voici le rapport combofix:
ComboFix 10-02-26.01 - YannBastian 26/02/2010 19:15:15.1.2 - x86
Microsoft® Windows Vista™ Édition Familiale Basique 6.0.6001.1.1252.33.1036.18.3070.2336 [GMT 1:00]
Lancé depuis: c:\users\YannBastian\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2373954164-2419952531-494492721-500
c:\$recycle.bin\S-1-5-21-3430781819-4112138520-4176161753-500
c:\$recycle.bin\S-1-5-21-379578684-575248035-2863804450-1000
c:\program files\autorun.inf
.
((((((((((((((((((((((((((((( Fichiers créés du 2010-01-26 au 2010-02-26 ))))))))))))))))))))))))))))))))))))
.
2010-02-26 18:27 . 2010-02-26 18:28 -------- d-----w- c:\users\YannBastian\AppData\Local\temp
2010-02-26 18:27 . 2010-02-26 18:27 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-02-25 16:14 . 2010-02-25 16:14 -------- d-----w- c:\users\YannBastian\AppData\Roaming\Malwarebytes
2010-02-25 16:14 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-02-25 16:14 . 2010-02-25 16:14 -------- d-----w- c:\programdata\Malwarebytes
2010-02-25 16:14 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-02-25 16:14 . 2010-02-25 16:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-02-25 14:40 . 2010-02-25 14:49 -------- d-----w- C:\Ad-Remover
2010-02-25 12:32 . 2010-02-25 12:33 -------- d-----w- c:\program files\trend micro
2010-02-25 12:32 . 2010-02-25 12:33 -------- d-----w- C:\rsit
2010-02-17 00:12 . 2010-02-17 00:17 194089856 ----a-w- C:\DungeonDefense_Install_2.2_JeuxVideo.com_14521.exe
2010-02-16 12:24 . 2010-02-16 12:24 467 ----a-w- C:\msmq.reg
2010-02-16 10:14 . 2010-02-17 17:49 23033 ----a-w- C:\Legend of the Seeker_2x11_HDTV.LOL.fr.zip
2010-02-06 16:38 . 2010-02-06 16:53 -------- d-----w- C:\cxl
2010-02-06 16:05 . 2010-02-08 17:47 -------- d-----w- C:\trainer torchlight
2010-02-02 20:16 . 2010-02-02 20:16 1882267 ----a-w- C:\AtlasLoot-v5.09.05.zip
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-02-26 18:23 . 2009-10-22 17:38 35465 ----a-w- c:\programdata\nvModes.dat
2010-02-26 17:53 . 2008-08-26 10:57 -------- d-----w- c:\programdata\NVIDIA
2010-02-26 17:51 . 2009-07-24 16:30 -------- d-----w- c:\users\YannBastian\AppData\Roaming\Mumble
2010-02-26 14:35 . 2009-08-29 12:13 -------- d-----w- c:\program files\Steam
2010-02-26 14:34 . 2009-11-24 20:08 -------- d-----w- c:\programdata\boost_interprocess
2010-02-26 01:01 . 2010-01-23 15:33 15944 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2010-02-25 17:21 . 2010-01-12 10:02 -------- d-----w- c:\users\YannBastian\AppData\Roaming\vlc
2010-02-24 14:07 . 2010-02-24 14:06 16 ----a-w- c:\users\YannBastian\AppData\Roaming\rbuwzv.dat
2010-02-24 10:15 . 2009-06-27 18:00 -------- d-----w- c:\programdata\Electronic Arts
2010-02-24 08:16 . 2009-10-02 16:53 181632 ------w- c:\windows\system32\MpSigStub.exe
2010-02-12 00:05 . 2009-07-04 07:32 284 ----a-w- c:\users\YannBastian\AppData\Roaming\wklnhst.dat
2010-02-11 02:17 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-02-08 17:52 . 2009-07-24 16:30 -------- d-----w- c:\program files\Mumble
2010-02-03 04:48 . 2009-01-28 11:30 -------- d-----w- c:\program files\World of Warcraft
2010-01-24 18:15 . 2010-01-24 18:03 -------- d-----w- c:\users\YannBastian\AppData\Roaming\dvdcss
2010-01-23 15:40 . 2010-01-23 15:33 -------- d-----w- c:\programdata\Hitman Pro
2010-01-23 15:33 . 2010-01-23 15:33 -------- d-----w- c:\program files\Hitman Pro 3.5
2010-01-23 15:33 . 2010-01-23 15:32 4955456 ----a-w- C:\HitmanPro35.exe
2010-01-21 07:48 . 2010-01-21 07:48 3268476 ----a-w- c:\programdata\AuctioneerSuite-5.7.4568.zip
2010-01-17 21:35 . 2010-01-17 21:35 1090977 ----a-w- c:\programdata\DBM-4.38-r3147-Core-and-WotLK-Mods.zip
2010-01-12 10:00 . 2010-01-12 10:00 -------- d-----w- c:\program files\VideoLAN
2010-01-12 09:59 . 2010-01-12 09:59 18030130 ----a-w- C:\vlc-1.0.3-win32.exe
2010-01-08 02:15 . 2008-08-26 10:59 -------- d-----w- c:\programdata\CyberLink
2009-12-31 02:21 . 2009-12-31 02:20 -------- d-----w- c:\program files\Google
2009-12-31 02:20 . 2009-02-14 18:12 -------- d-----w- c:\program files\DivX
2009-12-31 02:20 . 2009-12-31 02:20 -------- d-----w- c:\program files\Common Files\DivX Shared
2009-12-28 12:35 . 2010-02-10 02:10 11776 ----a-w- c:\windows\system32\tsbyuv.dll
2009-12-28 12:35 . 2010-02-10 02:10 1314816 ----a-w- c:\windows\system32\quartz.dll
2009-12-28 12:32 . 2010-02-10 02:10 22528 ----a-w- c:\windows\system32\msyuv.dll
2009-12-28 12:32 . 2010-02-10 02:10 31744 ----a-w- c:\windows\system32\msvidc32.dll
2009-12-28 12:32 . 2010-02-10 02:10 123904 ----a-w- c:\windows\system32\msvfw32.dll
2009-12-28 12:32 . 2010-02-10 02:10 13312 ----a-w- c:\windows\system32\msrle32.dll
2009-12-28 12:31 . 2010-02-10 02:10 82944 ----a-w- c:\windows\system32\mciavi32.dll
2009-12-28 12:31 . 2010-02-10 02:10 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2009-12-28 12:28 . 2010-02-10 02:10 91136 ----a-w- c:\windows\system32\avifil32.dll
2009-12-28 12:28 . 2010-02-10 02:10 65024 ----a-w- c:\windows\system32\avicap32.dll
2009-12-20 12:36 . 2009-12-20 12:36 12862712 ----a-w- C:\mumble-2009-12-16-1633-718da1.exe
2009-12-18 13:05 . 2010-01-22 03:36 833024 ----a-w- c:\windows\system32\wininet.dll
2009-12-18 13:01 . 2010-01-22 03:36 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-12-18 10:14 . 2010-01-22 03:36 26624 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-11 12:07 . 2010-02-10 02:10 301568 ----a-w- c:\windows\system32\drivers\srv.sys
2009-12-11 12:07 . 2010-02-10 02:10 98304 ----a-w- c:\windows\system32\drivers\srvnet.sys
2009-12-10 17:12 . 2009-12-10 17:12 246754 ----a-w- C:\Bartender4-4.4.2.zip
2009-12-09 19:37 . 2009-12-09 19:36 683716 ----a-w- C:\XPerl-3.0.7__3.3_Release_.zip
2009-12-09 19:36 . 2009-12-09 19:36 1058232 ----a-w- C:\DBM-4.32-r2645-Core-and-WotLK-Mods.zip
2009-12-08 20:52 . 2010-02-10 02:10 897624 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-12-08 20:52 . 2010-02-10 02:10 3597912 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-12-08 20:52 . 2010-02-10 02:10 3546200 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-12-08 14:04 . 2009-12-08 14:04 12836528 ----a-w- C:\Mumble-1.2.0~beta2.exe
2009-12-04 16:12 . 2010-02-10 02:10 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2009-12-04 16:12 . 2010-02-10 02:10 105472 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2009-12-04 12:37 . 2008-08-26 20:24 669328 ----a-w- c:\windows\system32\perfh00C.dat
2009-12-04 12:37 . 2008-08-26 20:24 123350 ----a-w- c:\windows\system32\perfc00C.dat
2004-07-23 14:50 . 2009-05-17 13:30 4363 ------w- c:\program files\ReadMe.txt
2004-07-23 07:53 . 2009-05-17 13:30 258048 ------w- c:\program files\Autorun.exe
2004-05-17 12:56 . 2009-05-17 13:30 3262 ------w- c:\program files\MedievalLords.ico
2003-12-19 10:45 . 2009-05-17 13:30 766 ------w- c:\program files\Autorun.ico
2003-12-19 10:45 . 2009-05-17 13:30 245408 ------w- c:\program files\unicows.dll
2008-08-26 20:38 . 2008-08-26 20:38 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-21 1233920]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-04-29 3338240]
"Steam"="c:\program files\steam\steam.exe" [2010-02-20 1217872]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"Multi File Downloader"="c:\program files\Multi File Downloader\MultiFileDownloader.exe" [2009-11-24 2744320]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-02 75008]
"DPService"="c:\program files\HP\DVDPlay\DPService.exe" [2008-06-11 90112]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_01\bin\jusched.exe" [2007-04-07 132760]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
R2 ezSharedSvc;Easybits Shared Services for Windows;c:\windows\system32\svchost.exe -k netsvcs [21/01/2008 03:33 21504]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [27/09/2009 15:48 240232]
S0 sptd;sptd;c:\windows\System32\drivers\sptd.sys [17/05/2009 18:44 721904]
S2 gupdate1ca89bfce2f08dc;Service Google Update (gupdate1ca89bfce2f08dc);c:\program files\Google\Update\GoogleUpdate.exe [31/12/2009 03:20 133104]
S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
--- Autres Services/Pilotes en mémoire ---
*Deregistered* - zroksaq
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
ezSharedSvc
.
Contenu du dossier 'Tâches planifiées'
2010-02-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-31 02:20]
2010-02-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-12-31 02:20]
.
.
------- Examen supplémentaire -------
.
FF - ProfilePath - c:\users\YannBastian\AppData\Roaming\Mozilla\Firefox\Profiles\g2ay6tdk.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1978305&SearchSource=3&q={searchTerms}
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1978305&q=
FF - component: c:\users\YannBastian\AppData\Roaming\Mozilla\Firefox\Profiles\g2ay6tdk.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Update\1.2.183.17\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-HPAdvisor - c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-02-26 19:27
Windows 6.0.6001 Service Pack 1 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\npggsvc]
"ImagePath"="c:\windows\system32\GameMon.des -service"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\zroksaq]
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-3430781819-4112138520-4176161753-1000\Software\SecuROM\License information*]
"datasecu"=hex:78,d7,71,06,eb,9d,f2,3f,5e,7c,94,76,94,37,9b,ac,02,00,40,61,30,
07,ea,ad,b6,b0,22,f4,10,06,3b,81,ab,c4,8c,bf,a9,e9,dd,5d,31,4a,5c,9c,d9,a6,\
"rkeysecu"=hex:3e,80,9e,c4,40,b4,90,83,87,8e,33,49,64,ac,f8,d9
.
Heure de fin: 2010-02-26 19:31:11
ComboFix-quarantined-files.txt 2010-02-26 18:31
Avant-CF: 169 337 008 128 octets libres
Après-CF: 169 280 077 824 octets libres
- - End Of File - - E406DBBE5A445DD32FC267A2D224A754