okay voila
ComboFix 08-03-14.4 - Philippe 2008-03-16 19:00:06.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.1.1252.1.1036.18.153 [GMT 1:00]
Endroit: C:\Documents and Settings\Philippe.PHILIPPE-ZVMRVT\Bureau\Killvundo.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\BM8f0f33ed.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\amuufucl.dll
C:\WINDOWS\system32\bgttbhth.dll
C:\WINDOWS\system32\bsjedmsm.dll
C:\WINDOWS\system32\bwmrobbb.dll
C:\WINDOWS\system32\eshetiha.dll
C:\WINDOWS\system32\fyivimed.dll
C:\WINDOWS\system32\gptvchoy.ini
C:\WINDOWS\system32\gviruomj.dll
C:\WINDOWS\system32\gwpnciyi.dll
C:\WINDOWS\system32\ibbbpvor.dll
C:\WINDOWS\system32\jasgpdma.dll
C:\WINDOWS\system32\jmllm.ini
C:\WINDOWS\system32\jmllm.ini2
C:\WINDOWS\system32\jqqrquyc.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\mllmj.dll
C:\WINDOWS\system32\nljcjaur.dll
C:\WINDOWS\system32\nwtnrkoy.dll
C:\WINDOWS\system32\pmnopmj.dll
C:\WINDOWS\system32\uhntnjkx.dll
C:\WINDOWS\system32\uixlpxww.dll
C:\WINDOWS\system32\xilioufy.dll
C:\WINDOWS\system32\xvhfxnuv.dll
C:\WINDOWS\system32\ydfmdiaw.dll
C:\WINDOWS\system32\ydpaixng.dll
C:\WINDOWS\system32\yohcvtpg.dll
C:\WINDOWS\system32\yswrfqah.dll
.
((((((((((((((((((((((((((((( Fichiers créés 2008-02-16 to 2008-03-16 ))))))))))))))))))))))))))))))))))))
.
2008-03-16 18:37 . 2008-03-16 18:37 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2008-03-16 18:31 . 2008-03-16 18:39 <REP> d----c--- C:\VundoFix Backups
2008-03-16 18:31 . 2008-03-16 18:31 <REP> d-------- C:\Program Files\Sunbelt Software
2008-03-16 14:48 . 2008-03-16 14:48 <REP> d----c--- C:\Documents and Settings\Philippe.PHILIPPE-ZVMRVT\Application Data\Grisoft
2008-03-16 14:48 . 2008-03-16 14:48 <REP> d----c--- C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft
2008-03-16 14:48 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-16 14:21 . 2008-03-16 14:21 <REP> d-------- C:\Program Files\CCleaner
2008-03-16 13:59 . 2008-03-16 18:27 <REP> d-------- C:\Program Files\Navilog1
2008-03-15 13:11 . 2008-03-16 13:12 752 ---hs---- C:\WINDOWS\system32\aunhekqb.ini
2008-03-14 22:47 . 2008-03-15 19:29 22,328 --a------ C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-03-14 22:46 . 2008-03-15 19:29 103,736 --a------ C:\WINDOWS\system32\PnkBstrB.exe
2008-03-14 22:33 . 2008-03-14 22:33 66,872 --a------ C:\WINDOWS\system32\PnkBstrA.exe
2008-03-14 21:17 . 2008-03-15 17:01 <REP> d-------- C:\Program Files\a-squared Free
2008-03-14 10:06 . 2008-03-15 13:11 5,146 ---hs---- C:\WINDOWS\system32\nnbycyyn.ini
2008-03-13 10:05 . 2008-03-14 10:05 4,786 ---hs---- C:\WINDOWS\system32\phgmdfvs.ini
2008-03-12 10:01 . 2008-03-13 10:01 4,006 ---hs---- C:\WINDOWS\system32\nsssygyd.ini
2008-03-11 08:47 . 2008-03-12 09:58 2,806 ---hs---- C:\WINDOWS\system32\skbiygpd.ini
2008-03-09 21:33 . 2008-03-11 08:44 2,094 ---hs---- C:\WINDOWS\system32\budidrwd.ini
2008-03-09 15:06 . 2008-03-09 15:06 108,144 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-03-08 21:32 . 2008-03-09 21:33 1,674 ---hs---- C:\WINDOWS\system32\feyffjao.ini
2008-03-08 12:38 . 2008-03-08 12:38 <REP> d----c--- C:\Documents and Settings\Philippe.PHILIPPE-ZVMRVT\Application Data\PC Tools
2008-03-08 12:38 . 2008-03-08 19:06 <REP> d-a--c--- C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-03-08 12:38 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-03-08 12:38 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-03-08 12:38 . 2008-02-01 12:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-03-08 12:38 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-03-08 12:37 . 2008-03-08 12:37 164 --a--c--- C:\install.dat
2008-03-08 12:35 . 2008-03-08 12:35 <REP> d----c--- C:\Documents and Settings\All Users.WINDOWS\Application Data\Prevx
2008-03-08 12:29 . 2008-03-08 12:29 <REP> d-------- C:\WINDOWS\system32\GroupPolicy
2008-03-07 21:36 . 2008-03-08 15:53 894 ---hs---- C:\WINDOWS\system32\feaiwwlc.ini
2008-03-06 21:34 . 2008-03-07 21:35 534 ---hs---- C:\WINDOWS\system32\mlwxvtya.ini
2008-03-06 21:26 . 2008-03-06 21:26 <REP> d-------- C:\Documents and Settings\PHILIP~1~PHI\LOCALS~1
2008-03-06 20:25 . 2008-03-06 20:25 <REP> d----c--- C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
2008-03-05 20:55 . 2008-03-15 15:02 <REP> d----c--- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-02-21 02:57 . 2008-02-21 02:57 54,608 --a------ C:\WINDOWS\system32\xfcodec.dll
2008-02-17 13:58 . 2008-02-17 13:58 <REP> d-------- C:\WINDOWS\Sun
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-16 18:08 --------- d-----w C:\Program Files\Wanadoo
2008-03-16 17:27 --------- dc----w C:\Documents and Settings\Philippe.PHILIPPE-ZVMRVT\Application Data\Xfire
2008-03-14 21:34 729,088 ----a-w C:\WINDOWS\iun6002.exe
2008-03-14 19:18 --------- d-----w C:\Program Files\Xfire
2008-03-12 09:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-12 09:30 --------- d-----w C:\Program Files\EA Games
2008-03-11 12:43 --------- dc----w C:\Documents and Settings\Philippe.PHILIPPE-ZVMRVT\Application Data\LimeWire
2008-03-06 19:24 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-01-22 19:05 17,536 -c--a-w C:\Documents and Settings\Philippe.PHILIPPE-ZVMRVT\Application Data\GDIPFONTCACHEV1.DAT
2008-01-18 19:06 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2008-01-04 23:45 98,304 ----a-w C:\WINDOWS\system32\Rey_SubClasser.dll
2007-07-01 13:28 278,528 ----a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2002-08-29 12:45 13312]
"WOOKIT"="C:\Program Files\Wanadoo\Shell.exe" [2004-08-23 13:50 122880]
"Steam"="" []
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-09-29 06:15 344064]
"Lexmark 2200 Series"="C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe" [2004-02-13 14:13 57344]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 08:41 282624]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00 132496]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-06-28 08:14 270648]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2002-08-29 12:45 13312]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Program Files\BitTorrent\bittorrent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
C:\Program Files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
C:\Program Files\ICQ6\ICQ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ Lite]
D:\Program Files\ICQLite\ICQLite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 12:55 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shareaza]
C:\Program Files\Shareaza\Shareaza.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
D:\Jeux Tout Prêts\Valve\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOWATCH]
C:\PROGRA~1\Wanadoo\Watch.exe
R1 fwdrv;Firewall Driver;C:\WINDOWS\System32\drivers\fwdrv.sys [2007-04-26 10:21]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\System32\drivers\khips.sys [2007-04-26 10:21]
R2 SPF4;Sunbelt Personal Firewall 4;"C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe" [2007-04-26 10:21]
R3 usbscan;Pilote de scanneur USB;C:\WINDOWS\System32\DRIVERS\usbscan.sys [2002-08-29 00:48]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2002-08-29 00:32]
*Newly Created Service* - ALG
*Newly Created Service* - IPNAT
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-03-13 09:51:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-16 19:08:00
Windows 5.1.2600 Service Pack 1 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\WINDOWS\System32\PnkBstrA.exe
C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-03-16 19:10:57 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-16 18:10:48
PS: cette fois ci jai laissé kerio et il na rien detecté peut-etre un espoir.....