voici le rapport de ComboFix
ComboFix 08-02.03.1 - Julien SERRET 2008-02-04 19:05:19.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.502 [GMT 1:00]
Endroit: C:\Documents and Settings\Julien SERRET\Temporary Internet Files\Content.IE5\1HGBC581\ComboFix[1].exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Julien SERRET\Mes documents\Ma musique\Java - Best of\Desktop_.ini
C:\Documents and Settings\Julien SERRET\Mes documents\Ma musique\Nathaniel Merrywheather\Desktop_.ini
C:\Documents and Settings\Julien SERRET\Mes documents\Ma musique\Nouvelle vague - Bande a part\Desktop_.ini
C:\Documents and Settings\Julien SERRET\Mes documents\Ma musique\Renaud - Bobino Live\Desktop_.ini
C:\Documents and Settings\Julien SERRET\Mes documents\Ma musique\The Roots - Come alive\Desktop_.ini
C:\Documents and Settings\Julien SERRET\Mes documents\Ma musique\The Roots - Do You Want More\Desktop_.ini
C:\Documents and Settings\Julien SERRET\Mes documents\Ma musique\Wax Tailor - Tales of the forgotten melodies\Desktop_.ini
C:\WINDOWS\Fonts\acrsec.fon
C:\WINDOWS\Fonts\acrsecB.fon
C:\WINDOWS\Fonts\acrsecI.fon
C:\WINDOWS\system32\6_exception.nls
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\poof
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-01-04 to 2008-02-04 ))))))))))))))))))))))))))))))))))))
.
2008-02-01 18:45 . 2008-02-01 18:45 <REP> d-------- C:\_OTMoveIt
2008-01-31 18:53 . 2008-01-31 18:53 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-01-31 06:57 . 2008-01-31 06:57 20,480 --ahs---- C:\WINDOWS\system32\adadix16n.dll
2008-01-30 21:46 . 2008-01-31 20:25 <REP> d-------- C:\fixwareout
2008-01-30 18:44 . 2008-01-30 20:23 <REP> d-------- C:\Program Files\a-squared Anti-Malware
2008-01-27 13:43 . 2008-01-27 13:43 <REP> d-------- C:\Documents and Settings\Julien SERRET\Application Data\Grisoft
2008-01-27 13:43 . 2008-01-27 13:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-27 13:43 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-27 13:30 . 2008-01-27 13:30 <REP> d-------- C:\Program Files\Trend Micro
2008-01-27 12:01 . 2008-01-27 12:01 <REP> d-------- C:\VundoFix Backups
2008-01-26 18:01 . 2008-01-26 18:01 <REP> d-------- C:\Program Files\NoBrand
2008-01-26 17:25 . 2005-06-01 05:04 408,064 -ra------ C:\WINDOWS\system32\drivers\O4501U.sys
2008-01-26 15:49 . 54,764 C:\WINDOWS\system32\drivers\fak32.sys
2008-01-26 15:49 . 2008-01-26 15:49 38,400 -r-hs---- C:\WINDOWS\system32\amcompatb.exe
2008-01-26 15:49 . 2008-02-04 17:45 143 --a-s---- C:\WINDOWS\system32\3956332696.dat
2008-01-26 15:49 . 2008-01-26 15:49 2 --a------ C:\541217827
2008-01-26 15:47 . 2007-06-13 14:22 1,075,713 --a------ C:\WINDOWS\dpqhqae.exe
2008-01-05 21:07 . 2008-01-05 21:07 227 --a------ C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
2008-01-05 21:07 . 2008-01-05 21:07 214 --a------ C:\WINDOWS\HP_48BitScanUpdatePatch.ini
2008-01-05 20:45 . 2008-01-05 20:45 221 --a------ C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-04 18:11 --------- d-----w C:\Program Files\Symantec AntiVirus
2008-01-26 17:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-26 16:59 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-01-06 19:16 --------- d-----w C:\Documents and Settings\Julien SERRET\Application Data\AdobeUM
2008-01-05 19:45 139,264 ----a-w C:\WINDOWS\system32\hpzjrd01.dll
2008-01-01 10:09 --------- d-----w C:\Program Files\eMule
2007-12-27 17:28 --------- d-----w C:\Program Files\Club-Internet
2007-12-27 17:24 --------- d-----w C:\Program Files\Motive
2007-12-23 16:17 --------- d-----w C:\Program Files\HP Wireless Adapter
2007-12-23 16:14 --------- d-----w C:\Program Files\Generic
2007-12-23 16:02 --------- d-----w C:\Program Files\Wireless LAN
2007-12-18 20:11 --------- d-----w C:\Program Files\QuickTime
2007-11-07 09:28 728,576 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:28 728,576 ------w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-11-06 11:53 318,828 ----a-w C:\WINDOWS\Math'x seconde Uninstaller.exe
2007-10-26 10:01 51,016 ----a-w C:\Documents and Settings\Julien SERRET\Application Data\GDIPFONTCACHEV1.DAT
2006-10-13 18:25 0 ----a-w C:\Documents and Settings\Julien SERRET\Application Data\wklnhst.dat
2005-09-24 06:49 12,288 ----a-w C:\WINDOWS\Fonts\RandFont.dll
2006-11-26 12:21 22 --sha-w C:\WINDOWS\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 22:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-20 08:15 68856]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 08:59 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2007-12-22 13:12 458752]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-04-26 20:48 7561216]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-04-26 20:48 86016]
"nwiz"="nwiz.exe" [2006-04-26 20:48 1519616 C:\WINDOWS\system32\nwiz.exe]
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-04-17 21:29 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-01 06:01 761946]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2006-04-11 20:54 102400]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 22:12 49152]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-03-07 13:38 131072]
"Cpqset"="C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-05-02 09:36 40960]
"RecGuard"="C:\Windows\SMINST\RecGuard.exe" [2005-10-11 09:23 1187840]
"TVPService"="C:\Program Files\HP\TVPlay\TVPService.exe" [2006-04-03 12:34 135168]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2004-03-31 14:38 66656]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2004-03-31 14:46 124128]
"USB Storage Toolbox"="C:\Program Files\USBToolbox\Res.EXE" [2004-08-12 04:42 122880]
"BJCFD"="C:\Program Files\BroadJump\Client Foundation\CFD.exe" [2003-01-27 16:16 376912]
"StandardInstall"="" []
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-18 21:11 282624]
"HPWireless"="C:\Program Files\HP Wireless Adapter\HPWLAN.exe" [2006-10-04 22:51 618496]
"Motive SmartBridge"="C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe" [2005-08-24 07:51 438359]
"Club-Internet_McciTrayApp"="C:\Program Files\Club-Internet\Agent Wi-Fi V2.1\McciTrayApp.exe" [2005-11-15 17:46 543232]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
"a-squared"="C:\Program Files\a-squared Anti-Malware\a2guard.exe" [2008-01-07 17:56 1816208]
"KernelFaultCheck"="C:\WINDOWS\system32\dumprep 0 -k" [ ]
"combofix"="C:\ComboFix[1]\kmd.exe" [2004-08-05 22:00 400896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 22:00 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
R2 CyberLink Media Library Service(HP TVPlay);CyberLink Media Library Service(HP TVPlay);"C:\Program Files\HP\TVPlay\Kernel\CLML_NTService\CLMLServer.exe" [2006-04-03 12:34]
R2 TVPCapSvc;CyberLink Background Capture Service (CBCS HP TVPlay);"C:\Program Files\HP\TVPlay\Kernel\TV\TVPCapSvc.exe" [2006-04-03 12:35]
R2 TVPSched;CyberLink Task Scheduler (CTS HP TVPlay);"C:\Program Files\HP\TVPlay\Kernel\TV\TVPSched.exe" [2006-04-03 12:35]
R3 nvsmu;nvsmu;C:\WINDOWS\system32\DRIVERS\nvsmu.sys [2006-03-06 00:49]
R3 WN4501HLFZZ(Technology Corporation);802.11g Wireless USB Adapter(Technology Corporation);C:\WINDOWS\system32\DRIVERS\O4501U.sys [2005-06-01 05:04]
S2 DefWatchLightScribeService;Symantec AntiVirus Definition Watcher DefWatchLightScribeService;C:\WINDOWS\system32\amcompatb.exe srv []
S3 MODBDA2;DiBcom MOD3000 TV receiver;C:\WINDOWS\system32\Drivers\modbda2.sys [2006-05-13 08:52]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1c24eeae-9a4b-11db-9a50-0016367e2849}]
\Shell\Auto\command - AdobeR.exe e
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2dd212d3-d7a8-11db-9ac1-0016367e2849}]
\Shell\Auto\command - setup.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2dd212d4-d7a8-11db-9ac1-0016367e2849}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe MS32DLL.dll.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6c201bbe-83ac-11db-9a1c-0016367e2849}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe MS32DLL.dll.vbs
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ac382526-68f7-11dc-9b27-0016367e2849}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c192ca89-83a2-11db-9a19-0016367e2849}]
\Shell\AutoRun\command - F:\PortableApps\PortableAppsMenu\PortableAppsMenu.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ccfe651a-5ea1-11db-99c9-0016367e2849}]
\Shell\Auto\command - AdobeR.exe e
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dc255e26-65aa-11db-99d9-4d6564696130}]
\Shell\AutoRun\command - F:\ReadMe.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{df158542-8e14-11db-9a29-0016367e2849}]
\Shell\Auto\command - setup.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ee25035b-f67b-11db-9add-0016367e2849}]
\Shell\Auto\command - F:\AdobeR.exe e
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f57c543e-5b9a-11db-99bf-0016367e2849}]
\Shell\Auto\command - AdobeR.exe e
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-02-03 19:00:00 C:\WINDOWS\Tasks\HPpromotions journeysoftware.job"
- C:\Program Files\hp\digital imaging\bin\hp promotions\journeysoftware\HPpromo.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-02-04 19:12:03
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
QlbCtrl = %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start?
Cpqset = C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe????????????,?@? ????L??????R?@?????,?@
KernelFaultCheck = %systemroot%\system32\dumprep 0 -k?
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\Program Files\a-squared Anti-Malware\a2service.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Windows Media Player\WMPNetwk.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Hewlett-Packard\HP Pavilion Webcam\HPWebcam.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\NoBrand\Wireless Network Manager\Monitor.exe
C:\Program Files\Club-Internet\Le Compagnon Club\bin\mpbtn.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-02-04 19:14:30 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-04 18:14:25
.
2008-01-26 16:11:59 --- E O F ---