voilà le rapport :
ComboFix 07-10-29.1 - pikka 2007-10-31 22:26:26.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.1.1252.1.1036.18.157 [GMT 1:00]Running from: C:\DOCUME~1\pikka\MESDOC~1\STEPHA~1\combofix.exe
* Created a new restore point
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data.\salesmonitor
C:\WINDOWS\system32\_000014_.tmp.dll
.
((((((((((((((((((((((((((((( Fichiers créés 2007-09-28 to 2007-10-31 ))))))))))))))))))))))))))))))))))))
.
2007-10-31 22:25 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-29 13:38 742,400 --a--c--- C:\WINDOWS\system32\dllcache\helpctr.exe
2007-10-29 13:38 159,744 --a--c--- C:\WINDOWS\system32\dllcache\icwhelp.dll
2007-10-29 13:38 73,728 --a--c--- C:\WINDOWS\system32\dllcache\icwtutor.exe
2007-10-29 13:38 65,536 --a--c--- C:\WINDOWS\system32\dllcache\icwres.dll
2007-10-29 13:38 57,344 --a--c--- C:\WINDOWS\system32\dllcache\icwconn.dll
2007-10-29 13:38 45,056 --a--c--- C:\WINDOWS\system32\dllcache\icwutil.dll
2007-10-29 13:38 40,960 --a--c--- C:\WINDOWS\system32\dllcache\trialoc.dll
2007-10-29 13:38 24,576 --a--c--- C:\WINDOWS\system32\dllcache\icwrmind.exe
2007-10-29 13:38 24,576 --a--c--- C:\WINDOWS\system32\dllcache\icwdl.dll
2007-10-29 13:35 190,464 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-10-29 13:35 190,464 --a--c--- C:\WINDOWS\system32\dllcache\wuaueng.dll
2007-10-29 13:35 142,848 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-10-29 13:35 142,848 --a--c--- C:\WINDOWS\system32\dllcache\wuauclt.exe
2007-10-29 13:35 82,432 --a--c--- C:\WINDOWS\system32\dllcache\comrepl.dll
2007-10-29 13:35 82,432 --a------ C:\WINDOWS\system32\comrepl.dll
2007-10-29 13:32 4,992 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys
2007-10-29 13:31 83,712 --a------ C:\WINDOWS\system32\drivers\NABTSFEC.sys
2007-10-29 13:31 16,384 --a------ C:\WINDOWS\system32\drivers\CCDECODE.sys
2007-10-29 13:30 18,560 --a------ C:\WINDOWS\system32\drivers\WSTCODEC.SYS
2007-10-29 13:17 50,688 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2007-10-29 13:00 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2007-10-29 13:00 24,661 --a--c--- C:\WINDOWS\system32\dllcache\spxcoins.dll
2007-10-29 13:00 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2007-10-29 13:00 13,312 --a--c--- C:\WINDOWS\system32\dllcache\irclass.dll
2007-10-26 21:36 217,088 -ra------ C:\WINDOWS\select3a.exe
2007-10-26 21:36 112,380 -ra------ C:\WINDOWS\system32\drivers\pfc027.sys
2007-10-26 21:36 57,344 -ra------ C:\WINDOWS\system32\VFWUI.dll
2007-10-26 21:36 40,960 -ra------ C:\WINDOWS\CleanDev.exe
2007-10-25 09:33 <REP> d-------- C:\WINDOWS\BDOSCAN8
2007-10-24 19:38 <REP> d-------- C:\Documents and Settings\LocalService\Menu Démarrer
2007-10-24 19:22 <REP> d-------- C:\WINDOWS\peernet
2007-10-24 19:21 <REP> d-------- C:\WINDOWS\provisioning
2007-10-24 18:55 613,376 --a------ C:\WINDOWS\system32\xpsp2res.dll
2007-10-24 18:55 185,856 --a------ C:\WINDOWS\system32\xpob2res.dll
2007-10-24 18:55 11,544 --a------ C:\WINDOWS\system32\drivers\RecAgent.sys
2007-10-24 18:50 <REP> d-------- C:\WINDOWS\EHome
2007-10-24 15:59 <REP> d-------- C:\Program Files\Navilog1
2007-10-20 08:05 89,088 --a------ C:\WINDOWS\system32\atl71.dll
2007-10-20 08:05 24,064 --a------ C:\WINDOWS\system32\msxml3a.dll
2007-10-19 16:34 <REP> d-------- C:\Documents and Settings\pikka\Application Data\Grisoft
2007-10-19 16:34 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-19 16:34 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-10-19 14:35 <REP> d-------- C:\WINDOWS\pss
2007-10-16 08:14 520,192 --a--c--- C:\WINDOWS\system32\dllcache\wmplayer.exe
2007-10-13 13:04 507,904 --a------ C:\WINDOWS\TMUPDATE.DLL
2007-10-13 13:04 286,720 --a------ C:\WINDOWS\PATCH.EXE
2007-10-13 13:04 69,689 --a------ C:\WINDOWS\UNZIP.DLL
2007-10-13 08:02 <REP> d--h----- C:\WINDOWS\ShellNew
2007-10-13 08:01 <REP> d-------- C:\Documents and Settings\pikka\Application Data\Microsoft Web Folders
2007-10-13 07:06 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2007-10-13 07:05 <REP> d-------- C:\Program Files\Windows Live Toolbar
2007-10-10 21:19 26,112 --a------ C:\WINDOWS\system32\xpsp1hfm.exe
2007-10-10 19:16 <REP> d-------- C:\Program Files\eMule
2007-10-10 17:42 <REP> d---s---- C:\Documents and Settings\pikka\UserData
2007-10-10 17:02 20,579 -ra------ C:\WINDOWS\system32\drivers\ozscr.sys
2007-10-10 17:01 <REP> d-------- C:\WINDOWS\Modio
2007-10-10 17:01 466,944 --a------ C:\WINDOWS\system32\SLLights.dll
2007-10-10 17:01 376,832 --a------ C:\WINDOWS\system32\slmh.exe
2007-10-10 17:01 167,936 --a------ C:\WINDOWS\system32\minirec.exe
2007-10-10 17:01 151,552 --a------ C:\WINDOWS\system32\amr_cpl.dll
2007-10-10 17:01 61,440 --a------ C:\WINDOWS\SmCfg.exe
2007-10-10 17:01 16,128 --a------ C:\WINDOWS\system32\drivers\MODEMCSA.sys
2007-10-10 17:01 14,976 --a------ C:\WINDOWS\system32\drivers\winddx.sys
2007-10-10 16:57 <REP> d-------- C:\Program Files\NSC
2007-10-10 16:09 <REP> d-------- C:\Program Files\ATI Technologies
2007-10-10 16:09 229,376 -ra------ C:\WINDOWS\system32\atiiiexx.dll
2007-10-10 16:00 <REP> d-------- C:\Program Files\Intel
2007-10-10 15:53 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-10 15:46 <REP> d-------- C:\Program Files\CCleaner
2007-10-10 15:40 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-10-10 12:47 <REP> d-------- C:\Program Files\Synaptics
2007-10-10 12:47 268,784 --a------ C:\WINDOWS\system32\drivers\SynTP.sys
2007-10-10 12:47 110,592 --a------ C:\WINDOWS\system32\SynCtrl.dll
2007-10-10 12:47 98,304 --a------ C:\WINDOWS\system32\SynTPAPI.dll
2007-10-10 12:47 77,824 --a------ C:\WINDOWS\system32\SynTPCoI.dll
2007-10-10 12:47 77,824 --a------ C:\WINDOWS\system32\SynCOM.dll
2007-10-10 12:47 65,536 --a------ C:\WINDOWS\system32\SynTPFcs.dll
2007-10-10 12:38 <REP> d-------- C:\Program Files\VIA Technologies, Inc
2007-10-10 12:38 765,952 -ra------ C:\WINDOWS\system\crlds3d.dll
2007-10-10 12:38 720,896 -ra------ C:\WINDOWS\system32\Audio3D.dll
2007-10-10 12:38 720,896 -ra------ C:\WINDOWS\system32\a3d.dll
2007-10-10 12:38 411,008 -ra------ C:\WINDOWS\system32\drivers\viaudios.sys
2007-10-10 12:38 327,168 --a------ C:\WINDOWS\IsUn040c.exe
2007-10-10 12:38 32,768 --a------ C:\WINDOWS\system32\UnAudioNT.dll
2007-10-10 12:37 935,936 ---h----- C:\NBDriver.exe
2007-10-10 12:33 6,550 --a------ C:\WINDOWS\jautoexp.dat
2007-10-10 12:32 113 --a------ C:\WINDOWS\system32\zonedon.reg
2007-10-10 12:32 113 --a------ C:\WINDOWS\system32\zonedoff.reg
2007-10-10 12:13 <REP> d-------- C:\Program Files\Common Files
2007-10-10 12:12 <REP> d--h----- C:\Program Files\InstallShield Installation Information
2007-10-10 12:12 131,072 -ra------ C:\WINDOWS\system32\Epcmlib.dll
2007-10-10 12:11 <REP> d-------- C:\Program Files\Fichiers communs\InstallShield
2007-10-10 12:07 <REP> d-------- C:\Program Files\EPSON
2007-10-10 12:07 72,825 --a------ C:\WINDOWS\system32\EBPMON24.DLL
2007-10-10 12:07 63,488 --a------ C:\WINDOWS\system32\ECBTEG.DLL
2007-10-10 12:07 34,304 --a------ C:\WINDOWS\system32\EBPCHP.DLL
2007-10-10 12:07 31,744 --a------ C:\WINDOWS\system32\E_DCINST.DLL
2007-10-10 12:07 182 --a------ C:\WINDOWS\system32\EBPPORT4.DAT
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-31 21:31 --------- d-----w C:\Program Files\Wanadoo
2007-10-28 21:49 --------- d-----w C:\Program Files\MSN Messenger
2007-10-13 07:01 --------- d-----w C:\Program Files\microsoft frontpage
2007-10-10 10:13 --------- d-----w C:\Program Files\Alwil Software
2007-10-10 10:07 --------- d-----w C:\Program Files\SuperCopier2
2007-10-10 09:59 --------- d-----w C:\Program Files\Fichiers communs\ODBC
2007-10-10 09:58 --------- d-----w C:\Program Files\Fichiers communs\SpeechEngines
2007-10-10 09:54 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2007-10-10 09:42 --------- d-----w C:\Program Files\Securitoo
2007-10-10 09:32 --------- d-----w C:\Program Files\Inventel
2007-10-10 09:16 --------- d-----w C:\Program Files\Services en ligne
2007-10-10 09:15 --------- d-----w C:\Program Files\Fichiers communs\MSSoap
2007-09-06 10:05 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-09-06 10:05 92,848 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-09-06 10:03 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-09-06 10:02 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-09-06 10:00 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 14:49]
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 16:55]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 02:06]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 11:06]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2003-03-27 10:43]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2003-03-27 10:43]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 09:24 C:\WINDOWS\system32\Ati2mdxx.exe]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-11-25 20:10]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
"NI.UGA6P_0001_N119M1510"="C:\DOCUME~1\pikka\MESDOC~1\STEPHA~1\install_en.exe" []
"EPSON Stylus C64 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.exe" [2003-05-27 04:08]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2002-08-30 13:00]
"WOOKIT"="C:\PROGRA~1\Wanadoo\Shell.exe" [2004-08-23 14:50]
"SuperCopier2.exe"="C:\Program Files\SuperCopier2\SuperCopier2.exe" [2006-07-07 17:45]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 15:46]
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 21:05:56]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Notification Packages"= scecli scecli
R3 CIF USB CAMERA Service;CIF USB CAMERA;C:\WINDOWS\System32\DRIVERS\pfc027.sys
R3 DP83815;National Semiconductor Corp. DP83815/816 NDIS 5.0 Miniport Driver;C:\WINDOWS\System32\DRIVERS\DP83815.SYS
S3 FA312;Pilote de la carte Fast Ethernet FA330/FA312/FA311 NETGEAR;C:\WINDOWS\System32\DRIVERS\FA312nd5.sys
.
**************************************************************************
catchme 0.3.1239 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-10-31 22:31:00
Windows 5.1.2600 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-31 22:32:56 - machine was rebooted
.
--- E O F ---