Salut, voila le rapport
ComboFix 08-03-30.3 - Martin 2008-03-31 12:28:46.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1607 [GMT 2:00]
Endroit: C:\Documents and Settings\Martin\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
((((((((((((((((((((((((((((( Fichiers créés 2008-02-28 to 2008-03-31 ))))))))))))))))))))))))))))))))))))
.
2008-03-31 02:09 . 2008-03-31 02:09 <REP> d-------- C:\WINDOWS\ERUNT
2008-03-31 02:08 . 2008-03-31 02:13 <REP> d-------- C:\SDFix
2008-03-31 01:44 . 2008-03-31 01:44 <REP> d-------- C:\Documents and Settings\Martin\Application Data\Grisoft
2008-03-31 01:44 . 2008-03-31 01:44 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-31 01:44 . 2007-05-30 14:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-31 01:42 . 2007-12-15 05:31 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
2008-03-31 01:42 . 2007-12-15 05:31 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-03-31 01:42 . 2007-12-14 21:45 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
2008-03-31 01:42 . 2007-12-15 05:31 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents
2008-03-31 01:42 . 2007-12-15 05:31 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
2008-03-31 01:42 . 2007-12-15 05:31 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris
2008-03-31 01:42 . 2007-12-15 05:31 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2008-03-31 01:42 . 2008-03-31 01:42 165 --a------ C:\WINDOWS\system32\drivers\fwdrv.err
2008-03-30 22:11 . 2008-03-30 22:11 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-03-30 22:11 . 2008-03-30 22:11 <REP> d-------- C:\Documents and Settings\Martin\Application Data\Malwarebytes
2008-03-30 22:11 . 2008-03-30 22:11 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-30 21:38 . 2008-03-30 21:38 <REP> d-------- C:\Program Files\mozill~1
2008-03-30 21:38 . 2008-03-30 21:40 <REP> d-------- C:\Downloads
2008-03-29 01:53 . 2008-03-29 01:53 7,680 --ahs---- C:\WINDOWS\Thumbs.db
2008-03-28 00:40 . 2008-03-28 00:41 3,186 --a------ C:\WINDOWS\system32\tmp.reg
2008-03-28 00:39 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-03-28 00:39 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-03-28 00:39 . 2008-03-22 16:49 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-03-28 00:39 . 2008-03-26 09:50 82,432 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-03-28 00:39 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-03-28 00:39 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-03-28 00:39 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-03-27 16:35 . 2008-03-27 16:35 <REP> d-------- C:\Logs
2008-03-27 15:09 . 2008-03-28 03:34 <REP> d-------- C:\VundoFix Backups
2008-03-27 01:36 . 2008-03-27 01:36 <REP> d-------- C:\Documents and Settings\Martin\Application Data\Talkback
2008-03-27 01:36 . 2008-03-27 01:36 0 --a------ C:\WINDOWS\nsreg.dat
2008-03-27 01:35 . 2008-03-27 01:50 <REP> d-------- C:\Program Files\Google
2008-03-27 00:55 . 2008-03-27 01:41 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-26 00:57 . 2008-03-26 00:57 38,400 --a------ C:\WINDOWS\system32\yayvuus.dll.bak
2008-03-25 21:42 . 2003-07-21 05:17 5,174 --a------ C:\WINDOWS\system32\nppt9x.vxd
2008-03-25 21:42 . 2005-01-04 20:43 4,682 --a------ C:\WINDOWS\system32\npptNT2.sys
2008-03-25 20:20 . 2008-03-25 20:20 <REP> d-------- C:\Program Files\Games-Masters.com
2008-03-19 17:33 . 2008-03-30 20:44 116 --a------ C:\WINDOWS\NeroDigital.ini
2008-03-19 14:32 . 2008-03-19 14:32 <REP> d-------- C:\Program Files\Hamachi
2008-03-14 20:18 . 2008-03-14 20:19 <REP> d-------- C:\Program Files\Fichiers communs\Ahead
2008-03-14 20:18 . 2008-03-14 20:18 <REP> d-------- C:\Program Files\Ahead
2008-03-14 20:18 . 2004-07-20 17:24 1,568,768 --------- C:\WINDOWS\system32\ImagX7.dll
2008-03-14 20:18 . 2004-07-20 17:24 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll
2008-03-14 20:18 . 2004-07-20 17:24 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll
2008-03-14 20:18 . 2004-07-09 09:43 364,544 --------- C:\WINDOWS\system32\TwnLib4.dll
2008-03-14 20:18 . 2004-07-20 17:24 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll
2008-03-14 20:18 . 2001-07-09 11:50 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2008-03-14 20:18 . 2000-06-26 11:45 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2008-03-14 20:18 . 2001-06-26 08:15 38,912 --------- C:\WINDOWS\system32\picn20.dll
2008-03-13 23:35 . 2008-03-31 00:32 <REP> d-------- C:\Documents and Settings\Martin\Application Data\Hamachi
2008-03-13 23:35 . 2008-03-19 14:32 25,280 --a------ C:\WINDOWS\system32\drivers\hamachi.sys
2008-03-13 20:49 . 2008-03-13 20:49 <REP> d-------- C:\Program Files\CAVEDOG
2008-03-10 22:16 . 2008-03-10 22:16 <REP> d-------- C:\Program Files\CCleaner
2008-03-09 00:20 . 2008-03-09 00:20 84,761 --a------ C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe
2008-03-09 00:01 . 2004-08-19 17:09 1,689,088 --a------ C:\WINDOWS\system32\379571d.dll
2008-03-08 23:28 . 2001-03-16 20:34 4,358,144 -ra------ C:\WINDOWS\uncsetup.exe
2008-03-08 23:28 . 2008-03-08 23:28 53,248 --a------ C:\WINDOWS\system32\unrar.dll
2008-03-06 13:01 . 2008-03-06 13:01 339,968 --a------ C:\WINDOWS\system32\mysidesearch_sidebar.dll
2008-03-05 01:24 . 2008-03-05 01:24 <REP> d-------- C:\Program Files\AxBx
2008-03-04 23:06 . 2004-08-19 17:09 1,689,088 --a------ C:\WINDOWS\system32\854b940.dll
2008-03-04 23:06 . 2004-08-19 17:09 1,689,088 --a------ C:\WINDOWS\system32\1cdb9fb9.dll
2008-03-04 23:06 . 2004-08-19 17:09 82,944 --a------ C:\WINDOWS\system32\1b70b79.dll
2008-03-04 23:06 . 2004-08-19 17:09 82,944 --a------ C:\WINDOWS\system32\16766d92.dll
2008-03-02 15:16 . 2008-03-02 15:16 <REP> d-------- C:\Program Files\Valve
2008-02-29 23:57 . 2006-02-07 12:58 77 --a------ C:\WINDOWS\system32\New Diablo 2 Event - newd2event.net.URL
2008-02-29 22:28 . 2004-08-19 17:09 82,944 --a------ C:\WINDOWS\system32\4753b17.dll
2008-02-29 19:34 . 2008-02-29 19:34 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Age of Empires 3
2008-02-29 19:33 . 2005-05-26 16:34 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
2008-02-29 19:22 . 2008-03-19 16:00 <REP> d-------- C:\Program Files\Microsoft Games
2008-02-27 19:51 . 2004-08-19 17:09 1,689,088 --a------ C:\WINDOWS\system32\63fd8d0.dll
2008-02-27 19:51 . 2004-08-19 17:09 82,944 --a------ C:\WINDOWS\system32\1207271.dll
2008-02-27 19:37 . 2004-08-19 17:09 1,689,088 --a------ C:\WINDOWS\system32\304494ea.dll
2008-02-27 19:37 . 2004-08-19 17:09 1,689,088 --a------ C:\WINDOWS\system32\12991b60.dll
2008-02-27 19:37 . 2004-08-19 17:09 82,944 --a------ C:\WINDOWS\system32\154268a.dll
2008-02-27 19:37 . 2004-08-19 17:09 82,944 --a------ C:\WINDOWS\system32\15044ad6.dll
2008-02-27 19:19 . 2008-02-27 19:19 <REP> d-------- C:\Documents and Settings\All Users\Application Data\InstallShield
2008-02-27 19:15 . 2008-02-27 19:15 <REP> d-------- C:\Program Files\gPotato.eu
2008-02-27 19:15 . 2005-08-11 16:29 73,728 --a------ C:\WINDOWS\system32\ISUSPM.cpl
2008-02-06 17:46 . 2008-03-31 02:21 <REP> d-------- C:\Program Files\Hijackthis Version Française
2008-02-06 17:28 . 2008-02-06 17:28 <REP> d-------- C:\Program Files\Lavasoft
2008-02-06 17:28 . 2008-02-06 17:28 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-02-06 17:28 . 2008-02-06 17:28 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-02-06 16:14 . 2008-02-06 16:14 46,300 --a------ C:\WINDOWS\system32\AdssiteSocial-uninstall.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-31 10:31 547,104 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-03-31 10:31 13,599,520 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-03-31 10:27 --------- d-----w C:\Documents and Settings\Martin\Application Data\Skype
2008-03-31 10:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-31 07:44 52,148 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-03-31 07:44 182,876 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-03-30 19:17 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-29 12:01 --------- d-----w C:\Program Files\MSN Messenger
2008-03-28 00:03 43,520 ----a-w C:\WINDOWS\system32\CmdLineExt03.dll
2008-03-28 00:03 --------- d-----w C:\Program Files\Diablo II
2008-03-27 23:19 --------- d-----w C:\Documents and Settings\Martin\Application Data\LimeWire
2008-03-27 14:27 --------- d-----w C:\Program Files\World of Warcraft
2008-03-01 20:04 --------- d-----w C:\Documents and Settings\Martin\Application Data\teamspeak2
2008-02-27 17:15 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-02-24 20:33 --------- d-----w C:\Program Files\LimeWire
2008-02-01 15:00 91,700 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2007-12-29 15:20 21,840 ----atw C:\WINDOWS\system32\SIntfNT.dll
2007-12-29 15:20 17,212 ----atw C:\WINDOWS\system32\SIntf32.dll
2007-12-29 15:20 12,067 ----atw C:\WINDOWS\system32\SIntf16.dll
2007-12-29 15:01 102,400 ----a-w C:\WINDOWS\DIIUnin.exe
2007-12-22 22:30 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
2007-12-22 22:04 669,184 ----a-w C:\WINDOWS\system32\pbsvc.exe
2007-12-22 22:04 66,872 ----a-w C:\WINDOWS\system32\PnkBstrA.exe
2007-12-22 22:04 22,328 ----a-w C:\Documents and Settings\Martin\Application Data\PnkBstrK.sys
2007-12-22 22:04 103,736 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
2007-12-21 14:39 10,752 ----a-w C:\WINDOWS\system32\WhoisCL.exe
2007-12-14 10:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
2000-01-01 00:01 45,056 --sh--r C:\WINDOWS\system32\widpwsdrv.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2006-05-19 19:11 18577448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2007-10-25 18:17 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-10-25 18:17 81920]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-10-25 18:17 8527872]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 04:10 55824 C:\WINDOWS\KHALMNPR.Exe]
"C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech SetPoint.lnk"="C:\Program Files\Logitech\SetPoint\SetPoint.exe" [2007-11-15 11:12 784912]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-19 17:10 110592 C:\WINDOWS\system32\bthprops.cpl]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" [2007-03-09 20:50 200768]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-19 17:09 15360]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-01-11 00:50:02 784912]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
c:\program files\fichiers communs\logitech\bluetooth\LBTWlgn.dll 2007-11-15 11:10 72208 c:\Program Files\Fichiers communs\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
C:\Program Files\AlienGUIse\fastload.dll 2001-12-21 00:34 24576 C:\Program Files\AlienGUIse\fastload.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\yayvuus]
yayvuus.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0-frFR-downloader.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\WINDOWS\\system32\\rundll32.exe"=
"C:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"C:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"C:\\WINDOWS\\system32\\PnkBstrA.exe"=
"C:\\WINDOWS\\system32\\PnkBstrB.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires III\\age3.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"C:\\Program Files\\Valve\\Steam\\steamapps\\marty80\\day of defeat\\hl.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires II\\empires2.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires II\\age2_x1\\age2_x1.exe"=
"C:\\WINDOWS\\system32\\dxdiag.exe"=
"C:\\WINDOWS\\system32\\dpnsvr.exe"=
"C:\\Program Files\\Games-Masters.com\\CABAL Online (Europe)\\launcher\\update\\ESTdnheadless.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-2.3.3.7799-to-2.4.0.8089-frFR-downloader.exe"=
"C:\\Program Files\\Valve\\Steam\\steamapps\\marty80\\counter-strike\\hl.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6112:TCP"= 6112:TCP:Blizzard Downloader 6112
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"10284:TCP"= 10284:TCP:BitComet 10284 TCP
"10284:UDP"= 10284:UDP:BitComet 10284 UDP
R0 Si3531;SiI-3531 SATA Controller;C:\WINDOWS\system32\DRIVERS\Si3531.sys [2006-10-06 09:50]
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-03-16 09:56]
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-03-16 09:56]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2c662881-aab4-11dc-b735-806d6172696f}]
\Shell\AutoRun\command - D:\Bin\Assetup.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-31 12:31:59
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"C:\\Documents and Settings\\All Users\\Menu Démarrer\\Programmes\\Démarrage\\Logitech SetPoint.lnk"="C:\\Program Files\\Logitech\\SetPoint\\SetPoint.exe"
.
Temps d'accomplissement: 2008-03-31 12:33:18
ComboFix-quarantined-files.txt 2008-03-31 10:33:13
Pre-Run: 154,999,492,608 octets libres
Post-Run: 154,988,158,976 octets libres
Merci pour l'aide :)
A+