Alor je vien de faire un scan avec combofix je vous place le rapor aussi :)
((((((((((((((((((((((((((((( Fichiers créés 2007-11-28 to 2007-12-28 ))))))))))))))))))))))))))))))))))))
.
2007-12-28 13:46 . 2007-12-28 13:46 <REP> d-------- C:\Documents and Settings\Frank\Application Data\Uniblue
2007-12-28 13:45 . 2007-12-28 13:45 <REP> d-------- C:\Program Files\Uniblue
2007-12-28 04:19 . 2007-12-28 04:19 <REP> d-------- C:\WINDOWS\report
2007-12-28 04:19 . 2007-12-28 04:19 <REP> d-------- C:\WINDOWS\AU_Temp
2007-12-28 04:19 . 2007-12-28 04:18 40,300,441 --a------ C:\WINDOWS\LPT$VPN.913
2007-12-28 04:18 . 2007-12-28 04:19 <REP> d-------- C:\WINDOWS\AU_Backup
2007-12-28 04:18 . 2007-12-28 04:18 40,300,441 --a------ C:\WINDOWS\VPTNFILE.913
2007-12-28 04:18 . 2007-12-28 04:18 1,906,226 --a------ C:\WINDOWS\tsc.ptn
2007-12-28 04:18 . 2007-12-28 04:19 1,163,344 --a------ C:\WINDOWS\vsapi32.dll
2007-12-28 04:18 . 2007-12-28 04:18 267,845 --a------ C:\WINDOWS\tsc.exe
2007-12-28 04:18 . 2007-12-28 04:19 86,094 --a------ C:\WINDOWS\BPMNT.dll
2007-12-28 04:18 . 2007-12-28 04:18 71,749 --a------ C:\WINDOWS\hcextoutput.dll
2007-12-28 04:18 . 2007-12-28 04:24 823 --a------ C:\WINDOWS\tsc.ini
2007-12-28 04:17 . 2007-12-28 04:17 <REP> d-------- C:\WINDOWS\AU_Log
2007-12-28 04:17 . 2007-12-28 04:17 507,904 --a------ C:\WINDOWS\TMUPDATE.DLL
2007-12-28 04:17 . 2007-12-28 04:17 286,720 --a------ C:\WINDOWS\PATCH.EXE
2007-12-28 04:17 . 2007-12-28 04:17 69,689 --a------ C:\WINDOWS\UNZIP.DLL
2007-12-28 04:17 . 2007-12-28 04:19 170 --a------ C:\WINDOWS\GetServer.ini
2007-12-28 03:36 . 2007-10-11 00:49 6,065,664 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2007-12-28 03:36 . 2007-07-01 04:31 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-12-28 03:36 . 2007-07-01 04:36 1,048,576 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2007-12-28 03:36 . 2007-10-11 00:49 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-12-28 03:36 . 2007-10-11 00:49 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-12-28 03:36 . 2007-10-11 00:49 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2007-12-28 03:36 . 2007-10-11 00:49 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2007-12-28 03:36 . 2007-10-11 00:49 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-12-28 03:36 . 2007-10-10 11:59 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-12-28 03:30 . 2007-12-28 03:30 <REP> d-------- C:\Program Files\MSXML 6.0
2007-12-28 03:30 . 2007-12-28 03:34 <REP> d-------- C:\4bb1e4801c84e181fc273a4c
2007-12-28 03:21 . 2007-10-29 23:43 1,293,824 -----c--- C:\WINDOWS\system32\dllcache\quartz.dll
2007-12-28 03:21 . 2007-08-21 07:17 683,520 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2007-12-28 03:21 . 2007-03-17 14:44 293,376 -----c--- C:\WINDOWS\system32\dllcache\winsrv.dll
2007-12-28 03:21 . 2006-10-12 12:09 256,512 -----c--- C:\WINDOWS\system32\dllcache\agentsvr.exe
2007-12-28 03:21 . 2007-03-09 14:48 57,344 --a--c--- C:\WINDOWS\system32\dllcache\agentdpv.dll
2007-12-28 03:21 . 2006-10-12 15:04 42,496 -----c--- C:\WINDOWS\system32\dllcache\agentdp2.dll
2007-12-28 03:20 . 2007-07-09 14:11 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-12-28 02:38 . 2007-12-28 02:39 <REP> d-------- C:\Documents and Settings\Frank\Contacts
2007-12-28 02:37 . 2007-12-28 02:37 <REP> d-------- C:\Program Files\MSN Messenger
2007-12-28 02:28 . 2007-12-28 04:07 <REP> d-------- C:\Program Files\a-squared Anti-Malware
2007-12-28 00:47 . 2007-12-28 05:42 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2007-12-28 00:35 . 2007-12-28 00:35 <REP> d-------- C:\Documents and Settings\Frank\Application Data\Lavasoft
2007-12-27 23:54 . 2007-12-27 23:57 <REP> d-------- C:\WINDOWS\nview
2007-12-27 23:54 . 2006-02-09 15:04 180,224 --a------ C:\WINDOWS\system32\NVUNINST.EXE
2007-12-27 23:54 . 2006-02-08 23:06 180,224 --a------ C:\WINDOWS\system32\nvudisp.exe
2007-12-27 23:54 . 2007-12-28 17:56 45,378 --a------ C:\WINDOWS\system32\nvapps.xml
2007-12-27 23:54 . 2006-02-08 23:06 16,683 --a------ C:\WINDOWS\system32\nvdisp.nvu
2007-12-27 23:52 . 2007-12-27 23:52 <REP> d-------- C:\Documents and Settings\Frank\Application Data\Infineon
2007-12-27 23:52 . 2007-12-27 23:52 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Infineon
2007-12-27 23:52 . 2005-10-21 04:19 36,352 -ra------ C:\WINDOWS\system32\drivers\ifxtpm.sys
2007-12-27 23:51 . 2007-12-27 23:51 <REP> d-------- C:\Program Files\Infineon
2007-12-27 23:50 . 2007-12-27 23:50 <REP> d-------- C:\Program Files\Elantech
2007-12-27 23:50 . 2006-03-17 03:03 27,904 -ra------ C:\WINDOWS\system32\drivers\Ktp.sys
2007-12-27 23:42 . 2007-12-27 23:42 <REP> d-------- C:\Program Files\Realtek
2007-12-27 23:42 . 2007-12-27 23:42 <REP> d--h----- C:\Program Files\InstallShield Installation Information
2007-12-27 23:42 . 2006-04-06 06:23 81,664 -ra------ C:\WINDOWS\system32\drivers\Rtenicxp.sys
2007-12-27 23:33 . 2007-12-27 23:51 <REP> d-------- C:\Program Files\Fichiers communs\InstallShield
2007-12-27 22:30 . 2007-12-27 22:30 <REP> d-------- C:\Documents and Settings\Frank\Application Data\Xentient
2007-12-27 22:14 . 2007-12-27 22:14 <REP> d-------- C:\Program Files\Trend Micro
2007-12-27 22:00 . 2007-12-27 22:00 <REP> d-------- C:\Documents and Settings\Frank\Application Data\Grisoft
2007-12-27 22:00 . 2007-12-27 22:00 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft
2007-12-27 22:00 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-27 21:56 . 2007-12-27 21:56 <REP> d-------- C:\Program Files\Yahoo!
2007-12-27 21:56 . 2007-12-27 21:56 <REP> d-------- C:\Program Files\CCleaner
2007-12-27 21:46 . 2007-12-27 21:46 <REP> d-------- C:\WINDOWS\Options
2007-12-27 21:46 . 2005-05-02 04:10 68,096 --------- C:\WINDOWS\system32\agrsmdel.exe
2007-12-27 21:44 . 2007-12-27 21:44 <REP> d-------- C:\Documents and Settings\Frank\Application Data\Intel
2007-12-27 21:44 . 2007-12-27 21:44 <REP> d-------- C:\Documents and Settings\Default User\Application Data\Intel
2007-12-27 21:44 . 2007-12-27 21:44 21,275 --a------ C:\WINDOWS\system32\drivers\AegisP.sys
2007-12-27 21:43 . 2007-12-28 02:37 <REP> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-12-27 21:43 . 2007-12-27 23:40 <REP> d-------- C:\Program Files\Intel
2007-12-27 21:43 . 2007-12-27 21:43 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Intel
2007-12-25 22:53 . 2007-12-25 22:53 <REP> d-------- C:\Documents and Settings\Frank\Application Data\Styler
2007-12-25 22:52 . 2007-12-25 22:52 <REP> d---s---- C:\WINDOWS\system32\Microsoft
2007-12-25 22:31 . 2007-12-28 03:38 <REP> d-------- C:\WINDOWS\system32\fr-fr
2007-12-25 22:31 . 2007-12-25 22:33 <REP> d-------- C:\WINDOWS\system32\en
2007-12-25 22:31 . 2007-12-25 22:31 <REP> d-------- C:\WINDOWS\system32\drivers\UMDF
2007-12-25 22:31 . 2007-12-28 03:42 <REP> dr-hsc--- C:\WINDOWS\system32\dllcache
2007-12-25 22:31 . 2007-12-25 22:31 <REP> d-------- C:\WINDOWS\NLDRV
2007-12-25 22:16 . 2001-08-17 21:59 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2007-12-25 22:15 . 2004-08-04 00:39 58,496 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2007-12-25 22:14 . 2001-08-17 21:46 6,400 --a------ C:\WINDOWS\system32\drivers\enum1394.sys
2007-12-25 22:13 . 2007-12-28 03:28 987,006 --a------ C:\WINDOWS\system32\PerfStringBackup.INI
2007-12-25 22:13 . 2004-08-28 14:00 66,082 --a------ C:\WINDOWS\system32\c_28603.nls
2007-12-25 22:13 . 2004-08-28 14:00 66,082 --a------ C:\WINDOWS\system32\c_28599.nls
2007-12-25 22:13 . 2004-08-28 14:00 66,082 --a------ C:\WINDOWS\system32\C_28595.NLS
2007-12-25 22:13 . 2007-12-25 21:54 4,205 --a------ C:\WINDOWS\ODBCINST.INI
2007-12-25 22:12 . 2007-12-25 22:12 <REP> d--h----- C:\Documents and Settings\Default User.WINDOWS\Voisinage réseau
2007-12-25 22:12 . 2007-12-25 22:12 <REP> d--h----- C:\Documents and Settings\Default User.WINDOWS\Voisinage d'impression
2007-12-25 22:12 . 2007-12-25 21:48 <REP> d--h----- C:\Documents and Settings\Default User.WINDOWS\Modèles
2007-12-25 22:12 . 2007-12-25 22:12 <REP> d-------- C:\Documents and Settings\Default User.WINDOWS\Mes documents
2007-12-25 22:12 . 2007-12-25 22:12 <REP> dr------- C:\Documents and Settings\Default User.WINDOWS\Menu Démarrer
2007-12-25 22:12 . 2007-12-25 21:25 <REP> d-------- C:\Documents and Settings\Default User.WINDOWS\Favoris
2007-12-25 22:12 . 2007-12-25 22:12 <REP> d-------- C:\Documents and Settings\Default User.WINDOWS\Bureau
2007-12-25 22:12 . 2007-12-25 22:12 <REP> d--h----- C:\Documents and Settings\All Users.WINDOWS\Modèles
2007-12-25 22:12 . 2007-12-25 22:53 <REP> dr------- C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer
2007-12-25 22:12 . 2007-12-25 22:12 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Favoris
2007-12-25 22:12 . 2007-12-25 21:19 <REP> dr------- C:\Documents and Settings\All Users.WINDOWS\Documents
2007-12-25 22:12 . 2007-12-28 02:37 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Bureau
2007-12-25 22:10 . 2007-12-25 22:06 1,385 --a------ C:\WINDOWS\system32\$winnt$.inf
2007-12-25 22:08 . 2007-12-25 22:08 <REP> d-------- C:\Program Files\Windows Defender
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-25 20:56 155,995 ----a-w C:\WINDOWS\java\Packages\WSCRJZDB.ZIP
2007-12-25 16:12 --------- d-----w C:\Program Files\Fichiers communs\SpeechEngines
2007-12-25 16:12 --------- d-----w C:\Program Files\Fichiers communs\ODBC
2007-12-25 15:20 --------- d-----w C:\Program Files\Services en ligne
2007-12-25 15:20 --------- d-----w C:\Program Files\Fichiers communs\MSSoap
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-29 22:43 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-28 14:00]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2007-01-10 21:59]
"Uniblue SpeedUpMyPC"="" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2007-01-10 21:59]
"VisualTaskTips"="C:\Windows\System32\VisualTaskTips.exe" [2004-08-28 14:00]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-02-28 14:25]
"KTPWare"="C:\Program Files\Elantech\ktp.exe" [2006-03-27 20:36]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-28 14:00 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2006-02-08 23:06 C:\WINDOWS\system32\nwiz.exe]
"a-squared"="C:\Program Files\a-squared Anti-Malware\a2guard.exe" [2007-12-28 02:44]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-28 14:00]
"TSClientMSIUninstaller"="cmd.exe" [2004-08-28 14:00 C:\WINDOWS\system32\cmd.exe]
"nltide3"="cmd.exe" [2004-08-28 14:00 C:\WINDOWS\system32\cmd.exe]
"nltide2"="cmd.exe" [2004-08-28 14:00 C:\WINDOWS\system32\cmd.exe]
"nltide_2"="regsvr32 /s /n /i:U shell32" []
"nltide_3"="advpack.dll" [2007-10-11 00:49 C:\WINDOWS\system32\advpack.dll]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoUserNameInStartMenu"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"NoSMBalloonTip"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoUserNameInStartMenu"= 1 (0x1)
"NoSMHelp"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IfxWlxEN]
IfxWlxEN.dll 2005-11-29 10:43 393216 C:\WINDOWS\system32\IfxWlxEN.dll
R0 Si3112;Si3112;C:\WINDOWS\system32\drivers\Si3112.sys [2004-08-28 14:00]
R0 Si3124;Si3124;C:\WINDOWS\system32\drivers\Si3124.sys [2004-08-28 14:00]
R0 Si3132r5;Si3132r5;C:\WINDOWS\system32\drivers\Si3132r5.sys [2004-08-28 14:00]
R0 Si3531;Si3531;C:\WINDOWS\system32\drivers\Si3531.sys [2004-08-28 14:00]
R1 lnsfw1;lnsfw1;C:\WINDOWS\system32\drivers\lnsfw1.sys [2007-12-25 22:04]
R1 PersonalSecureDrive;PersonalSecureDrive;C:\WINDOWS\system32\drivers\psd.sys [2005-11-29 11:50]
R3 IFXTPM;IFXTPM;C:\WINDOWS\system32\DRIVERS\IFXTPM.SYS [2005-10-21 04:19]
R3 Ktp;Elantech Touchpad;C:\WINDOWS\system32\DRIVERS\Ktp.sys [2006-03-17 03:03]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-12-29 01:58]
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2007-12-28 16:59:27 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2007-12-28 12:45:46 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
"2007-12-28 12:45:46 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-28 18:03:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
-> C:\Windows\System32\VttHooks.dll
.
Completion time: 2007-12-28 18:04:12
C:\ComboFix2.txt ... 2007-12-28 17:59