Re,
Je poste ici ton rapport Combofix (raccourci, j'ai enlevé le DirLook que tu ne souhaitais pas voir apparaitre)
ComboFix 09-03-22.01 - qwert 2009-03-24 8:44:33.4 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.2038.1508 [GMT 0:00]
Lancé depuis: c:\documents and settings\qwert\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\qwert\Bureau\CFScript.txt
AV: Avira AntiVir PersonalEdition Classic *On-access scanning disabled* (Updated)
* Un nouveau point de restauration a été créé
FILE ::
C:\biin.exe
c:\windows\system32\gasretyw0.VIR
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\biin.exe
c:\windows\system32\drivers\hosts\
c:\windows\system32\gasretyw0.VIR
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-24 au 2009-03-24 ))))))))))))))))))))))))))))))))))))
.
2009-03-23 21:14 . 2009-03-23 21:15 34,362 --a------ c:\windows\system32\vmscon.exe
2009-03-23 21:05 . 2009-03-23 21:05 18,944 --a------ c:\documents and settings\qwert\tvs2.exe
2009-03-23 21:05 . 2009-03-23 21:06 8,552 --a------ c:\documents and settings\qwert\bv2.exe
2009-03-23 12:57 . 2009-03-23 13:03 <REP> d-------- C:\rsit
2009-03-22 00:15 . 2009-03-22 00:15 <REP> d-------- c:\program files\Avira
2009-03-22 00:15 . 2009-03-22 00:15 <REP> d-------- c:\documents and settings\All Users\Application Data\Avira
2009-03-10 22:12 . 2009-03-10 22:12 <REP> d-------- c:\documents and settings\qwert\Application Data\Blender Foundation
2009-03-10 22:11 . 2009-03-10 22:11 <REP> d-------- c:\program files\Blender Foundation
2009-03-09 14:07 . 2009-03-09 14:07 <REP> d-------- c:\documents and settings\qwert\Application Data\.ssh
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-24 08:04 --------- d-----w c:\documents and settings\qwert\Application Data\skypePM
2009-03-24 07:55 --------- d-----w c:\documents and settings\qwert\Application Data\Skype
2009-03-24 07:04 --------- d-----w c:\documents and settings\qwert\Application Data\DNA
2009-03-24 07:04 --------- d-----w c:\documents and settings\qwert\Application Data\BitTorrent
2009-03-24 07:01 --------- d-----w c:\program files\DNA
2009-03-23 22:26 61,196 ----a-w c:\documents and settings\qwert\Application Data\wklnhst.dat
2009-03-23 13:03 --------- d-----w c:\program files\Trend Micro
2009-03-22 14:38 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-03-22 14:34 --------- d-----w c:\documents and settings\qwert\Application Data\FileZilla
2009-02-27 23:49 230,432 ----a-w C:\StiImg.dat
2009-02-19 14:30 --------- d-----w c:\program files\FileZilla FTP Client
2009-02-11 10:19 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 10:19 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-02-07 22:47 --------- d-----w c:\program files\Fichiers communs\Windows Live
2009-02-07 14:48 --------- d-----w c:\program files\LibUSB-Win32
2009-02-04 14:33 --------- d-----w c:\documents and settings\qwert\Application Data\Apple Computer
2009-02-03 15:33 17,761 ----a-w c:\windows\system32\drivers\hosts
2009-01-31 13:16 --------- d-----w c:\program files\Feneris
2009-01-05 20:52 96,229,862 ----a-w C:\Sauv.reg
2008-12-30 16:23 4,952 --sha-r C:\bootfont.bin
2008-12-30 16:13 22,528 --sh--r C:\bootwiz.sys
2008-04-27 14:35 32 -c--a-w c:\documents and settings\All Users\Application Data\ezsid.dat
((((((((((((((((((((((((((((( SnapShot@2009-03-23_20.00.36,06 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-24 08:47:00 16,384 ----atw c:\windows\temp\Perflib_Perfdata_7ac.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{ecdee021-0d17-467f-a1ff-c7a115230949}"= "c:\program files\free-downloads.net\tbfre0.dll" [2008-11-21 1784856]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ecdee021-0d17-467f-a1ff-c7a115230949}]
2008-11-21 14:44 1784856 --a------ c:\program files\free-downloads.net\tbfre0.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{ecdee021-0d17-467f-a1ff-c7a115230949}"= "c:\program files\free-downloads.net\tbfre0.dll" [2008-11-21 1784856]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{ECDEE021-0D17-467F-A1FF-C7A115230949}"= "c:\program files\free-downloads.net\tbfre0.dll" [2008-11-21 1784856]
[HKEY_CLASSES_ROOT\clsid\{ecdee021-0d17-467f-a1ff-c7a115230949}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="c:\program files\Dell Support\DSAgnt.exe" [2006-08-28 395776]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-14 68856]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-03-20 217544]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-23 21755688]
"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-08-11 1124352]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-12-21 342848]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-05 15360]
"BitTorrent"="c:\program files\BitTorrent\bittorrent.exe" [2008-04-29 587568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-07-21 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-07-21 86016]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-07-21 81920]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2006-05-01 843776]
"ISUSPM Startup"="c:\progra~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 221184]
"ISUSScheduler"="c:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2004-07-27 81920]
"RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 118784]
"ANIWZCS2Service"="c:\program files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2007-01-19 49152]
"D-Link D-Link Wireless G DWA-110"="c:\program files\D-Link\D-Link Wireless G DWA-110\AirGCFG.exe" [2007-05-04 1662976]
"Skype Recorder"="c:\program files\Skype Recorder\Skype Recorder.exe" [2008-03-14 720896]
"WD Drive Manager"="c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe" [2008-05-16 430080]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"OSSelectorReinstall"="c:\program files\Fichiers communs\Acronis\Acronis Disk Director\oss_reinstall.exe" [2006-04-12 1261475]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"vmscon"="c:\windows\system32\vmscon.exe" [2009-03-23 34362]
"PMX Daemon"="ICO.EXE" [2007-03-08 c:\windows\system32\ico.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-05 15360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\BitTorrent\\bittorrent.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Dell Support\\DSHelp.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"22:TCP"= 22:TCP:ssh
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-04-27 78416]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-04-27 20560]
R2 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [2008-05-16 102400]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.12.1;c:\windows\system32\drivers\libusb0.sys [2009-02-07 28672]
R3 PAC207;CamMaestro 3.01 DU PC Camera;c:\windows\system32\drivers\PFC027.sys [2005-05-27 162304]
R3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [2008-04-17 18432]
R3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [2008-04-17 14336]
S2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);c:\windows\system32\drivers\e4ldr.sys [2008-10-16 63555]
S3 AVPsys;AVPsys;\??\c:\windows\system32\drivers\cdaudio.sys --> c:\windows\system32\drivers\cdaudio.sys [?]
S3 e4usbaw;USB ADSL2 WAN Adapter;c:\windows\system32\drivers\e4usbaw.sys [2008-10-16 114616]
.
Contenu du dossier 'Tâches planifiées'
2009-03-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.com/
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*
http://fr.search.yahoo.com
IE: E&xporter vers Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
Trusted Zone: https
TCP: {97F80186-6F5A-4787-877D-00ED96AD0D9A} = 212.217.0.1,212.217.0.12
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-24 08:49:29
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'Explorer.EXE'(1272)
c:\windows\system32\msi.dll
c:\program files\Microsoft Office\OFFICE11\msohev.dll
c:\windows\system32\pmxscrll.dll
c:\windows\system32\PMXCOMM.dll
c:\windows\system32\PMXHOOKS.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\snmp.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
c:\windows\system32\PAStiSvc.exe
c:\windows\system32\wscntfy.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\guardgui.exe
c:\windows\system32\pmxmiced.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\guardgui.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\guardgui.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Heure de fin: 2009-03-24 8:51:11 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-03-24 08:51:09
ComboFix2.txt 2009-03-23 20:01:30
Avant-CF: 21 617 491 968 octets libres
Après-CF: 21,599,911,936 octets libres
Merci de ta reponse...c 'est toujours un TR/...mais pas tout à fait identique et c'est toujours dans C mais pas dans le même emplacement.
Merci