Voici le rapport
ComboFix 08-09-14.02 - Rémy TESTON 2008-09-15 11:29:36.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.243 [GMT 2:00]
Lancé depuis: C:\Documents and Settings\Rémy TESTON\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Camille TESTON\Cookies\camille_teston@bluestreak[1].txt
C:\Documents and Settings\Camille TESTON\Cookies\camille_teston@edt02[2].txt
C:\Documents and Settings\Camille TESTON\Cookies\camille_teston@ehg-dig.hitbox[1].txt
C:\Documents and Settings\Camille TESTON\Cookies\camille_teston@ehg-legonewyorkinc.hitbox[1].txt
C:\Documents and Settings\Camille TESTON\Cookies\camille_teston@fnac[1].txt
C:\Documents and Settings\Rémy TESTON\Cookies\rémy_teston@advertstream[2].txt
C:\Documents and Settings\Rémy TESTON\Cookies\rémy_teston@tradedoubler[1].txt
C:\WINDOWS\g32.txt
C:\WINDOWS\system32\phc5dfj0eg79.bmp
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASPIMGR
-------\Legacy_NPF
((((((((((((((((((((((((((((( Fichiers cr‚‚s du 2008-08-15 au 2008-09-15 ))))))))))))))))))))))))))))))))))))
.
2008-09-13 15:42 . 2008-09-13 15:42 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-09-13 13:10 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-09-13 13:10 . 2007-07-30 19:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-09-13 13:10 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-09-12 22:58 . 2008-09-12 22:58 <REP> d-------- C:\Program Files\Windows Live
2008-09-12 22:58 . 2008-09-12 22:58 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-09-12 22:58 . 2008-09-12 22:58 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-09-12 20:12 . 2008-09-12 20:12 <REP> d-------- C:\Program Files\CCleaner
2008-09-12 19:54 . 2008-09-12 19:54 <REP> d-------- C:\Documents and Settings\All Users\Application Data\NortonInstaller
2008-09-12 19:29 . 2008-09-12 19:29 <REP> d-------- C:\Program Files\Trend Micro
2008-09-12 19:12 . 2008-09-12 19:17 3,360 --a------ C:\Documents and Settings\Orph.egd
2008-09-12 19:09 . 2008-09-12 19:18 <REP> d-------- C:\ToolBar SD
2008-09-12 18:55 . 2008-09-12 18:55 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-12 18:55 . 2008-09-12 18:55 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-12 18:55 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-12 18:55 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-12 18:22 . 2008-09-12 18:33 3,556 --a------ C:\WINDOWS\system32\tmp.reg
2008-09-12 11:40 . 2008-09-12 17:12 <REP> d-------- C:\Program Files\DrWeb
2008-09-12 11:40 . 2008-09-12 11:40 77,824 --a----t- C:\WINDOWS\system32\DRWEBSP.DLL
2008-09-12 10:08 . 2008-09-12 10:08 <REP> d-------- C:\Documents and Settings\LocalService\Application Data\Webroot
2008-09-12 10:05 . 2008-09-12 10:05 164 --a------ C:\install.dat
2008-08-27 12:47 . 2008-08-27 12:47 11,022,034 --a------ C:\Program Files\setup-towebv2-fr.exe
2008-08-18 11:01 . 2008-08-18 11:01 <REP> d-------- C:\Program Files\Fichiers communs\Adobe AIR
2008-08-18 08:46 . 2008-08-29 19:18 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-08-18 08:46 . 2008-08-18 08:46 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-12 15:12 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-08 20:08 --------- d-----w C:\Program Files\eMule
2008-08-27 10:47 --------- d-----w C:\Program Files\Lauyan
2008-08-26 18:20 --------- d-----w C:\Documents and Settings\Camille TESTON\Application Data\MSN6
2008-07-28 15:39 --------- d-----w C:\Program Files\MP3 Player Utilities 4.17
2008-07-20 08:28 --------- d-----w C:\Program Files\Extrafilm FotoFacil
2008-07-16 13:34 --------- d-----w C:\Program Files\KONAMI
2008-03-21 18:06 6,105,952 ----a-w C:\Program Files\Firefox Setup 2.0.0.12.exe
2008-03-20 17:07 16,216,527 ----a-w C:\Program Files\jalbum_jalbum_7.4_version_windows_francais_12380.exe
2007-09-27 20:00 17,012,488 ----a-w C:\Program Files\setupfre.exe
2007-06-04 17:53 12,015,715 ----a-w C:\Program Files\Freeplayer-Win32-20070531.exe
2007-05-18 17:48 1,127,307 ----a-w C:\Program Files\wrar362fr.exe
2007-05-09 19:25 5,375,800 ----a-w C:\Program Files\picasaweb-current-setup.exe
2006-10-31 20:21 5,415,544 ----a-w C:\Program Files\DeliveryInstaller.exe
2006-09-23 19:53 14,405,024 ----a-w C:\Program Files\GoogleEarthWin.exe
2006-08-12 08:14 5,803,966 ----a-w C:\Program Files\Setup_FreeConverter.exe
2006-07-31 17:09 4,677,596 ----a-w C:\Program Files\eMule0.47a-Installer.exe
2006-03-28 11:42 11,778,429 ----a-w C:\Program Files\PDFCreator-0_9_0_GPLGhostscript.exe
2006-03-27 10:51 8,021,682 ----a-w C:\Program Files\setup-towebv1-fr.exe
2006-03-27 10:38 3,493,355 ----a-w C:\Program Files\FileZilla_2_2_19_setup.exe
2006-03-24 15:12 540,696 ----a-w C:\Program Files\webbuilder2.zip
2006-03-24 10:24 6,360,005 ----a-w C:\Program Files\nvu-1.0-win32-installer-fr.exe
2006-03-24 09:44 63,930,544 ----a-w C:\Program Files\Dreamweaver8-fr.exe
2006-03-14 18:30 2,187,668 ----a-w C:\Program Files\Tvants1_0_0_57Fr.exe
2005-11-24 17:54 33,417,372 ----a-w C:\Program Files\bestelsoft2.exe
2005-06-09 18:15 37,046,446 ----a-w C:\Program Files\NVE-3.1.0.7.exe
2005-06-09 18:12 33,831,916 ----a-w C:\Program Files\Nero-6.6.0.13.exe
2005-05-27 18:35 4,276,528 ----a-w C:\Program Files\eMule0.45b-Installer.exe
2004-11-23 13:52 5,248,968 ----a-w C:\Program Files\SetupDl.exe
2004-10-28 12:13 15,311,365 ----a-w C:\Program Files\AVSVideoConverter3.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-13 212992]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-06-10 339968]
"CapFax"="C:\Program Files\Classic PhoneTools\CapFax.EXE" [2001-12-10 20739]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"Microsoft Works Update Detection"="C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe" [2003-06-10 50688]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-17 69632]
"LVCOMS"="C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE" [2002-12-10 127022]
"LogitechGalleryRepair"="C:\Program Files\Logitech\ImageStudio\ISStart.exe" [2002-12-10 155648]
"LogitechImageStudioTray"="C:\Program Files\Logitech\ImageStudio\LogiTray.exe" [2002-12-10 61440]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2004-06-29 26112]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2004-06-29 98304]
"pdfw"="C:\Program Files\Amic Utilities\PDF Writer Pro\pdfwload.exe" [2004-03-25 32768]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 83608]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-20 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SRUUninstall"="C:\WINDOWS\System32\msiexec.exe" [2005-03-21 78848]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Uds77.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\SopCast\\SopCast\\SopCast.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\\Program Files\\Freeplayer\\vlc\\vlc.exe"=
"C:\\Program Files\\KONAMI\\Pro Evolution Soccer 2008\\PES2008.exe"=
"C:\\Program Files\\Lauyan\\TOWeb V1\\TOWeb.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
S0 Uds77;Uds77;C:\WINDOWS\system32\Drivers\Uds77.sys [ ]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;C:\WINDOWS\system32\DRIVERS\fbxusb32.sys [2004-10-20 21344]
S3 jfdcd;jfdcd;C:\DOCUME~1\RMYTES~1\LOCALS~1\Temp\jfdcd.sys [ ]
S3 MBAMSwissArmy;MBAMSwissArmy;C:\WINDOWS\system32\drivers\mbamswissarmy.sys [2008-09-10 38528]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{21db9c29-3e1b-11dd-b5ae-0007cb0000ff}]
\Shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e13f0161-7687-11dc-b3cb-0007cb0000ff}]
\Shell\Auto\command - cmd /C launch.bat
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL cmd /C launch.bat
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-Start WingMan Profiler - (no file)
HKCU-Run-WebCamRT.exe - (no file)
HKU-Default-Run-ALUAlert - C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe
HKU-Default-Run-Symantec NetDriver Warning - C:\PROGRA~1\SYMNET~1\SNDWarn.exe
.
------- Examen suppl‚mentaire -------
.
FireFox -: Profile - C:\Documents and Settings\Rémy TESTON\Application Data\Mozilla\Firefox\Profiles\sivknfkr.default\
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-15 11:40:06
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cach‚s ...
Recherche d'‚l‚ments en d‚marrage automatique cach‚s ...
Recherche de fichiers cach‚s ...
Scan termin‚ avec succŠs
Fichiers cach‚s: 0
**************************************************************************
.
--------------------- DLLs charg‚es dans les processus actifs ---------------------
PROCESSUS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
------------------------ Autres processus actifs ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Nikon\NkView6\NkvMon.exe
.
**************************************************************************
.
Heure de fin: 2008-09-15 11:47:00 - La machine a red‚marr‚
ComboFix-quarantined-files.txt 2008-09-15 09:46:54
Avant-CF: 28,902,285,312 octets libres
AprŠs-CF: 30,039,760,896 octets libres
182 --- E O F --- 2008-09-14 16:53:12