Le rapport combofix :
ComboFix 08-07-05.1 - HP_Propriétaire 2008-07-07 21:24:57.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.958 [GMT 2:00]
Endroit: C:\Documents and Settings\HP_Propriétaire\Bureau\Combo-Fix.exe
Command switches used :: C:\Documents and Settings\HP_Propriétaire\Bureau\CFscript.txt
* Création d'un nouveau point de restauration
FILE ::
C:\WINDOWS\system32\browseu.dll
C:\WINDOWS\system32\drivers\zwplsuvf.dat
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\browseu.dll
C:\WINDOWS\system32\drivers\zwplsuvf.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_YDDGQZBC
-------\Service_yddgqzbc
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-07 to 2008-07-07 ))))))))))))))))))))))))))))))))))))
.
2008-07-07 14:04 . 2008-07-07 14:11 <REP> d-------- C:\Program Files\Navilog1
2008-07-07 14:01 . 2008-07-07 21:20 <REP> d-------- C:\Program Files\Lopxp
2008-07-07 13:38 . 2008-07-07 13:40 <REP> d----c--- C:\Killbagle
2008-07-07 12:34 . 2008-07-07 12:34 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-07-07 12:34 . 2008-07-07 12:34 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-07 12:34 . 2008-06-28 14:16 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-07-07 12:34 . 2008-06-28 14:16 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-07-06 20:48 . 2008-07-06 20:48 <REP> d-------- C:\Program Files\Hijackthis Version Fran‡aise
2008-07-06 20:35 . 2008-07-06 20:35 <REP> d-------- C:\Program Files\Trend Micro
2008-07-01 20:41 . 2008-07-01 20:41 <REP> d-------- C:\Program Files\iPod
2008-06-29 14:27 . 2008-06-30 11:59 69 --a------ C:\WINDOWS\NeroDigital.ini
2008-06-29 14:23 . 2008-06-29 14:23 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Ahead
2008-06-29 14:15 . 2008-06-29 14:15 <REP> d-------- C:\Program Files\Nero
2008-06-29 14:15 . 2008-06-29 14:23 <REP> d-------- C:\Program Files\Fichiers communs\Ahead
2008-06-29 14:15 . 2008-06-29 14:15 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Nero
2008-06-29 12:47 . 2008-06-29 12:47 <REP> d-------- C:\Program Files\WinASPI
2008-06-29 12:47 . 2008-06-29 12:47 <REP> d-------- C:\Program Files\AviSynth 2.5
2008-06-29 12:46 . <REP> C:\Documents and Settings\HP_Propriétaire\NeoDivX Suite
2008-06-29 12:42 . 2008-06-29 12:45 <REP> d-------- C:\Program Files\MediaCoder Audio Edition
2008-06-25 01:59 . 2008-06-25 01:59 <REP> d----c--- C:\Photos
2008-06-20 15:35 . 2008-06-22 18:24 <REP> d-------- C:\Program Files\MessengerDiscovery
2008-06-19 20:46 . 2008-06-19 20:46 <REP> d-------- C:\Program Files\Boonty
2008-06-14 12:20 . 2008-06-14 12:20 <REP> d-------- C:\Program Files\Electronic Arts
2008-06-11 11:19 . 2008-06-14 19:59 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 11:19 . 2008-06-14 19:59 272,768 --------- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-09 17:47 . 2008-06-16 22:24 43,520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
2008-06-09 17:45 . 2008-06-12 13:02 <REP> d-------- C:\Program Files\GameSpy Arcade
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-07 19:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-07-07 16:17 --------- d-----w C:\Program Files\eMule
2008-07-07 10:22 --------- d-----w C:\Program Files\Spyware Doctor
2008-07-07 10:18 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-06 21:26 22,328 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-07-06 18:48 --------- d-----w C:\Program Files\Hijackthis Version Française
2008-07-03 12:50 --------- d-----w C:\Program Files\Mafia
2008-07-01 20:13 --------- d-----w C:\Program Files\Apple Software Update
2008-07-01 18:41 --------- d-----w C:\Program Files\iTunes
2008-07-01 18:39 --------- d-----w C:\Program Files\QuickTime
2008-06-29 10:46 --------- d-----w C:\Program Files\Replay Converter
2008-06-23 13:12 --------- d-----w C:\Program Files\EA SPORTS
2008-06-23 13:11 --------- d-----w C:\Program Files\DivX
2008-06-22 16:24 --------- d-----w C:\Program Files\MSN Messenger
2008-06-09 15:46 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-06-02 21:03 98,304 ----a-w C:\WINDOWS\DUMP4517.tmp
2008-06-01 12:20 --------- d-----w C:\Program Files\Wanadoo
2008-05-31 14:35 98,304 ----a-w C:\WINDOWS\DUMP50cf.tmp
2008-05-29 20:29 98,304 ----a-w C:\WINDOWS\DUMP3ece.tmp
2008-05-28 13:01 --------- d-----w C:\Program Files\Activision
2008-05-27 10:12 98,304 ----a-w C:\WINDOWS\DUMP469e.tmp
2008-05-24 08:29 98,304 ----a-w C:\WINDOWS\DUMP5e9a.tmp
2008-05-16 14:07 --------- d-----w C:\Program Files\Microsoft Games
2008-05-15 18:35 --------- d-----w C:\Program Files\KONAMI
2008-05-15 13:07 --------- d-----w C:\Program Files\New York Race
2008-05-14 10:55 716,272 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2008-05-14 09:27 --------- d-----w C:\Program Files\Intel
2008-05-12 11:33 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-12 11:30 691,545 ----a-w C:\WINDOWS\unins000.exe
2008-05-10 08:30 --------- d-----w C:\Program Files\Ubi Soft
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-04-27 12:36 737,280 ----a-w C:\WINDOWS\iun6002.exe
2007-11-25 17:30 99,925 ----a-w C:\Documents and Settings\HP_Propriétaire\z.dat
2007-11-25 17:30 5,681 ----a-w C:\Documents and Settings\HP_Propriétaire\x.dat
2007-05-07 18:12 74,784 ----a-w C:\Program Files\Uninstal.exe
2007-05-02 18:57 94,208 ----a-w C:\Program Files\template.o
2007-05-02 18:57 54,176 ----a-w C:\Program Files\temp.bin
2007-05-02 18:57 26,226 ----a-w C:\Program Files\tempa.bin
2007-02-19 13:04 21,880,832 ----a-w C:\Program Files\pes6.exe
2001-09-19 09:44 290,302,112 ----a-w C:\Program Files\media.pkr
2001-08-24 16:11 290 ----a-w C:\Program Files\Anet.inf
2001-08-22 12:10 40 ----a-w C:\Program Files\texture.dat
2001-07-12 07:55 299,571 ----a-w C:\Program Files\binkw32.dll
2001-05-03 15:13 23,552 ----a-w C:\Program Files\Getinfo.dll
2000-08-23 09:30 84,992 ----a-w C:\Program Files\Sysinv.dll
2000-08-23 09:30 84,480 ----a-w C:\Program Files\sysinfo.exe
2007-02-25 11:28 22 --sha-w C:\WINDOWS\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((( snapshot@2008-07-07_13.58.51.98 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-07 11:53:54 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-07-07 19:29:26 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-07-07 19:29:31 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_59c.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 20:00 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-20 19:50 68856]
"Creative WebCam Tray"="C:\Program Files\Creative\Shared Files\CamTray.exe" [2005-10-27 12:00 299008]
"Gadwin PrintScreen 3.5"="C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe" [2006-07-08 10:57 1101824]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 13:55 5674352]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-03-20 18:46 217544]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2007-06-01 10:21 153136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 18:04 52736]
"HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 08:35 49152]
"KBD"="C:\HP\KBD\KBD.EXE" [2005-02-02 16:44 61440]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-02-13 15:05 7557120]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 12:48 157592]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-01-21 20:00 185896]
"NeroFilterCheck"="c:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-06-02 11:13 267048]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 15:47 57344 C:\WINDOWS\ALCXMNTR.EXE]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.HFYU"= huffyuv.dll
"vidc.yv12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DXM6Patch_981116]
--a------ 1998-11-30 18:04 497376 C:\WINDOWS\p_981116.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-06-02 11:13 267048 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
--a------ 2006-02-13 15:05 7557120 C:\WINDOWS\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
--a------ 2006-02-13 15:05 86016 C:\WINDOWS\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
--a------ 2005-07-22 23:14 237568 C:\WINDOWS\SMINST\Recguard.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOKIT]
--a------ 2004-08-23 14:50 122880 C:\PROGRA~1\Wanadoo\Shell.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOWATCH]
--a------ 2004-08-23 14:49 20480 C:\PROGRA~1\Wanadoo\Watch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
--a------ 2004-09-07 15:47 57344 C:\WINDOWS\ALCXMNTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2006-02-13 15:05 1519616 C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\KONAMI\\Pro Evolution Soccer 6\\PES6.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\eMule\\eMule0.48a\\emule.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"C:\\Program Files\\Activision\\Call of Duty 2\\CoD2MP_s.exe"=
"C:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
"C:\\Program Files\\Atari\\TopSpin\\TopSpin.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"4662:TCP"= 4662:TCP:emule
"4672:UDP"= 4672:UDP:emule
"80:TCP"= 80:TCP:HTTP
"443:TCP"= 443:TCP:HTTPS
"21:TCP"= 21:TCP:FTP
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
R2 OPTENET_FILTER;Control Parental;C:\Program Files\Controle Parental\bin\optproxy.exe [2006-03-02 17:10]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
R3 V0260VID;Live! Cam Vista IM;C:\WINDOWS\system32\DRIVERS\V0260Vid.sys [2006-04-01 17:16]
S3 Boonty Games;Boonty Games;C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe [2007-01-03 21:58]
S3 iMSPQMn;iMSPQMn;C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\iMSPQMn.sys []
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C5CD9787-54F4-6B5A-7054-5E50F28A8F48}]
C:\WINDOWS\crack\crack.exe s
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-07-01 18:25:49 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-07-01 16:15:00 C:\WINDOWS\Tasks\avast! Antivirus.job"
- C:\PROGRA~1\ALWILS~1\Avast4\ashAvast.exe
"2008-07-07 14:02:00 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-07 21:29:48
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
C:\WINDOWS\explorer.exe [1452] 0x89767968
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\FTRTSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-07-07 21:34:15 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-07 19:34:10
ComboFix2.txt 2008-07-07 11:59:15
Pre-Run: 92,297,969,664 octets libres
Post-Run: 92,310,618,112 octets libres
250 --- E O F --- 2008-06-20 09:21:59
Merci de ta réponse
Je t'informes dès que j'ai fait tout ce que tu me conseilles
+ +