2ème tentative plus fructueuse, voici le rapport de ComboFix, autant dire du chinois pour moi:
ComboFix 09-05-25.A0 - Propriétaire 26/05/2009 16:20.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.32.1036.18.383.225 [GMT 2:00]
Lancé depuis: c:\documents and settings\Propriétaire\Bureau\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090525-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Exécution préalable -------
.
c:\windows\system32\ihqynxyb.ini
c:\windows\system32\nfr.assembly
c:\windows\system32\nfr.gpref
c:\windows\system32\pykuxwwo.ini
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-04-26 au 2009-05-26 ))))))))))))))))))))))))))))))))))))
.
2009-05-26 11:10 . 2009-04-06 13:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-05-26 11:10 . 2009-04-06 13:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-26 11:10 . 2009-05-26 11:10 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-26 11:10 . 2009-05-26 11:11 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-05-26 09:44 . 2009-05-26 09:44 -------- d-----w c:\program files\Candleworks
2009-05-25 12:37 . 2009-05-25 12:37 25992 ----a-w c:\windows\system32\pgdfgsvc.exe
2009-05-22 18:06 . 2009-05-22 18:06 -------- d-----w c:\program files\SecondLife
2009-05-17 20:39 . 2009-05-17 20:39 -------- d-----w c:\documents and settings\All Users\Application Data\TEMP
2009-05-17 20:38 . 2009-05-17 20:38 -------- d-----w c:\program files\CD Label Designer
2009-05-17 20:32 . 2009-05-17 20:33 -------- d-----w c:\program files\UnderCoverXP
2009-05-17 14:38 . 2008-04-17 11:12 15464 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-05-17 14:38 . 2008-04-17 11:12 107368 ----a-w c:\windows\system32\GEARAspi.dll
2009-05-17 14:36 . 2009-05-17 14:36 -------- d-----w c:\program files\iPod
2009-05-17 14:36 . 2009-05-17 14:38 -------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-05-17 14:36 . 2009-05-17 14:38 -------- d-----w c:\program files\iTunes
2009-05-17 14:35 . 2009-05-17 14:35 -------- d-----w c:\program files\Bonjour
2009-05-17 14:34 . 2009-05-17 14:36 -------- d-----w c:\program files\Fichiers communs\Apple
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-26 14:04 . 2008-09-29 22:52 -------- d-----w c:\program files\DNA
2009-05-17 14:36 . 2008-09-24 21:18 -------- d-----w c:\documents and settings\All Users\Application Data\Apple Computer
2009-05-14 20:02 . 2008-09-29 00:56 -------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-04-21 21:37 . 2004-08-05 11:00 73218 ----a-w c:\windows\system32\perfc00C.dat
2009-04-21 21:37 . 2004-08-05 11:00 464712 ----a-w c:\windows\system32\perfh00C.dat
2009-04-16 13:36 . 2009-04-16 13:30 -------- d-----w c:\documents and settings\All Users\Application Data\Logitech
2009-04-16 13:33 . 2009-04-16 13:33 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2009-04-16 13:31 . 2009-04-16 13:30 -------- d-----w c:\program files\Fichiers communs\Logishrd
2009-04-16 13:30 . 2008-06-12 16:03 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-16 13:30 . 2009-04-16 13:30 -------- d-----w c:\program files\Logitech
2009-04-08 20:41 . 2009-04-08 20:41 -------- d-----w c:\program files\CasinoOnNet
2009-04-06 16:07 . 2008-06-13 09:47 -------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-01 17:12 . 2009-04-01 16:48 -------- d-----w c:\program files\BOINC
2009-04-01 16:55 . 2009-04-01 16:39 -------- d-----w c:\program files\SETI@home
2009-03-27 21:53 . 2008-06-13 09:47 -------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-14 22:00 . 2009-03-14 22:00 114048 ----a-w c:\windows\system32\drivers\snapman.sys
2009-03-06 14:20 . 2004-08-05 11:00 286720 ----a-w c:\windows\system32\pdh.dll
2009-02-26 22:16 . 2009-02-26 22:16 75264 ---ha-w c:\windows\system32\mlfcache.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Google Update"="c:\documents and settings\Propriétaire\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-03-02 133104]
"BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-12-15 342848]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-05-15 335872]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2003-10-08 159744]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"OSSelectorReinstall"="c:\program files\Fichiers communs\Acronis\Acronis Disk Director\oss_reinstall.exe" [2007-07-11 2233008]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-05-06 172032]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2009-03-20 198160]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"AGRSMMSG"="AGRSMMSG.exe" - c:\windows\AGRSMMSG.exe [2005-04-19 88209]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" - c:\windows\KHALMNPR.Exe [2007-11-29 55824]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2009-4-16 789008]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave"= serwvdrv.dll
"MIDI1"= SYNCOR11.DLL
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\[u]0
/upgdfgsvc C 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Hyperappel du Petit Larousse 2008.lnk]
path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Hyperappel du Petit Larousse 2008.lnk
backup=c:\windows\pss\Hyperappel du Petit Larousse 2008.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Pando Networks\\Pando\\pando.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\DNA\\btdna.exe"=
"c:\\Program Files\\SecondLife\\SLVoice.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"56633:TCP"= 56633:TCP:Pando P2P TCP Listening Port
"56633:UDP"= 56633:UDP:Pando P2P UDP Listening Port
"58669:TCP"= 58669:TCP:Pando P2P TCP Listening Port
"58669:UDP"= 58669:UDP:Pando P2P UDP Listening Port
"58740:TCP"= 58740:TCP:Pando P2P TCP Listening Port
"58740:UDP"= 58740:UDP:Pando P2P UDP Listening Port
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 atiide;atiide;c:\windows\system32\drivers\atiide.sys [12/06/2008 18:27 5632]
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [13/06/2008 11:42 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [13/06/2008 11:42 20560]
S3 EverestDriver;Lavalys EVEREST Kernel Driver;c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt [14/03/2009 23:37 26224]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [24/01/2009 15:46 216232]
.
Contenu du dossier 'Tâches planifiées'
2009-05-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-05-26 c:\windows\Tasks\User_Feed_Synchronization-{01043ED8-10B1-4785-A872-82279463EEB3}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 01:05]
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{E2108E50-7B16-4867-BCC1-60BAA62CA32D} - (no file)
HKCU-Run-fsm - (no file)
Notify-nnnNFYop - nnnNFYop.dll
SafeBoot-procexp90.Sys
.
------- Examen supplémentaire -------
.
uInternet Settings,ProxyServer = http=localhost:7171
uInternet Settings,ProxyOverride = *.local;<local>
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} - hxxps://plugins.valueactive.eu/flashax/iefax.cab
FF - ProfilePath - c:\documents and settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\ca3hslik.default\
FF - component: c:\program files\Real\RealPlayer\browserrecord\components\nprpbrowserrecordplugin.dll
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Opera 10 Preview\program\plugins\npqtplugin.dll
FF - plugin: c:\program files\Opera 10 Preview\program\plugins\npqtplugin2.dll
FF - plugin: c:\program files\Opera 10 Preview\program\plugins\npqtplugin3.dll
FF - plugin: c:\program files\Opera 10 Preview\program\plugins\npqtplugin4.dll
FF - plugin: c:\program files\Opera 10 Preview\program\plugins\npqtplugin5.dll
FF - plugin: c:\program files\Opera 10 Preview\program\plugins\npqtplugin6.dll
FF - plugin: c:\program files\Opera 10 Preview\program\plugins\npqtplugin7.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-05-26 16:23
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\EverestDriver]
"ImagePath"="\??\c:\program files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt"
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(696)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2328)
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Heure de fin: 2009-05-26 16:26
ComboFix-quarantined-files.txt 2009-05-26 14:26
Avant-CF: 3.770.126.336 octets libres
Après-CF: 3.761.999.872 octets libres
183 --- E O F --- 2009-05-14 20:02