Bonjour,
voici mon rapport effectué avec combofix, j'aurais voulu avoir un avis sur ce rapport et savoir si mon PC est sain après tout ceci.
ComboFix 08-12-14.04 - Administrateur 2008-12-15 12:25:24.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.1023.731 [GMT 1:00]
Lancé depuis: c:\documents and settings\Administrateur.MAISON\Bureau\ComboFix.exe.exe
Commutateurs utilisés :: c:\documents and settings\Administrateur.MAISON\Bureau\WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
* Resident AV is active
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\TDSSmqlt.sys
c:\windows\system32\NCTAVIFile.dll
c:\windows\system32\NCTQuickTimeFile.dll
c:\windows\system32\NCTRMFile.dll
c:\windows\system32\NCTVideoCoreM.dll
c:\windows\system32\rsekd83jde.dll
c:\windows\system32\TDSSbrsr.dll
c:\windows\system32\TDSSlxwp.dll
c:\windows\system32\TDSSnmxh.log
c:\windows\system32\TDSSoiqh.dll
c:\windows\system32\TDSSosvd.dat
c:\windows\system32\TDSSrhym.log
c:\windows\system32\TDSSriqp.dll
c:\windows\system32\TDSSsihc.dll
c:\windows\system32\TDSStkdu.log
c:\windows\system32\TDSSxfum.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_TDSSSERV.SYS
-------\Legacy_TDSSSERV.SYS
((((((((((((((((((((((((((((( Fichiers créés du 2008-11-15 au 2008-12-15 ))))))))))))))))))))))))))))))))))))
.
2008-12-15 07:44 . 2008-12-15 08:16 <REP> d-------- c:\program files\FindyKill
2008-12-13 19:19 . 2008-12-13 19:19 579,584 --a--c--- c:\windows\system32\dllcache\user32.dll
2008-12-13 19:11 . 2008-12-13 19:11 <REP> d-------- c:\windows\ERUNT
2008-12-13 18:42 . 2008-12-13 19:34 <REP> d-------- C:\SDFix
2008-12-13 18:33 . 2008-12-13 18:33 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-13 18:33 . 2008-12-13 18:33 <REP> d-------- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2008-12-13 18:33 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-13 18:33 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-12 20:21 . 2008-12-12 20:33 <REP> d-------- c:\program files\NoAdware5.0
2008-12-12 20:02 . 2008-12-12 21:14 <REP> d-------- c:\program files\Spybot - Search & Destroy
2008-12-12 16:29 . 2008-12-12 16:29 0 --a------ c:\windows\nsreg.dat
2008-12-12 10:41 . 2008-12-12 10:42 70,656 --a------ C:\novtpm.exe
2008-12-10 21:16 . 2008-12-10 21:16 12,800 --a------ c:\windows\system32\ssqQihIB.dll
2008-12-10 21:15 . 2008-12-10 21:15 12,800 --a------ c:\windows\system32\tuvUKDSJ.dll
2008-12-10 21:14 . 2008-12-10 21:14 12,800 --a------ c:\windows\system32\rqRJAtQk.dll
2008-12-09 18:49 . 2008-12-09 18:49 <REP> d-------- c:\program files\XviD
2008-12-09 18:42 . 2005-07-21 13:33 2,846,720 --a------ c:\windows\system32\NCTAudioCompress3.dll
2008-12-09 18:42 . 2005-04-14 19:07 780,288 --a------ c:\windows\system32\NCTVideoCompress.dll
2008-12-09 18:42 . 2005-02-22 17:32 312,320 --a------ c:\windows\system32\NCTVideoView.dll
2008-12-09 18:42 . 2005-06-15 20:04 90,112 --a------ c:\windows\system32\NCTAudioFormatSettings3.dll
2008-12-09 18:41 . 2005-06-29 16:28 188,416 --a------ c:\windows\system32\NCTVideoFile.dll
2008-12-09 18:40 . 2008-12-09 18:40 <REP> d-------- c:\windows\system32\RMBin
2008-12-09 18:40 . 2008-12-09 18:55 <REP> d-------- c:\program files\A-Z
2008-12-09 18:40 . 2004-02-08 15:53 856,064 --a------ c:\windows\system32\mpgfiltr.ax
2008-12-09 18:40 . 2005-06-01 12:16 778,240 --a------ c:\windows\system32\NCTAudioCompress2.dll
2008-12-09 18:40 . 2002-01-05 14:40 487,424 --a------ c:\windows\system32\msvcp70.dll
2008-12-09 18:40 . 2005-11-25 21:46 421,888 --a------ c:\windows\system32\RealMediaSplitter.ax
2008-12-09 18:40 . 2002-01-05 15:37 344,064 --a------ c:\windows\system32\msvcr70.dll
2008-12-09 18:40 . 2003-08-07 15:01 237,568 --a------ c:\windows\system32\lame_enc.dll
2008-12-09 18:40 . 2005-07-01 18:09 215,552 --a------ c:\windows\system32\NCTWMVFile.dll
2008-12-09 18:40 . 2006-02-26 02:34 208,896 --a------ c:\windows\system32\VideoEdit.ocx
2008-12-09 18:40 . 2006-01-17 03:59 147,456 --a------ c:\windows\system32\viscomqtenc.dll
2008-12-09 18:40 . 2006-02-17 22:02 139,264 --a------ c:\windows\system32\viscomqtde.dll
2008-12-09 18:40 . 2003-08-19 04:31 81,920 --a------ c:\windows\system32\viscomwave.dll
2008-12-05 19:20 . 2008-12-05 19:20 <REP> d--h----- c:\windows\PIF
2008-11-29 17:55 . 2008-11-29 17:57 <REP> d-------- c:\documents and settings\Administrateur.MAISON\Application Data\vlc
2008-11-29 16:19 . 2008-11-29 16:19 <REP> d-------- c:\program files\Eidos Interactive
2008-11-29 09:33 . 2008-11-29 09:54 <REP> d-------- c:\program files\Time of War
2008-11-28 18:48 . 1998-09-02 09:02 194,320 --a------ c:\windows\system32\qcut.dll
2008-11-28 18:48 . 1998-08-27 05:51 182,032 --a------ c:\windows\system32\dxtmsft3.dll
2008-11-28 18:48 . 1998-08-20 12:02 140,800 --a------ c:\windows\system32\tm20dec.ax
2008-11-28 18:48 . 1998-09-02 09:28 63,488 --a------ c:\windows\system32\unam4ie.exe
2008-11-28 18:48 . 1998-09-02 09:28 38,160 --a------ c:\windows\system32\LMRTREND.dll
2008-11-28 18:48 . 1998-08-17 10:21 11,776 --a------ c:\windows\system32\mciqtz.drv
2008-11-28 18:48 . 1998-08-17 10:21 10,240 --a------ c:\windows\system32\vidx16.dll
2008-11-28 18:48 . 1998-08-17 10:21 5,672 --a------ c:\windows\system32\quartz.vxd
2008-11-28 18:48 . 2008-11-28 18:48 4,608 --a------ c:\windows\system32\w95inf32.dll
2008-11-28 18:48 . 2008-11-28 18:48 2,272 --a------ c:\windows\system32\w95inf16.dll
2008-11-28 18:47 . 2008-11-28 18:47 <REP> d-------- c:\program files\directx
2008-11-23 16:20 . 2008-11-29 15:50 <REP> d-------- c:\program files\DivX
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-15 10:40 --------- d-----w c:\documents and settings\Administrateur.MAISON\Application Data\Azureus
2008-12-12 09:42 14,336 ----a-w c:\windows\system32\svchost.exe
2008-12-11 18:13 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Microsoft Help
2008-12-10 20:43 --------- d-----w c:\program files\ESET
2008-12-05 22:14 --------- d-----w c:\documents and settings\Administrateur.MAISON\Application Data\dvdcss
2008-11-29 15:19 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-29 14:40 --------- d-----w c:\program files\Fichiers communs\Wise Installation Wizard
2008-11-21 16:06 --------- d-----w c:\program files\Azureus
2008-10-26 15:51 --------- d-----w c:\program files\Bit Che
2008-10-25 09:27 --------- d-----w c:\program files\VirtualDJ
2008-10-24 14:46 --------- d-----w c:\program files\Azureus 2
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 15:00 --------- d-----w c:\documents and settings\Administrateur.MAISON\Application Data\GamesCafe
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-22 16:16 --------- d-----w c:\documents and settings\Administrateur.MAISON\Application Data\ESET
2008-10-22 16:07 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\ESET
2008-10-22 15:58 --------- d-----w c:\program files\AntivirusFirewall
2008-10-22 10:06 --------- d-----w c:\program files\Fichiers communs\Webroot Shared
2008-10-22 10:06 --------- d-----w c:\documents and settings\All Users.WINDOWS\Application Data\Webroot
2008-10-22 09:55 --------- d-----w c:\program files\Webroot
2008-10-22 09:55 --------- d-----w c:\documents and settings\Administrateur.MAISON\Application Data\Webroot
2008-10-22 09:42 --------- d-----w c:\program files\Windows Doctor
2008-10-19 10:00 --------- d-----w c:\documents and settings\Administrateur.MAISON\Application Data\Tunebite
2008-10-18 09:49 107,888 ----a-w c:\windows\system32\CmdLineExt.dll
2008-10-17 15:07 --------- d-----w c:\program files\Disc2Phone
2008-10-16 20:18 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-16 05:57 --------- d-----w c:\program files\MatrixWorld 3D Screensaver
2008-10-15 15:14 --------- d-----w c:\program files\Electronic Arts
2008-10-03 10:03 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-09-19 21:55 200,704 ----a-w c:\windows\system32\ssldivx.dll
2008-09-19 21:55 1,044,480 ----a-w c:\windows\system32\libdivx.dll
2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
2007-05-20 17:53 278,528 ----a-w c:\program files\Fichiers communs\FDEUnInstaller.exe
2005-06-06 16:07 0 -c-ha-w c:\documents and settings\Default User\hpothb07.dat
2005-06-06 16:07 0 -c-ha-w c:\documents and settings\Administrateur.MS\hpothb07.dat
2004-10-01 13:00 40,960 ----a-w c:\program files\Uninstall_CDS.exe
2008-08-07 22:06 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008080820080809\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136]
"nodenable"="c:\program files\eset\nodenable.exe" [2008-09-23 326823]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2003-03-09 188416]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"SuperRam"="c:\program files\SuperRam\SuperRam.exe" [2008-01-22 1636824]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
"NeroFilterCheck"="c:\program files\Fichiers communs\Nero\Lib\NeroCheck.exe" [2008-02-28 570664]
"NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352]
"UVS11 Preload"="c:\program files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe" [2008-10-05 341488]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-02-20 1443072]
"NodLogin"="c:\program files\ESET\ESET Smart Security\nodlogin.exe" [2008-08-25 359202]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users.WINDOWS\Menu D‚marrer\Programmes\D‚marrage\
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2007-03-11 210520]
hp psc 1000 series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe [2003-04-06 147456]
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-04-06 28672]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
"vidc.vp31"= vp31vfw.dll
"msacm.dvacm"= c:\progra~1\FICHIE~1\ULEADS~1\Vio\Dvacm.acm
"msacm.MPEGacm"= c:\progra~1\FICHIE~1\ULEADS~1\MPEG\MPEGacm.acm
"msacm.ulmp3acm"= c:\progra~1\FICHIE~1\ULEADS~1\MPEG\ulmp3acm.acm
"vidc.xvid"= xvid.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
R2 ekrn;Eset Service;"c:\program files\ESET\ESET Smart Security\ekrn.exe" [2008-02-20 472320]
R2 wwEngineSvc;Window Washer Engine;c:\program files\Webroot\Washer\WasherSvc.exe [2008-10-22 598856]
S3 ham50;Creatix V.90 HAM Data Fax Modem;c:\windows\system32\DRIVERS\CTXH51.sys [2004-08-05 454815]
S3 SIS163u;SiS163 usb Wireless LAN Adapter Driver;c:\windows\system32\DRIVERS\sis163u.sys [2005-06-20 215040]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - g:\wd_windows_tools\WDSetup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{01ba1a7b-38a3-11dd-9c37-00032f4247ea}]
\Shell\AutoRun\command - G:\Setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2b1258ae-b3a2-11dc-8199-00032f4247ea}]
\Shell\AutoRun\command - I:\InstallTomTomHOME.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{638732c6-ffb4-11db-8fe3-806d6172696f}]
\Shell\AutoRun\command - F:\setup.exe
*Newly Created Service* - PROCEXP90
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{61E3FE32-07B9-4563-A3E0-2DE2D620FE10}]
c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Contenu du dossier 'Tâches planifiées'
2008-12-14 c:\windows\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1206108726.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-05 23:52]
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{D5BF49A2-94F1-42BD-F434-3604812C807D} - c:\windows\system32\rsekd83jde.dll
SharedTaskScheduler-{D5BF49A2-94F1-42BD-F434-3604812C807D} - c:\windows\system32\rsekd83jde.dll
.
------- Examen supplémentaire -------
.
uLocal Page = \blank.htm
uStart Page = hxxp://www.google.fr/
FF - ProfilePath - c:\documents and settings\Administrateur.MAISON\Application Data\Mozilla\Firefox\Profiles\3mviz0nx.default\
FF - plugin: c:\documents and settings\All Users.WINDOWS\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-15 12:30:52
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TDSSserv.sys]
"imagepath"="\systemroot\system32\drivers\TDSSmqlt.sys"
.
Heure de fin: 2008-12-15 12:32:39
ComboFix-quarantined-files.txt 2008-12-15 11:32:14
Avant-CF: 18,360,246,272 octets libres
Après-CF: 18,346,696,704 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /fastdetect /noexecute=optin
230 --- E O F --- 2008-12-11 18:14:06
