Voila le rapport.
costaud le bestiau
ComboFix 08-12-16.03 - ecco 2008-12-17 18:54:20.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.2046.1490 [GMT 1:00]
Lancé depuis: c:\documents and settings\ecco.ECCO-58A546ABD7\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/B/COLOR
.
[color=purple]Les fichiers ci-dessous ont été désactivés pendant l'exécution:/color
c:\program files\Agnitum\Outpost Firewall\wl_hook.dll
[i] ADS - svchost.exe: deleted 68 bytes in 1 streams. /i
[i] ADS - explorer.exe: deleted 132 bytes in 1 streams. /i
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\OPTIONS\CABS\_desktop.ini
c:\windows\system32\404Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
H:\autorun.inf
I:\autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_VFILT
-------\Service_VFILT
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-17 au 2008-12-17 ))))))))))))))))))))))))))))))))))))
.
2008-12-17 14:52 . 2008-10-16 14:06 268,648 --a------ c:\windows\system32\mucltui.dll
2008-12-17 14:52 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
2008-12-17 14:52 . 2008-10-16 14:06 27,496 --a------ c:\windows\system32\mucltui.dll.mui
2008-12-17 14:29 . 2008-12-17 14:29 98,304 --a------ c:\windows\system32\CmdLineExt.dll
2008-12-17 11:40 . 2008-12-17 11:40 <REP> d-------- c:\program files\MSECache
2008-12-17 10:25 . 2008-12-17 10:31 <REP> d-------- c:\program files\Windows Live
2008-12-17 10:25 . 2008-12-17 10:30 <REP> d--hsc--- c:\program files\Fichiers communs\WindowsLiveInstaller
2008-12-17 10:25 . 2008-12-17 10:27 <REP> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\WLInstaller
2008-12-17 10:04 . 2008-12-17 10:04 13,646 --a------ c:\windows\system32\wpa.bak
2008-12-17 08:22 . 2008-12-17 08:30 <REP> d-------- c:\windows\system32\CatRoot_bak
2008-12-17 08:18 . 2008-12-17 08:18 44,185,102 --a------ C:\Sauv.reg
2008-12-16 09:40 . 2008-12-16 09:50 0 --a------ c:\windows\system32\tmp.MSNFix
2008-12-16 09:39 . 2008-12-12 00:57 78,336 --a------ c:\windows\system32\Agent.OMZ.Fix.exe
2008-12-16 09:00 . 2008-12-16 09:00 <REP> d-------- c:\documents and settings\Administrateur\Application Data\Malwarebytes
2008-12-15 22:31 . 2008-12-15 22:37 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-15 22:31 . 2008-12-15 22:31 <REP> d-------- c:\documents and settings\ecco.ECCO-58A546ABD7\Application Data\Malwarebytes
2008-12-15 22:31 . 2008-12-15 22:31 <REP> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2008-12-15 22:31 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-15 22:31 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-15 22:25 . 2008-12-15 22:25 102,467 --a------ c:\windows\system32\msvcrt2.MSNFix
2008-12-15 21:58 . 2008-12-15 21:58 <REP> d-------- c:\program files\Java
2008-12-15 21:58 . 2008-12-15 21:58 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-15 21:58 . 2008-12-15 21:58 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-12-15 21:27 . 2008-12-15 21:28 <REP> d-------- c:\program files\Wanadoo
2008-12-15 21:27 . 2008-12-15 21:28 21 --a------ c:\windows\kit.ini
2008-12-15 21:23 . 2008-12-15 21:24 <REP> d-------- c:\program files\Inventel
2008-12-15 20:58 . 2008-12-16 09:50 <REP> d-------- C:\autorun.MSNFix
2008-12-15 20:57 . 2008-12-15 20:57 <REP> d-------- c:\documents and settings\ecco.ECCO-58A546ABD7\DoctorWeb
2008-12-15 17:48 . 2008-12-15 17:48 204 --a------ C:\nfts.MSNFix
2008-12-15 16:46 . 2008-12-17 08:27 <REP> d-------- c:\program files\EsetOnlineScanner
2008-12-15 16:41 . 2008-12-15 16:41 271,360 --a------ c:\windows\system32\drivers\atksgt.sys
2008-12-15 16:41 . 2008-12-15 16:41 18,048 --a------ c:\windows\system32\drivers\lirsgt.sys
2008-12-15 11:17 . 2008-12-16 20:04 <REP> d-------- c:\program files\Trend Micro
2008-12-15 10:30 . 2008-04-17 13:12 107,368 --a------ c:\windows\system32\GEARAspi.dll
2008-12-15 10:30 . 2008-04-17 13:12 15,464 --a------ c:\windows\system32\drivers\GEARAspiWDM.sys
2008-12-15 10:29 . 2008-12-15 10:29 <REP> d-------- c:\program files\iTunes
2008-12-15 10:29 . 2008-12-15 10:29 <REP> d-------- c:\program files\iPod
2008-12-15 10:29 . 2008-12-15 10:29 <REP> d-------- c:\program files\Bonjour
2008-12-15 10:29 . 2008-12-15 10:29 <REP> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-12-15 10:20 . 2008-12-15 10:21 <REP> d-------- c:\program files\QuickTime
2008-12-15 10:20 . 2008-12-15 10:20 <REP> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Apple Computer
2008-12-15 10:12 . 2008-12-15 10:20 <REP> d-------- c:\program files\Apple Software Update
2008-12-15 10:11 . 2008-12-15 10:29 <REP> d-------- c:\program files\Fichiers communs\Apple
2008-12-15 10:11 . 2008-12-15 10:11 <REP> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Apple
2008-12-15 09:03 . 2008-12-15 09:03 268 --ah----- C:\sqmdata00.sqm
2008-12-15 09:03 . 2008-12-15 09:03 244 --ah----- C:\sqmnoopt00.sqm
2008-12-15 08:04 . 2008-12-17 10:44 <REP> d-------- c:\documents and settings\ecco.ECCO-58A546ABD7\Contacts
2008-12-15 06:59 . 2008-12-17 19:02 <REP> d-------- c:\documents and settings\ecco.ECCO-58A546ABD7\Application Data\OpenOffice.org2
2008-12-15 06:55 . 2008-12-15 06:55 <REP> d-------- c:\program files\CyberLink
2008-12-15 06:55 . 2008-12-15 06:55 <REP> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\CyberLink
2008-12-15 06:55 . 2000-10-16 09:37 36,864 -r------- c:\windows\system32\ctrldll.dll
2008-12-15 06:55 . 2000-10-16 09:37 32,768 -r------- c:\windows\system32\rmctrl.exe
2008-12-14 17:31 . 2008-12-14 17:31 <REP> d-------- c:\documents and settings\Administrateur\Application Data\Bitdefender
2008-12-14 17:30 . 2008-12-13 20:44 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage réseau
2008-12-14 17:30 . 2008-12-13 20:44 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage d'impression
2008-12-14 17:30 . 2008-12-13 19:48 <REP> d--h----- c:\documents and settings\Administrateur\Modèles
2008-12-14 17:30 . 2008-12-15 08:54 <REP> d-------- c:\documents and settings\Administrateur\Mes documents
2008-12-14 17:30 . 2008-12-13 20:44 <REP> dr------- c:\documents and settings\Administrateur\Menu Démarrer
2008-12-14 17:30 . 2008-12-13 20:44 <REP> d-------- c:\documents and settings\Administrateur\Favoris
2008-12-14 17:30 . 2008-12-16 09:20 <REP> d-------- c:\documents and settings\Administrateur\Bureau
2008-12-14 17:30 . 2008-12-14 17:30 <REP> d-------- c:\documents and settings\Administrateur
2008-12-14 16:19 . 2008-12-14 16:19 <REP> d---s---- c:\documents and settings\ecco.ECCO-58A546ABD7\UserData
2008-12-14 15:54 . 2008-08-14 14:44 2,182,400 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-12-14 15:54 . 2008-08-14 14:44 2,138,112 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-12-14 15:54 . 2008-08-14 14:44 2,059,776 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-12-14 15:54 . 2008-08-14 14:44 2,017,792 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-12-14 15:54 . 2008-10-24 12:10 453,632 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-12-14 15:54 . 2008-06-14 18:59 272,768 --------- c:\windows\system32\drivers\bthport.sys
2008-12-14 15:54 . 2008-06-14 18:59 272,768 -----c--- c:\windows\system32\dllcache\bthport.sys
2008-12-14 12:07 . 2007-01-01 20:03 40,960 -ra------ c:\windows\system32\psfind.dll
2008-12-14 12:04 . 2007-03-08 00:51 129,784 --------- c:\windows\system32\pxafs.dll
2008-12-14 12:00 . 2008-12-14 15:53 <REP> d-------- c:\program files\Winamp
2008-12-14 11:43 . 2008-12-14 11:57 <REP> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\NOS
2008-12-14 11:02 . 2008-12-14 11:02 <REP> d-------- c:\documents and settings\ecco.ECCO-58A546ABD7\Application Data\Bitdefender
2008-12-14 11:01 . 2008-12-15 17:57 81,984 --a------ c:\windows\system32\bdod.bin
2008-12-14 10:56 . 2008-12-14 10:56 <REP> d-------- c:\program files\Softwin
2008-12-14 10:56 . 2008-12-14 10:56 <REP> d-------- c:\program files\Fichiers communs\Softwin
2008-12-14 10:56 . 2008-12-14 10:56 <REP> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\BitDefender
2008-12-14 10:50 . 2004-08-03 23:08 26,496 --a--c--- c:\windows\system32\dllcache\usbstor.sys
2008-12-13 21:12 . 2008-12-13 21:12 0 --a------ c:\windows\nsreg.dat
2008-12-13 20:47 . 2004-08-19 17:09 21,504 --a------ c:\windows\system32\hidserv.dll
2008-12-13 20:47 . 2001-08-17 22:59 3,072 --a------ c:\windows\system32\drivers\audstub.sys
2008-12-13 20:46 . 2004-08-19 16:54 58,496 --a------ c:\windows\system32\drivers\redbook.sys
2008-12-13 20:46 . 2001-08-17 22:46 6,400 --a------ c:\windows\system32\drivers\enum1394.sys
2008-12-13 20:45 . 2004-08-19 16:09 77,312 --a------ c:\windows\system32\usbui.dll
2008-12-13 20:45 . 2004-08-19 16:09 77,312 --a--c--- c:\windows\system32\dllcache\usbui.dll
2008-12-13 20:44 . 2008-12-13 20:44 <REP> d--h----- c:\documents and settings\Default User.WINDOWS\Voisinage réseau
2008-12-13 20:44 . 2008-12-13 20:44 <REP> d--h----- c:\documents and settings\Default User.WINDOWS\Voisinage d'impression
2008-12-13 20:44 . 2008-12-13 19:48 <REP> d--h----- c:\documents and settings\Default User.WINDOWS\Modèles
2008-12-13 20:44 . 2008-12-13 20:44 <REP> d-------- c:\documents and settings\Default User.WINDOWS\Mes documents
2008-12-13 20:44 . 2008-12-13 20:44 <REP> dr------- c:\documents and settings\Default User.WINDOWS\Menu Démarrer
2008-12-13 20:44 . 2008-12-13 20:44 <REP> d-------- c:\documents and settings\Default User.WINDOWS\Favoris
2008-12-13 20:44 . 2008-12-13 20:44 <REP> d-------- c:\documents and settings\Default User.WINDOWS\Bureau
2008-12-13 20:44 . 2008-12-13 20:33 <REP> d--h----- c:\documents and settings\All Users.WINDOWS\Modèles
2008-12-13 20:44 . 2008-12-17 10:04 <REP> dr------- c:\documents and settings\All Users.WINDOWS\Menu Démarrer
2008-12-13 20:44 . 2008-12-13 20:44 <REP> d-------- c:\documents and settings\All Users.WINDOWS\Favoris
2008-12-13 20:44 . 2008-12-13 19:49 <REP> dr------- c:\documents and settings\All Users.WINDOWS\Documents
2008-12-13 20:44 . 2008-12-17 14:26 <REP> d-------- c:\documents and settings\All Users.WINDOWS\Bureau
2008-12-13 20:42 . 2008-12-17 18:53 <REP> d--h----- c:\documents and settings\Default User.WINDOWS
2008-12-13 20:40 . 2008-12-13 19:53 560 --a------ c:\windows\system32\$winnt$.inf
2008-12-13 20:39 . 2008-12-13 20:39 <REP> d-------- c:\program files\VideoLAN
2008-12-13 20:38 . 2008-12-13 20:38 <REP> d-------- c:\program files\UltraISO
2008-12-13 20:38 . 2008-12-13 20:38 <REP> d-------- c:\program files\Fichiers communs\EZB Systems
2008-12-13 20:35 . 2008-12-13 20:36 <REP> d-------- c:\program files\Ace Utilities
2008-12-13 20:32 . 2008-12-13 20:32 <REP> d-------- c:\program files\K-Lite Codec Pack
2008-12-13 20:32 . 2008-03-21 21:30 3,596,288 --a------ c:\windows\system32\qt-dx331.dll
2008-12-13 20:32 . 2008-03-31 22:25 682,496 --a------ c:\windows\system32\divx.dll
2008-12-13 20:32 . 2006-09-24 16:11 389,120 --a------ c:\windows\system32\lameACM.acm
2008-12-13 20:32 . 2004-01-25 17:18 217,088 --a------ c:\windows\system32\yv12vfw.dll
2008-12-13 20:32 . 2007-09-04 17:56 164,352 --a------ c:\windows\system32\unrar.dll
2008-12-13 20:32 . 2007-09-21 01:52 118,784 --a------ c:\windows\system32\ac3acm.acm
2008-12-13 20:32 . 2008-03-21 21:28 81,920 --a------ c:\windows\system32\dpl100.dll
2008-12-13 20:32 . 2008-03-28 18:41 7,680 --a------ c:\windows\system32\ff_vfw.dll
2008-12-13 20:32 . 2007-07-10 17:10 547 --a------ c:\windows\system32\ff_vfw.dll.manifest
2008-12-13 20:32 . 2007-10-03 16:03 414 --a------ c:\windows\system32\lame_acm.xml
2008-12-13 20:30 . 2008-12-13 20:30 <REP> d-------- c:\program files\Kaspersky Lab
2008-12-13 20:30 . 2006-05-25 10:29 22,752 --a------ c:\windows\system32\spupdsvc.exe
2008-12-13 20:22 . 2007-03-08 00:51 43,528 --------- c:\windows\system32\drivers\PxHelp20.sys
2008-12-13 20:22 . 2006-05-19 22:16 2,560 --------- c:\windows\system32\drivers\cdralw2k.sys
2008-12-13 20:22 . 2006-05-19 22:16 2,432 --------- c:\windows\system32\drivers\cdr4_xp.sys
2008-12-13 20:20 . 2008-12-17 19:02 49 --a------ c:\windows\transp.gif
2008-12-13 20:17 . 2008-01-30 12:12 356,352 --a------ c:\windows\system32\nvudisp.exe
2008-12-13 20:17 . 2008-12-13 20:20 163,664 --a------ c:\windows\system32\nvapps.xml
2008-12-13 20:17 . 2008-01-30 12:12 17,737 --a------ c:\windows\system32\nvdisp.nvu
2008-12-13 20:16 . 2008-12-13 20:16 <REP> d-------- c:\documents and settings\ECCO~1~ECC\LOCALS~1
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-17 13:21 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-15 05:54 --------- d-----w c:\program files\Fichiers communs\InstallShield
2008-12-13 19:09 --------- d-----w c:\program files\Realtek
2008-12-11 12:59 --------- d-----w c:\program files\Fichiers communs\Agnitum Shared
2008-12-11 12:59 --------- d-----w c:\program files\Agnitum
2008-12-11 12:51 --------- d-----w c:\documents and settings\ecco\Application Data\InstallShield
2008-12-11 12:49 --------- d-----w c:\program files\Intel
2008-12-11 12:42 --------- d-----w c:\program files\microsoft frontpage
2008-12-11 12:40 --------- d-----w c:\program files\Services en ligne
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-12-17 09:49 67,688 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2008-12-17 09:49 54,368 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-12-17 09:49 34,944 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2008-12-17 09:49 46,712 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-12-17 09:49 172,136 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2006-03-02 15360]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-04-19 3297280]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-01-30 8523776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-01-30 81920]
"Outpost Firewall"="c:\program files\Agnitum\Outpost Firewall\outpost.exe" [2006-08-30 94720]
"OutpostFeedBack"="c:\program files\Agnitum\Outpost Firewall\feedback.exe" [2006-09-26 335872]
"BDMCon"="c:\program files\Softwin\BitDefender10\bdmcon.exe" [2007-04-02 290816]
"BDAgent"="c:\program files\Softwin\BitDefender10\bdagent.exe" [2007-03-26 69632]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2008-08-04 36352]
"RemoteControl"="c:\windows\system32\rmctrl.exe" [2000-10-16 32768]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-15 136600]
"nwiz"="nwiz.exe" [2008-01-30 c:\windows\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-04-12 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-03-02 15360]
c:\documents and settings\ecco\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 2.2.lnk - c:\program files\OpenOffice.org 2.2\program\quickstart.exe [2007-02-02 393216]
c:\documents and settings\ecco.ECCO-58A546ABD7\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 2.2.lnk - c:\program files\OpenOffice.org 2.2\program\quickstart.exe [2007-02-02 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Messenger\\Msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"f:\\anno 1701\\Anno1701.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R1 SandBox;Outpost Firewall Sandbox Driver;\??\c:\program files\Agnitum\Outpost Firewall\kernel\Sandbox.SYS [2008-12-11 244667]
R3 SIS163u;SiS163 usb Wireless LAN Adapter Driver;c:\windows\system32\DRIVERS\sis163u.sys [2005-06-20 215040]
S3 ADBLOCK.DLL;Outpost Firewall PlugIn (ADBLOCK.DLL);\??\c:\program files\Agnitum\Outpost Firewall\kernel\ADBLOCK.DLL [2008-12-11 33568]
S3 ARP.DLL;Outpost Firewall PlugIn (ARP.DLL);\??\c:\program files\Agnitum\Outpost Firewall\kernel\ARP.DLL [2008-12-11 17408]
S3 CONTENT.DLL;Outpost Firewall PlugIn (CONTENT.DLL);\??\c:\program files\Agnitum\Outpost Firewall\kernel\CONTENT.DLL [2008-12-11 4896]
S3 DNSCACHE.DLL;Outpost Firewall PlugIn (DNSCACHE.DLL);\??\c:\program files\Agnitum\Outpost Firewall\kernel\DNSCACHE.DLL [2008-12-11 14464]
S3 FTPFILT.DLL;Outpost Firewall PlugIn (FTPFILT.DLL);\??\c:\program files\Agnitum\Outpost Firewall\kernel\FTPFILT.DLL [2008-12-11 9248]
S3 HTMLFILT.DLL;Outpost Firewall PlugIn (HTMLFILT.DLL);\??\c:\program files\Agnitum\Outpost Firewall\kernel\HTMLFILT.DLL [2008-12-11 11552]
S3 HTTPFILT.DLL;Outpost Firewall PlugIn (HTTPFILT.DLL);\??\c:\program files\Agnitum\Outpost Firewall\kernel\HTTPFILT.DLL [2008-12-11 13216]
S3 IMAPFILT.DLL;Outpost Firewall PlugIn (IMAPFILT.DLL);\??\c:\program files\Agnitum\Outpost Firewall\kernel\IMAPFILT.DLL [2008-12-11 7168]
S3 MAILFILT.DLL;Outpost Firewall PlugIn (MAILFILT.DLL);\??\c:\program files\Agnitum\Outpost Firewall\kernel\MAILFILT.DLL [2008-12-11 14880]
S3 NNTPFILT.DLL;Outpost Firewall PlugIn (NNTPFILT.DLL);\??\c:\program files\Agnitum\Outpost Firewall\kernel\NNTPFILT.DLL [2008-12-11 6752]
S3 POP3FILT.DLL;Outpost Firewall PlugIn (POP3FILT.DLL);\??\c:\program files\Agnitum\Outpost Firewall\kernel\POP3FILT.DLL [2008-12-11 10048]
S3 PROTECT.DLL;Outpost Firewall PlugIn (PROTECT.DLL);\??\c:\program files\Agnitum\Outpost Firewall\kernel\PROTECT.DLL [2008-12-11 15200]
S3 SECRET.DLL;Outpost Firewall PlugIn (SECRET.DLL);\??\c:\program files\Agnitum\Outpost Firewall\kernel\SECRET.DLL [2008-12-11 12928]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - D:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - E:\livebox.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0fe320d0-c838-11dd-9f70-00032f3e7bc2}]
\Shell\AutoRun\command - i:\config\S-1-5-21-1482476501-1644491937-682003330-1013\Cfg.exe
\Shell\open\command - i:\config\S-1-5-21-1482476501-1644491937-682003330-1013\Cfg.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0fe320d4-c838-11dd-9f70-00032f3e7bc2}]
\Shell\AutoRun\command - i:\config\S-1-5-21-1482476501-1644491937-682003330-1013\Cfg.exe
\Shell\open\command - i:\config\S-1-5-21-1482476501-1644491937-682003330-1013\Cfg.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cc3e2ced-c785-11dd-9f67-001a4d5095ae}]
\Shell\AutoRun\command - h:\config\S-1-5-21-1482476501-1644491937-682003330-1013\Cfg.exe
\Shell\open\command - h:\config\S-1-5-21-1482476501-1644491937-682003330-1013\Cfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{28ABC5C0-4FCB-11CF-AAX5-21CX5C574571}]
c:\config\S-1-5-21-1482476501-1644491937-682003330-1013\Cfg.exe
.
.
------- Examen supplémentaire -------
.
uInternet Settings,ProxyOverride = *.local
c:\windows\bdoscandellang.ini - c:\windows\bdoscandel.exe
c:\windows\Downloaded Program Files\live.ini
c:\windows\Downloaded Program Files\scanoptions.tsi
c:\windows\Downloaded Program Files\lang.ini
c:\windows\Downloaded Program Files\ipsupd.dll
c:\windows\Downloaded Program Files\bdupd.dll
c:\windows\Downloaded Program Files\libfn.dll
c:\windows\Downloaded Program Files\bdcore.dll
c:\windows\Downloaded Program Files\oscan8.ocx
O16 -: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}
hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
c:\windows\Downloaded Program Files\oscan8.inf
FF - ProfilePath - c:\documents and settings\ecco.ECCO-58A546ABD7\Application Data\Mozilla\Firefox\Profiles\803vftn6.default\
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-17 19:02:37
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Inventel\Gateway\WLANCFG.EXE
c:\program files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
c:\program files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\rundll32.exe
c:\program files\OpenOffice.org 2.2\program\soffice.exe
c:\program files\OpenOffice.org 2.2\program\soffice.bin
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Heure de fin: 2008-12-17 19:03:41 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-12-17 18:03:39
Avant-CF: 24 144 183 296 octets libres
Après-CF: 24,118,251,520 octets libres
303 --- E O F --- 2008-12-17 07:57:11
edit
suite a cette analyse
bit defender a reussi a supprimer le virus
ce qui n'etait pas le cas jusqu'ici