Voila le rapport
ComboFix 08-03-26.3 - 2008-03-28 12:58:38.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.272 [GMT 1:00]
Endroit: C:\Documents and Settings\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Jessica\Bureau\CFScript.txt
* Création d'un nouveau point de restauration
* Resident AV is active
[color=red]
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/color]
FILE ::
C:\kleaner.tmp
C:\WINDOWS\image.jpg
C:\WINDOWS\system32\^^^^^.exe
C:\WINDOWS\system32\eoybkf.exe
C:\WINDOWS\system32\nqykmc.exe
.
-- Script messages for sUBs --
Findstr -MIF:/ sursen
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\image.jpg
C:\WINDOWS\system32\^^^^^.exe
C:\WINDOWS\system32\eoybkf.exe
C:\WINDOWS\system32\nqykmc.exe
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-02-28 to 2008-03-28 ))))))))))))))))))))))))))))))))))))
.
2008-03-27 18:20 . 2008-03-27 18:20 <REP> d-------- C:\SDFix
2008-03-27 14:34 . 2008-03-27 14:34 <REP> d-------- C:\Documents and Settings\Application Data\Grisoft
2008-03-26 11:55 . 2008-03-26 11:55 244 --ah----- C:\sqmnoopt01.sqm
2008-03-26 11:55 . 2008-03-26 11:55 232 --ah----- C:\sqmdata01.sqm
2008-03-26 10:25 . 2008-03-26 10:24 512,096 --a------ C:\WINDOWS\system32\drivers\amon.sys
2008-03-26 10:25 . 2008-03-26 10:24 298,104 --a------ C:\WINDOWS\system32\_mon.d00
2008-03-26 10:25 . 2008-03-26 10:24 15,424 --a------ C:\WINDOWS\system32\drivers\nod32drv.sys
2008-03-26 10:18 . 2008-03-26 10:18 244 --ah----- C:\sqmnoopt00.sqm
2008-03-26 10:18 . 2008-03-26 10:18 232 --ah----- C:\sqmdata00.sqm
2008-03-26 09:00 . 2008-03-26 08:58 298,104 --a------ C:\WINDOWS\system32\imon.dll
2008-03-26 08:58 . 2008-03-26 10:40 <REP> d-------- C:\Program Files\Eset
2008-03-25 21:12 . 2008-03-25 21:12 <REP> d--h----- C:\kleaner.tmp
2008-03-25 21:10 . 2008-03-25 21:10 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-03-23 16:24 . 2008-03-26 17:08 <REP> d-------- C:\Program Files\La QuatriŠme Proph‚tie2
2008-03-21 21:51 . 2008-03-21 21:51 <REP> d--hs---- C:\found.000
2008-03-21 10:27 . 2008-03-21 10:32 <REP> d-------- C:\Documents and Settings\Application Data\Ventrilo
2008-03-11 10:33 . 2008-03-26 15:37 <REP> d-------- C:\Program Files\Lyberia - La Quatrieme Prophetie
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-28 12:05 --------- d-----w C:\Program Files\Wanadoo
2008-03-27 12:58 --------- d-----w C:\Program Files\Windows Live
2008-03-27 12:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-03-26 16:08 --------- d-----w C:\Program Files\La Quatrième Prophétie2
2008-03-26 09:22 --------- d-----w C:\Program Files\eMule
2008-03-25 20:12 --------- d-----w C:\Program Files\Alwil Software
2008-03-22 10:42 --------- d-----w C:\Program Files\Java
2008-03-10 18:12 377 ----a-w C:\WINDOWS\Fonts\INSTALL.LOG
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WOOKIT"="C:\Program Files\Wanadoo\Shell.exe" [2004-08-23 14:50 122880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 17:17 159744]
"WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 14:49 20480]
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 16:55 32768]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-04-27 08:04 185896]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-09-20 08:35 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-09-20 08:32 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-09-20 08:36 114688]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"nod32kui"="C:\Program Files\Eset\nod32kui.exe" [2008-03-26 10:24 949376]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 12:00 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\The All-Seeing Eye\\eye.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\WINDOWS\\explorer.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Documents and Settings\\Jessica\\Bureau\\T4C 1.6\\prophexy.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Internet Security 7.0.1.325\\French\\setup.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009
"80:TCP"= 80:TCP:WWW
"5503:TCP"= 5503:TCP:WWW
"53:UDP"= 53:UDP:DNS
"25:UDP"= 25:UDP:SMTP
"6045:TCP"= 6045:TCP:WWW
"9186:TCP"= 9186:TCP:WWW
"2635:TCP"= 2635:TCP:WWW
"2124:TCP"= 2124:TCP:WWW
"1948:TCP"= 1948:TCP:WWW
"3808:TCP"= 3808:TCP:WWW
"1523:TCP"= 1523:TCP:WWW
"9381:TCP"= 9381:TCP:WWW
"5252:TCP"= 5252:TCP:WWW
"2989:TCP"= 2989:TCP:WWW
"6546:TCP"= 6546:TCP:WWW
"4496:TCP"= 4496:TCP:WWW
"4485:TCP"= 4485:TCP:WWW
"9985:TCP"= 9985:TCP:WWW
"6517:TCP"= 6517:TCP:WWW
"5105:TCP"= 5105:TCP:WWW
"7659:TCP"= 7659:TCP:WWW
"6009:TCP"= 6009:TCP:WWW
"2186:TCP"= 2186:TCP:WWW
"8011:TCP"= 8011:TCP:WWW
"8401:TCP"= 8401:TCP:WWW
"7239:TCP"= 7239:TCP:WWW
"4090:TCP"= 4090:TCP:WWW
"3499:TCP"= 3499:TCP:WWW
"9342:TCP"= 9342:TCP:WWW
"9564:TCP"= 9564:TCP:WWW
"7097:TCP"= 7097:TCP:WWW
"8696:TCP"= 8696:TCP:WWW
"7992:TCP"= 7992:TCP:WWW
"2269:TCP"= 2269:TCP:WWW
"1963:TCP"= 1963:TCP:WWW
"4680:TCP"= 4680:TCP:WWW
"5728:TCP"= 5728:TCP:WWW
"6017:TCP"= 6017:TCP:WWW
"7026:TCP"= 7026:TCP:WWW
"2969:TCP"= 2969:TCP:WWW
"2990:TCP"= 2990:TCP:WWW
"4859:TCP"= 4859:TCP:WWW
"6444:TCP"= 6444:TCP:WWW
"2958:TCP"= 2958:TCP:WWW
"5348:TCP"= 5348:TCP:WWW
"2133:TCP"= 2133:TCP:WWW
"19237:TCP"= 19237:TCP:BitComet 19237 TCP
"19237:UDP"= 19237:UDP:BitComet 19237 UDP
R3 phil2vid;Appareil photo VGA USB Philips PCVC690;C:\WINDOWS\system32\DRIVERS\philcam2.sys [2001-08-17 21:04]
S3 w300bus;Sony Ericsson W300 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\w300bus.sys [2006-03-13 16:49]
S3 w300mdfl;Sony Ericsson W300 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w300mdfl.sys [2006-03-13 16:50]
S3 w300mdm;Sony Ericsson W300 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w300mdm.sys [2006-03-13 16:50]
S3 w300mgmt;Sony Ericsson W300 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w300mgmt.sys [2006-03-13 16:50]
S3 w300obex;Sony Ericsson W300 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w300obex.sys [2006-03-13 16:50]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-28 13:04:50
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
--------------------- DLLs a charg‚ sous des processus courants ---------------------
PROCESS: C:\WINDOWS\system32\lsass.exe
-> C:\Program Files\Eset\pr_imon.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindService.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\Program Files\Fichiers communs\Teleca Shared\CapabilityManager.exe
C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-03-28 13:09:40 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-28 12:09:30
ComboFix2.txt 2008-03-28 11:32:12
Pre-Run: 39,086,497,792 octets libres
Post-Run: 39,084,642,304 octets libres
.
2008-03-20 06:29:38 --- E O F ---