ok alors j'ai fait un scan avec ELIBAGLA voici le log:
----------------------------------------------
Fri Sep 19 03:31:19 2008
EliBagle v11.74 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 18 de Septiembre del 2008)
----------------------------------------------
Lista de Acciones (por Accion Directa):
C:WINDOWSSYSTEM32DRIVERSHLDRRR.EXE --> Eliminado Bagle.dldr
Restaurada Clave: "SafeBootMinimal y Network"
Fri Sep 19 03:31:49 2008
EliBagle v11.74 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 18 de Septiembre del 2008)
----------------------------------------------
Lista de Acciones (por Exploracion):
Explorando Unidad C:
C:Program FilesSuperCopier2SUPERCOPIER2.EXE --> Eliminado Bagle.dldr
Nº Total de Directorios: 13757
Nº Total de Ficheros: 202229
Nº de Ficheros Analizados: 11600
Nº de Ficheros Infectados: 1
Nº de Ficheros Limpiados: 1
Fri Sep 19 03:45:30 2008
EliBagle v11.74 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 18 de Septiembre del 2008)
----------------------------------------------
Lista de Acciones (por Accion Directa):
Fri Sep 19 03:46:28 2008
EliBagle v11.74 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 18 de Septiembre del 2008)
----------------------------------------------
Lista de Acciones (por Accion Directa):
Fri Sep 19 03:46:31 2008
EliBagle v11.74 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 18 de Septiembre del 2008)
----------------------------------------------
Lista de Acciones (por Exploracion):
Explorando Unidad C:
Nº Total de Directorios: 13757
Nº Total de Ficheros: 202233
Nº de Ficheros Analizados: 11596
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0
Fri Sep 19 03:49:52 2008
EliBagle v11.74 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 18 de Septiembre del 2008)
----------------------------------------------
Lista de Acciones (por Exploracion):
Explorando Unidad C:
Nº Total de Directorios: 13753
Nº Total de Ficheros: 202233
Nº de Ficheros Analizados: 11596
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0
Fri Sep 19 23:57:23 2008
EliBagle v11.74 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 18 de Septiembre del 2008)
----------------------------------------------
Lista de Acciones (por Accion Directa):
Fri Sep 19 23:57:32 2008
EliBagle v11.74 (c)2008 S.G.H. / Satinfo S.L. (Actualizado el 18 de Septiembre del 2008)
----------------------------------------------
Lista de Acciones (por Exploracion):
Explorando Unidad C:
Nº Total de Directorios: 13767
Nº Total de Ficheros: 203128
Nº de Ficheros Analizados: 11621
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0
----------------------------------------------
Ensuite comme indiqué sur le lien j'ai fait un scan avec comboFix:
ComboFix 08-09-19.04 - Khemet Wang 2008-09-20 0:07:04.1 - NTFSx86
Microsoft Windows XP Edition familiale 5.1.2600.3.1252.1.1036.18.2486 [GMT 2:00]
Lancé depuis: C:Documents and SettingsKhemet WangBureaulabla.exe
* Un nouveau point de restauration a été créé
AVERTISSEMENT - LA CONSOLE DE RECUPERATION N'EST PAS INSTALLEE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:WINDOWSsystem32driversdownld
C:WINDOWSsystem32lsprst7.dll
C:WINDOWSsystem32msvcsv60.dll
C:WINDOWSsystem32ssprs.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-08-19 au 2008-09-19 ))))))))))))))))))))))))))))))))))))
.
2008-09-19 23:43 . 2008-09-19 23:43 0 --a------ C:WINDOWShlktmp
2008-09-19 17:35 . 2007-08-14 08:12 18,816 --------- C:WINDOWSsystem32SAVRKBootTasks.sys
2008-09-19 16:29 . 2008-09-19 16:29 <REP> d-------- C:Program FilesSophos
2008-09-19 14:04 . 2008-09-19 14:05 <REP> d-------- C:WINDOWSBDOSCAN8
2008-09-19 03:57 . 2008-09-19 03:57 <REP> d-------- C:WINDOWSsystem32Kaspersky Lab
2008-09-19 03:47 . 2008-09-19 03:47 7,680 --ahs---- C:WINDOWSsystem32Thumbs.db
2008-09-19 03:47 . 2008-09-19 03:47 7,168 --ahs---- C:WINDOWSThumbs.db
2008-09-19 03:04 . 2008-09-19 03:04 <REP> d-------- C:Documents and SettingsKhemet WangApplication DataAdvanced Font Viewer
2008-09-18 21:06 . 2000-05-24 15:02 298,496 --a------ C:WINDOWSunin040c.exe
2008-09-17 21:07 . 2003-06-25 16:05 266,360 --a------ C:WINDOWSsystem32TweakUI.exe
2008-09-17 21:07 . 2002-06-21 15:09 160,217 --a------ C:WINDOWSsystem32PowerToysLicense.rtf
2008-09-14 11:33 . 2008-05-02 02:38 301,656 --a------ C:WINDOWSsystem32BtCoreIf.dll
2008-09-14 11:32 . 2008-09-14 11:33 <REP> d-------- C:Program FilesFichiers communsLogishrd
2008-09-13 20:53 . 2008-09-13 20:53 38 --a------ C:WINDOWSavisplitter.INI
2008-09-07 18:49 . 2008-09-07 18:50 <REP> d-------- C:WINDOWS$regcmp$
2008-09-05 20:14 . 2008-09-05 20:19 <REP> d-------- C:WINDOWSsystem32NtmsData
2008-09-04 02:34 . 2006-11-22 10:01 693,760 --a------ C:WINDOWSsystem32drivershardlock.sys
2008-09-04 02:34 . 2001-06-21 21:39 73,728 --a------ C:WINDOWSsystem32driversSENTINEL.SYS
2008-09-04 02:34 . 2001-06-21 21:39 49,664 --a------ C:WINDOWSsystem32SNTI386.DLL
2008-09-04 02:34 . 2008-09-04 02:34 47,616 --a------ C:WINDOWSsystem32driversHaspnt.sys
2008-09-04 02:34 . 2001-06-21 21:39 20,032 -ra------ C:WINDOWSsystem32driversSNTNLUSB.SYS
2008-09-04 02:34 . 2001-06-21 21:39 18,432 --a------ C:WINDOWSsystem32RNBOVDD.DLL
2008-09-04 02:34 . 2008-09-04 02:34 6,656 --a------ C:WINDOWSsystem32haspvdd.dll
2008-09-04 02:34 . 2008-07-27 07:26 3,121 --a------ C:WINDOWSsystem32config.hsp
2008-09-04 02:34 . 2008-09-04 02:34 383 --a------ C:WINDOWSsystem32haspdos.sys
2008-09-04 02:33 . 2008-09-04 02:33 <REP> d-------- C:WINDOWSsystem32RNBOSENT
2008-09-04 02:33 . 2008-09-04 02:33 <REP> d-------- C:Program FilesGLOBEtrotter Software Inc
2008-09-04 02:33 . 2001-06-21 21:39 9,949 --------- C:WINDOWSsystem32SENTINEL.HLP
2008-09-04 02:33 . 1998-07-10 04:31 7,328 --a------ C:WINDOWSsystem32driversds1410d.sys
2008-09-04 02:25 . 2008-09-04 02:26 <REP> d-------- C:Program FilesFichiers communsAlias Shared
2008-09-04 02:24 . 2008-09-04 03:24 <REP> d-------- C:FlexLM
2008-09-04 01:22 . 2008-09-04 02:25 <REP> d-------- C:Program FilesFichiers communsAutodesk Shared
2008-09-04 01:22 . 2008-09-04 02:59 <REP> d-------- C:Program FilesAutodesk
2008-09-04 01:19 . 2008-09-04 01:19 <REP> d-------- C:Program FilesMSBuild
2008-09-04 01:12 . 2008-09-04 01:12 <REP> d-------- C:WINDOWSsystem32XPSViewer
2008-09-04 01:12 . 2008-09-04 01:12 <REP> d-------- C:Program FilesReference Assemblies
2008-09-04 01:11 . 2006-06-29 13:07 14,048 --------- C:WINDOWSsystem32spmsg2.dll
2008-08-31 23:52 . 2008-08-31 23:52 <REP> d-------- C:Program FilesReal
2008-08-31 23:52 . 2008-09-17 23:13 <REP> d-------- C:Program FilesFichiers communsReal
2008-08-29 20:36 . 2008-08-29 20:36 1,409 --a------ C:WINDOWSsystem32 mpC6CB7.FOT
2008-08-29 00:33 . 2008-08-29 00:38 <REP> d-------- C:Program Filesfraps
2008-08-26 20:39 . 2007-08-21 04:01 7,034,368 --a------ C:WINDOWSsystem32BCC5 Render Engine 8BPC.dll
2008-08-26 13:54 . 2008-08-26 13:54 1,131 --a------ C:WINDOWSBorisFX6.ini
2008-08-26 13:31 . 1998-10-29 17:45 306,688 --a------ C:WINDOWSIsUninst.exe
2008-08-26 13:31 . 2008-08-26 13:31 272 --a------ C:WINDOWS\_delis32.ini
2008-08-26 12:20 . 2008-08-26 12:20 <REP> d-------- C:Program FilesAIST
2008-08-26 11:54 . 2008-08-26 12:02 <REP> d-------- C:Program FilesMagicISO
2008-08-25 19:38 . 2008-08-25 19:38 <REP> d-------- C:Documents and SettingsAll UsersApplication DataAzureus
2008-08-25 19:32 . 2008-08-25 19:39 <REP> d-------- C:Program FilesAzureus
2008-08-25 19:32 . 2008-09-13 12:10 <REP> d-------- C:Documents and SettingsKhemet WangApplication DataAzureus
2008-08-25 19:09 . 2008-08-25 19:09 <REP> d-------- C:WINDOWSSun
2008-08-25 19:09 . 2008-06-10 02:32 73,728 --a------ C:WINDOWSsystem32javacpl.cpl
2008-08-25 19:08 . 2008-08-25 19:09 <REP> d-------- C:Program FilesJava
2008-08-23 21:12 . 2008-08-23 21:12 <REP> d-------- C:Program FilesApple Software Update
2008-08-23 21:12 . 2008-08-23 21:12 <REP> d-------- C:Documents and SettingsAll UsersApplication DataApple
2008-08-23 11:00 . 2008-08-23 11:00 0 --ah----- C:WINDOWSsystem32driversMsft_Kernel_LHidFilt_01005.Wdf
2008-08-20 16:22 . 2008-08-20 16:22 <REP> d-------- C:Documents and SettingsKhemet WangApplication DataGridIron
2008-08-20 16:16 . 2008-08-20 16:17 <REP> d-------- C:Documents and SettingsAll UsersApplication DataGridIron Software
2008-08-20 13:58 . 2008-08-24 23:47 <REP> d-------- C:Documents and SettingsKhemet WangApplication DataAutodesk
2008-08-20 05:21 . 2008-08-20 05:21 <REP> d-------- C:Documents and SettingsKhemet WangApplication DataArcSoft
2008-08-20 05:20 . 2008-08-20 05:20 0 --ah----- C:WINDOWSsystem32driversMsft_Kernel_phaudlwr_01005.Wdf
2008-08-20 05:15 . 2008-08-20 05:15 <REP> d-------- C:Program FilesFichiers communsArcSoft
2008-08-20 05:15 . 2005-04-27 16:36 245,408 --a------ C:WINDOWSsystem32unicows.dll
2008-08-20 05:15 . 1995-08-01 04:44 212,480 --a------ C:WINDOWSPCDLIB32.DLL
2008-08-20 05:14 . 2008-08-20 05:15 <REP> d-------- C:Program FilesPhilips_VLounge
2008-08-20 05:14 . 2008-08-20 05:14 <REP> d-------- C:Program FilesDIFX
2008-08-20 05:14 . 2007-07-12 15:00 3,033,856 --a------ C:WINDOWSsystem32driversspc1000.sys
2008-08-20 05:14 . 2007-07-12 14:59 675,840 --a------ C:WINDOWSvspc1000.exe
2008-08-20 05:14 . 2007-07-12 15:00 479,232 --a------ C:WINDOWSsystem32vspc1000.dll
2008-08-20 05:14 . 2007-07-12 14:58 88,320 --a------ C:WINDOWSsystem32driversphaudlwr.sys
2008-08-20 05:14 . 2007-04-22 16:24 77,824 --a------ C:WINDOWSVPro1000.exe
2008-08-20 05:14 . 2007-07-12 14:59 53,248 --a------ C:WINDOWSsystem32cspc1000.dll
2008-08-20 05:14 . 2007-07-12 15:00 28,672 --a------ C:WINDOWSsystem32driversspc1000c.sys
2008-08-20 05:14 . 2007-07-12 14:59 15,497 --a------ C:WINDOWSspc1000.ini
2008-08-20 05:14 . 2007-07-12 14:59 13,022 --a------ C:WINDOWSspc1000.src
2008-08-20 05:13 . 2008-08-20 05:13 <REP> d-------- C:WINDOWSPhilips
2008-08-20 05:13 . 2008-08-20 05:13 <REP> d-------- C:Program FilesPhilips
2008-08-20 05:13 . 2008-08-20 05:14 <REP> d-------- C:Program FilesFichiers communsSPC1000NC
2008-08-19 10:22 . 2008-08-19 10:22 231 --a------ C:WINDOWSsystem323dsmax.ini
2008-08-19 10:22 . 2008-08-19 10:22 43 --a------ C:WINDOWSsystem32InstallSettings.ini
2008-08-19 10:21 . 2008-09-04 01:22 <REP> d-------- C:Documents and SettingsAll UsersApplication DataAutodesk
2008-08-19 10:20 . 2007-05-16 16:45 3,497,832 --a------ C:WINDOWSsystem32d3dx9_34.dll
2008-08-19 10:20 . 2006-11-29 13:06 3,426,072 --a------ C:WINDOWSsystem32d3dx9_32.dll
2008-08-19 10:20 . 2006-09-28 16:05 2,414,360 --a------ C:WINDOWSsystem32d3dx9_31.dll
2008-08-19 10:20 . 2007-05-16 16:45 1,124,720 --a------ C:WINDOWSsystem32D3DCompiler_34.dll
2008-08-19 10:20 . 2007-05-16 16:45 443,752 --a------ C:WINDOWSsystem32d3dx10_34.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-19 22:09 71,131,168 --sha-w C:WINDOWSsystem32driversfidbox.dat
2008-09-19 15:49 22,528 ----a-w C:WINDOWSInternet LogsxDB40.tmp
2008-09-19 15:49 2,313,216 ----a-w C:WINDOWSInternet LogsxDB41.tmp
2008-09-19 15:45 841,160 --sha-w C:WINDOWSsystem32driversfidbox.idx
2008-09-19 15:45 2,929,152 ----a-w C:WINDOWSInternet LogsxDB3F.tmp
2008-09-19 15:25 --------- d-----w C:Documents and SettingsAll UsersApplication DataSpybot - Search & Destroy
2008-09-16 20:13 98,304 ----a-w C:WINDOWSInternet LogsxDB3D.tmp
2008-09-16 20:13 2,253,312 ----a-w C:WINDOWSInternet LogsxDB3E.tmp
2008-09-16 12:32 2,689,536 ----a-w C:WINDOWSInternet LogsxDB3C.tmp
2008-09-14 09:33 --------- d-----w C:Program FilesFichiers communsLogitech
2008-09-14 09:32 --------- d--h--w C:Program FilesInstallShield Installation Information
2008-09-12 14:34 3,024,896 ----a-w C:WINDOWSInternet LogsxDB3B.tmp
2008-09-10 10:13 --------- d-----w C:Program FilesMessenger Plus! Live
2008-09-08 02:17 2,235,392 ----a-w C:WINDOWSInternet LogsxDB3A.tmp
2008-09-04 00:55 97,792 ----a-w C:WINDOWSInternet LogsxDB38.tmp
2008-09-04 00:55 2,223,104 ----a-w C:WINDOWSInternet LogsxDB39.tmp
2008-09-04 00:49 3,073,536 ----a-w C:WINDOWSInternet LogsxDB36.tmp
2008-09-04 00:49 2,230,784 ----a-w C:WINDOWSInternet LogsxDB37.tmp
2008-09-03 22:39 --------- d-----w C:Program FilesFlashGet
2008-09-01 18:21 --------- d-----w C:Program Filesa-squared Free
2008-09-01 16:11 2,750,976 ----a-w C:WINDOWSInternet LogsxDB35.tmp
2008-09-01 14:12 2,959,360 ----a-w C:WINDOWSInternet LogsxDB33.tmp
2008-09-01 14:12 2,174,976 ----a-w C:WINDOWSInternet LogsxDB34.tmp
2008-08-31 02:56 109,568 ----a-w C:WINDOWSInternet LogsxDB32.tmp
2008-08-30 21:53 2,164,224 ----a-w C:WINDOWSInternet LogsxDB31.tmp
2008-08-30 17:05 53,760 ----a-w C:WINDOWSInternet LogsxDB2F.tmp
2008-08-30 17:05 2,163,712 ----a-w C:WINDOWSInternet LogsxDB30.tmp
2008-08-30 15:50 --------- d---a-w C:Documents and SettingsAll UsersApplication DataTEMP
2008-08-30 13:52 2,151,898 ----a-w C:WINDOWSInternet Logs vDebug.zip
2008-08-30 02:32 2,770,944 ----a-w C:WINDOWSInternet LogsxDB2E.tmp
2008-08-29 19:26 2,162,688 ----a-w C:WINDOWSInternet LogsxDB2D.tmp
2008-08-29 14:23 2,153,984 ----a-w C:WINDOWSInternet LogsxDB2C.tmp
2008-08-29 12:07 2,153,472 ----a-w C:WINDOWSInternet LogsxDB2B.tmp
2008-08-28 22:21 --------- d-----w C:Program FilesCelestia
2008-08-28 12:14 2,149,376 ----a-w C:WINDOWSInternet LogsxDB2A.tmp
2008-08-28 11:21 244,224 ----a-w C:WINDOWSInternet LogsxDB29.tmp
2008-08-27 14:02 66,560 ----a-w C:WINDOWSInternet LogsxDB28.tmp
2008-08-27 00:24 3,014,656 ----a-w C:WINDOWSInternet LogsxDB27.tmp
2008-08-26 21:15 2,145,280 ----a-w C:WINDOWSInternet LogsxDB26.tmp
2008-08-26 18:39 --------- d-----w C:Program FilesBoris FX, Inc
2008-08-25 20:26 3,012,096 ----a-w C:WINDOWSInternet LogsxDB25.tmp
2008-08-25 18:40 745,472 ----a-w C:WINDOWSInternet LogsxDB23.tmp
2008-08-25 18:40 2,113,024 ----a-w C:WINDOWSInternet LogsxDB24.tmp
2008-08-25 18:30 3,048,448 ----a-w C:WINDOWSInternet LogsxDB22.tmp
2008-08-25 16:25 2,095,104 ----a-w C:WINDOWSInternet LogsxDB21.tmp
2008-08-25 16:25 1,024,512 ----a-w C:WINDOWSInternet LogsxDB20.tmp
2008-08-25 10:12 2,086,400 ----a-w C:WINDOWSInternet LogsxDB1F.tmp
2008-08-24 17:16 3,030,528 ----a-w C:WINDOWSInternet LogsxDB1E.tmp
2008-08-23 19:13 --------- d-----w C:Program FilesQuickTime Alternative
2008-08-23 19:13 --------- d-----w C:Documents and SettingsAll UsersApplication DataApple Computer
2008-08-21 13:57 2,065,920 ----a-w C:WINDOWSInternet LogsxDB1D.tmp
2008-08-21 09:46 2,065,408 ----a-w C:WINDOWSInternet LogsxDB1C.tmp
2008-08-21 09:46 1,696,256 ----a-w C:WINDOWSInternet LogsxDB1B.tmp
2008-08-20 09:17 2,015,232 ----a-w C:WINDOWSInternet LogsxDB1A.tmp
2008-08-20 09:17 1,843,200 ----a-w C:WINDOWSInternet LogsxDB19.tmp
2008-08-20 03:17 2,009,600 ----a-w C:WINDOWSInternet LogsxDB18.tmp
2008-08-20 03:17 1,805,824 ----a-w C:WINDOWSInternet LogsxDB17.tmp
2008-08-20 03:14 --------- d-----w C:Program FilesFichiers communsInstallShield
2008-08-19 01:51 --------- d-----w C:Program FilesFichiers communsAdobe
2008-08-18 08:52 --------- d-----w C:Program FilesNVIDIA Corporation
2008-08-18 05:42 157,696 ----a-w C:WINDOWSInternet LogsxDB15.tmp
2008-08-18 05:42 1,965,568 ----a-w C:WINDOWSInternet LogsxDB16.tmp
2008-08-17 18:57 1,959,424 ----a-w C:WINDOWSInternet LogsxDB14.tmp
2008-08-16 19:14 1,658,880 ----a-w C:WINDOWSInternet LogsxDB13.tmp
2008-08-16 01:08 361,600 ----a-w C:WINDOWSsystem32driversTCPIP.SYS.ORIGINAL
2008-08-16 01:08 361,600 ----a-w C:WINDOWSsystem32driversTCPIP.SYS
2008-08-15 00:35 --------- d-----w C:Documents and SettingsKhemet WangApplication Datavlc
2008-08-15 00:31 --------- d-----w C:Program FilesVideoLAN
2008-08-14 15:55 --------- d-----w C:Program FileseMule
2008-08-14 15:54 --------- d-----w C:Documents and SettingsKhemet WangApplication DataeMule
2008-08-14 00:45 --------- d-----w C:Program FilesStellarium
2008-08-13 20:26 --------- d-----w C:Documents and SettingsKhemet WangApplication DataLogitech
2008-08-13 20:25 --------- d-----w C:Program FilesFichiers communsLogiShared
2008-08-13 20:25 --------- d-----w C:Documents and SettingsKhemet WangApplication DataLeadertech
2008-08-13 20:23 0 ---ha-w C:WINDOWSsystem32driversMsft_Kernel_LMouFilt_01005.Wdf
2008-08-13 20:22 --------- d-----w C:Program FilesLogitech
2008-08-13 20:22 --------- d-----w C:Documents and SettingsAll UsersApplication DataLogitech
2008-08-13 20:22 --------- d-----w C:Documents and SettingsAll UsersApplication DataLogiShrd
2008-08-12 16:12 --------- d-----w C:Program FilesQuickMediaConverter
2008-08-10 23:48 72,704 ----a-w C:WINDOWSInternet LogsxDB11.tmp
2008-08-10 23:48 1,863,168 ----a-w C:WINDOWSInternet LogsxDB12.tmp
2008-08-09 15:45 --------- d-----w C:Program FilesWaves
2008-08-09 15:44 --------- d-----w C:Program FilesAntares
2008-08-09 15:37 --------- d-----w C:Program FilesEast West
2008-08-09 13:28 --------- d-----w C:Documents and SettingsKhemet WangApplication DataWaves Audio
2008-08-09 12:58 --------- d-----w C:Program FilesNative Instruments
2008-08-09 12:48 --------- d-----w C:Program FilesFichiers communsNative Instruments
2008-08-09 12:31 --------- d-----w C:Program FilesCakewalk
2008-08-09 12:24 --------- d-----w C:Program FilesKORG
2008-08-09 12:24 --------- d-----w C:Program FilesFichiers communsKorg
2008-08-09 12:18 --------- d-----w C:Program FilesArturia
2008-08-09 12:17 --------- d-----w C:Program FilesDigidesign
2008-08-09 02:11 --------- d-----w C:Program FilesIK Multimedia
2008-08-08 23:48 --------- d-----w C:Program FilesBest Service
2008-08-08 22:56 --------- d-----w C:Program Filesero-G
2008-08-08 20:53 --------- d-----w C:Program FilesSpectrasonics
2008-08-08 20:15 186,368 ----a-w C:WINDOWSInternet LogsxDB10.tmp
2008-08-08 19:59 1,752,576 ----a-w C:WINDOWSInternet LogsxDBF.tmp
2008-08-08 14:02 --------- d-----w C:Program FilesDAEMON Tools Lite
2008-08-08 14:00 716,272 ----a-w C:WINDOWSsystem32driverssptd.sys
.
------- Sigcheck -------
2008-06-20 13:59 361600 ad978a1b783b5719720cff204b666c8e C:WINDOWS$hf_mig$KB951748SP3QFE cpip.sys
2006-03-02 14:00 359040 9f4b36614a0fc234525ba224957de55c C:WINDOWS$NtServicePackUninstall$ cpip.sys
2008-04-13 21:20 361344 93ea8d04ec73a85db02eb8805988f733 C:WINDOWS$NtUninstallKB951748$ cpip.sys
2008-04-13 21:20 361344 93ea8d04ec73a85db02eb8805988f733 C:WINDOWSServicePackFilesi386TCPIP.SYS
2008-08-16 03:08 361600 a29e1209f925a0e9b330e11da5fc7bab C:WINDOWSsystem32dllcacheTCPIP.SYS
2008-08-16 03:08 361600 a29e1209f925a0e9b330e11da5fc7bab C:WINDOWSsystem32driversTCPIP.SYS
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"SpybotSD TeaTimer"="C:Program FilesSpybot - Search & DestroyTeaTimer.exe" [2008-01-28 2097488]
"ctfmon.exe"="C:WINDOWSsystem32ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"avast!"="C:PROGRA~1ALWILS~1Avast4ashDisp.exe" [2008-07-19 78008]
"ZoneAlarm Client"="C:Program Filesone LabsoneAlarmzlclient.exe" [2008-07-09 919016]
"M-Audio Taskbar Icon"="C:WINDOWSSystem32M-AudioTaskBarIcon.exe" [2008-05-15 356864]
"NvCplDaemon"="C:WINDOWSsystem32NvCpl.dll" [2008-05-16 13529088]
"NvMediaCenter"="C:WINDOWSsystem32NvMcTray.dll" [2008-05-16 86016]
"H2O"="C:Program FilesSyncroSoftPosH2Ocledx.exe" [2005-11-01 307200]
"spc1000"="C:WINDOWSvspc1000.exe" [2007-07-12 675840]
"nwiz"="nwiz.exe" [2008-05-16 C:WINDOWSsystem32
wiz.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 C:WINDOWSKHALMNPR.Exe]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionpoliciessystem]
"DisableStatusMessages"= 1 (0x1)
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionpoliciesexplorer]
"NoFavoritesMenu"= 0 (0x0)
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoInstrumentation"= 0 (0x0)
"NoSimpleStartMenu"= 0 (0x0)
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionpoliciesexplorer]
"NoStrCmpLogical"= 1 (0x1)
"NoFavoritesMenu"= 0 (0x0)
"NoSMMyPictures"= 0 (0x0)
"NoStartMenuMyMusic"= 0 (0x0)
"NoRecentDocsNetHood"= 0 (0x0)
"NoUserNameInStartMenu"= 1 (0x1)
"NoInstrumentation"= 0 (0x0)
"NoStartMenuPinnedList"= 0 (0x0)
"ForceStartMenuLogoff"= 0 (0x0)
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversionwinlogon
otifyLBTWlgn]
2008-05-02 02:42 72208 c:Program FilesFichiers communsLogitechBluetoothLBTWLgn.dll
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversiondrivers32]
"VIDC.YV12"= yv12vfw.dll
"SENTINEL"= snti386.dll
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalaawservice]
@=""
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalsacsvr]
@="Service"
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalsglfb.sys]
@="Driver"
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalsr.sys]
@=""
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalSRService]
@=""
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimal ga.sys]
@="Driver"
[HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSafeBootMinimalwd.sys]
@="Driver"
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity centerMonitoringoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
"%windir%\system32\sessmgr.exe"=
"%windir%\Network Diagnostic\xpnetdiag.exe"=
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"=
"C:\Program Files\Windows Live\Messenger\livecall.exe"=
"C:\Program Files\Autodesk\Backburner\monitor.exe"=
"C:\Program Files\Autodesk\Backburner\manager.exe"=
"C:\Program Files\Autodesk\Backburner\server.exe"=
R1 aswSP;avast! Self Protection;C:WINDOWSsystem32driversaswSP.sys [2008-07-19 78416]
R1 SAVRKBootTasks;Boot Tasks Driver;C:WINDOWSsystem32SAVRKBootTasks.sys [2007-08-14 18816]
R2 aswFsBlk;aswFsBlk;C:WINDOWSsystem32DRIVERSaswFsBlk.sys [2008-07-19 20560]
R2 Dnscache;Client DNS;C:WINDOWSsystem32svchost.exe [2008-04-14 14336]
R3 CLEDX;Team H2O CLEDX service;C:WINDOWSsystem32DRIVERScledx.sys [2005-05-09 33792]
R3 MAUSBFTP;Service for M-Audio Fast Track Pro (WDM);C:WINDOWSsystem32DRIVERSmausb.sys [2008-03-11 143624]
R3 phaudlwr;Philips Audio Filter;C:WINDOWSsystem32DRIVERSphaudlwr.sys [2007-07-12 88320]
R3 SPC1000;USB2.0 PC Camera (SPC1000);C:WINDOWSsystem32DRIVERSspc1000.sys [2007-07-12 3033856]
S2 mi-raysat_3dsMax2009_32;mental ray 3.6 Satellite for Autodesk 3ds Max 2009 32-bit 32-bit;C:Program FilesAutodesk3ds Max 2009mentalraysatellite
aysat_3dsMax2009_32server.exe [2008-03-10 65536]
S3 MEMSWEEP2;MEMSWEEP2;C:WINDOWSsystem322.tmp [ ]
*Newly Created Service* - PROCEXP90
.
.
------- Examen supplémentaire -------
.
FireFox -: Profile - C:Documents and SettingsKhemet WangApplication DataMozillaFirefoxProfiles1d8o4pw3.default
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://home.myspace.com/index.cfm?fusea ... 0951cef238
FF -: plugin - C:Program FilesAdobeAcrobat 8.0Acrobatrowser
ppdf32.dll
FF -: plugin - C:Program FilesK-Lite Codec PackRealrowserplugins
ppl3260.dll
FF -: plugin - C:Program FilesK-Lite Codec PackRealrowserplugins
prpjplug.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-20 00:08:52
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINEsystemControlSet001ServicesMEMSWEEP2]
"ImagePath"="??C:WINDOWSsystem322.tmp"
.
Heure de fin: 2008-09-20 0:09:46
ComboFix-quarantined-files.txt 2008-09-19 22:09:43
Avant-CF: 65y075y261y440 octets libres
Après-CF: 65,071,497,216 octets libres
319 --- E O F --- 2008-08-16 19:14:52
Voilà ce que ça donne.
Donc là qu'est ce que je fais des résultats obtenus avec le scan en ligne Kaspersky ? Je supprime tout ce qui est suspect ?
Et sinon combofix m'a pondu un dossier a la racine de C:
EDIT: il y a les précédents scan ELIBAGLA que j'ai fait dans la journée apparement, j'aimerai savoir si il est possible que le bagle soit allé se nicher dans mes autres DD