J'espère que c bon, en redémarrant msn c connecté automatiquement
ComboFix 08-03-14.4 - Elise et vincent 2008-03-15 0:49:10.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.160 [GMT 1:00]
Endroit: C:\Documents and Settings\Elise et vincent\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM439f8f22.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\htfyjqhj.dll
C:\WINDOWS\system32\kvrvggtw.dll
C:\WINDOWS\system32\llnmp.ini
C:\WINDOWS\system32\llnmp.ini2
C:\WINDOWS\system32\pmnll.dll
C:\WINDOWS\system32\rmaqgpry.ini
C:\WINDOWS\system32\yrpgqamr.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\NPF
((((((((((((((((((((((((((((( Fichiers créés 2008-02-14 to 2008-03-14 ))))))))))))))))))))))))))))))))))))
.
2008-03-14 23:58 . 2008-03-14 23:58 <REP> d-------- C:\WINDOWS\LastGood.Tmp
2008-03-14 23:51 . 2008-03-14 23:51 <REP> d-------- C:\Program Files\Trend Micro
2008-03-14 23:42 . 2008-03-15 00:26 <REP> d-------- C:\Program Files\Lopxp
2008-03-14 23:21 . 2008-03-14 23:21 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-03-14 23:20 . 2008-03-14 23:20 <REP> d-------- C:\Program Files\Yahoo!
2008-03-10 20:31 . 2008-03-10 20:31 <REP> d-------- C:\Program Files\SFR ADSL
2008-03-10 20:30 . 2008-03-10 20:30 <REP> d-------- C:\WINDOWS\SFR_ADSL
2008-03-10 20:30 . 2008-03-10 20:30 <REP> d-------- C:\Documents and Settings\Elise et vincent\Application Data\InstallShield
2008-03-10 20:30 . 2008-03-10 20:30 27,072 --a------ C:\WINDOWS\system32\drivers\TV_551805_Sp50.sys
2008-03-08 09:41 . 2008-03-08 09:41 26,048 --a------ C:\WINDOWS\system32\efccyyw.dll
2008-03-01 11:01 . 2008-03-01 11:01 <REP> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2008-03-01 11:01 . 2006-11-29 13:06 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
2008-02-23 16:44 . 2008-02-23 16:44 <REP> d-------- C:\Program Files\Windows Media Connect 2
2008-02-23 16:42 . 2008-02-23 16:42 <REP> d-------- C:\WINDOWS\system32\LogFiles
2008-02-23 16:42 . 2008-02-23 16:43 <REP> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-02-17 16:53 . 2008-02-17 16:53 <REP> d-------- C:\Program Files\Hofmann
2008-02-17 16:47 . 2008-02-17 16:47 <REP> d-------- C:\WINDOWS\system32\URTTemp
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-10 20:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-03-10 19:32 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-10 16:49 --------- d-----w C:\Program Files\Google
2008-03-08 08:04 --------- d-----w C:\Program Files\Java
2008-03-02 10:53 --------- d-----w C:\Program Files\Windows Live
2008-03-01 09:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-29 15:26 --------- d-----w C:\Documents and Settings\Elise et vincent\Application Data\dvdcss
2008-02-08 14:56 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-02-01 10:17 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
2008-01-30 19:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Bluetooth
2008-01-13 13:08 87,608 ----a-w C:\Documents and Settings\Elise et vincent\Application Data\inst.exe
2008-01-13 13:08 47,360 ----a-w C:\Documents and Settings\Elise et vincent\Application Data\pcouffin.sys
2008-01-10 07:45 16,752 ----a-w C:\Documents and Settings\Elise et vincent\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}]
2008-03-08 09:41 26048 --a------ C:\WINDOWS\system32\efccyyw.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2005-03-24 14:20 77824 C:\WINDOWS\SOUNDMAN.EXE]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"Realtime Monitor"="E:\Program Files\CA\eTrustITM\realmon.exe" [2005-12-10 01:57 274432]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"EPSON Stylus DX4200 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAEE.exe" [2005-03-08 05:00 98304]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-05 13:00 110592 C:\WINDOWS\system32\bthprops.cpl]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 13:00 15360]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}"= C:\WINDOWS\system32\efccyyw.dll [2008-03-08 09:41 26048]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efccyyw]
efccyyw.dll 2008-03-08 09:41 26048 C:\WINDOWS\system32\efccyyw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"E:\\Program Files\\CA\\eTrustITM\\Apache\\bin\\Apache.exe"=
"C:\\WINDOWS\\system32\\msiexec.exe"=
"E:\\Program Files\\CA\\eTrustITM\\InoRpc.exe"=
"E:\\Program Files\\CA\\eTrustITM\\InoNmSrv.exe"=
"E:\\Program Files\\CA\\eTrustITM\\Realmon.exe"=
"E:\\Program Files\\CA\\eTrustITM\\Shellscn.exe"=
"E:\\Program Files\\CA\\eTrustITM\\inoweb.exe"=
"E:\\Program Files\\CA\\SharedComponents\\ThirdParty\\Tomcat\\5.5\\bin\\tomcat5.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"E:\\Program Files\\IVT Corporation\\BlueSoleil\\BlueSoleil.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R2 Alert Notification Server;Alert Notification Server;"E:\Program Files\CA\SharedComponents\Alert\ALERT.EXE" [2005-09-21 17:52]
R2 ApacheTomcatApplicationServer;Apache Tomcat Application Server;"E:\Program Files\CA\SharedComponents\ThirdParty\Tomcat\5.5\Bin\Tomcat5.exe" //RS//ApacheTomcatApplicationServer []
R2 InoNmSrv;eTrust ITM Server Service;"E:\Program Files\CA\eTrustITM\InoNmSrv.exe" [2007-12-28 21:51]
R2 InoWeb;eTrust ITM Web Access Service;"E:\Program Files\CA\eTrustITM\inoweb.exe" [2007-12-28 21:51]
S2 ApacheContentServer;Apache Content Server;"E:\Program Files\CA\eTrustITM\Apache\Bin\Apache.exe" -k runservice []
S3 TV_551805_Sp50;TV_551805_Sp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\TV_551805_Sp50.sys [2008-03-10 20:30]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-15 00:53:45
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs a chargé sous des processus courants ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\efccyyw.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\Ati2evxx.exe
E:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
E:\Program Files\CA\SharedComponents\iTechnology\igateway.exe
C:\WINDOWS\system32\rundll32.exe
E:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe
E:\Program Files\CA\eTrustITM\InoRpc.exe
E:\Program Files\CA\eTrustITM\InoRT.exe
E:\Program Files\CA\eTrustITM\InoTask.exe
C:\WINDOWS\system32\imapi.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\locator.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-03-15 0:55:33 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-14 23:55:30
.
2008-03-13 21:11:08 --- E O F ---