Re,
Dans résultats voici ce que j'ai.
File/Folder C:\Program Files\DefenseNetSurfage\updater.exe not found.
File/Folder C:\Program Files\DefenseNetSurfage not found.
File/Folder C:\Documents and Settings\All Users\DRM\DRMv1.bak C:\Documents and Settings\xx\Mes documents\~WRL0001.tmp C:\Documents and Settings\xx\Mes documents\~WRL0003.tmp C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp C:\WINDOWS\SoftwareDistribution\Download\778fd2fc3fe6b905e366b5ddbba384c8\BIT3.tmp not found.
File/Folder C:\Documents and Settings\xx\Mes documents\Ma musique\Sauvegarde de la licence\drmv1lic.bak not found.
Created on 10/15/2007 15:04:45
Puis le message
---------------------------
OTMoveIt
---------------------------
Cannot create file C:\_OTMoveIt\MovedFiles\10152007_150445.log.
---------------------------
OK
---------------------------
---------------------------
ComboFix 07-10-14.5 - xx 2007-10-15 15:17:51.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.305 [GMT 0:00]
Running from: C:\Documents and Settings\xx\Bureau\ComboFix.exe
* Created a new restore point
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\.protected
C:\Documents and Settings\xx\ResErrors.log
C:\WINDOWS\system32\drivers\etc\.protected
.
((((((((((((((((((((((((((((( Fichiers créés 2007-09-15 to 2007-10-15 ))))))))))))))))))))))))))))))))))))
.
2007-10-15 15:15 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-15 10:55 <REP> d-------- C:\WINDOWS\ERUNT
2007-10-14 20:39 <REP> d-------- C:\WINDOWS\BDOSCAN8
2007-10-11 23:11 <REP> d-------- C:\Documents and Settings\xx\Application Data\Grisoft
2007-10-11 23:10 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-11 23:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-10-10 23:03 2,760 --a------ C:\WINDOWS\system32\tmp.reg
2007-10-10 23:01 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2007-10-10 23:01 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-10-10 23:01 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-10-10 23:01 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-10-10 23:01 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2007-10-06 13:12 <REP> d-------- C:\Program Files\Kaspersky Lab
2007-10-06 13:12 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-10-06 13:12 3,268,640 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-10-06 13:12 67,360 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-10-06 03:00 <REP> d-------- C:\KAV
2007-10-06 02:09 <REP> d-------- C:\Program Files\Alwil Software
2007-10-03 21:00 <REP> d--hs---- C:\UGA6PV
2007-10-03 20:58 <REP> d-------- C:\Documents and Settings\xx\Application Data\ProtectionConue
2007-10-03 20:55 <REP> d-------- C:\Program Files\ProtectionConue
2007-10-03 20:55 <REP> d-------- C:\Documents and Settings\xx\Application Data\DefenseNetSurfage
2007-10-03 20:55 24,064 --a------ C:\WINDOWS\system32\msxml3a.dll
2007-10-01 21:44 <REP> d-------- C:\Program Files\Yahoo!
2007-10-01 21:44 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-09-17 20:21 <REP> d-------- C:\Program Files\Ahead
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-15 14:58 8,216 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2007-10-15 14:58 46,556 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2007-10-15 14:38 --------- d-----w C:\Program Files\eMule
2007-10-15 11:45 --------- d-----w C:\Program Files\Java
2007-10-06 13:06 --------- d-----w C:\Program Files\AskTBar
2007-10-06 13:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com
2007-10-04 22:10 --------- d-----w C:\Documents and Settings\xx\Application Data\Skype
2007-09-17 20:19 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2007-09-03 11:52 127,034 ------r C:\WINDOWS\bwUnin-8.1.1.50-8876480SL.exe
2007-08-21 06:17 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-07-30 17:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-07-30 17:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-07-30 17:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-30 17:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-07-30 17:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-07-30 17:19 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll
2007-07-30 17:19 207,736 ----a-w C:\WINDOWS\system32\muweb.dll
2007-07-30 17:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-07-30 17:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-30 17:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2004-02-25 14:15]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2004-02-25 15:15]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2004-02-25 15:06]
"DXDllRegExe"="dxdllreg.exe" []
"HPpromo psc 1300 series"="C:\Program Files\HP\Digital Imaging\Promotions\HPpromo.exe" [2003-10-09 10:17]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 07:41]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 01:06]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-28 07:14]
"NeroCheck"="C:\WINDOWS\system32\\NeroCheck.exe" [2001-07-09 10:50]
"kav"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" [2006-03-24 19:09]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 09:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 16:09]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 10:55]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" []
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" []
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-06-08 13:18]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"EnforceShellExtensionSecurity"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4bfc85c1-4bfc-11dc-a8b5-4d6564696130}]
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL copy.exe
*Newly Created Service* - CATCHME
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2007-08-16 07:20:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-10-15 15:10:00 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-10-15 15:20:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-15 15:21:27
.
--- E O F ---