Voici le rapport de combo fix:
--------------------------------------------------------------
ComboFix 09-05-25.05 - antoine 26/05/2009 14:12.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.2047.1747 [GMT 2:00]
Lancé depuis: c:\documents and settings\antoine\Bureau\moi.exe.exe
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\antoine\reader_s.exe
C:\InfoSat.txt
c:\windows\system32\OGACheckControl.dll
c:\windows\system32\reader_s.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-04-26 au 2009-05-26 ))))))))))))))))))))))))))))))))))))
.
2009-05-26 07:13 . 2009-05-26 07:16 -------- d-----w c:\documents and settings\antoine\DoctorWeb
2009-05-25 22:11 . 2009-05-25 22:11 -------- d-----w C:\FindyKill
2009-05-25 20:39 . 2007-01-18 12:00 3968 ----a-w c:\windows\system32\drivers\AvgArCln.sys
2009-05-25 13:36 . 2009-05-25 13:36 -------- d--h--w c:\windows\PIF
2009-05-25 13:36 . 2009-05-25 13:36 -------- d-----w c:\documents and settings\All Users\Application Data\MSN6
2009-05-25 13:27 . 2009-05-25 13:27 -------- d-----w c:\documents and settings\antoine\Application Data\MSN6
2009-05-25 13:26 . 2009-05-25 13:26 -------- d-----w c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-05-25 09:30 . 2009-05-25 09:30 -------- d-----w c:\documents and settings\All Users\Application Data\Electronic Arts
2009-05-25 08:19 . 2009-05-25 13:36 -------- d-----w c:\program files\Return to Castle Wolfenstein
2009-05-24 19:11 . 2009-05-24 19:11 10134 ----a-r c:\documents and settings\antoine\Application Data\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2009-05-24 19:11 . 2008-09-05 00:22 447752 ----a-r c:\windows\system32\vp6vfw.dll
2009-05-24 19:11 . 2009-05-24 19:11 -------- d-----w c:\program files\Microsoft WSE
2009-05-24 19:04 . 2009-05-24 19:04 -------- d-----w c:\program files\Electronic Arts
2009-05-20 16:37 . 2009-05-20 16:59 -------- d-----w c:\documents and settings\antoine\Application Data\dvdcss
2009-05-20 16:37 . 2009-05-20 16:37 -------- d-----w c:\documents and settings\antoine\Application Data\vlc
2009-05-20 16:37 . 2009-05-20 16:37 -------- d-----w c:\program files\VideoLAN
2009-05-15 12:17 . 2009-05-25 14:04 -------- d-----w c:\program files\Steam
2009-05-15 11:55 . 2009-05-15 11:55 -------- d-----w c:\program files\MSBuild
2009-05-15 11:55 . 2009-05-15 11:55 62304 ----a-w c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-05-15 11:53 . 2009-05-15 11:56 -------- d-----w c:\windows\system32\XPSViewer
2009-05-15 11:52 . 2009-05-15 11:52 -------- d-----w c:\program files\Reference Assemblies
2009-05-15 11:52 . 2006-06-29 11:07 14048 ------w c:\windows\system32\spmsg2.dll
2009-05-15 11:50 . 2009-05-15 11:51 -------- d-----w c:\program files\Microsoft Games for Windows - LIVE
2009-05-15 11:50 . 2009-05-15 11:50 -------- d-----w c:\windows\system32\xlive
2009-05-15 11:50 . 2008-07-31 08:41 238088 ----a-w c:\windows\system32\xactengine3_2.dll
2009-05-15 11:50 . 2008-07-31 08:41 68616 ----a-w c:\windows\system32\XAPOFX1_1.dll
2009-05-15 11:50 . 2008-07-31 08:40 509448 ----a-w c:\windows\system32\XAudio2_2.dll
2009-05-15 11:50 . 2008-07-12 06:18 467984 ----a-w c:\windows\system32\d3dx10_39.dll
2009-05-15 11:50 . 2008-07-12 06:18 3851784 ----a-w c:\windows\system32\D3DX9_39.dll
2009-05-15 11:50 . 2008-07-12 06:18 1493528 ----a-w c:\windows\system32\D3DCompiler_39.dll
2009-05-14 19:30 . 2009-05-14 19:30 -------- d-----w c:\documents and settings\antoine\Local Settings\Application Data\My Games
2009-05-14 13:17 . 2009-05-14 13:17 -------- d--h--r c:\documents and settings\antoine\Application Data\SecuROM
2009-05-14 12:28 . 2009-05-14 12:28 107888 ----a-w c:\windows\system32\CmdLineExt.dll
2009-05-14 12:21 . 2009-05-14 12:21 -------- d-----w c:\program files\Ubisoft
2009-05-12 23:48 . 2009-05-12 23:48 -------- d-----w c:\documents and settings\All Users\Application Data\PokerAcademy2
2009-05-12 23:48 . 2009-05-12 23:48 -------- d-----w c:\documents and settings\antoine\Application Data\PokerAcademy2
2009-05-12 23:48 . 2009-05-12 23:48 -------- d-----w c:\program files\PokerAcademy2
2009-05-04 06:27 . 2009-05-04 06:27 -------- d-----w c:\program files\Foxit Software
2009-05-04 06:27 . 2009-05-04 06:27 -------- d-----w c:\documents and settings\antoine\Application Data\Foxit
2009-04-28 09:12 . 2009-04-28 18:42 -------- d-----w c:\documents and settings\antoine\Application Data\teamspeak2
2009-04-28 09:12 . 2009-04-28 09:12 -------- d-----w c:\program files\Teamspeak2_RC2
2009-04-27 21:15 . 2009-04-27 23:14 -------- d-----w c:\program files\WowCartographe
2009-04-27 18:16 . 2009-04-27 18:16 -------- d-----w c:\program files\AIDA32 - Personal System Information
2009-04-27 16:56 . 2009-02-09 11:24 2191104 -c----w c:\windows\system32\dllcache\ntoskrnl.exe
2009-04-27 16:56 . 2009-02-06 10:10 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-27 16:56 . 2009-03-06 14:20 286720 -c----w c:\windows\system32\dllcache\pdh.dll
2009-04-27 16:56 . 2009-02-09 11:23 111104 -c----w c:\windows\system32\dllcache\services.exe
2009-04-27 16:56 . 2009-02-09 10:53 735744 -c----w c:\windows\system32\dllcache\lsasrv.dll
2009-04-27 16:56 . 2009-02-09 10:53 685568 -c----w c:\windows\system32\dllcache\advapi32.dll
2009-04-27 16:56 . 2009-02-09 10:53 473600 -c----w c:\windows\system32\dllcache\fastprox.dll
2009-04-27 16:56 . 2009-02-09 10:53 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-27 16:56 . 2009-02-09 10:53 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
2009-04-27 16:56 . 2009-02-09 11:23 2147328 -c----w c:\windows\system32\dllcache\ntkrnlmp.exe
2009-04-27 16:56 . 2009-02-09 10:53 739840 -c----w c:\windows\system32\dllcache\ntdll.dll
2009-04-27 16:55 . 2009-02-09 11:23 2025984 -c----w c:\windows\system32\dllcache\ntkrpamp.exe
2009-04-27 16:51 . 2008-06-14 17:33 272768 -c----w c:\windows\system32\dllcache\bthport.sys
2009-04-27 16:50 . 2008-04-21 21:15 219136 -c----w c:\windows\system32\dllcache\wordpad.exe
2009-04-27 16:14 . 2008-05-08 14:02 203136 -c----w c:\windows\system32\dllcache\rmcast.sys
2009-04-27 16:13 . 2008-10-24 11:21 455296 -c----w c:\windows\system32\dllcache\mrxsmb.sys
2009-04-27 16:12 . 2008-12-11 10:57 333952 -c----w c:\windows\system32\dllcache\srv.sys
2009-04-27 16:11 . 2008-05-01 14:36 331776 -c----w c:\windows\system32\dllcache\msadce.dll
2009-04-27 16:10 . 2008-04-11 19:05 691712 -c----w c:\windows\system32\dllcache\inetcomm.dll
2009-04-27 16:08 . 2008-12-16 12:31 354304 -c----w c:\windows\system32\dllcache\winhttp.dll
2009-04-27 16:07 . 2008-10-15 16:35 337408 -c----w c:\windows\system32\dllcache\netapi32.dll
2009-04-27 16:07 . 2008-09-04 17:16 1106944 -c----w c:\windows\system32\dllcache\msxml3.dll
2009-04-27 13:04 . 2008-04-13 09:45 15104 -c--a-w c:\windows\system32\dllcache\usbscan.sys
2009-04-27 13:04 . 2008-04-13 09:45 15104 ----a-w c:\windows\system32\drivers\usbscan.sys
2009-04-27 12:59 . 2006-12-27 22:00 66560 ----a-w c:\windows\system32\eswia7e.dll
2009-04-27 12:59 . 2006-12-27 22:00 208896 ----a-w c:\windows\system32\esint7e.dll
2009-04-27 12:59 . 2006-03-09 22:00 3584 ----a-w c:\windows\system32\eswiaml.dll
2009-04-27 12:58 . 2007-01-11 11:02 113664 ----a-w c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
2009-04-27 12:58 . 2009-04-27 12:58 -------- d-----w c:\documents and settings\All Users\Application Data\EPSON
2009-04-27 12:58 . 2004-09-11 03:12 49152 ----a-w c:\windows\system32\E_DCINST.DLL
2009-04-27 12:58 . 2006-12-08 09:04 76800 ----a-w c:\windows\system32\E_FLBCAE.DLL
2009-04-27 12:58 . 2006-04-19 09:00 62976 ----a-w c:\windows\system32\E_FD4BCAE.DLL
2009-04-27 12:58 . 2008-04-13 09:47 25856 -c--a-w c:\windows\system32\dllcache\usbprint.sys
2009-04-27 12:58 . 2008-04-13 09:47 25856 ----a-w c:\windows\system32\drivers\usbprint.sys
2009-04-27 12:58 . 2008-04-13 09:45 32128 -c--a-w c:\windows\system32\dllcache\usbccgp.sys
2009-04-27 12:58 . 2008-04-13 09:45 32128 ----a-w c:\windows\system32\drivers\usbccgp.sys
2009-04-27 12:57 . 2009-04-27 12:59 -------- d-----w c:\program files\EPSON
2009-04-27 07:24 . 2009-04-27 07:24 -------- d-----w c:\documents and settings\All Users\Application Data\Blizzard
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-25 13:36 . 2009-04-26 17:13 -------- d-----w c:\documents and settings\antoine\Application Data\uTorrent
2009-05-24 19:04 . 2009-04-26 15:25 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-21 15:34 . 2009-04-26 18:02 -------- d-----w c:\program files\World of Warcraft
2009-05-19 20:31 . 2009-04-26 17:04 138464 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-05-19 20:31 . 2009-04-26 17:03 111928 ----a-w c:\windows\system32\PnkBstrB.exe
2009-05-17 19:12 . 2009-04-26 15:58 13104 ----a-w c:\documents and settings\antoine\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-15 11:55 . 2003-04-24 12:00 79028 ----a-w c:\windows\system32\perfc00C.dat
2009-05-15 11:55 . 2003-04-24 12:00 494650 ----a-w c:\windows\system32\perfh00C.dat
2009-05-14 12:25 . 2009-04-26 17:04 22328 ----a-w c:\documents and settings\antoine\Application Data\PnkBstrK.sys
2009-05-14 12:25 . 2009-04-26 17:04 22328 ----a-w c:\documents and settings\antoine\Application Data\PnkBstrK.sys
2009-05-14 12:24 . 2009-04-26 17:03 66872 ----a-w c:\windows\system32\PnkBstrA.exe
2009-05-14 12:24 . 2009-04-26 17:03 2250024 ----a-w c:\windows\system32\pbsvc.exe
2009-04-27 13:00 . 2009-04-27 13:00 -------- d-----w c:\program files\InkSaver
2009-04-26 18:27 . 2009-04-26 18:02 -------- d-----w c:\program files\Fichiers communs\Blizzard Entertainment
2009-04-26 18:02 . 2009-04-26 16:46 -------- d-----w c:\program files\DAEMON Tools Lite
2009-04-26 17:13 . 2009-04-26 17:13 -------- d-----w c:\program files\uTorrent
2009-04-26 16:57 . 2009-04-26 16:57 -------- d-----w c:\program files\Activision
2009-04-26 16:54 . 2009-04-26 16:44 -------- d-----w c:\documents and settings\antoine\Application Data\DAEMON Tools Lite
2009-04-26 16:46 . 2009-04-26 16:46 -------- d-----w c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-04-26 16:46 . 2009-04-26 16:46 -------- d-----w c:\program files\DAEMON Tools Toolbar
2009-04-26 16:44 . 2009-04-26 16:44 721904 ----a-w c:\windows\system32\drivers\sptd.sys
2009-04-26 16:38 . 2009-04-26 16:38 0 ----a-w c:\windows\nsreg.dat
2009-04-26 16:33 . 2009-04-26 16:33 -------- d-----w c:\program files\Fichiers communs\Logitech
2009-04-26 16:33 . 2009-04-26 16:33 -------- d-----w c:\program files\Logitech
2009-04-26 16:33 . 2009-04-26 15:24 -------- d-----w c:\program files\Fichiers communs\InstallShield
2009-04-26 16:23 . 2009-04-26 16:23 -------- d-----w c:\documents and settings\All Users\Application Data\nView_Profiles
2009-04-26 16:17 . 2009-04-26 16:17 -------- d-----w c:\program files\AGEIA Technologies
2009-04-26 16:17 . 2009-04-26 16:17 -------- d-----w c:\program files\Fichiers communs\Wise Installation Wizard
2009-04-26 16:08 . 2009-04-26 16:08 -------- d-----w c:\program files\Alwil Software
2009-04-26 16:07 . 2009-04-26 16:07 -------- d-----w c:\program files\AMD
2009-04-26 16:06 . 2009-04-26 16:06 -------- d-----w c:\documents and settings\antoine\Application Data\InstallShield
2009-04-26 16:02 . 2009-04-26 16:02 -------- d-----w c:\program files\7-Zip
2009-04-26 15:56 . 2009-04-26 15:20 76487 ----a-w c:\windows\PCHealth\HelpCtr\OfflineCache\index.dat
2009-04-26 15:25 . 2009-04-26 15:25 17801 ----a-w c:\windows\system32\drivers\AegisP.sys
2009-04-26 15:24 . 2009-04-26 15:24 -------- d-----w c:\program files\USRobotics
2009-04-26 15:20 . 2009-04-26 15:20 -------- d-----w c:\program files\microsoft frontpage
2009-04-26 15:18 . 2009-04-26 15:18 21892 ----a-w c:\windows\system32\emptyregdb.dat
2009-04-26 15:18 . 2009-04-26 15:18 -------- d-----w c:\program files\Services en ligne
2009-03-06 14:20 . 2003-04-24 12:00 286720 ----a-w c:\windows\system32\pdh.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"InkSaver"="c:\program files\InkSaver\InkSaver.exe" [2007-05-24 589824]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-13 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
USRobotics Wireless PCI Adapter.lnk - c:\program files\USRobotics\Wireless PCI Manager\USR54G.exe [2006-4-14 667648]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.0.9.9551-to-3.1.0.9767-frFR-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.1.1.9835-to-3.1.2.9901-frFR-downloader.exe"=
"c:\\Program Files\\Steam\\SteamApps\\doudule\\counter-strike source\\hl2.exe"=
"c:\\Program Files\\Return to Castle Wolfenstein\\WolfMP.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
S1 glaide32;glaide32;\??\c:\windows\system32\drivers\glaide32.sys --> c:\windows\system32\drivers\glaide32.sys [?]
S3 USRPCI;USRobotics Wireless PCI Adapter Service;c:\windows\system32\drivers\USRPCI.sys [26/04/2009 17:24 469216]
S3 wlanndi5;wlanndi5 NDIS Protocol Driver;c:\windows\system32\wlanndi5.sys [21/04/2004 17:51 16384]
.
- - - - ORPHELINS SUPPRIMES - - - -
Notify-WgaLogon - (no file)
SafeBoot-procexp90.Sys
.
------- Examen supplémentaire -------
.
FF - ProfilePath - c:\documents and settings\antoine\Application Data\Mozilla\Firefox\Profiles\jabl1yq7.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr
FF - prefs.js: keyword.URL - hxxp://xeoo.com/?p=url&a=firefox&k=
FF - plugin: c:\program files\Mozilla Firefox\plugins\npFoxitReaderPlugin.dll
---- PARAMETRES FIREFOX ----
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.bookmark_page", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.current_page", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("pref.browser.homepage.disable_button.restore_default", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.places.importBookmarksHTML", true);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.places.importDefaults", false);
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.search.selectedEngine", "xeoo.com");
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("keyword.URL", "http://xeoo.com/?p=url&a=firefox&k=");
c:\program files\Mozilla Firefox\defaults\profile\prefs.js - user_pref("browser.startup.homepage", "http://www.xeoo.com/?p=h&a=firefox");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-26 14:13
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-1957994488-746137067-839522115-1004\Software\SecuROM\License information*]
"datasecu"=hex:c5,ba,fa,75,0b,37,71,86,30,4f,39,a6,e6,a5,b4,5e,1a,ab,43,c9,23,
52,3e,74,31,da,eb,42,a5,a8,7f,f5,2b,46,ea,04,58,db,33,42,be,a1,23,d0,e6,e9,\
"rkeysecu"=hex:7c,ee,31,4e,36,f3,cc,c4,3f,d8,5f,89,bc,3f,d3,6d
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\WPAEvents]
@Denied: (Full) (LocalSystem)
"OOBETimer"=hex:ff,d5,71,d6,8b,6a,8d,6f,d5,33,93,fd
.
Heure de fin: 2009-05-26 14:14
ComboFix-quarantined-files.txt 2009-05-26 12:14
Avant-CF: 107 876 519 936 octets libres
Après-CF: 107 895 558 144 octets libres
216 --- E O F --- 2009-05-13 22:33
-----------------------------------------------------------------------------------------------------
Je vais maintenant m'occuper de HostXpert.
Merci.