Bonjour jlpjlp,
Voici le rapport avec le combofix
ComboFix 08-03-26.1 - robert 2008-03-27 11:40:23.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.2.1033.18.298 [GMT -4:00]
Running from: C:\Documents and Settings\robert\Desktop\Killbeagle.exe
* Created a new restore point
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!/b/color
.
TimedOut: progfile.dat
-- Script messages for sUBs --
GREP -Fis \baiso
VFind -td "C:\WINDOWS\system32\*"
Findstr -MIF:/ sursen
Findstr -MIF:/ "\\TTC\.pdb InsertAdvertisement"
GREP -Eisf temp00
VFind -tf -s282624 "C:\Program Files\????????*[0-9].dll"
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\akl
C:\Program Files\akl\akl.dll
C:\Program Files\akl\akl.exe
C:\Program Files\akl\uninstall.exe
C:\Program Files\akl\unsetup.exe
C:\WINDOWS\dwnrpofk.dll
C:\WINDOWS\qvdntlmw.dll
.
((((((((((((((((((((((((( Files Created from 2008-02-27 to 2008-03-27 )))))))))))))))))))))))))))))))
.
2008-03-27 11:28 . 2008-03-27 11:31 <DIR> d-------- C:\Hijackthis
2008-03-27 11:23 . 2008-03-27 11:23 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-27 08:17 . 2008-03-27 08:17 <DIR> d-------- C:\VundoFix Backups
2008-03-27 06:22 . 2008-03-27 06:22 110,592 --a------ C:\WINDOWS\system32\tmpmvkpy.exe
2008-03-26 20:54 . 2008-03-27 11:47 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-26 20:54 . 2008-03-27 11:47 1,409 --a------ C:\WINDOWS\QTFont.for
2008-03-26 18:28 . 2008-03-26 18:28 <DIR> d-------- C:\Documents and Settings\robert\Desktopvirii
2008-03-26 18:28 . 2008-03-26 18:28 4,096 --a------ C:\Documents and Settings\robert\DesktopTrojan.Win32.BlackBird.exe
2008-03-26 18:28 . 2008-03-26 18:28 4,096 --a------ C:\Documents and Settings\robert\DesktopFWebdEditor.exe
2008-03-26 18:28 . 2008-03-26 18:28 4,096 --a------ C:\Documents and Settings\robert\Desktopfwebd.exe
2008-03-26 18:28 . 2008-03-26 18:28 4,096 --a------ C:\Documents and Settings\robert\Desktopfkwp2.0.exe
2008-03-26 18:28 . 2008-03-26 18:28 4,096 --a------ C:\Documents and Settings\robert\Desktopfkwp1.5.exe
2008-03-26 18:28 . 2008-03-26 18:28 4,096 --a------ C:\Documents and Settings\robert\Desktopfilemanagerclient.exe
2008-03-26 18:28 . 2008-03-26 18:28 4,096 --a------ C:\Documents and Settings\robert\DesktopEditorFKWP2.0.exe
2008-03-26 18:28 . 2008-03-26 18:28 4,096 --a------ C:\Documents and Settings\robert\DesktopEditorFKWP1.5.exe
2008-03-26 18:27 . 2008-03-26 18:27 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\lijqvgvy
2008-03-26 18:27 . 2008-03-26 18:27 98,304 --a------ C:\WINDOWS\system32\xqtepibi.exe
2008-03-26 18:26 . 2008-03-26 12:28 221,184 --a------ C:\WINDOWS\vbgtorfd.dll
2008-03-26 18:26 . 2008-03-26 12:28 212,992 --a------ C:\WINDOWS\kdftlboedsb.dll
2008-03-26 18:26 . 2008-03-26 12:28 81,920 --a------ C:\WINDOWS\norlatmx.exe
2008-03-26 18:26 . 2008-03-26 18:26 21,660 --a------ C:\Program Files\antiviirus.exe
2008-03-26 18:26 . 2008-03-26 18:26 16,536 -r-hs---- C:\Program Files\tmp3.exe
2008-03-26 18:26 . 2008-03-26 18:26 16,536 -r-hs---- C:\Program Files\tmp2.exe
2008-03-26 18:26 . 2008-03-26 18:26 16,536 -r-hs---- C:\Program Files\tmp1.exe
2008-03-26 18:26 . 2008-03-26 18:26 16,536 -r-hs---- C:\Program Files\tmp0.exe
2008-03-25 11:06 . 2008-03-25 11:12 <DIR> d-------- C:\Program Files\SmartDraw 2008
2008-03-23 14:46 . 2008-03-23 14:46 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\DivoGames
2008-03-10 16:45 . 2008-03-10 16:28 691,545 --a------ C:\WINDOWS\unins000.exe
2008-03-10 16:45 . 2008-03-10 16:45 2,548 --a------ C:\WINDOWS\unins000.dat
2008-03-09 21:34 . 2008-03-09 21:34 <DIR> d-------- C:\Program Files\Benjamin Moore
2008-03-09 21:34 . 2008-03-09 21:34 <DIR> d-------- C:\Benjamin Moore
2008-03-08 10:50 . 2008-03-08 10:50 <DIR> d-------- C:\Program Files\Room Arranger
2008-02-27 17:21 . 2008-02-27 17:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Go Go Gourmet
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-27 15:49 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-03-27 15:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-27 01:02 --------- d-----w C:\Program Files\ErrorKiller
2008-03-23 20:43 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-23 19:30 --------- d-----w C:\Documents and Settings\robert\Application Data\PlayFirst
2008-03-23 19:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\PlayFirst
2008-03-23 19:23 --------- d-----w C:\Program Files\IncrediGames
2008-03-19 12:50 --------- d-----w C:\Documents and Settings\robert\Application Data\Canon
2008-03-11 15:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-11 10:18 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-03-07 14:57 --------- d-----w C:\Documents and Settings\robert\Application Data\OpenOffice.org2
2008-03-07 01:32 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-03-07 01:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-03-07 01:32 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-03-05 20:26 --------- d-----w C:\Documents and Settings\robert\Application Data\Gamelab
2008-02-28 19:16 69,024 -c--a-w C:\Documents and Settings\robert\Application Data\GDIPFONTCACHEV1.DAT
2008-02-27 13:02 --------- d-----w C:\Program Files\Windows Live
2008-02-26 17:51 --------- d-----w C:\Program Files\Windows Live Toolbar
2008-02-26 17:51 --------- d-----w C:\Program Files\Windows Live Favorites
2008-02-26 17:43 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
2008-02-26 17:38 --------- d-----w C:\Program Files\MSN Messenger
2008-02-26 17:28 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-02-26 17:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-02-25 18:38 --------- d-----w C:\Program Files\Incredijeux
2008-02-25 18:30 --------- d-----w C:\Program Files\Common Files\Oberon Media
2008-02-22 19:35 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-02-22 19:35 --------- d-----w C:\Program Files\BookingBoard
2008-02-22 19:35 --------- d-----w C:\Program Files\Acoustica CD Label Maker
2008-02-22 16:32 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-22 16:29 --------- d-----w C:\Documents and Settings\robert\Application Data\Netscape
2008-02-18 12:27 --------- d-----w C:\Documents and Settings\robert\Application Data\Grisoft
2008-02-18 12:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-17 22:26 --------- d-----w C:\Program Files\IncrediMail
2008-02-17 16:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-17 00:46 85,504 ----a-w C:\WINDOWS\system32\VACFix.exe
2008-02-15 03:19 164 ----a-w C:\install.dat
2008-02-08 15:37 82,432 ----a-w C:\WINDOWS\system32\IEDFix.exe
2008-02-01 16:17 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
2008-01-30 15:43 --------- d-----w C:\Program Files\Creative
2008-01-30 15:38 --------- d-----w C:\Documents and Settings\robert\Application Data\SmartDraw
2006-02-23 22:12 32 -c--a-r C:\Documents and Settings\All Users\hash.dat
2003-11-22 21:49 1 -c--a-w C:\Documents and Settings\robert\scrcfg.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-03-09 08:52 67128]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2008-02-03 16:04 214456]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" []
"SoundMan"="SOUNDMAN.EXE" [2003-05-13 18:20 55296 C:\WINDOWS\SOUNDMAN.EXE]
"NeroCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 15:50 155648]
"IntelliType"="C:\Program Files\Microsoft Hardware\Keyboard\type32.exe" [2002-03-22 00:41 94208]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-09-05 20:32 77824]
"BigDogPath"="C:\WINDOWS\VM_STI.exe" [2003-01-21 18:19 40960]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2003-06-30 23:56 188416]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2003-07-01 00:00 65536]
"LogitechGalleryRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2003-06-30 23:56 188416]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2003-12-12 20:50 33792]
"Samsung Common SM"="C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe" [2005-07-03 03:20 372736]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-09-02 19:04 84640]
"osCheck"="C:\Program Files\Norton Internet Security\osCheck.exe" [2006-09-05 13:22 26248]
"Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2008-01-11 20:54 623992]
"Adobe_ID0EYTHM"="C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 16:40 1884160]
"!AVG Anti-Spyware"="C:\Documents and Settings\robert\Desktop\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25 6731312]
"antiviirus"="C:\Program Files\antiviirus.exe" [2008-03-26 18:26 21660]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 03:56 15360]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-27 21:17 443968]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"XKzCRxfxYt"= C:\Documents and Settings\All Users\Application Data\lijqvgvy\xcdebmti.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"KernelRunOnce"= {027f38ec-ac1b-40cf-92d4-542c2d310fa1} - C:\WINDOWS\Installer\{027f38ec-ac1b-40cf-92d4-542c2d310fa1}\KernelRunOnce.dll [2008-03-26 18:26 14378]
"zip"= {b4db913f-28ad-4a68-8b0b-09b8e09e40c6} - C:\WINDOWS\Installer\{b4db913f-28ad-4a68-8b0b-09b8e09e40c6}\zip.dll [2008-03-26 18:26 23198]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\WINDOWS\\system32\\dxdiag.exe"=
"C:\\WINDOWS\\system32\\dpnsvr.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImLc.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\WINDOWS\\system32\\rtcshare.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Documents and Settings\\robert\\My Documents\\My Received Files\\IziSpot 3\\IziSpot.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\\WINDOWS\\system32\\rundll32.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncrediMail_Install.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
S0 ElbyVCD;ElbyVCD;C:\WINDOWS\system32\DRIVERS\ElbyVCD.sys []
S3 Boonty Games;Boonty Games;"C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe" [2006-06-20 17:41]
*Newly Created Service* - CATCHME
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-03-27 15:00:01 C:\WINDOWS\Tasks\AB8E033691F5BF8A.job"
- c:\progra~1\funkfo~1\Open Mpeg Once.exe
"2008-03-27 15:00:02 C:\WINDOWS\Tasks\AE5D636E91CAE24E.job"
- c:\progra~1\funkfo~1\Open Mpeg Once.exe
"2008-03-27 15:00:02 C:\WINDOWS\Tasks\AEFBD04A91804086.job"
- c:\progra~1\funkfo~1\Open Mpeg Once.exe
"2008-03-22 00:00:40 C:\WINDOWS\Tasks\Norton Internet Security - Analyse système complète - robert.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\Navw32.exeh/TASK:
"2008-03-27 15:16:32 C:\WINDOWS\Tasks\SDMsgUpdate (TE).job"
- C:\PROGRA~1\SMARTD~1\Messages\SDNotify.exeW-PTE -V900 -SSDU.ini -A -Mhttp://www.smartdraw.com/msgs/messagecheck.aspx -D0 -T -N -X
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-27 11:49:33
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-03-27 11:59:35
ComboFix-quarantined-files.txt 2008-03-27 15:59:28
Pre-Run: 18,877,583,360 bytes free
Post-Run: 18,874,888,192 bytes free
.
2008-03-12 12:04:06 --- E O F ---
Maintenant pouvez vous me dire quoi faire ?