J'ai récupéré Combofix via un ami et il me semble qu'il a supprimé les fichiers TDS......... ça semble OK !
Merci de votre aide
ComboFix 08-12-14.01 - Erika 2008-12-14 22:39:28.3 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.511.134 [GMT 1:00]
Lancé depuis: c:\documents and settings\Erika\Bureau\Combo-Fix.exe
[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/B/COLOR
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\IE4 Error Log.txt
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\drivers\TDSSmhxt.sys
c:\windows\system32\TDSScfum.dll
c:\windows\system32\TDSSfxwp.dll
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSnrsr.dll
c:\windows\system32\TDSSofxh.dll
c:\windows\system32\TDSSosvd.dat
c:\windows\system32\TDSSrhym.log
c:\windows\system32\TDSSriqp.dll
c:\windows\system32\TDSSsbhc.dll
c:\windows\system32\TDSStkdv.log
c:\windows\system32\tmp.reg
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_TDSSSERV.SYS
-------\Legacy_TDSSSERV.SYS
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-14 au 2008-12-14 ))))))))))))))))))))))))))))))))))))
.
2008-12-14 22:04 . 2008-12-14 22:06 <REP> d-------- C:\logiciel_virus_14_12_2008
2008-12-14 17:00 . 2008-12-14 17:08 <REP> d-------- C:\ToolBar SD
2008-12-14 16:45 . 2008-12-14 16:45 <REP> d-------- c:\program files\Lopxp
2008-12-14 00:35 . 2008-12-14 00:39 <REP> d-------- c:\program files\Fighters
2008-12-14 00:35 . 2008-12-14 00:35 <REP> d-------- c:\documents and settings\All Users\Application Data\Fighters
2008-12-14 00:28 . 2008-12-14 00:28 <REP> d-------- c:\documents and settings\All Users\Application Data\Grisoft
2008-12-14 00:28 . 2007-05-30 13:10 10,872 --a------ c:\windows\system32\drivers\AvgAsCln.sys
2008-12-13 18:57 . 2008-12-13 18:57 <REP> d-------- c:\program files\Trend Micro
2008-12-13 17:06 . 2008-12-14 12:55 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-13 14:08 . 2008-12-13 14:08 <REP> d-------- c:\program files\Lavasoft
2008-12-13 14:08 . 2008-12-13 14:09 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2008-12-13 14:07 . 2008-12-13 14:07 <REP> d-------- c:\program files\Fichiers communs\Wise Installation Wizard
2008-12-13 13:51 . 2008-12-13 16:26 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-13 13:27 . 2008-12-13 13:27 0 --a------ c:\windows\nsreg.dat
2008-12-13 13:09 . 2008-12-13 13:09 <REP> d-------- c:\program files\Avira
2008-12-13 13:09 . 2008-12-13 13:09 <REP> d-------- c:\documents and settings\All Users\Application Data\Avira
2008-12-13 12:51 . 2008-12-13 12:51 22,148,280 --a------ c:\program files\antivir_workstation_winu_fr_h.exe
2008-12-07 18:48 . 2008-12-07 18:48 <REP> d-------- c:\program files\Alwil Software
2008-12-07 18:37 . 2008-12-07 18:37 29,540,960 --a------ c:\program files\setupfre.exe
2008-12-06 14:31 . 2008-12-14 20:55 <REP> d-------- c:\program files\adslTV
2008-12-06 14:30 . 2008-12-06 14:30 29,216,423 --a------ c:\program files\setup-adsltv.exe
2008-11-24 10:05 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-24 10:04 . 2008-09-04 18:16 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-18 11:01 . 2008-11-18 11:01 15,496 --a------ c:\windows\system32\drivers\vffilter.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-14 11:52 --------- d-----w c:\program files\Google
2008-12-07 17:43 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:18 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-03 10:03 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
2008-09-08 21:40 6,108,728 ----a-w c:\program files\picasaweb-current-setup.exe
2008-08-05 21:53 26,828,699 ----a-w c:\program files\Setup Hofmann Digital Album.exe
2007-11-04 22:51 1,271,557 -c--a-w c:\program files\wrar371fr.exe
2007-09-20 18:08 12,015,715 -c--a-w c:\program files\Freeplayer-Win32-20070531.exe
2007-09-19 18:16 9,679,815 -c--a-w c:\program files\vlc-0.8.6c-win32.exe
2007-09-12 19:37 23,661,600 -c--a-w c:\program files\DivXInstaller.exe
2006-09-15 20:58 14,066,359 -c--a-w c:\program files\LivreAlbumFujiPhoto.exe
.
((((((((((((((((((((((((((((( snapshot@2008-12-14_21.36.38.27 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-12-14 20:31:38 16,384 -c--a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-12-14 21:23:57 16,384 -c--a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-12-14 20:31:38 32,768 -c--a-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\index.dat
+ 2008-12-14 21:23:57 32,768 -c--a-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [BU]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2008-08-21 443968]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ezShieldProtector for Px"="c:\windows\System32\ezSP_Px.exe" [2002-08-20 40960]
"HKSERV.EXE"="c:\program files\Sony\HotKey Utility\HKserv.exe" [2004-02-12 98304]
"SonyPowerCfg"="c:\program files\sony\vaio power management\SPMgr.exe" [2003-12-11 167936]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"!AVG Anti-Spyware"="c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [BU]
"VAIO Update 2"="c:\program files\sony\vaio update 2\VAIOUpdt.exe" [2004-01-17 135168]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-01-21 155648]
"ISBMgr.exe"="c:\program files\Sony\ISB Utility\ISBMgr.exe" [2004-02-20 32768]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 241664]
"Hcontrol"="c:\windows\ATK0100\Hcontrol.exe" [2003-09-19 61440]
"Drag'n Drop CD+DVD"="c:\program files\drag'n drop cd+dvd\BinFiles\DragDrop.exe" [2004-02-02 1183744]
"BigDogPath"="c:\windows\VM_STI.EXE" [2004-06-09 40960]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-03-03 335872]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2003-11-07 114688]
"Mouse Suite 98 Daemon"="ICO.EXE" [2002-03-14 c:\windows\system32\ico.exe]
"BluetoothAuthenticationAgent"="irprops.cpl" [2008-04-14 c:\windows\system32\irprops.cpl]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 c:\windows\system32\Ati2mdxx.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Assistant d'Acrobat.lnk - c:\program files\Adobe\Acrobat 6.0\Distillr\acrotray.exe [2003-07-30 217195]
DSLMON.lnk - c:\program files\SAGEM\SAGEM F@st 800-840\dslmon.exe [2004-10-24 954475]
D‚marrage rapide de HP Photosmart Premier.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2006-02-10 73728]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= c:\progra~1\FICHIE~1\SONYSH~1\videolib\sonydv.dll
"SENTINEL"= snti386.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\adslTV\\adsltv.exe"=
R2 BBDemon;Backbone Service;c:\program files\Dassault Systemes\B10\intel_a\code\bin\CATSysDemon.exe -service []
R2 MioNet;MioNet Service;"c:\program files\MioNet\MioNetManager.exe" -s "c:\program files\MioNet\wrapper.conf" [2005-07-15 139264]
R2 PTK License-FIGHTERS-297811811;PTK License-FIGHTERS-297811811;c:\program files\Fighters\licenseservice.exe [2008-11-18 283272]
R2 PTK Scanner-FIGHTERS-297811811;PTK Scanner-FIGHTERS-297811811;c:\program files\Fighters\ScannerService.exe [2008-11-18 311944]
R2 PTK SharedAccess-FIGHTERS-297811811;PTK SharedAccess-FIGHTERS-297811811;c:\program files\Fighters\configservice.exe [2008-11-18 139912]
R3 SPI;Périphérique de contrôle d'E/S programmable Sony;c:\windows\system32\DRIVERS\SonyPI.sys [2004-03-25 37040]
R3 Vfscan;Vfscan;c:\windows\system32\DRIVERS\vffilter.sys [2008-11-18 15496]
S2 PTK Live Update-FIGHTERS-297811811;PTK Live Update-FIGHTERS-297811811;c:\program files\Fighters\updateservice.exe [2008-11-18 307848]
S3 ExpBRG;LAN-Express BR 802.11 Network Adapter Driver;c:\windows\system32\DRIVERS\ExpBRG.sys [2005-05-14 338176]
S3 FTD2XX;FTD2XX.SYS FT8U2XX device driver;c:\windows\system32\Drivers\FTD2XX.sys [2008-03-09 34431]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6baa2ea7-4945-11dd-83b0-080046d8a93b}]
\Shell\AutoRun\command - G:\wdsync.exe
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-Share-to-Web Namespace Daemon - c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
HKLM-Run-AVPCC - c:\program files\Kaspersky Lab\Kaspersky Anti-Virus Personal\avpcc.exe
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
c:\windows\system32\WS2_32.DLL - c:\windows\system32\CMDLGFR.DLL
c:\windows\system32\STDFTFR.DLL
c:\windows\system32\MSCMCFR.DLL
c:\windows\system32\MSSTKPRP.DLL
c:\windows\system32\MSPRPFR.DLL
c:\windows\system32\OLEAUT32.DLL
c:\windows\system32\OLEPRO32.DLL
c:\windows\system32\ASYCFILT.DLL
c:\windows\system32\STDOLE2.TLB
c:\windows\system32\COMCAT.DLL
c:\windows\system32\VB6FR.DLL
c:\windows\system32\MSVBVM60.DLL
c:\windows\phs.ico
c:\windows\system32\WINSKFR.DLL
c:\windows\system32\MSWINSCK.OCX
c:\windows\system32\DPDlg.ocx
c:\windows\System32\MSCOMCTL.OCX
c:\windows\System32\MSSTDFMT.DLL
c:\windows\System32\COMDLG32.OCX
c:\windows\system32\RsaCrypt.dll
c:\windows\Downloaded Program Files\newUpload.ocx
O16 -: {983AB2CC-3D50-11D9-ADFE-00062919A34C}
hxxp://www.photoservice.com/activeX/newUpload.CAB
c:\windows\Downloaded Program Files\newUpload.INF
FF - ProfilePath - c:\documents and settings\Erika\Application Data\Mozilla\Firefox\Profiles\vvldt90q.default\
FF - plugin: c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF - plugin: c:\program files\DivX\DivX Content Uploader\npUpload.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava11.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava12.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava13.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava14.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJava32.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF - plugin: c:\program files\Java\j2re1.4.2_03\bin\NPOJI610.dll
FF - plugin: c:\program files\Picasa2\npPicasa2.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-14 22:50:54
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\program files\Dassault Systemes\B10\intel_a\code\bin\CATSysDemon.exe
c:\windows\system32\Hummbird\inetd32.exe
c:\program files\MioNet\MioNetManager.exe
c:\windows\system32\HPZipm12.exe
c:\program files\MioNet\jvm\bin\MioNet.exe
c:\windows\system32\fxssvc.exe
c:\program files\sony\HotKey Utility\HKWnd.exe
c:\windows\ATK0100\ATKOSD.exe
c:\program files\Apoint\ApntEx.exe
c:\program files\HP\Digital Imaging\bin\hpqimzone.exe
.
**************************************************************************
.
Heure de fin: 2008-12-14 23:06:51 - La machine a redémarré [Erika]
ComboFix-quarantined-files.txt 2008-12-14 22:06:34
Avant-CF: 15,237,382,144 octets libres
Après-CF: 15,223,115,776 octets libres
223 --- E O F --- 2008-12-13 13:04:55