voici le rapport
ComboFix 08-11-11.01 - darty 2008-11-12 15:22:16.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.343 [GMT 1:00]
Lancé depuis: c:\documents and settings\darty\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\outlook
c:\windows\system32\awtutttU.dll
c:\windows\system32\dljkbm.dll
c:\windows\system32\dplpfleu.dll
c:\windows\system32\dtmmdjkv.dll
c:\windows\system32\fgadsfhm.ini
c:\windows\system32\gfdciiva.dll
c:\windows\system32\iqkakp.dll
c:\windows\system32\lmwnlegj.dll
c:\windows\system32\lousqglx.dll
c:\windows\system32\mhfsdagf.dll
c:\windows\system32\qusqftwi.dll
c:\windows\system32\raywtz.dll
c:\windows\system32\tdfkrdri.dll
c:\windows\system32\Utttutwa.ini
c:\windows\system32\Utttutwa.ini2
c:\windows\system32\vkjdmmtd.ini
c:\windows\system32\wzxqjh.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-12 au 2008-11-12 ))))))))))))))))))))))))))))))))))))
.
2008-11-12 13:58 . 2008-11-12 15:10 <REP> d-------- c:\program files\Navilog1
2008-11-12 13:46 . 2008-11-12 14:21 <REP> d-------- c:\program files\UsbFix
2008-11-12 13:23 . 2008-11-12 13:50 <REP> d-------- c:\program files\NOS
2008-11-12 13:23 . 2008-11-12 13:50 <REP> d-------- c:\documents and settings\All Users\Application Data\NOS
2008-11-12 13:04 . 2008-11-12 13:04 <REP> d-------- C:\rsit
2008-11-12 13:04 . 2008-11-12 13:04 <REP> d-------- c:\program files\trend micro
2008-11-11 21:41 . 2008-11-11 21:43 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-11-11 15:00 . 2008-11-12 13:49 <REP> d-------- c:\program files\Spybot - Search & Destroy
2008-11-11 15:00 . 2008-11-12 13:05 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-10 14:03 . 2008-11-11 20:17 <REP> d-------- c:\program files\Fighters
2008-11-10 14:03 . 2008-11-10 14:03 <REP> d-------- c:\documents and settings\All Users\Application Data\Fighters
2008-11-05 13:17 . 2008-11-05 13:17 <REP> d-------- c:\documents and settings\darty\Application Data\Vodafone Mobile Connect
2008-11-04 15:02 . 2008-11-04 15:02 <REP> d-------- c:\program files\DAEMON Tools Lite
2008-11-04 14:55 . 2008-11-04 14:55 <REP> d-------- c:\documents and settings\darty\Application Data\DAEMON Tools
2008-11-04 14:55 . 2008-11-04 14:55 717,296 --a------ c:\windows\system32\drivers\sptd.sys
2008-10-24 09:42 . 2008-10-15 17:35 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-10-16 10:55 . 2008-08-14 14:23 2,191,232 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-10-16 10:55 . 2008-08-14 14:23 2,147,328 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-10-16 10:55 . 2008-08-14 14:23 2,068,096 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-10-16 10:55 . 2008-08-14 14:23 2,025,984 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-10-16 10:55 . 2008-09-15 16:26 1,846,528 -----c--- c:\windows\system32\dllcache\win32k.sys
2008-10-16 10:55 . 2008-09-08 11:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
2008-10-13 21:27 . 2008-10-13 21:27 <REP> d-------- c:\program files\Canal
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-12 14:31 --------- d-----w c:\program files\Wanadoo
2008-11-12 12:43 --------- d-----w c:\documents and settings\darty\Application Data\Skype
2008-11-12 12:38 --------- d-----w c:\program files\Java
2008-11-12 12:31 --------- d-----w c:\program files\Fichiers communs\Adobe
2008-11-05 12:18 --------- d-----w c:\program files\Vodafone
2008-11-01 23:52 --------- d-----w c:\documents and settings\darty\Application Data\PacificPoker4
2008-11-01 23:42 --------- d-----w c:\program files\Google
2008-11-01 23:33 --------- d-----w c:\program files\eMule
2008-10-16 23:41 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2008-10-10 17:49 --------- d-----w c:\program files\iTunes
2008-10-10 17:30 --------- d-----w c:\documents and settings\darty\Application Data\Apple Computer
2008-10-10 17:30 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-10 17:29 --------- d-----w c:\program files\iPod
2008-10-10 17:29 --------- d-----w c:\program files\Bonjour
2008-10-10 17:29 --------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2008-10-10 17:28 --------- d-----w c:\program files\QuickTime
2008-10-10 17:28 --------- d-----w c:\program files\Fichiers communs\Apple
2008-10-08 20:57 --------- d-----w c:\program files\Apple Software Update
2008-10-08 20:57 --------- d-----w c:\documents and settings\All Users\Application Data\Apple
2008-10-01 11:01 32,000 ----a-w c:\windows\system32\drivers\usbaapl.sys
2008-09-19 07:18 --------- d-----w c:\program files\BitTorrent Fastest Tool
2008-09-19 04:06 --------- d-----w c:\documents and settings\darty\Application Data\.ABC
2008-09-18 12:10 --------- d-----w c:\program files\ABC
2008-09-17 22:37 --------- d-----w c:\documents and settings\darty\Application Data\Roxio
2008-09-17 18:05 --------- d-----w c:\documents and settings\darty\Application Data\LaCie
2008-03-22 20:18 256 -c--a-w c:\documents and settings\darty\pool.bin
2007-04-06 13:09 278,528 -c--a-w c:\program files\Fichiers communs\FDEUnInstaller.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WOOKIT"="c:\progra~1\Wanadoo\GestMaj.exe" [2004-10-14 32768]
"SsAAD.exe"="c:\progra~1\Sony\SONICS~1\SsAAD.exe" [2006-05-08 81920]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2006-01-18 19477544]
"ISUSPM"="c:\documents and settings\All Users\Application Data\Macrovision\FLEXnet Connect\6\ISUSPM.exe" [2007-03-29 222128]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-07-06 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-07-06 7561216]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-11-17 118784]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"VAIOCameraUtility"="c:\program files\Sony\VAIO Camera Utility\VCUServe.exe" [2005-12-27 69632]
"SonyPowerCfg"="c:\program files\Sony\VAIO Power Management\SPMgr.exe" [2006-06-27 217088]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
"Switcher.exe"="c:\program files\Sony\Wireless Switch Setting Utility\Switcher.exe" [2006-02-14 176128]
"AppMon Utility"="c:\program files\Sony\AppMonUtil\AppMonUtility.exe" [2006-06-22 29696]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2005-03-03 483328]
"WOOWATCH"="c:\progra~1\Wanadoo\Watch.exe" [2004-08-23 20480]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2007-02-01 366400]
"VAIO Update 3"="c:\program files\Sony\VAIO Update 3\VAIOUpdt.exe" [2007-01-25 546936]
"WOOTASKBARICON"="c:\progra~1\Wanadoo\GestMaj.exe" [2004-10-14 32768]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"RoxWatchTray"="c:\program files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-08-16 236016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"Canal Widget"="c:\program files\Canal\Canal Widget\Launcher.exe" [2008-10-28 103992]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Mouse Suite 98 Daemon"="ICO.EXE" [2002-03-14 c:\windows\system32\ico.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\darty\Menu D‚marrer\Programmes\D‚marrage\
PowerReg Scheduler V3.exe [2007-03-31 225280]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= c:\windows\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= c:\windows\Resources\Themes\Royale.theme
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2006-03-09 13:51 73728 c:\windows\system32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=dljkbm.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"VIDC.dvsd"= c:\progra~1\FICHIE~1\SONYSH~1\VideoLib\sonydv.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Sony\\VAIO Media 5.0\\Vc.exe"=
"c:\\Program Files\\Adobe\\Photoshop Elements 4.0\\AdobePhotoshopElementsMediaServer.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Roxio\\Media Manager 9\\MediaManager9.exe"=
"c:\\Program Files\\Roxio\\Digital Home 9\\RoxioUPnPRenderer9.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\ABC\\abc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 CanalPlus.VOD;CanalPlus.VOD;c:\program files\Canal\Canal Widget\VOD\CanalPlus.VOD.exe [2008-11-01 61440]
R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe [2002-12-17 7520337]
R3 5U870CAP_VID_1262&PID_25FD;Sony Visual Communication Camera VGP-VCC2 ;c:\windows\system32\Drivers\5U870CAP.sys [2006-06-30 75264]
R3 SonyImgF;Sony Image Conversion Filter Driver;c:\windows\system32\DRIVERS\SonyImgF.sys [2006-03-06 30080]
R3 ti21sony;ti21sony;c:\windows\system32\drivers\ti21sony.sys [2007-04-23 812544]
R3 USBSTOR;Pilote de stockage de masse USB;c:\windows\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 AVerM115S;AVerM115S service;c:\windows\system32\DRIVERS\AVerM115S.sys [2006-07-26 754688]
S3 CnxEtP;ZTE ZXDSL852 Adapter Filter Driver;c:\windows\system32\DRIVERS\CnxEtP.sys [ ]
S3 CnxEtU;ZTE ZXDSL852 Interface Device Driver;c:\windows\system32\DRIVERS\CnxEtU.sys [ ]
S3 CnxTgNW;ZTE ZXDSL852 WAN PPPoA Adapter Driver;c:\windows\system32\DRIVERS\CnxTgNW.sys [ ]
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.SYS [2003-07-24 17149]
S3 Image Converter video recording monitor for VAIO Entertainment;Image Converter video recording monitor for VAIO Entertainment;c:\program files\Sony\Image Converter 2\IcVzMon.exe [2005-07-14 32768]
S3 PEEK5;PEEK5 Protocol Driver;c:\docume~1\darty\MESDOC~1\ERIC~1.BIG\CRACKW~1\WINAIR~1\PEEK5.SYS [ ]
S3 SIS163u;SiS163 usb Wireless LAN Adapter Driver;c:\windows\system32\DRIVERS\sis163u.sys [2005-06-20 215040]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;c:\program files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE [2002-12-17 311872]
S3 TSClient;Tatara Protocol Driver;c:\windows\system32\drivers\tsclient.sys [ ]
S3 usbscan;Pilote de scanneur USB;c:\windows\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 wg51und5;NETGEAR WG511U Wireless Network Adapter Service;c:\windows\system32\DRIVERS\wg51und5.sys [ ]
.
Contenu du dossier 'Tâches planifiées'
2008-11-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{5269A040-71BD-4442-94EE-4E87BBC1A254} - c:\windows\system32\awtutttU.dll
BHO-{bf60c61f-4a81-4e45-8ca0-16524ad66e99} - c:\windows\system32\dljkbm.dll
BHO-{C31C05B4-0A01-4DC2-8E5E-0315459F508E} - c:\windows\system32\wvUlmKbA.dll
HKCU-Run-updateMgr - c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
HKCU-Run-TomTomHOME.exe - c:\program files\TomTom HOME 2\HOMERunner.exe
HKLM-Run-54a58e5f - c:\windows\system32\mhfsdagf.dll
ShellExecuteHooks-{C31C05B4-0A01-4DC2-8E5E-0315459F508E} - c:\windows\system32\wvUlmKbA.dll
Notify-wvUlmKbA - wvUlmKbA.dll
.
------- Examen supplémentaire -------
.
FireFox -: Profile - c:\documents and settings\darty\Application Data\Mozilla\Firefox\Profiles\xpwlagrj.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.programme-tv.net/
FF -: plugin - c:\program files\Canal\Canal Widget\VOD\npCpVod.dll
FF -: plugin - c:\program files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\np_gp.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-12 15:31:01
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Intel\Wireless\Bin\EvtEng.exe
c:\program files\Intel\Wireless\Bin\S24EvMon.exe
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\windows\system32\FTRTSVC.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\ehome\ehRec.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Intel\Wireless\Bin\RegSrvc.exe
c:\program files\SigmaTel\C-Major Audio\WDM\stacsv.exe
c:\program files\Sony\VAIO Event Service\VESMgr.exe
c:\program files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
c:\windows\system32\searchindexer.exe
c:\windows\ehome\mcrdsvc.exe
c:\program files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
c:\program files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
c:\windows\system32\wscntfy.exe
c:\windows\ehome\ehmsas.exe
c:\program files\Apoint\ApntEx.exe
c:\progra~1\Wanadoo\TaskBarIcon.exe
c:\windows\system32\dllhost.exe
c:\program files\Sony\SonicStage Mastering Studio\Audio Filter\SSMSFilter.exe
c:\program files\Windows Desktop Search\WindowsSearch.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\searchfilterhost.exe
c:\windows\system32\searchprotocolhost.exe
.
**************************************************************************
.
Heure de fin: 2008-11-12 15:36:58 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-11-12 14:36:49
Avant-CF: 14 356 480 000 octets libres
Après-CF: 14,373,941,248 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /fastdetect /NoExecute=OptOut
257 --- E O F --- 2008-10-26 16:27:51