Merci Cyril.
Voici le rapport :
ComboFix 08-05-01.3 - Marie 2008-05-06 21:43:20.11 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.2200 [GMT 2:00]
Endroit: C:\Users\Marie\Desktop\ComboFix.exe
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\system32\drivers\down
C:\Windows\system32\kxvo.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2008-04-06 to 2008-05-06 ))))))))))))))))))))))))))))))))))))
.
Pas de nouveau fichier créé dans cet espace de temps
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-06 19:43 3,145,728 --sha-w C:\Users\Propriétaire\NTUSER.DAT
2008-05-06 19:43 3,145,728 --sha-w C:\Users\Propriétaire\NTUSER.DAT
2008-05-06 19:43 1,048,576 --sha-w C:\Users\Invité\NTUSER.DAT
2008-05-06 19:43 1,048,576 --sha-w C:\Users\Invité\NTUSER.DAT
2008-05-06 19:28 --------- d-----w C:\Users\Marie\AppData\Roaming\OpenOffice.org2
2008-05-06 16:13 --------- d-----w C:\Program Files\Trend Micro
2008-05-06 12:04 0 ----a-w C:\osy3.sys
2008-05-06 09:28 --------- d-----w C:\Program Files\Panda Security
2008-05-04 13:23 --------- d-----w C:\Users\Propriétaire\AppData\Roaming\OpenOffice.org2
2008-04-25 14:08 --------- d-----w C:\Users\Marie\AppData\Roaming\Image Zone Express
2008-04-22 14:07 --------- d-----w C:\Users\Marie\AppData\Roaming\Zylom
2008-04-20 09:51 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-04-18 08:37 --------- d-----w C:\Program Files\iTunes
2008-04-18 08:36 --------- d-----w C:\Program Files\QuickTime
2008-04-18 08:36 --------- d-----w C:\Program Files\iPod
2008-04-18 08:36 --------- d-----w C:\PROGRA~2\Apple Computer
2008-04-18 08:34 --------- d-----w C:\Program Files\Apple Software Update
2008-04-16 15:48 --------- d-----w C:\Program Files\Fish Aquarium 3D Screensaver
2008-04-10 07:01 --------- d-----w C:\Program Files\Windows Mail
2008-04-08 17:19 --------- d-----w C:\Program Files\fishaquarium
2008-04-07 08:14 --------- d-----w C:\PROGRA~2\HPSSUPPLY
2008-04-07 08:13 --------- d-----w C:\Users\Propriétaire\AppData\Roaming\Printer Info Cache
2008-04-07 08:13 --------- d-----w C:\Users\Propriétaire\AppData\Roaming\Image Zone Express
2008-04-07 07:12 --------- d-s---w C:\Users\Propriétaire\AppData\Roaming\Microsoft
2008-04-07 07:12 --------- d-----w C:\Program Files\HP
2008-04-07 01:49 8,140,915 ----a-w C:\Windows\breve.scr
2008-04-07 01:49 237,568 ----a-w C:\Windows\glut32.dll
2008-03-29 18:35 319,456 ----a-w C:\Windows\DIFxAPI.dll
2008-03-29 18:35 --------- d-----w C:\Users\Propriétaire\AppData\Roaming\WinBatch
2008-03-29 18:35 --------- d-----w C:\Program Files\Realtek
2008-03-29 08:49 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-03-24 13:27 12,400 ----a-w C:\Windows\system32\drivers\SECDRV.SYS
2008-03-24 13:24 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-24 12:48 --------- d-----w C:\Program Files\Maxis
2008-03-24 12:46 --------- d-----w C:\Program Files\Common Files\InstallShield
2008-03-24 12:12 --------- d-----w C:\Users\Marie\AppData\Roaming\Ahead
2008-03-16 09:25 643,920 ----a-w C:\PortableRoboForm.exe
2008-02-29 06:51 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-02-29 06:39 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-02-29 06:39 371,712 ----a-w C:\Windows\System32\srcore.dll
2008-02-29 06:38 313,856 ----a-w C:\Windows\System32\rstrui.exe
2008-02-29 06:38 16,384 ----a-w C:\Windows\System32\srdelayed.exe
2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-02-29 06:34 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll
2008-02-29 04:14 2,028,544 ----a-w C:\Windows\System32\win32k.sys
2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll
2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll
2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
2008-02-21 04:43 296,448 ----a-w C:\Windows\System32\gdi32.dll
2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
2008-02-19 05:10 620,088 ----a-w C:\Windows\System32\ci.dll
2008-02-14 23:19 944,184 ----a-w C:\Windows\System32\winload.exe
2008-02-13 09:04 194,560 ----a-w C:\Windows\System32\WebClnt.dll
2008-02-13 09:02 3,505,720 ----a-w C:\Windows\System32\ntkrnlpa.exe
2008-02-13 09:02 3,471,928 ----a-w C:\Windows\System32\ntoskrnl.exe
2008-02-13 09:01 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
2008-02-13 09:01 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
2008-02-13 09:01 4,247,552 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
2008-02-13 09:01 24,064 ----a-w C:\Windows\System32\netcfg.exe
2008-02-13 09:01 22,016 ----a-w C:\Windows\System32\netiougc.exe
2008-02-13 09:01 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
2008-02-13 09:01 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
2008-02-13 09:01 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
2008-02-13 09:01 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
2008-02-13 09:01 1,686,528 ----a-w C:\Windows\System32\gameux.dll
2008-02-02 22:18 174 --sha-w C:\Program Files\desktop.ini
2007-12-29 15:25 612 ----a-w C:\Users\Marie\AppData\Roaming\wklnhst.dat
2007-12-25 14:50 47,360 ----a-w C:\Users\Marie\AppData\Roaming\pcouffin.sys
2007-11-07 14:03 126 ----a-w C:\Users\Propriétaire\AppData\Roaming\wklnhst.dat
2008-02-04 13:13 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008020420080205\index.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-09 12:28 1232896]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 20:03 152872]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 14:35 125440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2007-09-01 16:56 1006264]
"KBD"="C:\HP\KBD\KbdStub.EXE" [2006-12-08 18:16 65536]
"OsdMaestro"="C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 13:59 118784]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-06-14 20:31 178968]
"StartCCC"="c:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 12:35 90112]
"RtHDVCpl"="RtHDVCpl.exe" [2008-01-15 12:26 4874240 C:\Windows\RtHDVCpl.exe]
"CCUTRAYICON"="FactoryMode" []
"HP Health Check Scheduler"="c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-05-24 13:13 71176]
"SunJavaUpdateReg"="C:\Windows\system32\jureg.exe" [2007-09-25 02:11 54672]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 22:52 49152]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-01 16:57 153136]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2007-08-31 13:25 249896]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="%WINDIR%\SMINST\launcher.exe" [ ]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 22:40:10 210520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.I420"= i263_32.drv
"vidc.yv12"= yv12vfw.dll
"VIDC.HFYU"= huffyuv.dll
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= divxa32.acm
"vidc.3ivx"= 3ivxVfWCodec.dll
"vidc.3iv2"= 3ivxVfWCodec.dll
"VIDC.i263"= i263_32.drv
"msacm.imc"= imc32.acm
"VIDC.VP31"= vp31vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-918319700-1789878857-3928151191-1001]
"EnableNotificationsRef"=dword:00000025
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-918319700-1789878857-3928151191-1002]
"EnableNotificationsRef"=dword:0000001d
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-918319700-1789878857-3928151191-501]
"EnableNotificationsRef"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{C811BB3A-C6BF-48F1-A9B2-9E3A25CD7478}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{EF6CA61F-9863-45F4-8549-FD48443B7E7E}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{AD63F5DE-D4D5-42A6-8136-9102C7EF05E3}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel(R) Viiv(TM) Media Server
"{0AB6ED54-0E52-40D4-9621-20AB7D749574}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel(R) Viiv(TM) Media Server
"{66FF50A4-40D9-4C3E-A4CD-BC4C3A933208}"= UDP:C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel(R) Remoting Service
"{DBCB39EF-C1D7-4419-9ECE-DE15D7C52483}"= TCP:C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel(R) Remoting Service
"{2B83BC5B-2FC0-449C-91AE-F09F87BA0CCF}"= TCP:9442:127.0.0.1:Intel(R) Viiv(TM) Media Server Discovery
"{069B212C-2947-402F-BD6A-6350E37F07BA}"= TCP:1900:LocalSubnet:LocalSubnet:Intel(R) Viiv(TM) Media Server UPnP Discovery
"{9D29FF59-F50C-4BA1-94E7-82EE4774A370}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{2F331BA3-FEE9-45EE-9FAD-333B66B1B548}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{B7C2AFAF-395A-4625-94FA-518E61011C64}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R2 DQLWinService;DQLWinService;"C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe" [2006-09-03 10:32]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-07-10 02:35]
S2 IntelDHSvcConf;Intel DH Service;"C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe" [2006-05-10 09:13]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f0d427ef-fa42-11dc-8759-001d60539785}]
\shell\AutoRun\command - K:\apj.com
\shell\explore\Command - K:\apj.com
\shell\open\Command - K:\apj.com
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-05-06 19:44:00 C:\Windows\Tasks\User_Feed_Synchronization-{7C3D90E6-AD2A-4875-97E6-4A717C6CB81D}.job"
- C:\Windows\system32\msfeedssync.exe
"2008-05-05 19:44:11 C:\Windows\Tasks\User_Feed_Synchronization-{A285B298-96D4-42DD-A080-185995B07532}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-06 21:45:59
Windows 6.0.6000 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 1
**************************************************************************
.
Temps d'accomplissement: 2008-05-06 21:46:51
ComboFix-quarantined-files.txt 2008-05-06 19:46:47
Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
191 --- E O F --- 2008-04-09 19:55:47