Sur le premier ordi infecté, combofix à été aussi executé voici le rapport :
ComboFix 08-07-15.4 - GEORGES 2008-07-18 15:20:46.1 - [color=red][b]FAT32
/b/colorx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.330 [GMT 2:00]
Endroit: C:\Documents and Settings\GEORGES\Bureau\Combo-Fix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\InfoSat.txt
C:\WINDOWS\Downloaded Program Files\setup.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_SROSA
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-18 to 2008-07-18 ))))))))))))))))))))))))))))))))))))
.
2008-07-18 15:26 . 2008-07-18 15:26 <REP> d-------- C:\WINDOWS\system32\drivers\downld
2008-07-17 16:41 . 2008-07-17 16:41 <REP> d-------- C:\Program Files\LimeWire
2008-07-17 16:41 . 2008-07-17 16:41 <REP> d-------- C:\Documents and Settings\GEORGES\Application Data\LimeWire
2008-07-17 16:07 . 2008-07-17 16:07 <REP> d-------- C:\Program Files\Panda Security
2008-07-17 16:07 . 2008-06-19 17:24 28,544 --a------ C:\WINDOWS\system32\drivers\pavboot.sys
2008-07-16 23:16 . 2008-07-16 23:16 <REP> d-------- C:\Deckard
2008-07-16 23:09 . 2008-07-16 23:09 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-07-16 22:28 . 2008-07-16 22:28 <REP> d-------- C:\Documents and Settings\GEORGES\DoctorWeb
2008-07-16 21:43 . 2008-07-16 21:43 <REP> d-------- C:\Muestras
2008-07-16 10:39 . 2008-07-16 10:39 <REP> d--hs---- C:\FOUND.000
2008-07-13 13:48 . 2008-07-13 13:48 <REP> d-------- C:\Program Files\K-Lite Codec Pack
2008-07-01 14:12 . 2008-07-01 14:12 <REP> d-------- C:\Program Files\eMule
2008-06-30 11:35 . 2008-06-30 11:35 <REP> d-------- C:\Documents and Settings\GEORGES\Application Data\U3
2008-06-23 13:11 . 2008-06-23 13:11 0 --ah----- C:\WINDOWS\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2008-06-23 13:11 . 2008-06-23 13:11 0 --ah----- C:\WINDOWS\system32\drivers\Msft_Kernel_motmodem_01005.Wdf
2008-06-23 13:06 . 2006-11-13 14:45 1,419,232 --a------ C:\WINDOWS\system32\wdfcoinstaller01005.dll
2008-06-23 13:06 . 2007-02-27 14:31 21,504 --a------ C:\WINDOWS\system32\drivers\motmodem.sys
2008-06-23 13:05 . 2008-06-23 13:05 <REP> d-------- C:\Program Files\Fichiers communs\Motorola Shared
2008-06-20 19:41 . 2008-06-20 19:41 247,808 --------- C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 12:44 . 2008-06-20 12:44 138,368 --------- C:\WINDOWS\system32\dllcache\afd.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-16 11:10 15,360 ----a-w C:\WINDOWS\system32\dllcache\register.exe
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-12 18:36 7,680 ----a-w C:\WINDOWS\system32\ff_vfw.dll
2008-06-08 14:22 --------- d-----w C:\Documents and Settings\GEORGES\Application Data\vlc
2008-06-08 14:21 --------- d-----w C:\Program Files\adslTV
2008-05-30 23:22 683,520 ----a-w C:\WINDOWS\system32\divx.dll
2008-05-22 22:22 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
2008-05-22 22:19 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys
2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:15 1,293,824 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2008-04-23 20:16 3,591,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-04-22 07:41 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
2008-04-22 07:41 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-04-22 07:39 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-04-20 05:07 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
2008-03-09 15:03 92,064 ----a-w C:\Documents and Settings\GEORGES\mqdmmdm.sys
2008-03-09 15:03 9,232 ----a-w C:\Documents and Settings\GEORGES\mqdmmdfl.sys
2008-03-09 15:03 79,328 ----a-w C:\Documents and Settings\GEORGES\mqdmserd.sys
2008-03-09 15:03 66,656 ----a-w C:\Documents and Settings\GEORGES\mqdmbus.sys
2008-03-09 15:03 6,208 ----a-w C:\Documents and Settings\GEORGES\mqdmcmnt.sys
2008-03-09 15:03 5,936 ----a-w C:\Documents and Settings\GEORGES\mqdmwhnt.sys
2008-03-09 15:03 4,048 ----a-w C:\Documents and Settings\GEORGES\mqdmcr.sys
2008-03-09 15:03 25,600 ----a-w C:\Documents and Settings\GEORGES\usbsermptxp.sys
2008-03-09 15:03 22,768 ----a-w C:\Documents and Settings\GEORGES\usbsermpt.sys
2003-01-21 01:00 13,112,456 ----a-r C:\WINDOWS\system32\config\systemprofile\MpSetup.exe
2003-01-21 01:00 13,112,456 ----a-r C:\Documents and Settings\Default User\MpSetup.exe
2005-05-15 17:04 0 --sha-w C:\WINDOWS\system32\.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
"RamBooster"="C:\Program Files\RamBooster 2.0\Rambooster.exe" [2006-06-05 06:09 684032]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2003-04-23 00:09 417871]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 00:09 15360]
"OE"="C:\Program Files\Trend Micro\Internet Security 2007\TMAS_OE\TMAS_OEMon.exe" [2006-09-27 22:29 315392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Wbutton"="C:\Program Files\Launch Manager\Wbutton.exe" [2004-04-22 14:14 73728]
"Watch"="C:\PROGRA~1\minitel\Watch.exe" [2002-01-14 15:01 20480]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2003-11-20 16:19 98304]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2003-11-20 16:18 499712]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-21 11:52 40960]
"preload"="C:\Windows\RUNXMLPL.exe" [2004-04-20 08:49 40960]
"PowerKey"="C:\Program Files\Launch Manager\PowerKey.exe" [2002-08-30 15:02 94208]
"LtMoh"="C:\Program Files\ltmoh\Ltmoh.exe" [2003-04-28 15:08 184320]
"LMgrOSD"="C:\Program Files\Launch Manager\OSDCtrl.exe" [2004-03-30 16:36 49152]
"LManager"="C:\Program Files\Launch Manager\HotkeyApp.exe" [2004-05-12 14:24 49152]
"LaunchAp"="C:\Program Files\Launch Manager\LaunchAp.exe" [2004-01-28 17:46 32768]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152]
"eCarteBleue-BP"="C:\Program Files\e-Carte Bleue\Banque Populaire\ECB-BP.exe" [2003-06-20 11:09 188416]
"CtrlVol"="C:\Program Files\Launch Manager\CtrlVol.exe" [2004-01-28 17:48 184320]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-02-10 21:10 335872]
"AcerNotebookManager"="C:\Program Files\Acer\Notebook Manager\almxptray.exe" [2004-03-18 15:42 510464]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe" [2006-10-02 06:22 3121152]
"SoundMan"="SOUNDMAN.EXE" [2004-02-26 16:53 65024 C:\WINDOWS\SOUNDMAN.EXE]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 16:24 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2003-11-19 15:41 88363 C:\WINDOWS\AGRSMMSG.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-20 00:09 15360]
"DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2005-04-25 13:45 36040]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.CEGSM"= mobilev.acm
"msacm.l3fhg"= mp3fhg.acm
"msacm.divxa32"= divxa32.acm
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wd.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\MsnMsgr.Exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R0 pavboot;pavboot;C:\WINDOWS\system32\drivers\pavboot.sys [2008-06-19 17:24]
R1 Hotkey;Hotkey;C:\WINDOWS\system32\drivers\Hotkey.sys [2003-04-28 11:27]
R2 acernbm;acernbm;C:\WINDOWS\system32\drivers\acernbm.sys [2004-03-18 18:42]
R2 Dnscache;Client DNS;C:\WINDOWS\System32\svchost.exe [2004-08-20 00:10]
R2 osadmi;osadmi;C:\WINDOWS\system32\drivers\osadmi.sys [2004-03-04 19:40]
R3 atiusbf;atiusbf;C:\WINDOWS\system32\DRIVERS\atiusbf.sys [2004-03-12 18:18]
R3 POWERKEY;POWERKEY;C:\Program Files\Launch Manager\POWERKEY.sys [2000-12-19 18:29]
R3 PRISM;IEEE 802.11 Wireless NIC Driver;C:\WINDOWS\system32\DRIVERS\EXPRESS.sys [2002-11-15 11:02]
S1 Wbutton;Wbutton;C:\WINDOWS\system32\drivers\Wbutton.sys []
S3 fbxusb;Carte réseau virtuelle FreeBox USB;C:\WINDOWS\system32\DRIVERS\fbxusb32.sys [2004-10-20 14:23]
S3 SI15CI;SI15CI;c:\elements\1stboot\SI15CI.SYS []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{20886fea-688b-11da-bb23-a23c3c76a5b3}]
\Shell\AutoRun\command - F:\setupSNK.exe
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-07-17 18:40:50 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
- - - - ORPHANS REMOVED - - - -
HKU-Default-Run-MS MSN Menssenger 7.0 - MSMSN7.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-18 15:25:51
Windows 5.1.2600 Service Pack 2 FAT NTAPI
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
--------------------- DLLs a charg‚ sous des processus courants ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRAM FILES\WINDOWS DEFENDER\MSMPENG.EXE
C:\PROGRAM FILES\TREND MICRO\INTERNET SECURITY 2007\PCCTLCOM.EXE
C:\WINDOWS\SYSTEM32\HPZIPM12.EXE
C:\PROGRAM FILES\TREND MICRO\INTERNET SECURITY 2007\TMNTSRV.EXE
C:\PROGRAM FILES\TREND MICRO\INTERNET SECURITY 2007\TMPFW.EXE
C:\PROGRAM FILES\TREND MICRO\INTERNET SECURITY 2007\TMPROXY.EXE
C:\WINDOWS\SYSTEM32\FXSSVC.EXE
C:\WINDOWS\System32\irftp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PcScnSrv.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-07-18 15:28:47 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-18 13:28:42
Pre-Run: 3,724,132,352 octets libres
Post-Run: 4,616,355,840 octets libres
205 --- E O F --- 2008-07-18 08:40:25