGACY_RUNTIME2.reg.cf
2007-06-10 19:33 750 --a------ C:\Qoobox\Quarantine\Registry_backups\services_runtime.reg.cf
Structure du dossier
Le num‚ro de s‚rie du volume est 304B-F6AD
C:\QOOBOX
\---Quarantine
+---C
| | U.exe.vir
| |
| +---avenger
| +---DOCUME~1
| | \---noel
| | \---Bureau
| | Internet.lnk.vir
| |
| \---WINDOWS
| \---system32
| | 2_exception.nls.vir
| |
| \---drivers
| ip6fw.sys.vir
| runtime2.sys.vir
|
\---Registry_backups
LEGACY_RUNTIME.reg.cf
LEGACY_RUNTIME2.reg.cf
services_runtime.reg.cf
[/code]