Rapport killbagle:
ComboFix 08-05-08.1 - le cusinier nomade 2008-05-09 20:59:39.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.1.1252.1.1036.18.198 [GMT 2:00]
Endroit: C:\Documents and Settings\le cusinier nomade\Bureau\KillBagle.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\WINDOWS\system32\_003344_.tmp.dll
C:\WINDOWS\system32\_003350_.tmp.dll
C:\WINDOWS\system32\_003392_.tmp.dll
C:\WINDOWS\system32\_003398_.tmp.dll
C:\WINDOWS\system32\_003502_.tmp.dll
C:\WINDOWS\system32\_003503_.tmp.dll
C:\WINDOWS\system32\_003504_.tmp.dll
C:\WINDOWS\system32\_003505_.tmp.dll
C:\WINDOWS\system32\_003512_.tmp.dll
C:\WINDOWS\system32\_003513_.tmp.dll
C:\WINDOWS\system32\_003514_.tmp.dll
C:\WINDOWS\system32\_003515_.tmp.dll
C:\WINDOWS\system32\_003517_.tmp.dll
C:\WINDOWS\system32\_003518_.tmp.dll
C:\WINDOWS\system32\_003521_.tmp.dll
C:\WINDOWS\system32\_003522_.tmp.dll
C:\WINDOWS\system32\_003524_.tmp.dll
C:\WINDOWS\system32\_003525_.tmp.dll
C:\WINDOWS\system32\_003526_.tmp.dll
C:\WINDOWS\system32\_003528_.tmp.dll
C:\WINDOWS\system32\_003529_.tmp.dll
C:\WINDOWS\system32\_003531_.tmp.dll
C:\WINDOWS\system32\_003535_.tmp.dll
C:\WINDOWS\system32\_003536_.tmp.dll
C:\WINDOWS\system32\_003538_.tmp.dll
C:\WINDOWS\system32\_003541_.tmp.dll
C:\WINDOWS\system32\_003543_.tmp.dll
C:\WINDOWS\system32\_003544_.tmp.dll
C:\WINDOWS\system32\_003545_.tmp.dll
C:\WINDOWS\system32\_003546_.tmp.dll
C:\WINDOWS\system32\_003547_.tmp.dll
C:\WINDOWS\system32\_003550_.tmp.dll
C:\WINDOWS\system32\_003551_.tmp.dll
C:\WINDOWS\system32\_003552_.tmp.dll
C:\WINDOWS\system32\_003553_.tmp.dll
C:\WINDOWS\system32\_003560_.tmp.dll
C:\WINDOWS\system32\_003561_.tmp.dll
C:\WINDOWS\system32\_003562_.tmp.dll
C:\WINDOWS\system32\_003564_.tmp.dll
C:\WINDOWS\system32\_003565_.tmp.dll
C:\WINDOWS\system32\_003568_.tmp.dll
C:\WINDOWS\system32\_003569_.tmp.dll
C:\WINDOWS\system32\_003571_.tmp.dll
C:\WINDOWS\system32\_003572_.tmp.dll
C:\WINDOWS\system32\_003573_.tmp.dll
C:\WINDOWS\system32\_003575_.tmp.dll
C:\WINDOWS\system32\_003576_.tmp.dll
C:\WINDOWS\system32\_003578_.tmp.dll
C:\WINDOWS\system32\_003582_.tmp.dll
C:\WINDOWS\system32\_003583_.tmp.dll
C:\WINDOWS\system32\_003585_.tmp.dll
C:\WINDOWS\system32\_003588_.tmp.dll
C:\WINDOWS\system32\_003590_.tmp.dll
C:\WINDOWS\system32\_003591_.tmp.dll
C:\WINDOWS\system32\_003592_.tmp.dll
C:\WINDOWS\system32\_003593_.tmp.dll
C:\WINDOWS\system32\_003596_.tmp.dll
C:\WINDOWS\system32\_003598_.tmp.dll
C:\WINDOWS\system32\_003599_.tmp.dll
C:\WINDOWS\system32\_003600_.tmp.dll
C:\WINDOWS\system32\_003604_.tmp.dll
C:\WINDOWS\system32\amvo.exe
C:\WINDOWS\system32\amvo0.dll
C:\WINDOWS\system32\amvo1.dll
C:\WINDOWS\system32\pac.txt
.
((((((((((((((((((((((((((((( Fichiers créés 2008-04-09 to 2008-05-09 ))))))))))))))))))))))))))))))))))))
.
2008-05-09 20:48 . 2008-05-09 20:48 <REP> d-------- C:\Program Files\Tall Emu
2008-05-09 20:48 . 2008-05-09 20:53 <REP> d-------- C:\Documents and Settings\le cusinier nomade\Application Data\OnlineArmor
2008-05-09 20:48 . 2008-05-09 20:48 <REP> d-------- C:\Documents and Settings\All Users\Application Data\OnlineArmor
2008-05-09 20:48 . 2007-11-08 06:37 68,608 --a------ C:\WINDOWS\system32\drivers\OADriver.sys
2008-05-09 20:48 . 2007-09-29 00:06 25,600 --a------ C:\WINDOWS\system32\drivers\OAmon.sys
2008-05-09 20:48 . 2007-09-29 00:06 18,944 --a------ C:\WINDOWS\system32\drivers\ndisrd.sys
2008-05-09 20:00 . 2008-05-09 20:00 <REP> d-------- C:\Program Files\Trend Micro
2008-05-09 19:45 . 2008-05-09 19:45 <REP> d-------- C:\Program Files\El Juky
2008-05-09 10:10 . 2008-05-09 10:10 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-09 10:10 . 2008-05-09 10:10 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-09 09:55 . 2008-05-09 09:55 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Macrovision
2008-05-08 13:14 . 2008-05-08 13:14 <REP> d-------- C:\Temp\maxsv15
2008-05-08 13:14 . 2008-05-09 20:59 <REP> d-------- C:\Temp
2008-05-08 13:14 . 2008-05-09 19:45 <REP> d-------- C:\Program Files\winvi
2008-05-08 13:14 . 2008-05-08 13:14 371,261 --a------ C:\Temp\midE98k.exe
2008-05-08 12:34 . 2008-05-08 12:36 <REP> d-------- C:\Program Files\MAGIX
2008-05-08 10:55 . 2008-05-08 10:55 <REP> d-------- C:\Program Files\Neuf
2008-05-02 19:07 . 2008-05-02 19:07 <REP> d-------- C:\Program Files\Alwil Software
2008-05-02 19:07 . 2003-03-18 21:14 499,712 --a------ C:\WINDOWS\system32\MSVCP71.dll
2008-05-02 16:01 . 2008-05-02 18:49 <REP> d-------- C:\Program Files\Yahoo!
2008-05-02 16:01 . 2008-05-02 16:01 <REP> d-------- C:\Program Files\CCleaner
2008-04-11 13:23 . 2008-04-11 13:23 46,592 --a------ C:\FACTURE suppléments boart longyear.doc
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-09 17:45 --------- d-----w C:\Documents and Settings\le cusinier nomade\Application Data\dvdcss
2008-05-09 07:50 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-06 11:10 --------- d-----w C:\Documents and Settings\le cusinier nomade\Application Data\FaxCtr
2008-05-02 17:35 --------- d-----w C:\Program Files\Google
2008-04-13 04:03 69,632 ----a-w C:\WINDOWS\DUMP9191.tmp
2008-04-08 11:54 --------- d-----w C:\Program Files\FTPExpert
2008-04-08 11:48 --------- d-----w C:\Program Files\DVD Genie
2008-04-06 15:56 103,966 --sh--r C:\t.com
2008-03-17 15:52 --------- d-----w C:\Program Files\FontLab
2008-03-17 15:51 --------- d-----w C:\Program Files\SuperDVD Video Editor
2008-03-17 15:51 --------- d-----w C:\Program Files\PCFriendly
2008-03-17 15:34 --------- d-----w C:\Program Files\SlySoft
2008-03-15 18:57 --------- d-----w C:\Program Files\Free Easy Burner
.
------- Sigcheck -------
2004-08-04 08:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\SoftwareDistribution\Download\70ccc3de7e94865059fbcf2f809c03b1\ip6fw.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2003-04-24 14:00 13312]
"AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe" [2003-09-08 09:00 288768]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-02-12 13:33 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AzMixerSel"="C:\Program Files\Realtek\InstallShield\AzMixerSel.exe" [2005-02-14 04:18 53248]
"Hcontrol"="C:\WINDOWS\ATK0100\Hcontrol.exe" [2004-07-19 07:05 61440]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-10-10 07:28 36352]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 15:57 282624]
"Device Detector"="C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe" [2003-11-27 10:16 217088]
"FaxCenterServer"="C:\Program Files\\Lexmark Fax Solutions\fm3032.exe" [2007-05-07 20:10 312240]
"ElbyCheckAnyDVD"="C:\Program Files\SlySoft\AnyDVD\ElbyCheck.exe" [2002-11-02 08:33 45056]
"AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe" [2003-09-08 09:00 288768]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 12:06 79224]
"OnlineArmor GUI"="C:\Program Files\Tall Emu\Online Armor\oaui.exe" [2007-11-16 07:51 5029952]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2003-04-24 14:00 13312]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Post-it© Software Notes Lite.lnk - C:\Program Files\3M\PSNLite\PsnLite.exe [2004-10-15 14:26:54 2080768]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
R0 IABFilt;Iomega Snapshot Volume Filter;C:\WINDOWS\System32\DRIVERS\IABFilt.sys [2005-07-01 10:15]
R0 SSFS041A;SSFS041A;C:\WINDOWS\System32\Drivers\SSFS041A.SYS [2006-07-07 16:41]
R1 NDISRD;NDISRD;C:\WINDOWS\system32\drivers\NDISRD.sys [2007-09-29 00:06]
R1 OADevice;OADriver;C:\WINDOWS\system32\drivers\OADriver.sys [2007-11-08 06:37]
R1 OAmon;OAmon;C:\WINDOWS\system32\drivers\OAmon.sys [2007-09-29 00:06]
R2 SvcOnlineArmor;Online Armor;"C:\Program Files\Tall Emu\Online Armor\oasrv.exe" [2007-11-16 07:51]
R3 NBXG7031;NB 802.11g XG703 SP1 Driver;C:\WINDOWS\System32\DRIVERS\WlanUIG.sys [2004-09-17 11:56]
R3 SPI;Périphérique de contrôle d'E/S programmable Sony;C:\WINDOWS\System32\DRIVERS\SonyPI.sys [2001-08-17 21:51]
S3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\System32\Drivers\PCASp50.sys [2005-11-19 03:13]
*Newly Created Service* - CATCHME
*Newly Created Service* - NDISRD
*Newly Created Service* - OADEVICE
*Newly Created Service* - OAMON
*Newly Created Service* - SVCONLINEARMOR
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-05-09 16:29:45 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-09 21:02:08
Windows 5.1.2600 Service Pack 1 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-05-09 21:03:24
ComboFix-quarantined-files.txt 2008-05-09 19:03:15
Pre-Run: 5,874,487,296 octets libres
Post-Run: 5,866,483,712 octets libres
183 --- E O F --- 2007-10-11 06:08:03