Je viens de terminer ComboFix & voici le rapport.
A la fin, il a redémarré mon ordinateur, puis affiché le rapport après le redémarrage, mais je ne l'ai pas remis en mode sans échec lors du redémarrage..
ComboFix 08-08-17.01 - Propriétaire 2008-08-17 21:40:40.1 - NTFSx86 MINIMAL
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.33.1036.18.758 [GMT 2:00]
Endroit: C:\Documents and Settings\Propriétaire\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Propriétaire\Application Data\inst.exe
C:\Documents and Settings\Propriétaire\Application Data\macromedia\Flash Player\#SharedObjects\5HL57BJX\interclick.com
C:\Documents and Settings\Propriétaire\Application Data\macromedia\Flash Player\#SharedObjects\5HL57BJX\interclick.com\ud.sol
C:\Documents and Settings\Propriétaire\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\Propriétaire\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\Propriétaire\Cookies\propriétaire@ad.yieldmanager[1].txt
C:\Documents and Settings\Propriétaire\Cookies\propriétaire@ad.yieldmanager[2].txt
C:\Documents and Settings\Propriétaire\Cookies\propriétaire@ads.revsci[1].txt
C:\Documents and Settings\Propriétaire\Cookies\propriétaire@cubics[1].txt
C:\Documents and Settings\Propriétaire\Cookies\propriétaire@portfolio[1].txt
C:\Documents and Settings\Propriétaire\Cookies\propriétaire@revsci[2].txt
C:\Documents and Settings\Propriétaire\Menu Démarrer\Programmes\Antivirus 2008
C:\Documents and Settings\Propriétaire\Menu Démarrer\Programmes\Antivirus 2008\Antivirus-2008.lnk
C:\Documents and Settings\Propriétaire\UserData
C:\Documents and Settings\Propriétaire\UserData\index.dat
C:\WINDOWS\system32\mvffynkx.ini
C:\WINDOWS\system32\RYJRXyxx.ini
C:\WINDOWS\system32\RYJRXyxx.ini2
C:\WINDOWS\system32\tppqlliq.ini
C:\WINDOWS\system32\ymyruvph.ini
D:\Autorun.inf
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-07-17 to 2008-08-17 ))))))))))))))))))))))))))))))))))))
.
2008-08-17 17:36 . 2008-08-17 17:36 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-17 17:36 . 2008-08-17 17:36 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-17 17:36 . 2008-07-30 20:07 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-17 17:36 . 2008-07-30 20:07 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-08-16 23:40 . 2008-08-17 00:08 3,838 --a------ C:\Documents and Settings\Orph.egd
2008-08-16 23:38 . 2008-08-17 00:09 <REP> d-------- C:\Toolbar SD
2008-08-16 22:36 . 2008-08-16 23:02 3,980 --a------ C:\WINDOWS\system32\tmp.reg
2008-08-16 22:34 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-08-16 22:34 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-08-16 22:34 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-08-16 22:34 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-08-16 22:34 . 2008-08-14 21:52 82,432 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-08-16 22:34 . 2008-08-09 15:37 82,432 --a------ C:\WINDOWS\system32\404Fix.exe
2008-08-16 22:34 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-08-16 22:34 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-08-16 22:34 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-08-16 18:40 . 2008-08-16 18:40 <REP> d-------- C:\Program Files\Trend Micro
2008-08-13 16:47 . 2008-08-13 16:52 <REP> d-------- C:\Program Files\Okoker CD&DVD Burner
2008-08-13 16:41 . 2008-08-13 16:41 94,208 --a------ C:\WINDOWS\system32\drivers\ezplay.sys
2008-08-13 13:24 . 2008-08-13 13:24 <REP> d-------- C:\Program Files\iPod
2008-08-13 13:23 . 2008-08-13 13:23 <REP> d-------- C:\Program Files\Bonjour
2008-08-13 13:15 . 2008-08-13 13:15 <REP> d-------- C:\Program Files\Safari
2008-08-10 18:10 . 2008-08-10 19:14 1,042 --a------ C:\WINDOWS\eReg.dat
2008-08-10 17:54 . 2008-08-10 18:01 <REP> d-------- C:\Program Files\Maxis
2008-07-25 10:32 . <REP> C:\Documents and Settings\Propriétaire\GHARR
2008-07-25 01:56 . 2004-08-20 00:09 159,232 --a------ C:\WINDOWS\system32\ptpusd.dll
2008-07-25 01:56 . 2001-08-23 17:47 5,632 --a------ C:\WINDOWS\system32\ptpusb.dll
2008-07-18 20:39 . 2008-07-18 20:39 587,264 --a------ C:\WINDOWS\WLXPGSS.SCR
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-15 09:45 --------- d-----w C:\Program Files\AviSynth 2.5
2008-08-14 08:43 --------- d-----w C:\Program Files\VSO
2008-08-14 08:40 --------- d-----w C:\Program Files\AVSMedia
2008-08-14 07:59 --------- d-----w C:\Program Files\Fichiers communs\LightScribe
2008-08-14 07:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\Droppix
2008-08-13 11:44 --------- d-----w C:\Program Files\Apple Software Update
2008-08-13 11:25 --------- d-----w C:\Program Files\iTunes
2008-08-13 11:23 --------- d-----w C:\Program Files\QuickTime
2008-08-10 17:13 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-07-25 09:07 --------- d-----w C:\Program Files\Elaborate Bytes
2008-07-25 08:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2008-07-25 08:26 47,360 ----a-w C:\WINDOWS\system32\drivers\pcouffin.sys
2008-07-22 18:32 32,000 ----a-w C:\WINDOWS\system32\drivers\usbaapl.sys
2008-07-15 15:19 --------- d-----w C:\Program Files\Fichiers communs\AVSMedia
2008-07-15 15:19 --------- d-----w C:\Program Files\AVS4YOU
2008-07-10 20:40 --------- d-----w C:\Program Files\NCH Software
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-17 22:20 --------- d-----w C:\Program Files\ICQ
2008-06-17 22:15 --------- d-----w C:\Program Files\Astonsoft
2008-04-04 18:19 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2008-01-12 12:03 32 -c--a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-12-05 20:59 18,074,624 ----a-w C:\Program Files\VeohSetup-3.7.1.1044.exe
2007-11-21 21:59 1,658,048 ----a-w C:\Program Files\pf-setup.exe
2007-11-18 18:24 3,966,288 ----a-w C:\Program Files\MsgPlusLive-423.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe" [2007-09-20 16:35 202024]
"BackupNotify"="c:\Program Files\HP\Digital Imaging\bin\backupnotify.exe" [2004-01-09 02:34 32768]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 01:09 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 17:04 52736]
"HPHUPD05"="c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe" [2003-08-21 04:23 49152]
"HPHmon05"="C:\WINDOWS\System32\hphmon05.exe" [2003-08-21 04:16 483328]
"KBD"="C:\HP\KBD\KBD.EXE" [2003-02-11 20:02 61440]
"UpdateManager"="C:\Program Files\Fichiers communs\Sonic\Update Manager\sgtray.exe" [2003-08-19 09:01 110592]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2003-11-03 17:50 221184]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-10-16 16:57 81920]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-09-20 10:51 1836328]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 16:38 78008]
"AppleSyncNotifier"="C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 20:42 116040]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-30 10:47 289064]
"VTTimer"="VTTimer.exe" [2003-08-20 19:56 45056 C:\WINDOWS\system32\VTTimer.exe]
"AlcxMonitor"="ALCXMNTR.EXE" [2003-04-03 21:35 50176 C:\WINDOWS\ALCXMNTR.EXE]
"AdslTaskBar"="stmctrl.dll" [2003-12-12 16:50 151552 C:\WINDOWS\system32\stmctrl.dll]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"NoDispSettingPage"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= C:\WINDOWS\system32\l3codecp.acm
"msacm.dvacm"= C:\PROGRA~1\FICHIE~1\ULEADS~1\Vio\Dvacm.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Nero\\Nero8\\Nero Home\\NeroHome.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"20042:TCP"= 20042:TCP:BitComet 20042 TCP
"20042:UDP"= 20042:UDP:BitComet 20042 UDP
"86:TCP"= 86:TCP:BroadCam Web Server
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 16:35]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 16:37]
R3 MusCVideo32;MusCVideo32;C:\WINDOWS\system32\DRIVERS\MusCVideo32.sys [2008-06-04 10:19]
R3 Stmatm;ATM/ADSL miniport;C:\WINDOWS\system32\DRIVERS\stmatm.sys [2003-09-15 09:33]
R3 TaurusPci;ADSL Modem PCI Service;C:\WINDOWS\system32\DRIVERS\toruspci.sys [2003-12-15 09:59]
S3 GAB20Scan;USB 2.0 Still Image;C:\WINDOWS\system32\Drivers\GABscan.sys [2003-08-12 15:22]
S3 M028USB20GAB;AVerDVD EZMaker USB 2.0 Video Capture;C:\WINDOWS\system32\Drivers\M8Mini20.sys [2004-02-13 13:17]
S3 MusCDriverV32;MusCDriverV32;C:\WINDOWS\system32\drivers\MusCDriverV32.sys []
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-04 07:58]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 08:08]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Fichiers communs\LightScribe\LSRunOnce.exe"
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
2008-08-13 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - (no file)
HKCU-Run-Registry Helper - C:\Program Files\Registry Helper\RegistryHelper.Exe
HKCU-Run-RecordNow! - (no file)
HKLM-Run-Mirabilis ICQ - C:\Program Files\ICQ\icq.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Propriétaire\Application Data\Mozilla\Firefox\Profiles\u2cwy3rf.default\
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-17 21:46:42
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Fichiers communs\InterVideo\DeviceService\DevSvc.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-08-17 21:58:11 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-17 19:58:05
Pre-Run: 30,591,275,008 octets libres
Post-Run: 30,348,390,400 octets libres
192 --- E O F --- 2008-08-13 14:20:29