Tres bien je continue.....
le rapport
ComboFix 08-11-09.04 - Administrateur 2008-11-10 22:55:13.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.369 [GMT 1:00]
Lancé depuis: c:\documents and settings\Administrateur\Bureau\C-Fix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrateur\Mes documents\My Documents.url
c:\install\install.exe
c:\program files\Applications\iebr.dll
c:\program files\Applications\iebt.dll
c:\program files\Applications\iebu.exe
c:\program files\Applications\myd.ico
c:\program files\Applications\mym.ico
c:\program files\Applications\myp.ico
c:\program files\Applications\myv.ico
c:\program files\Applications\ot.ico
c:\program files\Applications\ts.ico
c:\program files\Applications\wcm.exe
c:\program files\Applications\wcs.exe
c:\windows\system32\_000003_.tmp.dll
c:\windows\system32\892267
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-10 au 2008-11-10 ))))))))))))))))))))))))))))))))))))
.
2008-11-10 22:50 . 2008-11-10 22:50 <REP> d-------- C:\CFix.exe
2008-11-10 22:32 . 2008-11-10 22:41 <REP> d-------- C:\ToolBar SD
2008-11-10 21:19 . 2008-11-10 21:26 <REP> d-------- c:\program files\ViRsLab
2008-11-10 21:19 . 2008-11-10 22:59 <REP> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2008-11-10 21:17 . 2008-11-10 22:57 <REP> d-------- c:\program files\Applications
2008-11-08 21:41 . 2008-11-08 21:42 <REP> d-------- c:\program files\TVAnts
2008-11-08 21:11 . 2008-11-08 21:11 <REP> d-------- c:\program files\SopCast
2008-11-05 20:57 . 2008-11-05 20:57 <REP> d-------- c:\documents and settings\All Users\Application Data\TVU Networks
2008-11-04 19:52 . 2008-11-10 21:15 54,156 --ah----- c:\windows\QTFont.qfn
2008-11-04 19:52 . 2008-11-04 19:52 1,409 --a------ c:\windows\QTFont.for
2008-11-04 19:42 . 2008-11-04 19:42 <REP> dr-h----- c:\documents and settings\Administrateur\Application Data\SecuROM
2008-11-01 14:41 . 2008-11-01 14:41 107,888 --a------ c:\windows\system32\CmdLineExt.dll
2008-11-01 14:40 . 2008-11-01 14:40 <REP> d-------- c:\documents and settings\Administrateur\Application Data\Leadertech
2008-11-01 14:13 . 2008-11-01 14:13 <REP> d-------- c:\program files\EA Sports
2008-11-01 14:09 . 2001-08-23 17:04 12,288 --a------ c:\windows\system32\drivers\mouhid.sys
2008-11-01 14:09 . 2001-08-23 17:04 12,288 --a--c--- c:\windows\system32\dllcache\mouhid.sys
2008-11-01 14:07 . 2008-11-01 14:07 <REP> d-------- c:\program files\Logitech
2008-11-01 14:07 . 2008-11-01 14:07 <REP> d-------- c:\program files\Fichiers communs\Logitech
2008-11-01 14:07 . 2004-04-14 11:08 44,064 --a------ c:\windows\system32\drivers\WmXlCore.sys
2008-11-01 14:07 . 2004-04-14 11:08 21,280 --a------ c:\windows\system32\drivers\WmFilter.sys
2008-11-01 14:07 . 2004-04-14 11:08 10,144 --a------ c:\windows\system32\drivers\WmBEnum.sys
2008-11-01 14:07 . 2004-04-14 11:08 5,600 --a------ c:\windows\system32\drivers\WmVirHid.sys
2008-10-20 23:52 . 2008-10-20 23:52 3,532 --a------ C:\drmHeader.bin
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-10 20:26 --------- d-----w c:\program files\PokerStars
2008-11-08 20:41 15,360 --s-a-w c:\windows\system32\ebmkdz.dll
2008-11-01 13:07 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-02 21:09 --------- d-----w c:\documents and settings\Administrateur\Application Data\BSplayer
2008-09-24 21:25 --------- d-----w c:\program files\eMule
2008-09-24 20:12 --------- d-----w c:\program files\MSN Messenger
2008-09-24 20:08 --------- d-----w c:\program files\PPMate
2008-09-24 20:05 --------- d-----w c:\documents and settings\Administrateur\Application Data\SopCast
2008-09-24 20:03 --------- d-----w c:\documents and settings\Administrateur\Application Data\ppStream
2008-09-24 20:01 --------- d-----w c:\program files\Fichiers communs\Synacast
2008-09-24 20:01 --------- d-----w c:\documents and settings\Administrateur\Application Data\PPMate
2008-09-19 21:54 --------- d-----w c:\program files\Webteh
2008-09-19 21:54 --------- d-----w c:\documents and settings\Administrateur\Application Data\BSplayer Pro
2008-09-15 15:39 1,846,144 ----a-w c:\windows\system32\win32k.sys
2008-09-14 15:14 228,362 ----a-w C:\.reg
2008-08-20 05:37 663,552 ----a-w c:\windows\system32\wininet.dll
2008-08-14 13:44 2,182,400 ----a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 13:44 2,059,776 ----a-w c:\windows\system32\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Camfrog"="c:\program files\Camfrog\Camfrog Video Chat\CamfrogNet.exe" [2003-09-29 36352]
"ViRsLab"="c:\program files\ViRsLab\ViRsLab.exe" [2008-11-05 1810432]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Monitor"="c:\windows\Philips\SPC610NC\Monitor.exe" [2006-11-03 319488]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-12-02 185896]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-01-31 385024]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"NeroCheck"="c:\windows\system32\\NeroCheck.exe" [2001-07-09 155648]
"FixCamera"="c:\windows\FixCamera.exe" [2007-07-11 20480]
"tsnp2std"="c:\windows\tsnp2std.exe" [2007-05-12 270336]
"snp2std"="c:\windows\vsnp2std.exe" [2007-05-10 344064]
c:\documents and settings\Administrateur\Menu D‚marrer\Programmes\D‚marrage\
Enregistrement de FIFA 09.lnk - c:\program files\EA Sports\FIFA 09\Support\EAregister.exe [2008-08-13 4369408]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
VProperty.lnk - c:\windows\VPro610.exe [2007-11-25 465408]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Mythology\\aomx.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Camfrog\\Camfrog Video Chat\\Camfrog Video Chat.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"c:\\Program Files\\SopCast\\SopCast.exe"=
"c:\\Program Files\\TVAnts\\Tvants.exe"=
"c:\\Program Files\\PPMate\\ppmate.exe"=
"c:\\Program Files\\PPMate\\ppamnet.exe"=
"c:\\Program Files\\Zattoo\\zattood.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"25245:TCP"= 25245:TCP:BitComet 25245 TCP
"25245:UDP"= 25245:UDP:BitComet 25245 UDP
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R3 SNP2STD;USB2.0 PC Camera (SNP2STD);c:\windows\system32\DRIVERS\snp2sxp.sys [2007-07-23 12178944]
S3 Ltn_stk7070P;PCTV based TV tuner device;c:\windows\system32\DRIVERS\Ltn_stk7070P.sys [2007-06-14 466048]
S3 Ltn_stkrc;PCTV Infrared Receiver;c:\windows\system32\DRIVERS\Ltn_stkrc.sys [2007-06-13 13440]
S3 SPC610NC;SPC 610NC Laptop Camera;c:\windows\system32\DRIVERS\SPC610NC.SYS [2006-12-04 492416]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e51c7624-d34d-11dc-a240-0002b35c6a40}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe pagefile.sys.vbs
.
Contenu du dossier 'Tâches planifiées'
2008-11-04 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{8710DF42-3171-4A3B-9079-3F7D7101552B} - c:\program files\Applications\iebt.dll
Toolbar-{E43B6656-814B-4839-8FF8-AFFDE0DA9A3F} - c:\program files\Applications\iebr.dll
WebBrowser-{E43B6656-814B-4839-8FF8-AFFDE0DA9A3F} - c:\program files\Applications\iebr.dll
HKLM-Run-EdenFlirt - c:\program files\Eden Flirt\EdenFlirt.exe
HKLM-Explorer_Run-smile - c:\program files\Applications\wcs.exe
.
------- Examen supplémentaire -------
.
FireFox -: Profile - c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\knkanj06.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://search.camfrog.com/search.php?q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://fr.blackle.com/
FF -: plugin - c:\program files\Yahoo!\Common\npyaxmpb.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-10 22:59:18
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\WgaTray.exe
c:\program files\Camfrog\Camfrog Video Chat\Camfrog Video Chat.exe
.
**************************************************************************
.
Heure de fin: 2008-11-10 23:03:20 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-11-10 22:03:15
Avant-CF: 1 488 199 680 octets libres
Après-CF: 1,706,070,016 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
171 --- E O F --- 2008-11-05 02:02:14