eh hééé ça a marché!
voici voila
ComboFix 08-10-08.05 - moi 2008-10-09 20:09:12.2 - NTFSx86
Lancé depuis: C:\Documents and Settings\moi\Bureau\ComboFix.exe
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\drivers\fad.sys
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\TDSSadw.dll
C:\WINDOWS\system32\TDSSerrors.log
C:\WINDOWS\system32\tdssinit.dll
C:\WINDOWS\system32\tdssl.dll
C:\WINDOWS\system32\TDSSlog.dll
C:\WINDOWS\system32\tdssmain.dll
C:\WINDOWS\system32\tdssserf.dll
C:\WINDOWS\system32\TDSSserf1.dll
C:\WINDOWS\system32\tdssservers.dat
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TDSSSERV
-------\Service_TDSSserv
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-09 au 2008-10-09 ))))))))))))))))))))))))))))))))))))
.
2008-10-09 17:57 . 2008-10-09 19:35 <REP> d-------- C:\Program Files\a-squared Free
2008-10-09 16:05 . 2008-10-09 16:05 579,584 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\user32.dll
2008-10-09 16:02 . 2008-10-09 16:03 <REP> d-------- C:\WINDOWS\ERUNT
2008-10-09 16:02 . 2001-08-18 13:00 1,688 --a------ C:\WINDOWS\SYSTEM32\AUTOEXEC.NT
2008-10-09 16:00 . 2008-10-09 16:16 <REP> d-------- C:\SDFix
2008-10-07 22:54 . 2008-10-07 22:54 <REP> d-------- C:\Documents and Settings\moi\Application Data\Uniblue
2008-10-07 22:38 . 2008-10-09 16:01 <REP> d-------- C:\Program Files\FindyKill
2008-10-06 21:13 . 2008-10-06 21:13 <REP> d-------- C:\Lop SD
2008-10-03 16:09 . 2008-10-03 16:10 <REP> d-------- C:\WINDOWS\BDOSCAN8
2008-10-03 15:59 . 2008-10-03 15:59 <REP> d-------- C:\ToolBar SD
2008-10-03 15:43 . 2008-10-03 15:43 <REP> d-------- C:\Program Files\Trend Micro
2008-10-03 15:10 . 2008-04-13 19:33 712,704 --------- C:\WINDOWS\SYSTEM32\windowscodecs.dll
2008-10-03 15:06 . 2008-04-13 09:36 144,384 --------- C:\WINDOWS\SYSTEM32\DRIVERS\hdaudbus.sys
2008-10-03 15:06 . 2008-04-13 11:40 10,240 --------- C:\WINDOWS\SYSTEM32\DRIVERS\sffp_mmc.sys
2008-10-03 15:05 . 2006-12-28 12:01 19,569 --a------ C:\WINDOWS\
003252_.tmp
2008-10-03 15:05 . 2008-10-03 15:20 2,675 --a------ C:\WINDOWS\imsins.BAK
2008-10-02 20:28 . 2008-10-02 20:28 <REP> d-------- C:\Program Files\CCleaner
2008-10-02 16:30 . 2008-10-09 20:04 <REP> d-------- C:\SmitfraudFix
2008-10-02 16:28 . 2008-10-02 16:28 1,659,439 --a------ C:\SmitfraudFix.exe
2008-09-29 22:14 . 2008-04-13 19:33 185,344 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\framedyn.dll
2008-09-28 19:20 . 2008-09-28 19:20 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Malwarebytes
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-09 18:04 --------- d-----w C:\Program Files\Kazaa
2008-10-09 14:01 5,632 --sha-w C:\Program Files\Fichiers communs\Thumbs.db
2008-10-09 14:01 --------- d-----w C:\Program Files\eMule
2008-10-09 14:01 --------- d-----w C:\Program Files\DivX
2008-10-07 17:38 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-07 17:32 --------- d-----w C:\Program Files\Logitech
2008-10-07 15:37 --------- d-----w C:\Program Files\Microsoft Works
2008-10-01 17:01 90,112 ----a-w C:\WINDOWS\DUMP4788.tmp
2008-10-01 16:59 90,112 ----a-w C:\WINDOWS\DUMP440d.tmp
2008-09-29 16:15 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-09-10 13:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-09-09 22:04 38,528 ----a-w C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-09 22:03 17,200 ----a-w C:\WINDOWS\system32\drivers\mbam.sys
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\cdm.dll
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\SYSTEM32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\SYSTEM32\wuauclt.exe
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\SYSTEM32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\SYSTEM32\wups.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\SYSTEM32\wuapi.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\SYSTEM32\wucltui.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\SYSTEM32\wuweb.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\SYSTEM32\wuaueng.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\SYSTEM32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\SYSTEM32\muweb.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" [2004-04-11 290816]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-04-11 53248]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-03-15 122933]
"UpdateManager"="C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" [2003-08-19 110592]
"LVCOMS"="C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE" [2002-12-10 127022]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-03-31 77824]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" [2005-06-23 57344]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-19 155648]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-13 15360]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2006-03-11 113664]
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
LedWallpaper.lnk - C:\Program Files\LED\LedWallpaper\LedWallpaper.exe [2007-11-04 372736]
Windows Desktop Search.lnk - C:\Program Files\Windows Desktop Search\WindowsSearch.exe [2007-02-05 118784]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.SP53"= SP5X_32.DLL
"VIDC.SP54"= SP5X_32.DLL
"VIDC.SP55"= SP5X_32.DLL
"VIDC.SP56"= SP5X_32.DLL
"VIDC.SP57"= SP5X_32.DLL
"VIDC.SP58"= SP5X_32.DLL
"VIDC.SP59"= SP5X_32.DLL
"msacm.l3acm"= l3codecp.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\SYSTEM32\\rtcshare.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
*Newly Created Service* - A2FREE
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-Sonic RecordNow! - (no file)
HKCU-Run-WebCamRT.exe - (no file)
HKU-Default-Run-ALUAlert - C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe
.
------- Examen supplémentaire -------
.
FireFox -: Profile - C:\Documents and Settings\moi\Application Data\Mozilla\Firefox\Profiles\92jyhs88.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.jag-en-ligne.com/
FF -: plugin - C:\Documents and Settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\DivX\DivX Content Uploader\npUpload.dll
FF -: plugin - C:\Program Files\Veoh Networks\Veoh\Plugins\noreg\NPVeohVersion.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-09 20:11:38
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
C:\DOCUME~1\moi\LOCALS~1\Temp\RGI10.tmp
Scan terminé avec succès
Fichiers cachés: 1
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\RXHUOFPE]
"ImagePath"="\??\C:\WINDOWS\system32\rxhuofpe.gee"
.
Heure de fin: 2008-10-09 20:13:11
ComboFix-quarantined-files.txt 2008-10-09 18:13:08
Avant-CF: 92,183,429,120 octets libres
Après-CF: 92,205,457,408 octets libres
163 --- E O F --- 2008-10-06 16:10:28