Voila les rapports de VundoFix, VirtumundoBeGone et ComboFix :
*****************************************************************
VundoFix V6.7.8
Checking Java version...
Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.
Scan started at 11:31:01 24/02/2008
Listing files found while scanning....
C:\WINDOWS\system32\urqqolm.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\urqqolm.dll
C:\WINDOWS\system32\urqqolm.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\system32\urqqolm.dll
C:\WINDOWS\system32\urqqolm.dll Could not be deleted.
Performing Repairs to the registry.
Done!
************************************************************************
[02/24/2008, 11:55:26] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Jérôme\Bureau\VirtumundoBeGone.exe" )
[02/24/2008, 11:55:45] - Detected System Information:
[02/24/2008, 11:55:45] - Windows Version: 5.1.2600, Service Pack 2
[02/24/2008, 11:55:45] - Current Username: Jérôme (Admin)
[02/24/2008, 11:55:45] - Windows is in NORMAL mode.
[02/24/2008, 11:55:45] - Searching for Browser Helper Objects:
[02/24/2008, 11:55:45] - BHO 1: {02478D38-C3F9-4EFB-9B51-7695ECA05670} (Yahoo! Toolbar Helper)
[02/24/2008, 11:55:45] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/24/2008, 11:55:45] - BHO 3: {23D44BCF-AA7A-41D6-8905-E808F16322EF} ()
[02/24/2008, 11:55:45] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/24/2008, 11:55:45] - Checking for HKLM\...\Winlogon\Notify\urqqolm
[02/24/2008, 11:55:45] - Key not found: HKLM\...\Winlogon\Notify\urqqolm, continuing.
[02/24/2008, 11:55:45] - BHO 4: {2ef9162c-ce44-4d60-be31-8ed364e665ac} ()
[02/24/2008, 11:55:45] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/24/2008, 11:55:45] - Checking for HKLM\...\Winlogon\Notify\olgmgeoi
[02/24/2008, 11:55:45] - Key not found: HKLM\...\Winlogon\Notify\olgmgeoi, continuing.
[02/24/2008, 11:55:45] - BHO 5: {2F85D76C-0569-466F-A488-493E6BD0E955} (dsWebAllowBHO Class)
[02/24/2008, 11:55:45] - BHO 6: {5CA3D70E-1895-11CF-8E15-001234567890} (DriveLetterAccess)
[02/24/2008, 11:55:45] - BHO 7: {6E657B72-ED98-4B36-9FD9-69D61C844279} ()
[02/24/2008, 11:55:45] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/24/2008, 11:55:45] - Checking for HKLM\...\Winlogon\Notify\mljjj
[02/24/2008, 11:55:45] - Key not found: HKLM\...\Winlogon\Notify\mljjj, continuing.
[02/24/2008, 11:55:45] - BHO 8: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[02/24/2008, 11:55:45] - BHO 9: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[02/24/2008, 11:55:45] - BHO 10: {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} (Barre d'outils MSN Search Helper)
[02/24/2008, 11:55:45] - Finished Searching Browser Helper Objects
[02/24/2008, 11:55:45] - Finishing up...
[02/24/2008, 11:55:45] - Nothing found! Exiting...
*****************************************************************************************
ComboFix 08-02-15.1 - Jérôme 2008-02-24 11:57:46.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.1479 [GMT 1:00]
Endroit: C:\Documents and Settings\Jérôme\Bureau\Combo-Fix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Program Files\Helper
C:\WINDOWS\system32\kchpdbpu.ini
C:\WINDOWS\system32\urqqolm.dll
----- BITS: Possible sites infect‚s -----
hxxp://au.download.windowsupdate.c
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_MSUPDATE
-------\msupdate
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-01-24 to 2008-02-24 ))))))))))))))))))))))))))))))))))))
.
2008-02-24 10:37 . 2008-02-24 11:51 <REP> d-------- C:\VundoFix Backups
2008-02-24 10:17 . 2008-02-24 10:17 <REP> d-------- C:\Program Files\Yahoo!
2008-02-24 10:17 . 2008-02-24 10:18 <REP> d-------- C:\Program Files\CCleaner
2008-02-23 23:05 . 2008-02-23 23:05 8 --a------ C:\WINDOWS\system32\6450f617
2008-02-20 20:30 . 2008-02-20 20:30 <REP> d-------- C:\Program Files\Trend Micro
2008-02-19 22:10 . 2008-02-19 22:10 <REP> d-------- C:\Program Files\Avira
2008-02-19 22:10 . 2008-02-19 22:10 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-02-19 21:33 . 2008-02-19 21:33 <REP> d-------- C:\Program Files\RogueRemover FREE
2008-02-15 21:45 . 2008-02-15 21:45 54,762 --a------ C:\WINDOWS\system32\jkghje.dll
2008-02-15 21:45 . 2008-02-15 21:45 2 --a------ C:\1683022902
2008-02-15 21:39 . 2008-02-15 21:39 <REP> d-------- C:\temp
2008-02-15 21:19 . 2007-07-19 18:14 3,727,720 --a------ C:\WINDOWS\system32\d3dx9_35.dll
2008-02-15 21:19 . 2007-05-16 16:45 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll
2008-02-15 21:19 . 2007-07-19 18:14 1,358,192 --a------ C:\WINDOWS\system32\D3DCompiler_35.dll
2008-02-15 21:19 . 2007-05-16 16:45 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll
2008-02-15 21:19 . 2007-07-19 18:14 444,776 --a------ C:\WINDOWS\system32\d3dx10_35.dll
2008-02-15 21:19 . 2007-05-16 16:45 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll
2008-02-15 21:19 . 2007-07-20 00:57 267,112 --a------ C:\WINDOWS\system32\xactengine2_9.dll
2008-02-15 21:19 . 2007-06-20 20:46 266,088 --a------ C:\WINDOWS\system32\xactengine2_8.dll
2008-02-15 21:19 . 2007-01-24 15:27 255,848 --a------ C:\WINDOWS\system32\xactengine2_6.dll
2008-02-15 21:19 . 2007-07-20 00:54 18,280 --a------ C:\WINDOWS\system32\x3daudio1_2.dll
2008-02-15 21:02 . 2008-02-15 21:02 <REP> d-------- C:\Program Files\MagicDisc
2008-02-15 21:02 . 2008-02-11 23:36 92,544 --a------ C:\WINDOWS\system32\drivers\mcdbus.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-24 10:29 --------- d-----w C:\Program Files\Java
2008-02-24 09:40 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-02-24 08:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-02-19 20:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Media Center Programs
2008-02-15 20:17 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-06 08:31 --------- d-----w C:\Program Files\Neuf
2007-06-11 13:20 0 ----a-w C:\Documents and Settings\Christa\Application Data\wklnhst.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2ef9162c-ce44-4d60-be31-8ed364e665ac}]
C:\WINDOWS\system32\olgmgeoi.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6E657B72-ED98-4B36-9FD9-69D61C844279}]
C:\WINDOWS\system32\mljjj.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 13:00 15360]
"TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-11 15:08 65536]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24 1694208]
"Steam"="C:\Program Files\Valve\Steam\Steam.exe" [2007-12-04 23:36 1266936]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 12:34 64512]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 00:02 761948]
"RTHDCPL"="RTHDCPL.EXE" [2006-05-05 14:59 16206848 C:\WINDOWS\RTHDCPL.exe]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2004-08-18 11:37 184320]
"AGRSMMSG"="AGRSMMSG.exe" [2005-12-13 15:50 88204 C:\WINDOWS\agrsmmsg.exe]
"THotkey"="C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe" [2006-08-25 12:47 356352]
"TPSMain"="TPSMain.exe" [2005-08-03 15:09 266240 C:\WINDOWS\system32\TPSMain.exe]
"NDSTray.exe"="NDSTray.exe" []
"Tvs"="C:\Program Files\TOSHIBA\Tvs\TvsTray.exe" [2006-02-02 12:11 73728]
"SmoothView"="C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe" [2005-05-17 08:24 118784]
"TFncKy"="TFncKy.exe" []
"DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-10-06 04:20 122940]
"IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-08-02 00:38 802816]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-08-02 00:32 696320]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-11 23:12 49152]
"CFSServ.exe"="CFSServ.exe" []
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-02-03 21:56 223232]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 09:54 282624]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-05-01 21:04 7557120]
"nwiz"="nwiz.exe" [2006-05-01 21:04 1519616 C:\WINDOWS\system32\nwiz.exe]
"NVRotateSysTray"="C:\WINDOWS\system32\nvsysrot.dll" [2006-05-01 21:04 49152]
"6450e499"="C:\WINDOWS\system32\upbdphck.dll" [ ]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-19 22:12 249896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 13:00 15360]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-06-16 00:15 366400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2006-03-13 12:11 233472]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
"LoadAppInit_DLLs"=1 (0x1)
R3 X10Hid;X10 Hid Device;C:\WINDOWS\system32\Drivers\x10hid.sys [2005-11-28 09:45]
S3 tosrfec;Bluetooth ACPI from TOSHIBA;C:\WINDOWS\system32\DRIVERS\tosrfec.sys [2005-09-09 13:47]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-02-16 20:59:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-24 12:04:01
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\Program Files\TOSHIBA\Commandes TOSHIBA\TFncKy.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-02-24 12:09:44 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-24 11:09:40
.
2008-02-13 02:03:40 --- E O F ---