Voilà, c'est fait ! Qu'est-ce qui cloche ? C'est vraiment si infesté que ça ? En tout cas, merci beaucoup beaucoup... Rapport :
ComboFix 08-12-21.04 - HP_Administrateur 2008-12-23 16:21:01.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.511.146 [GMT 1:00]
Running from: c:\documents and settings\HP_Administrateur\Bureau\ComboFix.exe
Command switches used :: c:\documents and settings\HP_Administrateur\Bureau\WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\bold.log
c:\documents and settings\HP_Administrateur\Application Data\inst.exe
c:\documents and settings\HP_Administrateur\Local Settings\Temporary Internet Files\1d050d09.bmp
c:\documents and settings\HP_Administrateur\Local Settings\Temporary Internet Files\25050c67.bmp
c:\documents and settings\HP_Administrateur\Local Settings\Temporary Internet Files\7a051471.bmp
c:\documents and settings\HP_Administrateur\Local Settings\Temporary Internet Files\9405131e.bmp
c:\documents and settings\HP_Administrateur\Local Settings\Temporary Internet Files\ed051360.bmp
c:\documents and settings\HP_Administrateur\Local Settings\Temporary Internet Files\EUP409.tmp
c:\program files\SurfAccuracy
c:\program files\SurfAccuracy\License.lnk
c:\program files\SurfAccuracy\SAcc.cfg
c:\windows\Downloaded Program Files\setup.inf
c:\windows\Downloaded Program Files\ysbActivex.dll
c:\windows\IE4 Error Log.txt
c:\windows\system32\404Fix.exe
c:\windows\system32\86FKUKnf.exe.a_a
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\lICw1751.exe
c:\windows\system32\lICw1751.exe.a_a
c:\windows\system32\lICw1751.exe_
c:\windows\system32\nKEy7427.dll
c:\windows\system32\o4Patch.exe
c:\windows\system32\OrUAHKG2.exe.a_a
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
D:\Autorun.inf
.
((((((((((((((((((((((((( Files Created from 2008-11-23 to 2008-12-23 )))))))))))))))))))))))))))))))
.
2008-12-23 14:58 . 2008-12-12 00:57 78,336 --a------ c:\windows\system32\Agent.OMZ.Fix.exe
2008-12-23 12:48 . 2008-12-23 16:33 121 ---hs---- c:\windows\system32\azasosuh.ini
2008-12-22 10:00 . 2008-12-22 10:00 <REP> dr------- c:\documents and settings\NetworkService\Favoris
2008-12-22 10:00 . 2008-12-22 10:00 <REP> d-------- c:\documents and settings\NetworkService\Application Data\Yahoo!
2008-12-21 18:33 . 2008-12-21 19:20 <REP> d-------- c:\documents and settings\HP_Administrateur\Application Data\Lavasoft
2008-12-20 19:03 . 2008-12-20 19:01 31,744 --a------ c:\windows\system32\OrUAHKG2.exe
2008-12-20 19:02 . 2008-12-20 19:01 31,744 --a------ c:\windows\system32\86FKUKnf.exe
2008-12-19 18:14 . 2008-12-19 18:14 <REP> d-------- c:\documents and settings\All Users\Application Data\f-secure
2008-12-17 20:17 . 2008-12-17 20:17 <REP> d-------- c:\program files\Fichiers communs\Windows Live
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-23 11:48 97,883 ----a-w c:\windows\system32\sigubahi.dll.vir
2008-12-23 11:48 85,282 --sha-w c:\windows\system32\husosaza.dll
2008-12-22 20:33 94,780 --sha-w c:\windows\system32\royubide.dll
2008-12-22 20:33 85,224 --sha-w c:\windows\system32\silahije.dll
2008-12-22 19:33 61,076 --sha-w c:\windows\system32\mozehete.dll
2008-12-21 20:46 --------- d-----w c:\documents and settings\HP_Administrateur\Application Data\FrostWire
2008-12-21 11:31 372 ----a-w c:\documents and settings\HP_Administrateur\Application Data\wklnhst.dat
2008-12-20 11:16 --------- d-----w c:\program files\Microsoft Picture It! 9
2008-12-19 17:15 --------- d-----w c:\program files\Pack Sécurité
2008-11-29 22:23 --------- d-----w c:\documents and settings\HP_Administrateur\Application Data\uTorrent
2008-11-22 14:02 --------- d-----w c:\program files\DivX
2008-11-22 11:10 --------- d-----w c:\documents and settings\HP_Administrateur\Application Data\Samsung
2008-11-22 10:56 --------- d--h--w c:\program files\InstallShield Installation Information
2008-11-02 18:41 --------- d-----w c:\program files\iTunes
2008-11-02 18:41 --------- d-----w c:\program files\iPod
2008-11-02 18:41 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-11-02 18:39 --------- d-----w c:\program files\Bonjour
2008-11-02 18:38 --------- d-----w c:\program files\QuickTime
2008-11-02 18:36 --------- d-----w c:\program files\Apple Software Update
2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 13:00 283,648 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:18 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-03 10:17 247,326 ----a-w c:\windows\system32\strmdll.dll
2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
2008-07-28 19:44 47,360 ----a-w c:\documents and settings\HP_Administrateur\Application Data\pcouffin.sys
2008-04-25 14:53 144,720 ----a-w c:\documents and settings\HP_Administrateur\Application Data\GDIPFONTCACHEV1.DAT
2006-01-09 20:06 1,976 ----a-w c:\program files\naoual.txt
2005-06-10 19:31 346 ----a-w c:\program files\yasmine.txt
2005-06-10 19:10 15 ----a-w c:\program files\nomutil.txt
2005-01-01 22:53 251 ----a-w c:\program files\wt3d.ini
2008-09-22 19:33 61,076 --sha-w c:\windows\system32\jedevihi.dll
2008-09-22 19:33 61,076 --sha-w c:\windows\system32\ridogeku.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e3a6dad3-6f45-4200-9263-e95e142fa0f2}]
2008-09-22 20:33 61076 --ahs---- c:\windows\system32\jedevihi.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-10 15360]
"Acme.PCHButton"="c:\progra~1\HELPAN~1\Pavilion\XPEWWBF4\plugin\bin\pchbutton.exe" [2004-01-01 159744]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"Veoh"="c:\program files\Veoh Networks\Veoh\VeohClient.exe" [2007-12-19 3477504]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-01 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"HPHUPD06"="c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 49152]
"HPHmon06"="c:\windows\system32\hphmon06.exe" [2004-06-07 659456]
"KBD"="c:\hp\KBD\KBD.EXE" [2003-02-11 61440]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"SiS Windows KeyHook"="c:\windows\system32\keyhook.exe" [2004-05-20 249856]
"PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-26 339968]
"CTDVDDET"="c:\program files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDet.EXE" [2003-06-18 45056]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"Microsoft Works Update Detection"="c:\program files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe" [2003-06-10 50688]
"snpstd"="c:\windows\vsnpstd.exe" [2003-12-31 40960]
"Clicker"="c:\program files\Wiziway\Clicker\TagClick.exe" [2005-09-23 237568]
"AVG7_CC"="c:\progra~1\Grisoft\AVG7\avgcc.exe" [2008-01-21 579072]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-10 208952]
"IMEKRMIG6.1"="c:\windows\ime\imkr6_1\IMEKRMIG.EXE" [2004-08-10 44032]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-10 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-10 455168]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"rivufelegi"="c:\windows\system32\ridogeku.dll" [2008-09-22 61076]
"0854be61"="c:\windows\system32\husosaza.dll" [2008-12-23 85282]
"CTHelper"="CTHELPER.EXE" [2003-11-14 c:\windows\system32\CTHELPER.EXE]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 c:\windows\AGRSMMSG.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"AVG7_Run"="c:\progra~1\Grisoft\AVG7\avgw.exe" [2008-01-21 219136]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"StartMS"="c:\program files\Creative\Shared Files\Media Sniffer\StartMS.EXE" [2003-03-26 57344]
"CMSRegOW.exe"="c:\program files\InstallShield Installation Information\{56F3E1FF-54FE-4384-A153-6CCABA097814}\CMSRegOW.exe" [2003-06-16 57344]
"SetDefaultMIDI"="MIDIDEF.EXE" [2003-06-21 c:\windows\MIDIDEF.EXE]
c:\documents and settings\HP_Administrateur\Menu D‚marrer\Programmes\D‚marrage\
Outil de d‚tection de support Picture Motion Browser.lnk - c:\program files\Sony\Sony Picture Utility\VolumeWatcher\SPUVolumeWatcher.exe [2008-03-20 368640]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"-"= msvideo8
"VIDC.YUY2"= vvlcodec.dll
"VIDC.UYVY"= vvlcodec.dll
"VIDC.I420"= vvlcodec.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli c:\windows\system32\livugafo.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avginet.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgamsvr.exe"=
"c:\\Program Files\\Grisoft\\AVG7\\avgcc.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\FrostWire\\FrostWire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\hp\\KBD\\kbd.exe"=
"c:\\WINDOWS\\system32\\CTHELPER.EXE"=
"c:\\WINDOWS\\ehome\\ehtray.exe"=
"c:\\WINDOWS\\vsnpstd.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\WINDOWS\\system32\\rundll32.exe"=
R2 BackWeb Plug-in - 361343;Pack Sécurité;c:\progra~1\PACKSC~1\backweb\361343\Program\SERVIC~1.EXE [2006-10-26 32807]
S4 Inmhipcmcscp;Inmhipcmcscp; []
.
Contents of the 'Scheduled Tasks' folder
2008-12-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - (no file)
HKCU-Run-WinFixer2005 - c:\program files\WinFixer 2005\UWFX5.exe
HKLM-Run-SurfAccuracy - c:\program files\SurfAccuracy\SAcc.exe
HKLM-Run-F-Secure Manager - c:\program files\Pack Sécurité\Common\FSM32.EXE
HKLM-Run-F-Secure Startup Wizard - c:\program files\Pack Sécurité\FSGUI\FSSW.EXE
HKLM-Run-F-Secure TNB - c:\program files\Pack Sécurité\FSGUI\TNBUtil.exe
HKLM-Run-CPM0b678dfd - c:\windows\system32\sigubahi.dll
HKLM-Run-VTTimer - VTTimer.exe
.
------- Supplementary Scan -------
.
uInternet Connection Wizard,ShellNext = hxxp://sonique.com/cgi-bin/sonique_online_redir?requestedlink=download+music&version=sonique+1.05.3&distro=unknown&ID=0evBWi9tEYH4zBrekVIIi8&numtimesrun=1&usage=0,0,1,0,0,0,0,0,0,0,0,0,0,0,skin_original_default=0
uInternet Settings,ProxyOverride = *.local
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~4\Office10\EXCEL.EXE/3000
TCP: {84CB0C51-03AA-4174-B754-14DC7BABA9EA} = 192.168.1.1
O16 -: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} - hxxp://minitelweb.minitel.com/imin_data/ocx/MDM.cab
c:\windows\Downloaded Program Files\MDM.inf
c:\windows\system32\unicows.dll - c:\windows\Downloaded Program Files\MypixUploader.ocx
O16 -: {1F83CD9E-505E-4F87-BECE-0832A763E36F}
hxxp://www.mypixmania.com/fr/fr/importer/MypixUploader.cab
c:\windows\Downloaded Program Files\MypixUploader.inf
c:\windows\system32\comctl32.ocx - c:\windows\system32\msvbvm60.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\olepro32.dll
c:\windows\system32\asycfilt.dll
c:\windows\system32\stdole2.tlb
c:\windows\system32\comcat.dll
c:\windows\system32\IVBExtractImageLib.tlb
c:\windows\system32\dbgwproc.dll
c:\windows\system32\ISHF_Ex.tlb
c:\windows\system32\JPegsize.dll
c:\windows\Downloaded Program Files\MCLPhoto.ocx
O16 -: {AD7A67A5-5461-4B6B-A9C5-09DD071527F5}
hxxp://auchan.fujifilmnet.com/MCLPhoto.CAB
c:\windows\Downloaded Program Files\MCLPhoto.INF
c:\windows\Downloaded Program Files\happlayer41140wd.EXE - O16 -: {DEADBEEF-DEAD-BEEF-DEAD-BEEFDEADBEEF}
hxxp://www.haptek.com/products/player/autoinstall/data/latest.cab
c:\windows\Downloaded Program Files\SETUP.INF
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-12-23 16:31:34
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\progra~1\Grisoft\AVG7\avgamsvr.exe
c:\progra~1\Grisoft\AVG7\avgupsvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\CTSVCCDA.EXE
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Pack Sécurité\backweb\361343\Program\fsbwsys.exe
c:\program files\Pack Sécurité\Common\FSMA32.EXE
c:\program files\Pack Sécurité\Common\FSMB32.EXE
c:\program files\Pack Sécurité\backweb\361343\Program\fspex.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Pack Sécurité\Common\FCH32.EXE
c:\program files\Pack Sécurité\Common\FAMEH32.EXE
c:\program files\Pack Sécurité\FSPC\fspc.exe
c:\windows\system32\MsPMSPSv.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\rundll32.exe
c:\program files\Pack Sécurité\FSGUI\fsguidll.exe
c:\windows\ehome\ehmsas.exe
c:\windows\system32\dllhost.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\HP\Digital Imaging\bin\hpqtra08.exe
c:\program files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
.
**************************************************************************
.
Completion time: 2008-12-23 16:40:12 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-23 15:40:04
Pre-Run: 118ÿ186ÿ270ÿ720 octets libres
Post-Run: 122,633,887,744 octets libres
276 --- E O F --- 2008-12-22 13:35:14