Bonjour !
Combofix, je l'avais passé pour une infection ancienne (en octobre je crois)
Je viens de le repasser, et voici le rapport :
ComboFix 09-01-21.04 - Patrick 2009-01-28 13:29:13.9 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.2046.1472 [GMT 1:00]
Lancé depuis: c:\documents and settings\Patrick\Bureau\Fificombo.exe
AV: Kaspersky Internet Security *On-access scanning disabled* (Updated)
FW: Kaspersky Internet Security *disabled*
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Patrick\Application Data\inst.exe
C:\InfoSat.txt
c:\windows\system32\hjpwqtet.ini
c:\windows\system32\kxhejffg.ini
c:\windows\system32\xdfitnmg.ini
D:\resycled
E:\resycled
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-28 au 2009-01-28 ))))))))))))))))))))))))))))))))))))
.
2009-01-26 22:45 . 2009-01-26 22:45 <REP> d-------- C:\combofifix
2009-01-25 18:16 . 2009-01-25 18:16 2,688 --a------ c:\windows\system32\settings.aaw
2009-01-25 18:16 . 2009-01-25 18:16 960 --a------ c:\windows\system32\history.aaw
2009-01-18 23:18 . 2009-01-25 12:59 54,156 --ah----- c:\windows\QTFont.qfn
2009-01-18 23:18 . 2009-01-18 23:18 1,409 --a------ c:\windows\QTFont.for
2009-01-18 19:27 . 2009-01-19 21:40 237,568 --a------ c:\windows\system32\rmc_rtspdl.dll
2009-01-18 19:27 . 2009-01-19 21:40 156,672 --a------ c:\windows\system32\rmc_fixasf.exe
2009-01-18 19:26 . 2009-01-19 21:40 323,584 --a------ c:\windows\system32\AUDIOGENIE2.DLL
2009-01-18 19:25 . 2009-01-18 19:25 <REP> d-------- c:\windows\Replay Media Catcher
2009-01-18 19:25 . 2009-01-19 21:52 <REP> d-------- c:\program files\Replay Media Catcher
2009-01-18 16:58 . 2009-01-18 16:58 <REP> d-------- C:\temp
2009-01-11 22:37 . 2009-01-11 22:37 <REP> d-------- c:\program files\FotoSketcher
2009-01-11 22:37 . 2009-01-11 22:37 <REP> d-------- c:\program files\eRightSoft
2009-01-11 22:19 . 2009-01-11 22:37 <REP> d-------- c:\program files\FrostWire
2009-01-11 11:29 . 2009-01-11 22:37 <REP> d-------- c:\program files\eRightSoft(2)
2009-01-11 11:18 . 2009-01-11 23:06 <REP> d-------- c:\program files\Free PDF to Word Doc Converter
2009-01-10 18:21 . 2009-01-10 18:21 <REP> d-------- c:\program files\uTorrent
2009-01-09 16:39 . 2009-01-09 16:39 <REP> d-------- c:\documents and settings\Patrick\Application Data\FreshDiagnose
2009-01-07 16:58 . 2009-01-07 21:59 <REP> d-------- c:\documents and settings\Patrick\.gimp-2.6
2009-01-07 16:58 . 2009-01-07 16:58 <REP> d-------- c:\documents and settings\Patrick\.gegl-0.0
2009-01-02 16:21 . 2009-01-02 16:21 <REP> d-------- c:\program files\RapidSolution
2009-01-01 15:30 . 2009-01-01 15:30 <REP> d-------- c:\documents and settings\Patrick\Application Data\KC Softwares
2008-12-29 18:04 . 2008-12-29 18:04 <REP> d-------- c:\program files\BitSpirit
2008-12-28 22:17 . 2008-12-28 22:17 <REP> d-------- c:\documents and settings\All Users\Application Data\Mindjet
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-28 12:32 41,343,264 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-01-28 12:32 3,756,064 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-01-28 12:09 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-01-27 21:53 557,924 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-01-27 21:53 357,020 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-01-25 18:05 --------- d-----w c:\program files\RegClean 4.1a
2009-01-25 17:27 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-01-25 17:22 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-01-25 17:14 --------- d-----w c:\program files\Fichiers communs\Wise Installation Wizard
2009-01-25 11:59 --------- d-----w c:\documents and settings\Patrick\Application Data\Corel
2009-01-25 11:58 2,516 --sha-w c:\windows\system32\KGyGaAvL.sys
2009-01-23 17:44 --------- d-----w c:\documents and settings\Patrick\Application Data\uTorrent
2009-01-19 11:13 --------- d-----w c:\documents and settings\All Users\Application Data\Babylon
2009-01-18 17:39 --------- d-----w c:\program files\Project URL Snooper
2009-01-18 17:18 37,440 ----a-w c:\windows\system32\drivers\pssdklbf.drv
2009-01-18 17:18 30,272 ----a-w c:\windows\system32\drivers\pssdk31.drv
2009-01-18 17:18 --------- d-----w c:\program files\Tube Master Plus 1.1.0.4
2009-01-17 23:04 --------- d-----w c:\documents and settings\Patrick\Application Data\dvdcss
2009-01-17 15:22 --------- d-----w c:\documents and settings\Patrick\Application Data\Vso
2009-01-14 15:11 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-01-14 15:11 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-01-11 21:26 --------- d-----w c:\documents and settings\Patrick\Application Data\FrostWire
2009-01-07 15:57 --------- d-----w c:\program files\GIMP-2.0
2008-12-29 11:21 --------- d-----w c:\documents and settings\Patrick\Application Data\CmapTools
2008-12-28 14:06 --------- d-----w c:\documents and settings\Patrick\Application Data\Pump
2008-12-28 14:05 --------- d-----w c:\documents and settings\Patrick\Application Data\Azureus
2008-12-28 14:02 --------- d-----w c:\program files\eMule
2008-12-26 17:15 --------- d-----w c:\program files\MediaInfo
2008-12-25 22:52 --------- d-----w c:\program files\Joost
2008-12-25 22:52 --------- d-----w c:\documents and settings\Patrick\Application Data\Joost
2008-12-25 20:50 --------- d-----w c:\documents and settings\Patrick\Application Data\ImgBurn
2008-12-25 20:49 --------- d-----w c:\program files\CCleaner
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-07 17:05 --------- d-----w c:\documents and settings\Patrick\Application Data\vlc
2008-12-07 16:58 --------- d-----w c:\program files\Winamp
2008-12-07 16:46 --------- d-----w c:\documents and settings\Patrick\Application Data\Winamp
2008-12-06 20:06 --------- d-----w c:\program files\VideoLAN
2008-12-06 18:32 --------- d-----w c:\program files\PCFriendly
2008-12-05 18:56 --------- d-----w c:\program files\Lphant
2008-12-03 15:10 --------- d-----w c:\program files\Java
2008-11-29 22:28 --------- d-----w c:\program files\free-downloads.net
2008-11-29 22:28 --------- d-----w c:\program files\Conduit
2008-11-29 22:26 2,560 ----a-w c:\windows\_MSRSTRT.EXE
2008-11-29 17:32 --------- d-----w c:\program files\DVDFab 5
2008-11-29 17:04 --------- d-----w c:\documents and settings\All Users\Application Data\vsosdk
2008-11-29 14:00 --------- d-----w c:\documents and settings\Patrick\Application Data\AdobeUM
2008-11-29 13:41 47,360 ----a-w c:\windows\system32\drivers\pcouffin.sys
2008-11-29 13:41 47,360 ----a-w c:\documents and settings\Patrick\Application Data\pcouffin.sys
2008-11-28 22:25 --------- d-----w c:\program files\IHMC CmapTools
2008-11-10 04:43 410,984 ----a-w c:\windows\system32\deploytk.dll
2008-11-03 08:26 3,023,817 ----a-r c:\program files\TRISTAN.exe
2008-10-28 22:36 823,296 ----a-w c:\windows\system32\divx_xx0c.dll
2008-10-28 22:36 823,296 ----a-w c:\windows\system32\divx_xx07.dll
2008-10-28 22:35 815,104 ----a-w c:\windows\system32\divx_xx0a.dll
2008-10-28 22:35 802,816 ----a-w c:\windows\system32\divx_xx11.dll
2008-10-28 22:35 684,032 ----a-w c:\windows\system32\DivX.dll
2008-04-02 15:46 744,339 ----a-w c:\program files\PAVARK.exe
2008-02-17 14:31 591 ----a-w c:\program files\Media Player Classic.lnk
2007-10-05 22:29 81,920 ----a-w c:\documents and settings\Patrick\Application Data\ezpinst.exe
2007-08-28 13:58 30 ----a-w c:\program files\Exiferupdate.ini
2006-12-28 17:54 810,704 ----a-w c:\program files\Panda Anti-Rootkit.exe
2006-03-27 17:49 3,809,280 ----a-w c:\program files\Guitools.exe
2005-11-19 08:31 532,480 ----a-w c:\program files\CWShredder 2.19.exe
2003-01-15 20:30 322,550 ----a-w c:\program files\Pop-up Stopper fr.exe
2001-09-11 18:24 670,720 ----a-w c:\program files\PlanetAnim.exe
1999-10-30 21:54 561,152 ----a-w c:\program files\Convert.exe
1999-06-30 13:06 151,552 ----a-r c:\windows\inf\Agfa\Message.exe
2005-06-26 14:32 616,448 --sha-r c:\windows\system32\cygwin1.dll
2005-06-21 21:37 45,568 --sha-r c:\windows\system32\cygz.dll
2006-05-03 10:06 163,328 --sh--r c:\windows\system32\flvDX.dll
2007-02-21 11:47 31,232 --sh--r c:\windows\system32\msfDX.dll
2008-03-16 13:30 216,064 --sh--r c:\windows\system32\nbDX.dll
2005-02-28 12:16 240,128 --sha-r c:\windows\system32\x.264.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Mobipocket Reader Notifications"="c:\program files\Mobipocket.com\Mobipocket Reader\readernotify.exe" [2006-06-20 57344]
"NBJ"="c:\program files\Ahead\Nero BackItUp\NBJ.exe" [2006-09-15 2048000]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-11-26 4608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"MedionVFD"="c:\program files\Medion Info Display\MdionLCM.exe" [2006-04-17 184320]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-04-27 7573504]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"OmniPage"="c:\progra~1\Caere\OMNIPA~1.0\opware32.exe" [1999-11-08 53248]
"UVS11 Preload"="c:\program files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe" [2008-01-23 341488]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-01-12 32768]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600]
"MMReminderService"="c:\program files\Mindjet\MindManager 7\MMReminderService.exe" [2008-03-19 37144]
"nwiz"="nwiz.exe" [2006-04-27 c:\windows\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-05-18 c:\windows\RTHDCPL.exe]
"Tweak UI"="TWEAKUI.CPL" [2001-03-19 c:\windows\system32\TWEAKUI.CPL]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"WIAWizardMenu"="c:\windows\system32\sti_ci.dll" [2008-04-14 138240]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
D‚marrage rapide du logiciel HP Image Zone.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-28 53248]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 241664]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.i420"= i420vfw.dll
"VIDC.ACDV"= ACDV.dll
"msacm.dvacm"= c:\progra~1\FICHIE~1\ULEADS~1\Vio\Dvacm.acm
"msacm.MPEGacm"= c:\progra~1\FICHIE~1\ULEADS~1\MPEG\MPEGacm.acm
"msacm.ulmp3acm"= c:\progra~1\FICHIE~1\ULEADS~1\MPEG\ulmp3acm.acm
[HKLM\~\startupfolder\C:^DOCUME~1^Patrick^Menu Démarrer^Programmes^Démarrage^QuickShelf.lnk]
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Babylon Client]
--a------ 2006-12-13 16:15 2785256 c:\program files\Babylon\Babylon-Pro\Babylon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CloneCDTray]
--a------ 2006-09-28 20:21 57344 c:\program files\SlySoft\CloneCD\CloneCDTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
--a------ 2004-05-12 14:18 241664 c:\program files\HP\hpcoretech\hpcmpmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
--a------ 2006-03-23 16:06 1398272 c:\program files\Ahead\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2008-04-14 03:34 1695232 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
--a------ 2006-05-16 18:04 2879488 c:\windows\SkyTel.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
"c:\\Program Files\\Joost\\xulrunner\\tvprunner.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\uTorrent\\utorrent.exe"=
R3 3xHybrid;Philips SAA713x PCI Card;c:\windows\system32\drivers\3xHybrid.sys [2006-11-15 882688]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [2007-12-13 24592]
R3 X10Hid;X10 Hid Device;c:\windows\system32\drivers\x10hid.sys [2006-11-15 7040]
R4 DVRMSFileWatcherService;DVRMSFileWatcherService;c:\program files\DVRMSToolbox\DVRMSFileWatcherService.exe [2007-08-18 20480]
S3 NPF;Netgroup Packet Filter;c:\windows\system32\drivers\npf.sys [2005-08-02 32512]
S3 PsSdk31;PsSdk31;c:\windows\system32\drivers\pssdk31.drv [2008-07-06 30272]
S3 PsSdkLBF;PsSdkLBF;c:\windows\system32\drivers\pssdklbf.drv [2008-07-06 37440]
.
- - - - ORPHELINS SUPPRIMES - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://abonnes.lemonde.fr/
mWindow Title =
uInternet Settings,ProxyOverride = *.local
IE: &Tout télécharger avec FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Télécharger avec FlashGet - c:\program files\FlashGet\jc_link.htm
IE: &Télécharger avec NetTransport - c:\program files\NetTransport 2\NTAddLink.html
IE: Afficher cette page dans Firefox - file://c:\documents and settings\Patrick\Application Data\Mozilla\Firefox\Profiles\[u]0/u1t6xtq9.default\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewpage.html
IE: Ajouter à Kaspersky Anti-Bannière - c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Envoyer au périphérique &Bluetooth... - c:\program files\Belkin\Bluetooth Software\btsendto_ie_ctx.htm
IE: Ouvrir la cible dans Firefox - file://c:\documents and settings\Patrick\Application Data\Mozilla\Firefox\Profiles\[u]0/u1t6xtq9.default\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewlink.html
IE: Tout t&élécharger avec NetTransport - c:\program files\NetTransport 2\NTAddList.html
IE: Translate with &Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
IE: Télécharger avec &BitSpirit - c:\program files\BitSpirit\bsurl.htm
Handler: copernicagent - {A979B6BD-E40B-4A07-ABDD-A62C64A4EBF6} - c:\progra~1\COPERN~1\COPERN~1.DLL
Handler: copernicagentcache - {AAC34CFD-274D-4A9D-B0DC-C74C05A67E1D} - c:\progra~1\COPERN~1\COPERN~1.DLL
Handler: ms-its51 - {F6F1E82D-DE4D-11D2-875C-0000F8105754} - c:\program files\Fichiers communs\Microsoft Shared\Information Retrieval\itss51.dll
DPF: {09CC593B-E8A9-4491-927D-A3E33534DDD4} - hxxp://m6video.m6.fr/1click/install/files/installer2.cab
FF - ProfilePath - c:\documents and settings\Patrick\Application Data\Mozilla\Firefox\Profiles\[u]0/u1t6xtq9.default\
FF - prefs.js: browser.search.selectedEngine - Wikipédia (Français)
FF - prefs.js: browser.startup.homepage - hxxp://abonnes.lemonde.fr/
FF - component: c:\documents and settings\Patrick\Application Data\Mozilla\Firefox\Profiles\[u]0/u1t6xtq9.default\extensions\{DD43485F-44CC-4452-A6C6-69356A7E33DA}\platform\WINNT_x86-msvc\components\ahWinUtils_32.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbabelgum.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPNTCatcher.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPNTCatcherAudio.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPNTCatcherVideo.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npvirtools.dll
---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.homepage.dontask - true.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-28 13:32:59
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PsSdk31]
"ImagePath"="\??\c:\windows\system32\Drivers\pssdk31.drv"
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PsSdkLBF]
"ImagePath"="\??\c:\windows\system32\Drivers\pssdklbf.drv"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(656)
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\windows\system32\klogon.dll
- - - - - - - > 'lsass.exe'(712)
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\dnsq.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\miscr3.dll
c:\program files\Kaspersky Lab\Kaspersky Internet Security 7.0\fssync.dll
.
Heure de fin: 2009-01-28 13:35:06
ComboFix-quarantined-files.txt 2009-01-28 12:35:04
ComboFix2.txt 2008-11-06 18:42:07
ComboFix3.txt 2008-11-05 13:41:18
ComboFix4.txt 2008-11-04 18:33:35
ComboFix5.txt 2009-01-26 21:45:55
Avant-CF: 31,215,730,688 octets libres
Après-CF: 31,191,162,880 octets libres
265 --- E O F --- 2009-01-13 18:28:24