Voila le resultat
ComboFix 07-12-21.4 - ked 2007-12-26 22:53:45.1 - NTFSx86
Running from: C:\Documents and Settings\ked\Bureau\ComboFix.exe
* Created a new restore point
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\Documents and Settings\ked\Application Data\setup_fr[1].exe
C:\WINDOWS\system32\koos.exe
C:\WINDOWS\system32\kprof
C:\WINDOWS\system32\poof
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_POOF
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-11-26 to 2007-12-26 ))))))))))))))))))))))))))))))))))))
.
2007-12-26 16:08 . 2007-12-26 16:08 <REP> d-------- C:\VundoFix Backups
2007-12-26 15:22 . 2007-12-26 15:22 <REP> d-------- C:\Program Files\Trend Micro
2007-12-26 14:56 . 2007-12-26 14:56 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-26 14:55 . 2007-12-26 14:55 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2007-12-26 09:03 . 2007-12-26 09:03 <REP> d-------- C:\Documents and Settings\ked\Application Data\Talkback
2007-12-26 09:03 . 2007-12-26 09:03 0 --a------ C:\WINDOWS\nsreg.dat
2007-12-25 21:47 . 2007-12-26 14:56 <REP> d-------- C:\Program Files\Lavasoft
2007-12-21 20:18 . 2007-12-21 20:18 <REP> d-------- C:\Program Files\Picasa2
2007-12-21 20:17 . 2007-12-26 10:03 <REP> d-------- C:\Program Files\Norton Security Scan
2007-12-21 20:16 . 2007-12-21 20:19 <REP> d-------- C:\Program Files\Google
2007-12-21 20:16 . 2007-12-26 22:49 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
2007-12-16 21:53 . 2007-12-16 21:53 164 --a------ C:\install.dat
2007-12-16 21:36 . 2007-12-16 21:36 <REP> dr------- C:\Documents and Settings\LocalService\Favoris
2007-12-16 20:39 . 2007-12-26 13:55 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-16 20:16 . 2005-09-23 08:29 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-12-09 02:27 . 2007-10-11 00:49 6,065,664 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2007-12-09 02:27 . 2007-04-17 10:32 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2007-12-09 02:27 . 2007-03-08 06:10 1,048,576 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2007-12-09 02:27 . 2007-10-11 00:49 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2007-12-09 02:27 . 2007-10-11 00:49 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2007-12-09 02:27 . 2007-10-11 00:49 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2007-12-09 02:27 . 2007-10-11 00:49 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2007-12-09 02:27 . 2007-10-11 00:49 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2007-12-09 02:27 . 2007-10-10 11:59 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2007-12-09 02:26 . 2007-12-09 02:27 <REP> d-------- C:\WINDOWS\system32\fr-fr
2007-12-09 02:25 . 2007-12-09 02:25 1,188,375 --a------ C:\WINDOWS\system32\libeay32.dll
2007-12-09 02:25 . 2007-12-09 02:25 741,632 --a------ C:\WINDOWS\system32\qxyopqwz.dat
2007-12-09 02:25 . 2007-12-09 02:25 246,545 --a------ C:\WINDOWS\system32\libssl32.dll
2007-12-09 02:25 . 2007-12-09 02:25 119,552 --a------ C:\WINDOWS\system32\ytksevaq.dat
2007-12-09 02:25 . 2007-12-09 02:25 42,240 --a------ C:\WINDOWS\system32\jpvgyiaz.dat
2007-12-09 02:25 . 2007-12-09 02:25 36,096 --a------ C:\WINDOWS\system32\fqwuvtdy.dat
2007-12-09 02:25 . 2007-12-09 02:25 35,072 --a------ C:\WINDOWS\system32\bqiznufi.dat
2007-12-09 02:21 . 2007-08-13 18:54 33,792 --a--c--- C:\WINDOWS\system32\dllcache\custsat.dll
2007-12-09 02:15 . 2007-12-09 02:25 83,456 --a------ C:\WINDOWS\system32\d3dimf.dll.bak
2007-12-09 02:14 . 2007-12-09 02:14 <REP> d-------- C:\WINDOWS\system32\AppCert
2007-12-09 02:14 . 2004-08-05 12:00 84,992 --a------ C:\WINDOWS\system32\eventlogv.dll
2007-12-09 02:14 . 19,456 C:\WINDOWS\system32\drivers\afwyeunl.dat
2007-12-06 13:00 . 2007-12-06 13:00 <REP> d-------- C:\WINDOWS\system32\LogFiles
2007-12-05 21:53 . 2007-12-12 23:38 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-05 21:53 . 2007-12-05 21:53 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-05 21:05 . 2007-12-05 21:07 <REP> d-------- C:\Documents and Settings\ked\Shared
2007-12-05 21:05 . 2007-12-05 21:10 <REP> d-------- C:\Documents and Settings\ked\Incomplete
2007-12-05 21:05 . 2007-12-11 07:08 <REP> d-------- C:\Documents and Settings\ked\Application Data\FrostWire
2007-12-05 21:05 . 2007-07-12 02:22 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2007-12-05 21:02 . 2007-12-05 21:05 <REP> d-------- C:\Program Files\FrostWire
2007-12-05 20:50 . 2007-12-05 20:50 <REP> d-------- C:\Documents and Settings\All Users\Application Data\F-Secure
2007-12-05 20:50 . 2005-11-18 16:04 70,896 --a------ C:\WINDOWS\system32\drivers\fsdfw.sys
2007-12-05 20:50 . 2005-11-18 16:04 33,584 --a------ C:\WINDOWS\system32\drivers\fsndis5.sys
2007-12-05 20:46 . 2007-12-05 20:46 118,842 -r------- C:\WINDOWS\bwUnin-6.3.2.123-6588780L.exe
2007-12-05 19:48 . 2007-12-05 20:48 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-04 20:51 . 2007-12-04 23:45 <REP> d-------- C:\Documents and Settings\ked\Application Data\Azureus
2007-12-04 20:51 . 2007-12-04 20:51 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Azureus
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-21 19:24 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2007-12-21 18:51 --------- d-----w C:\Program Files\eMule
2007-12-05 20:05 --------- d-----w C:\Program Files\Java
2007-12-05 19:49 --------- d-----w C:\Program Files\AntivirusFirewall
2007-11-18 12:11 --------- d-----w C:\Documents and Settings\ked\Application Data\AVS4YOU
2007-11-18 12:10 --------- d-----w C:\Program Files\Fichiers communs\AVSMedia
2007-11-18 12:10 --------- d-----w C:\Program Files\AVS4YOU
2007-11-18 12:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\AVS4YOU
2007-11-18 12:03 --------- d-----w C:\Documents and Settings\ked\Application Data\Apple Computer
2007-11-18 12:01 --------- d-----w C:\Program Files\QuickTime
2007-11-18 12:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-11-18 11:13 --------- d-----w C:\Program Files\Apple Software Update
2007-11-18 11:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-29 22:43 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-20 05:01 227,328 ----a-w C:\WINDOWS\system32\wmasf.dll
2006-02-19 01:28 12,288 ----a-w C:\WINDOWS\Fonts\RandFont.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{083B0080-06BD-4458-A8C8-08DAE5EB102E}]
2004-08-05 12:00 84992 --a------ C:\WINDOWS\system32\eventlogv.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3C66EAAF-A696-42BE-9D14-29A29A16A885}]
c:\windows\system32\d3dimf.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 12:00]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:55]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-12-21 20:16]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-14 23:28]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-14 23:26]
"F-Secure Manager"="C:\Program Files\AntivirusFirewall\Common\FSM32.exe" [2005-10-26 02:51]
"F-Secure TNB"="C:\Program Files\AntivirusFirewall\TNB\TNBUtil.exe" [2005-07-18 15:51]
"F-Secure Startup Wizard"="C:\Program Files\AntivirusFirewall\FSGUI\FSSW.exe" [2005-10-18 09:29]
"News Service"="C:\Program Files\AntivirusFirewall\FSGUI\ispnews.exe" [2005-05-31 13:45]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-19 20:16]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 12:00]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vsxeqiqv]
d3dimf.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Démarrage rapide de HP Photosmart Premier.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Démarrage rapide de HP Photosmart Premier.lnk
backup=C:\WINDOWS\pss\Démarrage rapide de HP Photosmart Premier.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
AGRSMMSG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
2005-03-22 20:05 339968 --a------ C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CFSServ.exe]
CFSServ.exe -NoClient
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe /s
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dla]
2004-08-03 01:05 122939 --a------ C:\WINDOWS\system32\dla\tfswctrl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2006-02-19 01:41 49152 --a------ C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh]
2003-09-06 01:16 184320 --a------ C:\Program Files\ltmoh\Ltmoh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MS32DLL]
C:\WINDOWS\MS32DLL.dll.vbs
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NDSTray.exe]
NDSTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\News Service]
2005-05-31 13:45 356352 --a------ C:\Program Files\AntivirusFirewall\FSGUI\ispnews.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PadTouch]
2004-11-17 10:56 1077327 --a------ C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmoothView]
2004-12-21 09:48 118784 --a------ C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2004-07-27 12:48 1388544 --a------ C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TFncKy]
TFncKy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\THotkey]
2005-01-14 16:45 352256 --a------ C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TOSCDSPD]
2003-09-15 16:19 65536 --a------ C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPSMain]
TPSMain.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tvs]
2004-11-12 17:57 73728 --a------ C:\Program Files\Toshiba\Tvs\TvsTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirtualCloneDrive]
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe /s
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"TAPPSRV"=2 (0x2)
"SoundMAX Agent Service (default)"=2 (0x2)
"ose"=3 (0x3)
"FSMA"=2 (0x2)
"FSDFWD"=3 (0x3)
"fsbwsys"=2 (0x2)
"F-Secure Gatekeeper Handler Starter"=2 (0x2)
"CFSvcs"=2 (0x2)
"BackWeb Plug-in - 6588780"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
R0 FSFW;F-Secure Firewall Driver;C:\WINDOWS\system32\drivers\fsdfw.sys [2005-11-18 16:04]
R0 honqwmkg;honqwmkg;C:\WINDOWS\system32\drivers\afwyeunl.dat []
R2 BackWeb Plug-in - 6588780;Antivirus Firewall;C:\PROGRA~1\ANTIVI~1\backweb\6588780\Program\SERVIC~1.EXE [2007-12-05 20:46]
R2 F-Secure Filter;F-Secure File System Filter;C:\Program Files\AntivirusFirewall\Anti-Virus\Win2K\FSfilter.sys [2004-09-10 16:14]
R2 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Program Files\AntivirusFirewall\Anti-Virus\Win2K\FSgk.sys [2007-12-05 20:58]
R2 F-Secure Recognizer;F-Secure File System Recognizer;C:\Program Files\AntivirusFirewall\Anti-Virus\Win2K\FSrec.sys [2004-06-01 10:03]
S2 hxdvjyzl;USB to IEEE-1284.4 Translation HPZius12Support;C:\WINDOWS\System32\svchost.exe -k netsvcs []
S3 tosrfec;Bluetooth ACPI from TOSHIBA;C:\WINDOWS\system32\DRIVERS\tosrfec.sys [2004-05-17 23:18]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
hxdvjyzl
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{40436cb1-5ca9-11dc-a972-00a0d1239b31}]
\Shell\AutoRun\command - F:\setupSNK.exe
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2007-12-18 14:31:08 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-21 19:17:41 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
"2005-10-21 11:51:48 C:\WINDOWS\Tasks\Rappel d'enregistrement 1.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
"2007-12-26 21:37:03 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-26 23:01:30
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\WINDOWS\system32\AppCert\prx93f.dll
.
Completion time: 2007-12-26 23:03:16 - machine was rebooted
.
2007-12-12 22:46:46 --- E O F ---