Ok merci, je vais faire un bon nettoyage ...et voici le rapport.
Par contre a la fin de l analyse, j ai eu une tentative de piratage(C/windowsregedit.exe)est ce normal ?
ComboFix 07-11-19.4C - Stick 2007-11-30 8:31:50.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.219 [GMT 1:00]
Running from: C:\Documents and Settings\Stick\Local Settings\Temporary Internet Files\Content.IE5\JDO1QOBE\ComboFix[1].exe
* Created a new restore point
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\2.tmp
.
((((((((((((((((((((((((((((( Fichiers créés 2007-10-28 to 2007-11-30 ))))))))))))))))))))))))))))))))))))
.
2007-11-21 10:03 49,265 --a------ C:\WINDOWS\system32\jpicpl32.cpl
2007-11-21 10:02 <REP> d-------- C:\Program Files\Fichiers communs\Java
2007-11-21 06:26 <REP> d-------- C:\Program Files\FxTrading
2007-11-17 13:09 <REP> d-------- C:\Documents and Settings\All Users\Application Data\McAfee
2007-11-14 17:56 <REP> d-------- C:\Documents and Settings\Stick\FxTrading
2007-11-14 17:56 <REP> d-------- C:\Documents and Settings\Stick\fxprops
2007-11-14 07:08 <REP> d-------- C:\f5cc56a85d36b4d1ac5c3581f71d
2007-11-08 19:31 <REP> d-------- C:\Program Files\TuneUp Utilities 2007
2007-11-08 19:30 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2007-10-14 16:56 242,448 --a------ C:\WINDOWS\system32\scedll.dll
2007-10-14 16:56 49,936 --a------ C:\WINDOWS\system32\SeCEdit.exe
2007-10-14 16:56 29,968 --a------ C:\WINDOWS\system32\Rshx32_5.dll
2007-10-14 16:52 <REP> d-------- C:\ZebProtect
2007-10-13 10:32 <REP> d-------- C:\Regseeker
2007-10-13 08:56 <REP> d-------- C:\Program Files\Navilog1
2007-10-13 08:15 <REP> d-------- C:\ZonedOut
2007-10-13 07:48 <REP> d-------- C:\HiJackThis
2007-10-13 07:03 <REP> d-------- C:\Program Files\Alwil Software
2007-10-08 06:14 3,596,288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2007-10-08 06:10 <REP> d-------- C:\Program Files\K-Lite Codec Pack
2007-10-07 10:44 <REP> d-------- C:\Documents and Settings\Stick\Application Data\vlc
2007-10-07 10:42 <REP> d-------- C:\Program Files\VideoLAN
2007-10-07 08:00 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Zylom
2007-10-02 12:29 <REP> d-------- C:\Program Files\inKline Global
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-30 07:29 106,268 ----a-w C:\WINDOWS\system32\drivers\APPFCONT.DAT
2007-11-30 07:28 --------- d-----w C:\Documents and Settings\Stick\Application Data\EoRezo
2007-11-30 06:02 1,132 ----a-w C:\WINDOWS\system32\drivers\APPFLTR.CFG
2007-11-29 21:18 --------- d-----w C:\Documents and Settings\Stick\Application Data\Skype
2007-11-25 20:25 --------- d-----w C:\Documents and Settings\Stick\Application Data\ChessBase
2007-11-25 10:35 --------- d-----w C:\Program Files\eMule
2007-11-21 09:03 --------- d-----w C:\Program Files\Java
2007-11-16 19:02 --------- d-----w C:\Documents and Settings\Stick\Application Data\AdobeUM
2007-11-12 10:29 --------- d-----w C:\Program Files\VTTrader
2007-11-08 20:39 --------- d-----w C:\Program Files\Wanadoo
2007-11-08 20:39 --------- d-----w C:\Program Files\Motamo
2007-10-23 19:26 --------- d-----w C:\Program Files\Synthesis Bank
2007-10-13 09:25 16,384 ----a-w C:\WINDOWS\system32\try.exe
2007-10-11 19:29 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-10-10 06:35 --------- d-----w C:\Program Files\Google
2007-10-07 08:39 --------- d-----w C:\Program Files\DivX
2007-10-02 11:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-08-21 06:17 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-03-29 13:01 278,528 ----a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
2005-11-30 15:23 483,401 ----a-w C:\Documents and Settings\Stick\314_gotomypc.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-04 06:38]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoRecentDocsMenu"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
avldr.dll 2005-09-27 11:13 45056 C:\WINDOWS\system32\avldr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 relog_ap
R0 netflt;Panda Net Driver [NDIS Layer];C:\WINDOWS\system32\Drivers\NETFLT.SYS
R0 snapman;Acronis Snapshots Manager;C:\WINDOWS\system32\DRIVERS\snapman.sys
R0 timounter;Acronis True Image Backup Archive Explorer;C:\WINDOWS\system32\DRIVERS\timntr.sys
R1 APPFLT;App Filter Plugin;\??\C:\WINDOWS\system32\Drivers\APPFLT.SYS
R1 DSAFLT;DSA Filter Plugin;\??\C:\WINDOWS\system32\Drivers\DSAFLT.SYS
R1 FNETMON;NetMon Filter Plugin;\??\C:\WINDOWS\system32\Drivers\fnetmon.SYS
R1 IDSFLT;Ids Filter Plugin;\??\C:\WINDOWS\system32\Drivers\IDSFLT.SYS
R1 NETFLTDI;Panda Net Driver [TDI Layer];\??\C:\WINDOWS\system32\Drivers\NETFLTDI.SYS
R1 ShldDrv;Panda File Shield Driver;C:\WINDOWS\system32\drivers\ShldDrv.sys
R1 SMSFLT;SMS Filter Plugin;\??\C:\WINDOWS\system32\Drivers\SMSFLT.SYS
R1 WNMFLT;Wifi Monitor Filter Plugin;\??\C:\WINDOWS\system32\Drivers\WNMFLT.SYS
R2 cpoint;Panda CPoint Driver;C:\WINDOWS\system32\Drivers\cpoint.sys
R2 PavProc;Panda Process Protection Driver;\??\C:\WINDOWS\system32\DRIVERS\PavProc.sys
R2 PStrip;PStrip;C:\WINDOWS\system32\drivers\pstrip.sys
R2 tifsfilter;Acronis True Image FS Filter;C:\WINDOWS\system32\DRIVERS\tifsfilt.sys
R2 UxTuneUp;TuneUp Extension de thème;C:\WINDOWS\System32\svchost.exe -k netsvcs
R3 AvFlt;Antivirus Filter Driver;C:\WINDOWS\system32\drivers\av5flt.sys
R3 ComFiltr;Panda Anti-Dialer;\??\C:\WINDOWS\system32\DRIVERS\COMFiltr.sys
R3 PavSRK.sys;PavSRK.sys;\??\C:\WINDOWS\system32\PavSRK.sys
R3 PD1030VID;Creative WebCam Pro;C:\WINDOWS\system32\DRIVERS\P1030Vid.sys
S2 ohbusb;Open Host Controller Miniport USB Driver;\??\C:\WINDOWS\system32\drivers\ohbusb.sys
S3 SIS163u;SiS163 usb Wireless LAN Adapter Driver;C:\WINDOWS\system32\DRIVERS\sis163u.sys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - CATCHME
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2007-11-25 21:12:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-30 07:38:54 C:\WINDOWS\Tasks\User_Feed_Synchronization-{9F3A16D8-13F2-49FD-9F29-BD847117CC6D}.job"
- C:\WINDOWS\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1262 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-11-30 08:39:57
Windows 5.1.2600 Service Pack 2 NTFS
detected NTDLL code modification:
ZwEnumerateKey, ZwClose, ZwEnumerateValueKey, ZwQueryValueKey, ZwOpenFile
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-30 8:42:33
.
--- E O F ---