Voici le rapport Combofix (PS: j'ai pas vu le message "Type 1 to continue, or 2 to abort" à aucun moment, mais le scan s'est déroulé normalement) :
ComboFix 09-03-23.01 - Guillaume LAGOUE 2009-03-25 16:19:28.3 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.447.144 [GMT 4:00]
Lancé depuis: c:\documents and settings\Guillaume LAGOUE.NOM-AA766E5D725\Bureau\combofix.exe
Commutateurs utilisés :: c:\documents and settings\Guillaume LAGOUE.NOM-AA766E5D725\Bureau\CFScript.txt
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated)
FW: Norton Internet Worm Protection *disabled*
* Un nouveau point de restauration a été créé
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-25 au 2009-03-25 ))))))))))))))))))))))))))))))))))))
.
2009-03-25 14:38 . 2009-03-25 14:38 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-25 14:38 . 2009-03-25 14:38 <REP> d-------- c:\documents and settings\Guillaume LAGOUE.NOM-AA766E5D725\Application Data\Malwarebytes
2009-03-25 14:38 . 2009-03-25 14:38 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-25 14:38 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-25 14:38 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-25 12:16 . 2009-03-25 12:17 <REP> d-------- C:\rsit
2009-03-25 10:10 . 2009-03-25 10:10 <REP> d-------- c:\program files\Enigma Software Group
2009-03-24 21:46 . 2009-03-24 21:46 244 --ah----- C:\sqmnoopt01.sqm
2009-03-24 21:46 . 2009-03-24 21:46 232 --ah----- C:\sqmdata01.sqm
2009-03-23 19:00 . 2009-03-23 19:00 <REP> dr------- c:\documents and settings\NetworkService\Favoris
2009-03-23 18:08 . 2009-03-23 18:08 126,468 --a------ c:\windows\system32\msxml71.dll.ren
2009-03-23 15:45 . 2009-03-23 15:45 <REP> d-------- c:\program files\360desktop
2009-03-23 15:45 . 2009-03-23 15:45 <REP> d-------- c:\documents and settings\Guillaume LAGOUE.NOM-AA766E5D725\Application Data\360desktop
2009-03-23 15:25 . 2009-03-23 15:25 <REP> d-------- c:\program files\X'nBeep 1.1
2009-03-23 15:19 . 2009-03-23 15:19 <REP> d-------- c:\program files\Vista Buttons Trial
2009-03-21 22:18 . 2009-03-21 22:18 <REP> d-------- c:\documents and settings\All Users\Application Data\Mushroom Age
2009-03-14 12:25 . 2009-03-25 09:24 <REP> d-------- c:\documents and settings\All Users\Application Data\Google Updater
2009-03-14 12:24 . 2009-03-14 12:36 <REP> d-------- c:\program files\Google
2009-03-05 19:03 . 2009-03-05 19:03 <REP> d-------- c:\documents and settings\All Users\Application Data\SpinTop Games
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-25 12:27 --------- d-----w c:\program files\Wanadoo
2009-03-25 08:54 --------- d-----w c:\program files\CCleaner
2009-03-25 06:14 --------- d-----w c:\program files\Spyware Terminator
2009-03-25 06:14 --------- d-----w c:\documents and settings\All Users\Application Data\Spyware Terminator
2009-03-25 05:48 --------- d-----w c:\documents and settings\Guillaume LAGOUE.NOM-AA766E5D725\Application Data\Spyware Terminator
2009-03-24 17:58 --------- d-----w c:\program files\Trend Micro
2009-03-24 16:35 --------- d-----w c:\program files\Naval Strike
2009-03-24 16:35 --------- d-----w c:\program files\Feeding Frenzy
2009-03-23 11:44 --------- d-----w c:\program files\Fichiers communs\Wise Installation Wizard
2009-03-22 16:08 --------- d-----w c:\program files\QuickTime
2009-03-22 12:09 --------- d-----w c:\program files\Radio Fr Solo
2009-03-21 19:07 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-03-21 17:56 --------- d-----w c:\program files\Oberon Media
2009-03-21 16:54 --------- d-----w c:\documents and settings\All Users\Application Data\Flood Light Games
2009-03-21 09:24 --------- d-----w c:\program files\GamesBar
2009-03-18 09:08 --------- d-----w c:\documents and settings\Guillaume LAGOUE.NOM-AA766E5D725\Application Data\Image Zone Express
2009-03-13 12:29 --------- d-----w c:\program files\TubeMaster
2009-02-27 09:32 --------- d-----w c:\program files\Fichiers communs\Adobe
2009-02-15 18:00 --------- d-----w c:\program files\AOL 9.0b
2009-02-15 18:00 --------- d-----w c:\program files\Andre Agassi Tennis
2009-02-12 18:49 --------- d-----w c:\documents and settings\All Users\Application Data\EscapeTheMuseum
2009-01-28 19:02 --------- d-----w c:\documents and settings\All Users\Application Data\Last.fm
2009-01-28 19:00 --------- d-----w c:\program files\Last.fm
2008-07-30 10:16 26,040 ----a-w c:\documents and settings\Guillaume LAGOUE.NOM-AA766E5D725\Application Data\GDIPFONTCACHEV1.DAT
2007-07-11 17:57 3,655,608 ----a-w c:\program files\FLV PlayerRCATSetup.exe
2007-07-11 17:56 25,990,432 ----a-w c:\program files\FLV PlayerRCSetup.exe
2007-03-09 08:12 27,648 --sha-w c:\windows\system32\AVSredirect.dll
2006-05-03 10:06 163,328 --sh--r c:\windows\system32\flvDX.dll
2007-02-21 11:47 31,744 --sh--r c:\windows\system32\msfDX.dll
2008-06-10 17:07 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008061020080611\index.dat
2008-07-18 06:59 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008071820080719\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"WOOKIT"="c:\program files\Wanadoo\Shell.exe" [2008-06-27 122880]
"X'nBeep"="c:\program files\X'nBeep 1.1\XnBeep.exe" [2007-01-06 1067520]
"360desktop"="c:\program files\360desktop\360desktop.exe" [2008-12-22 1307904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WOOWATCH"="c:\progra~1\Wanadoo\Watch.exe" [2004-08-23 20480]
"WOOTASKBARICON"="c:\progra~1\Wanadoo\GestMaj.exe" [2008-05-17 32768]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-01-31 385024]
"SpywareTerminator"="c:\program files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-05-01 1817600]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-20 266497]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
"VTTimer"="VTTimer.exe" [2005-03-08 c:\windows\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2006-03-23 c:\windows\system32\VTTrayp.exe]
"SoundMan"="SOUNDMAN.EXE" [2006-06-21 c:\windows\SOUNDMAN.EXE]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 c:\windows\system32\bthprops.cpl]
"C-Media Mixer"="Mixer.exe" [2003-03-20 c:\windows\mixer.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-06-07 553021]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2007-02-05 118784]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.I420"= i420vfw.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\[u]0/ustera
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Wanadoo\\WOOBrowser\\WOOBrowser.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"c:\\Program Files\\360desktop\\360desktop.exe"=
"c:\\Program Files\\360desktop\\360manager.exe"=
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\system32\drivers\sp_rsdrv2.sys [2008-02-23 141312]
R2 X4HSX32Ex;X4HSX32Ex;c:\program files\Player Metaboli\X4HSX32Ex.sys [2008-06-20 29856]
S0 fsflt;fsflt;c:\windows\system32\Drivers\fsflt.sys --> c:\windows\system32\Drivers\fsflt.sys [?]
S2 gupdate1c9a47fd27536ce;Service Google Update (gupdate1c9a47fd27536ce);c:\program files\Google\Update\GoogleUpdate.exe [2009-03-14 133104]
S3 jfdcd;jfdcd;\??\c:\docume~1\ELODIE~1.NOM\LOCALS~1\Temp\jfdcd.sys --> c:\docume~1\ELODIE~1.NOM\LOCALS~1\Temp\jfdcd.sys [?]
.
Contenu du dossier 'Tâches planifiées'
2009-03-16 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
2009-03-23 c:\windows\Tasks\At1.job
- c:\windows\system32\2iy30rrX.exe []
2009-03-23 c:\windows\Tasks\At10.job
- c:\windows\system32\2iy30rrX.exe []
2009-03-25 c:\windows\Tasks\At11.job
- c:\windows\system32\2iy30rrX.exe []
2009-03-25 c:\windows\Tasks\At12.job
- c:\windows\system32\2iy30rrX.exe []
2009-03-25 c:\windows\Tasks\At13.job
- c:\windows\system32\2iy30rrX.exe []
2009-03-25 c:\windows\Tasks\At14.job
- c:\windows\system32\2iy30rrX.exe []
2009-03-25 c:\windows\Tasks\At15.job
- c:\windows\system32\2iy30rrX.exe []
2009-03-25 c:\windows\Tasks\At16.job
- c:\windows\system32\2iy30rrX.exe []
2009-03-24 c:\windows\Tasks\At17.job
- c:\windows\system32\2iy30rrX.exe []
2009-03-24 c:\windows\Tasks\At18.job
- c:\windows\system32\2iy30rrX.exe []
2009-03-24 c:\windows\Tasks\At19.job
- c:\windows\system32\2iy30rrX.exe []
2009-03-23 c:\windows\Tasks\At2.job
- c:\windows\system32\2iy30rrX.exe []
2009-03-24 c:\windows\Tasks\At20.job
- c:\windows\system32\2iy30rrX.exe []
2009-03-24 c:\windows\Tasks\At21.job
- c:\windows\system32\2iy30rrX.exe []
2009-03-24 c:\windows\Tasks\At22.job
- c:\windows\system32\2iy30rrX.exe []
2009-03-24 c:\windows\Tasks\At23.job
- c:\windows\system32\2iy30rrX.exe []
2009-03-24 c:\windows\Tasks\At24.job
- c:\windows\system32\2iy30rrX.exe []
2009-03-23 c:\windows\Tasks\At3.job
- c:\windows\system32\2iy30rrX.exe []
2009-03-23 c:\windows\Tasks\At4.job
- c:\windows\system32\2iy30rrX.exe []
2009-03-23 c:\windows\Tasks\At5.job
- c:\windows\system32\2iy30rrX.exe []
2009-03-23 c:\windows\Tasks\At6.job
- c:\windows\system32\2iy30rrX.exe []
2009-03-23 c:\windows\Tasks\At7.job
- c:\windows\system32\2iy30rrX.exe []
2009-03-23 c:\windows\Tasks\At8.job
- c:\windows\system32\2iy30rrX.exe []
2009-03-23 c:\windows\Tasks\At9.job
- c:\windows\system32\2iy30rrX.exe []
2009-03-25 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-24 23:36]
2009-03-25 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-14 12:35]
2009-03-25 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
2009-03-25 c:\windows\Tasks\{F897AA24-BDC3-11D1-B85B-00C04FB93981}_NOM-AA766E5D725_Guillaume LAGOUE.job
- c:\windows\system32\mobsync.exe [2008-04-14 06:34]
.
.
------- Examen supplémentaire -------
.
uStart Page =
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
uInternet Connection Wizard,ShellNext = iexplore
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Compare Prices with &Dealio - c:\documents and settings\Guillaume LAGOUE.NOM-AA766E5D725\Application Data\Dealio\kb127\res\DealioSearch.html
IE: Crawler Search - tbr:iemenu
IE: Envoyer au périphérique &Bluetooth... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: { - c:\program files\Messenger\msmsgs.exe
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game12.zylom.com/activex/zylomgamesplayer.cab
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-25 16:29:09
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\a-squared Free\a2service.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\FTRTSVC.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Spyware Terminator\sp_rsser.exe
c:\program files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
c:\windows\system32\searchindexer.exe
c:\windows\system32\rundll32.exe
c:\progra~1\Wanadoo\TaskBarIcon.exe
c:\windows\system32\wscntfy.exe
c:\progra~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
c:\program files\HP\Digital Imaging\bin\hpqste08.exe
c:\windows\system32\searchprotocolhost.exe
c:\windows\system32\searchfilterhost.exe
.
**************************************************************************
.
Heure de fin: 2009-03-25 16:39:41 - La machine a redémarré [Guillaume LAGOUE]
ComboFix-quarantined-files.txt 2009-03-25 12:39:33
ComboFix2.txt 2009-03-25 09:47:08
Avant-CF: 98,657,841,152 octets libres
Après-CF: 98,657,492,992 octets libres
248 --- E O F --- 2009-03-21 21:17:11