1° - Lignes ci-dessus bien fixer !!!
2° - StarWindService bien Desactiver. Ps: Non je n'ai pas Xp2000
3° - Par contre je n'ai pas reussi a obtenir de rapport avec NOD32, mais les resultat du scan sont Negatif aucun danger trouver.
J'ai bien scanner le Pc avec ATF_Cleaner en Mode sans Echec, et Combofix a Bien fait son travail, Voici le Log :
ComboFix 08-02-22.2 - jonathan 2008-02-22 15:02:02.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.1575 [GMT 1:00]
Endroit: C:\Documents and Settings\jonathan\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\winsys.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2008-01-22 to 2008-02-22 ))))))))))))))))))))))))))))))))))))
.
2008-02-22 11:49 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\362f7938.dll
2008-02-22 11:49 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\69a8ff4.dll
2008-02-22 11:31 . 2008-02-22 11:31 <REP> d-------- C:\Program Files\Trend Micro
2008-02-22 11:20 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\8904c5c.dll
2008-02-22 11:20 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\10cf680.dll
2008-02-22 10:58 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\35d874b.dll
2008-02-22 10:58 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\10abf030.dll
2008-02-22 10:58 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\2fd7d00.dll
2008-02-22 10:58 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\15e176c1.dll
2008-02-22 10:26 . 2008-02-22 12:15 <REP> d-------- C:\Program Files\EsetOnlineScanner
2008-02-22 10:23 . 2008-02-22 10:23 122 --a------ C:\WINDOWS\system32\privacy.xml
2008-02-21 20:44 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\19770d4.dll
2008-02-21 16:09 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\13d4f351.dll
2008-02-21 15:43 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\50ab18.dll
2008-02-21 15:43 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\167dc14b.dll
2008-02-21 15:43 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\b238d76.dll
2008-02-21 15:43 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\1e17a210.dll
2008-02-21 14:02 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\e734140.dll
2008-02-21 14:02 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\8c9101e.dll
2008-02-21 02:37 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\81ee10c.dll
2008-02-21 02:37 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\17f4c8df.dll
2008-02-21 00:24 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\a0f40d2.dll
2008-02-21 00:24 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\ab6ed0.dll
2008-02-21 00:22 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\549e1.dll
2008-02-21 00:22 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\1f901b14.dll
2008-02-21 00:22 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\6a58404.dll
2008-02-21 00:22 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\14a2ece4.dll
2008-02-20 23:57 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\f668be.dll
2008-02-20 23:57 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\4cf2b4.dll
2008-02-20 23:57 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\1fc1a1ae.dll
2008-02-20 23:57 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\162060.dll
2008-02-20 23:56 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\78f704.dll
2008-02-20 23:56 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\3110f64.dll
2008-02-20 23:56 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\c8edf40.dll
2008-02-20 23:56 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\bebc7fd.dll
2008-02-20 23:15 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\1130b266.dll
2008-02-20 23:08 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\5a72b50.dll
2008-02-20 21:55 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\63a0128.dll
2008-02-20 21:55 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\1f49a98c.dll
2008-02-20 19:43 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\17c4f7e8.dll
2008-02-20 19:02 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\17da026c.dll
2008-02-20 19:02 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\2cc3180.dll
2008-02-20 18:25 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\21f7a891.dll
2008-02-20 18:25 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\4565cc5.dll
2008-02-20 17:47 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\75288a.dll
2008-02-20 17:47 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\216af51.dll
2008-02-20 17:47 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\2e3eaa61.dll
2008-02-20 17:47 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\1f00117f.dll
2008-02-20 17:42 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\211da5d0.dll
2008-02-20 14:21 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\7bbb97d.dll
2008-02-20 14:21 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\12550a60.dll
2008-02-20 14:21 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\7d5e318.dll
2008-02-20 14:21 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\460ec00.dll
2008-02-20 13:55 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\248ab83e.dll
2008-02-20 13:55 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\18f63db0.dll
2008-02-20 13:55 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\dc3500.dll
2008-02-20 13:55 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\1638f28b.dll
2008-02-20 01:26 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\e8330da.dll
2008-02-19 23:35 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\128a1490.dll
2008-02-17 16:23 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\364e97c.dll
2008-02-17 16:23 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\13b792b9.dll
2008-02-17 16:23 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\24d27368.dll
2008-02-17 16:23 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\13fc1af6.dll
2008-02-17 14:28 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\209bf082.dll
2008-02-17 13:53 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\96c2fcf.dll
2008-02-17 02:18 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\a79a72.dll
2008-02-17 02:05 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\1c1fe782.dll
2008-02-16 14:28 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\821fd3.dll
2008-02-16 14:28 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\80373ba.dll
2008-02-16 14:28 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\661fc.dll
2008-02-16 14:28 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\99c2d4c.dll
2008-02-16 14:28 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\10f1088.dll
2008-02-15 19:07 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\177b392c.dll
2008-02-15 18:27 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\ad42837.dll
2008-02-15 18:27 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\25e72ab.dll
2008-02-15 18:27 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\63a4614.dll
2008-02-15 18:27 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\4653ccc.dll
2008-02-15 18:27 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\132d178a.dll
2008-02-15 10:26 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\8a71e23.dll
2008-02-15 10:19 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\22d47bba.dll
2008-02-15 10:19 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\7fdb9eb.dll
2008-02-15 10:16 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\1d032d08.dll
2008-02-15 10:16 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\251d9e1.dll
2008-02-14 23:16 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\5f168be.dll
2008-02-14 23:16 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\2484780.dll
2008-02-14 22:13 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\a89972a.dll
2008-02-14 22:13 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\30c460b0.dll
2008-02-14 22:13 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\21ebb22c.dll
2008-02-14 22:13 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\10d6cf3e.dll
2008-02-14 21:45 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\10ccf8.dll
2008-02-14 19:38 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\57721e0.dll
2008-02-14 19:38 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\10e15211.dll
2008-02-14 19:38 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\3853b580.dll
2008-02-14 19:30 . 2008-02-14 19:30 <REP> d-------- C:\Program Files\BitDefender
2008-02-14 19:30 . 2008-02-14 19:30 <REP> d-------- C:\Documents and Settings\LocalService\Menu Démarrer
2008-02-14 19:15 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\83dcb00.dll
2008-02-14 19:15 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\48b3f84.dll
2008-02-14 19:15 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\30697d20.dll
2008-02-14 19:15 . 2006-03-02 13:00 1,689,088 --a------ C:\WINDOWS\system32\21c27924.dll
2008-02-14 19:15 . 2006-03-02 13:00 82,944 --a------ C:\WINDOWS\system32\e517fad.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-21 19:43 --------- d-----w C:\Documents and Settings\jonathan\Application Data\teamspeak2
2008-02-14 18:30 85,520 ----a-w C:\WINDOWS\system32\drivers\bdfndisf.sys
2008-02-11 20:32 --------- d-----w C:\Documents and Settings\jonathan\Application Data\DMCache
2008-02-01 18:09 81,984 ----a-w C:\WINDOWS\system32\bdod.bin
2008-01-30 14:38 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-30 14:38 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-01-28 09:44 --------- d--h--w C:\Program Files\MSN Messenger
2008-01-27 14:18 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-23 09:40 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-01-21 11:33 215,144 ----a-w C:\WINDOWS\patchw32.dll
2008-01-07 16:41 196,368 ----a-w C:\WINDOWS\system32\drivers\bdfsfltr.sys
2008-01-06 11:41 --------- d-----w C:\Documents and Settings\jonathan\Application Data\InstallShield
2007-12-07 02:08 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
2007-12-05 01:53 356,352 ----a-w C:\WINDOWS\system32\NVUNINST.EXE
2007-12-04 18:41 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
2007-11-27 15:46 77,824 ----a-w C:\WINDOWS\system32\xcomm.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{381FFDE8-2394-4F90-B10D-FC6124A40F8C}
[HKEY_CLASSES_ROOT\clsid\{381ffde8-2394-4f90-b10d-fc6124a40f8c}]
[HKEY_CLASSES_ROOT\BitDefender Toolbar]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 13:00 15360]
"NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" [2007-07-03 11:32 81920]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 09:59 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-05-27 03:47 16208384 C:\WINDOWS\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2006-05-16 11:04 2879488 C:\WINDOWS\SkyTel.exe]
"SW20"="C:\WINDOWS\system32\sw20.exe" [2006-06-01 10:22 208896]
"SW24"="C:\WINDOWS\system32\sw24.exe" [2006-06-01 10:22 69632]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"CoolSwitch"="C:\WINDOWS\system32\taskswitch.exe" [2002-03-19 17:30 45632]
"BackgroundSwitcher"="C:\WINDOWS\system32\bgswitch.exe" [2001-10-19 12:14 19520]
"FastUser"="C:\WINDOWS\system32\fast.exe" [2001-10-19 12:14 49216]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"razer"="D:\Program Files\Razer\Copperhead\razerhid.exe" [2005-10-08 16:27 155648]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776]
"nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920]
"BitDefender Antiphishing Helper"="D:\Program Files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 15:46 61440]
"BDAgent"="D:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" [2008-02-15 18:43 360448]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 13:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igndlm.exe]
D:\Program Files\IGN\Download Manager\DLM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2007-01-19 12:55 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PlayNC Launcher]
d:\program files\ncsoft\launcher\NCLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2007-11-30 13:42 1266936 d:\progra~1\steam\steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SuperCopier2.exe]
--a------ 2006-07-07 17:45 1052672 C:\Program Files\SuperCopier2\SuperCopier2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--------- 2006-11-03 09:59 204288 C:\Program Files\Windows Media Player\WMPNSCFG.exe
R1 bdftdif;bdftdif;C:\Program Files\Fichiers communs\BitDefender\BitDefender Firewall\bdftdif.sys [2008-02-05 17:17]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\WINDOWS\system32\DRIVERS\bdfndisf.sys [2008-02-14 19:30]
R3 bdfsfltr;bdfsfltr;C:\WINDOWS\system32\drivers\bdfsfltr.sys [2008-01-07 17:41]
R3 BDSelfPr;BDSelfPr;D:\Program Files\BitDefender\BitDefender 2008\bdselfpr.sys [2008-02-02 13:31]
R3 Razerlow;Razer Copperhead Driver;C:\WINDOWS\system32\Drivers\Razerlow.sys [2005-08-12 10:11]
R3 scan;BitDefender Threat Scanner;C:\WINDOWS\System32\svchost.exe [2006-03-02 13:00]
S3 ALSysIO;ALSysIO;C:\DOCUME~1\jonathan\LOCALS~1\Temp\ALSysIO.sys []
S3 uisp;Freescale USB JW32 driver;C:\WINDOWS\system32\Drivers\usbicp.sys [2001-01-04 10:12]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-22 15:03:31
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-02-22 15:03:48
ComboFix-quarantined-files.txt 2008-02-22 14:03:47
.
2008-02-14 00:58:07 --- E O F ---