Merci !
voici les rapports :
ComboFix 08-08-05.05 - sebastien 2008-08-06 18:19:40.1 - [color=red][b]FAT32/b/colorx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.510 [GMT 2:00]
Endroit: C:\Documents and Settings\sebastien\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\sebastien\Mes documents\My Documents.url
C:\WINDOWS\g32.txt
C:\WINDOWS\system32\msvrl.dll
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-07-06 to 2008-08-06 ))))))))))))))))))))))))))))))))))))
.
2008-08-06 16:44 . 2008-08-06 16:44 <REP> d-------- C:\Program Files\Navilog1
2008-08-05 20:55 . 2008-08-05 20:55 <REP> d-------- C:\Program Files\Fichiers communs\Symantec Shared
2008-08-05 20:54 . 2008-08-05 20:54 <REP> d-------- C:\WINDOWS\system32\fr
2008-08-05 20:54 . 2008-08-05 20:54 <REP> d-------- C:\Program Files\Trustix
2008-08-05 20:54 . 2008-08-05 20:54 <REP> d-------- C:\Program Files\SUPERAntiSpyware
2008-08-05 20:54 . 2008-08-05 20:54 <REP> d-------- C:\Documents and Settings\tordinateur\Application Data\SUPERAntiSpyware.com
2008-08-05 20:53 . 2008-08-05 20:53 <REP> d-------- C:\Documents and Settings\tordinateur\Application Data\Malwarebytes
2008-08-04 20:56 . 2008-08-04 20:56 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-08-04 20:35 . 2008-08-04 20:35 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-08-04 20:33 . 2008-08-04 20:33 579,584 --a------ C:\WINDOWS\system32\dllcache\user32.dll
2008-08-04 20:31 . 2008-08-04 20:31 <REP> d-------- C:\WINDOWS\ERUNT
2008-08-04 18:29 . 2008-08-04 18:29 <REP> d-------- C:\Program Files\Comodo
2008-08-04 18:29 . 2008-08-04 18:29 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Comodo
2008-08-04 15:15 . 2008-05-08 16:02 203,136 --------- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-08-04 15:05 . 2008-08-04 15:05 <REP> d-------- C:\WINDOWS\l2schemas
2008-08-04 14:32 . 2008-04-14 04:10 2,524 --------- C:\WINDOWS\system32\pid.inf
2008-08-04 13:15 . 2008-08-04 13:15 <REP> d-------- C:\WINDOWS\system32\CatRoot2
2008-08-04 12:47 . 2008-08-04 12:47 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Malwarebytes
2008-08-03 22:43 . 2008-08-03 22:43 <REP> d-------- C:\Documents and Settings\tordinateur\Application Data\Uniblue
2008-08-03 22:13 . 2001-08-28 20:00 5,632 --a------ C:\WINDOWS\system32\write.exe
2008-08-03 22:05 . 2004-07-17 11:35 283,685 --a------ C:\WINDOWS\Helpmsoe.chm
2008-08-03 22:05 . 2001-08-28 13:00 80,692 --a------ C:\WINDOWS\Helpwab.chm
2008-08-03 22:05 . 2001-08-28 13:00 58,431 --a------ C:\WINDOWS\Helpmsoe.hlp
2008-08-03 22:05 . 2001-08-28 13:00 29,341 --a------ C:\WINDOWS\Helpwab.hlp
2008-08-03 22:05 . 2001-08-28 13:00 19,826 --a------ C:\WINDOWS\Helpmsoeacct.hlp
2008-08-03 22:00 . 2004-08-19 16:09 81,408 --a------ C:\directdb.dll
2008-08-03 21:12 . 2008-06-14 19:33 272,768 --------- C:\WINDOWS\system32\dllcache\bthport.sys
2008-08-03 20:37 . 2008-08-03 20:37 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-08-01 22:02 . 2008-08-01 22:02 <REP> d-------- C:\Documents and Settings\sebastien\Application Data\Malwarebytes
2008-08-01 22:02 . 2008-08-01 22:02 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-01 21:16 . 2008-08-01 21:16 19,774 --a------ C:\Program Files\Fichiers communs\azybeci.dat
2008-08-01 21:16 . 2008-08-01 21:16 19,643 --a------ C:\Program Files\Fichiers communs\pobubomik.sys
2008-08-01 21:16 . 2008-08-01 21:16 19,642 --a------ C:\Program Files\Fichiers communs\yjaboryv.dat
2008-08-01 21:16 . 2008-08-01 21:16 19,494 --a------ C:\Documents and Settings\tordinateur\Application Data\arijit.pif
2008-08-01 21:16 . 2008-08-01 21:16 19,011 --a------ C:\WINDOWS\wijajotyl._dl
2008-08-01 21:16 . 2008-08-01 21:16 16,723 --a------ C:\Documents and Settings\tordinateur\Application Data\acofil.vbs
2008-08-01 21:16 . 2008-08-01 21:16 16,418 --a------ C:\WINDOWS\system32\vodumuju.scr
2008-08-01 21:16 . 2008-08-01 21:16 15,717 --a------ C:\Documents and Settings\tordinateur\Application Data\kulu.scr
2008-08-01 21:16 . 2008-08-01 21:16 15,466 --a------ C:\WINDOWS\system32\ejasezekas._dl
2008-08-01 21:16 . 2008-08-01 21:16 13,787 --a------ C:\WINDOWS\qeqomedaxu.reg
2008-08-01 21:16 . 2008-08-01 21:16 13,492 --a------ C:\Program Files\Fichiers communs\taqebog.vbs
2008-08-01 21:16 . 2008-08-01 21:16 13,389 --a------ C:\Documents and Settings\All Users\Application Data\uban.sys
2008-08-01 21:16 . 2008-08-01 21:16 13,388 --a------ C:\Documents and Settings\All Users\Application Data\utoxadocuz.com
2008-08-01 21:16 . 2008-08-01 21:16 12,990 --a------ C:\WINDOWS\uqiwixuwok.db
2008-08-01 21:16 . 2008-08-01 21:16 11,039 --a------ C:\WINDOWS\system32\ymekavut.db
2008-08-01 21:15 . 2008-07-27 22:29 172,295 --a------ C:\WINDOWS\system32\_scui.cpl
2008-08-01 21:15 . 2008-08-01 21:15 19,270 --a------ C:\WINDOWS\yvyxafi.ban
2008-08-01 21:15 . 2008-08-01 21:15 18,484 --a------ C:\Program Files\Fichiers communs\bypoholih.bin
2008-08-01 21:15 . 2008-08-01 21:15 16,222 --a------ C:\Documents and Settings\tordinateur\Application Data\wiviruwes.reg
2008-08-01 21:15 . 2008-08-01 21:15 15,273 --a------ C:\WINDOWS\duwomemo.com
2008-08-01 21:15 . 2008-08-01 21:15 14,281 --a------ C:\WINDOWS\obesicypi.inf
2008-08-01 21:15 . 2008-08-01 21:15 13,460 --a------ C:\Documents and Settings\tordinateur\Application Data\egytugo.dll
2008-08-01 21:15 . 2008-08-01 21:15 12,288 --a------ C:\Program Files\Fichiers communs\gojykulo.bin
2008-08-01 21:15 . 2008-08-01 21:15 12,145 --a------ C:\Documents and Settings\tordinateur\Application Data\esinuvyr.scr
2008-08-01 21:15 . 2008-08-01 21:15 11,687 --a------ C:\WINDOWS\system32\pyqutiwuc.dl
2008-08-01 21:15 . 2008-08-01 21:15 11,348 --a------ C:\WINDOWS\system32\ekicyrujyf._dl
2008-08-01 18:17 . 2008-08-01 18:17 268 --ah----- C:\sqmdata05.sqm
2008-08-01 18:17 . 2008-08-01 18:17 244 --ah----- C:\sqmnoopt05.sqm
2008-08-01 13:06 . 2008-08-01 13:06 268 --ah----- C:\sqmdata04.sqm
2008-08-01 13:06 . 2008-08-01 13:06 244 --ah----- C:\sqmnoopt04.sqm
2008-07-12 23:12 . 2008-07-12 23:12 268 --ah----- C:\sqmdata03.sqm
2008-07-12 23:12 . 2008-07-12 23:12 244 --ah----- C:\sqmnoopt03.sqm
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-06 15:09 2,208 ----a-w C:\WINDOWS\system32\PerfStringBackup.TMP
2008-08-01 19:16 15,616 ----a-w C:\Program Files\Fichiers communs\sumowyzuv.inf
2008-06-24 20:40 --------- d-----w C:\Documents and Settings\tordinateur\Application Data\Azureus
2008-06-20 18:55 --------- d-----w C:\Program Files\Fichiers communs\xing shared
2008-06-20 17:47 247,808 ----a-w C:\WINDOWS\system32\MSWSOCK.DLL
2008-06-20 17:47 247,808 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:47 147,968 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 11:51 361,600 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 11:51 361,600 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 11:40 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 11:40 138,496 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 11:08 225,856 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-20 11:08 225,856 ------w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-17 19:06 --------- d-----w C:\Documents and Settings\sebastien\Application Data\Azureus
2008-06-17 19:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Azureus
2008-06-14 17:33 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-05-09 10:55 90,112 ----a-w C:\WINDOWS\system32\wshext.dll
2008-05-09 10:55 90,112 ------w C:\WINDOWS\system32\dllcache\wshext.dll
2008-05-09 10:55 512,000 ------w C:\WINDOWS\system32\dllcache\jscript.dll
2008-05-09 10:55 430,080 ----a-w C:\WINDOWS\system32\vbscript.dll
2008-05-09 10:55 430,080 ------w C:\WINDOWS\system32\dllcache\vbscript.dll
2008-05-09 10:55 180,224 ----a-w C:\WINDOWS\system32\scrobj.dll
2008-05-09 10:55 180,224 ------w C:\WINDOWS\system32\dllcache\scrobj.dll
2008-05-09 10:55 172,032 ----a-w C:\WINDOWS\system32\scrrun.dll
2008-05-09 10:55 172,032 ------w C:\WINDOWS\system32\dllcache\scrrun.dll
2008-05-08 11:24 155,648 ----a-w C:\WINDOWS\system32\wscript.exe
2008-05-08 11:24 155,648 ------w C:\WINDOWS\system32\dllcache\wscript.exe
2008-05-07 09:07 135,168 ----a-w C:\WINDOWS\system32\cscript.exe
2008-05-07 09:07 135,168 ------w C:\WINDOWS\system32\dllcache\cscript.exe
2008-05-07 05:11 1,294,336 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-07 05:11 1,294,336 ------w C:\WINDOWS\system32\dllcache\quartz.dll
2006-01-25 16:38 4,371 ----a-w C:\Program Files\SolidWorksswxJRNL.BAK
2005-12-16 19:10 278,528 ----a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WOOKIT"="C:\PROGRA~1\WANADOO\GestMaj.exe" [2004-10-14 17:55 32768]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 04:34 15360]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 15:57 282624]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-14 04:34 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.iv31"= C:\WINDOWS\system32\ir32_32.dll
"vidc.iv32"= C:\WINDOWS\system32\ir32_32.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli scecli scecli scecli scecli scecli
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"AOL Spyware Protection"="C:\PROGRA~1\FICHIE~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
"AOLDialer"=C:\Program Files\Fichiers communs\AOL\ACS\AOLDial.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1723:TCP"= 1723:TCP:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:@xpsp2res.dll,-22017
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
R3 C4C_BSC2;C4C_BSC2;C:\WINDOWS\system32\DRIVERS\C4C_BSC2.sys [2002-07-08 19:32]
R3 PAC7311;Trust WB-3400T Webcam;C:\WINDOWS\system32\DRIVERS\PA707UCM.SYS [2007-03-14 10:57]
R3 usbstor;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 08:08]
S2 OPTENET_FILTER;Orange Contrôle Parental;C:\Program Files\Controle Parental\bin\optproxy.exe [2006-12-21 20:15]
S3 Connexion dictionnaire;Navigation étendue et définition;C:\WINDOWS\System32\Weather.exe []
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-04 07:58]
S3 ZDCndis5;ZDCndis5 Protocol Driver;C:\WINDOWS\System32\ZDCndis5.SYS []
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.wanadoo.fr
R0 -: HKCU-Main,SearchMigratedDefaultURL = 687474703a2f2f7777772e676f6f676c652e636f6d2f
R0 -: HKCU-Main,Default_Search_URL = 687474703a2f2f7777772e676f6f676c652e636f6d2f
R0 -: HKLM-Main,SearchMigratedDefaultURL = 687474703a2f2f7777772e676f6f676c652e636f6d2f
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
R1 -: HKLM-Internet Explorer,SearchURL = 687474703a2f2f7777772e676f6f676c652e636f6d2f
O16 -: {1B3E3251-658E-4F03-8881-68302FE3CE9E} - hxxp://www.friend.fr/friend/Friend2005-03.xms
C:\WINDOWS\Downloaded Program Files\Friend.inf
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-06 18:22:26
Windows 5.1.2600 Service Pack 3 FAT NTAPI
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V1.1.4322\ASPNET_STATE.EXE
C:\WINDOWS\SYSTEM32\DLLHOST.EXE
C:\WINDOWS\SYSTEM32\FTRTSVC.EXE
C:\WINDOWS\SYSTEM32\HPZIPM12.EXE
.
**************************************************************************
.
Temps d'accomplissement: 2008-08-06 18:24:07 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-06 16:24:06
Pre-Run: 32,743,424,000 octets libres
Post-Run: 33,063,141,376 octets libres
201 --- E O F --- 2008-08-04 18:12:35
Logfile of HijackThis v1.99.1
Scan saved at 18:24:47, on 06/08/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\dllhost.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\tordinateur\Bureau\net\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\WANADOO\GestMaj.exe EspaceWanadoo.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O16 - DPF: {1B3E3251-658E-4F03-8881-68302FE3CE9E} - http://www.friend.fr/friend/Friend2005-03.xms
O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Navigation étendue et définition (Connexion dictionnaire) - Unknown owner - C:\WINDOWS\System32\Weather.exe (file missing)
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Orange Contrôle Parental (OPTENET_FILTER) - Orange - C:\Program Files\Controle Parental\bin\optproxy.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe