Ok voici le rapport
ComboFix 09-03-14.01 - Sam 2009-03-15 15:20:54.3 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.3071.2477 [GMT 1:00]
Lancé depuis: c:\documents and settings\Sam\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\Sam\Bureau\CFScript.txt
* Un nouveau point de restauration a été créé
FILE ::
C:\bjj3iccf.com
C:\nar.vbs
c:\windows\nar.vbs
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
C:\bjj3iccf.com
C:\nar.vbs
c:\windows\nar.vbs
D:\Autorun.inf
E:\Autorun.inf
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-15 au 2009-03-15 ))))))))))))))))))))))))))))))))))))
.
2009-03-04 20:34 . 2009-03-04 20:35 <REP> d-------- c:\documents and settings\Sam\Application Data\InfraRecorder
2009-03-02 22:51 . 2009-03-02 22:51 <REP> d-------- c:\documents and settings\All Users\Application Data\ATI
2009-03-02 22:50 . 2009-03-02 22:52 <REP> d-------- c:\program files\ATI
2009-03-02 22:49 . 2009-02-03 21:05 593,920 --------- c:\windows\system32\ati2sgag.exe
2009-03-02 22:38 . 2009-03-02 22:38 10 --a------ c:\windows\WININIT.INI
2009-02-28 14:37 . 2003-07-16 07:17 5,174 --a------ c:\windows\system32\nppt9x.vxd
2009-02-28 14:37 . 2004-12-30 22:43 4,682 --a------ c:\windows\system32\npptNT2.sys
2009-02-28 14:36 . 2009-02-28 14:36 <REP> d-------- c:\program files\Common Files
2009-02-28 13:20 . 2009-02-28 13:20 <REP> d-------- c:\documents and settings\All Users\Application Data\InstallShield
2009-02-26 12:12 . 2009-02-26 12:12 <REP> d-------- c:\program files\Eicon
2009-02-26 12:12 . 2001-10-03 15:46 279,040 --a------ c:\windows\system32\gsi.cpl
2009-02-26 12:12 . 2001-09-28 11:05 250,706 --a------ c:\windows\system32\drivers\gwausb.sys
2009-02-26 12:12 . 2001-10-03 14:08 106,496 --------- c:\windows\system32\instDll.dll
2009-02-26 12:12 . 2001-10-02 08:42 98,304 --------- c:\windows\system32\gspnDll.dll
2009-02-26 12:12 . 2001-10-10 09:26 75,776 --a------ c:\windows\system32\gsicon.exe
2009-02-26 12:12 . 2001-10-03 15:01 71,680 --------- c:\windows\system32\GCPL_FRENCH.dll
2009-02-26 12:12 . 2001-09-28 11:07 26,987 --a------ c:\windows\system32\drivers\gafwload.sys
2009-02-26 12:12 . 2001-10-02 08:43 25,088 --a------ c:\windows\system32\CoInst.dll
2009-02-26 12:12 . 2001-10-02 08:42 24,576 --------- c:\windows\system32\delaySpawn.exe
2009-02-26 12:12 . 2001-10-02 08:42 16,384 --a------ c:\windows\system32\dslagent.exe
2009-02-26 12:12 . 2001-10-23 15:24 3,570 --------- c:\windows\wwdslcfg.ini
2009-02-26 11:17 . 2003-03-18 21:20 1,060,864 --a------ c:\windows\system32\MFC71.dll
2009-02-20 19:01 . 2009-02-20 19:01 107,888 --a------ c:\windows\system32\CmdLineExt.dll
2009-02-20 19:00 . 2009-02-20 19:00 <REP> d-------- c:\documents and settings\All Users\Application Data\KONAMI
2009-02-16 20:01 . 2009-02-16 20:01 <REP> d-------- c:\documents and settings\All Users\Application Data\Blizzard
2009-02-16 19:54 . 2009-02-19 19:00 <REP> d-------- c:\program files\Fichiers communs\Blizzard Entertainment
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-15 14:21 --------- d-----w c:\documents and settings\Sam\Application Data\SlimBrowser
2009-03-15 10:55 --------- d-----w c:\program files\lx_cats
2009-03-14 19:26 --------- d-----w c:\documents and settings\Sam\Application Data\Skype
2009-03-14 15:03 --------- d-----w c:\documents and settings\Sam\Application Data\skypePM
2009-03-13 17:00 --------- d-----w c:\program files\Norton Security Scan
2009-03-13 16:42 --------- d--h--w c:\program files\InstallShield Installation Information
2009-03-11 20:31 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-03-11 17:00 --------- d-----w c:\program files\Fichiers communs\Symantec Shared
2009-03-10 18:41 --------- d-----w c:\program files\Windows Live
2009-03-10 18:38 --------- d-----w c:\documents and settings\All Users\Application Data\WLInstaller
2009-03-02 21:49 --------- d-----w c:\program files\ATI Technologies
2009-02-28 12:16 --------- d-----w c:\program files\Fichiers communs\InstallShield
2009-02-11 09:19 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 09:19 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-02-09 14:05 1,846,912 ----a-w c:\windows\system32\win32k.sys
2009-02-04 07:27 3,488,768 ----a-w c:\windows\system32\drivers\ati2mtag.sys
2009-02-04 05:57 11,702,272 ----a-w c:\windows\system32\atioglxx.dll
2009-02-04 05:03 290,816 ----a-w c:\windows\system32\atiok3x2.dll
2009-02-04 04:56 442,368 ----a-w c:\windows\system32\ATIDEMGX.dll
2009-02-04 04:55 324,096 ----a-w c:\windows\system32\ati2dvag.dll
2009-02-04 04:44 196,608 ----a-w c:\windows\system32\atipdlxx.dll
2009-02-04 04:44 155,648 ----a-w c:\windows\system32\Oemdspif.dll
2009-02-04 04:43 43,520 ----a-w c:\windows\system32\ati2edxx.dll
2009-02-04 04:43 26,112 ----a-w c:\windows\system32\Ati2mdxx.exe
2009-02-04 04:43 155,648 ----a-w c:\windows\system32\ati2evxx.dll
2009-02-04 04:41 602,112 ----a-w c:\windows\system32\ati2evxx.exe
2009-02-04 04:40 53,248 ----a-w c:\windows\system32\ATIDDC.DLL
2009-02-04 04:30 3,884,768 ----a-w c:\windows\system32\ati3duag.dll
2009-02-04 04:14 2,645,504 ----a-w c:\windows\system32\ativvaxx.dll
2009-02-04 03:58 49,664 ----a-w c:\windows\system32\amdpcom32.dll
2009-02-04 03:54 471,040 ----a-w c:\windows\system32\atikvmag.dll
2009-02-04 03:53 122,880 ----a-w c:\windows\system32\atiadlxx.dll
2009-02-04 03:52 53,248 ----a-w c:\windows\system32\drivers\ati2erec.dll
2009-02-04 03:52 17,408 ----a-w c:\windows\system32\atitvo32.dll
2009-02-04 03:46 626,688 ----a-w c:\windows\system32\ati2cqag.dll
2009-02-04 03:44 307,200 ----a-w c:\windows\system32\atiiiexx.dll
2009-02-04 02:43 45,056 ----a-w c:\windows\system32\aticalrt.dll
2009-02-04 02:42 45,056 ----a-w c:\windows\system32\aticalcl.dll
2009-02-04 02:40 3,244,032 ----a-w c:\windows\system32\aticaldd.dll
2009-01-28 18:26 --------- d-----w c:\documents and settings\Sam\Application Data\Audacity
2009-01-26 17:56 --------- d-----w c:\documents and settings\Sam\Application Data\atitray
2009-01-21 15:34 --------- d-----w c:\documents and settings\All Users\Application Data\DVD Shrink
2009-01-21 14:57 --------- d-----w c:\program files\CyberLink
2009-01-21 14:57 --------- d-----w c:\documents and settings\All Users\Application Data\CyberLink
2009-01-16 20:30 --------- d-----w c:\documents and settings\All Users\Application Data\Elaborate Bytes
2009-01-16 17:34 499,712 ----a-w c:\windows\system32\msvcp71.dll
2008-12-20 22:47 826,368 ----a-w c:\windows\system32\wininet.dll
2008-12-15 19:06 81,920 ------r c:\windows\bwUnin-6.1.4.61-8876480L.exe
2008-12-15 18:59 315,392 ----a-w c:\windows\HideWin.exe
.
((((((((((((((((((((((((((((( SnapShot@2009-03-13_19.55.47,15 )))))))))))))))))))))))))))))))))))))))))
.
- 2009-02-03 23:21:12 21,244,864 ----a-w c:\windows\system32\MRT.exe
+ 2009-02-25 11:55:00 24,768,960 ----a-w c:\windows\system32\MRT.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MsnMsgr"="c:\progra~1\WINDOW~4\MESSEN~1\msnmsgr.exe" [2007-10-18 5724184]
"Steam"="d:\jeux\Steam\Steam.exe" [2009-01-19 1410296]
"AtiTrayTools"="d:\program files\Ray Adams\ATI Tray Tools\atitray.exe" [2007-05-22 521128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools-1033"="d:\program files\D-Tools\daemon.exe" [2004-08-22 81920]
"lxctmon.exe"="c:\program files\Lexmark 5400 Series\lxctmon.exe" [2006-11-22 291760]
"Lexmark 5400 Series Fax Server"="c:\program files\Lexmark 5400 Series\fm3032.exe" [2006-11-22 304048]
"EzPrint"="c:\program files\Lexmark 5400 Series\ezprint.exe" [2006-11-22 82864]
"LXCTCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCTtime.dll" [2006-11-21 106496]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_03\bin\jusched.exe" [2005-04-13 36975]
"QuickTime Task"="d:\program files\QuickTime\qttask.exe" [2007-06-29 286720]
"Flashget"="d:\program files\FlashGet\FlashGet.exe" [2007-09-25 2007088]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-02-03 61440]
"Logitech Utility"="Logi_MwX.Exe" [2003-12-11 c:\windows\LOGI_MWX.EXE]
"RTHDCPL"="RTHDCPL.EXE" [2007-08-10 c:\windows\RTHDCPL.exe]
"GSICONEXE"="GSICON.EXE" [2001-10-10 c:\windows\system32\gsicon.exe]
"DSLAGENTEXE"="dslagent.exe" [2001-10-02 c:\windows\system32\dslagent.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2008-12-15 169472]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\
0aswBoot.exe /A:* /L:French /KBD:2
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\WINDOWS\\system32\\lxctcoms.exe"=
"d:\\Program Files\\LimeWire\\LimeWire.exe"=
"d:\\Jeux\\AoM\\aomx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"d:\\Program Files\\FlashGet\\flashget.exe"=
"d:\\Download\\EyeInstaller.exe"=
"d:\\Jeux\\MOHAA\\MOHAA.exe"=
"d:\\Jeux\\GameSpy\\Aphex.exe"=
"d:\\Jeux\\Steam\\steamapps\\kenshy001\\day of defeat source\\hl2.exe"=
"d:\\Program Files\\eMule\\emule.exe"=
"d:\\Jeux\\PES 2009\\pes2009.exe"=
"d:\\Jeux\\Archlord\\Archlord_FR.exe"=
"d:\\Jeux\\Archlord\\Archlord.exe"=
"d:\\Jeux\\Archlord\\alefclient.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"d:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 atitray;atitray;d:\program files\Ray Adams\ATI Tray Tools\atitray.sys [2007-05-22 18088]
R3 wsvad_driver;WS Audio Device;c:\windows\system32\drivers\VirtualAudio.sys [2009-01-28 16896]
S2 gafwload;Eicon Networks USB ADSL Loader;c:\windows\system32\drivers\gafwload.sys [2009-02-26 26987]
.
Contenu du dossier 'Tâches planifiées'
2009-03-13 c:\windows\Tasks\Norton Security Scan for Sam.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 04:18]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-nar - c:\windows\nar.vbs
.
------- Examen supplémentaire -------
.
IE: &Tout télécharger avec FlashGet - d:\program files\FlashGet\jc_all.htm
IE: &Télécharger avec FlashGet - d:\program files\FlashGet\jc_link.htm
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {CAC677B6-4963-4305-9066-0BD135CD9233} - hxxps://asp.photoprintit.de/microsite/999/defaults/activex/ips/IPSUploader4.cab
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-15 15:21:47
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCTCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCTtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(568)
c:\windows\system32\Ati2evxx.dll
.
Heure de fin: 2009-03-15 15:22:31
ComboFix-quarantined-files.txt 2009-03-15 14:22:29
ComboFix2.txt 2009-03-13 18:56:14
ComboFix3.txt 2008-12-15 19:30:11
Avant-CF: 6 005 518 336 octets libres
Après-CF: 6,001,029,120 octets libres
199 --- E O F --- 2009-03-14 18:42:16