Voilà le combofix
ComboFix 08-09-04.09 - Propriétaire 2008-09-05 18:36:18.1 - NTFSx86
Microsoft Windows XP Edition familiale 5.1.2600.2.1252.1.1036.18.627 [GMT 4:00]
Endroit: C:Documents and SettingsPropriétaireBureauComboFix.exe
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:WINDOWSsystem32 dssadw.dll
C:WINDOWSsystem32 dssinit.dll
C:WINDOWSsystem32 dssl.dll
C:WINDOWSsystem32 dsslog.dll
C:WINDOWSsystem32 dssmain.dll
C:WINDOWSsystem32 dssservers.dat
.
((((((((((((((((((((((((((((( Fichiers créés 2008-08-05 to 2008-09-05 ))))))))))))))))))))))))))))))))))))
.
2008-09-05 18:23 . 2008-09-05 18:23 <REP> d-------- C:e0a26d8ed2089d225e
2008-09-04 09:25 . 2008-09-04 09:25 12,288 --a------ C:WINDOWSsystem32 dssserf.dll
2008-09-04 07:16 . 2004-06-18 16:07 656,542 --a------ C:271_icol.dll
2008-09-03 22:15 . 2008-09-03 22:15 <REP> d-------- C:Documents and SettingsPropriétaireApplication DataFindeXer
2008-09-03 22:10 . 2008-09-03 22:10 152,695 --a------ C:WINDOWSBricoPackUninst.cmd
2008-09-03 22:04 . 2008-09-03 22:04 <REP> d-------- C:Program FilesRK Launcher
2008-09-03 22:04 . 2008-09-04 07:16 <REP> d-------- C:Program FilesCursorXP
2008-09-03 22:03 . 2008-09-04 07:38 <REP> d-------- C:Program FilesMacSearch_v.1.4.3
2008-09-03 22:02 . 2008-09-03 22:13 <REP> d-------- C:Program FilesiColorFolder
2008-09-03 22:01 . 2008-09-03 22:01 3,936,310 --a------ C:WINDOWSBricoPack Wallpaper.bmp
2008-09-03 21:56 . 2008-09-03 22:10 7,915 --a------ C:WINDOWSBricoPackFoldersDelete.cmd
2008-09-03 21:55 . 2008-09-03 21:55 <REP> d-------- C:WINDOWSBricoPacks
2008-09-03 20:46 . 2006-09-05 23:28 38,480 --------- C:WINDOWSsystem32IJRMF.exe
2008-08-29 00:55 . 2008-08-29 17:06 <REP> d-------- C:WINDOWSsystem32CatRoot_bak
2008-08-08 03:04 . 2008-08-08 03:04 <REP> d-------- C:Program FilesMicrosoft CAPICOM 2.1.0.2
2008-08-07 09:07 . 2008-08-07 09:07 <REP> d-------- C:Documents and SettingsPropriétaireApplication DataAmbient Design
2008-08-07 07:33 . 2008-07-18 22:07 270,880 --a------ C:WINDOWSsystem32mucltui.dll
2008-08-07 07:33 . 2008-07-18 22:07 210,976 --a------ C:WINDOWSsystem32muweb.dll
2008-08-07 07:33 . 2008-07-18 22:07 29,728 --a------ C:WINDOWSsystem32mucltui.dll.mui
2008-08-06 14:19 . 2008-08-06 14:19 <REP> d--hsc--- C:Program FilesFichiers communsWindowsLiveInstaller
2008-08-06 14:19 . 2008-08-06 14:19 <REP> d-------- C:Documents and SettingsAll UsersApplication DataWLInstaller
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-05 14:33 --------- d-----w C:Documents and SettingsPropriétaireApplication DatauTorrent
2008-09-05 14:32 --------- d-----w C:Documents and SettingsPropriétaireApplication DataOpenOffice.org2
2008-09-05 14:08 390,919 ----a-w C:WINDOWSsystem32driversfwdrv.err
2008-09-05 13:21 --------- d-----w C:Documents and SettingsPropriétaireApplication DataSkype
2008-09-05 13:19 --------- d-----w C:Documents and SettingsPropriétaireApplication DataskypePM
2008-09-04 16:03 --------- d-----w C:Documents and SettingsAll UsersApplication DataSpybot - Search & Destroy
2008-09-04 15:22 --------- d-----w C:Program FileseMule
2008-09-04 15:02 --------- d-----w C:Program FilesHijackthis Version Française
2008-09-04 05:42 --------- d-----w C:Program FilesESTsoft
2008-09-04 05:42 --------- d-----w C:Documents and SettingsPropriétaireApplication DataESTsoft
2008-09-03 16:55 --------- d--h--w C:Program FilesInstallShield Installation Information
2008-09-03 16:55 --------- d-----w C:Program FilesSamsung
2008-09-03 16:44 --------- d-----w C:Program FilesALCATEL PC Suite
2008-09-03 16:09 --------- d-----w C:Program FilesuTorrent
2008-08-06 10:27 --------- d-----w C:Program FilesFichiers communsAdobe
2008-07-18 18:10 94,920 ----a-w C:WINDOWSsystem32cdm.dll
2008-07-18 18:10 53,448 ----a-w C:WINDOWSsystem32wuauclt.exe
2008-07-18 18:10 45,768 ----a-w C:WINDOWSsystem32wups2.dll
2008-07-18 18:10 36,552 ----a-w C:WINDOWSsystem32wups.dll
2008-07-18 18:09 563,912 ----a-w C:WINDOWSsystem32wuapi.dll
2008-07-18 18:09 325,832 ----a-w C:WINDOWSsystem32wucltui.dll
2008-07-18 18:09 205,000 ----a-w C:WINDOWSsystem32wuweb.dll
2008-07-18 18:09 1,811,656 ----a-w C:WINDOWSsystem32wuaueng.dll
2008-07-07 20:31 253,952 ----a-w C:WINDOWSsystem32es.dll
2008-06-24 16:23 74,240 ----a-w C:WINDOWSsystem32mscms.dll
2008-06-23 16:15 671,232 ----a-w C:WINDOWSsystem32Wininet.dll
2008-06-20 17:41 247,808 ----a-w C:WINDOWSsystem32mswsock.dll
.
------- Sigcheck -------
2008-04-14 06:34 512000 dd73d6b9f6b4cb630cf35b438b540174 C:WINDOWSSoftwareDistributionDownload23ec66f2314a80d718b5483ab6e865afwinlogon.exe
2004-08-05 16:00 546304 bdbd27fa935d482a3d6890c69913f8a4 C:WINDOWSsystem32winlogon.exe
2004-08-05 16:00 546304 bdbd27fa935d482a3d6890c69913f8a4 C:WINDOWSsystem32dllcachewinlogon.exe
2004-08-05 16:00 506368 d2de785aeab0bb8ca4c14a8a199dbe4e C:WINDOWSVistaMizeroldwinlogon.exe
2005-03-02 13:13 2059008 5311776074b6c13f983dc75baeac9c0c C:WINDOWS$hf_mig$KB890859SP2QFE
tkrnlpa.exe
2005-09-29 22:28 2017792 7a319c9e0c14ed6410e8b2753e3a32ce C:WINDOWS$NtUninstallKB929338$
tkrnlpa.exe
2006-12-19 22:45 2019328 c46168890982d41fb8accdbac8e0a56c C:WINDOWS$NtUninstallKB931784$
tkrnlpa.exe
2007-02-28 20:08 2061440 7a56a64eb50399613587e90292dd2aab C:WINDOWSDriver Cachei386
tkrnlpa.exe
2008-04-14 06:07 2067968 b71a8f101cefaf82fc5ec16130a54a3f C:WINDOWSSoftwareDistributionDownload23ec66f2314a80d718b5483ab6e865af
tkrnlpa.exe
2007-02-28 20:08 2278912 5ca4ef71ebb4def93fb671c8d4be8689 C:WINDOWSsystem32
tkrnlpa.exe
2007-02-28 20:08 2278912 5ca4ef71ebb4def93fb671c8d4be8689 C:WINDOWSsystem32dllcache
tkrnlpa.exe
2007-02-28 20:08 2019328 3e3df9f5d56b719f055e7d652e79f96b C:WINDOWSVistaMizerold
tkrnlpa.exe
2005-03-02 22:13 2181632 3e2a0a4a0c0b19fc113618a9562a3b2a C:WINDOWS$hf_mig$KB890859SP2QFE
toskrnl.exe
2005-09-29 22:28 2138112 cd6a9f81c8b9baf1e4393c6c476d17e7 C:WINDOWS$NtUninstallKB929338$
toskrnl.exe
2006-12-19 22:45 2139648 d9f5291648962a1733f8d3e59da47bee C:WINDOWS$NtUninstallKB931784$
toskrnl.exe
2007-02-28 20:08 2184192 8e244108562e0e452eb68dff64cb08a9 C:WINDOWSDriver Cachei386
toskrnl.exe
2008-04-14 06:08 2191104 099d639da1ef6968d4e41795bb507e6b C:WINDOWSSoftwareDistributionDownload23ec66f2314a80d718b5483ab6e865af
toskrnl.exe
2007-02-28 20:08 2399232 2595e01cbdf4d3a2257952e15c353325 C:WINDOWSsystem32
toskrnl.exe
2007-02-28 20:08 2399232 2595e01cbdf4d3a2257952e15c353325 C:WINDOWSsystem32dllcache
toskrnl.exe
2007-02-28 20:08 2139648 de41f3b43b9f15e08ccd4b98a7bb2ca3 C:WINDOWSVistaMizerold
toskrnl.exe
2007-06-13 17:22 1555968 b9dd2a11ec8414088970c8c46a2e6668 C:WINDOWSexplorer.exe
2007-06-13 17:10 1037312 b795475444d6d57a572c14b9e1a29839 C:WINDOWS$hf_mig$KB938828SP2QFEexplorer.exe
2004-08-05 16:00 1036288 4c33e5b9a6197b6ed215f6cfba0a2daa C:WINDOWS$NtUninstallKB938828$explorer.exe
2008-04-14 06:34 1037824 f2317622d29f9ff0f88aeecd5f60f0dd C:WINDOWSSoftwareDistributionDownload23ec66f2314a80d718b5483ab6e865afexplorer.exe
2007-06-13 17:22 3192832 f39d8e0f795d7937910593b9ed4250ad C:WINDOWSsystem32dllcacheexplorer.exe
2007-06-13 17:22 1037312 d0288319660edcfed07c7e74c4ea38a5 C:WINDOWSVistaMizeroldexplorer.exe
2008-04-14 06:33 15360 59dc5bb82e4c8e0b3eadcfdbc44ba6e4 C:WINDOWSSoftwareDistributionDownload23ec66f2314a80d718b5483ab6e865afctfmon.exe
2004-08-05 16:00 25088 af699a4a5f2fb5e3d73e931c2e6bedc4 C:WINDOWSsystem32ctfmon.exe
2004-08-05 16:00 25088 af699a4a5f2fb5e3d73e931c2e6bedc4 C:WINDOWSsystem32dllcachectfmon.exe
2004-08-05 16:00 15360 5584247b568c2e53934873f4b655fe6a C:WINDOWSVistaMizeroldctfmon.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"CTFMON.EXE"="C:WINDOWSsystem32ctfmon.exe" [2004-08-05 25088]
"µTorrent"="C:Program FilesuTorrentutorrent.exe" [2008-08-14 267056]
"SuperCopier2.exe"="C:Program FilesSuperCopier2SuperCopier2.exe" [2006-07-07 1052672]
"MediaDico"="C:Program FilesMicro ApplicationMediaDICOLanceMediaDICO.exe" [2002-01-09 197632]
"SpybotSD TeaTimer"="C:Program FilesSpybot - Search & DestroyTeaTimer.exe" [2008-01-28 2097488]
"CursorXP"="C:Program FilesCursorXPCursorXP.exe" [2005-01-19 128000]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"SunJavaUpdateSched"="C:Program FilesJavajre1.6.0_03injusched.exe" [2007-09-25 132496]
"FuncKey"="C:Program FilesHotkey ManagementFuncKey.exe" [2006-09-05 139264]
"NvCplDaemon"="C:WINDOWSsystem32NvCpl.dll" [2006-08-16 7585792]
"fscp"="C:Program FilesAVC Finger-sensing Pad Driverfscp.exe" [2006-08-31 995328]
"SSBkgdUpdate"="C:Program FilesFichiers communsScansoft SharedSSBkgdUpdateSSBkgdupdate.exe" [2003-09-30 155648]
"OpwareSE4"="C:Program FilesScanSoftOmniPageSE4.0OpwareSE4.exe" [2006-03-21 69632]
"PVR Agent"="C:Program FilesKWorld MultimediaPVR PlusTVRScheduled.exe" [2005-12-21 754176]
"NeroFilterCheck"="C:WINDOWSsystem32NeroCheck.exe" [2001-07-09 155648]
"snpstd"="C:WINDOWSvsnpstd.exe" [2004-06-10 286720]
"avast!"="C:PROGRA~1ALWILS~1Avast4ashDisp.exe" [2008-07-19 78008]
"QuickTime Task"="C:Program FilesQuickTimeqttask.exe" [2007-06-29 286720]
"Easy-PrintToolBox"="C:Program FilesCanonEasy-PrintToolBoxBJPSMAIN.EXE" [2006-10-17 398944]
"nwiz"="nwiz.exe" [2006-08-16 C:WINDOWSsystem32
wiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-07-21 C:WINDOWSRTHDCPL.EXE]
"SkyTel"="SkyTel.EXE" [2006-05-16 C:WINDOWSSkyTel.exe]
[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
"CTFMON.EXE"="C:WINDOWSsystem32CTFMON.EXE" [2004-08-05 25088]
C:Documents and SettingsPropri,taireMenu D,marrerProgrammesD,marrage
OpenOffice.org 2.3.lnk - C:Program FilesOpenOffice.org 2.3programquickstart.exe [2007-08-17 393216]
C:Documents and SettingsAll UsersMenu D,marrerProgrammesD,marrage
Adobe Gamma Loader.lnk - C:Program FilesFichiers communsAdobeCalibrationAdobe Gamma Loader.exe [2007-07-03 113664]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversiondrivers32]
"msacm.l3acm"= l3codecp.acm
"VIDC.MJPG"= mtkjpeg.dll
"msacm.l3codec"= l3codecp.acm
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
"%windir%\system32\sessmgr.exe"=
"C:\Program Files\eMule\emule.exe"=
"C:\Program Files\Mozilla Firefox\firefox.exe"=
"C:\Program Files\MSN Messenger\msnmsgr.exe"=
"C:\Program Files\MSN Messenger\livecall.exe"=
"C:\Program Files\Nero\Nero 7\Nero ShowTime\ShowTime.exe"=
"%windir%\Network Diagnostic\xpnetdiag.exe"=
"C:\Program Files\Messenger\msmsgs.exe"=
"C:\Program Files\uTorrent\utorrent.exe"=
"C:\Program Files\Skype\Phone\Skype.exe"=
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileGloballyOpenPortsList]
"13463:TCP"= 13463:TCP:µ
R1 aswSP;avast! Self Protection;C:WINDOWSsystem32driversaswSP.sys [2008-07-19 78416]
R1 fwdrv;Firewall Driver;C:WINDOWSsystem32driversfwdrv.sys [2007-04-26 302000]
R1 khips;Kerio HIPS Driver;C:WINDOWSsystem32driverskhips.sys [2007-04-26 72624]
R2 aswFsBlk;aswFsBlk;C:WINDOWSsystem32DRIVERSaswFsBlk.sys [2008-07-19 20560]
R2 FspadSvc;FspadSvc;C:Program FilesAVC Finger-sensing Pad DriverFspadSvr.exe [2006-08-23 520704]
R3 fspad;AVC Finger-sensing Pad Driver for Windows 2000/XP;C:WINDOWSsystem32DRIVERSfspad.sys [2006-09-01 22912]
S2 SPF4;Sunbelt Personal Firewall 4;C:Program FilesSunbelt SoftwarePersonal Firewallkpf4ss.exe [ ]
S3 CnxEtP;ZTE ZXDSL852 Adapter Filter Driver;C:WINDOWSsystem32DRIVERSCnxEtP.sys [ ]
S3 CnxEtU;ZTE ZXDSL852 Interface Device Driver;C:WINDOWSsystem32DRIVERSCnxEtU.sys [ ]
S3 CnxTgNW;ZTE ZXDSL852 WAN PPPoA Adapter Driver;C:WINDOWSsystem32DRIVERSCnxTgNW.sys [ ]
S3 ComFiltr;Panda Anti-Dialer;C:WINDOWSsystem32DRIVERSCOMFiltr.sys [ ]
S3 odysseyIM4;Odyssey Network Agent Miniport;C:WINDOWSsystem32DRIVERSodysseyIM4.sys [2005-05-18 173056]
S3 PavSRK.sys;PavSRK.sys;C:WINDOWSsystem32PavSRK.sys [ ]
S3 PavTPK.sys;PavTPK.sys;C:WINDOWSsystem32PavTPK.sys [ ]
S3 SIS163u;SiS163 USB Wireless LAN Adapter Driver;C:WINDOWSsystem32DRIVERSsis163u.sys [2006-07-03 217600]
S3 USB28xxBGA;USB 2861 Device;C:WINDOWSsystem32DRIVERSemBDA.sys [2006-02-08 217216]
S3 USB28xxOEM;USB 28xx OEM Filter;C:WINDOWSsystem32DRIVERSemOEM.sys [2006-02-08 17792]
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2{4535be56-1b64-11dd-8f85-00140b01f7c2}]
ShellAutoRuncommand - G:setupSNK.exe
*Newly Created Service* - PROCEXP90
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-PowerManager - C:Program FilesPower ManagerPM.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:Documents and SettingsPropriétaireApplication DataMozillaFirefoxProfiles9vcciku8.default
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-05 18:43:26
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINEsystemControlSet001ServicesTDSSserv]
"imagepath"="systemrootsystem32driversTDSSserv.sys"
[HKEY_LOCAL_MACHINEsystemControlSet001ServicesmchInjDrv]
"ImagePath"="??C:DOCUME~1PROPRI~1LOCALS~1Tempmc21.tmp"
.
Temps d'accomplissement: 2008-09-05 18:47:43
ComboFix-quarantined-files.txt 2008-09-05 14:47:35
Pre-Run: 7,854,755,840 octets libres
Post-Run: 7,858,995,200 octets libres
198 --- E O F --- 2008-08-24 23:03:34