Voilà le compte rendu :
ComboFix 08-08-21.02 - Marine 2008-08-23 13:39:29.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.229 [GMT 2:00]
* CrÚation d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE R+CUP+RATION N'EST PAS INSTALL+E SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Marine\Application Data\m
C:\Documents and Settings\Marine\Application Data\m\flec006.exe
C:\Documents and Settings\Marine\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
C:\WINDOWS\system32\ban_list.txt
C:\WINDOWS\system32\drivers\downld
C:\WINDOWS\system32\drivers\downld\101515.exe
C:\WINDOWS\system32\drivers\downld\1047546.exe
C:\WINDOWS\system32\drivers\downld\106000.exe
C:\WINDOWS\system32\drivers\downld\106437.exe
C:\WINDOWS\system32\drivers\downld\1091734.exe
C:\WINDOWS\system32\drivers\downld\109265.exe
C:\WINDOWS\system32\drivers\downld\1099578.exe
C:\WINDOWS\system32\drivers\downld\119734.exe
C:\WINDOWS\system32\drivers\downld\119812.exe
C:\WINDOWS\system32\drivers\downld\126265.exe
C:\WINDOWS\system32\drivers\downld\127000.exe
C:\WINDOWS\system32\drivers\downld\128781.exe
C:\WINDOWS\system32\drivers\downld\133640.exe
C:\WINDOWS\system32\drivers\downld\135156.exe
C:\WINDOWS\system32\drivers\downld\136687.exe
C:\WINDOWS\system32\drivers\downld\173937.exe
C:\WINDOWS\system32\drivers\downld\184375.exe
C:\WINDOWS\system32\drivers\downld\195578.exe
C:\WINDOWS\system32\drivers\downld\219671.exe
C:\WINDOWS\system32\drivers\downld\220781.exe
C:\WINDOWS\system32\drivers\downld\239750.exe
C:\WINDOWS\system32\drivers\downld\247781.exe
C:\WINDOWS\system32\drivers\downld\605218.exe
C:\WINDOWS\system32\drivers\downld\620468.exe
C:\WINDOWS\system32\drivers\downld\89656.exe
C:\WINDOWS\system32\drivers\downld\940531.exe
C:\WINDOWS\system32\drivers\downld\953171.exe
C:\WINDOWS\system32\drivers\downld\954437.exe
C:\WINDOWS\system32\drivers\downld\960859.exe
C:\WINDOWS\system32\drivers\downld\962375.exe
C:\WINDOWS\system32\drivers\downld\97375.exe
C:\WINDOWS\system32\drivers\downld\995968.exe
C:\WINDOWS\system32\drivers\downld\999375.exe
C:\WINDOWS\system32\drivers\hldrrr.exe
C:\WINDOWS\system32\drivers\mdelk.exe
C:\WINDOWS\system32\drivers\srosa.sys
C:\WINDOWS\system32\mdelk.exe
C:\WINDOWS\system32\wintems.exe
.
((((((((((((((((((((((((((((( Fichiers crÚÚs 2008-07-23 to 2008-08-23 ))))))))))))))))))))))))))))))))))))
.
2008-08-22 17:44 . 2008-08-22 17:44 1,782 --a------ C:\FindB.txt)
2008-08-22 17:36 . 2008-08-22 17:58 <REP> d-------- C:\Program Files\Microsoft Windows OneCare Live
2008-08-22 15:01 . 2008-08-22 15:01 <REP> d--hs---- C:\WINDOWS\ftpcache
2008-08-22 15:01 . 2008-08-22 15:01 <REP> d-------- C:\Program Files\Free
2008-08-18 14:08 . 2008-08-18 14:08 4,096 --ahs---- C:\WINDOWS\system32\Thumbs.db
2008-08-15 13:30 . 2008-08-15 13:30 <REP> d-------- C:\Documents and Settings\Marine\Application Data\Samsung
2008-08-15 13:19 . 2006-05-03 22:53 174,592 --a------ C:\WINDOWS\system32\framedyn.dll
2008-08-15 13:18 . 2006-07-24 16:05 5,632 --a------ C:\WINDOWS\system32\drivers\StarOpen.sys
2008-08-15 13:15 . 2008-08-15 13:19 <REP> d-------- C:\WINDOWS\system32\Samsung_USB_Drivers
2008-08-15 13:15 . 2008-08-15 13:15 <REP> d-------- C:\Program Files\Samsung
2008-08-15 13:15 . 2005-08-30 17:59 94,000 --a------ C:\WINDOWS\system32\drivers\ss_mdm.sys
2008-08-15 13:15 . 2005-08-30 17:57 58,320 --a------ C:\WINDOWS\system32\drivers\ss_bus.sys
2008-08-15 13:15 . 2005-08-30 17:58 8,304 --a------ C:\WINDOWS\system32\drivers\ss_mdfl.sys
2008-08-15 13:15 . 2005-08-30 17:58 6,144 --a------ C:\WINDOWS\system32\drivers\ss_cmnt.sys
2008-08-15 13:15 . 2005-08-30 17:58 6,144 --a------ C:\WINDOWS\system32\drivers\ss_cm.sys
2008-08-15 13:15 . 2005-08-30 17:57 5,808 --a------ C:\WINDOWS\system32\drivers\ss_whnt.sys
2008-08-15 13:15 . 2005-08-30 17:57 5,808 --a------ C:\WINDOWS\system32\drivers\ss_wh.sys
2008-08-15 13:15 . 2005-08-28 20:51 766 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-08-10 16:04 . 2008-08-10 16:04 <REP> d-------- C:\Documents and Settings\Marine\Application Data\Apple Computer
2008-07-28 18:42 . 2008-08-22 17:36 <REP> d-------- C:\Program Files\Windows Live Safety Center
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-22 14:45 729,632 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-08-22 14:45 56,014,368 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-08-22 14:36 754,136 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-08-22 14:36 72,488 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-08-15 11:18 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-18 14:09 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-07-18 14:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Adobe Systems
2008-07-18 14:06 --------- d-----w C:\Program Files\Fichiers communs\Adobe Systems Shared
2008-07-14 12:49 --------- d-----w C:\Documents and Settings\Marine\Application Data\Desperate Housewives
2008-07-11 13:56 98,304 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2008-07-11 13:49 --------- d-----w C:\Documents and Settings\Marine\Application Data\InstallShield
2008-06-30 19:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-06-30 19:26 --------- d-----w C:\Program Files\Apple Software Update
2008-06-30 19:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-06-20 13:49 64,111 ----a-w C:\WINDOWS\BricoPackUninst.cmd
2008-06-20 13:49 6,116 ----a-w C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-06-20 13:49 219,648 ----a-w C:\WINDOWS\system32\uxtheme.dll
.
------- Sigcheck -------
2007-07-30 19:19 68440 84d9a61860272d6177d46c86b8431557 C:\WINDOWS\system32\wuauclt.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ÚlÚments vides & les ÚlÚments initiaux lÚgitimes ne sont pas listÚs
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="D:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe" [2007-03-19 00:05 630784]
"MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" [2008-05-07 14:52 190024]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
"eMuleAutoStart"="D:\Emule\emule.exe" [2007-05-13 16:57 5308416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"SNPSTD2"="C:\WINDOWS\vsnpstd2.exe" [2004-08-30 18:37 286720]
"QuickTime Task"="D:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 14:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 14:00 455168]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 14:00 208952]
"Adobe Reader Speed Launcher"="D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 20:51 39792]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 15:28 577536 C:\WINDOWS\soundman.exe]
C:\Documents and Settings\Marine\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50 113664]
RocketDock.lnk - D:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe [2007-03-19 00:05:02 630784]
TransBar.lnk - D:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe [2005-06-01 21:41:18 65536]
UberIcon.lnk - D:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe [2006-05-21 09:43:08 180224]
[HKLM\~\startupfolder\C:^Documents and Settings^Marine^Menu Démarrer^Programmes^Démarrage^Y'z Shadow.lnk]
backup=C:\WINDOWS\pss\Y'z Shadow.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R3 snpstd2;Trust WB-3100P Portable Webcam;C:\WINDOWS\system32\DRIVERS\snpstd2.sys [2004-10-14 19:12]
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 17:57]
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 17:58]
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 17:59]
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Scheduled Tasks/TÔches planifiÚes'
2008-08-13 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
2008-08-19 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1211047110.job
- D:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2002-12-02 21:38]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-RegistryMechanic - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Marine\Application Data\Mozilla\Firefox\Profiles\y0hgrvya.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://skyrock.com
FF -: plugin - D:\Program Files\Adobe\Reader 8.0\Reader\browser\nppdf32.dll
FF -: plugin - D:\Program Files\DivX\DivX Player\npDivxPlayerPlugin.dll
FF -: plugin - D:\Program Files\QuickTime\Plugins\npqtplugin.dll
FF -: plugin - D:\Program Files\QuickTime\Plugins\npqtplugin2.dll
FF -: plugin - D:\Program Files\QuickTime\Plugins\npqtplugin3.dll
FF -: plugin - D:\Program Files\QuickTime\Plugins\npqtplugin4.dll
FF -: plugin - D:\Program Files\QuickTime\Plugins\npqtplugin5.dll
FF -: plugin - D:\Program Files\QuickTime\Plugins\npqtplugin6.dll
FF -: plugin - D:\Program Files\QuickTime\Plugins\npqtplugin7.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-23 13:40:36
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachÚs ...
Balayage cachÚ autostart entries ...
Balayage des fichiers cachÚs ...
Scan terminÚ avec succÞs
Les fichiers cachÚs: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\wdfmgr.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-08-23 13:41:21 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-23 11:41:18
Pre-Run: 1,765,081,088 octets libres
Post-Run: 2,175,631,360 octets libres
186 --- E O F --- 2008-05-07 10:52:32