Slt jlp,
j'ai fais ce que tu m'as dis de faire, voici les rapports:
1° Rapport OTMoveIt:
C:\WINDOWS\system32\rchsxmfi.exe moved successfully.
C:\Documents and Settings\All Users\Application Data\vavcngni\razyrehg.exe moved successfully.
OTMoveIt2 by OldTimer - Version 1.0.21 log created on 03252008_190950
-------------------------------------------------------------------------
2° Rapport Combofix:
ComboFix 08-03-25.1 - g 2008-03-25 19:15:00.1 - [color=red][b]FAT32/b/colorx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.213 [GMT 1:00]
Endroit: C:\Documents and Settings\g\Bureau\KillBagle.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\dwnrpofk.dll
C:\WINDOWS\rs.txt
C:\WINDOWS\system32\drivers\npf.sys
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\WanPacket.dll
C:\WINDOWS\system32\wpcap.dll
.
((((((((((((((((((((((((((((( Fichiers créés 2008-02-25 to 2008-03-25 ))))))))))))))))))))))))))))))))))))
.
2008-03-25 19:09 . 2008-03-25 19:09 <REP> d-------- C:\_OTMoveIt
2008-03-24 20:44 . 2008-03-24 20:44 <REP> d-------- C:\Program Files\Trend Micro
2008-03-24 18:19 . 2008-03-24 18:25 3,358 --a------ C:\WINDOWS\system32\tmp.reg
2008-03-24 01:00 . 2008-03-24 01:00 <REP> d-------- C:\Program Files\TechSmith
2008-03-24 01:00 . 2008-03-24 01:00 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TechSmith
2008-03-24 00:58 . 2008-03-24 00:58 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-03-23 21:37 . 2008-03-23 21:37 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-23 21:31 . 2008-03-23 21:31 <REP> d-------- C:\Program Files\Trojan Remover
2008-03-23 21:31 . 2008-03-23 21:31 <REP> d-------- C:\Documents and Settings\g\Application Data\Simply Super Software
2008-03-23 16:11 . 2008-03-23 16:11 <REP> d-------- C:\Program Files\PC-Cleaner
2008-03-23 15:31 . 2008-03-23 15:31 <REP> d-------- C:\Documents and Settings\g\Bureauvirii
2008-03-23 15:31 . 2008-03-23 15:31 <REP> d-------- C:\Documents and Settings\All Users\Application Data\vavcngni
2008-03-23 15:31 . 2008-03-23 15:31 4,096 --a------ C:\Documents and Settings\g\BureauTrojan.Win32.BlackBird.exe
2008-03-23 15:31 . 2008-03-23 15:31 4,096 --a------ C:\Documents and Settings\g\BureauFWebdEditor.exe
2008-03-23 15:31 . 2008-03-23 15:31 4,096 --a------ C:\Documents and Settings\g\Bureaufwebd.exe
2008-03-23 15:31 . 2008-03-23 15:31 4,096 --a------ C:\Documents and Settings\g\Bureaufkwp2.0.exe
2008-03-23 15:31 . 2008-03-23 15:31 4,096 --a------ C:\Documents and Settings\g\Bureaufkwp1.5.exe
2008-03-23 15:31 . 2008-03-23 15:31 4,096 --a------ C:\Documents and Settings\g\Bureaufilemanagerclient.exe
2008-03-23 15:31 . 2008-03-23 15:31 4,096 --a------ C:\Documents and Settings\g\BureauEditorFKWP2.0.exe
2008-03-23 15:31 . 2008-03-23 15:31 4,096 --a------ C:\Documents and Settings\g\BureauEditorFKWP1.5.exe
2008-03-15 15:46 . 2008-03-15 15:46 <REP> d-------- C:\Program Files\bwin
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-23 08:04 212,992 ----a-w C:\WINDOWS\kdftlboeslg.dll
2008-02-09 22:10 --------- d-----w C:\Program Files\VoipBuster.com
2008-02-04 21:11 --------- d-----w C:\Program Files\VideoCap
2008-02-04 18:06 --------- d-----w C:\Program Files\Fichiers communs\AOL
2008-02-04 18:06 --------- d-----w C:\Program Files\AIM6
2008-01-11 05:36 44,544 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-06 01:15 68856]
"ccleaner"="C:\Program Files\CCleaner\ccleaner.exe" [2006-12-15 12:13 590728]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 05:00 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [2005-06-08 14:44 196608]
"VoipBuster"="C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe" [2008-01-17 15:54 8811824]
"ahwdibik"="C:\WINDOWS\system32\rchsxmfi.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-04 11:12 102490]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-04 11:11 708698]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"SoundMan"="SOUNDMAN.EXE" [2005-04-15 11:01 77824 C:\WINDOWS\SOUNDMAN.EXE]
"preload"="C:\Windows\RUNXMLPL.exe" [2005-05-19 17:09 32768]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 05:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 05:00 455168]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 05:00 59392]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-05 05:00 208952]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-08-24 12:50 94208]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-08-24 12:51 114688]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-08-24 12:47 77824]
"eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\Monitor.exe" [2006-01-24 18:00 397312]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-07-19 17:32 221184]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-06-08 15:24 458752]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-06-08 15:14 217088]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 05:00 15360]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
SnagIt 8.lnk - C:\Program Files\TechSmith\SnagIt 8\SnagIt32.exe [2007-02-16 18:40:52 6379080]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"MHKiJZQ5m8"= C:\Documents and Settings\All Users\Application Data\vavcngni\razyrehg.exe
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{93994DE8-8239-4655-B1D1-5F4E91300429}"= C:\PROGRA~1\DVDREG~1\DVDShell.dll [2004-10-09 15:18 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="LogonUI.EXE"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\VoipBuster.com\\VoipBuster\\VoipBuster.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Fichiers communs\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 Hotkey;Hotkey;C:\WINDOWS\system32\drivers\Hotkey.sys [2003-04-28 11:27]
R1 OsaFsLoc;OsaFsLoc;C:\WINDOWS\system32\drivers\OsaFsLoc.sys [2005-10-15 18:20]
R2 EpmPsd;Acer EPM Power Scheme Driver;C:\WINDOWS\system32\drivers\epm-psd.sys [2004-07-19 13:10]
R2 EpmShd;Acer EPM System Hardware Driver;C:\WINDOWS\system32\drivers\epm-shd.sys [2005-04-07 18:08]
R2 int15.sys;int15.sys;C:\Acer\Empowering Technology\eRecovery\int15.sys [2005-01-13 14:46]
R2 osaio;osaio;C:\WINDOWS\system32\drivers\osaio.sys [2005-06-30 16:58]
R2 osanbm;osanbm;C:\WINDOWS\system32\drivers\osanbm.sys [2005-01-14 15:57]
S3 NdisFilt;OSA NdisFilter Protocol;C:\WINDOWS\system32\Drivers\NdisFilt.sys [2005-09-13 15:34]
S3 P1001VID;Creative WebCam (WDM);C:\WINDOWS\system32\DRIVERS\P1001Vid.sys [2002-06-03 21:38]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - ie.exe
\Shell\explore\Command - ie.exe
\Shell\open\Command - ie.exe
*Newly Created Service* - INT15.SYS
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-01-28 17:24:04 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-25 19:17:00
Windows 5.1.2600 Service Pack 2 FAT NTAPI
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-03-25 19:17:26
ComboFix-quarantined-files.txt 2008-03-25 18:17:24
.
2008-03-20 00:14:49 --- E O F ---