Bonjour Green Day, j'espère que ce week end a bien commencé pour toi.
Voici donc le nouveau rapport .
ComboFix 07-11-08.1 - Propriétaire 2007-11-17 16:04:01.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.1473 [GMT 1:00]
Running from: H:\Documents and Settings\Propriétaire\Bureau\ComboFix.exe
Command switches used :: H:\Documents and Settings\Propriétaire\Bureau\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((((((( Fichiers créés 2007-10-17 to 2007-11-17 ))))))))))))))))))))))))))))))))))))
.
2007-11-16 18:41 51,200 --a------ H:\WINDOWS\NirCmd.exe
2007-11-16 15:58 145,984 --a------ H:\WINDOWS\system32\vpejhohv.dll
2007-11-16 14:15 85,056 --a------ H:\WINDOWS\system32\rygrtbvs.dll
2007-11-16 14:12 81,984 --a------ H:\WINDOWS\system32\mbtqlwlb.dll
2007-11-16 14:06 71,232 --a------ H:\WINDOWS\system32\lhvdtlcg.exe
2007-11-15 14:07 79,936 --a------ H:\WINDOWS\system32\mlyeneaq.dll
2007-11-15 14:04 71,232 --a------ H:\WINDOWS\system32\kfcyypoc.exe
2007-11-14 15:46 80,448 --a------ H:\WINDOWS\system32\drlieegi.dll
2007-11-14 15:18 71,232 --a------ H:\WINDOWS\system32\lttgicxv.exe
2007-11-13 15:37 145,984 --a------ H:\WINDOWS\system32\bafxxpsg.dll
2007-11-13 15:20 88,128 --a------ H:\WINDOWS\system32\pgdvithg.dll
2007-11-13 15:17 80,448 --a------ H:\WINDOWS\system32\bmceavgo.dll
2007-11-13 15:17 71,232 --a------ H:\WINDOWS\system32\bcwjuxab.exe
2007-11-12 21:18 <REP> d-------- H:\Documents and Settings\Propriétaire\Application Data\XnView
2007-11-12 15:20 81,472 --a------ H:\WINDOWS\system32\lcfqwlmv.dll
2007-11-12 15:17 71,232 --a------ H:\WINDOWS\system32\etqjjfno.exe
2007-11-12 00:15 196,608 --a------ H:\WINDOWS\system32\anfysave.scr
2007-11-11 15:23 79,936 --a------ H:\WINDOWS\system32\dlutjsaf.dll
2007-11-11 15:20 88,128 --a------ H:\WINDOWS\system32\ialqllym.dll
2007-11-11 15:20 71,232 --a------ H:\WINDOWS\system32\hpcuettu.exe
2007-11-10 15:26 81,472 --a------ H:\WINDOWS\system32\tvoeihfr.dll
2007-11-10 15:17 71,232 --a------ H:\WINDOWS\system32\mwkdylvm.exe
2007-11-10 14:19 <REP> d-------- H:\Program Files\Opera
2007-11-09 15:26 77,888 --a------ H:\WINDOWS\system32\ppqgukps.dll
2007-11-09 15:23 71,232 --a------ H:\WINDOWS\system32\cfhakrfx.exe
2007-11-09 13:07 557,056 --a------ H:\WINDOWS\MrSetupUninstall.0.2.exe
2007-11-08 15:35 80,448 --a------ H:\WINDOWS\system32\sbcdbpyb.dll
2007-11-08 15:17 71,232 --a------ H:\WINDOWS\system32\qkegging.exe
2007-11-08 13:25 104,093 --a------ H:\WINDOWS\hpoins04.dat
2007-11-08 13:25 17,176 --------- H:\WINDOWS\hpomdl04.dat
2007-11-07 23:50 <REP> d-------- H:\VundoFix Backups
2007-11-07 20:44 <REP> d-------- H:\Documents and Settings\Propriétaire\Application Data\Grisoft
2007-11-07 20:31 2,650 --a------ H:\WINDOWS\system32\tmp.reg
2007-11-07 20:16 <REP> d-------- H:\Documents and Settings\All Users\Application Data\Grisoft
2007-11-07 20:16 10,872 --a------ H:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-11-07 15:26 86,080 --a------ H:\WINDOWS\system32\yufmlhck.dll
2007-11-07 15:19 79,936 --a------ H:\WINDOWS\system32\wplwloer.dll
2007-11-07 15:19 71,232 --a------ H:\WINDOWS\system32\llrqwfjc.exe
2007-11-07 15:17 145,984 --a------ H:\WINDOWS\system32\dvsnoekr.dll
2007-11-05 20:35 <REP> d-------- H:\Documents and Settings\All Users\Application Data\FLEXnet
2007-11-05 18:06 <REP> d-------- H:\Program Files\CoffeeCup Software
2007-11-03 22:24 <REP> d-------- H:\Documents and Settings\Propriétaire\Application Data\BitTorrent
2007-11-03 22:23 <REP> d-------- H:\Program Files\BitTorrent_DNA
2007-11-03 22:23 <REP> d-------- H:\Program Files\BitTorrent
2007-11-03 22:23 <REP> d-------- H:\Documents and Settings\Propriétaire\Application Data\BitTorrent DNA
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-17 15:06 --------- d-----w H:\Program Files\PeerGuardian2
2007-11-16 17:56 --------- d-----w H:\Documents and Settings\Propriétaire\Application Data\MSN Pictures Displayer
2007-11-16 17:33 332 ----a-w H:\WINDOWS\system32\drivers\fwdrv.err
2007-11-13 14:49 --------- d-----w H:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-07 16:06 --------- d-----w H:\Program Files\Fichiers communs\Macrovision Shared
2007-11-07 16:05 --------- d-----w H:\Program Files\Fichiers communs\Adobe
2007-11-04 15:44 --------- d-----w H:\Program Files\Fichiers communs\Ulead Systems
2007-11-04 15:41 --------- d-----w H:\Documents and Settings\Propriétaire\Application Data\Ulead Systems
2007-11-04 15:41 --------- d-----w H:\Documents and Settings\All Users\Application Data\Ulead Systems
2007-11-03 21:07 --------- d-----w H:\Documents and Settings\Propriétaire\Application Data\LimeWire
2007-10-25 17:05 94,416 ----a-w H:\WINDOWS\system32\drivers\aswmon2.sys
2007-10-25 17:05 93,264 ----a-w H:\WINDOWS\system32\drivers\aswmon.sys
2007-10-25 17:03 23,152 ----a-w H:\WINDOWS\system32\drivers\aswRdr.sys
2007-10-25 17:01 42,912 ----a-w H:\WINDOWS\system32\drivers\aswTdi.sys
2007-10-25 16:58 26,624 ----a-w H:\WINDOWS\system32\drivers\aavmker4.sys
2007-10-25 16:24 815,480 ----a-w H:\WINDOWS\system32\aswBoot.exe
2007-10-25 16:14 95,608 ----a-w H:\WINDOWS\system32\AvastSS.scr
2007-10-18 07:25 --------- d-----w H:\Program Files\IncrediMail
2007-10-01 21:23 --------- d-----w H:\Program Files\Happyneuron
2007-10-01 04:43 --------- d-----w H:\Documents and Settings\Propriétaire\Application Data\U3
2007-09-27 21:17 --------- d-----w H:\Program Files\MSN Pictures Displayer
2007-09-24 20:50 --------- d-----w H:\Program Files\Devomaxx
2007-09-24 20:24 --------- d-----w H:\Program Files\Belarc
2007-09-22 08:57 --------- d--h--w H:\Program Files\InstallShield Installation Information
2007-09-22 08:57 --------- d-----w H:\Program Files\JetAudio
2007-09-22 08:57 --------- d-----w H:\Documents and Settings\Propriétaire\Application Data\COWON
2007-09-21 21:08 --------- d-----w H:\Program Files\eChanblard
2007-09-18 19:51 --------- d-----w H:\Program Files\Transcript
2007-09-18 19:51 --------- d-----w H:\Documents and Settings\Propriétaire\Application Data\Transcript
2007-09-18 14:47 --------- d-----w H:\Program Files\Win Généalogic
2007-09-18 14:44 --------- d-----w H:\Program Files\BrainsBreaker
2007-09-18 14:06 --------- d-----w H:\Documents and Settings\Propriétaire\Application Data\TuneUp Software
2007-09-18 14:06 --------- d-----w H:\Documents and Settings\All Users\Application Data\TuneUp Software
2007-09-18 14:04 --------- d-----w H:\Program Files\Fichiers communs\Wise Installation Wizard
2007-09-17 08:53 --------- d-----w H:\Documents and Settings\Propriétaire\Application Data\OpenOffice.org2
2007-09-13 09:33 737,280 ----a-w H:\WINDOWS\iun6002.exe
2007-08-29 21:47 54,600 ----a-w H:\npbittorrent.dll
2007-08-21 06:17 683,520 ----a-w H:\WINDOWS\system32\inetcomm.dll
2006-12-12 10:58 547 ----a-w H:\Documents and Settings\Propriétaire\DMOrganizer.dat
2006-12-12 10:58 547 ----a-w H:\Documents and Settings\Propriétaire\DMOrganizer.dat
2006-08-22 07:15 774,144 ----a-w H:\Program Files\RngInterstitial.dll
2005-05-13 15:12:00 217,073 --sha-r H:\WINDOWS\meta4.exe
2005-10-24 09:13:58 66,560 --sha-r H:\WINDOWS\MOTA113.exe
2005-10-13 19:27:00 422,400 --sha-r H:\WINDOWS\x2.64.exe
2005-10-07 17:14:52 308,224 --sha-r H:\WINDOWS\system32\avisynth.dll
2005-07-14 10:31:20 27,648 --sha-r H:\WINDOWS\system32\AVSredirect.dll
2006-08-12 21:57:35 56 --sh--r H:\WINDOWS\system32\BDD24D686A.sys
2005-06-26 13:32:28 616,448 --sha-r H:\WINDOWS\system32\cygwin1.dll
2005-06-21 20:37:42 45,568 --sha-r H:\WINDOWS\system32\cygz.dll
2006-05-20 18:06:36 5 --sha-w H:\WINDOWS\system32\fecfdaed_s.dll
2004-01-24 22:00:00 70,656 --sha-r H:\WINDOWS\system32\i420vfw.dll
2006-08-12 21:57:35 1,890 --sha-w H:\WINDOWS\system32\KGyGaAvL.sys
2006-04-27 08:24:24 2,945,024 --sha-r H:\WINDOWS\system32\Smab.dll
2000-02-03 22:00:00 116,224 --sh--w H:\WINDOWS\system32\UnzDll.dll
2005-02-28 11:16:22 240,128 --sha-r H:\WINDOWS\system32\x.264.exe
2000-02-03 22:00:00 130,560 --sh--w H:\WINDOWS\system32\ZipDll.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{15965B67-E521-4FDC-9157-AF5D888116FC}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{38A5FF63-C05F-4C02-82B5-6B688AD83E1D}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A4734CBD-B828-4233-B127-46D73C72B7E3}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AACDE09E-1D91-4EDA-A707-03AA87AFD00A}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B8D3FCF5-EF31-45DC-95FD-42F7277FF174}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E135EDA3-8E60-4066-91FB-64C66998F320}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F1EBBD4C-CE59-4204-9FCC-EFDB2D6839AE}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2003-03-27 16:34 H:\WINDOWS\SOUNDMAN.EXE]
"Disk Monitor"="H:\Program Files\Generic\USB Card Reader Driver v1.9e3\Disk_Monitor.exe" [2003-06-18 11:57]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 09:06 H:\WINDOWS\AGRSMMSG.exe]
"SiSPower"="SiSPower.dll" [2006-01-09 11:57 H:\WINDOWS\system32\SiSPower.dll]
"WinPatrol"="H:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2007-08-11 23:48]
"Picasa Media Detector"="H:\Program Files\Picasa2\PicasaMediaDetector.exe" [2006-12-12 01:36]
"QuickTime Task"="H:\Program Files\QuickTime\qttask.exe" [2006-03-31 12:59]
"Adobe Photo Downloader"="H:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" [2005-06-23 20:33]
"Cobian Backup 8 interface"="H:\Program Files\Cobian Backup 8\cbInterface.exe" [2007-03-20 23:35]
"avast!"="H:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-10-25 17:20]
"SANSUNMouse "="H:\PROGRA~1\MOUSED~1\mousedriver.exe" [2004-12-28 19:08]
"UnlockerAssistant"="H:\Program Files\Unlocker\UnlockerAssistant.exe" [2006-09-07 18:19]
"FileBackup"="C:\Program Files\Optimark\OTB\OTB.exe" []
"!AVG Anti-Spyware"="I:\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="H:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00]
"MsnMsgr"="H:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:55]
"IncrediMail"="H:\Program Files\IncrediMail\bin\IncMail.exe" [2007-10-09 11:02]
"PeerGuardian"="H:\Program Files\PeerGuardian2\pg2.exe" [2005-09-18 17:40]
"swg"="H:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-21 23:17]
"TweakMeter"="C:\Program Files\TweakDUN\TweakMeter.exe" [2001-09-21 10:00]
"Gadwin PrintScreen 3.1"="C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe" [2005-09-27 01:18]
"IncrediMail Tray Application"="H:\PROGRA~1\INCRED~1\bin\IncMail.exe" [2007-10-09 11:02]
"BitTorrent DNA"="H:\Program Files\BitTorrent_DNA\dna.exe" [2007-11-03 22:23]
H:\Documents and Settings\Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
MSN Pictures Displayer.lnk - H:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe [2007-05-06 22:24:38]
H:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Utility Tray.lnk - H:\WINDOWS\system32\sistray.exe [2006-02-15 12:51:50]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qbzcymho]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iPhox]
H:\Program Files\iPhox\iPhox.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"H:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSUSBRG]
H:\WINDOWS\SiSUSBrg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
H:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\warez]
"J:\divers drivers téléchargés\Warez P2P Client\warez.exe" -h
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"FolderShare"="D:\FolderShare.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"KBDriver"=H:\Program Files\Keyboard Driver\OEMDriver.exe
"Windows Defender"="H:\Program Files\Windows Defender\MSASCui.exe" -hide
"HP Software Update"="I:\HP Software Update\HPWuSchd2.exe"
"HP Component Manager"="H:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
R1 ewido security suite driver;ewido security suite driver;\??\H:\Program Files\ewido anti-malware\guard.sys
R1 fwdrv;Firewall Driver;H:\WINDOWS\system32\drivers\fwdrv.sys
R1 khips;Kerio HIPS Driver;H:\WINDOWS\system32\drivers\khips.sys
R2 UxTuneUp;TuneUp Extension de thème;H:\WINDOWS\System32\svchost.exe -k netsvcs
R3 pgfilter;pgfilter;\??\H:\Program Files\PeerGuardian2\pgfilter.sys
R3 usbstor;Pilote de stockage de masse USB;H:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
S0 NeroCdNt;NeroCdNt;H:\WINDOWS\system32\drivers\NeroCdNt.sys
S3 Boonty Games;Boonty Games;"H:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe"
S3 C-Dilla;C-Dilla;\??\H:\WINDOWS\system32\drivers\CDANT.SYS
S3 CoachUsb;Coach Digital Camera on USB;H:\WINDOWS\system32\DRIVERS\CoachUsb.sys
S3 DTVFW;DVB-T USB adapter firmware;H:\WINDOWS\system32\DRIVERS\dtvfw.sys
S3 KCAP2;ADS - DVBT-USB Driver;H:\WINDOWS\system32\Drivers\kcap2.sys
S3 KLOAD2;KWorld - DVBT-USB2.0 firmware loader;H:\WINDOWS\system32\DRIVERS\kload2.sys
S3 NPF;NetGroup Packet Filter Driver;H:\WINDOWS\system32\drivers\npf.sys
S3 usbdtv;DVB-T TV Tuner;H:\WINDOWS\system32\Drivers\usbdtv.sys
S3 usbscan;Pilote de scanneur USB;H:\WINDOWS\system32\DRIVERS\usbscan.sys
S4 VFILT;Outpost Firewall Kernel Driver;\??\H:\PROGRA~1\Agnitum\OUTPOS~1.0\kernel\2000\FILTNT.SYS
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - PGFILTER
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2007-11-16 16:15:00 H:\WINDOWS\Tasks\Maintenance en 1 clic.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
"2007-11-17 00:57:12 H:\WINDOWS\Tasks\MP Scheduled Scan.job"
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-17 16:08:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-17 16:10:40
H:\ComboFix2.txt ... 2007-11-16 18:56
.
--- E O F ---