voici le rapport de combofix !
ComboFix 10-08-24.02 - seb 24/08/2010 21:42:50.1.4 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.3070.2441 [GMT 2:00]
Lancé depuis: c:\documents and settings\seb\Mes documents\Downloads\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\seb\Application Data\cisvc.exe
c:\documents and settings\seb\Application Data\Microsoft\comrepl.exe
c:\documents and settings\seb\Application Data\Microsoft\spoolsv.exe
c:\documents and settings\seb\Application Data\mstsc.exe
c:\documents and settings\seb\Local Settings\Application Data\Microsoft\logman.exe
c:\documents and settings\seb\Local Settings\Application Data\Microsoft\rsvp.exe
c:\documents and settings\seb\Local Settings\Application Data\Microsoft\sessmgr.exe
c:\documents and settings\seb\Local Settings\Application Data\spoolsv.exe
c:\windows\CISVC.exe
c:\windows\Downloaded Program Files\f3initialsetup1.0.1.1.inf
c:\windows\logman.exe
c:\windows\system\dllhst3g.exe
c:\windows\system32\drivers\comrepl.exe
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MYWEBSEARCHSERVICE
((((((((((((((((((((((((((((( Fichiers créés du 2010-07-24 au 2010-08-24 ))))))))))))))))))))))))))))))))))))
.
2010-08-24 18:05 . 2010-08-24 19:05 -------- d-----w- c:\program files\ZHPDiag
2010-08-24 17:17 . 2010-08-24 17:17 -------- d-----w- c:\documents and settings\All Users\Application Data\AVS4YOU
2010-08-24 17:17 . 2010-08-24 17:17 -------- d-----w- c:\documents and settings\seb\Application Data\AVS4YOU
2010-08-24 17:17 . 2010-08-24 17:17 -------- d-----w- c:\program files\Fichiers communs\AVSMedia
2010-08-24 17:17 . 2009-06-30 15:32 24576 ----a-w- c:\windows\system32\msxml3a.dll
2010-08-23 10:38 . 2010-08-23 10:38 -------- d-----w- c:\documents and settings\seb\Application Data\Uniblue
2010-08-23 10:38 . 2010-08-23 10:38 -------- d-----w- c:\program files\Uniblue
2010-08-19 10:35 . 2010-08-19 10:35 -------- d-----w- c:\documents and settings\seb\Application Data\Malwarebytes
2010-08-19 10:35 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-19 10:35 . 2010-08-19 10:35 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-08-19 10:35 . 2010-08-19 10:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-08-19 10:35 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-08-19 10:06 . 2010-08-19 13:02 -------- d-----w- c:\documents and settings\seb\Application Data\vlc
2010-08-19 09:35 . 2008-04-14 02:33 221184 ----a-w- c:\windows\system32\wmpns.dll
2010-08-18 15:26 . 2010-08-18 15:26 -------- d-----w- c:\program files\Fichiers communs\Java
2010-08-18 14:53 . 2010-08-18 14:53 503808 ----a-w- c:\documents and settings\seb\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5db06adf-n\msvcp71.dll
2010-08-18 14:53 . 2010-08-18 14:53 499712 ----a-w- c:\documents and settings\seb\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5db06adf-n\jmc.dll
2010-08-18 14:53 . 2010-08-18 14:53 348160 ----a-w- c:\documents and settings\seb\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5db06adf-n\msvcr71.dll
2010-08-18 14:53 . 2010-08-18 14:53 61440 ----a-w- c:\documents and settings\seb\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-2ed7a594-n\decora-sse.dll
2010-08-18 14:53 . 2010-08-18 14:53 12800 ----a-w- c:\documents and settings\seb\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-2ed7a594-n\decora-d3d.dll
2010-08-17 09:03 . 2010-08-19 13:55 -------- d-----w- c:\documents and settings\seb\Local Settings\Application Data\WMTools Downloaded Files
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-24 19:50 . 2009-08-28 14:29 16608 ----a-w- c:\windows\gdrv.sys
2010-08-24 17:42 . 2010-06-21 20:13 69632 ----a-w- c:\documents and settings\seb\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-24 16:35 . 2009-09-01 16:47 -------- d-----w- c:\program files\IncrediMail
2010-08-19 12:52 . 2009-09-01 13:26 -------- d-----w- c:\program files\Windows Media Connect 2
2010-08-19 09:41 . 2010-07-16 16:02 -------- d-----w- c:\program files\Softonic_France
2010-08-18 15:25 . 2009-09-29 19:23 -------- d-----w- c:\program files\Java
2010-08-18 15:16 . 2006-03-02 12:00 85644 ----a-w- c:\windows\system32\perfc00C.dat
2010-08-18 15:16 . 2006-03-02 12:00 513498 ----a-w- c:\windows\system32\perfh00C.dat
2010-08-18 15:12 . 2009-09-01 12:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-07-17 17:21 . 2009-08-28 14:46 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-17 17:21 . 2010-07-17 17:21 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-07-17 17:21 . 2009-08-28 14:46 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-07-17 03:00 . 2010-06-02 07:26 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-16 16:06 . 2009-11-03 09:42 -------- d-----w- c:\documents and settings\seb\Application Data\GigaTribe
2010-07-16 16:02 . 2010-07-16 16:02 -------- d-----w- c:\program files\Conduit
2010-06-30 12:32 . 2006-03-02 12:00 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-24 12:17 . 2006-03-02 12:00 832512 ----a-w- c:\windows\system32\wininet.dll
2010-06-24 12:17 . 2006-03-02 12:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2010-06-24 12:17 . 2006-03-02 12:00 17408 ----a-w- c:\windows\system32\corpol.dll
2010-06-24 09:02 . 2006-03-02 12:00 1852032 ----a-w- c:\windows\system32\win32k.sys
2010-06-21 15:27 . 2006-03-02 12:00 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-17 14:03 . 2006-03-02 12:00 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2009-08-28 13:51 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-14 07:42 . 2006-03-02 12:00 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-06-03 15:03 . 2009-08-28 14:46 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-27 17:50 . 2010-05-27 17:50 503808 ----a-w- c:\documents and settings\seb\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-1b0c023d-n\msvcp71.dll
2010-05-27 17:50 . 2010-05-27 17:50 499712 ----a-w- c:\documents and settings\seb\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-1b0c023d-n\jmc.dll
2010-05-27 17:50 . 2010-05-27 17:50 348160 ----a-w- c:\documents and settings\seb\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-1b0c023d-n\msvcr71.dll
2010-05-27 17:50 . 2010-05-27 17:50 61440 ----a-w- c:\documents and settings\seb\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-24d16ad7-n\decora-sse.dll
2010-05-27 17:50 . 2010-05-27 17:50 12800 ----a-w- c:\documents and settings\seb\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-24d16ad7-n\decora-d3d.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}]
2009-10-15 08:53 165184 ----a-w- c:\program files\SFR\Kit\SFRNavErrorHelper.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\seb\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-09-01 133104]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"IncrediMail"="c:\program files\IncrediMail\bin\IncMail.exe" [2010-08-24 353736]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GEST"="c:\program files\GIGABYTE\GEST\RUN.exe" [2007-12-14 236040]
"RTHDCPL"="RTHDCPL.EXE" [2009-03-02 17530368]
"AVG9_TRAY"="c:\progra~1\AVG\AVG9\avgtray.exe" [2010-07-17 2065760]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2010-05-14 248552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\seb\Menu D'marrer\Programmes\D'marrage\
GigaTribe.lnk - c:\program files\GigaTribe\gigatribe.exe [2009-11-3 1071616]
c:\documents and settings\All Users\Menu D'marrer\Programmes\D'marrage\
hp psc 2000 Series.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe [2003-4-9 323646]
hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-9 28672]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-07-17 17:21 12536 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^seb^Menu Démarrer^Programmes^Démarrage^Groom.lnk]
path=c:\documents and settings\seb\Menu Démarrer\Programmes\Démarrage\Groom.lnk
backup=c:\windows\pss\Groom.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^seb^Menu Démarrer^Programmes^Démarrage^Notification de cadeaux MSN.lnk]
path=c:\documents and settings\seb\Menu Démarrer\Programmes\Démarrage\Notification de cadeaux MSN.lnk
backup=c:\windows\pss\Notification de cadeaux MSN.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2009-10-30 11:57 369200 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
2005-06-08 12:44 196608 ----a-w- c:\program files\Logitech\Video\ManifestEngine.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
2005-06-08 13:24 458752 ----a-w- c:\program files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
2005-06-08 13:14 217088 ----a-w- c:\program files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
2005-07-19 15:32 221184 ----a-w- c:\windows\system32\LVCOMSX.EXE
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\GIGABYTE\\GEST\\run.exe"=
"c:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\Microsoft Games\\Halo\\halo.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\GigaTribe\\gigatribe.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImLc.exe"=
"c:\\Program Files\\MC2\\Sniper Elite\\SniperElite.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [28/08/2009 16:46 216400]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [28/08/2009 16:46 243024]
R2 avg9wd;AVG Free WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [17/07/2010 19:21 308136]
R3 GEST Service;GEST Service for program management.;c:\program files\GIGABYTE\GEST\GSvr.exe [28/08/2009 16:31 47624]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [31/08/2009 13:12 1684736]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [23/09/2009 14:50 238960]
S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [21/03/2010 12:35 691696]
.
Contenu du dossier 'Tâches planifiées'
2009-12-01 c:\windows\Tasks\FRU Task 2003-04-10 00:56ewlett-Packard2003-04-10 00:56p psc 2100 series272A572217594EBCF1CEE215E352B92AD073FDE4251829507.job
- c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-09 15:56]
2010-08-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-1637723038-839522115-1004Core.job
- c:\documents and settings\seb\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-01 11:40]
2010-08-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1123561945-1637723038-839522115-1004UA.job
- c:\documents and settings\seb\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-01 11:40]
.
.
------- Examen supplémentaire -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {50DC58D0-C870-4BE6-BC41-971ED2D5F022} - hxxp://www.super-messenger.fr/tab/HookWlmEx.cab
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-AdobeBridge - (no file)
HKLM-Explorer_Run-Mstsc - c:\docume~1\seb\APPLIC~1\mstsc.exe
HKU-Default-Explorer_Run-SessMgr - c:\docume~1\seb\LOCALS~1\APPLIC~1\MICROS~1\sessmgr.exe
MSConfigStartUp-My Web Search Bar Search Scope Monitor - c:\progra~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-08-24 21:47
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-1123561945-1637723038-839522115-1004\Software\SecuROM\License information*]
"datasecu"=hex:8b,71,8f,2f,98,84,53,bf,86,aa,5b,d5,ff,1f,20,ad,9a,a7,cd,c7,04,
86,ea,73,d3,8f,ec,3a,52,0d,34,d3,24,23,79,15,5e,85,d3,9c,f8,1f,52,c2,2c,28,\
"rkeysecu"=hex:7c,29,d6,5f,06,79,5b,b3,a3,1e,39,f2,9e,46,b9,ce
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(704)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(3656)
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\RTHDCPL.EXE
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\HPZipm12.exe
c:\program files\IncrediMail\bin\IMApp.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
.
**************************************************************************
.
Heure de fin: 2010-08-24 21:51:34 - La machine a redémarré
ComboFix-quarantined-files.txt 2010-08-24 19:51
Avant-CF: 228 256 153 600 octets libres
Après-CF: 228 135 612 416 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
- - End Of File - - FD41554211CDFCC015C8051634FC1017
Non, ce n'est pas le même :))
O47 - AAKE:Key Export SP - "C:\DOCUME~1\seb\LOCALS~1\Temp\~temp\mlp315\mdm.exe" [Enabled] .(.Pas de propriétaire - Pas de description.) (.not file.) -- C:\DOCUME~1\seb\LOCALS~1\Temp\~temp\mlp315\mdm.exe
--> Dans le dossier temp, c'est un malware.
@+
=)