Précédent
- 1
- 2
Salut, en attendant j'ai passé Combofix et depuis cela semble ok . Il a trouvé les fameuses dll et les a supprimé. Il semble rester des traces dans les registres. Qu'en penses-tu ? et encore merci pour ton aide. En fonction de ta réponse je passerai le sujet en résolu.
ComboFix 07-11-19.4 - valou 2007-11-26 22:58:21.1 - [color=red][b]FAT32[/b][/color]x86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.184 [GMT 1:00]
Running from: C:\Documents and Settings\valou\Bureau\ComboFix.exe
* Created a new restore point
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Menu Démarrer\Live Safety Center.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Online Security Guide.lnk
C:\Documents and Settings\valou\Bureau\Live Safety Center.lnk
C:\Documents and Settings\valou\Bureau\Online Security Guide.lnk
C:\Documents and Settings\valou\Favoris\Online Security Guide.lnk
C:\Documents and Settings\valou\Menu Démarrer\Programmes\InternetGameBox
C:\Documents and Settings\valou\Menu Démarrer\Programmes\InternetGameBox\InternetGameBox.lnk
C:\Documents and Settings\valou\Menu Démarrer\Programmes\InternetGameBox\Uninstall.lnk
C:\Documents and Settings\valou\Menu Démarrer\Programmes\InternetGameBox\Website.lnk
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\ststv.ini
C:\WINDOWS\system32\ststv.ini2
C:\WINDOWS\system32\vtsts.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\DomainService
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-10-26 to 2007-11-26 ))))))))))))))))))))))))))))))))))))
.
2007-11-26 17:41 <REP> d-------- C:\Program Files\Avira
2007-11-26 15:31 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2007-11-25 11:39 775,832 ---hs---- C:\WINDOWS\system32\motlclen.ini
2007-11-25 10:41 775,892 ---hs---- C:\WINDOWS\system32\juyvgicj.ini
2007-11-24 14:03 <REP> d-------- C:\Program Files\Fichiers communs\PCSuite
2007-11-24 14:03 <REP> d-------- C:\Program Files\Fichiers communs\Nokia
2007-11-24 14:03 <REP> d-------- C:\Program Files\DIFX
2007-11-24 14:03 <REP> d-------- C:\Documents and Settings\valou\Application Data\Nokia
2007-11-24 14:02 <REP> d-------- C:\Program Files\PC Connectivity Solution
2007-11-24 14:02 <REP> d-------- C:\Program Files\Nokia2
2007-11-24 14:02 <REP> d-------- C:\Documents and Settings\valou\Application Data\PC Suite
2007-11-24 14:02 137,216 --a------ C:\WINDOWS\system32\drivers\nmwcd.sys
2007-11-24 14:02 65,536 --a------ C:\WINDOWS\system32\nmwcdcocls.dll
2007-11-24 14:02 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcm.sys
2007-11-24 14:02 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcj.sys
2007-11-24 14:02 8,320 --a------ C:\WINDOWS\system32\drivers\nmwcdc.sys
2007-11-24 08:16 775,832 ---hs---- C:\WINDOWS\system32\okfkwsvn.ini
2007-11-23 20:47 <REP> d-------- C:\Program Files\Convertisseur Pro HTML vers RTF
2007-11-22 23:18 738,306 ---hs---- C:\WINDOWS\system32\tlckufwh.ini
2007-11-22 23:16 6,575,800 --a------ C:\Temp\sunbelt-personal-firewall-ex-kerio_sunbelt_personal_firewall_4.3.916_francais_11071.exe
2007-11-22 23:13 17,788,920 --a------ C:\Temp\antivir-personal-edition-7_antivir_personal_edition_classic_7_7.06.00.270_anglais_10821.exe
2007-11-21 23:21 <REP> d-------- C:\sauvegarde jo
2007-11-21 20:02 <REP> d-------- C:\WINDOWS\BDOSCAN8
2007-11-21 14:39 <REP> d-------- C:\Documents and Settings\valou\Application Data\Grisoft
2007-11-21 14:39 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-21 12:18 <REP> d-------- C:\Program Files\CCleaner
2007-11-21 10:33 <REP> d-------- C:\Program Files\Trend Micro
2007-11-19 23:01 689,472 ---hs---- C:\WINDOWS\system32\gknytkda.ini
2007-11-19 19:10 <REP> dr------- C:\Documents and Settings\LocalService\Favoris
2007-11-19 19:08 427,520 --a------ C:\WINDOWS\WRServices.dll
2007-11-19 10:00 11,133 --a------ C:\Documents and Settings\valou\z.dat
2007-11-19 10:00 3,280 --a------ C:\Documents and Settings\valou\x.dat
2007-11-18 10:23 <REP> d-------- C:\Documents and Settings\valou\Application Data\AVS4YOU
2007-11-18 10:11 <REP> d-------- C:\Program Files\AVS4YOU
2007-11-17 22:26 <REP> d-------- C:\WINDOWS\AU_Temp
2007-11-17 21:39 <REP> d--hs---- C:\FOUND.015
2007-11-17 19:01 120 --a------ C:\n.bat
2007-11-17 19:00 0 --a------ C:\z.dat
2007-11-17 19:00 0 --a------ C:\x.dat
2007-11-17 18:59 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2007-11-17 17:25 <REP> d-------- C:\Program Files\MPEGTOAVI
2007-11-17 16:55 <REP> d-------- C:\Program Files\plugins
2007-11-17 16:55 <REP> d-------- C:\Program Files\aviproxy
2007-11-17 07:57 <REP> d-------- C:\Documents and Settings\valou\Application Data\AVSMedia
2007-11-17 07:55 <REP> d-------- C:\Program Files\Fichiers communs\AVSMedia
2007-11-17 07:55 <REP> d-------- C:\Program Files\AVSMedia
2007-11-17 07:55 53,248 --a------ C:\WINDOWS\system32\xvid.ax
2007-11-17 07:55 24,576 --a------ C:\WINDOWS\system32\msxml3a.dll
2007-11-16 23:26 313,344 --a------ C:\Program Files\hjsplit.exe
2007-11-16 23:02 <REP> d-------- C:\Program Files\DVDStyler
2007-11-16 19:39 <REP> d-------- C:\savcam
2007-11-15 22:57 <REP> d-------- C:\Program Files\Ontrack
2007-11-13 09:36 <REP> d-------- C:\sauvegarde cle du 13nov2007
2007-11-06 13:15 84,544 -ra------ C:\WINDOWS\system32\drivers\v800mdm.sys
2007-11-06 13:15 77,760 -ra------ C:\WINDOWS\system32\drivers\v800mgmt.sys
2007-11-06 13:15 75,584 -ra------ C:\WINDOWS\system32\drivers\v800obex.sys
2007-11-06 13:15 52,416 -ra------ C:\WINDOWS\system32\drivers\v800bus.sys
2007-11-06 13:15 6,160 -ra------ C:\WINDOWS\system32\drivers\v800mdfl.sys
2007-11-06 13:15 6,144 -ra------ C:\WINDOWS\system32\drivers\v800cmnt.sys
2007-11-06 13:15 6,144 -ra------ C:\WINDOWS\system32\drivers\v800cm.sys
2007-11-06 13:15 5,776 -ra------ C:\WINDOWS\system32\drivers\v800whnt.sys
2007-11-06 13:15 5,776 -ra------ C:\WINDOWS\system32\drivers\v800wh.sys
2007-11-06 13:14 <REP> d-------- C:\Documents and Settings\valou\Application Data\Teleca
2007-11-06 13:13 <REP> d-------- C:\Documents and Settings\valou\Application Data\Sony Ericsson
2007-11-06 13:09 <REP> d-------- C:\Program Files\Sony Ericsson
2007-11-06 13:09 <REP> d-------- C:\Program Files\Fichiers communs\Teleca Shared
2007-11-06 13:09 <REP> d-------- C:\Program Files\Fichiers communs\Sony Ericsson Shared
2007-10-30 09:28 <REP> d-------- C:\WINDOWS\system32\DRVSTORE
2007-10-30 09:28 <REP> d-------- C:\Documents and Settings\valou\Contacts
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-21 19:13 22 ----a-w C:\WINDOWS\Fonts\a.zip
2007-10-25 16:56 8,510,976 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-25 09:26 53,248 ----a-w C:\WINDOWS\bdoscandel.exe
2007-10-21 16:15 --------- d-----w C:\Program Files\MP3 Player Utilities 3.10
2007-10-21 15:43 292 ----a-w C:\mediamp3.dat
2007-10-21 15:41 --------- d-----w C:\Program Files\MP3 Player Utilities 4.17
2007-09-05 22:22 289,144 ----a-w C:\WINDOWS\system32\VCCLSID.exe
2007-07-08 13:36 1,806,232 ----a-w C:\Documents and Settings\All Users\daemon4091-x86.exe
2007-02-15 17:25 77,448 ----a-w C:\Documents and Settings\valou\Application Data\GDIPFONTCACHEV1.DAT
2006-12-13 09:55 4,115,866 ----a-w C:\Documents and Settings\All Users\DVDx_2_5_1_setup.zip
2006-12-13 09:17 697,743 ----a-w C:\Documents and Settings\All Users\InstAviSplitC.zip
2006-12-09 20:33 8,907,760 ----a-w C:\Documents and Settings\All Users\VOB2AVI-v1.00.exe
2006-11-19 08:51 70,487 ----a-w C:\Documents and Settings\All Users\KillBox.zip
2006-11-19 08:47 613,944 ----a-w C:\Documents and Settings\All Users\blbetac.exe
2006-02-08 02:02 73,728 ----a-w C:\Documents and Settings\All Users\KillBox.exe
2004-08-09 22:30 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{99B1C4B0-0057-49A9-B798-A81576B7FEB0}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-05 05:00 C:\WINDOWS\system32\rundll32.exe]
"MediaSync"="C:\Program Files\Acer\Acer eConsole\MediaSync.exe" [2005-06-01 14:25]
"LaunchApp"="Alaunch" []
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2007-11-26 17:43]
"AspireService"="C:\Program Files\Acer\Acer eMode Management\AspireService.exe" [2005-06-04 12:40]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 09:06 C:\WINDOWS\AGRSMMSG.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 05:00]
"Nokia.PCSync"="C:\Program Files\Nokia2\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 10:17]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\vtsts.dll
R0 ElbyVCD;ElbyVCD;C:\WINDOWS\system32\DRIVERS\ElbyVCD.sys
R1 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys
S3 P1120VID;Creative WebCam NX Ultra;C:\WINDOWS\system32\DRIVERS\P1120Vid.sys
S3 v800bus;Sony Ericsson V800-Vodafone 802SE driver (WDM);C:\WINDOWS\system32\DRIVERS\v800bus.sys
S3 v800mdfl;Sony Ericsson V800-Vodafone 802SE USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\v800mdfl.sys
S3 v800mdm;Sony Ericsson V800-Vodafone 802SE USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\v800mdm.sys
S3 v800mgmt;Sony Ericsson V800-Vodafone 802SE USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\v800mgmt.sys
S3 v800obex;Sony Ericsson V800-Vodafone 802SE USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\v800obex.sys
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2007-11-26 19:00:02 C:\WINDOWS\Tasks\HPpromotions photosmart 2600 series.job"
- C:\Program Files\HP\Digital Imaging\bin\HP Promotions\AiOMVC\HPpromo.exe
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-26 23:02:55
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-26 23:03:53 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-18 08:25
C:\ComboFix2.txt ... 2007-07-18 08:25
.
--- E O F ---
ComboFix 07-11-19.4 - valou 2007-11-26 22:58:21.1 - [color=red][b]FAT32[/b][/color]x86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.184 [GMT 1:00]
Running from: C:\Documents and Settings\valou\Bureau\ComboFix.exe
* Created a new restore point
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Menu Démarrer\Live Safety Center.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Online Security Guide.lnk
C:\Documents and Settings\valou\Bureau\Live Safety Center.lnk
C:\Documents and Settings\valou\Bureau\Online Security Guide.lnk
C:\Documents and Settings\valou\Favoris\Online Security Guide.lnk
C:\Documents and Settings\valou\Menu Démarrer\Programmes\InternetGameBox
C:\Documents and Settings\valou\Menu Démarrer\Programmes\InternetGameBox\InternetGameBox.lnk
C:\Documents and Settings\valou\Menu Démarrer\Programmes\InternetGameBox\Uninstall.lnk
C:\Documents and Settings\valou\Menu Démarrer\Programmes\InternetGameBox\Website.lnk
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\ststv.ini
C:\WINDOWS\system32\ststv.ini2
C:\WINDOWS\system32\vtsts.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\DomainService
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-10-26 to 2007-11-26 ))))))))))))))))))))))))))))))))))))
.
2007-11-26 17:41 <REP> d-------- C:\Program Files\Avira
2007-11-26 15:31 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2007-11-25 11:39 775,832 ---hs---- C:\WINDOWS\system32\motlclen.ini
2007-11-25 10:41 775,892 ---hs---- C:\WINDOWS\system32\juyvgicj.ini
2007-11-24 14:03 <REP> d-------- C:\Program Files\Fichiers communs\PCSuite
2007-11-24 14:03 <REP> d-------- C:\Program Files\Fichiers communs\Nokia
2007-11-24 14:03 <REP> d-------- C:\Program Files\DIFX
2007-11-24 14:03 <REP> d-------- C:\Documents and Settings\valou\Application Data\Nokia
2007-11-24 14:02 <REP> d-------- C:\Program Files\PC Connectivity Solution
2007-11-24 14:02 <REP> d-------- C:\Program Files\Nokia2
2007-11-24 14:02 <REP> d-------- C:\Documents and Settings\valou\Application Data\PC Suite
2007-11-24 14:02 137,216 --a------ C:\WINDOWS\system32\drivers\nmwcd.sys
2007-11-24 14:02 65,536 --a------ C:\WINDOWS\system32\nmwcdcocls.dll
2007-11-24 14:02 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcm.sys
2007-11-24 14:02 12,288 --a------ C:\WINDOWS\system32\drivers\nmwcdcj.sys
2007-11-24 14:02 8,320 --a------ C:\WINDOWS\system32\drivers\nmwcdc.sys
2007-11-24 08:16 775,832 ---hs---- C:\WINDOWS\system32\okfkwsvn.ini
2007-11-23 20:47 <REP> d-------- C:\Program Files\Convertisseur Pro HTML vers RTF
2007-11-22 23:18 738,306 ---hs---- C:\WINDOWS\system32\tlckufwh.ini
2007-11-22 23:16 6,575,800 --a------ C:\Temp\sunbelt-personal-firewall-ex-kerio_sunbelt_personal_firewall_4.3.916_francais_11071.exe
2007-11-22 23:13 17,788,920 --a------ C:\Temp\antivir-personal-edition-7_antivir_personal_edition_classic_7_7.06.00.270_anglais_10821.exe
2007-11-21 23:21 <REP> d-------- C:\sauvegarde jo
2007-11-21 20:02 <REP> d-------- C:\WINDOWS\BDOSCAN8
2007-11-21 14:39 <REP> d-------- C:\Documents and Settings\valou\Application Data\Grisoft
2007-11-21 14:39 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-21 12:18 <REP> d-------- C:\Program Files\CCleaner
2007-11-21 10:33 <REP> d-------- C:\Program Files\Trend Micro
2007-11-19 23:01 689,472 ---hs---- C:\WINDOWS\system32\gknytkda.ini
2007-11-19 19:10 <REP> dr------- C:\Documents and Settings\LocalService\Favoris
2007-11-19 19:08 427,520 --a------ C:\WINDOWS\WRServices.dll
2007-11-19 10:00 11,133 --a------ C:\Documents and Settings\valou\z.dat
2007-11-19 10:00 3,280 --a------ C:\Documents and Settings\valou\x.dat
2007-11-18 10:23 <REP> d-------- C:\Documents and Settings\valou\Application Data\AVS4YOU
2007-11-18 10:11 <REP> d-------- C:\Program Files\AVS4YOU
2007-11-17 22:26 <REP> d-------- C:\WINDOWS\AU_Temp
2007-11-17 21:39 <REP> d--hs---- C:\FOUND.015
2007-11-17 19:01 120 --a------ C:\n.bat
2007-11-17 19:00 0 --a------ C:\z.dat
2007-11-17 19:00 0 --a------ C:\x.dat
2007-11-17 18:59 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2007-11-17 17:25 <REP> d-------- C:\Program Files\MPEGTOAVI
2007-11-17 16:55 <REP> d-------- C:\Program Files\plugins
2007-11-17 16:55 <REP> d-------- C:\Program Files\aviproxy
2007-11-17 07:57 <REP> d-------- C:\Documents and Settings\valou\Application Data\AVSMedia
2007-11-17 07:55 <REP> d-------- C:\Program Files\Fichiers communs\AVSMedia
2007-11-17 07:55 <REP> d-------- C:\Program Files\AVSMedia
2007-11-17 07:55 53,248 --a------ C:\WINDOWS\system32\xvid.ax
2007-11-17 07:55 24,576 --a------ C:\WINDOWS\system32\msxml3a.dll
2007-11-16 23:26 313,344 --a------ C:\Program Files\hjsplit.exe
2007-11-16 23:02 <REP> d-------- C:\Program Files\DVDStyler
2007-11-16 19:39 <REP> d-------- C:\savcam
2007-11-15 22:57 <REP> d-------- C:\Program Files\Ontrack
2007-11-13 09:36 <REP> d-------- C:\sauvegarde cle du 13nov2007
2007-11-06 13:15 84,544 -ra------ C:\WINDOWS\system32\drivers\v800mdm.sys
2007-11-06 13:15 77,760 -ra------ C:\WINDOWS\system32\drivers\v800mgmt.sys
2007-11-06 13:15 75,584 -ra------ C:\WINDOWS\system32\drivers\v800obex.sys
2007-11-06 13:15 52,416 -ra------ C:\WINDOWS\system32\drivers\v800bus.sys
2007-11-06 13:15 6,160 -ra------ C:\WINDOWS\system32\drivers\v800mdfl.sys
2007-11-06 13:15 6,144 -ra------ C:\WINDOWS\system32\drivers\v800cmnt.sys
2007-11-06 13:15 6,144 -ra------ C:\WINDOWS\system32\drivers\v800cm.sys
2007-11-06 13:15 5,776 -ra------ C:\WINDOWS\system32\drivers\v800whnt.sys
2007-11-06 13:15 5,776 -ra------ C:\WINDOWS\system32\drivers\v800wh.sys
2007-11-06 13:14 <REP> d-------- C:\Documents and Settings\valou\Application Data\Teleca
2007-11-06 13:13 <REP> d-------- C:\Documents and Settings\valou\Application Data\Sony Ericsson
2007-11-06 13:09 <REP> d-------- C:\Program Files\Sony Ericsson
2007-11-06 13:09 <REP> d-------- C:\Program Files\Fichiers communs\Teleca Shared
2007-11-06 13:09 <REP> d-------- C:\Program Files\Fichiers communs\Sony Ericsson Shared
2007-10-30 09:28 <REP> d-------- C:\WINDOWS\system32\DRVSTORE
2007-10-30 09:28 <REP> d-------- C:\Documents and Settings\valou\Contacts
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-21 19:13 22 ----a-w C:\WINDOWS\Fonts\a.zip
2007-10-25 16:56 8,510,976 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-10-25 09:26 53,248 ----a-w C:\WINDOWS\bdoscandel.exe
2007-10-21 16:15 --------- d-----w C:\Program Files\MP3 Player Utilities 3.10
2007-10-21 15:43 292 ----a-w C:\mediamp3.dat
2007-10-21 15:41 --------- d-----w C:\Program Files\MP3 Player Utilities 4.17
2007-09-05 22:22 289,144 ----a-w C:\WINDOWS\system32\VCCLSID.exe
2007-07-08 13:36 1,806,232 ----a-w C:\Documents and Settings\All Users\daemon4091-x86.exe
2007-02-15 17:25 77,448 ----a-w C:\Documents and Settings\valou\Application Data\GDIPFONTCACHEV1.DAT
2006-12-13 09:55 4,115,866 ----a-w C:\Documents and Settings\All Users\DVDx_2_5_1_setup.zip
2006-12-13 09:17 697,743 ----a-w C:\Documents and Settings\All Users\InstAviSplitC.zip
2006-12-09 20:33 8,907,760 ----a-w C:\Documents and Settings\All Users\VOB2AVI-v1.00.exe
2006-11-19 08:51 70,487 ----a-w C:\Documents and Settings\All Users\KillBox.zip
2006-11-19 08:47 613,944 ----a-w C:\Documents and Settings\All Users\blbetac.exe
2006-02-08 02:02 73,728 ----a-w C:\Documents and Settings\All Users\KillBox.exe
2004-08-09 22:30 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{99B1C4B0-0057-49A9-B798-A81576B7FEB0}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-05 05:00 C:\WINDOWS\system32\rundll32.exe]
"MediaSync"="C:\Program Files\Acer\Acer eConsole\MediaSync.exe" [2005-06-01 14:25]
"LaunchApp"="Alaunch" []
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2007-11-26 17:43]
"AspireService"="C:\Program Files\Acer\Acer eMode Management\AspireService.exe" [2005-06-04 12:40]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 09:06 C:\WINDOWS\AGRSMMSG.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 05:00]
"Nokia.PCSync"="C:\Program Files\Nokia2\Nokia PC Suite 6\PcSync2.exe" [2007-06-19 10:17]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\system32\vtsts.dll
R0 ElbyVCD;ElbyVCD;C:\WINDOWS\system32\DRIVERS\ElbyVCD.sys
R1 UBHelper;UBHelper;C:\WINDOWS\system32\drivers\UBHelper.sys
S3 P1120VID;Creative WebCam NX Ultra;C:\WINDOWS\system32\DRIVERS\P1120Vid.sys
S3 v800bus;Sony Ericsson V800-Vodafone 802SE driver (WDM);C:\WINDOWS\system32\DRIVERS\v800bus.sys
S3 v800mdfl;Sony Ericsson V800-Vodafone 802SE USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\v800mdfl.sys
S3 v800mdm;Sony Ericsson V800-Vodafone 802SE USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\v800mdm.sys
S3 v800mgmt;Sony Ericsson V800-Vodafone 802SE USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\v800mgmt.sys
S3 v800obex;Sony Ericsson V800-Vodafone 802SE USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\v800obex.sys
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2007-11-26 19:00:02 C:\WINDOWS\Tasks\HPpromotions photosmart 2600 series.job"
- C:\Program Files\HP\Digital Imaging\bin\HP Promotions\AiOMVC\HPpromo.exe
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-26 23:02:55
Windows 5.1.2600 Service Pack 2 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-26 23:03:53 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-07-18 08:25
C:\ComboFix2.txt ... 2007-07-18 08:25
.
--- E O F ---
Précédent
- 1
- 2