voila ce qui ressort :
ComboFix 07-10-23.1 - rachou 2007-10-25 12:07:42.1 - NTFSx86
Microsoft Windows XP dition familiale 5.1.2600.2.1252.1.1036.18.293 [GMT 2:00]
Running from: C:\Documents and Settings\rachou\Mes documents\ComboFix.exe
* Created a new restore point
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\check_LSA7.txt
C:\Documents and Settings\Corann\Application Data\addon.dat
C:\Documents and Settings\Nolwenn\Application Data\addon.dat
C:\Documents and Settings\rachou\Application Data\addon.dat
C:\WINDOWS\cookies.ini
C:\WINDOWS\ktd32.atm
C:\WINDOWS\system32\__c0065A9A.dat
C:\WINDOWS\system32\__c006A589.dat
C:\WINDOWS\system32\__c00793E.dat
C:\WINDOWS\system32\__c008D8FD.dat
C:\WINDOWS\system32\__c00BEF49.dat
C:\WINDOWS\system32\absaoiwh.ini
C:\WINDOWS\system32\acykeimx.dll
C:\WINDOWS\system32\aonxglfn.dll
C:\WINDOWS\system32\awvvw.dll
C:\WINDOWS\system32\bpjxcrox.ini
C:\WINDOWS\system32\brwtjwwf.ini
C:\WINDOWS\system32\bsofenog.ini
C:\WINDOWS\system32\bxdqlftu.ini
C:\WINDOWS\system32\cbkplnhu.ini
C:\WINDOWS\system32\cjplrwgi.ini
C:\WINDOWS\system32\dcmvtjoj.ini
C:\WINDOWS\system32\dwxaydkq.ini
C:\WINDOWS\system32\eayeqjxk.ini
C:\WINDOWS\system32\emcrsfgf.dll
C:\WINDOWS\system32\ffmdjnol.ini
C:\WINDOWS\system32\fgfsrcme.ini
C:\WINDOWS\system32\fplevqrs.dll
C:\WINDOWS\system32\fwwjtwrb.dll
C:\WINDOWS\system32\gonefosb.dll
C:\WINDOWS\system32\gvawkxex.dll
C:\WINDOWS\system32\hwfajjkk.dll
C:\WINDOWS\system32\hwioasba.dll
C:\WINDOWS\system32\igwrlpjc.dll
C:\WINDOWS\system32\iidtemrm.dll
C:\WINDOWS\system32\ivmfcbxw.dll
C:\WINDOWS\system32\jcmbawfn.dll
C:\WINDOWS\system32\jherotmj.ini
C:\WINDOWS\system32\jmckijxl.ini
C:\WINDOWS\system32\jmtorehj.dll
C:\WINDOWS\system32\jojtvmcd.dll
C:\WINDOWS\system32\kdfifpjy.dll
C:\WINDOWS\system32\kdhiphnk.ini
C:\WINDOWS\system32\kkjjafwh.ini
C:\WINDOWS\system32\kmytxghw.dll
C:\WINDOWS\system32\knhpihdk.dll
C:\WINDOWS\system32\kxjqeyae.dll
C:\WINDOWS\system32\lonjdmff.dll
C:\WINDOWS\system32\lxjikcmj.dll
C:\WINDOWS\system32\mgubwqmn.dll
C:\WINDOWS\system32\nflgxnoa.ini
C:\WINDOWS\system32\nfwabmcj.ini
C:\WINDOWS\system32\nmqwbugm.ini
C:\WINDOWS\system32\nqwenvst.ini
C:\WINDOWS\system32\oexqmmlt.dll
C:\WINDOWS\system32\olkcrahy.dll
C:\WINDOWS\system32\oywhlrav.dll
C:\WINDOWS\system32\qkdyaxwd.dll
C:\WINDOWS\system32\renxdxsv.dll
C:\WINDOWS\system32\rxbquwkt.dll
C:\WINDOWS\system32\srqvelpf.ini
C:\WINDOWS\system32\thmaiocm.dll
C:\WINDOWS\system32\tkwuqbxr.ini
C:\WINDOWS\system32\tlmmqxeo.ini
C:\WINDOWS\system32\tsvnewqn.dll
C:\WINDOWS\system32\uhnlpkbc.dll
C:\WINDOWS\system32\upssbhyx.ini
C:\WINDOWS\system32\utflqdxb.dll
C:\WINDOWS\system32\vaqcctie.dll
C:\WINDOWS\system32\varlhwyo.ini
C:\WINDOWS\system32\vncitkxv.ini
C:\WINDOWS\system32\vsxdxner.ini
C:\WINDOWS\system32\vxkticnv.dll
C:\WINDOWS\system32\whgxtymk.ini
C:\WINDOWS\system32\wvvwa.bak1
C:\WINDOWS\system32\wvvwa.bak2
C:\WINDOWS\system32\wvvwa.ini
C:\WINDOWS\system32\wvvwa.ini2
C:\WINDOWS\system32\wvvwa.tmp
C:\WINDOWS\system32\wxbcfmvi.ini
C:\WINDOWS\system32\xexkwavg.ini
C:\WINDOWS\system32\xmiekyca.ini
C:\WINDOWS\system32\xorcxjpb.dll
C:\WINDOWS\system32\xyhbsspu.dll
C:\WINDOWS\system32\yharcklo.ini
C:\WINDOWS\system32\yjpfifdk.ini
D:\Autorun.inf
.
((((((((((((((((((((((((((((( Fichiers créés 2007-09-25 to 2007-10-25 ))))))))))))))))))))))))))))))))))))
.
2007-10-25 12:05 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-25 11:57 84,544 --a------ C:\WINDOWS\system32\ljcqjnte.dll
2007-10-25 11:54 10,816 --a------ C:\WINDOWS\system32\osgqbuvi.dll
2007-10-25 11:54 10,816 --a------ C:\WINDOWS\system32\nmykvoxr.dll
2007-10-25 11:49 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2007-10-25 11:48 <REP> d-------- C:\VundoFix Backups
2007-10-25 11:39 <REP> d-------- C:\Program Files\Trend Micro
2007-10-25 11:30 10,816 --a------ C:\WINDOWS\system32\iweoyvam.dll
2007-10-25 11:27 10,816 --a------ C:\WINDOWS\system32\dnalipem.dll
2007-10-25 08:27 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2007-10-25 08:04 <REP> d-------- C:\Program Files\Navilog1
2007-10-25 07:26 10,816 --a------ C:\WINDOWS\system32\qnhlhage.dll
2007-10-25 07:23 10,816 --a------ C:\WINDOWS\system32\jgogyafq.dll
2007-10-25 07:22 10,816 --a------ C:\WINDOWS\system32\wpkgqmgl.dll
2007-10-25 07:22 10,816 --a------ C:\WINDOWS\system32\uwfpxxft.dll
2007-10-25 07:22 10,816 C:\Documents and Settings\Invité\Application Data\__c00F74C.dat
2007-10-24 21:18 <REP> C:\Documents and Settings\Invité\Application Data\Micro Application
2007-10-24 21:17 <REP> C:\Documents and Settings\Invité\Application Data\DivX
2007-10-24 21:15 84,544 --a------ C:\WINDOWS\system32\yfsrwnsc.dll
2007-10-24 20:59 <REP> d-------- C:\Program Files\QuickTime
2007-10-24 20:26 84,544 --a------ C:\WINDOWS\system32\bxiktube.dll
2007-10-24 20:24 84,544 --a------ C:\WINDOWS\system32\bqakosko.dll
2007-10-24 15:47 84,544 --a------ C:\WINDOWS\system32\nfnbomkh.dll
2007-10-24 14:01 84,544 --a------ C:\WINDOWS\system32\dcfnqotl.dll
2007-10-24 13:49 84,544 --------- C:\WINDOWS\system32\dtagknia.dll
2007-10-24 12:22 84,544 --a------ C:\WINDOWS\system32\gigqjeju.dll
2007-10-24 07:09 84,544 --a------ C:\WINDOWS\system32\jvfwsyfn.dll
2007-10-24 07:00 19,520 --a------ C:\WINDOWS\system32\ifyqpifl.dll
2007-10-24 06:58 19,520 --a------ C:\WINDOWS\system32\snkinfyc.dll
2007-10-24 06:57 19,520 --a------ C:\WINDOWS\system32\kbndqnak.dll
2007-10-23 20:33 84,544 --a------ C:\WINDOWS\system32\edbektyo.dll
2007-10-17 13:49 <REP> d-------- C:\Documents and Settings\Corann\Application Data\MailFrontier
2007-10-14 19:57 <REP> d-------- C:\Documents and Settings\Nolwenn\Application Data\MailFrontier
2007-10-14 18:23 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2007-10-14 18:21 <REP> d-------- C:\WINDOWS\Internet Logs
2007-10-13 07:51 <REP> d-------- C:\Program Files\Windows Live Favorites
2007-10-12 21:41 84,032 --a------ C:\WINDOWS\system32\gkvcssvh.dll
2007-10-10 15:49 582,656 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-10-09 16:18 82,496 --a------ C:\WINDOWS\system32\jyncculd.dll
2007-10-06 18:25 85,056 --a------ C:\WINDOWS\system32\uglimfcw.dll
2007-10-02 07:46 85,056 --a------ C:\WINDOWS\system32\kdlintcr.dll
2007-10-02 07:40 85,056 --a------ C:\WINDOWS\system32\vrehslur.dll
2007-10-02 07:25 85,056 --a------ C:\WINDOWS\system32\lfvwxfpo.dll
2007-10-01 18:51 87,104 --a------ C:\WINDOWS\system32\hmqqllls.dll
2007-09-30 15:14 <REP> d-------- C:\Documents and Settings\Nolwenn\Application Data\Creative
2007-09-27 16:31 <REP> d-------- C:\Documents and Settings\rachou\Application Data\InstallShield Installation Information
2007-09-27 16:31 <REP> d-------- C:\Documents and Settings\rachou\Application Data\InstallShield
2007-09-27 07:05 <REP> d-------- C:\Documents and Settings\rachou\Application Data\MSNInstaller
2007-09-26 12:16 <REP> d-------- C:\Program Files\Windows Desktop Search
2007-09-26 12:16 <REP> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-25 10:17 --------- d-----w C:\Program Files\Wanadoo
2007-10-25 09:53 --------- d-----w C:\Program Files\eMule
2007-10-25 06:28 --------- d-----w C:\Program Files\Lavasoft
2007-10-25 05:22 1,310,720 ---ha-w C:\Documents and Settings\Invité\ntuser.dat
2007-10-24 19:16 --------- d-s---w C:\Documents and Settings\Invité\Application Data\Microsoft
2007-10-24 19:06 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-24 19:06 --------- d-----w C:\Program Files\Micro Application
2007-10-24 11:45 --------- d-----w C:\Program Files\Picasa2
2007-10-18 17:28 --------- d-----w C:\Program Files\vso
2007-10-18 05:15 --------- d-----w C:\Program Files\MumboJumbo
2007-10-18 05:15 --------- d-----w C:\Program Files\Creative
2007-10-13 05:51 --------- d-----w C:\Program Files\Windows Live Toolbar
2007-10-06 09:54 --------- d-----w C:\Documents and Settings\rachou\Application Data\Creative
2007-10-03 09:30 --------- d-----w C:\Program Files\BoontyGames
2007-09-27 14:31 --------- d-----w C:\Documents and Settings\rachou\Application Data\Knight Online
2007-09-27 05:03 --------- d-----w C:\Program Files\Windows Live
2007-09-14 06:10 --------- d-----w C:\Program Files\SLD Codec Pack
2007-09-12 18:37 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2007-09-12 05:31 --------- d-----w C:\Documents and Settings\rachou\Application Data\AdobeUM
2007-09-10 12:08 --------- d-----w C:\Program Files\Dealio
2007-09-08 17:19 --------- d-----w C:\Program Files\LGGSM
2007-09-08 17:19 --------- d-----w C:\Program Files\LG Electronics
2007-09-06 10:05 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-09-06 10:05 92,848 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-09-06 10:03 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-09-06 10:02 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-09-06 10:00 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-09-04 10:54 --------- d-----w C:\Documents and Settings\rachou\Application Data\Template
2007-09-04 10:52 0 ----a-w C:\Documents and Settings\rachou\Application Data\wklnhst.dat
2007-08-31 19:15 --------- d-----w C:\Documents and Settings\rachou\Application Data\CyberLink
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CHotkey"="zHotkey.exe" []
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 13:22]
"WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 15:49]
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 17:55]
"NvMediaCenter"="NvMCTray.dll" [2006-10-22 13:22 C:\WINDOWS\system32\nvmctray.dll]
"EoEngine"="" []
"EoWeather"="" []
"EoClock"="" []
"EoComputer"="" []
"EoRss"="" []
"EoNet"="" []
"EoSudoku"="" []
"EoPhoto"="" []
"MSKDetectorExe"="C:\Program Files\McAfee\SpamKiller\MSKDetct.exe" [2006-11-07 15:49]
"AVFX Engine"="C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exe" [2006-10-19 19:44]
"V0220Mon.exe"="C:\WINDOWS\V0220Mon.exe" [2006-06-29 01:01]
"SoundMan"="SOUNDMAN.EXE" [2005-09-26 15:07 C:\WINDOWS\soundman.exe]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 03:01]
"Reminder"="%WINDIR%\Creator\Remind_XP.exe" []
"Recguard"="%WINDIR%\SMINST\RECGUARD.EXE" []
"readericon"="C:\Program Files\Digital Media Reader\readericon45G.exe" [2005-12-09 18:44]
"nwiz"="nwiz.exe" [2006-10-22 13:22 C:\WINDOWS\system32\nwiz.exe]
"NeroFilterCheck"="C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe" []
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 12:06]
"au"="C:\Program Files\Dealio\DealioAU.exe" [2007-06-27 12:46]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 09:41]
"ecc4edf0"="C:\WINDOWS\system32\ljcqjnte.dll" [2007-10-25 11:57]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"{9B71D88C-C598-4935-C5D1-43AA4DB90836}"="C:\WINDOWS\system32\drivers\winsock.exe" []
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 21:00]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-08-16 16:19]
"Power2GoExpress"="C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" [2006-01-11 18:17]
"eMuleAutoStart"="C:\Program Files\eMule\eMule.exe" [2007-05-13 16:57]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Power2GoExpress"=NA
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" /background
"Picasa Media Detector"=C:\Program Files\Picasa2\PicasaMediaDetector.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebbyxw]
gebbyxw.dll
R2 OPTENET_FILTER;Control Parental;C:\Program Files\Controle Parental\bin\optproxy.exe
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\WINDOWS\system32\DRIVERS\bdfndisf.sys
R3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
R3 V0220Dev;Live! Cam Video IM;C:\WINDOWS\system32\DRIVERS\V0220Dev.sys
R3 V0220Vfx;V0220VFX;C:\WINDOWS\system32\DRIVERS\V0220Vfx.sys
S1 bdftdif;bdftdif;\??\C:\Program Files\Fichiers communs\Softwin\BitDefender Firewall\bdftdif.sys
S3 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe"
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2007-10-18 10:59:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
"2007-05-03 16:35:34 C:\WINDOWS\Tasks\MP Scheduled Quick Scan.job"
- C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MpCmdRun.exe
"2007-10-25 10:12:02 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
.
**************************************************************************
catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-10-25 12:16:47
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-25 12:19:52 - machine was rebooted
.
--- E O F ---