Alors,
=j'ai repris ttes les manip depuis le début,
=télécharger combofix
=scan
___________________________
rapport
"Mr N'GAMAMBA" - 2007-06-08 14:39:59 Service Pack 2
ComboFix 07-06-3B - Running from: "C:\Documents and Settings\Mr N'GAMAMBA\Bureau\"
((((((((((((((((((((((((( Files Created from 2007-05-08 to 2007-06-08 )))))))))))))))))))))))))))))))
2007-06-07 13:05 <REP> d-------- C:\VundoFix Backups
2007-06-07 11:52 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-06-07 11:07 <REP> d---s---- C:\DOCUME~1\MRN'GA~1\UserData
2007-06-06 09:54 <REP> d-------- C:\Program Files\SUPERAntiSpyware
2007-06-06 09:54 <REP> d-------- C:\DOCUME~1\MRN'GA~1\APPLIC~1\SUPERAntiSpyware.com
2007-06-06 09:54 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\SUPERAntiSpyware.com
2007-06-05 09:56 <REP> d-------- C:\Program Files\Navilog1
2007-06-04 18:06 2,270 --a------ C:\WINDOWS\system32\tmp.reg
2007-06-04 18:05 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-06-04 18:05 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-06-04 18:05 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-06-04 17:17 <REP> d-------- C:\!KillBox
2007-06-04 14:09 <REP> d-------- C:\Program Files\a-squared Free
2007-06-04 13:27 <REP> d-------- C:\WINDOWS\pss
2007-06-03 23:53 <REP> d--hs---- C:\FOUND.002
2007-06-03 22:19 79,552 -r-hs---- C:\AUT0EXEC.BAT
2007-06-03 22:19 1,392,671 -r-hs---- C:\msvbvm60.dll
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-04-30 15:46:10 745,600 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-04-30 15:41:56 85,952 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-04-30 15:41:42 94,552 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-04-30 15:39:42 23,416 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-04-30 15:38:52 43,176 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-04-30 15:37:24 26,888 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-04-30 15:35:28 95,872 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-04-18 16:14:18 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-03-17 13:44:48 293,376 ----a-w C:\WINDOWS\system32\winsrv.dll
2007-03-08 15:37:50 578,560 ----a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:37:50 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:37:50 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 15:33:58 1,843,712 ----a-w C:\WINDOWS\system32\win32k.sys
2004-08-05 13:00:00 1,392,671 --sh--r C:\WINDOWS\system32\msvbvm60.dll
2004-08-05 13:00:00 1,392,671 --sh--r C:\WINDOWS\system32\dllcache\msvbvm60.dll
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{02478D38-C3F9-4EFB-9B51-7695ECA05670}=C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2005-12-07 15:06]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}=C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx [2001-04-16 16:39]
{53707962-6F74-2D53-2644-206D7942484F}=C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2005-05-31 01:04]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-09-29 06:38 C:\WINDOWS\SOUNDMAN.EXE]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-20 16:20]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-20 16:20]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-09-09 21:10]
"Control Center"="C:\Progra~1\ASUS\WLAN Card Utilities\Center.exe" [2004-11-30 11:33]
"RemoteControl"="C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe" [2003-10-31 19:42]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-04-30 16:42]
"Blank AntiViri"="C:\AUT0EXEC.BAT StartUp" []
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-05-30 13:30]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE" [2004-02-24 16:20]
"SuperCopier.exe"="C:\Program Files\SuperCopier\SuperCopier.exe" [2003-04-24 23:03]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-05-23 10:12]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"AllowLegacyWebView"=1 (0x1)
"AllowUnhashedWebView"=1 (0x1)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"="C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2006-12-20 13:55]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 13:29]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{23e8d4c2-77f3-11db-a4b7-0011d8cea4b8}]
Auto\command- RavMonE.exe e
AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RavMonE.exe e
**************************************************************************
catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-06-08 14:41:09
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Files hidden from API:
C:\WINDOWS\Tasse … caf‚.bmp
C:\WINDOWS\Jour de pˆche.bmp
C:\WINDOWS\RiviŠre Sumida.bmp
C:\WINDOWS\system32\ChaŒnes.scf
Completion time: 2007-06-08 14:42:14
--- E O F ---
________________________________________
*2007-06-03 22:19 1,392,671 -r-hs---- C:\msvbvm60.dll
[ Ce message a été modifié par : : boboboss le 08-06-2007 16:01 ]