Le voici
ComboFix 08-06-12.2 - Frederic 2008-06-15 15:53:32.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.182 [GMT 2:00]
Endroit: C:\Documents and Settings\Frederic\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
* Resident AV is active
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\dcads_sidebar_uninstall.exe
C:\WINDOWS\system32\drivers\Icon.exe
C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-05-15 to 2008-06-15 ))))))))))))))))))))))))))))))))))))
.
2008-06-14 01:22 . 2008-06-14 01:22 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-06-14 01:15 . 2008-06-14 01:15 <REP> d-------- C:\Program Files\Yahoo!
2008-06-14 01:15 . 2008-06-14 01:15 <REP> d-------- C:\Program Files\CCleaner
2008-06-13 23:13 . 2008-06-13 23:13 14,744,627 --a------ C:\upload_moi_FRED.tar.gz
2008-06-13 22:08 . 2008-06-13 22:08 <REP> d-------- C:\Documents and Settings\Frederic\Application Data\Malwarebytes
2008-06-13 22:08 . 2008-06-13 22:08 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-06-13 22:08 . 2008-06-10 19:02 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-06-13 22:08 . 2008-06-10 19:02 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-06-13 21:47 . 2008-06-13 21:47 <REP> d-------- C:\Program Files\Trend Micro
2008-06-13 18:37 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-06-13 18:37 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-06-13 18:37 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-06-13 18:37 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-06-13 18:37 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\404Fix.exe
2008-06-13 18:37 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-06-13 18:37 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-06-13 18:37 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-06-13 18:12 . 2008-06-13 20:48 2,478 --a------ C:\WINDOWS\system32\tmp.reg
2008-06-13 17:12 . 2008-06-15 11:36 <REP> d-------- C:\WINDOWS\BDOSCAN8
2008-06-11 08:22 . 2008-04-14 17:52 272,768 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-13 21:05 --------- d-----w C:\Program Files\eTarget20d
2008-06-04 15:39 --------- d-----w C:\Documents and Settings\Frederic\Application Data\LimeWire
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 18:51 --------- d-----w C:\Program Files\Sun
2008-05-07 18:50 --------- d-----w C:\Program Files\Java
2008-04-22 07:12 --------- d-----w C:\Documents and Settings\Frederic\Application Data\HPAppData
2008-04-17 21:56 --------- d-----w C:\Program Files\MSXML 4.0
2008-04-16 18:26 --------- d-----w C:\Documents and Settings\Frederic\Application Data\HP
2008-04-16 14:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\WEBREG
2008-04-16 14:49 --------- d-----w C:\WINDOWS\system32\config\systemprofile\Application Data\HPAppData
2008-04-16 14:49 --------- d-----w C:\Program Files\HP
2008-04-16 14:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
2008-04-16 14:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2008-04-16 14:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP Product Assistant
2008-04-16 14:45 --------- d-----w C:\Program Files\Fichiers communs\HP
2008-04-16 14:44 --------- d-----w C:\Program Files\Hewlett-Packard
2008-04-16 14:44 --------- d-----w C:\Program Files\Fichiers communs\Hewlett-Packard
2008-04-16 14:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-04-16 14:12 --------- d-----w C:\Program Files\Snapshot Viewer
2008-04-16 14:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\SBT
2008-04-16 14:11 --------- d-----w C:\Program Files\microsoft frontpage
2008-04-16 13:56 --------- d-----w C:\Documents and Settings\Frederic\Application Data\Microsoft Web Folders
2008-04-15 21:33 --------- d-----w C:\Program Files\Windows Live
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 16:09 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BDMCon"="C:\Program Files\Softwin\BitDefender10\bdmcon.exe" [2007-04-02 16:48 290816]
"BDAgent"="C:\Program Files\Softwin\BitDefender10\bdagent.exe" [2007-03-26 15:49 69632]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 17:24 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-03-22 21:10 335872]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-11 11:56 286720]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 13:10 267048]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=sockspy.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R2 MTC0005_MTCDIO;Wireless HotKey Driver;C:\WINDOWS\system32\drivers\MTCDIO.sys [2003-09-22 11:04]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\WINDOWS\system32\DRIVERS\bdfndisf.sys [2007-02-02 17:40]
S2 MTCDIO;MTCDIO;C:\WINDOWS\system32\DRIVERS\MTCDIO.sys [2003-09-22 11:04]
S3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys [2007-05-23 04:15]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-06-02 16:06:05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-06-15 16:00:25
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
--------------------- DLLs a charg‚ sous des processus courants ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-06-15 16:03:41 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-15 14:03:37
Pre-Run: 39,286,591,488 octets libres
Post-Run: 39,229,136,896 octets libres
132 --- E O F --- 2008-06-11 07:25:56