Voici le rapport généré par ComboFix :
ComboFix 08-07-09.5 - Tof' 2008-07-10 20:53:22.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.637 [GMT 2:00]
Endroit: C:\Documents and Settings\Administrateur\Bureau\Combo-Fix.exe
* Création d'un nouveau point de restauration
[color=red]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/color]
.
ADS - svchost.exe: deleted 68 bytes in 1 streams.
ADS - ntoskrnl.exe: deleted 68 bytes in 1 streams.
ADS - explorer.exe: deleted 100 bytes in 1 streams.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\drivers\downld
C:\WINDOWS\system32\drivers\downld\1085718.exe
C:\WINDOWS\system32\drivers\downld\1095921.exe
C:\WINDOWS\system32\drivers\downld\1161515.exe
C:\WINDOWS\system32\drivers\downld\1188546.exe
C:\WINDOWS\system32\drivers\downld\1199312.exe
C:\WINDOWS\system32\drivers\downld\1377609.exe
C:\WINDOWS\system32\drivers\downld\1379859.exe
C:\WINDOWS\system32\drivers\downld\15487734.exe
C:\WINDOWS\system32\drivers\downld\15506015.exe
C:\WINDOWS\system32\drivers\downld\15683234.exe
C:\WINDOWS\system32\drivers\downld\15713015.exe
C:\WINDOWS\system32\drivers\downld\15723968.exe
C:\WINDOWS\system32\drivers\downld\44815609.exe
C:\WINDOWS\system32\drivers\downld\44837046.exe
C:\WINDOWS\system32\drivers\downld\45028000.exe
C:\WINDOWS\system32\drivers\downld\45089546.exe
C:\WINDOWS\system32\drivers\downld\45102921.exe
C:\WINDOWS\system32\drivers\downld\665640.exe
C:\WINDOWS\system32\drivers\downld\687406.exe
C:\WINDOWS\system32\drivers\downld\787671.exe
C:\WINDOWS\system32\drivers\downld\807656.exe
C:\WINDOWS\system32\drivers\downld\871968.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2008-06-10 to 2008-07-10 ))))))))))))))))))))))))))))))))))))
.
2008-07-10 08:07 . 2008-07-10 08:07 <REP> d-------- C:\Program Files\CCleaner
2008-07-09 08:12 . 2008-07-09 08:12 <REP> d-------- C:\Deckard
2008-07-09 07:22 . 2008-07-09 07:22 <REP> d-------- C:\Program Files\Panda Security
2008-07-09 07:22 . 2008-06-19 17:24 28,544 --a------ C:\WINDOWS\system32\drivers\pavboot.sys
2008-07-08 23:53 . 2008-07-09 20:35 <REP> d-------- C:\WINDOWS\BDOSCAN8
2008-07-08 23:12 . 2008-07-08 23:12 <REP> d-------- C:\Program Files\Analyse-it
2008-07-08 22:13 . 2008-07-08 22:13 <REP> d-------- C:\WINDOWS\report
2008-07-08 22:13 . 2008-07-08 22:06 25,124,249 --a------ C:\WINDOWS\LPT$VPN.393
2008-07-08 22:06 . 2008-07-08 22:06 <REP> d-------- C:\WINDOWS\AU_Backup
2008-07-08 22:06 . 2008-07-08 22:06 25,124,249 --a------ C:\WINDOWS\VPTNFILE.393
2008-07-08 22:06 . 2008-07-08 22:06 1,960,861 --a------ C:\WINDOWS\tsc.ptn
2008-07-08 22:06 . 2008-07-08 22:06 1,213,784 --a------ C:\WINDOWS\vsapi32.dll
2008-07-08 22:06 . 2008-07-08 22:06 333,576 --a------ C:\WINDOWS\TSC.exe
2008-07-08 22:06 . 2008-07-08 22:06 91,744 --a------ C:\WINDOWS\BPMNT.dll
2008-07-08 22:06 . 2008-07-08 22:06 71,749 --a------ C:\WINDOWS\hcextoutput.dll
2008-07-08 22:06 . 2008-07-08 23:47 823 --a------ C:\WINDOWS\tsc.ini
2008-07-08 22:01 . 2008-07-08 22:06 <REP> d-------- C:\WINDOWS\AU_Temp
2008-07-08 22:01 . 2008-07-08 22:01 <REP> d-------- C:\WINDOWS\AU_Log
2008-07-08 22:01 . 2008-07-08 22:01 507,904 --a------ C:\WINDOWS\TMUPDATE.DLL
2008-07-08 22:01 . 2008-07-08 22:01 286,720 --a------ C:\WINDOWS\PATCH.EXE
2008-07-08 22:01 . 2008-07-08 22:01 69,689 --a------ C:\WINDOWS\UNZIP.DLL
2008-07-08 22:01 . 2008-07-08 22:01 170 --a------ C:\WINDOWS\GetServer.ini
2008-07-01 21:00 . 2008-07-01 23:50 43,520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
2008-07-01 20:59 . 2001-06-14 10:30 1,044,480 --a------ C:\WINDOWS\system32\ROBOEX32.DLL
2008-07-01 20:59 . 1996-11-08 02:48 368,912 --a------ C:\WINDOWS\system32\vbar332.dll
2008-07-01 20:59 . 2004-02-04 14:16 163,840 --a------ C:\WINDOWS\system32\egusound.ocx
2008-07-01 20:59 . 1999-03-13 00:00 127,488 --a------ C:\WINDOWS\system32\Ccrpsld.ocx
2008-07-01 20:59 . 2004-05-12 09:31 49,152 --a------ C:\WINDOWS\system32\Inetwh32.dll
2008-07-01 19:16 . 2008-07-01 20:36 34,134 --a------ C:\WINDOWS\Run32A40.mch
2008-07-01 19:15 . 2008-07-01 20:36 <REP> d-------- C:\WINDOWS\A4W_DATA
2008-07-01 19:15 . 2008-07-01 19:30 35 --a------ C:\WINDOWS\A4W.INI
2008-07-01 19:14 . 2008-07-01 19:35 <REP> d-------- C:\SUPER
2008-07-01 19:14 . 2008-07-01 19:14 <REP> d-------- C:\Documents and Settings\Administrateur\WINDOWS
2008-07-01 19:14 . 1998-10-29 16:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-06-21 13:25 . 2008-06-21 13:25 <REP> d-------- C:\Program Files\FLV Player
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-08 21:50 --------- d-----w C:\Program Files\Ecolo-info
2008-07-04 18:31 --------- d-----w C:\Program Files\Mozilla Thunderbird
2008-07-01 21:53 --------- d-----w C:\Program Files\Digital Picture Recovery
2008-06-23 14:04 120 ----a-w C:\drmHeader.bin
2008-05-26 19:23 --------- d-----w C:\Program Files\Object Rescue
2008-05-25 21:01 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Thunderbird
2008-05-25 20:01 --------- d-----w C:\Program Files\Java
2008-05-25 19:58 --------- d-----w C:\Program Files\Fichiers communs\Java
2008-05-25 19:57 --------- d-----w C:\Program Files\iPod
2008-05-25 19:55 --------- d-----w C:\Program Files\QuickTime
2008-05-25 19:55 --------- d-----w C:\Program Files\Bonjour
2008-05-25 19:50 --------- d-----w C:\Program Files\Apple Software Update
2008-05-14 17:54 --------- d-----w C:\Program Files\Avast4
2004-03-15 15:51 114,688 ----a-w C:\Program Files\internet explorer\plugins\LV71ActiveXControl.dll
2006-01-23 08:32 131,072 ----a-w C:\Program Files\internet explorer\plugins\LV80ActiveXControl.dll
2007-02-08 08:48 133,920 ----a-w C:\Program Files\internet explorer\plugins\LV82ActiveXControl.dll
2007-07-24 17:03 118,784 ----a-w C:\Program Files\internet explorer\plugins\LV85ActiveXControl.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8b7625de-675d-4627-9ebe-bd02b7d0a89a}]
2008-07-08 23:50 1569304 --a------ C:\Program Files\Ecolo-info\tbEco0.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{8b7625de-675d-4627-9ebe-bd02b7d0a89a}"= "C:\Program Files\Ecolo-info\tbEco0.dll" [2008-07-08 23:50 1569304]
[HKEY_CLASSES_ROOT\clsid\{8b7625de-675d-4627-9ebe-bd02b7d0a89a}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{8B7625DE-675D-4627-9EBE-BD02B7D0A89A}"= "C:\Program Files\Ecolo-info\tbEco0.dll" [2008-07-08 23:50 1569304]
[HKEY_CLASSES_ROOT\clsid\{8b7625de-675d-4627-9ebe-bd02b7d0a89a}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 17:09 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avast!"="C:\PROGRA~1\Avast4\ashDisp.exe" [2008-05-12 18:39 79224]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-01-26 00:22 185896]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="D:\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe" [2008-03-25 04:28 144784]
"Logitech Utility"="Logi_MwX.Exe" [2002-11-08 11:50 19968 C:\WINDOWS\LOGI_MWX.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 17:09 15360]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26 29696]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wd.sys]
@="Driver"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Belkin 802.11g Wireless PCI Card Configuration Utility.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Belkin 802.11g Wireless PCI Card Configuration Utility.lnk
backup=C:\WINDOWS\pss\Belkin 802.11g Wireless PCI Card Configuration Utility.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\Freeplayer\\vlc\\vlc.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"D:\\Emule\\eMule0.47c\\emule.exe"=
"C:\\Program Files\\Neoteris\\Secure Application Manager\\dsSamProxy.exe"=
"D:\\Real One Player\\realplay.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"D:\\iTunes\\iTunes.exe"=
R0 NIPALK;NIPALK;C:\WINDOWS\system32\drivers\nipalk.sys [2007-07-18 21:11]
R0 nipbcfk;National Instruments Class Upper Filter Driver;C:\WINDOWS\system32\drivers\nipbcfk.sys [2007-07-10 20:08]
R0 pavboot;pavboot;C:\WINDOWS\system32\drivers\pavboot.sys [2008-06-19 17:24]
R0 si3112r;Silicon Image SiI 3112 SATARaid Controller;C:\WINDOWS\system32\drivers\si3112r.sys [2003-05-30 11:05]
R0 SiWinAcc;SiWinAcc;C:\WINDOWS\system32\drivers\SiWinAcc.sys [2003-02-12 07:37]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-12 18:36]
R1 NEOFLTR_510_9029;Juniper Networks TDI Filter Driver (NEOFLTR_510_9029);C:\WINDOWS\system32\Drivers\NEOFLTR_510_9029.SYS [2005-08-17 03:51]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-12 18:38]
R2 cvintdrv;cvintdrv;C:\WINDOWS\system32\drivers\cvintdrv.sys [2007-08-02 10:00]
R2 mxssvr;NI Configuration Manager;D:\Labview\MAX\nimxs.exe [2007-03-08 17:29]
R2 NITaggerService;National Instruments Variable Engine;D:\Labview\Shared\Tagger\tagsrv.exe [2007-07-23 09:29]
R2 NiViPxiK;NI-VISA PXI Driver;C:\WINDOWS\system32\drivers\NiViPxiKl.sys [2007-07-19 11:56]
R3 st3tgbus;st3tgbus;C:\WINDOWS\system32\DRIVERS\st3tgbus.sys [2003-03-12 20:37]
R3 st3tiger;st3tiger;C:\WINDOWS\system32\DRIVERS\st3tiger.sys [2003-03-12 20:38]
S3 adxapie;adxapie;C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\adxapie.sys []
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;C:\PROGRA~1\Belkin\BELKIN~1.11G\DNINDIS5.SYS [2003-07-24 13:10]
S3 nidimk;nidimk;C:\WINDOWS\system32\drivers\nidimkl.sys [2007-07-12 18:18]
S3 niorbk;niorbk;C:\WINDOWS\system32\drivers\niorbkl.sys [2007-07-12 17:31]
S3 nipalfwedl;nipalfwedl;C:\WINDOWS\system32\drivers\nipalfwedl.sys [2007-07-18 21:11]
S3 nipalusbedl;nipalusbedl;C:\WINDOWS\system32\drivers\nipalusbedl.sys [2007-07-18 21:12]
S3 NiViFWK;NI-VISA FireWire Driver;C:\WINDOWS\system32\drivers\NiViFWKl.sys [2007-07-19 11:48]
S3 NiViPciK;NI-VISA PCI Driver;C:\WINDOWS\system32\drivers\NiViPciKl.sys [2007-07-19 11:56]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9081ba5e-0406-11dd-810f-806d6172696f}]
\Shell\AutoRun\command - K:\nideiect.com
\Shell\explore\Command - K:\nideiect.com
\Shell\open\Command - K:\nideiect.com
*Newly Created Service* - CATCHME
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-05-25 19:51:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-zBrowser Launcher - C:\Program Files\Logitech\iTouch\iTouch.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-10 20:54:39
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs a chargé sous des processus courants ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\Ati2evxx.dll
.
Temps d'accomplissement: 2008-07-10 20:55:38
ComboFix-quarantined-files.txt 2008-07-10 18:55:17
Pre-Run: 861,016,064 octets libres
Post-Run: 990,597,120 octets libres
196