voilà c'est fait ! voici le rapport :
ComboFix 10-07-24.03 - yoan schieber 25/07/2010 12:46:24.1.1 - FAT32x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1022.631 [GMT 2:00]
Lancé depuis: c:\documents and settings\yoan schieber\Bureau\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: Panda Antivirus 2008 *On-access scanning disabled* (Updated) {EEE2D94A-D4C1-421A-AB2C-2CE8FE51747A}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\yoan schieber\Application Data\avdrn.dat
c:\documents and settings\yoan schieber\real.txt
c:\program files\Internet Explorer\fxavx.ini
c:\program files\WinPCap
c:\program files\WinPCap\rpcapd.exe
c:\windows\system32\_000005_.tmp.dll
c:\windows\system32\1054w.exe
c:\windows\system32\4043179183.dat
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\real.txt
c:\windows\system32\SHELLLNK.TLB
c:\windows\system32\tmp.reg
c:\windows\system32\WanPacket.dll
c:\windows\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_BOONTY_GAMES
-------\Legacy_NPF
-------\Legacy_NTLMSSPWUAUSERV
-------\Service_Boonty Games
-------\Service_npf
-------\Service_NtLmSspwuauserv
((((((((((((((((((((((((((((( Fichiers créés du 2010-06-25 au 2010-07-25 ))))))))))))))))))))))))))))))))))))
.
2010-07-25 10:55 . 2010-07-25 10:55 32 ----a-w- c:\windows\system32\4043179183.dat
2010-07-25 08:37 . 2010-07-25 08:37 -------- d-----w- c:\program files\ZHPDiag
2010-07-24 09:23 . 2010-07-24 09:23 -------- d-----w- C:\smit
2010-07-23 20:09 . 2010-07-23 20:09 -------- d-----w- c:\windows\system32\wbem\Repository
2010-07-23 19:15 . 2009-06-30 07:37 28552 ----a-w- c:\windows\system32\drivers\pavboot.sys
2010-07-23 19:15 . 2010-07-23 19:15 -------- d-----w- c:\program files\Panda Security
2010-07-23 17:43 . 2010-07-23 17:43 -------- d-----w- c:\windows\BDOSCAN8
2010-07-23 08:28 . 2010-07-25 08:27 63488 ----a-w- c:\documents and settings\yoan schieber\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-07-23 08:28 . 2010-07-23 08:28 52224 ----a-w- c:\documents and settings\yoan schieber\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-07-23 08:28 . 2010-07-25 08:26 117760 ----a-w- c:\documents and settings\yoan schieber\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-07-23 08:27 . 2010-07-23 08:27 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-07-23 08:27 . 2010-07-23 08:27 -------- d-----w- c:\documents and settings\yoan schieber\Application Data\SUPERAntiSpyware.com
2010-07-23 08:27 . 2010-07-23 08:27 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-07-23 08:16 . 2010-07-23 08:16 -------- d-----w- c:\documents and settings\All Users\Application Data\Comodo Downloader
2010-07-22 19:10 . 2010-07-22 19:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
2010-07-22 12:56 . 2010-07-22 12:56 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2010-07-22 11:03 . 2010-07-22 11:03 -------- d-----w- c:\program files\TeaTimer (Spybot - Search & Destroy)
2010-07-22 11:03 . 2010-07-22 11:03 -------- d-----w- c:\program files\SDHelper (Spybot - Search & Destroy)
2010-07-22 11:03 . 2010-07-22 11:03 -------- d-----w- c:\program files\Misc. Support Library (Spybot - Search & Destroy)
2010-07-22 11:03 . 2010-07-22 11:03 -------- d-----w- c:\program files\File Scanner Library (Spybot - Search & Destroy)
2010-07-22 10:22 . 2008-04-13 18:40 34688 ----a-w- c:\windows\system32\drivers\lbrtfdc.sys
2010-07-22 10:22 . 2008-04-13 18:40 34688 ----a-w- c:\windows\system32\dllcache\lbrtfdc.sys
2010-07-22 10:22 . 2008-04-13 18:41 8576 ----a-w- c:\windows\system32\drivers\i2omgmt.sys
2010-07-22 10:22 . 2008-04-13 18:41 8576 ----a-w- c:\windows\system32\dllcache\i2omgmt.sys
2010-07-22 10:21 . 2008-04-13 18:40 8192 ----a-w- c:\windows\system32\drivers\Changer.sys
2010-07-22 10:21 . 2008-04-13 18:40 8192 ----a-w- c:\windows\system32\dllcache\changer.sys
2010-07-15 15:28 . 2010-07-15 15:28 -------- d-----w- c:\documents and settings\yoan schieber\Application Data\muvee Technologies
2010-07-15 15:27 . 2010-07-15 15:28 -------- d-----w- c:\program files\muvee Technologies
2010-07-15 15:27 . 2010-07-15 15:27 -------- d-----w- c:\windows\SxsCaPendDel
2010-07-15 15:27 . 2010-07-15 15:27 -------- d-----w- c:\documents and settings\All Users\Application Data\muvee Technologies
2010-07-14 04:11 . 2010-06-14 14:31 744448 ------w- c:\windows\system32\dllcache\helpsvc.exe
2010-07-12 16:26 . 2010-07-12 16:27 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2010-07-12 16:14 . 2010-07-12 16:14 -------- d-----w- c:\documents and settings\yoan schieber\Application Data\ElevatedDiagnostics
2010-07-12 15:02 . 2010-07-12 15:03 60348 ----a-w- c:\windows\system32\ZoomUnin.exe
2010-07-12 14:30 . 2010-07-12 14:30 -------- d-----w- c:\documents and settings\All Users\Application Data\Creative
2010-07-12 14:28 . 2010-07-12 14:28 -------- d--h--w- c:\documents and settings\All Users\Application Data\{907A85CA-E023-4161-8F5C-E72C340031D2}
2010-07-12 14:28 . 2008-10-31 04:58 2641598 ----a-w- c:\documents and settings\All Users\Application Data\{907A85CA-E023-4161-8F5C-E72C340031D2}\VadoHDCodec.exe
2010-07-12 14:28 . 2010-07-12 14:28 -------- d-----w- c:\program files\Creative
2010-07-10 17:27 . 2010-07-10 17:27 -------- d-----w- c:\program files\Steinberg
2010-07-10 17:26 . 2010-07-10 17:26 2892 ----a-w- c:\windows\system32\audcon.sys
2010-07-10 17:26 . 2010-07-10 17:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Syncrosoft
2010-07-10 17:26 . 2006-11-23 16:20 18432 ----a-w- c:\windows\system32\drivers\synasUSB.sys
2010-07-10 17:26 . 2006-01-29 10:48 45056 ----a-w- c:\windows\system32\Synsopos.exe
2010-07-10 17:26 . 2007-02-23 11:57 757760 ----a-w- c:\windows\system32\SYNSOACC.dll
2010-07-10 17:26 . 2006-01-29 10:48 147456 ----a-w- c:\windows\system32\SynsoLChk.dll
2010-07-10 17:26 . 2010-07-10 17:26 -------- d-----w- c:\program files\Syncrosoft
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-22 12:56 . 2010-07-22 11:28 36 ----a-w- c:\windows\system32\config\systemprofile\Application Data\vdnxlf.dat
2010-07-22 10:21 . 2010-07-22 10:21 12 ----a-w- c:\documents and settings\NetworkService\Application Data\vdnxlf.dat
2010-07-15 15:28 . 2006-05-25 08:06 48032 ----a-w- c:\documents and settings\yoan schieber\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-06-24 04:27 . 2005-01-23 10:37 85984 ----a-w- c:\windows\system32\perfc00C.dat
2010-06-24 04:27 . 2005-01-23 10:37 512624 ----a-w- c:\windows\system32\perfh00C.dat
2010-06-14 14:31 . 2004-08-05 03:00 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\HelpSvc.exe
2010-06-11 12:01 . 2010-06-11 12:01 61440 ----a-w- c:\documents and settings\yoan schieber\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-56d30c0a-n\decora-sse.dll
2010-06-11 12:01 . 2010-06-11 12:01 503808 ----a-w- c:\documents and settings\yoan schieber\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-3dc35842-n\msvcp71.dll
2010-06-11 12:01 . 2010-06-11 12:01 499712 ----a-w- c:\documents and settings\yoan schieber\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-3dc35842-n\jmc.dll
2010-06-11 12:01 . 2010-06-11 12:01 348160 ----a-w- c:\documents and settings\yoan schieber\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-3dc35842-n\msvcr71.dll
2010-06-11 12:01 . 2010-06-11 12:01 12800 ----a-w- c:\documents and settings\yoan schieber\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-56d30c0a-n\decora-d3d.dll
2010-06-08 04:24 . 2010-06-06 15:39 1 ----a-w- c:\documents and settings\yoan schieber\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-06-06 15:39 . 2010-06-06 15:39 -------- d-----w- c:\documents and settings\yoan schieber\Application Data\OpenOffice.org
2010-06-06 15:37 . 2010-06-06 15:37 -------- d-----w- c:\program files\JRE
2010-06-06 15:37 . 2010-06-06 15:37 -------- d-----w- c:\program files\OpenOffice.org 3
2010-06-06 15:34 . 2009-08-17 16:40 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-05-06 10:33 . 2005-07-03 01:16 916480 ----a-w- c:\windows\system32\wininet.dll
2010-05-02 08:08 . 2005-03-02 17:07 1851392 ----a-w- c:\windows\system32\win32k.sys
2009-08-16 12:07 . 2009-08-16 11:21 32 --sha-w- c:\windows\system32\drivers\fidbox.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2010-03-29 2343120]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-07-19 2403568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-04 8523776]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\yoan schieber\Menu D'marrer\Programmes\D'marrage\
ntuser_mssec.exe [2008-4-14 81920]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avldr]
2007-02-15 18:02 50736 ----a-w- c:\windows\system32\avldr.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Fmu43.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MNetTraceCleaner]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Boonty Games"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [23/07/2010 21:15 28552]
R1 Asapi;Asapi;c:\windows\system32\drivers\asapi.sys [3/07/2007 6:31 10240]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [17/02/2010 20:25 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [10/05/2010 20:41 67656]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [16/08/2009 14:22 108289]
S0 Fmu43;Fmu43;c:\windows\system32\Drivers\Fmu43.sys --> c:\windows\system32\Drivers\Fmu43.sys [?]
S1 soqwx32;soqwx32;\??\c:\windows\system32\drivers\soqwx32.sys --> c:\windows\system32\drivers\soqwx32.sys [?]
S2 AcerSamSs;Acer Media Server AcerSamSs;c:\windows\system32\1033d.exe srv --> c:\windows\system32\1033d.exe srv [?]
S2 CoachCap;FUJIFILM EX-10/EX-20 PC V1.00;c:\windows\system32\drivers\CoachCap.sys --> c:\windows\system32\drivers\CoachCap.sys [?]
S2 myAgtSvc;Service de protection contre les virus et les logiciels espions McAfee;"c:\program files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe" /ServiceStart --> c:\program files\McAfee\Managed VirusScan\Agent\myAgtSvc.exe [?]
S3 02e99;02e99;\??\c:\windows\system32\02e99.sys --> c:\windows\system32\02e99.sys [?]
S3 0318D;0318D;\??\c:\windows\system32\0318D.sys --> c:\windows\system32\0318D.sys [?]
S3 15a96;15a96;\??\c:\windows\system32\15a96.sys --> c:\windows\system32\15a96.sys [?]
S3 186A1;186A1;\??\c:\windows\system32\186A1.sys --> c:\windows\system32\186A1.sys [?]
S3 1b293;1b293;\??\c:\windows\system32\1b293.sys --> c:\windows\system32\1b293.sys [?]
S3 2257E;2257E;\??\c:\windows\system32\2257E.sys --> c:\windows\system32\2257E.sys [?]
S3 3d492;3d492;\??\c:\windows\system32\3d492.sys --> c:\windows\system32\3d492.sys [?]
S3 3e386;3e386;\??\c:\windows\system32\3e386.sys --> c:\windows\system32\3e386.sys [?]
S3 4b487;4b487;\??\c:\windows\system32\4b487.sys --> c:\windows\system32\4b487.sys [?]
S3 5907D;5907D;\??\c:\windows\system32\5907D.sys --> c:\windows\system32\5907D.sys [?]
S3 62797;62797;\??\c:\windows\system32\62797.sys --> c:\windows\system32\62797.sys [?]
S3 62e9F;62e9F;\??\c:\windows\system32\62e9F.sys --> c:\windows\system32\62e9F.sys [?]
S3 77895;77895;\??\c:\windows\system32\77895.sys --> c:\windows\system32\77895.sys [?]
S3 78c83;78c83;\??\c:\windows\system32\78c83.sys --> c:\windows\system32\78c83.sys [?]
S3 7c59D;7c59D;\??\c:\windows\system32\7c59D.sys --> c:\windows\system32\7c59D.sys [?]
S3 80f8A;80f8A;\??\c:\windows\system32\80f8A.sys --> c:\windows\system32\80f8A.sys [?]
S3 82785;82785;\??\c:\windows\system32\82785.sys --> c:\windows\system32\82785.sys [?]
S3 8509E;8509E;\??\c:\windows\system32\8509E.sys --> c:\windows\system32\8509E.sys [?]
S3 8548B;8548B;\??\c:\windows\system32\8548B.sys --> c:\windows\system32\8548B.sys [?]
S3 9e57F;9e57F;\??\c:\windows\system32\9e57F.sys --> c:\windows\system32\9e57F.sys [?]
S3 9e881;9e881;\??\c:\windows\system32\9e881.sys --> c:\windows\system32\9e881.sys [?]
S3 9f291;9f291;\??\c:\windows\system32\9f291.sys --> c:\windows\system32\9f291.sys [?]
S3 a109A;a109A;\??\c:\windows\system32\a109A.sys --> c:\windows\system32\a109A.sys [?]
S3 a569B;a569B;\??\c:\windows\system32\a569B.sys --> c:\windows\system32\a569B.sys [?]
S3 b02A7;b02A7;\??\c:\windows\system32\b02A7.sys --> c:\windows\system32\b02A7.sys [?]
S3 c328F;c328F;\??\c:\windows\system32\c328F.sys --> c:\windows\system32\c328F.sys [?]
S3 c5389;c5389;\??\c:\windows\system32\c5389.sys --> c:\windows\system32\c5389.sys [?]
S3 d24A6;d24A6;\??\c:\windows\system32\d24A6.sys --> c:\windows\system32\d24A6.sys [?]
S3 d88A3;d88A3;\??\c:\windows\system32\d88A3.sys --> c:\windows\system32\d88A3.sys [?]
S3 daa82;daa82;\??\c:\windows\system32\daa82.sys --> c:\windows\system32\daa82.sys [?]
S3 DMSKSSRh;DMSKSSRh;\??\c:\docume~1\YOANSC~1\LOCALS~1\Temp\DMSKSSRh.sys --> c:\docume~1\YOANSC~1\LOCALS~1\Temp\DMSKSSRh.sys [?]
S3 e548E;e548E;\??\c:\windows\system32\e548E.sys --> c:\windows\system32\e548E.sys [?]
S3 f01A5;f01A5;\??\c:\windows\system32\f01A5.sys --> c:\windows\system32\f01A5.sys [?]
S3 faaA2;faaA2;\??\c:\windows\system32\faaA2.sys --> c:\windows\system32\faaA2.sys [?]
S3 LGDDCDevice;LGDDCDevice;c:\program files\LG Soft India\forteManager\bin\I2CDriver.sys [21/05/2009 18:02 14336]
S3 LGII2CDevice;LGII2CDevice;c:\program files\LG Soft India\forteManager\bin\pii2cdriver.sys [21/05/2009 18:02 17408]
S3 motport;Motorola USB Diagnostic Port;c:\windows\system32\drivers\motport.sys [24/12/2008 14:57 21376]
S3 PAC207;Trust WB-1400T Webcam;c:\windows\system32\drivers\pfc027.sys [24/02/2005 12:29 162176]
S3 SynasUSB;SynasUSB;c:\windows\system32\drivers\synasUSB.sys [10/07/2010 19:26 18432]
S3 z530bus;Sony Ericsson Z530 Driver driver (WDM);c:\windows\system32\drivers\z530bus.sys [5/01/2007 13:41 58288]
S3 z530mdfl;Sony Ericsson Z530 USB WMC Modem Filter;c:\windows\system32\drivers\z530mdfl.sys [5/01/2007 13:41 8336]
S3 z530mdm;Sony Ericsson Z530 USB WMC Modem Driver;c:\windows\system32\drivers\z530mdm.sys [5/01/2007 13:41 94064]
S3 z530mgmt;Sony Ericsson Z530 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\z530mgmt.sys [6/01/2007 18:23 85408]
S3 z530obex;Sony Ericsson Z530 USB WMC OBEX Interface;c:\windows\system32\drivers\z530obex.sys [6/01/2007 18:23 83344]
.
Contenu du dossier 'Tâches planifiées'
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.be/
uInternet Connection Wizard,ShellNext = hxxp://google.be/
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.zebulon.fr/scan8/oscan8.cab
.
- - - - ORPHELINS SUPPRIMES - - - -
Toolbar-Locked - (no file)
AddRemove-RD - c:\program files\d-lusion\DT\uninstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-07-25 12:57
Windows 5.1.2600 Service Pack 3 FAT NTAPI
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
c:\documents and settings\yoan schieber\Menu Démarrer\Programmes\Démarrage\ntuser_mssec.exe 98304 bytes
Scan terminé avec succès
Fichiers cachés: 1
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(708)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\avldr.dll
- - - - - - - > 'explorer.exe'(1040)
c:\windows\system32\eappprxy.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\System32\PAStiSvc.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2010-07-25 12:58:37 - La machine a redémarré
ComboFix-quarantined-files.txt 2010-07-25 10:58
Avant-CF: 62.808.293.376 octets libres
Après-CF: 62.741.905.408 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
- - End Of File - - FFD5154C6DCBAE447F0E8DB7C9558AD3