Merci pour ta rapidité.
J'avais déjà fait avec ComboFix. Mais je viens de le refaire et te joins le rapport.
ComboFix 08-08-26.03 - Kojak 2008-08-27 20:55:31.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.544 [GMT 2:00]
Endroit: C:\Documents and Settings\kojax\Bureau\ComboFix.exe
* Resident AV is active
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-07-27 to 2008-08-27 ))))))))))))))))))))))))))))))))))))
.
2008-08-27 19:45 . 2008-08-27 19:45 <REP> d-------- C:\VundoFix Backups
2008-08-26 19:54 . 2008-08-26 19:54 <REP> d-------- C:\Documents and Settings\Kojak\Application Data\Spyware Terminator
2008-08-25 23:02 . 2008-08-25 23:02 <REP> d-------- C:\Documents and Settings\Kojak\Application Data\Malwarebytes
2008-08-24 20:07 . 2008-08-24 20:07 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-24 20:07 . 2008-08-24 20:07 <REP> d-------- C:\Documents and Settings\Kojak\Application Data\Malwarebytes
2008-08-24 20:07 . 2008-08-24 20:07 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-24 20:07 . 2008-08-17 15:01 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-24 20:07 . 2008-08-17 15:01 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-08-23 17:52 . 2008-08-23 17:52 <REP> d-------- C:\Program Files\Trend Micro
2008-08-23 10:49 . 2008-08-23 10:49 912 --a------ C:\WINDOWS\system32\dvptbktf.dll
2008-08-22 19:35 . 2008-08-22 19:35 912 --a------ C:\WINDOWS\system32\aubpbang.dll
2008-08-22 19:32 . 2008-08-22 19:32 912 --a------ C:\WINDOWS\system32\wtnwmrdf.dll
2008-08-22 19:32 . 2008-08-22 19:32 912 --a------ C:\WINDOWS\system32\updubhji.dll
2008-08-21 20:24 . 2008-08-21 20:24 <REP> d-------- C:\Program Files\Crawler
2008-08-21 20:23 . 2008-08-26 23:48 <REP> d-------- C:\Program Files\Spyware Terminator
2008-08-21 20:23 . 2008-08-26 23:45 <REP> d-------- C:\Documents and Settings\Kojak\Application Data\Spyware Terminator
2008-08-21 20:23 . 2008-08-26 23:48 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2008-08-21 20:23 . 2008-08-21 20:23 141,312 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-08-17 10:21 . 2008-08-17 10:21 <REP> d-------- C:\Documents and Settings\Kojak\Application Data\TmpRecentIcons
2008-08-16 09:59 . 2008-08-16 09:59 <REP> d-------- C:\Documents and Settings\Kojak\Application Data\TuneUp Software
2008-08-13 10:55 . 2008-08-13 10:55 25 --a------ C:\WINDOWS\cdplayer.ini
2008-08-13 09:43 . 2008-04-11 21:05 691,712 -----c--- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-13 09:43 . 2008-05-01 16:36 331,776 -----c--- C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-07 11:53 . 2008-08-07 11:55 <REP> d-------- C:\Documents and Settings\Kojak\Application Data\GARMIN
2008-08-07 10:31 . 2008-08-07 10:31 <REP> d-------- C:\Program Files\NOS
2008-08-07 10:31 . 2008-08-07 10:53 <REP> d-------- C:\Documents and Settings\All Users\Application Data\NOS
2008-08-07 10:06 . 2007-01-05 22:51 23,208 --a------ C:\WINDOWS\system32\drivers\grmn0200.sys
2008-08-07 10:06 . 2007-01-05 22:51 17,448 --a------ C:\WINDOWS\system32\drivers\grmn1200.sys
2008-08-07 09:12 . 2008-08-07 12:02 <REP> d-------- C:\Garmin
2008-07-28 10:50 . 2008-07-28 10:50 <REP> d-------- C:\Documents and Settings\Administrateur.MAISON\Application Data\Ulead Systems
2008-07-28 10:49 . 2008-07-28 10:49 <REP> d-------- C:\Documents and Settings\Administrateur.MAISON\Application Data\Logitech
2008-07-28 10:49 . 2008-07-28 10:49 <REP> d-------- C:\Documents and Settings\Administrateur.MAISON\Application Data\Intel
2008-07-28 10:49 . 2008-07-28 10:49 <REP> d-------- C:\Documents and Settings\Administrateur.MAISON\Application Data\BitDefender
2008-07-28 10:48 . 2008-03-29 12:55 <REP> d--h----- C:\Documents and Settings\Administrateur.MAISON\Voisinage r‚seau
2008-07-28 10:48 . 2008-03-29 12:55 <REP> d--h----- C:\Documents and Settings\Administrateur.MAISON\Voisinage d'impression
2008-07-28 10:48 . 2008-03-29 12:06 <REP> d--h----- C:\Documents and Settings\Administrateur.MAISON\ModŠles
2008-07-28 10:48 . 2008-07-29 16:14 <REP> dr------- C:\Documents and Settings\Administrateur.MAISON\Mes documents
2008-07-28 10:48 . 2008-03-29 12:55 <REP> dr------- C:\Documents and Settings\Administrateur.MAISON\Menu D‚marrer
2008-07-28 10:48 . 2008-07-28 10:49 <REP> dr------- C:\Documents and Settings\Administrateur.MAISON\Favoris
2008-07-28 10:48 . 2008-03-29 12:55 <REP> d-------- C:\Documents and Settings\Administrateur.MAISON\Bureau
2008-07-28 10:48 . 2008-07-28 10:48 <REP> d-------- C:\Documents and Settings\Administrateur.MAISON
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-27 17:15 --------- d-----w C:\Program Files\Fichiers communs\Real
2008-08-24 15:22 --------- d-----w C:\Program Files\VaudTax2007
2008-08-24 14:21 --------- d-----w C:\Program Files\Windows Live
2008-08-17 08:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-08-16 08:05 40,072 ----a-w C:\Documents and Settings\Kojak\Application Data\GDIPFONTCACHEV1.DAT
2008-08-16 01:30 196,608 ----a-w C:\WINDOWS\system32\drivers\nStandard.bin
2008-08-07 08:34 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-08-07 07:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-02 12:33 --------- d-----w C:\Program Files\BIZ
2008-07-18 18:39 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
2008-06-18 11:55 36,184 ----a-w C:\Documents and Settings\Kojak\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((( snapshot@2008-08-27_20.07.52.31 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-08-27 18:03:03 81,984 ----a-w C:\WINDOWS\system32\bdod.bin
+ 2008-08-27 18:57:32 81,984 ----a-w C:\WINDOWS\system32\bdod.bin
+ 2008-08-27 18:59:07 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_10c.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS SmartDoctor"="C:\Program Files\ASUS\SmartDoctor\SmartDoctor.exe" [2007-05-22 16:21 1114112]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-03-29 14:57 68856]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 04:33 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DiskeeperSystray"="C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" [2006-02-24 20:29 196709]
"ipTray.exe"="C:\Program Files\Intel\IDU\iptray.exe" [2006-12-28 19:07 2242328]
"BDAgent"="C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe" [2008-06-25 19:30 368640]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-05-11 00:03 8429568]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-05-11 00:03 81920]
"UVS11 Preload"="C:\Program Files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe" [2007-07-23 13:55 341232]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 15:57 282624]
"ISUSPM"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" [2006-03-20 17:34 213936]
"Corel File Shell Monitor"="C:\Program Files\Corel\Corel MediaOne\CorelIOMonitor.exe" [2007-12-01 17:38 38400]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 02:38 34672]
"atchk"="C:\Program Files\Intel\AMT\atchk.exe" [2007-06-28 06:18 404248]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2006-03-28 18:38 94208 C:\WINDOWS\KHALMNPR.Exe]
"nwiz"="nwiz.exe" [2007-05-11 00:03 1626112 C:\WINDOWS\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2007-06-28 06:17 16132608 C:\WINDOWS\RTHDCPL.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.asv2"= asusasv2.dll
"msacm.dvacm"= C:\PROGRA~1\FICHIE~1\ULEADS~1\Vio\Dvacm.acm
"msacm.MPEGacm"= C:\PROGRA~1\FICHIE~1\ULEADS~1\MPEG\MPEGacm.acm
"msacm.ulmp3acm"= C:\PROGRA~1\FICHIE~1\ULEADS~1\MPEG\ulmp3acm.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Macromedia\\Dreamweaver MX\\Dreamweaver.exe"=
"C:\\Program Files\\InterVideo\\DVD8\\WinDVD.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R2 atchksrv;Intel(R) Active Management Technology System Status Service;C:\Program Files\Intel\AMT\atchksrv.exe [2007-06-28 06:18]
R2 LMS;Intel(R) Active Management Technology Local Management Service;C:\Program Files\Intel\AMT\LMS.exe [2007-06-28 06:18]
R2 NwSapAgent;Agent SAP;C:\WINDOWS\system32\svchost.exe [2008-04-14 04:34]
R2 osaio;osaio;C:\WINDOWS\system32\drivers\osaio.sys [2008-03-29 12:56]
R2 UNS;Intel(R) Active Management Technology User Notification Service;C:\Program Files\Intel\AMT\UNS.exe [2007-06-28 06:18]
R3 asusgsb;ASUS Virtual Video Capture Device Driver;C:\WINDOWS\system32\drivers\asusgsb.sys [2007-05-31 14:29]
R3 ASUSVRC;ASUSTeK Virtual Capture Device;C:\WINDOWS\system32\DRIVERS\AsusVRC.sys [2007-01-29 17:12]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\WINDOWS\system32\DRIVERS\bdfndisf.sys [2008-06-25 19:30]
R3 Video3D;ASUS Video3D Service;C:\WINDOWS\system32\Drivers\Video3D32.sys [2007-05-31 14:29]
S3 getPlus(R) Helper;getPlus(R) Helper;C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2008-06-26 10:24]
S3 grmn0200;grmn0200.Sys Garmin USB DCP driver (install);C:\WINDOWS\system32\Drivers\grmn0200.sys [2007-01-05 22:51]
S3 grmn1200;grmn0200.Sys Garmin USB DCP driver;C:\WINDOWS\system32\Drivers\grmn1200.sys [2007-01-05 22:51]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4816a02e-00e4-11dd-8cf4-0019d1a3924a}]
\Shell\AutoRun\command - ie.exe
\Shell\explore\Command - ie.exe
\Shell\open\Command - ie.exe
.
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.forwardhc.ch/
O8 -: Crawler Search - tbr:iemenu
O8 -: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O18 -: Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-27 20:59:07
Windows 5.1.2600 Service Pack 3 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\bdfsfltr]
"ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\bdfsfltr]
"ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\ATKKBService.exe
C:\Program Files\Intel\IDU\awServ.exe
C:\Program Files\Fichiers communs\InterVideo\DeviceService\DevSvc.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Fichiers communs\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Fichiers communs\Logitech\KhalShared\KHALMNPR.exe
C:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-08-27 21:03:08 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-27 19:03:02
ComboFix2.txt 2008-08-27 18:08:16
Pre-Run: 304,094,072,832 octets libres
Post-Run: 304,074,346,496 octets libres
187 --- E O F --- 2008-08-13 09:14:42
Pour le rapport Malware voilà, mais fait après plusieurs correction
Malwarebytes' Anti-Malware 1.25
Version de la base de données: 1082
Windows 5.1.2600 Service Pack 3
23:25:29 26.08.2008
mbam-log-08-26-2008 (23-25-29).txt
Type de recherche: Examen rapide
Eléments examinés: 1
Temps écoulé: 2 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
(Aucun élément nuisible détecté)
Pour BitDefender voilà :
Je n'ai plus rien.
Merci pour ton aide. A plus.