Tout a fonctionné, du moins logiquement.. Ci-joint Compte-Rendu
ComboFix 09-02-02.04 - max 2009-02-03 22:07:06.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.958.613 [GMT 1:00]
Lancé depuis: c:\documents and settings\max\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Application Data\CrucialSoft Ltd
c:\windows\config.ini
c:\windows\system32\Drivers\TDSSmvpt.sys
c:\windows\system32\TDSShrhx.dll
c:\windows\system32\TDSSkgbi.log
c:\windows\system32\TDSSoiqn.dll
c:\windows\system32\TDSSotqo.dll
c:\windows\system32\TDSSwryv.dat
c:\windows\system32\TDSSxnjt.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_PACKET
-------\Legacy_TDSSSERV.SYS
-------\Service_TDSSserv.sys
((((((((((((((((((((((((((((( Fichiers créés du 2009-01-03 au 2009-02-03 ))))))))))))))))))))))))))))))))))))
.
2009-02-03 20:52 . 2009-02-03 20:54 <REP> d-------- C:\Rooter$
2009-02-03 19:14 . 2009-02-03 19:14 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-03 19:14 . 2009-01-14 16:11 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-03 19:14 . 2009-01-14 16:11 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-03 12:42 . 2009-01-19 15:35 15,688 --a------ c:\windows\system32\lsdelete.exe
2009-02-03 12:16 . 2009-02-03 12:16 <REP> d-------- c:\program files\Lavasoft
2009-02-03 12:16 . 2009-02-03 12:16 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-03 12:16 . 2009-02-03 12:16 <REP> d--h-c--- c:\documents and settings\All Users\Application Data\{2BAE6915-8510-4B9F-B498-02DA86258AA0}
2009-02-03 12:16 . 2009-01-19 15:35 64,160 --a------ c:\windows\system32\drivers\Lbd.sys
2009-02-03 09:51 . 2009-02-03 09:54 <REP> d-------- c:\program files\WinClamAVShield
2009-02-03 09:08 . 2009-02-03 09:49 <REP> d-------- c:\program files\Spyware Terminator
2009-02-03 09:08 . 2009-02-03 09:49 <REP> d-------- c:\documents and settings\max\Application Data\Spyware Terminator
2009-02-03 09:08 . 2009-02-03 09:49 <REP> d-------- c:\documents and settings\All Users\Application Data\Spyware Terminator
2009-02-03 09:08 . 2009-02-03 09:08 141,312 --a------ c:\windows\system32\drivers\sp_rsdrv2.sys
2009-02-03 08:43 . 2009-02-03 08:43 <REP> d-------- c:\program files\ClamWin
2009-02-03 08:43 . 2009-02-03 08:43 <REP> d-------- c:\documents and settings\max\Application Data\.clamwin
2009-02-03 08:43 . 2009-02-03 08:43 <REP> d-------- c:\documents and settings\All Users\.clamwin
2009-02-02 20:37 . 2009-02-02 20:37 <REP> d--h----- C:\$AVG8.VAULT$
2009-02-02 11:35 . 2009-02-03 08:37 <REP> d-------- c:\windows\ClamWin Portable
2009-02-02 10:48 . 2004-08-20 11:30 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage réseau
2009-02-02 10:48 . 2004-08-20 11:30 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage d'impression
2009-02-02 10:48 . 2004-08-20 11:30 <REP> d--h----- c:\documents and settings\Administrateur\Modèles
2009-02-02 10:48 . 2006-12-09 10:25 <REP> dr------- c:\documents and settings\Administrateur\Mes documents
2009-02-02 10:48 . 2004-08-20 11:30 <REP> dr------- c:\documents and settings\Administrateur\Menu Démarrer
2009-02-02 10:48 . 2009-02-03 20:49 <REP> dr------- c:\documents and settings\Administrateur\Favoris
2009-02-02 10:48 . 2009-02-02 11:04 <REP> d-------- c:\documents and settings\Administrateur\Bureau
2009-02-02 10:48 . 2009-02-03 11:55 <REP> d-------- c:\documents and settings\Administrateur
2009-02-02 10:44 . 2009-02-02 11:04 116,453,622 --a------ c:\documents and settings\Administrateur\sdat5513.exe
2009-01-27 13:25 . 1996-08-20 20:37 15,840 --a------ c:\windows\system32\Machnm1.exe
2009-01-27 13:25 . 2005-09-25 16:37 5,632 --a------ c:\windows\system32\Machnm64.sys
2009-01-27 13:25 . 2009-01-27 13:25 3,120 --a------ c:\windows\system32\118290.54
2009-01-27 13:25 . 2009-01-27 13:25 3,120 --a------ c:\windows\118294.78
2009-01-27 13:25 . 2003-08-13 00:27 2,304 --a------ c:\windows\system32\Machnm32.sys
2009-01-18 20:11 . 2009-01-18 20:11 118 --a------ c:\windows\system32\MRT.INI
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-03 18:14 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-02-03 10:55 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2009-02-03 08:49 --------- d-----w c:\program files\Azureus
2009-01-28 21:15 45,368 ----a-w c:\documents and settings\max\Application Data\wklnhst.dat
2009-01-27 12:25 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-25 18:36 --------- d-----w c:\documents and settings\max\Application Data\Canon
2009-01-21 18:51 --------- d-----w c:\documents and settings\max\Application Data\OpenOffice.org2
2008-12-24 15:16 --------- d-----w c:\program files\AVG
2008-12-24 12:15 --------- d-----w c:\program files\Panda Security
2008-12-24 12:08 --------- d-----w c:\program files\Trend Micro
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-12-06 14:41 --------- d-----w c:\program files\Java
2008-12-04 12:12 --------- d-----w c:\documents and settings\max\Application Data\U3
2008-10-26 20:15 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLdw.DAT
2008-10-26 20:12 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT
2007-12-03 18:09 32 -c--a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2008-03-25 19:19 168 -csh--r c:\windows\system32\2D236C520D.sys
2008-03-25 19:19 5,018 -csha-w c:\windows\system32\KGyGaAvL.sys
2008-10-07 19:36 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008100720081008\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"SetDefaultMIDI"="MIDIDef.exe" [2004-12-22 c:\windows\MIDIDEF.EXE]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-23 7630848]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-08-23 86016]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-06 136600]
"DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 94208]
"CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-10-31 57344]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"VoiceCenter"="c:\program files\Creative\VoiceCenter\AndreaVC.exe" [2006-02-16 1118208]
"DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940]
"ISUSPM Startup"="c:\progra~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"Demon"="c:\progra~1\MESSAG~1\Demon.exe" [2002-09-03 40960]
"SpeedTouch USB Diagnostics"="c:\program files\Alcatel\SpeedTouch USB\Dragdiag.exe" [2002-06-06 861184]
"PCSuiteTrayApplication"="c:\progra~1\Nokia\NOKIAP~1\LAUNCH~1.EXE" [2006-06-15 229376]
"BJCFD"="c:\program files\BroadJump\Client Foundation\CFD.exe" [2003-01-27 376912]
"Omnipage"="c:\program files\ScanSoft\OmniPageSE\opware32.exe" [2002-06-03 49152]
"Motive SmartBridge"="c:\progra~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe" [2005-08-24 438359]
"AppleSyncNotifier"="c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"ClamWin"="c:\program files\ClamWin\bin\ClamTray.exe" [2008-11-09 86016]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-02-03 509784]
"nwiz"="nwiz.exe" [2006-08-23 c:\windows\system32\nwiz.exe]
"SigmatelSysTrayApp"="stsystra.exe" [2006-08-15 c:\windows\stsystra.exe]
"MBMon"="CTMBHA.DLL" [2006-06-29 c:\windows\system32\CTMBHA.DLL]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\max\Menu D‚marrer\Programmes\D‚marrage\
Nikon Monitor.lnk - c:\program files\Fichiers communs\Nikon\Monitor\NkMonitor.exe [2007-10-18 479232]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
LE COMPAGNON CLUB.lnk - c:\program files\Club-Internet\Le Compagnon Club\bin\matcli.exe [2007-01-31 217088]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\[u]0/u\[u]0/ulsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WooCnxMon]
-----c--- 2002-09-05 16:44 24576 c:\progra~1\Wanadoo\CnxMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOTASKBARICON]
-----c--- 2002-09-05 16:44 45056 c:\progra~1\Wanadoo\TaskBarIcon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOWATCH]
-----c--- 2002-09-05 16:44 20480 c:\progra~1\Wanadoo\Watch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\TEMP\\CI_HITACHI\\MAJ_Hitachi.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\Soulseek-Test\\slsk.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-02-03 64160]
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [2008-12-24 28544]
R2 ADSLAutoconnect;ADSLAutoconnect;c:\program files\ADSL Autoconnect\ADSL Autoconnect.exe [2006-12-23 446464]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-01-19 950096]
S3 FileObjInfo;STFileDriver;c:\documents and settings\All Users\Application Data\Spyware Terminator\fileobjinfo.sys [2009-02-03 5632]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{97f3cda0-8fab-11dd-abca-00188b754775}]
\Shell\AutoRun\command - K:\memorybar.exe
.
Contenu du dossier 'Tâches planifiées'
2009-02-03 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-02-03 21:35]
2008-12-05 c:\windows\Tasks\Analyse McAfee.com - Mon ordinateur (JOU-JOU-max).job
- c:\program files\mcafee.com\vso\mcmnhdlr.exe []
2008-12-05 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uInternet Connection Wizard,ShellNext = hxxp://127.0.0.1:4664/first_usage&s=NFr07MudO-XULBR-C26nVoij5Ak
uInternet Settings,ProxyOverride = 127.0.0.1;*.local
DPF: Microsoft XML Parser for Java - file:///C:/WINDOWS/Java/classes/xmldso.cab
DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.3.5.cab
DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.new2.foto.com/ImageUploader5.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.zebulon.fr/scan8/oscan8.cab
DPF: {FB90BA05-66E6-4C56-BCD3-D65B0F7EBA39} - hxxp://webalbum.foto.com/SFUploader/SpeedUploader.cab
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-03 22:10:40
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Fichiers communs\Creative Labs Shared\Service\CreativeLicensing.exe
c:\windows\system32\CTSVCCDA.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\rundll32.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\Club-Internet\Le Compagnon Club\bin\mpbtn.exe
.
**************************************************************************
.
Heure de fin: 2009-02-03 22:18:39 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-02-03 21:18:19
Avant-CF: 126 027 288 576 octets libres
Après-CF: 126,976,647,168 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
213 --- E O F --- 2009-01-18 19:11:36