Voila le rapport désolé du retard :
ComboFix 09-10-01.05 - Quentin 03/10/2009 13:07.1.4 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.3326.2865 [GMT 2:00]
Lancé depuis: f:\mes téléchargements\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrateur\Application Data\020000005a788f4f517C.manifest
c:\documents and settings\Administrateur\Application Data\020000005a788f4f517O.manifest
c:\documents and settings\Administrateur\Application Data\020000005a788f4f517P.manifest
c:\documents and settings\Administrateur\Application Data\020000005a788f4f517S.manifest
c:\recycler\S-1-5-21-448539723-2000478354-839522115-500
F:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Service_NPF
((((((((((((((((((((((((((((( Fichiers créés du 2009-09-03 au 2009-10-03 ))))))))))))))))))))))))))))))))))))
.
2009-10-02 12:44 . 2009-10-02 12:44 -------- d-----w- c:\documents and settings\Quentin\Application Data\Malwarebytes
2009-10-02 12:44 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-10-02 12:44 . 2009-10-02 12:44 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-10-02 12:44 . 2009-10-02 12:44 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2009-10-02 12:44 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-10-02 12:38 . 2009-10-02 12:42 -------- d-----w- C:\ToolBar SD
2009-10-02 11:58 . 2009-10-02 11:59 -------- d-----w- C:\rsit
2009-10-01 17:24 . 2009-10-01 17:24 -------- d--h--w- c:\windows\PIF
2009-10-01 17:07 . 2009-10-01 17:07 -------- d-----w- c:\windows\system32\wbem\Repository
2009-10-01 17:07 . 2009-10-01 17:07 -------- d-----w- c:\documents and settings\Quentin\Application Data\IDM
2009-09-16 16:43 . 2009-09-19 11:12 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\NOS
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-03 11:27 . 2009-08-03 17:36 -------- d-----w- c:\documents and settings\Quentin\Application Data\DMCache
2009-10-02 22:13 . 2009-02-04 16:51 -------- d-----w- c:\documents and settings\Quentin\Application Data\vlc
2009-10-01 20:10 . 2009-02-04 17:27 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2009-10-01 17:09 . 2008-12-27 00:58 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-10-01 17:07 . 2009-02-06 17:20 -------- d-----w- c:\documents and settings\Quentin\Application Data\dvdcss
2009-10-01 09:20 . 2009-01-14 10:25 -------- d-----w- c:\program files\BitComet
2009-09-29 11:43 . 2009-07-26 21:16 -------- d-----w- c:\documents and settings\Quentin\Application Data\Babylon
2009-09-29 11:43 . 2009-07-26 21:16 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Babylon
2009-09-26 09:22 . 2009-08-11 22:52 -------- d-----w- c:\program files\Free FLV Converter
2009-09-21 15:28 . 2009-08-03 17:36 198064 ----a-w- c:\documents and settings\Quentin\Application Data\IDM\idmmzcc3\components\idmmzcc.dll
2009-09-19 11:30 . 2001-08-24 12:00 79268 ----a-w- c:\windows\system32\perfc00C.dat
2009-09-19 11:30 . 2001-08-24 12:00 495068 ----a-w- c:\windows\system32\perfh00C.dat
2009-08-29 15:06 . 2009-08-29 15:06 -------- d-----w- c:\program files\MSN Reaper
2009-08-26 14:32 . 2009-08-11 22:52 299008 ----a-w- c:\windows\system32\TubeFinder.exe
2009-08-24 23:44 . 2009-08-03 18:14 -------- d-----w- c:\program files\Glary Utilities
2009-08-24 12:52 . 2009-06-25 15:43 -------- d-----w- c:\program files\Bewan Powerline E200
2009-08-18 12:39 . 2009-05-03 15:25 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-08-14 18:28 . 2009-08-11 22:35 -------- d-----w- c:\program files\Replay Converter 3
2009-08-11 00:43 . 2009-02-15 23:18 -------- d-----w- c:\documents and settings\Quentin\Application Data\LimeWire
2009-08-07 21:41 . 2009-08-07 17:51 -------- d-----w- c:\documents and settings\Quentin\Application Data\DivX
2009-08-07 17:39 . 2009-08-07 16:26 -------- d-----w- c:\program files\DivX
2009-08-07 17:38 . 2009-08-07 17:38 -------- d-----w- c:\program files\Fichiers communs\DivX Shared
2009-08-07 16:27 . 2009-08-07 16:26 -------- d-----w- c:\documents and settings\Quentin\Application Data\Dr. DivX 2.0 OSS
2009-08-06 18:42 . 2009-08-06 18:42 -------- d-----w- c:\program files\VirtualDubMOD
2009-08-03 17:12 . 2009-08-03 17:12 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"IDMan"="c:\downloads\IDM-Internet-Download-Manager-v.5.17\IDMan.exe" [2009-04-27 2799024]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-03 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"KMCONFIG"="c:\program files\Keyboard & Mouse Driver\StartAutorun.exe" [2008-05-30 212992]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-03-07 7557120]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-03-07 86016]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2008-06-27 16875008]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-03-07 1519616]
c:\documents and settings\All Users.WINDOWS\Menu D‚marrer\Programmes\D‚marrage\
MSI US54SE 802.11b+g USB Stick Utility.lnk - c:\program files\MSI\US54SE_Utility\ZDWlan.exe [2009-6-3 483328]
[HKLM\~\startupfolder\C:^Documents and Settings^Quentin^Menu Démarrer^Programmes^Démarrage^Yahoo! Widget Engine.lnk]
backup=c:\windows\pss\Yahoo! Widget Engine.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe"
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"SW24"=c:\windows\system32\sw24.exe
"SW20"=c:\windows\system32\sw20.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"f:\\Incoming\\Emule extrem\\emule.exe"=
"c:\\Program Files\\THQ\\Frontlines-Fuel of War\\Binaries\\FFOW.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaWmp.exe"=
"c:\\Program Files\\Activision\\Call of Duty - World at War\\CoDWaW.exe"=
"c:\\Program Files\\Deep Silver\\S.T.A.L.K.E.R. - Clear Sky\\bin\\xrEngine.exe"=
"c:\\Program Files\\Deep Silver\\S.T.A.L.K.E.R. - Clear Sky\\bin\\dedicated\\xrEngine.exe"=
"f:\\Incoming\\Defcon.READNFO-PSYFER\\defcon.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Free Music Zilla\\FMZilla.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"28420:TCP"= 28420:TCP:BitComet 28420 TCP
"28420:UDP"= 28420:UDP:BitComet 28420 UDP
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [03/05/2009 17:25 108289]
R2 gearsec;gearsec;c:\windows\system32\gearsec.exe [01/12/2003 15:27 53248]
R2 KMWDSERVICE;Keyboard And Mouse Communication Service;c:\program files\Keyboard & Mouse Driver\KMWDSrv.exe [23/06/2008 22:28 208896]
R3 ovt530;Webcam Deluxe;c:\windows\system32\drivers\ov530vid.sys [12/02/2009 20:09 161792]
S2 gupdate1c9bc9162b38fbb;Google Update Service (gupdate1c9bc9162b38fbb);c:\program files\Google\Update\GoogleUpdate.exe [14/04/2009 01:41 133104]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\magix\Common\Database\bin\fbserver.exe [08/03/2009 17:14 1527900]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [29/05/2009 17:13 234864]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9C450606-ED24-4958-92BA-B8940C99D441}]
c:\program files\PixiePack Codec Pack\InstallerHelper.exe
.
Contenu du dossier 'Tâches planifiées'
2009-09-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-10-03 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-08-03 14:55]
2009-10-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-13 23:41]
2009-10-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-04-13 23:41]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.files-ftp.com/~unicorni/phpBB2/index.php
mWindow Title =
uInternet Settings,ProxyOverride = *.local
IE: &Clean Traces
IE: &D&ownload &with BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
IE: &D&ownload all video with BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
IE: &D&ownload all with BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
IE: &Download with &DAP
IE: Download &all with DAP
IE: E&xporter vers Microsoft Excel - c:\progra~1\MI1933~1\Office12\EXCEL.EXE/3000
IE: Translate this web page with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
IE: Translate with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm
IE: Télécharger avec IDM - c:\downloads\IDM-Internet-Download-Manager-v.5.17\IEExt.htm
IE: Télécharger le contenu de video FLV avec IDM - c:\downloads\IDM-Internet-Download-Manager-v.5.17\IEGetVL.htm
IE: Télécharger tous les liens avec IDM - c:\downloads\IDM-Internet-Download-Manager-v.5.17\IEGetAll.htm
IE: {{F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - res://c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm
FF - ProfilePath - c:\documents and settings\Quentin\Application Data\Mozilla\Firefox\Profiles\hmdq83ht.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
FF - prefs.js: network.proxy.type - 2
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{FF6C3CF0-4B15-11D1-ABED-709549C10000} - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-10-03 13:26
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
"scansk"=hex(0):ee,d4,74,c2,d4,66,7a,bb,89,c1,07,f0,04,c0,51,89,ff,31,42,f2,62,
c4,96,3f,e2,03,fc,79,72,38,c7,68,f2,33,ef,78,fe,69,a3,ab,00,00,00,00,00,00,\
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{e0535561-c7b6-4a16-baa8-87b02ab9e214}]
@Denied: (Full) (Everyone)
"Model"=dword:000000f3
"Therad"=dword:0000001e
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,85,b1,12,f9,90,dd,23,a1,49,8c,bf,1a,9d,fe,41,71,cb,3f,46,a4,7c,ab,\
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'explorer.exe'(3968)
c:\windows\system32\msi.dll
c:\windows\system32\dvmurl.dll
c:\program files\Bonjour\mdnsNSP.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\Hercules\WebCam Station\PhotoImpression\share\pihook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\nvsvc32.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\Keyboard & Mouse Driver\KMCONFIG.exe
c:\windows\system32\rundll32.exe
c:\program files\Keyboard & Mouse Driver\KMProcess.exe
c:\windows\SoundMan.exe
.
**************************************************************************
.
Heure de fin: 2009-10-03 13:30 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-10-03 11:30
Avant-CF: 71 485 382 656 octets libres
Après-CF: 71 399 686 144 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
226