Excuses j'ai eu un imprévu, voici le rapport de combofix
ComboFix 09-07-31.04 - yves_2 01/08/2009 17:13.1.1 - FAT32x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1023.383 [GMT 2:00]
Running from: c:\documents and settings\yves_2.ACER-E3B0141A93\Bureau\CFix.exe
AV: AntiVirus Firewall 7.03 *On-access scanning disabled* (Updated) {E7512ED5-4245-4B4D-AF3A-382D3F313F15}
FW: AntiVirus Firewall 7.03 *enabled* {D4747503-0346-49EB-9262-997542F79BF4}
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\FI2985~1.WEV
c:\windows\FI2E5D~1.WEV
c:\windows\FI525C~1.WEV
c:\windows\FI52DE~1.WEV
c:\windows\FI5977~1.WEV
c:\windows\FI94AE~1.WEV
c:\windows\FIC244~1.WEV
c:\windows\FIC414~1.WEV
c:\windows\FID23E~1.WEV
c:\windows\FID3EF~1.WEV
c:\windows\FIDF5A~1.WEV
c:\windows\FIE794~1.WEV
c:\windows\FIFA5C~1.WEV
c:\windows\FIFB5C~1.WEV
c:\windows\fiypu.2ev
c:\windows\fiypu.3ev
c:\windows\fiypu.4ev
c:\windows\fiypu.5ev
c:\windows\fiypu.6ev
c:\windows\fiypu.7ev
c:\windows\fiypu.wev
c:\windows\FIYPU~1.WEV
c:\windows\FIYPU~2.WEV
c:\windows\FIYPU~3.WEV
c:\windows\FIYPU~4.WEV
c:\windows\Installer\335fa6.msi
c:\windows\Installer\942c5f.msp
c:\windows\pp.exe
c:\windows\system32\Microsoft\backup.ftp
c:\windows\system32\Microsoft\backup.tftp
c:\windows\system32\msapi.dll
.
((((((((((((((((((((((((( Files Created from 2009-07-01 to 2009-08-01 )))))))))))))))))))))))))))))))
.
2009-08-01 12:53 . 2009-08-01 12:53 -------- d-sh--w- C:\FOUND.005
2009-08-01 09:20 . 2009-08-01 09:20 -------- d-sh--w- C:\FOUND.004
2009-08-01 07:39 . 2009-08-01 07:39 -------- d-----w- c:\documents and settings\yves_2.ACER-E3B0141A93\Application Data\Malwarebytes
2009-08-01 07:38 . 2009-07-13 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-08-01 07:38 . 2009-08-01 07:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-08-01 07:38 . 2009-07-13 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-08-01 07:38 . 2009-08-01 07:38 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-08-01 07:17 . 2009-08-01 07:17 -------- d-----w- C:\rsit
2009-08-01 07:08 . 2009-08-01 07:08 -------- d-----w- c:\program files\CCleaner
2009-08-01 06:53 . 2009-08-01 06:53 -------- d-sh--w- C:\FOUND.003
2009-07-31 10:00 . 2009-07-31 10:00 -------- d-----w- c:\documents and settings\Yves\Application Data\PC Tools
2009-07-30 18:51 . 2009-07-30 18:51 -------- d-----w- C:\ToolBar SD
2009-07-30 18:14 . 2009-07-30 18:14 -------- d-sh--w- C:\FOUND.002
2009-07-30 16:09 . 2009-07-30 16:10 -------- d-----w- c:\documents and settings\All Users\Application Data\TEMP
2009-07-30 16:08 . 2009-07-30 16:08 -------- d-----w- c:\program files\PC Tools AntiVirus
2009-07-29 20:09 . 2009-07-29 20:09 -------- d-----w- c:\program files\Trend Micro
2009-07-29 19:35 . 2009-07-29 19:35 -------- d-----w- c:\documents and settings\Camille\Application Data\F-Secure
2009-07-29 19:30 . 2009-07-29 19:30 -------- d-sh--w- C:\FOUND.001
2009-07-29 19:07 . 2009-07-29 19:07 -------- d-sh--w- C:\FOUND.000
2009-07-10 15:13 . 2009-07-10 15:13 -------- d-----w- c:\program files\wletmin
2009-07-03 06:00 . 2009-07-03 06:00 -------- d-----w- c:\documents and settings\LocalService\Bureau
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-03 16:57 . 1979-12-31 22:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-28 07:57 . 2009-06-28 07:57 -------- d-----w- c:\program files\Fichiers communs\Adobe
2009-06-28 07:54 . 2009-06-28 07:54 -------- d-----w- c:\program files\NOS
2009-06-28 07:54 . 2009-06-28 07:54 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2009-06-27 22:05 . 2009-06-27 22:05 -------- d-----w- c:\program files\monAlbumPhoto
2009-06-16 14:40 . 1979-12-31 22:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:40 . 1979-12-31 22:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-11 20:10 . 1979-12-31 22:00 68586 ----a-w- c:\windows\system32\perfc00C.dat
2009-06-11 20:10 . 1979-12-31 22:00 456430 ----a-w- c:\windows\system32\perfh00C.dat
2009-06-03 19:10 . 1979-12-31 22:00 1297408 ----a-w- c:\windows\system32\quartz.dll
2009-05-07 15:33 . 1979-12-31 22:00 348672 ----a-w- c:\windows\system32\localspl.dll
2008-06-12 19:24 . 2008-06-12 19:24 278528 ----a-w- c:\program files\Fichiers communs\FDEUnInstaller.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"eRecoveryService"="c:\program files\Acer\eRecovery\Monitor.exe" [2005-06-20 352256]
"ntiMUI"="c:\program files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2005-05-11 45056]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"AspireService"="c:\program files\Acer\Acer eMode Management\AspireService.exe" [2005-09-26 114688]
"MediaSync"="c:\program files\Acer\Acer eConsole\MediaSync.exe" [2005-09-21 425984]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-09-12 196608]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-05-27 221184]
"Backup NOW! Scheduler"="c:\program files\NewTech Infosystems\NTI Backup NOW! 4\Schdlr32.exe" [2005-03-24 86016]
"OPTENET_GUI"="c:\progra~1\CONTRO~1\bin\optgui.exe" [2006-12-20 404536]
"SystrayORAHSS"="c:\program files\Orange\Systray\SystrayApp.exe" [2007-09-25 94208]
"ORAHSSSessionManager"="c:\program files\Orange\SessionManager\SessionManager.exe" [2007-09-25 102400]
"F-Secure Manager"="c:\program files\Orange\AntivirusFirewall\Common\FSM32.EXE" [2008-04-23 182936]
"F-Secure TNB"="c:\program files\Orange\AntivirusFirewall\FSGUI\TNBUtil.exe" [2008-04-23 744032]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-06-01 7618560]
"NvMediaCenter"="NvMCTray.dll" - c:\windows\system32\nvmctray.dll [2006-06-01 86016]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"usnjsvc"=3 (0x3)
"Service CANALPLAY"=3 (0x3)
"ose"=3 (0x3)
"OPTENET_FILTER"=2 (0x2)
"IDriverT"=3 (0x3)
"FTRTSVC"=2 (0x2)
"FSMA"=2 (0x2)
"FSDFWD"=3 (0x3)
"fsbwsys"=2 (0x2)
"F-Secure Gatekeeper Handler Starter"=2 (0x2)
"Creative Service for CDROM Access"=2 (0x2)
"BackWeb Plug-in - 8520111"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"MoneyStartUp10.0"="c:\program files\Microsoft Money\System\Activation.exe"
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"LogitechVideoRepair"=c:\program files\Logitech\Video\ISStart.exe
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe"
"nwiz"=nwiz.exe /install
"NVMixerTray"="c:\program files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
"LogitechVideoTray"=c:\program files\Logitech\Video\LogiTray.exe
"NvMediaCenter"=RunDLL32.exe NvMCTray.dll,NvTaskbarInit
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\System32\\usmt\\migwiz.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\MSNMSGR.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [05/07/2008 09:10 51072]
R0 nvcchflt;NVIDIA Disk Cache Filter Driver;c:\windows\system32\drivers\nvcchflt.sys [01/01/1980 16640]
R0 PxHelper;PxHelper;c:\windows\system32\drivers\PxHelper.sys [19/11/2006 21:07 16000]
R1 F-Secure HIPS;F-Secure HIPS;c:\program files\Orange\AntivirusFirewall\HIPS\fshs.sys [05/07/2008 09:09 41184]
R3 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\Orange\AntivirusFirewall\Anti-Virus\minifilter\fsgk.sys [05/07/2008 09:09 77824]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [01/08/2009 09:38 38160]
S4 F-Secure Filter;F-Secure File System Filter;c:\program files\Orange\AntivirusFirewall\Anti-Virus\win2k\fsfilter.sys [05/07/2008 09:09 39776]
S4 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\Orange\AntivirusFirewall\Anti-Virus\win2k\fsrec.sys [05/07/2008 09:09 25184]
S4 OPTENET_FILTER;Orange Contrôle Parental;c:\program files\Controle Parental\bin\optproxy.exe [26/04/2008 09:21 624376]
.
Contents of the 'Scheduled Tasks' folder
2009-08-01 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2006-07-07 15:26]
2009-07-03 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2009-08-01 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-02-23 15:10]
2009-08-01 c:\windows\Tasks\Scheduled scanning task.job
- c:\progra~1\Orange\ANTIVI~1\ANTI-V~1\fsav.exe [2008-07-05 16:11]
2009-08-01 c:\windows\Tasks\User_Feed_Synchronization-{F7AC12C2-66BF-4C72-80F2-8F90F387C7A1}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 02:31]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{3041D03E-FD4B-44E0-B742-2D9B88305F98} - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.orange.fr/
mWindow Title =
LSP: c:\program files\Orange\AntivirusFirewall\FSPS\program\FSLSP.DLL
Trusted Zone: canalplay.com
Trusted Zone: canalplusactive.com
DPF: {304171C0-65EA-4B51-B5D9-93A311E26EB1} - hxxp://www.lessablesdolonne.com/webcam/MxPEG_ActiveX.cab
DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} - hxxp://as.photoprintit.de/ips-opdata/layout/default01/activex/IPSUploader.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-08-01 17:26
Windows 5.1.2600 Service Pack 3 FAT NTAPI
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-644092879-1985905135-1689222798-1010\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:e2,0c,1f,69,78,79,bd,02,cc,e7,b9,e3,40,b6,77,3e,f3,c3,60,89,4b,ae,1a,
90,c9,2a,8b,ca,8b,0d,c3,26,32,44,24,b5,0b,84,61,84,d0,47,4b,d4,c8,63,7c,f3,\
"??"=hex:22,09,a1,26,20,42,99,8f,25,ac,2f,8f,21,07,73,02
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"C0403E1900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
[HKEY_LOCAL_MACHINE\software\mpDRM\LicenseStore*]
"CheckValue"=dword:ba3464ba
"DA39A3EE"="E5E6B4B0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(700)
c:\windows\system32\Ati2evxx.dll
c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll
- - - - - - - > 'lsass.exe'(756)
c:\program files\Orange\AntivirusFirewall\FSPS\program\FSLSP.DLL
c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll
- - - - - - - > 'explorer.exe'(3884)
c:\program files\Orange\AntivirusFirewall\Spam Control\fsscoepl.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
- - - - - - - > 'csrss.exe'(660)
c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdc.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Orange\AntivirusFirewall\Anti-Virus\fsgk32st.exe
c:\program files\Orange\AntivirusFirewall\Common\FSMA32.EXE
c:\program files\Orange\AntivirusFirewall\Anti-Virus\FSGK32.EXE
c:\windows\system32\nvsvc32.exe
c:\program files\Orange\AntivirusFirewall\Common\FSMB32.EXE
c:\windows\system32\MsPMSPSv.exe
c:\program files\Orange\AntivirusFirewall\Common\FCH32.EXE
c:\program files\Orange\AntivirusFirewall\Common\FAMEH32.EXE
c:\program files\Orange\AntivirusFirewall\Anti-Virus\fsqh.exe
c:\program files\Orange\AntivirusFirewall\FSAUA\program\fsaua.exe
c:\program files\Orange\AntivirusFirewall\Anti-Virus\fssm32.exe
c:\program files\Orange\AntivirusFirewall\FWES\Program\fsdfwd.exe
c:\windows\system32\wscntfy.exe
c:\program files\Orange\AntivirusFirewall\Anti-Virus\fsav32.exe
c:\progra~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\1\AlertModule.exe
c:\windows\system32\rundll32.exe
c:\program files\Orange\AntivirusFirewall\FSGUI\fsguidll.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-08-01 17:31 - machine was rebooted
ComboFix-quarantined-files.txt 2009-08-01 15:31
Pre-Run: 58 711 965 696 octets libres
Post-Run: 65 172 307 968 octets libres
254 --- E O F --- 2009-07-29 10:23