Il fait un peu peur ce logiciel quand même :D
Voici le log :
ComboFix 09-04-23.A3 - PiERRE 23/04/2009 23:16.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.1022.546 [GMT 2:00]
Lancé depuis: c:\documents and settings\PiERRE\Bureau\ComboFix.exe
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated)
FW: Norton Internet Worm Protection *disabled*
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\PiERRE\PiERRE.exe
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TDSSSERV
-------\Legacy_WLANCFGFAX
-------\Service_tdssserv
-------\Service_WlancfgFax
((((((((((((((((((((((((((((( Fichiers créés du 2009-05-23 au 2009-4-23 ))))))))))))))))))))))))))))))))))))
.
2009-04-23 16:44 . 2009-04-23 16:44 -------- d-----w C:\Rooter$
2009-04-23 16:40 . 2009-04-23 16:40 -------- d-----w C:\rsit
2009-04-21 20:33 . 2009-04-21 20:33 -------- d-----w c:\program files\Trend Micro
2009-04-20 15:58 . 2009-04-20 15:58 32 --s-a-w c:\windows\system32\1353889894.dat
2009-04-16 10:05 . 2009-03-06 14:20 286720 ------w c:\windows\system32\dllcache\pdh.dll
2009-04-16 10:05 . 2009-02-09 11:23 111104 ------w c:\windows\system32\dllcache\services.exe
2009-04-16 10:05 . 2009-02-09 10:53 401408 ------w c:\windows\system32\dllcache\rpcss.dll
2009-04-16 10:05 . 2009-02-06 10:10 227840 ------w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-16 10:05 . 2009-02-09 10:53 685568 ------w c:\windows\system32\dllcache\advapi32.dll
2009-04-16 10:05 . 2009-02-09 10:53 473600 ------w c:\windows\system32\dllcache\fastprox.dll
2009-04-16 10:05 . 2009-02-09 10:53 735744 ------w c:\windows\system32\dllcache\lsasrv.dll
2009-04-16 10:05 . 2009-02-09 10:53 739840 ------w c:\windows\system32\dllcache\ntdll.dll
2009-04-16 10:05 . 2009-02-09 10:53 453120 ------w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-16 10:04 . 2008-12-16 12:31 354304 ------w c:\windows\system32\dllcache\winhttp.dll
2009-04-16 10:04 . 2009-03-27 06:54 1203922 ------w c:\windows\system32\dllcache\sysmain.sdb
2009-04-16 10:04 . 2008-04-21 21:15 219136 ------w c:\windows\system32\dllcache\wordpad.exe
2009-04-14 18:17 . 2009-04-14 18:17 41808 ----a-w c:\windows\system32\xfcodec.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-23 21:20 . 2007-02-15 16:54 -------- d-----w c:\program files\Symantec AntiVirus
2009-04-23 16:44 . 2009-04-23 16:44 3850 ----a-w C:\Rooter.txt
2009-04-17 23:31 . 2008-09-04 16:31 -------- d-----w c:\documents and settings\PiERRE\Application Data\Xfire
2009-04-17 21:53 . 2008-05-15 18:03 189072 ----a-w c:\windows\system32\PnkBstrB.exe
2009-04-17 21:26 . 2008-05-15 18:03 138920 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-04-17 11:57 . 2008-09-04 16:30 -------- d-----w c:\program files\Xfire
2009-04-16 12:33 . 2005-10-10 11:39 64724 ----a-w c:\windows\system32\perfc00C.dat
2009-04-16 12:33 . 2005-10-10 11:39 446984 ----a-w c:\windows\system32\perfh00C.dat
2009-04-15 11:05 . 2007-02-12 21:34 -------- d-----w c:\program files\Piolet
2009-04-15 11:02 . 2008-08-26 10:59 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-06 13:32 . 2008-08-26 10:59 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 13:32 . 2008-08-26 10:59 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-03-21 14:07 . 2009-03-21 14:07 1054720 ------w c:\windows\system32\dllcache\kernel32.dll
2009-03-13 18:58 . 2006-12-17 11:01 268 ---ha-w C:\sqmdata04.sqm
2009-03-13 18:58 . 2006-12-17 11:01 244 ---ha-w C:\sqmnoopt04.sqm
2009-03-12 21:07 . 2007-04-01 21:28 -------- d-----w c:\program files\BitComet
2009-03-06 14:20 . 2004-08-10 11:00 286720 ----a-w c:\windows\system32\pdh.dll
2009-03-03 22:31 . 2007-08-19 10:46 -------- d-----w c:\documents and settings\PiERRE\Application Data\mIRC
2009-03-03 22:20 . 2007-09-23 16:20 -------- d-----w c:\program files\mIRC
2009-03-03 00:13 . 2004-08-10 11:00 826368 ----a-w c:\windows\system32\wininet.dll
2009-03-03 00:13 . 2004-08-10 11:00 826368 ----a-w c:\windows\system32\dllcache\wininet.dll
2009-02-28 04:54 . 2004-08-10 11:00 636072 ----a-w c:\windows\system32\dllcache\iexplore.exe
2009-02-27 22:14 . 2008-05-15 18:03 75064 ----a-w c:\windows\system32\PnkBstrA.exe
2009-02-20 10:20 . 2007-05-09 07:59 13824 ------w c:\windows\system32\dllcache\ieudinit.exe
2009-02-20 10:20 . 2004-08-10 11:00 70656 ----a-w c:\windows\system32\dllcache\ie4uinit.exe
2009-02-20 05:14 . 2004-08-10 04:00 161792 ----a-w c:\windows\system32\dllcache\ieakui.dll
2009-02-10 17:06 . 2008-10-15 06:43 2068096 ------w c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-09 14:05 . 2008-10-15 06:43 1846912 ------w c:\windows\system32\dllcache\win32k.sys
2009-02-09 14:05 . 2004-08-10 11:00 1846912 ----a-w c:\windows\system32\win32k.sys
2009-02-09 11:24 . 2008-10-15 06:43 2191104 ------w c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-09 11:23 . 2008-10-15 06:43 2025984 ------w c:\windows\system32\dllcache\ntkrpamp.exe
2009-02-09 11:23 . 2004-08-10 11:00 2025984 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-09 11:23 . 2008-10-15 06:43 2147328 ------w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-02-09 11:23 . 2004-08-10 11:00 2147328 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-09 11:23 . 2004-08-10 11:00 111104 ----a-w c:\windows\system32\services.exe
2009-02-09 10:53 . 2004-08-10 11:00 735744 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 10:53 . 2004-08-10 11:00 739840 ----a-w c:\windows\system32\ntdll.dll
2009-02-09 10:53 . 2004-08-10 11:00 685568 ----a-w c:\windows\system32\advapi32.dll
2009-02-09 10:53 . 2004-08-10 11:00 401408 ----a-w c:\windows\system32\rpcss.dll
2009-02-06 10:39 . 2004-08-10 04:00 35328 ----a-w c:\windows\system32\sc.exe
2009-02-06 10:39 . 2004-08-10 04:00 35328 ----a-w c:\windows\system32\dllcache\sc.exe
2009-02-03 19:58 . 2009-02-03 19:58 56832 ------w c:\windows\system32\dllcache\secur32.dll
2009-02-03 19:58 . 2004-08-10 11:00 56832 ----a-w c:\windows\system32\secur32.dll
2009-01-26 22:32 . 2009-01-26 22:32 50728 ----a-w c:\documents and settings\PiERRE\Application Data\GDIPFONTCACHEV1.DAT
2008-12-25 21:39 . 2006-12-16 15:45 50728 ----a-w c:\documents and settings\PiERRE\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2008-05-15 18:03 . 2008-05-15 18:03 22328 ----a-w c:\documents and settings\PiERRE\Application Data\PnkBstrK.sys
2006-12-17 09:51 . 2006-12-17 09:51 278528 ----a-w c:\program files\Fichiers communs\FDEUnInstaller.exe
2006-12-17 00:04 . 2006-12-16 13:28 129 ----a-w c:\documents and settings\PiERRE\Local Settings\Application Data\fusioncache.dat
2006-09-19 03:51 . 2006-09-19 03:51 137 ----a-w c:\documents and settings\Administrateur\Local Settings\Application Data\fusioncache.dat
2007-08-03 15:53 . 2007-08-03 15:53 10856 --sha-w c:\windows\system32\KGyGaAvL.sys
2008-10-23 20:58 . 2008-10-23 20:58 32768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008102320081024\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-21 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-02-22 143360]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-08-27 8466432]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-22 237568]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 249856]
"Reminder"="c:\windows\Creator\Remind_XP.exe" [2004-12-14 663552]
"HP Software Update"="c:\program files\HP\HP Software Update\HPwuSchd2.exe" [2005-02-17 49152]
"ccApp"="c:\program files\Fichiers communs\Symantec Shared\ccApp.exe" [2004-08-20 66680]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2004-11-24 161496]
"LogitechCommunicationsManager"="c:\program files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe" [2007-03-06 488984]
"LogitechQuickCamRibbon"="c:\program files\Labtec\WebCam10\WebCam10.exe" [2007-03-06 1060376]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2006-07-21 16261632]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2007-08-27 1626112]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\system32\bthprops.cpl [2008-04-14 110592]
c:\documents and settings\PiERRE\Menu D‚marrer\Programmes\D‚marrage\
Pin.lnk - c:\hp\bin\CLOAKER.EXE [2006-9-19 27136]
PinMcLnk.lnk - c:\hp\bin\cloaker.exe [2006-9-19 27136]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Piolet\\Piolet.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"c:\\Program Files\\Artefacts Studio\\PetanqueDemo\\bin\\releaseDemo\\Petanque.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Sports Interactive\\Football Manager 2008\\fm.exe"=
"c:\\Program Files\\Xfire\\xfire.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare v1.7\\iw3mp.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\Lavasoft\\Ad-Aware\\Ad-Aware.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\Executive Software\\DiskeeperLite\\ShowHtml.exe"=
"c:\\Program Files\\Symantec AntiVirus\\VPC32.EXE"=
"c:\\WINDOWS\\system32\\taskmgr.exe"=
"c:\\WINDOWS\\system32\\netsh.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\CCleaner\\CCleaner.exe"=
"c:\\Program Files\\Intel\\Intel Matrix Storage Manager\\Iaanotif.exe"=
"c:\\Program Files\\HP\\HP Software Update\\HPwuSchd2.exe"=
"c:\\Program Files\\Fichiers communs\\Symantec Shared\\ccApp.exe"=
"c:\\Program Files\\Symantec AntiVirus\\VPTray.exe"=
"c:\\Program Files\\Fichiers communs\\LogiShrd\\LComMgr\\Communications_Helper.exe"=
"c:\\Program Files\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe"=
"c:\\Program Files\\Fichiers communs\\LogiShrd\\LComMgr\\LVComSX.exe"=
"c:\\HP\\KBD\\KBD.EXE"=
"c:\\windows\\system\\hpsysdrv.exe"=
"c:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"=
"c:\\WINDOWS\\system32\\logon.scr"=
"c:\\WINDOWS\\system32\\userinit.exe"=
"c:\\WINDOWS\\RTHDCPL.EXE"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"16786:TCP"= 16786:TCP:BitComet 16786 TCP
"16786:UDP"= 16786:UDP:BitComet 16786 UDP
R2 acpi32;acpi32; [x]
R2 amd64si;amd64si; [x]
R2 ati64si;ati64si; [x]
R2 fips32cup;fips32cup; [x]
R2 i386si;i386si; [x]
R2 ksi32sk;ksi32sk; [x]
R2 netsik;netsik; [x]
R2 nicsk32;nicsk32; [x]
R2 port135sik;port135sik; [x]
R2 securentm;securentm; [x]
R2 systemntmi;systemntmi; [x]
R2 ws2_32sik;ws2_32sik; [x]
R3 imhidusb;Immersion's HID USB Driver;c:\windows\system32\DRIVERS\imhidusb.sys [2002-05-02 30920]
R3 PID_0920;Labtec WebCam(PID_0920);c:\windows\system32\DRIVERS\LV532AV.SYS [2005-01-19 163328]
R3 SavRoam;SavRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2004-11-24 173792]
R3 SIS163u;SiS163 usb Wireless LAN Adapter Driver;c:\windows\system32\DRIVERS\sis163u.sys [2005-06-20 215040]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1e13273d-8d11-11db-b767-0018f3ae0e93}]
\Shell\AutoRun\command - j:\quarantine\S-53-6-28-3434476501-1644491937-600003330-1213\dllview.exe
\Shell\open\command - j:\quarantine\S-53-6-28-3434476501-1644491937-600003330-1213\dllview.exe
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-PiERRE - c:\documents and settings\PiERRE\PiERRE.exe
HKCU-Run-Steam - (no file)
HKLM-Run-PCDrProfiler - (no file)
Notify-WgaLogon - (no file)
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
uInternet Connection Wizard,ShellNext = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Download all links using BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: Download all videos using BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: Download link using &BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-04-23 23:20
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(3012)
c:\windows\system32\nview.dll
c:\windows\system32\NVWRSFR.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\nvwddi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Fichiers communs\Symantec Shared\ccSetMgr.exe
c:\program files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\rundll32.exe
c:\windows\system32\rundll32.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Executive Software\DiskeeperLite\DKService.exe
c:\windows\ehome\ehrecvr.exe
c:\windows\ehome\ehSched.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
c:\program files\Fichiers communs\LightScribe\LSSrvc.exe
c:\program files\Fichiers communs\LogiShrd\LComMgr\LVComSX.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\program files\Inventel\Gateway\WLANCFG.EXE
c:\program files\Intel\IntelDH\Intel(R) Quick Resume Technology Drivers\ELService.exe
c:\windows\ehome\mcrdsvc.exe
c:\windows\system32\dllhost.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2009-04-23 23:22 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-04-23 21:22
Avant-CF: 27 985 211 392 octets libres
Après-CF: 27 960 975 360 octets libres
258 --- E O F --- 2009-04-16 10:14
En attendant ta réponse avec impatience.
Merci d'avance.