rapport combofix
merci et à demain
ComboFix 08-07-27.3 - gilles 2008-07-27 15:57:41.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.196 [GMT -7:00]
Endroit: C:\Documents and Settings\gilles\Bureau\outil.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\WINDOWS\system32\bund1
C:\WINDOWS\system32\bund1\temp.txt
D:\Autorun.inf
.
((((((((((((((((((((((((((((( Fichiers créés 2008-06-27 to 2008-07-27 ))))))))))))))))))))))))))))))))))))
.
2008-07-27 14:09 . 2008-07-27 14:09 <REP> d-------- C:\Deckard
2008-07-22 18:19 . 2008-07-22 18:19 <REP> d-------- C:\Program Files\Avira
2008-07-22 18:19 . 2008-07-22 18:19 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-07-22 16:40 . 2008-07-27 15:49 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-07-22 16:40 . 2008-07-22 16:40 1,409 --a------ C:\WINDOWS\QTFont.for
2008-07-16 20:16 . 2008-06-14 10:33 272,768 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-07-16 20:13 . 2008-05-08 07:02 203,136 -----c--- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-07-16 20:06 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-07-16 20:06 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-07-16 19:54 . 2008-07-16 19:54 <REP> d-------- C:\WINDOWS\system32\fr
2008-07-16 19:54 . 2008-07-16 19:54 <REP> d-------- C:\WINDOWS\l2schemas
2008-07-16 19:27 . 2008-04-13 19:33 712,704 --------- C:\WINDOWS\system32\windowscodecs.dll
2008-07-16 19:27 . 2008-04-13 19:33 346,112 --------- C:\WINDOWS\system32\windowscodecsext.dll
2008-07-16 19:27 . 2008-04-13 19:33 276,992 --------- C:\WINDOWS\system32\wmphoto.dll
2008-07-16 19:27 . 2008-04-13 19:33 69,120 --------- C:\WINDOWS\system32\wlanapi.dll
2008-07-16 19:27 . 2008-04-13 19:33 53,248 --------- C:\WINDOWS\system32\tsgqec.dll
2008-07-16 19:27 . 2008-04-13 19:33 50,688 --------- C:\WINDOWS\system32\tspkg.dll
2008-07-16 19:25 . 2008-04-13 19:33 397,312 --------- C:\WINDOWS\system32\mmcex.dll
2008-07-16 19:24 . 2008-04-13 19:33 651,264 --------- C:\WINDOWS\system32\dot3ui.dll
2008-07-16 18:31 . 2008-07-17 10:46 <REP> d-------- C:\Program Files\Unlocker
2008-07-16 17:14 . 2008-07-16 17:14 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-16 17:14 . 2008-07-27 12:33 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-16 13:09 . 2008-07-16 13:09 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-07-16 13:09 . 2008-07-16 13:09 <REP> d-------- C:\Downloads
2008-07-16 13:09 . 2008-07-27 13:07 <REP> d-------- C:\Documents and Settings\gilles\Application Data\GetRightToGo
2008-07-15 19:37 . 2004-10-15 18:17 60,496 --a------ C:\WINDOWS\system32\drivers\Teefer.sys
2008-07-15 19:37 . 2004-10-15 18:18 21,075 --a------ C:\WINDOWS\system32\drivers\wpsdrvnt.sys
2008-07-15 19:37 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg6n.sys
2008-07-15 19:37 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg5n.sys
2008-07-15 19:37 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg4n.sys
2008-07-15 19:37 . 2004-10-15 18:32 14,568 --a------ C:\WINDOWS\system32\drivers\wg3n.sys
2008-07-15 19:36 . 2008-07-16 13:09 <REP> d-------- C:\Program Files\Sygate
2008-07-15 19:36 . 2004-10-15 18:32 83,096 --a------ C:\WINDOWS\system32\SSSensor.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-27 22:49 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-27 21:19 --------- d-----w C:\Program Files\MSN Messenger
2008-07-27 18:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-07-23 01:12 --------- d-----w C:\Program Files\Navilog1
2008-07-23 01:09 --------- d-----w C:\Program Files\ArcSoft
2008-07-18 03:19 --------- d-----w C:\Program Files\eMule
2008-07-17 04:22 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-07-17 03:01 96,384 ----a-w C:\WINDOWS\system32\drivers\sptd8205.sys
2008-07-16 22:02 --------- d-----w C:\Program Files\Norton Security Scan
2008-07-16 20:08 --------- d-----w C:\Program Files\Spyware Doctor
2008-06-20 17:47 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 11:51 361,600 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 11:40 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 11:08 225,856 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-14 17:33 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-07 03:14 --------- d-----w C:\Program Files\PokerStars
2008-05-09 10:55 90,112 ----a-w C:\WINDOWS\system32\wshext.dll
2008-05-09 10:55 430,080 ----a-w C:\WINDOWS\system32\vbscript.dll
2008-05-09 10:55 180,224 ----a-w C:\WINDOWS\system32\scrobj.dll
2008-05-09 10:55 172,032 ----a-w C:\WINDOWS\system32\scrrun.dll
2008-05-08 11:24 155,648 ----a-w C:\WINDOWS\system32\wscript.exe
2008-05-07 09:07 135,168 ----a-w C:\WINDOWS\system32\cscript.exe
2008-05-07 05:11 1,294,336 ----a-w C:\WINDOWS\system32\quartz.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 19:33 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-11 17:21 68856]
"EPSON Stylus CX8400 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICEA.EXE" [2007-02-15 06:00 179200]
"OM2_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2007-05-28 16:59 95800]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 09:42 2156368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-07-24 15:45 335872]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2006-03-23 17:06 1398272]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2004-10-08 11:52 221184]
"WG511WLU"="C:\Program Files\NETGEAR\WG511\Utility\WG511WLU.exe" [2004-04-29 18:28 450560]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-01-18 17:47 458752]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-01-18 17:37 217088]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-21 11:52 29744]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"SmcService"="C:\PROGRA~1\Sygate\SPF\smc.exe" [2004-10-15 19:40 2577632]
"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 12:55 1103240]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 14:28 266497]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 01:24 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-13 19:33 15360]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2007-04-04 20:47:51 450560]
Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-07-11 17:21:32 125624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.divxa32"= divxa32.acm
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
--a------ 2005-01-18 17:07 196608 C:\Program Files\Logitech\Video\ManifestEngine.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"25061:TCP"= 25061:TCP:BitComet 25061 TCP
"25061:UDP"= 25061:UDP:BitComet 25061 UDP
R2 ABBYY.Licensing.FineReader.Professional.9.0;ABBYY FineReader 9.0 PE Licensing Service;C:\Program Files\Fichiers communs\ABBYY\FineReader\9.00\Licensing\PE\NetworkLicenseServer.exe [2007-12-06 21:03]
R3 AWINDIS5;AWINDIS5 Protocol Driver;C:\WINDOWS\System32\AWINDIS5.SYS [2002-04-11 17:43]
R3 SiS7012;Service for AC'97 Sample Driver (WDM);C:\WINDOWS\system32\drivers\sis7012.sys [2003-01-16 20:44]
S3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-04-21 11:52]
S3 PRISM_ICB;NETGEAR WG511 Wireless LAN Driver;C:\WINDOWS\system32\DRIVERS\WG511ICB.sys [2004-03-22 16:50]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 11:45]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 11:45]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d87e471-559d-11db-8769-00030d024db3}]
\Shell\AutoRun\command - I:\ybj8df.exe
\Shell\explore\Command - I:\ybj8df.exe
\Shell\open\Command - I:\ybj8df.exe
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
2008-07-12 C:\WINDOWS\Tasks\Norton Security Scan.job
- C:\Program Files\Norton Security Scan\Nss.exe [2007-09-18 23:42]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-kamsoft - C:\WINDOWS\system32\ckvo.exe
HKLM-Run-UnlockerAssistant - C:\Program Files\Unlocker\UnlockerAssistant.exe
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://google.fr/
R1 -: HKCU-Internet Settings,ProxyOverride = *.local
O8 -: &D&ownload &with BitComet - C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 -: &D&ownload all video with BitComet - C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 -: &D&ownload all with BitComet - C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 -: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 -: {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O16 -: DirectAnimation Java Classes - file://C:\WINDOWS\Java\classes\dajava.cab
C:\WINDOWS\Downloaded Program Files\DirectAnimation Java Classes.osd
O16 -: Microsoft XML Parser for Java - file://C:\WINDOWS\Java\classes\xmldso.cab
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-27 16:01:31
Windows 5.1.2600 Service Pack 3 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet003\Services\vsdatant]
"ImagePath"=""
.
Temps d'accomplissement: 2008-07-27 16:06:47
ComboFix-quarantined-files.txt 2008-07-27 23:06:42
Pre-Run: 2,453,839,872 octets libres
Post-Run: 2,438,922,240 octets libres
177 --- E O F --- 2008-07-27 20:32:48