Mission ComboFix effectuée, voici le résultat :
ComboFix 07-10-22.7 - MARCO 2007-10-22 20:38:48.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1130 [GMT 2:00]
Running from: C:\Documents and Settings\MARCO\Mes documents\Flec006\Logiciels kill flec006\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\pack.epk
C:\WINDOWS\system32\cmesys.exe
C:\WINDOWS\winlogon.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_RDRIV
-------\nm
-------\rdriv
((((((((((((((((((((((((((((( Fichiers créés 2007-09-22 to 2007-10-22 ))))))))))))))))))))))))))))))))))))
.
2007-10-22 19:07 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-22 18:27 <REP> d-------- C:\Muestras
2007-10-22 14:40 <REP> d-------- C:\Program Files\Trend Micro
2007-10-22 14:20 <REP> d--h----- C:\Documents and Settings\MARCO\Application Data\m
2007-10-21 23:19 <REP> d-------- C:\WINDOWS\system32\ZoneLabs
2007-10-21 23:18 <REP> d-------- C:\Program Files\Alwil Software
2007-10-21 23:18 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2007-10-21 22:39 <REP> d-------- C:\WINDOWS\LastGood
2007-10-21 22:39 <REP> d-------- C:\WINDOWS\BDOSCAN8
2007-10-21 21:04 801,144 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-10-21 21:04 94,416 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-10-21 21:04 92,848 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-10-21 21:04 36,176 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-10-21 21:04 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-10-21 21:04 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-10-21 20:53 <REP> d-------- C:\Program Files\PcHeal
2007-10-21 11:37 748,805 --------- C:\WINDOWS\system32\drivers\HIDR.EXE.VIR
2007-10-21 10:47 <REP> d-------- C:\Program Files\Microsoft Money Plus
2007-10-21 09:38 <REP> d-------- C:\WINDOWS\SxsCaPendDel
2007-10-20 05:45 584,192 --------- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2007-10-19 18:43 <REP> d-------- C:\Program Files\a-squared Free
2007-10-03 08:06 <REP> d-------- C:\Program Files\SPAMfighter
2007-10-03 08:06 <REP> d-------- C:\Program Files\Fichiers communs\Application
2007-10-03 08:06 <REP> d-------- C:\Program Files\Fichiers communs\Ankiro
2007-10-01 01:11 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-09-27 07:37 <REP> d-------- C:\Documents and Settings\MARCO\Application Data\Spamihilator
2007-09-22 09:34 <REP> d-------- C:\Program Files\AMD
2007-09-22 09:34 29,696 --a------ C:\WINDOWS\system32\drivers\AmdTools.sys
2007-09-22 09:33 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-22 11:09 --------- d-----w C:\Program Files\Uniblue
2007-10-21 21:32 --------- d-----w C:\Documents and Settings\MARCO\Application Data\Uniblue
2007-10-19 17:37 --------- d-----w C:\Program Files\Intelore
2007-10-19 17:37 --------- d-----w C:\Program Files\ElcomSoft
2007-10-19 16:50 --------- d-----w C:\Program Files\Java
2007-10-19 16:35 --------- d-----w C:\Program Files\a2 Free
2007-10-17 15:04 --------- d-----w C:\Program Files\Microsoft Encarta
2007-09-27 19:35 --------- d-----w C:\Program Files\HyperSnap-DX 5
2007-09-27 06:15 --------- d-----w C:\Documents and Settings\MARCO\Application Data\RTE
2007-09-27 05:38 --------- d-----w C:\Documents and Settings\MARCO\Application Data\Desktop Sidebar
2007-09-13 19:10 --------- d-----w C:\Documents and Settings\MARCO\Application Data\ma-config.com
2007-09-13 19:09 --------- d-----w C:\Program Files\ma-config.com
2007-09-13 19:09 --------- d-----w C:\Program Files\HardwareDetection
2006-10-27 03:53 69,376 ------w C:\Documents and Settings\MARCO\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A7D7AC4D-DB5A-4383-97B7-634153E41B33}]
2006-01-16 15:29 21084 --a------ C:\WINDOWS\system32\wio32spl.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"EPSON Stylus Photo RX420 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.exe" [2004-04-09 05:00]
"NVCLOCK"="nvclock.dll" [2003-04-14 10:59 C:\WINDOWS\system32\nvclock.dll]
"nwiz"="nwiz.exe" [2006-10-22 13:22 C:\WINDOWS\system32\nwiz.exe]
"NeroFilterCheck"="C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2007-03-01 15:57]
"NvMediaCenter"="NvMCTray.dll" [2006-10-22 13:22 C:\WINDOWS\system32\nvmctray.dll]
"nvchost"="C:\WINDOWS\winlogon.exe" []
"RegistryMechanic"="" []
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 01:09]
"EPSON Stylus Photo RX420 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.exe" [2004-04-09 05:00]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveSearch"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoLowDiskSpaceCheck"=0 (0x0)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 relog_ap
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger.lnk]
backup=C:\WINDOWS\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech SetPoint.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech SetPoint.lnk
backup=C:\WINDOWS\pss\Logitech SetPoint.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKAGENTEXE]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NI.UWFX5V_0001_N57M1212]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\World Clocks Wallpaper]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"C-DillaSrv"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" /background
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"LiveMonitor"=C:\Program Files\MSI\Live Update 3\LMonitor.exe
"LogitechVideoRepair"=C:\Program Files\Logitech\Video\ISStart.exe
"LogitechVideoTray"=C:\Program Files\Logitech\Video\LogiTray.exe
"Logitech Hardware Abstraction Layer"=KHALMNPR.EXE
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" -atboottime
"ISUSPM Startup"=c:\program files\fichiers communs\installshield\updateservice\isuspm.exe -startup
"ISUSScheduler"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
"nwiz"=nwiz.exe /install
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{48716f4a-0149-11dc-bb3d-0011092513df}]
AutoRun\command - M:\LaunchU3.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7cf92255-3ade-11dc-bbf6-0011092513df}]
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe MS32DLL.dll.vbs
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2007-10-19 15:15:00 C:\WINDOWS\Tasks\Maintenance en 1 clic.job"
"2007-10-22 18:40:00 C:\WINDOWS\Tasks\User_Feed_Synchronization-{625D108B-613B-4003-B233-CFACB04AF59E}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-10-22 20:42:14
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-22 20:42:40 - machine was rebooted
.
--- E O F ---