bonsoir
voila le rapport de combofix
ComboFix 07-12-12.3 - reg mus 2007-12-13 20:33:57.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.119 [GMT 0:00]
Running from: C:\Documents and Settings\reg mus\Bureau\ComboFix.exe
* Created a new restore point
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\svchost.ini
C:\WINDOWS\system32\awvvt.dll
C:\WINDOWS\system32\jxtqdopo.ini2
C:\WINDOWS\system32\jxtqdopo.tmp
C:\WINDOWS\system32\tvvwa.bak2
C:\WINDOWS\system32\tvvwa.ini
C:\WINDOWS\system32\tvvwa.ini2
C:\WINDOWS\system32\tvvwa.tmp
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-11-13 to 2007-12-13 ))))))))))))))))))))))))))))))))))))
.
2007-12-13 12:26 . 2007-12-13 12:26 <REP> d-------- C:\VundoFix Backups
2007-12-11 22:55 . 2007-12-11 22:55 <REP> d-------- C:\Program Files\Trend Micro
2007-12-11 21:53 . 2007-12-11 21:53 <REP> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2007-12-11 21:52 . 2007-12-12 23:22 <REP> d-------- C:\Program Files\SUPERAntiSpyware
2007-12-11 21:52 . 2007-12-11 21:52 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2007-12-11 21:52 . 2007-12-11 21:52 <REP> d-------- C:\Documents and Settings\reg mus\Application Data\SUPERAntiSpyware.com
2007-12-11 21:13 . 2007-12-11 21:13 <REP> d-------- C:\Documents and Settings\reg mus\Application Data\Simple Star
2007-12-11 21:09 . 2007-12-11 21:13 <REP> d-------- C:\Documents and Settings\reg mus\Application Data\Nero
2007-12-11 20:55 . 2007-12-11 21:01 <REP> d-------- C:\Program Files\Fichiers communs\Nero
2007-12-11 20:55 . 2007-12-11 20:55 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2007-12-10 22:42 . 2007-12-10 22:47 <REP> d-------- C:\Program Files\WinMPG VideoConvert
2007-12-10 22:42 . 2002-06-08 20:00 466,944 --a------ C:\WINDOWS\system32\iviaudio.ax
2007-12-10 22:08 . 2007-12-10 22:13 <REP> d-------- C:\Program Files\Trackmaker
2007-12-10 22:00 . 2007-12-10 22:07 <REP> d-------- C:\Program Files\TTQV3
2007-12-10 21:56 . 2007-12-10 23:22 <REP> d-------- C:\OziExplorer
2007-12-10 21:34 . 2007-12-10 21:39 <REP> d-------- C:\Program Files\Mapdekode
2007-12-10 21:34 . 2007-12-10 21:34 958,464 --------- C:\WINDOWS\Setup1.exe
2007-12-10 21:34 . 2007-12-10 21:34 73,216 --a------ C:\WINDOWS\ST6UNST.EXE
2007-12-10 21:03 . 2007-12-10 21:03 <REP> d-------- C:\Program Files\Fichiers communs\SWF Studio
2007-12-10 20:57 . 2007-12-10 20:57 <REP> d-------- C:\Documents and Settings\reg mus\Application Data\ACAMPREF
2007-12-10 20:57 . 2001-02-16 13:51 724 --a------ C:\WINDOWS\wacam.ini
2007-12-10 19:11 . 2007-12-10 19:15 2,784 --a------ C:\WINDOWS\NotionDemo.INI
2007-12-10 11:12 . 2007-12-11 20:47 <REP> d-------- C:\Program Files\Ahead
2007-12-10 10:49 . 2007-12-10 10:49 834,100 ---hs---- C:\WINDOWS\system32\felebdco.ini
2007-12-10 10:36 . 2007-12-10 10:39 834,160 ---hs---- C:\WINDOWS\system32\ljvkqeiv.ini
2007-12-10 10:21 . 2007-12-10 10:21 <REP> d-------- C:\Documents and Settings\reg mus\Application Data\Ahead
2007-12-10 10:16 . 2007-12-11 20:55 <REP> d-------- C:\Program Files\Nero
2007-12-10 10:16 . 2007-12-10 11:08 <REP> d-------- C:\Program Files\Fichiers communs\Ahead
2007-12-09 21:17 . 2007-12-09 21:17 <REP> d-------- C:\Program Files\Kontakt Player 2
2007-12-09 11:36 . 2007-12-09 12:53 <REP> d-------- C:\Program Files\RegDoctor
2007-12-09 11:36 . 2000-12-18 23:11 291,328 --a------ C:\WINDOWS\system32\xzipper30.ocx
2007-12-09 11:36 . 2000-11-06 12:02 267,264 --a------ C:\WINDOWS\system32\xunzip30.ocx
2007-12-09 11:36 . 2005-02-12 15:43 245,760 --a------ C:\WINDOWS\system32\vbalColumnTreeView6.ocx
2007-12-09 11:36 . 2004-03-08 18:00 152,848 --a------ C:\WINDOWS\system32\Comdlg32.ocx
2007-12-09 11:36 . 1999-08-02 16:11 57,344 --a------ C:\WINDOWS\system32\CGZipLibrary.DLL
2007-12-09 11:36 . 2003-01-26 13:41 40,960 --a------ C:\WINDOWS\system32\SSubTmr6.dll
2007-12-09 11:36 . 1999-03-12 01:20 18,728 --a------ C:\WINDOWS\system32\ISHF_Ex.tlb
2007-12-09 11:36 . 1998-03-18 16:45 8,096 --a------ C:\WINDOWS\system32\OLEGUIDS.TLB
2007-12-09 10:50 . 2007-12-09 10:50 77 --a------ C:\WINDOWS\system32\nglqgesa.dll
2007-12-09 07:47 . 2007-12-09 07:47 77 --a------ C:\WINDOWS\system32\guygsvyg.dll
2007-12-08 10:14 . 2007-12-08 10:14 143 --a------ C:\WINDOWS\system32\mcrh.tmp
2007-12-08 09:41 . 2007-12-11 20:49 <REP> d-------- C:\Temp
2007-12-08 09:30 . 2007-12-13 19:56 90,980 --a------ C:\WINDOWS\system32\drivers\klin.dat
2007-12-08 09:30 . 2007-12-13 19:56 85,860 --a------ C:\WINDOWS\system32\drivers\klick.dat
2007-12-08 09:29 . 2007-12-13 20:57 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-08 09:29 . 2007-12-13 20:57 20,486,176 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2007-12-08 09:29 . 2007-12-13 20:56 294,188 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2007-12-08 09:29 . 2007-12-13 20:57 273,184 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2007-12-08 09:29 . 2007-12-13 20:56 30,812 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2007-12-08 08:38 . 2007-12-08 10:07 832,251 ---hs---- C:\WINDOWS\system32\ekoeaaco.ini
2007-12-07 19:35 . 2007-12-07 19:35 <REP> d-------- C:\Program Files\ARAR
2007-12-07 19:11 . 2007-12-08 19:58 274 --a------ C:\WINDOWS\qzip.ini
2007-12-07 19:06 . 2007-12-07 19:11 <REP> d-------- C:\Program Files\QuickZip
2007-12-07 18:23 . 2007-12-07 19:13 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WinZip
2007-12-07 17:03 . 2007-12-10 19:35 <REP> d-------- C:\Program Files\WinAce
2007-12-07 13:10 . 2007-12-07 13:10 <REP> d-------- C:\Documents and Settings\reg mus\Application Data\CyberLink
2007-12-07 13:06 . 2007-12-07 13:06 <REP> d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2007-12-07 13:04 . 2007-12-07 13:04 <REP> d-------- C:\Program Files\CyberLink
2007-12-07 12:41 . 2007-12-07 12:41 <REP> d-------- C:\Program Files\Smart Projects
2007-12-07 11:20 . 2007-12-07 11:20 <REP> d-------- C:\Program Files\Fonts
2007-12-07 08:21 . 2007-12-07 08:21 <REP> d-------- C:\Documents and Settings\reg mus\Application Data\GARMIN
2007-12-05 13:55 . 2001-08-17 21:28 794,654 --a--c--- C:\WINDOWS\system32\dllcache\usr1801.sys
2007-12-05 13:54 . 2004-08-03 22:41 404,990 --a--c--- C:\WINDOWS\system32\dllcache\slntamr.sys
2007-12-05 13:53 . 2001-08-23 17:18 899,914 --a--c--- C:\WINDOWS\system32\dllcache\r2mdkxga.sys
2007-12-05 13:52 . 2004-08-04 00:54 4,274,816 --a--c--- C:\WINDOWS\system32\dllcache\nv4_disp.dll
2007-12-05 13:51 . 2001-08-17 21:28 802,683 --a--c--- C:\WINDOWS\system32\dllcache\ltsm.sys
2007-12-05 13:50 . 2004-08-03 22:41 1,041,536 --a--c--- C:\WINDOWS\system32\dllcache\hsfdpsp2.sys
2007-12-05 13:49 . 2001-08-23 17:46 1,733,120 --a--c--- C:\WINDOWS\system32\dllcache\g400d.dll
2007-12-05 13:48 . 2001-08-23 17:04 980,034 --a--c--- C:\WINDOWS\system32\dllcache\cicap.sys
2007-12-05 13:47 . 2001-08-17 21:28 871,388 --a--c--- C:\WINDOWS\system32\dllcache\bcmdm.sys
2007-12-05 13:46 . 2001-08-17 21:28 762,780 --a--c--- C:\WINDOWS\system32\dllcache\3cwmcru.sys
2007-12-05 13:45 . 2001-08-23 17:46 66,048 --a--c--- C:\WINDOWS\system32\dllcache\s3legacy.dll
2007-12-03 10:31 . 2007-12-03 10:31 <REP> d-------- C:\Program Files\Fichiers communs\Adobe
2007-12-02 23:40 . 2007-12-02 23:40 <REP> d-------- C:\Program Files\Fichiers communs\xing shared
2007-12-02 23:40 . 2007-12-02 23:40 <REP> d-------- C:\Program Files\Fichiers communs\Real
2007-12-02 03:00 . 2007-12-02 03:00 <REP> d-------- C:\Program Files\Windows Live Favorites
2007-11-28 17:46 . 1994-12-05 23:00 12,800 --a------ C:\WINDOWS\system32\WING32.DLL
2007-11-28 17:45 . 2007-11-28 17:46 <REP> d-------- C:\Program Files\QuickTime
2007-11-28 17:45 . 2007-11-28 17:45 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-11-25 11:37 . 2007-11-25 11:37 <REP> d-------- C:\Program Files\VSTplugins
2007-11-25 11:37 . 2007-11-25 11:37 <REP> d-------- C:\Documents and Settings\reg mus\Application Data\Publish Providers
2007-11-25 11:28 . 2007-11-25 11:28 <REP> d-------- C:\Documents and Settings\reg mus\Application Data\Sony
2007-11-25 11:20 . 2007-11-25 11:21 <REP> d-------- C:\WINDOWS\system32\URTTemp
2007-11-25 10:51 . 2007-11-25 11:05 <REP> d-------- C:\Documents and Settings\reg mus\Application Data\AdobeUM
2007-11-23 21:01 . 2007-11-23 21:02 <REP> d-------- C:\QURAN
2007-11-23 20:40 . 2007-11-23 20:40 <REP> d-------- C:\MINIPAD
2007-11-23 20:40 . 2007-11-23 20:40 45,712 --a------ C:\WINDOWS\system\msacm.dll
2007-11-23 20:40 . 2007-11-23 20:40 22,096 --a------ C:\WINDOWS\system\msacm.drv
2007-11-23 20:40 . 2007-11-23 20:40 15,600 --a------ C:\WINDOWS\system\msadpcm.acm
2007-11-23 20:40 . 2007-11-23 20:40 10,320 --a------ C:\WINDOWS\system\imaadpcm.acm
2007-11-23 20:40 . 2007-11-23 20:40 7,056 --a------ C:\WINDOWS\system\speaker.drv
2007-11-23 20:40 . 2007-11-25 11:02 1,316 --a------ C:\WINDOWS\quran.ini
2007-11-23 20:40 . 2007-11-23 21:02 1,124 --a------ C:\WINDOWS\QURAN.ORG
2007-11-23 20:40 . 2007-11-23 21:01 49 --a------ C:\WINDOWS\minipad.ini
2007-11-23 14:11 . 2007-11-23 14:11 <REP> d--h----- C:\Documents and Settings\reg mus\Nouveau dossier
2007-11-23 13:51 . 2007-11-23 14:09 <REP> d-------- C:\Documents and Settings\reg mus\Application Data\Windows Desktop Search
2007-11-23 13:48 . 2007-11-23 13:49 <REP> d-------- C:\WINDOWS\system32\fr-FR
2007-11-23 13:48 . 2007-11-23 13:49 <REP> d-------- C:\Program Files\Windows Desktop Search
2007-11-23 12:30 . 2007-04-13 08:50 108,424 -ra------ C:\WINDOWS\system32\drivers\zebrmdmc.sys
2007-11-23 12:30 . 2007-04-13 08:50 108,296 -ra------ C:\WINDOWS\system32\drivers\zebrmdm.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-06 20:56 --------- d---a-w C:\Documents and Settings\All Users\Application Data\MakeMusic
2007-12-02 03:01 --------- d-----w C:\Program Files\Windows Live Toolbar
2007-11-15 00:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-11-11 23:25 --------- d-----w C:\Program Files\MSBuild
2007-11-11 23:25 --------- d-----w C:\Program Files\Microsoft Works
2007-11-07 01:40 --------- d-----w C:\Program Files\Windows Defender
2007-11-07 01:34 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-11-07 01:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
2007-11-07 01:29 --------- d-----w C:\Program Files\MSN Messenger
2007-11-07 01:20 --------- d-----w C:\Program Files\SmartMusic 9
2007-11-07 00:39 --------- d-----w C:\Program Files\microsoft frontpage
2007-11-07 00:37 --------- d-----w C:\Program Files\Services en ligne
2007-11-07 00:36 --------- d-----w C:\Program Files\Fichiers communs\MSSoap
2007-11-07 00:07 --------- d-----w C:\Program Files\Fichiers communs\SpeechEngines
2007-11-07 00:07 --------- d-----w C:\Program Files\Fichiers communs\ODBC
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:54]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:55]
"mRouterConfig"="C:\Program Files\Intuwave\Shared\mRouterRuntime\mRouterConfig.exe" [2006-03-02 11:54]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06]
"eMuleAutoStart"="E:\Program Files\eMule\emule.exe" [2007-05-13 14:57]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20]
"SSBkgdUpdate"="C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-09-30 00:14]
"PDF4 Registry Controller"="C:\Program Files\ScanSoft\PDF Professional 4.0\\RegistryController.exe" [2006-08-22 19:09]
"ISUSPM Startup"="C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-04-17 12:41]
"ISUSScheduler"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2004-04-13 06:07]
"PC Suite for Smartphones"="C:\Program Files\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe" [2007-05-28 10:14]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-11-28 17:46]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-12-02 23:40]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 03:01]
"AVP"="e:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" [2007-03-09 17:50]
"RegDoctor"="C:\Program Files\RegDoctor\RegDoctor.exe" [2007-08-14 12:38]
"NeroFilterCheck"="C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe" [2007-03-01 15:57]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-08-08 09:25]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 00:54]
"DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 09:01]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2007-02-05 15:39 294400]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
R2 HPPECP00;hppecp00;\??\C:\WINDOWS\system32\drivers\hppecp00.sys
R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3;C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
R3 ES1370;Creative AudioPCI (ES1370), SB PCI 64/128 (WDM);C:\WINDOWS\system32\drivers\ES1370MP.sys
R3 zebrceb;Sony Ericsson Cable Emulation Bus (WDM);C:\WINDOWS\system32\DRIVERS\zebrceb.sys
S3 zebrbus;Sony Ericsson Composite Device driver;C:\WINDOWS\system32\DRIVERS\zebrbus.sys
S3 zebrmdfl;Sony Ericsson Modem Filter;C:\WINDOWS\system32\DRIVERS\zebrmdfl.sys
S3 zebrmdm;Sony Ericsson Port (WDM);C:\WINDOWS\system32\DRIVERS\zebrmdm.sys
S3 zebrmdmc;Sony Ericsson mRouter Port (WDM);C:\WINDOWS\system32\DRIVERS\zebrmdmc.sys
S3 zebrsce;Sony Ericsson PC-Connect Port;C:\WINDOWS\system32\DRIVERS\zebrsce.sys
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2007-12-13 02:13:03 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2007-12-13 19:57:11 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-13 20:57:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-12-13 20:59:59 - machine was rebooted
.
2007-12-02 03:01:06 --- E O F ---