Voici le rapport:
ComboFix 08-04-01.2 - JEAN MARIE 2008-04-02 19:34:20.1 - NTFSx86 MINIMAL
Microsoft Windows XP Professionnel 5.1.2600.0.1252.1.1036.18.147 [GMT 2:00]
Endroit: C:\Documents and Settings\JEAN MARIE\Bureau\Combo-Fix.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
.
[i] ADS - system32: deleted 70168 bytes in 1 streams.
/i
((((((((((((((((((((((((((((( Fichiers créés 2008-03-02 to 2008-04-02 ))))))))))))))))))))))))))))))))))))
.
2008-04-02 19:08 . 2008-04-02 19:08 <REP> d-------- C:\Program Files\Windows Live
2008-04-02 11:49 . 2008-04-02 11:50 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-02 11:49 . 2008-04-02 11:49 <REP> d-------- C:\Documents and Settings\JEAN MARIE\Application Data\Malwarebytes
2008-04-02 11:49 . 2008-04-02 11:49 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-02 00:45 . 2008-04-02 00:45 <REP> d-------- C:\WINDOWS\Sun
2008-03-31 21:15 . 2008-03-31 21:15 <REP> d-------- C:\Program Files\Trend Micro
2008-03-31 20:58 . 2008-03-31 20:58 <REP> d-------- C:\Program Files\CCleaner
2008-03-30 19:10 . 2008-04-02 19:27 <REP> d-------- C:\Documents and Settings\JEAN MARIE\Application Data\OpenOffice.org2
2008-03-30 19:01 . 2008-03-30 19:02 <REP> d-------- C:\Program Files\OpenOffice.org 2.4
2008-03-30 18:59 . 2008-02-22 02:33 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-03-30 18:54 . 2008-03-31 20:02 <REP> d-------- C:\Program Files\Java
2008-03-30 18:54 . 2008-03-30 18:54 <REP> d-------- C:\Program Files\Fichiers communs\Java
2008-03-30 17:00 . 2008-03-30 17:00 91,700 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-03-30 17:00 . 2008-03-30 17:00 85,860 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-03-30 16:58 . 2008-03-30 16:58 <REP> d-------- C:\Program Files\Kaspersky Lab
2008-03-30 16:58 . 2008-04-02 18:11 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-03-30 16:58 . 2008-04-02 19:27 2,625,312 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-03-30 16:58 . 2008-04-02 19:27 67,872 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-03-30 16:58 . 2008-04-02 19:27 36,236 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-03-30 16:58 . 2008-04-02 19:27 7,436 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-03-30 16:10 . 2008-03-30 16:10 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-30 13:54 . 2008-03-30 16:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-30 00:52 . 2008-03-30 00:52 <REP> dr------- C:\Documents and Settings\LocalService\Favoris
2008-03-28 23:23 . 2008-03-28 23:23 1,494,510 --a------ C:\WINDOWS\system32\cfmom.exe
2008-03-28 23:23 . 2008-03-28 23:23 1,494,510 --a------ C:\WINDOWS\cdti.exe
2008-03-28 23:23 . 2008-04-02 19:26 5,224 --a------ C:\WINDOWS\ upd.dll
2008-03-28 23:04 . 2008-03-28 23:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\ESET
2008-03-28 20:01 . 2007-03-28 20:42 29,704 --a------ C:\WINDOWS\system32\uxtuneup.dll
2008-03-28 20:00 . 2008-03-30 19:48 <REP> d-------- C:\Program Files\TuneUp Utilities 2007
2008-03-28 20:00 . 2008-03-28 20:00 <REP> d-------- C:\Documents and Settings\JEAN MARIE\Application Data\TuneUp Software
2008-03-28 19:59 . 2008-03-30 19:50 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-03-28 19:59 . 2008-03-28 19:59 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2008-03-25 20:48 . 2008-03-25 20:48 148 --a------ C:\WINDOWS\Readiris.ini
2008-03-25 12:50 . 2008-03-25 12:50 0 --a------ C:\WINDOWS\musicmaker.INI
2008-03-25 12:39 . 2008-03-25 12:50 340 --a------ C:\WINDOWS\BeatBox.INI
2008-03-25 12:36 . 2004-08-11 21:53 38,912 --a------ C:\WINDOWS\system32\mgxasio.dll
2008-03-25 12:30 . 2008-03-25 12:30 <REP> d-------- C:\Program Files\Fichiers communs\MAGIX
2008-03-25 12:30 . 2007-04-27 10:43 120,200 --a------ C:\WINDOWS\system32\DLLDEV32i.dll
2008-03-25 11:19 . 2008-03-25 11:19 <REP> d-------- C:\Documents and Settings\JEAN MARIE\Application Data\MAGIX
2008-03-25 11:18 . 2003-04-18 17:46 1,233,920 --a------ C:\WINDOWS\system32\msxml4.dll
2008-03-25 11:18 . 2003-04-18 17:29 82,432 --a------ C:\WINDOWS\system32\msxml4r.dll
2008-03-25 11:18 . 2003-04-18 17:29 44,544 --a------ C:\WINDOWS\system32\msxml4a.dll
2008-03-25 11:17 . 2008-03-25 11:18 <REP> d-------- C:\Documents and Settings\All Users\Application Data\MAGIX
2008-03-25 11:17 . 2007-02-07 11:53 663,552 --a------ C:\WINDOWS\system32\mgxoschk.dll
2008-03-25 11:16 . 2008-03-25 11:21 <REP> d-------- C:\Program Files\Fichiers communs\MAGIX Shared
2008-03-25 11:14 . 1998-10-15 18:28 85,504 --a------ C:\WINDOWS\system32\HtmlWH.dll
2008-03-25 11:13 . 2008-03-25 12:56 <REP> d-------- C:\WINDOWS\system32\MAGIX
2008-03-25 11:13 . 2008-03-25 12:37 6,651 --a------ C:\WINDOWS\mgxoschk.ini
2008-03-24 02:17 . 2008-03-24 02:17 <REP> d-------- C:\Documents and Settings\All Users\Application Data\BASAL7
2008-03-22 23:15 . 2006-03-13 18:38 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
2008-03-22 23:15 . 2006-03-13 18:38 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-03-22 23:15 . 2006-03-13 18:46 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
2008-03-22 23:15 . 2006-03-13 18:38 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents
2008-03-22 23:15 . 2006-03-13 18:38 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
2008-03-22 23:15 . 2006-03-13 18:38 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris
2008-03-22 23:15 . 2006-03-13 18:38 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2008-03-22 15:15 . 2008-03-22 15:15 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-03-22 01:04 . 2000-11-03 19:56 638,976 --a------ C:\WINDOWS\system32\eJ_Editorctrl.ocx
2008-03-22 01:03 . 2001-05-23 10:05 307,200 --a------ C:\WINDOWS\system32\drumpad.dll
2008-03-22 01:03 . 2000-03-29 02:58 280,576 --a------ C:\WINDOWS\system32\pxd_kom.dll
2008-03-22 01:03 . 2000-03-28 15:27 75,976 --a------ C:\WINDOWS\system32\BASSDEC.dll
2008-03-22 01:03 . 2001-04-01 19:16 45,056 --a------ C:\WINDOWS\system32\fader.dll
2008-03-21 18:53 . 2008-03-26 16:48 <REP> d-------- C:\Program Files\Ares
2008-03-21 18:43 . 2008-03-21 18:53 <REP> d-------- C:\Documents and Settings\JEAN MARIE\Application Data\BitTorrent
2008-03-20 21:18 . 2002-01-23 19:10 86,016 --a------ C:\WINDOWS\unvise32qt.exe
2008-03-20 21:15 . 2008-03-20 21:20 <REP> d-------- C:\Documents and Settings\All Users\Application Data\QuickTime
2008-03-20 19:48 . 2007-07-30 20:19 38,232 --a------ C:\WINDOWS\system32\wucltui.dll.mui
2008-03-20 19:48 . 2007-07-30 20:20 30,040 --a------ C:\WINDOWS\system32\wuaucpl.cpl.mui
2008-03-20 19:48 . 2007-07-30 20:19 30,040 --a------ C:\WINDOWS\system32\wuapi.dll.mui
2008-03-20 19:48 . 2007-07-30 20:18 21,336 --a------ C:\WINDOWS\system32\wuaueng.dll.mui
2008-03-19 17:30 . 2008-03-19 17:30 0 --a------ C:\WINDOWS\nsreg.dat
2008-03-19 17:15 . 2008-03-22 14:40 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-03-19 17:14 . 2008-04-02 19:08 <REP> d-------- C:\Program Files\Messenger Plus! Live
2008-03-19 16:59 . 2008-03-21 18:24 <REP> d-------- C:\Documents and Settings\JEAN MARIE\Contacts
2008-03-19 16:57 . 2008-04-02 19:08 <REP> d-------- C:\Program Files\MSN Messenger
2008-03-19 16:00 . 2007-01-11 12:18 31,547 -ra------ C:\WINDOWS\system32\drivers\usbiad.sys
2008-03-06 20:26 . 2008-03-28 22:01 <REP> d-------- C:\Program Files\Sony Ericsson
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-28 20:02 --------- d-----w C:\Program Files\Fichiers communs\Real
2008-03-28 19:23 --------- d-----w C:\Documents and Settings\JEAN MARIE\Application Data\ACAMPREF
2008-03-26 18:35 47,696 ----a-w C:\Program Files\print.pdf
2008-03-22 19:58 --------- d-----w C:\Program Files\Maxis
2008-02-24 17:05 52,224 --sha-w C:\Program Files\Thumbs.db
2008-02-24 17:05 --------- d-----w C:\Program Files\Micro Application
2008-02-16 18:23 --------- d-----w C:\Documents and Settings\JEAN MARIE\Application Data\vlc
2008-02-16 18:02 --------- d-----w C:\Program Files\VideoLAN
2008-02-10 10:55 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-02-08 16:37 219,664 ----a-w C:\WINDOWS\system32\klogon.dll
2008-02-08 16:35 23,604 ----a-w C:\WINDOWS\system32\drivers\klopp.dat
2008-02-02 12:15 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-02 12:13 --------- d-----w C:\Documents and Settings\JEAN MARIE\Application Data\XCPCSync.OEM
2008-02-02 12:12 --------- d-----w C:\Program Files\Ulead Systems
2008-02-02 12:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ulead Systems
2008-02-02 12:10 --------- d-----w C:\Program Files\DivX
2008-02-02 11:59 --------- d-----w C:\Program Files\Wanadoo
2008-02-02 10:44 --------- d-----w C:\Program Files\Fichiers communs\Ahead
2006-07-10 22:36 278,528 ----a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
2006-02-03 16:37 17,943,552 ------w C:\Program Files\TIConnectV1.6_Fra.exe
2001-08-28 10:00 4,096 --sha-w C:\WINDOWS\system32\7776.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AtiPTA"="atiptaxx.exe" [2001-09-27 02:39 245760 C:\WINDOWS\system32\atiptaxx.exe]
"mscdti"="C:\WINDOWS\cdti.exe" [2008-03-28 23:23 1494510]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2008-02-08 18:36 227856]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2001-08-28 12:00 13312]
C:\Documents and Settings\JEAN MARIE\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 2.4.lnk - C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 15:41:28 393216]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2008-02-02 14:25:23 110592]
BlueSoleil.lnk - C:\Program Files\IVT Corporation\BlueSoleil\BlueSoleil.exe [2006-03-16 12:37:25 1183744]
hdip.exe [2008-03-24 02:03:49 55808]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"AllowLegacyWebView"= 1 (0x1)
"AllowUnhashedWebView"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Documents and Settings\\All Users\\Menu Démarrer\\Programmes\\Démarrage\\hdip.exe"=
S2 Ca533av;Cam 3200, WDM Video Capture;C:\WINDOWS\System32\Drivers\Ca533av.sys []
S2 cfm;cfm;C:\WINDOWS\system32\cfmom.exe [2008-03-28 23:23]
S2 UxTuneUp;TuneUp Extension de thème;C:\WINDOWS\System32\svchost.exe [2001-08-28 12:00]
S3 ati2mpaa;ati2mpaa;C:\WINDOWS\System32\DRIVERS\ati2mpaa.sys [2001-08-23 17:59]
S3 ati2mtaa;ati2mtaa;C:\WINDOWS\System32\DRIVERS\ati2mtaa.sys [2001-09-27 01:32]
S3 C-Dilla;C-Dilla;C:\WINDOWS\System32\drivers\CDANT.SYS [2002-04-03 14:17]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\System32\DRIVERS\klim5.sys [2007-12-13 13:28]
S3 MBAMCatchMe;MBAMCatchMe;C:\Program Files\Malwarebytes' Anti-Malware\catchme.sys [2008-04-01 19:54]
S3 PALLADIA;Palladia 300/400 Usb Adsl Modem;C:\WINDOWS\System32\DRIVERS\usbiad.sys [2007-01-11 12:18]
S3 RescueDrv;Inventel Access Point USB Rescue Driver;C:\WINDOWS\System32\Drivers\resc_dwb.sys []
S3 SIS163u;SiS163 USB Wireless LAN Adapter Driver;C:\WINDOWS\System32\DRIVERS\sis163u.sys [2006-03-01 19:37]
S3 UPnPService;UPnPService;C:\Program Files\Fichiers communs\MAGIX Shared\UPnPService\UPnPService.exe [2006-12-14 17:00]
S3 USBCamera;DSC Still Image Capture (CA100);C:\WINDOWS\System32\Drivers\Bulk533.sys []
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{50C413FA-25F9-4C54-EB6C-03AE71A313CE}]
C:\WINDOWS\System32:svchost.exe
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-03-28 18:49:35 C:\WINDOWS\Tasks\Maintenance en 1 clic.job"
- C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-04-02 19:37:02
Windows 5.1.2600 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-04-02 19:38:09
ComboFix-quarantined-files.txt 2008-04-02 17:37:54
Pre-Run: 17,429,602,304 octets libres
Post-Run: 17,415,479,296 octets libres
.
2008-03-20 18:05:36 --- E O F ---
Petit probléme, mon antivirus a vient de detecter un virus et parait-il qu'il vient de Combofix, est-ce normal? Il s'appele virus Heur.Invader
PS: mon virus principal est helas toujours la!