KioskeaKioskeaCommentCaMarcheInscrivez-vous, c'est gratuit !
Samedi 17 mai 2008 - 11:58:16

Chevaux de Troies & Virus

Rechercher : dans
Chevaux de Troies & Virus
par moncey
 Fil de Discussions
Statut : Non résolu
mercredi 20 février 2008 à 12:52:00
Bonjour,

Mon PC est infecté par plusieurs chevaux de troie qu'Avast nomme :
Win32:Small-JMK
Win32-Agent-NJB
Win32:Agent-MEB

Il infecte les fichiers placés sous :
C:\WINDOWS\System32\ftpdll.dll
C:\Documents and Settings\Local Service\ftpdll.dll
C:\WINDOWS\System32\Drivers\ip6fw.sys
C:\WINDOWS\System3\drivers\runtime.sys

Dès qu'Avast repère ces fichiers, ils sont immédiatement supprimés.
Mais à chaque scan, ils réapparaissent.

Il y a également un virus qu'Avast nomme "Win32:Agent-NGJ"

Comment faire pour s'en débarrasser définitivement ?

D'avance merci !
Configuration: Windows XP SP2
Internet Explorer 6.0
Répondre à moncey  Signaler ce message aux modérateurs Aller au dernier message

1


  • Ce message vous semble utile, votez !
  • Signaler ce message aux modérateurs
Par jlpjlp, le mercredi 20 février 2008 à 19:03:15 Fil de Discussions
slt,


colle un rapport hijackthis


http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

manuel :

http://leblogdeclaude.blogspot.com/2006/10/informatique-section-hijackthis.html

Je conseille de renomer Hijackthis, pour contrer une éventuelle infection de Vundo.

ex:Renomme le fichier HijackThis.exe en eden.exe pour cela, fais un clic droit sur le fichier HijackThis.exe et choisis renommer dans la liste

Ensuite avec Explorer créer un dossier c:\hijackthis
Décompresser Hijackthis dans ce dossier.
C'est important pour les sauvegardes."

_____________________

combofix (colle le rapport)
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

_____________________
Répondre à jlpjlp

2


  • Ce message vous semble utile, votez !
  • Signaler ce message aux modérateurs
Par moncey, le mercredi 20 février 2008 à 21:09:36 Fil de Discussions
jlpjlp,

Tout d'abord, merci de m'avoir répondu.
Voici le rapport Hijackthis :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:56:56, on 20/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
E:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
E:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\drivers\spools.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\spools.exe
E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\FTRTSVC.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
E:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
E:\Program Files\Alwil Software\Avast4\ashWebSv.exe
E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Wanadoo\Watch.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\MSN Messenger\usnsvc.exe
E:\hijackthis\eden.exe
C:\Documents and Settings\Famille Moncey\Local Settings\Application Data\cftmon.exe
C:\Documents and Settings\Famille Moncey\Local Settings\Application Data\cftmon.exe
C:\Documents and Settings\Famille Moncey\Local Settings\Application Data\cftmon.exe
C:\Documents and Settings\Famille Moncey\Local Settings\Application Data\cftmon.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Module - {221BBF54-3327-4548-9006-84385B1A5840} - ssymman.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - E:\Program Files\NetTransport 2\NTIEHelper.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [avast!] E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [autoload] C:\Documents and Settings\LocalService\Local Settings\Application Data\cftmon.exe
O4 - HKLM\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"
O4 - HKLM\..\Run: [EPSON Product Rappel concernant l'enregistrement] C:\WINDOWS\Temp\RegModule.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe EspaceWanadoo.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [autoload] C:\Documents and Settings\Famille Moncey\Local Settings\Application Data\cftmon.exe
O4 - HKCU\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: GigaTribe.lnk = E:\Program Files\GigaTribe\gigatribe.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Lancement rapide d'Adobe Acrobat.lnk = ?
O4 - Global Startup: Lancement rapide de Microsoft Office OneNote 2003.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: &Télécharger avec NetTransport - E:\Program Files\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Tout t&élécharger avec NetTransport - E:\Program Files\NetTransport 2\NTAddList.html
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\..\{DB51C8BA-3ED8-43F5-8056-E6472502D077}: NameServer = 81.253.149.1 80.10.246.3
O20 - Winlogon Notify: sysfldr - C:\WINDOWS\SYSTEM32\sysfldr.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - E:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - E:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - E:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - E:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Planificateur de tâches (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\spools.exe
End of file - 10368 bytes

Voici le rapport Combofix :

ComboFix 08-02-20.2 - Famille Moncey 2008-02-20 21:01:11.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.559 [GMT 1:00]
Endroit: C:\Documents and Settings\Famille Moncey\Bureau\combofix.exe
* Création d'un nouveau point de restauration

[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Famille Moncey\~tmp1174.exe
C:\Documents and Settings\Famille Moncey\Local Settings\Application Data\cftmon.exe
C:\Documents and Settings\LocalService\Local Settings\Application Data\cftmon.exe
C:\WINDOWS\system32\8_exception.nls
C:\WINDOWS\system32\conf.dat
C:\WINDOWS\system32\dllsys.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\runtime


((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-01-20 to 2008-02-20 ))))))))))))))))))))))))))))))))))))
.

2008-02-20 11:25 . 2008-02-20 11:25 21,632 --a------ C:\WINDOWS\system32\drivers\Yyg66.sys
2008-02-20 11:25 . 2008-02-20 11:25 7,168 --a------ C:\WINDOWS\system32\WLCtrl32.dll
2008-02-20 08:47 . 2008-02-20 20:53 5,120 --a------ C:\Documents and Settings\LocalService\ftpdll.dll
2008-02-19 18:15 . 2008-02-19 18:15 <REP> d-------- C:\WINDOWS\Sun
2008-02-19 18:11 . 2008-02-20 20:53 5,120 --a------ C:\WINDOWS\system32\ftpdll.dll
2008-02-18 21:18 . 2008-02-18 21:25 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-18 21:14 . 2008-02-18 21:15 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-18 21:13 . 2008-02-18 21:13 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-02-17 19:02 . 2008-02-17 19:02 <REP> d-------- C:\Documents and Settings\Famille Moncey\Application Data\vlc
2008-02-17 18:55 . 2003-08-29 00:55 423,424 --a------ C:\WINDOWS\system32\WMAVDS32.ax
2008-02-17 18:55 . 2001-03-26 03:41 245,760 --a------ C:\WINDOWS\system32\mp4sds32.ax
2008-02-17 17:45 . 2008-02-17 17:46 <REP> d-------- C:\Program Files\ABBYY FineReader 6.0 Sprint
2008-02-17 17:32 . 2008-02-17 17:35 <REP> d-------- C:\Documents and Settings\All Users\Application Data\UDL
2008-02-17 17:28 . 2004-11-25 06:07 79,679 --a------ C:\WINDOWS\system32\E_FLMACE.DLL
2008-02-17 17:28 . 2003-05-21 03:27 64,000 --a------ C:\WINDOWS\system32\E_FBCBACE.DLL
2008-02-17 17:28 . 2004-09-10 21:12 49,152 --a------ C:\WINDOWS\system32\E_DCINST.DLL
2008-02-17 17:28 . 2000-06-07 02:01 34,304 --a------ C:\WINDOWS\system32\E_FBCHACE.DLL
2008-02-17 17:28 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-02-17 17:28 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-02-17 17:27 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-02-17 17:27 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-02-17 17:27 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-02-17 17:27 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-02-17 17:26 . 2008-02-17 17:33 <REP> d-------- C:\Program Files\epson
2008-02-17 17:26 . 2005-02-25 00:00 46,080 --a------ C:\WINDOWS\system32\escimgd.dll
2008-02-17 17:26 . 2005-02-25 00:00 29,696 --a------ C:\WINDOWS\system32\escwiad.dll
2008-02-17 17:26 . 2005-02-25 00:00 22,016 --a------ C:\WINDOWS\system32\esccmd.dll
2008-02-17 17:26 . 2008-02-17 17:26 25 --a------ C:\WINDOWS\CDE DX3800EFGIPSD.ini
2008-02-17 17:24 . 2002-01-23 18:10 86,016 --a------ C:\WINDOWS\unvise32qt.exe
2008-02-17 17:23 . 2008-02-17 17:24 <REP> d-------- C:\Program Files\QuickTime
2008-02-17 17:23 . 2008-02-17 17:24 <REP> d-------- C:\Documents and Settings\All Users\Application Data\QuickTime
2008-02-17 17:22 . 2008-02-17 17:22 <REP> d-------- C:\Program Files\Fichiers communs\Kodak
2008-02-17 17:21 . 2008-02-17 17:21 <REP> d-------- C:\WINDOWS\system32\color
2008-02-17 17:21 . 2008-02-17 17:21 <REP> d-------- C:\KPCMS
2008-02-17 17:18 . 2008-02-17 17:23 <REP> d-------- C:\Program Files\Kodak
2008-02-17 17:18 . 2008-02-17 17:18 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Kodak
2008-02-17 16:36 . 2008-02-17 20:44 116 --a------ C:\WINDOWS\NeroDigital.ini
2008-02-17 14:25 . 2008-02-20 18:22 200 --a------ C:\Documents and Settings\Famille Moncey\Application Data\wklnhst.dat
2008-02-17 09:02 . 2008-02-17 09:02 <REP> d-------- C:\Documents and Settings\Famille Moncey\Application Data\GigaTribe
2008-02-16 23:03 . 2008-02-16 23:03 268 --ah----- C:\sqmdata01.sqm
2008-02-16 23:03 . 2008-02-16 23:03 244 --ah----- C:\sqmnoopt01.sqm
2008-02-16 22:51 . 2008-02-17 13:47 <REP> d-------- C:\Documents and Settings\Famille Moncey\Application Data\LimeWire
2008-02-16 22:41 . 2008-02-16 22:41 <REP> d-------- C:\Documents and Settings\Famille Moncey\Application Data\AdobeUM
2008-02-16 22:34 . 2007-12-14 01:59 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-02-16 22:29 . 2008-02-16 22:29 <REP> d-------- C:\Program Files\Fichiers communs\Java
2008-02-16 22:10 . 2007-07-09 14:11 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-02-16 21:51 . 2008-02-16 21:51 43,150 ---hs---- C:\WINDOWS\system32\drivers\spools.exe
2008-02-16 21:42 . 2008-02-17 09:02 <REP> d-------- C:\Documents and Settings\Famille Moncey\Contacts
2008-02-16 21:41 . 2008-02-16 21:41 <REP> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-02-16 21:41 . 2008-02-16 22:58 <REP> d-------- C:\Program Files\MSN Messenger
2008-02-16 21:41 . 2008-02-16 21:41 268 --ah----- C:\sqmdata00.sqm
2008-02-16 21:41 . 2008-02-16 21:41 244 --ah----- C:\sqmnoopt00.sqm
2008-02-16 21:36 . 2008-02-16 21:36 <REP> d-------- C:\Program Files\Fichiers communs\Adobe Systems Shared
2008-02-16 21:36 . 2008-02-16 21:36 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-02-16 21:33 . 2008-02-16 21:33 <REP> d-------- C:\Program Files\Fichiers communs\Adobe
2008-02-16 21:21 . 2008-02-16 21:22 <REP> d-------- C:\Program Files\Microsoft AutoRoute
2008-02-16 21:20 . 2008-02-16 21:20 <REP> d-------- C:\Program Files\Encarta
2008-02-16 21:18 . 2008-02-16 21:20 <REP> d-------- C:\Program Files\Picture It! Premium 10
2008-02-16 21:17 . 2008-02-16 21:18 <REP> d-------- C:\Program Files\microsoft money 2005
2008-02-16 21:16 . 2008-02-16 21:17 <REP> d-------- C:\Program Files\Microsoft Works
2008-02-16 21:15 . 2008-02-16 21:15 <REP> d-------- C:\Program Files\Microsoft Works Suite 2005
2008-02-16 21:13 . 2008-02-17 16:37 <REP> d-------- C:\Documents and Settings\Famille Moncey\Application Data\Ahead
2008-02-16 21:12 . 2008-02-16 21:12 <REP> d-------- C:\Program Files\Realtek AC97
2008-02-16 21:10 . 2008-02-16 21:10 <REP> d-------- C:\Program Files\Nero
2008-02-16 21:10 . 2008-02-16 21:10 <REP> d-------- C:\Program Files\Fichiers communs\Ahead
2008-02-16 21:08 . 2008-02-16 21:08 <REP> d-------- C:\Program Files\Windows Live
2008-02-16 21:08 . 2008-02-16 21:18 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-02-16 21:08 . 2008-02-16 21:08 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-16 21:07 . 2008-02-16 23:11 <REP> d--h----- C:\WINDOWS\$hf_mig$
2008-02-16 21:03 . 2007-07-30 19:19 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2008-02-16 21:03 . 2007-07-30 19:19 38,232 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-02-16 21:03 . 2007-07-30 19:20 30,040 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-02-16 21:03 . 2007-07-30 19:19 30,040 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-02-16 21:03 . 2007-07-30 19:18 21,336 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-02-16 20:59 . 2008-02-16 20:59 <REP> d---s---- C:\Documents and Settings\Famille Moncey\UserData
2008-02-16 20:40 . 2008-02-16 20:40 <REP> d-------- C:\Documents and Settings\LocalService\Menu D‚marrer
2008-02-16 19:35 . 2004-08-19 16:09 2,113,536 --------- C:\WINDOWS\system32\dxdiagn.dll
2008-02-16 19:34 . 2008-02-16 19:34 <REP> d-------- C:\WINDOWS\ServicePackFiles
2008-02-16 19:32 . 2005-06-28 10:21 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-02-16 19:32 . 2004-07-17 11:40 19,528 --a------ C:\WINDOWS\[u]002211_.tmp
2008-02-16 19:31 . 2008-02-16 19:35 <REP> d-------- C:\WINDOWS\EHome

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-20 20:04 --------- d-----w C:\Program Files\Wanadoo
2008-02-17 16:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-17 16:38 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-02-16 21:34 --------- d-----w C:\Program Files\Java
2008-02-16 17:32 --------- d-----w C:\Program Files\DVD Shrink
2008-02-16 17:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-02-16 17:31 --------- d-----w C:\Program Files\VideoLAN
2008-02-16 17:19 --------- d-----w C:\Program Files\Microsoft.NET
2008-02-16 16:38 --------- d-----w C:\Program Files\Wanadoo Messager
2008-02-16 16:26 --------- d-----w C:\Program Files\microsoft frontpage
2008-02-16 16:25 558,142 ----a-w C:\WINDOWS\java\Packages\HZ5F7HFB.ZIP
2008-02-16 16:25 155,995 ----a-w C:\WINDOWS\java\Packages\A0WK5VJ5.ZIP
2008-02-16 16:23 --------- d-----w C:\Program Files\Services en ligne
.

((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{221BBF54-3327-4548-9006-84385B1A5840}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 16:09 15360]
"WOOKIT"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 16:55 32768]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352]
"SpybotSD TeaTimer"="E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NWEReboot"="" []
"WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 14:49 20480]
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 16:55 32768]
"avast!"="E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 05:42 577536 C:\WINDOWS\soundman.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 02:12 483328]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-17 17:24 77824]
"EPSON Stylus DX3800 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.exe" [2005-02-08 05:00 98304]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 16:09 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sysfldr]
sysfldr.dll 2004-08-19 16:09 14336 C:\WINDOWS\system32\sysfldr.dll

S3 Yyg66;Yyg66;C:\WINDOWS\System32\drivers\Yyg66.sys [2008-02-20 11:25]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-02-20 21:04:09
Windows 5.1.2600 Service Pack 2 NTFS

Balayage processus cach‚s ...

Balayage cach‚ autostart entries ...

Balayage des fichiers cach‚s ...

Scan termin‚ avec succŠs
Les fichiers cach‚s: 0

**************************************************************************
.
--------------------- DLLs a charg‚ sous des processus courants ---------------------

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\sysfldr.dll
.
------------------------ Other Running Processes ------------------------
.
E:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
E:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\FTRTSVC.exe
E:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
E:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
.
**************************************************************************
.
Temps d'accomplissement: 2008-02-20 21:05:47 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-20 20:05:43
.
2008-02-16 22:12:14 --- E O F ---

Et voilà !

A tout de suite si tu es connecté !

Moncey
Répondre à moncey

3


  • Ce message vous semble utile, votez !
  • Signaler ce message aux modérateurs
Par moncey, le mercredi 20 février 2008 à 21:10:06 Fil de Discussions
jlpjlp,

Tout d'abord, merci de m'avoir répondu.
Voici le rapport Hijackthis :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:56:56, on 20/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
E:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
E:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\drivers\spools.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\drivers\spools.exe
E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\System32\FTRTSVC.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
E:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
E:\Program Files\Alwil Software\Avast4\ashWebSv.exe
E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Wanadoo\Watch.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\MSN Messenger\usnsvc.exe
E:\hijackthis\eden.exe
C:\Documents and Settings\Famille Moncey\Local Settings\Application Data\cftmon.exe
C:\Documents and Settings\Famille Moncey\Local Settings\Application Data\cftmon.exe
C:\Documents and Settings\Famille Moncey\Local Settings\Application Data\cftmon.exe
C:\Documents and Settings\Famille Moncey\Local Settings\Application Data\cftmon.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Module - {221BBF54-3327-4548-9006-84385B1A5840} - ssymman.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - E:\Program Files\NetTransport 2\NTIEHelper.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [avast!] E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [autoload] C:\Documents and Settings\LocalService\Local Settings\Application Data\cftmon.exe
O4 - HKLM\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"
O4 - HKLM\..\Run: [EPSON Product Rappel concernant l'enregistrement] C:\WINDOWS\Temp\RegModule.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe EspaceWanadoo.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [autoload] C:\Documents and Settings\Famille Moncey\Local Settings\Application Data\cftmon.exe
O4 - HKCU\..\Run: [ntuser] C:\WINDOWS\system32\drivers\spools.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: GigaTribe.lnk = E:\Program Files\GigaTribe\gigatribe.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Lancement rapide d'Adobe Acrobat.lnk = ?
O4 - Global Startup: Lancement rapide de Microsoft Office OneNote 2003.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: &Télécharger avec NetTransport - E:\Program Files\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Tout t&élécharger avec NetTransport - E:\Program Files\NetTransport 2\NTAddList.html
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\..\{DB51C8BA-3ED8-43F5-8056-E6472502D077}: NameServer = 81.253.149.1 80.10.246.3
O20 - Winlogon Notify: sysfldr - C:\WINDOWS\SYSTEM32\sysfldr.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - E:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - E:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - E:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - E:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Planificateur de tâches (Schedule) - Unknown owner - C:\WINDOWS\system32\drivers\spools.exe
End of file - 10368 bytes

Voici le rapport Combofix :

ComboFix 08-02-20.2 - Famille Moncey 2008-02-20 21:01:11.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.559 [GMT 1:00]
Endroit: C:\Documents and Settings\Famille Moncey\Bureau\combofix.exe
* Création d'un nouveau point de restauration

[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Famille Moncey\~tmp1174.exe
C:\Documents and Settings\Famille Moncey\Local Settings\Application Data\cftmon.exe
C:\Documents and Settings\LocalService\Local Settings\Application Data\cftmon.exe
C:\WINDOWS\system32\8_exception.nls
C:\WINDOWS\system32\conf.dat
C:\WINDOWS\system32\dllsys.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\runtime


((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-01-20 to 2008-02-20 ))))))))))))))))))))))))))))))))))))
.

2008-02-20 11:25 . 2008-02-20 11:25 21,632 --a------ C:\WINDOWS\system32\drivers\Yyg66.sys
2008-02-20 11:25 . 2008-02-20 11:25 7,168 --a------ C:\WINDOWS\system32\WLCtrl32.dll
2008-02-20 08:47 . 2008-02-20 20:53 5,120 --a------ C:\Documents and Settings\LocalService\ftpdll.dll
2008-02-19 18:15 . 2008-02-19 18:15 <REP> d-------- C:\WINDOWS\Sun
2008-02-19 18:11 . 2008-02-20 20:53 5,120 --a------ C:\WINDOWS\system32\ftpdll.dll
2008-02-18 21:18 . 2008-02-18 21:25 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-18 21:14 . 2008-02-18 21:15 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-18 21:13 . 2008-02-18 21:13 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-02-17 19:02 . 2008-02-17 19:02 <REP> d-------- C:\Documents and Settings\Famille Moncey\Application Data\vlc
2008-02-17 18:55 . 2003-08-29 00:55 423,424 --a------ C:\WINDOWS\system32\WMAVDS32.ax
2008-02-17 18:55 . 2001-03-26 03:41 245,760 --a------ C:\WINDOWS\system32\mp4sds32.ax
2008-02-17 17:45 . 2008-02-17 17:46 <REP> d-------- C:\Program Files\ABBYY FineReader 6.0 Sprint
2008-02-17 17:32 . 2008-02-17 17:35 <REP> d-------- C:\Documents and Settings\All Users\Application Data\UDL
2008-02-17 17:28 . 2004-11-25 06:07 79,679 --a------ C:\WINDOWS\system32\E_FLMACE.DLL
2008-02-17 17:28 . 2003-05-21 03:27 64,000 --a------ C:\WINDOWS\system32\E_FBCBACE.DLL
2008-02-17 17:28 . 2004-09-10 21:12 49,152 --a------ C:\WINDOWS\system32\E_DCINST.DLL
2008-02-17 17:28 . 2000-06-07 02:01 34,304 --a------ C:\WINDOWS\system32\E_FBCHACE.DLL
2008-02-17 17:28 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-02-17 17:28 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-02-17 17:27 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-02-17 17:27 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-02-17 17:27 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-02-17 17:27 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-02-17 17:26 . 2008-02-17 17:33 <REP> d-------- C:\Program Files\epson
2008-02-17 17:26 . 2005-02-25 00:00 46,080 --a------ C:\WINDOWS\system32\escimgd.dll
2008-02-17 17:26 . 2005-02-25 00:00 29,696 --a------ C:\WINDOWS\system32\escwiad.dll
2008-02-17 17:26 . 2005-02-25 00:00 22,016 --a------ C:\WINDOWS\system32\esccmd.dll
2008-02-17 17:26 . 2008-02-17 17:26 25 --a------ C:\WINDOWS\CDE DX3800EFGIPSD.ini
2008-02-17 17:24 . 2002-01-23 18:10 86,016 --a------ C:\WINDOWS\unvise32qt.exe
2008-02-17 17:23 . 2008-02-17 17:24 <REP> d-------- C:\Program Files\QuickTime
2008-02-17 17:23 . 2008-02-17 17:24 <REP> d-------- C:\Documents and Settings\All Users\Application Data\QuickTime
2008-02-17 17:22 . 2008-02-17 17:22 <REP> d-------- C:\Program Files\Fichiers communs\Kodak
2008-02-17 17:21 . 2008-02-17 17:21 <REP> d-------- C:\WINDOWS\system32\color
2008-02-17 17:21 . 2008-02-17 17:21 <REP> d-------- C:\KPCMS
2008-02-17 17:18 . 2008-02-17 17:23 <REP> d-------- C:\Program Files\Kodak
2008-02-17 17:18 . 2008-02-17 17:18 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Kodak
2008-02-17 16:36 . 2008-02-17 20:44 116 --a------ C:\WINDOWS\NeroDigital.ini
2008-02-17 14:25 . 2008-02-20 18:22 200 --a------ C:\Documents and Settings\Famille Moncey\Application Data\wklnhst.dat
2008-02-17 09:02 . 2008-02-17 09:02 <REP> d-------- C:\Documents and Settings\Famille Moncey\Application Data\GigaTribe
2008-02-16 23:03 . 2008-02-16 23:03 268 --ah----- C:\sqmdata01.sqm
2008-02-16 23:03 . 2008-02-16 23:03 244 --ah----- C:\sqmnoopt01.sqm
2008-02-16 22:51 . 2008-02-17 13:47 <REP> d-------- C:\Documents and Settings\Famille Moncey\Application Data\LimeWire
2008-02-16 22:41 . 2008-02-16 22:41 <REP> d-------- C:\Documents and Settings\Famille Moncey\Application Data\AdobeUM
2008-02-16 22:34 . 2007-12-14 01:59 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-02-16 22:29 . 2008-02-16 22:29 <REP> d-------- C:\Program Files\Fichiers communs\Java
2008-02-16 22:10 . 2007-07-09 14:11 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-02-16 21:51 . 2008-02-16 21:51 43,150 ---hs---- C:\WINDOWS\system32\drivers\spools.exe
2008-02-16 21:42 . 2008-02-17 09:02 <REP> d-------- C:\Documents and Settings\Famille Moncey\Contacts
2008-02-16 21:41 . 2008-02-16 21:41 <REP> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-02-16 21:41 . 2008-02-16 22:58 <REP> d-------- C:\Program Files\MSN Messenger
2008-02-16 21:41 . 2008-02-16 21:41 268 --ah----- C:\sqmdata00.sqm
2008-02-16 21:41 . 2008-02-16 21:41 244 --ah----- C:\sqmnoopt00.sqm
2008-02-16 21:36 . 2008-02-16 21:36 <REP> d-------- C:\Program Files\Fichiers communs\Adobe Systems Shared
2008-02-16 21:36 . 2008-02-16 21:36 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-02-16 21:33 . 2008-02-16 21:33 <REP> d-------- C:\Program Files\Fichiers communs\Adobe
2008-02-16 21:21 . 2008-02-16 21:22 <REP> d-------- C:\Program Files\Microsoft AutoRoute
2008-02-16 21:20 . 2008-02-16 21:20 <REP> d-------- C:\Program Files\Encarta
2008-02-16 21:18 . 2008-02-16 21:20 <REP> d-------- C:\Program Files\Picture It! Premium 10
2008-02-16 21:17 . 2008-02-16 21:18 <REP> d-------- C:\Program Files\microsoft money 2005
2008-02-16 21:16 . 2008-02-16 21:17 <REP> d-------- C:\Program Files\Microsoft Works
2008-02-16 21:15 . 2008-02-16 21:15 <REP> d-------- C:\Program Files\Microsoft Works Suite 2005
2008-02-16 21:13 . 2008-02-17 16:37 <REP> d-------- C:\Documents and Settings\Famille Moncey\Application Data\Ahead
2008-02-16 21:12 . 2008-02-16 21:12 <REP> d-------- C:\Program Files\Realtek AC97
2008-02-16 21:10 . 2008-02-16 21:10 <REP> d-------- C:\Program Files\Nero
2008-02-16 21:10 . 2008-02-16 21:10 <REP> d-------- C:\Program Files\Fichiers communs\Ahead
2008-02-16 21:08 . 2008-02-16 21:08 <REP> d-------- C:\Program Files\Windows Live
2008-02-16 21:08 . 2008-02-16 21:18 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-02-16 21:08 . 2008-02-16 21:08 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-16 21:07 . 2008-02-16 23:11 <REP> d--h----- C:\WINDOWS\$hf_mig$
2008-02-16 21:03 . 2007-07-30 19:19 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2008-02-16 21:03 . 2007-07-30 19:19 38,232 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-02-16 21:03 . 2007-07-30 19:20 30,040 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-02-16 21:03 . 2007-07-30 19:19 30,040 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-02-16 21:03 . 2007-07-30 19:18 21,336 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-02-16 20:59 . 2008-02-16 20:59 <REP> d---s---- C:\Documents and Settings\Famille Moncey\UserData
2008-02-16 20:40 . 2008-02-16 20:40 <REP> d-------- C:\Documents and Settings\LocalService\Menu D‚marrer
2008-02-16 19:35 . 2004-08-19 16:09 2,113,536 --------- C:\WINDOWS\system32\dxdiagn.dll
2008-02-16 19:34 . 2008-02-16 19:34 <REP> d-------- C:\WINDOWS\ServicePackFiles
2008-02-16 19:32 . 2005-06-28 10:21 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-02-16 19:32 . 2004-07-17 11:40 19,528 --a------ C:\WINDOWS\[u]002211_.tmp
2008-02-16 19:31 . 2008-02-16 19:35 <REP> d-------- C:\WINDOWS\EHome

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-20 20:04 --------- d-----w C:\Program Files\Wanadoo
2008-02-17 16:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-17 16:38 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-02-16 21:34 --------- d-----w C:\Program Files\Java
2008-02-16 17:32 --------- d-----w C:\Program Files\DVD Shrink
2008-02-16 17:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-02-16 17:31 --------- d-----w C:\Program Files\VideoLAN
2008-02-16 17:19 --------- d-----w C:\Program Files\Microsoft.NET
2008-02-16 16:38 --------- d-----w C:\Program Files\Wanadoo Messager
2008-02-16 16:26 --------- d-----w C:\Program Files\microsoft frontpage
2008-02-16 16:25 558,142 ----a-w C:\WINDOWS\java\Packages\HZ5F7HFB.ZIP
2008-02-16 16:25 155,995 ----a-w C:\WINDOWS\java\Packages\A0WK5VJ5.ZIP
2008-02-16 16:23 --------- d-----w C:\Program Files\Services en ligne
.

((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{221BBF54-3327-4548-9006-84385B1A5840}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 16:09 15360]
"WOOKIT"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 16:55 32768]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:54 5674352]
"SpybotSD TeaTimer"="E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NWEReboot"="" []
"WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 14:49 20480]
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 16:55 32768]
"avast!"="E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 05:42 577536 C:\WINDOWS\soundman.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"Acrobat Assistant 7.0"="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 02:12 483328]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-17 17:24 77824]
"EPSON Stylus DX3800 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.exe" [2005-02-08 05:00 98304]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 16:09 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sysfldr]
sysfldr.dll 2004-08-19 16:09 14336 C:\WINDOWS\system32\sysfldr.dll

S3 Yyg66;Yyg66;C:\WINDOWS\System32\drivers\Yyg66.sys [2008-02-20 11:25]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-02-20 21:04:09
Windows 5.1.2600 Service Pack 2 NTFS

Balayage processus cach‚s ...

Balayage cach‚ autostart entries ...

Balayage des fichiers cach‚s ...

Scan termin‚ avec succŠs
Les fichiers cach‚s: 0

**************************************************************************
.
--------------------- DLLs a charg‚ sous des processus courants ---------------------

PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\sysfldr.dll
.
------------------------ Other Running Processes ------------------------
.
E:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
E:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\FTRTSVC.exe
E:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
E:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
.
**************************************************************************
.
Temps d'accomplissement: 2008-02-20 21:05:47 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-20 20:05:43
.
2008-02-16 22:12:14 --- E O F ---

Et voilà !

A tout de suite si tu es connecté !

Moncey
Répondre à moncey

4


  • Ce message vous semble utile, votez !
  • Signaler ce message aux modérateurs
Par moncey, le mercredi 20 février 2008 à 21:36:09 Fil de Discussions
jlpjlp,

Prends en compte les rapports ci-dessous, j'ai eu droit à plusieurs messages de Spybot Search & Destroy.
Voici donc le rapport Hijackthis :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:29:29, on 20/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
E:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
E:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE
E:\Program Files\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
E:\Program Files\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\WINDOWS\System32\FTRTSVC.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
E:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
E:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Wanadoo\Watch.exe
C:\PROGRA~1\Wanadoo\WOOBrowser\WOOBrowser.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\MSN Messenger\usnsvc.exe
E:\hijackthis\eden.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Module - {221BBF54-3327-4548-9006-84385B1A5840} - ssymman.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: NTIECatcher Class - {C56CB6B0-0D96-11D6-8C65-B2868B609932} - E:\Program Files\NetTransport 2\NTIEHelper.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [avast!] E:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [EPSON Stylus DX3800 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIACE.EXE /P26 "EPSON Stylus DX3800 Series" /O6 "USB001" /M "Stylus DX3800"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "E:\Program Files\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe EspaceWanadoo.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] E:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: GigaTribe.lnk = E:\Program Files\GigaTribe\gigatribe.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Lancement rapide d'Adobe Acrobat.lnk = ?
O4 - Global Startup: Lancement rapide de Microsoft Office OneNote 2003.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: &Télécharger avec NetTransport - E:\Program Files\NetTransport 2\NTAddLink.html
O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Tout t&élécharger avec NetTransport - E:\Program Files\NetTransport 2\NTAddList.html
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - E:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.wanadoo.fr (file missing) (HKCU)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\..\{DB51C8BA-3ED8-43F5-8056-E6472502D077}: NameServer = 81.253.149.1 80.10.246.3
O20 - Winlogon Notify: sysfldr - C:\WINDOWS\SYSTEM32\sysfldr.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - E:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - E:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - E:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - E:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - E:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - E:\Program Files\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
End of file - 9508 bytes

Et voicl le rapport Combofix :

ComboFix 08-02-20.2 - Famille Moncey 2008-02-20 21:31:53.3 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.583 [GMT 1:00]
Endroit: C:\Documents and Settings\Famille Moncey\Bureau\combofix.exe

[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.

((((((((((((((((((((((((((((( Fichiers créés 2008-01-20 to 2008-02-20 ))))))))))))))))))))))))))))))))))))
.

2008-02-20 21:12 . 2008-02-20 21:12 <REP> d-------- C:\Documents and Settings\Famille Moncey\Application Data\Grisoft
2008-02-20 21:12 . 2008-02-20 21:12 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-20 21:12 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-20 11:25 . 2008-02-20 11:25 21,632 --a------ C:\WINDOWS\system32\drivers\Yyg66.sys
2008-02-20 11:25 . 2008-02-20 11:25 7,168 --a------ C:\WINDOWS\system32\WLCtrl32.dll
2008-02-20 08:47 . 2008-02-20 20:53 5,120 --a------ C:\Documents and Settings\LocalService\ftpdll.dll
2008-02-19 18:15 . 2008-02-19 18:15 <REP> d-------- C:\WINDOWS\Sun
2008-02-19 18:11 . 2008-02-20 20:53 5,120 --a------ C:\WINDOWS\system32\ftpdll.dll
2008-02-18 21:18 . 2008-02-18 21:25 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-18 21:14 . 2008-02-18 21:15 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-18 21:13 . 2008-02-18 21:13 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-02-17 19:02 . 2008-02-17 19:02 <REP> d-------- C:\Documents and Settings\Famille Moncey\Application Data\vlc
2008-02-17 18:55 . 2003-08-29 00:55 423,424 --a------ C:\WINDOWS\system32\WMAVDS32.ax
2008-02-17 18:55 . 2001-03-26 03:41 245,760 --a------ C:\WINDOWS\system32\mp4sds32.ax
2008-02-17 17:45 . 2008-02-17 17:46 <REP> d-------- C:\Program Files\ABBYY FineReader 6.0 Sprint
2008-02-17 17:32 . 2008-02-17 17:35 <REP> d-------- C:\Documents and Settings\All Users\Application Data\UDL
2008-02-17 17:28 . 2004-11-25 06:07 79,679 --a------ C:\WINDOWS\system32\E_FLMACE.DLL
2008-02-17 17:28 . 2003-05-21 03:27 64,000 --a------ C:\WINDOWS\system32\E_FBCBACE.DLL
2008-02-17 17:28 . 2004-09-10 21:12 49,152 --a------ C:\WINDOWS\system32\E_DCINST.DLL
2008-02-17 17:28 . 2000-06-07 02:01 34,304 --a------ C:\WINDOWS\system32\E_FBCHACE.DLL
2008-02-17 17:28 . 2004-08-03 23:01 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2008-02-17 17:28 . 2004-08-03 23:01 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2008-02-17 17:27 . 2004-08-03 23:08 31,616 --a------ C:\WINDOWS\system32\drivers\usbccgp.sys
2008-02-17 17:27 . 2004-08-03 23:08 31,616 --a--c--- C:\WINDOWS\system32\dllcache\usbccgp.sys
2008-02-17 17:27 . 2004-08-03 22:58 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2008-02-17 17:27 . 2004-08-03 22:58 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2008-02-17 17:26 . 2008-02-17 17:33 <REP> d-------- C:\Program Files\epson
2008-02-17 17:26 . 2005-02-25 00:00 46,080 --a------ C:\WINDOWS\system32\escimgd.dll
2008-02-17 17:26 . 2005-02-25 00:00 29,696 --a------ C:\WINDOWS\system32\escwiad.dll
2008-02-17 17:26 . 2005-02-25 00:00 22,016 --a------ C:\WINDOWS\system32\esccmd.dll
2008-02-17 17:26 . 2008-02-17 17:26 25 --a------ C:\WINDOWS\CDE DX3800EFGIPSD.ini
2008-02-17 17:24 . 2002-01-23 18:10 86,016 --a------ C:\WINDOWS\unvise32qt.exe
2008-02-17 17:23 . 2008-02-17 17:24 <REP> d-------- C:\Program Files\QuickTime
2008-02-17 17:23 . 2008-02-17 17:24 <REP> d-------- C:\Documents and Settings\All Users\Application Data\QuickTime
2008-02-17 17:22 . 2008-02-17 17:22 <REP> d-------- C:\Program Files\Fichiers communs\Kodak
2008-02-17 17:21 . 2008-02-17 17:21 <REP> d-------- C:\WINDOWS\system32\color
2008-02-17 17:21 . 2008-02-17 17:21 <REP> d-------- C:\KPCMS
2008-02-17 17:18 . 2008-02-17 17:23 <REP> d-------- C:\Program Files\Kodak
2008-02-17 17:18 . 2008-02-17 17:18 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Kodak
2008-02-17 16:36 . 2008-02-17 20:44 116 --a------ C:\WINDOWS\NeroDigital.ini
2008-02-17 14:25 . 2008-02-20 18:22 200 --a------ C:\Documents and Settings\Famille Moncey\Application Data\wklnhst.dat
2008-02-17 09:02 . 2008-02-17 09:02 <REP> d-------- C:\Documents and Settings\Famille Moncey\Application Data\GigaTribe
2008-02-16 23:03 . 2008-02-16 23:03 268 --ah----- C:\sqmdata01.sqm
2008-02-16 23:03 . 2008-02-16 23:03 244 --ah----- C:\sqmnoopt01.sqm
2008-02-16 22:51 . 2008-02-17 13:47 <REP> d-------- C:\Documents and Settings\Famille Moncey\Application Data\LimeWire
2008-02-16 22:41 . 2008-02-16 22:41 <REP> d-------- C:\Documents and Settings\Famille Moncey\Application Data\AdobeUM
2008-02-16 22:34 . 2007-12-14 01:59 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-02-16 22:29 . 2008-02-16 22:29 <REP> d-------- C:\Program Files\Fichiers communs\Java
2008-02-16 22:10 . 2007-07-09 14:11 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-02-16 21:51 . 2008-02-16 21:51 43,150 ---hs---- C:\WINDOWS\system32\drivers\spools.exe
2008-02-16 21:42 . 2008-02-17 09:02 <REP> d-------- C:\Documents and Settings\Famille Moncey\Contacts
2008-02-16 21:41 . 2008-02-16 21:41 <REP> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-02-16 21:41 . 2008-02-16 22:58 <REP> d-------- C:\Program Files\MSN Messenger
2008-02-16 21:41 . 2008-02-16 21:41 268 --ah----- C:\sqmdata00.sqm
2008-02-16 21:41 . 2008-02-16 21:41 244 --ah----- C:\sqmnoopt00.sqm
2008-02-16 21:36 . 2008-02-16 21:36 <REP> d-------- C:\Program Files\Fichiers communs\Adobe Systems Shared
2008-02-16 21:36 . 2008-02-16 21:36 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-02-16 21:33 . 2008-02-16 21:33 <REP> d-------- C:\Program Files\Fichiers communs\Adobe
2008-02-16 21:21 . 2008-02-16 21:22 <REP> d-------- C:\Program Files\Microsoft AutoRoute
2008-02-16 21:20 . 2008-02-16 21:20 <REP> d-------- C:\Program Files\Encarta
2008-02-16 21:18 . 2008-02-16 21:20 <REP> d-------- C:\Program Files\Picture It! Premium 10
2008-02-16 21:17 . 2008-02-16 21:18 <REP> d-------- C:\Program Files\microsoft money 2005
2008-02-16 21:16 . 2008-02-16 21:17 <REP> d-------- C:\Program Files\Microsoft Works
2008-02-16 21:15 . 2008-02-16 21:15 <REP> d-------- C:\Program Files\Microsoft Works Suite 2005
2008-02-16 21:13 . 2008-02-17 16:37 <REP> d-------- C:\Documents and Settings\Famille Moncey\Application Data\Ahead
2008-02-16 21:12 . 2008-02-16 21:12 <REP> d-------- C:\Program Files\Realtek AC97
2008-02-16 21:10 . 2008-02-16 21:10 <REP> d-------- C:\Program Files\Nero
2008-02-16 21:10 . 2008-02-16 21:10 <REP> d-------- C:\Program Files\Fichiers communs\Ahead
2008-02-16 21:08 . 2008-02-16 21:08 <REP> d-------- C:\Program Files\Windows Live
2008-02-16 21:08 . 2008-02-16 21:18 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-02-16 21:08 . 2008-02-16 21:08 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-16 21:07 . 2008-02-16 23:11 <REP> d--h----- C:\WINDOWS\$hf_mig$
2008-02-16 21:03 . 2007-07-30 19:19 43,352 --a------ C:\WINDOWS\system32\wups2.dll
2008-02-16 21:03 . 2007-07-30 19:19 38,232 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-02-16 21:03 . 2007-07-30 19:20 30,040 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-02-16 21:03 . 2007-07-30 19:19 30,040 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-02-16 21:03 . 2007-07-30 19:18 21,336 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-02-16 20:59 . 2008-02-16 20:59 <REP> d---s---- C:\Documents and Settings\Famille Moncey\UserData
2008-02-16 20:40 . 2008-02-16 20:40 <REP> d-------- C:\Documents and Settings\LocalService\Menu Démarrer
2008-02-16 19:35 . 2004-08-19 16:09 2,113,536 --------- C:\WINDOWS\system32\dxdiagn.dll
2008-02-16 19:34 . 2008-02-16 19:34 <REP> d-------- C:\WINDOWS\ServicePackFiles
2008-02-16 19:32 . 2005-06-28 10:21 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-02-16 19:32 . 2004-07-17 11:40 19,528 --a------ C:\WINDOWS\[u]002211_.tmp
2008-02-16 19:31 . 2008-02-16 19:35 <REP> d-------- C:\WINDOWS\EHome

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-20 20:31 --------- d-----w C:\Program Files\Wanadoo
2008-02-17 16:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-17 16:38 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-02-16 21:34 --------- d-----w C:\Program Files\Java
2008-02-16 17:32 --------- d-----w C:\Program Files\DVD Shrink
2008-02-16 17:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-02-16 17:31 --------- d-----w C:\Program Files\VideoLAN
2008-02-16 17:19 --------- d-----w C:\Program Files\Microsoft.NET
2008-02-16 16:38 --------- d-----w C:\Program Files\Wanadoo Messager
2008-02-16 16:26 --------- d-----w C:\Program Files\microsoft frontpage
2008-02-16 16:25 558,142 ----a-w C:\WINDOWS\java\Packages\HZ5F7HFB.ZIP
2008-02-16 16:25 155,995 ----a-w C:\WINDOWS\java\Packages\A0WK5VJ5.ZIP
2008-02-16 16:23 --------- d-----w C:\Program Files\Services en ligne
2008-01-10 12:16 159,839 ----a-w C:\WINDOWS\system32\xvidvfw.dll
20