Voici le rapport du pc avec xp
ComboFix 08-10-11.04 - partage 2008-10-12 21:07:35.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.316 [GMT 2:00]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\partage\Application Data\m
C:\Documents and Settings\partage\Application Data\m\flec006.exe
C:\WINDOWS\system32\ban_list.txt
C:\WINDOWS\system32\drivers\downld
C:\WINDOWS\system32\drivers\downld\105015.exe
C:\WINDOWS\system32\drivers\downld\107953.exe
C:\WINDOWS\system32\drivers\downld\108906.exe
C:\WINDOWS\system32\drivers\downld\109625.exe
C:\WINDOWS\system32\drivers\downld\110828.exe
C:\WINDOWS\system32\drivers\downld\111375.exe
C:\WINDOWS\system32\drivers\downld\111812.exe
C:\WINDOWS\system32\drivers\downld\114765.exe
C:\WINDOWS\system32\drivers\downld\116265.exe
C:\WINDOWS\system32\drivers\downld\124531.exe
C:\WINDOWS\system32\drivers\downld\126031.exe
C:\WINDOWS\system32\drivers\downld\127546.exe
C:\WINDOWS\system32\drivers\downld\133093.exe
C:\WINDOWS\system32\drivers\downld\137500.exe
C:\WINDOWS\system32\drivers\downld\142406.exe
C:\WINDOWS\system32\drivers\downld\144171.exe
C:\WINDOWS\system32\drivers\downld\150750.exe
C:\WINDOWS\system32\drivers\downld\152234.exe
C:\WINDOWS\system32\drivers\downld\154296.exe
C:\WINDOWS\system32\drivers\downld\160187.exe
C:\WINDOWS\system32\drivers\downld\164562.exe
C:\WINDOWS\system32\drivers\downld\165078.exe
C:\WINDOWS\system32\drivers\downld\167500.exe
C:\WINDOWS\system32\drivers\downld\180812.exe
C:\WINDOWS\system32\drivers\downld\185531.exe
C:\WINDOWS\system32\drivers\downld\213546.exe
C:\WINDOWS\system32\drivers\downld\217640.exe
C:\WINDOWS\system32\drivers\downld\217906.exe
C:\WINDOWS\system32\drivers\downld\227937.exe
C:\WINDOWS\system32\drivers\downld\230703.exe
C:\WINDOWS\system32\drivers\downld\239781.exe
C:\WINDOWS\system32\drivers\downld\251281.exe
C:\WINDOWS\system32\drivers\downld\260062.exe
C:\WINDOWS\system32\drivers\downld\262203.exe
C:\WINDOWS\system32\drivers\downld\272921.exe
C:\WINDOWS\system32\drivers\downld\279281.exe
C:\WINDOWS\system32\drivers\downld\288906.exe
C:\WINDOWS\system32\drivers\downld\289953.exe
C:\WINDOWS\system32\drivers\downld\359578.exe
C:\WINDOWS\system32\drivers\downld\388406.exe
C:\WINDOWS\system32\drivers\downld\390203.exe
C:\WINDOWS\system32\drivers\downld\415984.exe
C:\WINDOWS\system32\drivers\downld\420375.exe
C:\WINDOWS\system32\drivers\downld\429296.exe
C:\WINDOWS\system32\drivers\downld\457359.exe
C:\WINDOWS\system32\drivers\downld\466218.exe
C:\WINDOWS\system32\drivers\downld\508187.exe
C:\WINDOWS\system32\drivers\downld\523406.exe
C:\WINDOWS\system32\drivers\downld\534453.exe
C:\WINDOWS\system32\drivers\downld\94640.exe
C:\WINDOWS\system32\drivers\downld\97203.exe
C:\WINDOWS\system32\drivers\downld\98171.exe
C:\WINDOWS\system32\drivers\downld\99046.exe
C:\WINDOWS\system32\drivers\hldrrr.exe
C:\WINDOWS\system32\drivers\srosa.sys
C:\WINDOWS\system32\MabryObj.dll
C:\WINDOWS\system32\mdelk.exe
C:\WINDOWS\system32\mdm.exe
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\wintems.exe
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_BOONTY_GAMES
-------\Service_Boonty Games
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-12 au 2008-10-12 ))))))))))))))))))))))))))))))))))))
.
2008-10-12 20:40 . 2008-10-12 20:40 <REP> d-------- C:\CATHIE
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-05 21:57 --------- d-----w C:\Program Files\Windows Live
2008-10-05 21:43 413,472 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-10-05 21:43 41,540 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-10-05 21:43 211,580 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-05 21:43 15,515,168 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-05 21:04 --------- d-----w C:\Program Files\eMule
2008-10-05 20:41 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-05 19:03 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-09-09 09:41 --------- d-----w C:\Program Files\Java
2008-08-30 15:32 --------- d-----w C:\Program Files\Dofus
2008-07-18 18:39 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
2008-07-16 18:33 691,545 ----a-w C:\WINDOWS\unins000.exe
2006-12-10 14:26 275 ----a-w C:\Documents and Settings\Incomplete\downloads.dat
2006-11-01 21:29 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2005-12-22 18:03 93 ---ha-w C:\Program Files\desktop.ini
2005-07-11 20:06 37 ----a-w C:\Documents and Settings\partage\getfile.dat
2004-11-20 08:02 21 ----a-w C:\Program Files\AVPersonalAVWIN.INI
2003-11-20 19:34 33,208 ----a-w C:\Documents and Settings\partage\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\Msmsgs.exe" [2005-06-08 1658080]
"DAEMON Tools Pro Agent"="C:\Program Files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 136136]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-10-12 786440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-03-27 155648]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"ISUSScheduler"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2005-12-10 133016]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"snpstd"="C:\WINDOWS\vsnpstd.exe" [2004-06-10 286720]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-20 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableStatusMessages"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"=hex(2):25,53,79,73,74,65,6d,52,6f,6f,74,25,5c,73,79,73,74,65,6d,33,32,\
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"vidc.dmb1"= m3jpeg32.dll
"vidc.jpeg"= m3jpeg32.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Exif Launcher.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Exif Launcher.lnk
backup=C:\WINDOWS\pss\Exif Launcher.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^hp psc 1000 series.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\hp psc 1000 series.lnk
backup=C:\WINDOWS\pss\hp psc 1000 series.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^hpoddt01.exe.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\hpoddt01.exe.lnk
backup=C:\WINDOWS\pss\hpoddt01.exe.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech Desktop Messenger.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Slim Multimedia Keyboard.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Slim Multimedia Keyboard.lnk
backup=C:\WINDOWS\pss\Slim Multimedia Keyboard.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^partage^Menu Démarrer^Programmes^Démarrage^MSN Pictures Displayer.lnk]
path=C:\Documents and Settings\partage\Menu Démarrer\Programmes\Démarrage\MSN Pictures Displayer.lnk
backup=C:\WINDOWS\pss\MSN Pictures Displayer.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^partage^Menu Démarrer^Programmes^Démarrage^Thumbs.db]
path=C:\Documents and Settings\partage\Menu Démarrer\Programmes\Démarrage\Thumbs.db
backup=C:\WINDOWS\pss\Thumbs.dbStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ACTIVBOARD]
--a------ 2003-05-02 11:31 24576 c:\APPS\ABoard\ABOARD.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a------ 2004-05-15 21:10 339968 C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IncrediMail]
--a------ 2005-05-25 13:07 188459 C:\Program Files\IncrediMail\bin\IncMail.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2006-02-23 15:45 278528 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
--a------ 2006-01-09 21:42 20480 C:\Program Files\Logitech\Desktop Messenger\8876480\Program\backWeb-8876480.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mmtask]
--a------ 2004-08-29 13:36 53248 C:\Program Files\Musicmatch\mmtask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2005-06-08 11:17 1658080 C:\PROGRA~1\MESSEN~1\Msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 11:50 155648 C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2006-03-27 00:00 155648 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VCSPlayer]
--a------ 2003-08-13 10:33 299008 C:\Program Files\Virtual CD v4 SDK\System\vcsplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\Messenger\\Msmsgs.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"C:\\Program Files\\MSN7\\MSN Messenger\\msnmsgr.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\BitTornado\\btdownloadgui.exe"=
"C:\\Program Files\\Musicmatch\\mm_server.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=
"C:\\Program Files\\BitTornado 0-3-7\\btdownloadgui.exe"=
"C:\\Program Files\\BitTornado 0-3-14\\btdownloadgui.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\iMesh Applications\\iMesh\\iMesh.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 PzWDM;PzWDM;C:\WINDOWS\system32\Drivers\PzWDM.sys [2004-03-10 15172]
R1 Asapi;Asapi;C:\WINDOWS\system32\drivers\Asapi.sys [2002-08-06 11264]
R1 kbfilter;Keyboard Filter Driver;C:\WINDOWS\system32\drivers\kbfilter.sys [2001-11-27 11886]
R1 vcsmpdrv;vcsmpdrv;C:\WINDOWS\system32\DRIVERS\vcsmpdrv.sys [2003-06-16 49024]
R2 NwSapAgent;Agent SAP;C:\WINDOWS\System32\svchost.exe [2004-08-20 14336]
R2 SVKP;SVKP;C:\WINDOWS\System32\SVKP.sys [2003-11-11 2368]
R2 VCSSecS;Virtual CD v4 Security service (SDK - Version);C:\Program Files\Virtual CD v4 SDK\system\vcssecs.exe [2002-05-16 139264]
R3 HCWBT8XX;Hauppauge WinTV 848/9 WDM Video Driver;C:\WINDOWS\system32\drivers\HCWBT8XX.sys [2005-03-02 465988]
S1 Klmc;Klmc;C:\WINDOWS\system32\drivers\klmc.sys [ ]
S2 FILESpy;FILESpy;C:\Program Files\Softwin\BitDefender8\filespy.sys [ ]
S3 camvid20;Philips ToUcam Camera; Video;C:\WINDOWS\system32\DRIVERS\camdrv21.sys [ ]
S3 MRVW225;802.11g/b Wireless LAN Dirver for Windows XP;C:\WINDOWS\system32\DRIVERS\MRVW225.sys [2006-09-29 299904]
.
- - - - ORPHELINS SUPPRIMES - - - -
WebBrowser-{1E4BF1D1-35F3-4BC5-9D2B-B843C47312ED} - (no file)
HKLM-Run-ISUSPM Startup - C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe
HKLM-Run-StandardInstall - (no file)
MSConfigStartUp-Kapersky - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe
MSConfigStartUp-KAVPersonal50 - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\kav.exe
MSConfigStartUp-LogitechSoftwareUpdate - C:\Program Files\Logitech\Video\ManifestEngine.exe
MSConfigStartUp-LogitechVideoRepair - C:\Program Files\Logitech\Video\ISStart.exe
MSConfigStartUp-LogitechVideoTray - C:\Program Files\Logitech\Video\LogiTray.exe
MSConfigStartUp-LVCOMSX - C:\WINDOWS\system32\LVCOMSX.EXE
MSConfigStartUp-New - C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL
MSConfigStartUp-REGSHAVE - C:\Program Files\REGSHAVE\REGSHAVE.EXE
MSConfigStartUp-Sony Ericsson PC Suite - C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
MSConfigStartUp-SunJavaUpdateSched - C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
MSConfigStartUp-SwPrnMon - C:\Program Files\Fichiers communs\Sowedoo Shared\Sowedoo PDF Printer V4\SwPrnMon.exe
MSConfigStartUp-Windows Accelerators - c:\documents and settings\partage\application data\setup.exe
MSConfigStartUp-WindowsServicesStartup - C:\DOCUME~1\partage\LOCALS~1\Temp\svchost.exe
MSConfigStartUp-TkBellExe - realsched.exe
.
------- Examen supplémentaire -------
.
FireFox -: Profile - C:\Documents and Settings\partage\Application Data\Mozilla\Firefox\Profiles\default.o3b\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://fr.yahoo.com/
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-12 21:23:16
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
PROCESSUS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
------------------------ Autres processus actifs ------------------------
.
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
.
**************************************************************************
.
Heure de fin: 2008-10-12 21:33:52 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-10-12 19:33:47
Avant-CF: 59,515,146,240 octets libres
Après-CF: 59,338,289,152 octets libres
252 --- E O F --- 2008-09-21 14:16:33