Bonjour,
Tout d'abord, merci pour le coup de main, je crois qu'il faudra bien si mettre à plusieurs...
j'ai bien effectué les 2 scans, comme indiqué...
Voici les rapports:
1 -- VirtumundoBeGone
[03/04/2008, 18:22:16] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\denis\Bureau\VirtumundoBeGone.exe" )
[03/04/2008, 18:22:21] - Detected System Information:
[03/04/2008, 18:22:21] - Windows Version: 5.1.2600, Service Pack 2
[03/04/2008, 18:22:21] - Current Username: denis (Admin)
[03/04/2008, 18:22:21] - Windows is in NORMAL mode.
[03/04/2008, 18:22:21] - Searching for Browser Helper Objects:
[03/04/2008, 18:22:21] - BHO 1: {02478D38-C3F9-4EFB-9B51-7695ECA05670} (Yahoo! Toolbar Helper)
[03/04/2008, 18:22:21] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Aide pour le lien d'Adobe PDF Reader)
[03/04/2008, 18:22:21] - BHO 3: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[03/04/2008, 18:22:21] - BHO 4: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[03/04/2008, 18:22:21] - Finished Searching Browser Helper Objects
[03/04/2008, 18:22:21] - Finishing up...
[03/04/2008, 18:22:21] - Nothing found! Exiting...
----------------------------------------------------------------------------------------------------------------------------------------
2 -- ComboFix
ComboFix 08-03-04.2 - denis 2008-03-04 18:29:49.1 - NTFSx86 MINIMAL
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1770 [GMT 1:00]
Endroit: C:\Documents and Settings\denis\Bureau\ComboFix.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\guosepin.ini
C:\WINDOWS\system32\jaabhyxq.ini
C:\WINDOWS\system32\khxbpavj.ini
.
((((((((((((((((((((((((((((( Fichiers créés 2008-02-04 to 2008-03-04 ))))))))))))))))))))))))))))))))))))
.
2008-03-04 10:13 . 2008-03-04 10:13 <REP> d-------- C:\fsaua.data
2008-03-04 09:36 . 2008-03-04 09:56 <REP> d-------- C:\WINDOWS\BDOSCAN8
2008-03-04 08:26 . 2008-03-04 08:26 <REP> d-------- C:\Documents and Settings\denis\Application Data\Grisoft
2008-03-04 08:26 . 2008-03-04 08:26 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-04 08:26 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-03 16:12 . 2008-03-03 16:12 <REP> d-------- C:\WINDOWS\ERUNT
2008-03-03 16:03 . 2008-03-03 16:17 <REP> d-------- C:\SDFix
2008-03-03 15:40 . 2008-03-03 15:40 5,376 --a------ C:\WINDOWS\system32\drivers\MS1000.sys
2008-03-03 15:39 . 2008-03-04 08:53 <REP> d-------- C:\Program Files\The Cleaner Free
2008-02-28 17:11 . 2008-02-28 17:11 <REP> d-------- C:\VundoFix Backups
2008-02-25 07:47 . 2008-02-28 17:14 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-02-21 17:45 . 2008-02-21 17:45 <REP> d-------- C:\Program Files\Yahoo!
2008-02-12 13:37 . 2008-02-12 13:37 <REP> d-------- C:\rdm6
2008-02-11 12:30 . 2008-03-03 10:17 <REP> d-------- C:\Program Files\Trojan Remover
2008-02-11 11:32 . 2008-03-04 18:26 <REP> d-------- C:\Program Files\SUPERAntiSpyware
2008-02-11 11:32 . 2008-02-11 11:32 <REP> d-------- C:\Documents and Settings\denis\Application Data\SUPERAntiSpyware.com
2008-02-11 11:32 . 2008-02-11 11:32 <REP> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-11 10:18 . 2008-02-11 10:19 <REP> d-------- C:\Program Files\Crawler
2008-02-11 09:57 . 2008-03-03 09:02 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-11 09:57 . 2008-02-11 10:12 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-11 09:45 . 2008-02-11 10:50 714 ---hs---- C:\WINDOWS\system32\nknwsqnj.ini
2008-02-11 08:01 . 2008-03-03 14:32 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-07 13:35 . 2008-02-07 13:35 <REP> d-------- C:\Program Files\Lavasoft
2008-02-07 13:35 . 2008-02-07 13:36 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-06 11:00 . 2008-02-06 11:01 <REP> d-------- C:\Program Files\SPIT_Expert
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-04 17:32 --------- d-----w C:\Documents and Settings\denis\Application Data\StarOffice8
2008-03-03 08:26 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-13 12:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-02-11 10:32 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-02-11 07:07 --------- d-----w C:\Program Files\Trend Micro
2008-01-31 17:03 --------- d-----w C:\Documents and Settings\denis\Application Data\Azureus
2008-01-31 12:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Azureus
2008-01-15 08:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2006-06-23 06:48 32,768 ----a-r C:\WINDOWS\inf\UpdateUSB.exe
2007-10-26 10:04 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat
2007-10-31 14:01 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012007103120071101\index.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2007-08-02 13:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2007-09-26 11:22 1694208]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 14:34 868352]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2006-07-13 06:12 729088]
"JMB36X IDE Setup"="C:\WINDOWS\JM\JMInsIDE.exe" [2006-10-30 13:44 36864]
"JMB36X Configure"="C:\WINDOWS\system32\JMRaidSetup.exe" [2006-10-30 13:44 1953792]
"Matrox PowerDesk 8"="C:\Program Files\Matrox Graphics Inc\PowerDesk HF\matrox.powerdesk.exe" [2005-08-10 11:43 102400]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe" [2006-09-29 07:24 3121152]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"vspdfprsrv.exe"="C:\Program Files\Visage\PDF Printer\vspdfprsrv.exe" [2004-07-14 22:33 905216]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2007-08-02 13:00 15360]
"DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 09:01 437160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"TSClientMSIUninstaller"="cmd.exe" [2007-08-02 13:00 400896 C:\WINDOWS\system32\cmd.exe]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
R2 BcmSqlStartupSvc;Service de démarrage SQL Server pour le Gestionnaire de contacts professionnels;"C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe" [2008-01-16 09:46]
R3 MTXPARH;MTXPARH;C:\WINDOWS\system32\DRIVERS\MTXPARHM.sys [2005-08-10 12:54]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);"c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ []
S3 SQLWriter;Enregistreur VSS SQL Server;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2006-04-14 09:04]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ddb41936-83b7-11dc-9614-806d6172696f}]
\Shell\AutoRun\command - D:\Bin\Assetup.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-04 18:33:02
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Matrox Graphics Inc\PowerDesk HF\Matrox.PowerDesk.PDeskNet.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Sun\StarOffice 8\program\soffice.exe
C:\Program Files\Sun\StarOffice 8\program\soffice.BIN
c:\program files\matrox graphics inc\powerdesk hf\Matrox.PowerDesk.Communications.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\UPHClean\uphclean.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-03-04 18:35:06 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-04 17:34:55
.
2008-03-04 12:00:41 --- E O F ---
Bonjour,
j'ai bien reçu le message et j'ai effectué les 2 scans, comme indiqué...
Voici les rapports:
VirtumundoBeGone
[03/04/2008, 18:22:16] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\denis\Bureau\VirtumundoBeGone.exe" )
[03/04/2008, 18:22:21] - Detected System Information:
[03/04/2008, 18:22:21] - Windows Version: 5.1.2600, Service Pack 2
[03/04/2008, 18:22:21] - Current Username: denis (Admin)
[03/04/2008, 18:22:21] - Windows is in NORMAL mode.
[03/04/2008, 18:22:21] - Searching for Browser Helper Objects:
[03/04/2008, 18:22:21] - BHO 1: {02478D38-C3F9-4EFB-9B51-7695ECA05670} (Yahoo! Toolbar Helper)
[03/04/2008, 18:22:21] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Aide pour le lien d'Adobe PDF Reader)
[03/04/2008, 18:22:21] - BHO 3: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[03/04/2008, 18:22:21] - BHO 4: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[03/04/2008, 18:22:21] - Finished Searching Browser Helper Objects
[03/04/2008, 18:22:21] - Finishing up...
[03/04/2008, 18:22:21] - Nothing found! Exiting...
ComboFix 08-03-04.2 - denis 2008-03-04 18:29:49.1 - NTFSx86 MINIMAL
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1770 [GMT 1:00]
Endroit: C:\Documents and Settings\denis\Bureau\ComboFix.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\guosepin.ini
C:\WINDOWS\system32\jaabhyxq.ini
C:\WINDOWS\system32\khxbpavj.ini
.
((((((((((((((((((((((((((((( Fichiers créés 2008-02-04 to 2008-03-04 ))))))))))))))))))))))))))))))))))))
.
2008-03-04 10:13 . 2008-03-04 10:13 <REP> d-------- C:\fsaua.data
2008-03-04 09:36 . 2008-03-04 09:56 <REP> d-------- C:\WINDOWS\BDOSCAN8
2008-03-04 08:26 . 2008-03-04 08:26 <REP> d-------- C:\Documents and Settings\denis\Application Data\Grisoft
2008-03-04 08:26 . 2008-03-04 08:26 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-04 08:26 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-03 16:12 . 2008-03-03 16:12 <REP> d-------- C:\WINDOWS\ERUNT
2008-03-03 16:03 . 2008-03-03 16:17 <REP> d-------- C:\SDFix
2008-03-03 15:40 . 2008-03-03 15:40 5,376 --a------ C:\WINDOWS\system32\drivers\MS1000.sys
2008-03-03 15:39 . 2008-03-04 08:53 <REP> d-------- C:\Program Files\The Cleaner Free
2008-02-28 17:11 . 2008-02-28 17:11 <REP> d-------- C:\VundoFix Backups
2008-02-25 07:47 . 2008-02-28 17:14 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-02-21 17:45 . 2008-02-21 17:45 <REP> d-------- C:\Program Files\Yahoo!
2008-02-12 13:37 . 2008-02-12 13:37 <REP> d-------- C:\rdm6
2008-02-11 12:30 . 2008-03-03 10:17 <REP> d-------- C:\Program Files\Trojan Remover
2008-02-11 11:32 . 2008-03-04 18:26 <REP> d-------- C:\Program Files\SUPERAntiSpyware
2008-02-11 11:32 . 2008-02-11 11:32 <REP> d-------- C:\Documents and Settings\denis\Application Data\SUPERAntiSpyware.com
2008-02-11 11:32 . 2008-02-11 11:32 <REP> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-02-11 10:18 . 2008-02-11 10:19 <REP> d-------- C:\Program Files\Crawler
2008-02-11 09:57 . 2008-03-03 09:02 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-11 09:57 . 2008-02-11 10:12 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-11 09:45 . 2008-02-11 10:50 714 ---hs---- C:\WINDOWS\system32\nknwsqnj.ini
2008-02-11 08:01 . 2008-03-03 14:32 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-07 13:35 . 2008-02-07 13:35 <REP> d-------- C:\Program Files\Lavasoft
2008-02-07 13:35 . 2008-02-07 13:36 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-06 11:00 . 2008-02-06 11:01 <REP> d-------- C:\Program Files\SPIT_Expert
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-04 17:32 --------- d-----w C:\Documents and Settings\denis\Application Data\StarOffice8
2008-03-03 08:26 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-13 12:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-02-11 10:32 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-02-11 07:07 --------- d-----w C:\Program Files\Trend Micro
2008-01-31 17:03 --------- d-----w C:\Documents and Settings\denis\Application Data\Azureus
2008-01-31 12:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Azureus
2008-01-15 08:18 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2006-06-23 06:48 32,768 ----a-r C:\WINDOWS\inf\UpdateUSB.exe
2007-10-26 10:04 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat
2007-10-31 14:01 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012007103120071101\index.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2007-08-02 13:00 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2007-09-26 11:22 1694208]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-06-21 14:06 1318912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 14:34 868352]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2006-07-13 06:12 729088]
"JMB36X IDE Setup"="C:\WINDOWS\JM\JMInsIDE.exe" [2006-10-30 13:44 36864]
"JMB36X Configure"="C:\WINDOWS\system32\JMRaidSetup.exe" [2006-10-30 13:44 1953792]
"Matrox PowerDesk 8"="C:\Program Files\Matrox Graphics Inc\PowerDesk HF\matrox.powerdesk.exe" [2005-08-10 11:43 102400]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe" [2006-09-29 07:24 3121152]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"vspdfprsrv.exe"="C:\Program Files\Visage\PDF Printer\vspdfprsrv.exe" [2004-07-14 22:33 905216]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2007-08-02 13:00 15360]
"DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 09:01 437160]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"TSClientMSIUninstaller"="cmd.exe" [2007-08-02 13:00 400896 C:\WINDOWS\system32\cmd.exe]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 13:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
R2 BcmSqlStartupSvc;Service de démarrage SQL Server pour le Gestionnaire de contacts professionnels;"C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe" [2008-01-16 09:46]
R3 MTXPARH;MTXPARH;C:\WINDOWS\system32\DRIVERS\MTXPARHM.sys [2005-08-10 12:54]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);"c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ []
S3 SQLWriter;Enregistreur VSS SQL Server;"c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe" [2006-04-14 09:04]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ddb41936-83b7-11dc-9614-806d6172696f}]
\Shell\AutoRun\command - D:\Bin\Assetup.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-04 18:33:02
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Matrox Graphics Inc\PowerDesk HF\Matrox.PowerDesk.PDeskNet.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Sun\StarOffice 8\program\soffice.exe
C:\Program Files\Sun\StarOffice 8\program\soffice.BIN
c:\program files\matrox graphics inc\powerdesk hf\Matrox.PowerDesk.Communications.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\UPHClean\uphclean.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-03-04 18:35:06 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-04 17:34:55
.
2008-03-04 12:00:41 --- E O F ---
Après redémarrage, j'ai réinstallé Ccleaner et j'ai retenté de le lancer...
--- même "jetage" que précédamment...
Il semblerait que le bougre soit très coriace...
J'espère que les rapports pourront servir pour trouver une faille dans son système...
A+ pour de nouvelles manip...