Voici le rapport de Combofix ! ;)
ComboFix 09-04-04.01 - Compaq_Proprietaire 2009-04-09 12:45:32.1 - NTFSx86
Microsoft Windows XP Edition familiale 5.1.2600.3.1251.7.1036.18.958.599 [GMT 2:00]
Running from: c:\documents and settings\Compaq_Proprietaire\Bureau\moi.exe
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\COMPAQ~1\LOCALS~1\Temp\tmp2.tmp
c:\docume~1\COMPAQ~1\LOCALS~1\Temp\winlogon.exe
c:\documents and settings\Christine\Application Data\WinAntiVirus Pro 2006
c:\documents and settings\Christine\Application Data\WinAntiVirus Pro 2006\Logs\update.log
c:\documents and settings\Christine\Application Data\WinAntiVirus Pro 2006\PGE.dat
c:\documents and settings\Compaq_Proprietaire\Application Data\HbTools_Icons
c:\documents and settings\Compaq_Proprietaire\Application Data\HbTools_Icons\games2.ico
c:\documents and settings\Compaq_Proprietaire\Application Data\HbTools_Icons\Registryrepair.ico
c:\documents and settings\Compaq_Proprietaire\Application Data\HbTools_Icons\wallpapere1.ico
c:\documents and settings\Compaq_Proprietaire\Application Data\inst.exe
c:\documents and settings\Compaq_Proprietaire\Application Data\WinAntiVirus Pro 2006
c:\documents and settings\Compaq_Proprietaire\Local Settings\Application Data\cgkcqua.dat
c:\documents and settings\Compaq_Proprietaire\Local Settings\Application Data\cgkcqua_nav.dat
c:\documents and settings\Compaq_Proprietaire\Local Settings\Application Data\cgkcqua_navps.dat
c:\documents and settings\Eric\Application Data\WinAntiVirus Pro 2006
c:\documents and settings\Eric\Application Data\WinAntiVirus Pro 2006\Logs\update.log
c:\documents and settings\Eric\Application Data\WinAntiVirus Pro 2006\PGE.dat
c:\program files\Hotbar
c:\program files\mailskinner
c:\program files\mailskinner\autosmiley.xml
c:\program files\mailskinner\OESkinner.dll
c:\windows\IE4 Error Log.txt
c:\windows\msskinner
c:\windows\msskinner\msbackup.dat
c:\windows\system32\agitedif.ini
c:\windows\system32\ahirafed.ini
c:\windows\system32\ajukesub.ini
c:\windows\system32\akosugat.ini
c:\windows\system32\akusubet.ini
c:\windows\system32\amozujoj.ini
c:\windows\system32\asewowel.ini
c:\windows\system32\asiwuyol.ini
c:\windows\system32\bcqlfcojwy.dat
c:\windows\system32\bcqlfcojwy_nav.dat
c:\windows\system32\bcqlfcojwy_navps.dat
c:\windows\system32\danuzihi.dll
c:\windows\system32\drivers\vspf_hk5.sys
c:\windows\system32\ejakisan.ini
c:\windows\system32\ekirogon.ini
c:\windows\system32\eraperut.ini
c:\windows\system32\eweleniv.ini
c:\windows\system32\eyapagev.ini
c:\windows\system32\fijiveni.dll
c:\windows\system32\gebrnhld.dat
c:\windows\system32\gebrnhld_nav.dat
c:\windows\system32\gebrnhld_navps.dat
c:\windows\system32\ibefodak.ini
c:\windows\system32\igahiraw.ini
c:\windows\system32\ikojekaj.ini
c:\windows\system32\ipozazil.ini
c:\windows\system32\itowigir.ini
c:\windows\system32\iwodogaz.ini
c:\windows\system32\lijahaji.dll
c:\windows\system32\mdm.exe
c:\windows\system32\nawonane.dll
c:\windows\system32\nvs2.inf
c:\windows\system32\obitadoz.ini
c:\windows\system32\obuviges.ini
c:\windows\system32\ogotagah.ini
c:\windows\system32\ohemunev.ini
c:\windows\system32\ojapuwuv.ini
c:\windows\system32\ojapuwuv.ini2
c:\windows\system32\ojapuwuv.tmp
c:\windows\system32\olupifok.ini
c:\windows\system32\oposonel.ini
c:\windows\system32\osamonon.ini
c:\windows\system32\osapajav.ini
c:\windows\system32\otepewon.ini
c:\windows\system32\owisesum.ini
c:\windows\system32\paduzebe.dll
c:\windows\system32\real.txt
c:\windows\system32\rofefuzi.dll
c:\windows\system32\soyitajo.dll
c:\windows\system32\stera.log
c:\windows\system32\ubizelem.ini
c:\windows\system32\ubodidem.ini
c:\windows\system32\ubofutad.ini
c:\windows\system32\uhulayed.ini
c:\windows\system32\ulibujam.ini
c:\windows\system32\umajafey.ini
c:\windows\system32\upolahat.ini
c:\windows\system32\upufiteb.ini
c:\windows\system32\usidepob.ini
c:\windows\system32\usozoven.ini
c:\windows\system32\uzaligey.ini
c:\windows\system32\uzebusaw.ini
c:\windows\system32\vegapaye.dll
c:\windows\system32\yefajamu.dll
c:\windows\system32\yemavema.dll
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_BOONTY_GAMES
-------\Service_Boonty Games
((((((((((((((((((((((((( Files Created from 2009-03-09 to 2009-04-09 )))))))))))))))))))))))))))))))
.
2009-04-09 12:39 . 2006-03-03 00:42 73,728 --a------ C:\pv.exe
2009-04-09 12:38 . 2009-04-09 12:39 <REP> d-------- C:\32788R22FWJFW
2009-04-07 20:37 . 2009-04-07 20:37 <REP> d-------- c:\program files\Trend Micro
2009-04-06 10:06 . 2009-04-06 10:06 <REP> d-------- c:\windows\system32\fr
2009-04-06 10:06 . 2009-04-06 10:06 <REP> d-------- c:\windows\system32\bits
2009-04-06 10:06 . 2009-04-06 10:06 <REP> d-------- c:\windows\l2schemas
2009-04-06 10:04 . 2009-04-06 10:04 <REP> d-------- c:\windows\ServicePackFiles
2009-04-06 09:57 . 2009-04-06 09:57 <REP> d-------- c:\windows\EHome
2009-04-03 13:16 . 2008-04-14 04:33 69,120 --------- c:\windows\system32\wlanapi.dll
2009-04-03 13:16 . 2004-08-03 22:29 25,471 --------- c:\windows\system32\drivers\watv10nt.sys
2009-04-03 13:16 . 2004-08-03 22:29 22,271 --------- c:\windows\system32\drivers\watv06nt.sys
2009-04-03 13:16 . 2008-04-13 20:43 14,208 --------- c:\windows\system32\drivers\wacompen.sys
2009-04-03 13:16 . 2004-08-03 22:29 11,935 --------- c:\windows\system32\drivers\wadv11nt.sys
2009-04-03 13:16 . 2004-08-03 22:29 11,871 --------- c:\windows\system32\drivers\wadv09nt.sys
2009-04-03 13:16 . 2004-08-03 22:29 11,807 --------- c:\windows\system32\drivers\wadv07nt.sys
2009-04-03 13:16 . 2004-08-03 22:29 11,295 --------- c:\windows\system32\drivers\wadv08nt.sys
2009-04-03 13:14 . 2004-08-03 22:41 1,041,536 --------- c:\windows\system32\drivers\hsfdpsp2.sys
2009-03-22 21:49 . 2009-03-22 21:49 <REP> d-------- C:\Sounds
2009-03-22 21:47 . 2009-03-22 21:47 <REP> d-------- c:\program files\LG Electronics
2009-03-22 21:47 . 2008-09-04 07:27 24,832 --a------ c:\windows\system32\drivers\lgusbmodem.sys
2009-03-22 21:47 . 2008-09-04 07:28 19,968 --a------ c:\windows\system32\drivers\lgusbdiag.sys
2009-03-22 21:47 . 2008-09-04 07:27 13,056 --a------ c:\windows\system32\drivers\lgusbbus.sys
2009-03-22 21:45 . 2009-03-28 19:35 <REP> d-------- c:\program files\LG PC Suite II
2009-03-22 21:45 . 2009-03-22 21:45 <REP> d-------- c:\documents and settings\Compaq_Proprietaire\Application Data\LG Electronics
2009-03-22 21:45 . 2005-03-18 17:55 630,784 --a------ c:\windows\system32\vsflex8u.ocx
2009-03-22 21:45 . 2005-09-26 23:55 419,240 --a------ c:\windows\system32\Vsflex7L.ocx
2009-03-22 21:43 . 2009-03-22 21:43 <REP> d-------- c:\documents and settings\Compaq_Proprietaire\Application Data\InstallShield
2009-03-15 18:55 . 2009-03-15 18:55 <REP> d-------- c:\program files\Live-Player
2009-03-15 18:55 . 2009-03-15 18:55 <REP> d-------- c:\documents and settings\Compaq_Proprietaire\Application Data\live-player
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-08 09:53 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-04-02 15:07 --------- d-----w c:\program files\Microsoft Silverlight
2009-03-28 19:32 --------- d-----w c:\documents and settings\Compaq_Proprietaire\Application Data\Pro Cycling Manager 2008
2009-03-28 10:56 --------- d-----w c:\program files\Windows Live Safety Center
2009-03-22 19:47 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-13 11:17 --------- d-----w c:\program files\Messenger Plus! Live
2009-02-11 16:53 --------- d-----w c:\program files\Google
2008-08-23 10:33 324 ----a-w c:\documents and settings\Christine\Application Data\wklnhst.dat
2008-05-22 16:30 0 ----a-w c:\documents and settings\Compaq_Proprietaire\zphqix.exe
2008-04-25 16:32 0 ----a-w c:\documents and settings\Compaq_Proprietaire\tovxqt.exe
2008-04-24 16:31 0 ----a-w c:\documents and settings\Compaq_Proprietaire\hetqia.exe
2008-02-20 12:08 47,360 ----a-w c:\documents and settings\Compaq_Proprietaire\Application Data\pcouffin.sys
2007-01-14 17:28 94,080 ----a-w c:\documents and settings\Compaq_Proprietaire\Application Data\ezplay.sys
2007-01-14 17:28 81,920 ----a-w c:\documents and settings\Compaq_Proprietaire\Application Data\ezpinst.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-04 68856]
"Shareaza"="c:\program files\Shareaza\Shareaza.exe" [2007-02-05 4354048]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"Veoh"="c:\program files\Veoh Networks\Veoh\VeohClient.exe" [2008-08-13 3660848]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-14 344064]
"KBD"="c:\hp\KBD\KBD.EXE" [2005-02-03 61440]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-22 237568]
"HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-02-17 49152]
"HyperappelPL2003"="c:\program files\Larousse\Petit Larousse 2003\bin\HiPL2002popup.exe" [2002-07-08 114688]
"ISUSPM Startup"="c:\progra~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-28 221184]
"ISUSScheduler"="c:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2004-07-28 81920]
"BigDog305"="c:\windows\VM305_STI.EXE" [2005-08-05 61440]
"AliceSAV"="c:\program files\TechCity Solutions\AliceSAV\AliceAgent.exe" [2005-12-16 81408]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"ClamWin"="c:\program files\ClamWin\bin\ClamTray.exe" [2008-11-09 86016]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 c:\windows\ALCXMNTR.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\[u]0
/ustera\[u]0
/ulsdelete
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Cyanide\\Pro Cycling Manager - Season 2008\\PCM.exe"=
"c:\\Program Files\\Cyanide\\Pro Cycling Manager - Season 2008\\Autorun\\Exe\\Autorun.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Microsoft Office\\Office\\OSA9.EXE"=
"c:\\Program Files\\Larousse\\Petit Larousse 2003\\bin\\HIPL2002Popup.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\usnsvc.exe"=
"c:\\WINDOWS\\system32\\ati2evxx.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\Google\\Common\\Google Updater\\GoogleUpdaterService.exe"=
"c:\\WINDOWS\\system32\\spoolsv.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\iPod\\bin\\iPodService.exe"=
"c:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"=
"c:\\Program Files\\iTunes\\iTunesHelper.exe"=
"c:\\hp\\KBD\\kbd.exe"=
"c:\\WINDOWS\\VM305_STI.EXE"=
"c:\\Program Files\\Fichiers communs\\Apple\\Mobile Device Support\\bin\\AppleMobileDeviceService.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R1 appdrv01;Application Driver (01);c:\windows\system32\drivers\appdrv01.sys [2008-07-24 3468904]
R2 acedrv11;acedrv11;c:\windows\system32\drivers\acedrv11.sys [2008-07-30 277736]
R3 USB_RNDIS_51;Broadcom USB Remote NDIS Device Driver;c:\windows\system32\drivers\usb8023.sys [2004-08-05 12800]
S2 appdrvrem01;Application Driver Auto Removal Service (01);c:\windows\System32\appdrvrem01.exe svc --> c:\windows\System32\appdrvrem01.exe svc [?]
S3 Fadpu16E;Fadpu16E;\??\c:\docume~1\COMPAQ~1\LOCALS~1\Temp\Fadpu16E.sys --> c:\docume~1\COMPAQ~1\LOCALS~1\Temp\Fadpu16E.sys [?]
S3 ZSMC0305;VIMICRO USB PC Camera V;c:\windows\system32\drivers\usbVM305.sys [2007-01-27 391099]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b02715c2-1bbe-11de-8ae7-0016381b66ac}]
\Shell\AutoRun\command - J:\USBAutoRun.exe
.
Contents of the 'Scheduled Tasks' folder
2009-04-06 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-04-09 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-24 17:15]
2009-04-09 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDetect.exe []
.
- - - - ORPHANS REMOVED - - - -
BHO-{7a34dd14-d53c-4fc8-a322-e59750013f1c} - c:\windows\system32\tumtbr.dll
HKCU-Run-Odebit Multimedia V2 - c:\program files\Odebit Multimedia\V2\Odebit.exe
HKCU-Run-cgkcqua - c:\documents and settings\compaq_proprietaire\local settings\application data\cgkcqua.exe
HKLM-Run-PS2 - c:\windows\system32\ps2.exe
HKLM-Run-Adobe Photo Downloader - c:\program files\Adobe\Photoshop Album Edition Dйcouverte\3.0\Apps\apdproxy.exe
HKLM-Run-ASuite - j:\asuitevdl\SuitePortable.exe
HKLM-Run-4c0fae34 - c:\windows\system32\vuwupajo.dll
HKLM-Run-CPM4f3c9da8 - c:\windows\system32\fijiveni.dll
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.fr/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} - hxxp://minitelweb.minitel.com/imin_data/ocx/MDM.cab
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-09 12:55:05
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
AliceSAV = c:\program files\TechCity Solutions\AliceSAV\AliceAgent.exe????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(664)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-04-09 12:58:33 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-09 10:58:30
Pre-Run: 95 558 946 816 octets libres
Post-Run: 96,192,225,280 octets libres
285 --- E O F --- 2009-04-07 07:51:05