Merci de votre aide voici le raport de combofix
ComboFix 08-08-30.03 - CHILL 2008-08-31 13:20:06.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.561 [GMT 2:00]
Endroit: C:\Documents and Settings\CHILL\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\CHILL\Application Data\Adssite Advanced Toolbar
C:\Documents and Settings\CHILL\Application Data\Adssite Advanced Toolbar\selected.xml
C:\Program Files\Adssite Advanced Toolbar
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TDSSSERV
-------\Service_TDSSserv
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-07-28 to 2008-08-31 ))))))))))))))))))))))))))))))))))))
.
2008-08-31 12:10 . 2008-08-31 12:10 <REP> d-------- C:\Documents and Settings\CHILL\Application Data\Malwarebytes
2008-08-31 12:10 . 2008-08-17 15:01 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-08-31 12:09 . 2008-08-31 12:10 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-31 12:09 . 2008-08-31 12:09 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-31 12:09 . 2008-08-17 15:01 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-31 11:59 . 2008-08-31 11:59 <REP> d-------- C:\Program Files\Trend Micro
2008-08-31 01:09 . 2008-08-31 01:15 <REP> d-------- C:\Lop SD
2008-08-24 18:21 . 2008-08-24 18:21 <REP> d-------- C:\WINDOWS\system32\fr
2008-08-24 18:21 . 2008-08-24 18:21 <REP> d-------- C:\WINDOWS\system32\bits
2008-08-24 18:21 . 2008-08-24 18:21 <REP> d-------- C:\WINDOWS\l2schemas
2008-08-24 18:18 . 2008-08-24 18:21 <REP> d-------- C:\WINDOWS\ServicePackFiles
2008-08-24 18:10 . 2008-08-24 18:10 <REP> d-------- C:\WINDOWS\EHome
2008-08-23 21:18 . 2004-08-03 22:29 25,471 --------- C:\WINDOWS\system32\drivers\watv10nt.sys
2008-08-23 21:18 . 2004-08-03 22:29 22,271 --------- C:\WINDOWS\system32\drivers\watv06nt.sys
2008-08-23 21:18 . 2004-08-03 22:29 11,935 --------- C:\WINDOWS\system32\drivers\wadv11nt.sys
2008-08-23 21:18 . 2004-08-03 22:29 11,871 --------- C:\WINDOWS\system32\drivers\wadv09nt.sys
2008-08-23 21:18 . 2004-08-03 22:29 11,807 --------- C:\WINDOWS\system32\drivers\wadv07nt.sys
2008-08-23 21:18 . 2004-08-03 22:29 11,295 --------- C:\WINDOWS\system32\drivers\wadv08nt.sys
2008-08-23 21:16 . 2004-08-04 00:38 701,440 --------- C:\WINDOWS\system32\drivers\ati2mtag.sys
2008-08-22 18:57 . 2008-08-22 18:57 <REP> d-------- C:\Program Files\Western Digital Technologies
2008-08-16 23:44 . 2008-08-16 23:45 <REP> d-------- C:\Program Files\HomePlayer
2008-08-15 02:56 . 2008-05-01 16:36 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-15 02:55 . 2008-04-11 21:05 691,712 --------- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-08-13 20:16 . 2008-08-13 20:16 <REP> d-------- C:\Program Files\PowerQuest
2008-07-22 13:28 . 2008-08-26 22:49 <REP> d-------- C:\Documents and Settings\CHILL\.homeplayer
2008-07-16 08:50 . 2008-07-16 08:51 <REP> d-------- C:\Documents and Settings\CHILL\Application Data\U3
2008-07-09 00:14 . 2008-04-13 20:46 37,888 --a------ C:\WINDOWS\system32\drivers\bthmodem.sys
2008-07-09 00:14 . 2008-04-14 03:59 25,856 --a------ C:\WINDOWS\system32\drivers\hidbth.sys
2008-07-09 00:11 . 2008-04-14 04:34 153,088 --a------ C:\WINDOWS\system32\irftp.exe
2008-07-09 00:11 . 2008-04-13 20:51 101,120 --a------ C:\WINDOWS\system32\drivers\bthpan.sys
2008-07-09 00:11 . 2008-04-13 20:46 59,136 --a------ C:\WINDOWS\system32\drivers\rfcomm.sys
2008-07-09 00:11 . 2008-04-14 04:33 29,184 --a------ C:\WINDOWS\system32\irmon.dll
2008-07-09 00:11 . 2008-04-13 20:46 18,944 --a------ C:\WINDOWS\system32\drivers\bthusb.sys
2008-07-09 00:11 . 2008-04-13 20:46 17,024 --a------ C:\WINDOWS\system32\drivers\bthenum.sys
2008-07-09 00:11 . 2008-04-14 04:33 8,192 --a------ C:\WINDOWS\system32\wshirda.dll
2008-07-07 22:28 . 2008-07-07 22:28 253,952 --------- C:\WINDOWS\system32\dllcache\es.dll
2008-07-02 15:46 . 1999-01-20 05:01 210,032 --a------ C:\WINDOWS\system32\DBCLIENT.DLL
2008-07-02 15:46 . 1999-11-12 05:11 183,808 --a------ C:\WINDOWS\system32\BDEADMIN.CPL
2008-07-02 15:45 . 2008-07-02 15:45 <REP> d-------- C:\Program Files\Fichiers communs\Borland Shared
2008-07-02 15:45 . 2005-01-10 17:42 361,472 --a------ C:\WINDOWS\system32\wPDF200A.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-30 22:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-22 16:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-08-13 18:19 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-12 10:01 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-08-11 20:34 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-08-07 08:48 --------- d-----w C:\Documents and Settings\CHILL\Application Data\Canon
2008-07-10 13:56 --------- d-----w C:\Program Files\adslTV
2008-07-04 11:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\CanonIJPLM
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 04:33 15360]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
"ccleaner"="C:\program files sam\CCleaner\ccleaner.exe" [2007-09-10 16:03 701680]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 14:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 14:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 14:00 455168]
"ACTIVBOARD"="c:\apps\ABoard\ABoard.exe" [2003-05-02 11:31 24576]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-11 21:43 7630848]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-11 21:43 86016]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-09-15 22:27 180269]
"ZSSnp211"="C:\WINDOWS\ZSSnp211.exe" [2006-08-19 05:37 49152]
"Domino"="C:\WINDOWS\Domino.exe" [2006-08-18 10:58 49152]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"CanonSolutionMenu"="C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-04-03 18:00 644696]
"CanonMyPrinter"="C:\Program Files\Canon\MyPrinter\BJMyPrt.exe" [2007-04-03 18:50 1603152]
"SSBkgdUpdate"="C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 09:03 210472]
"OpwareSE4"="C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe" [2007-02-04 12:02 79400]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"Ad-Watch"="C:\program files sam\ad-award\Ad-Watch2007.exe" [2007-06-13 15:18 4177920]
"Raccourci vers la page des propriétés de High Definition Audio"="HDAudPropShortcut.exe" [2004-03-17 15:10 61952 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
"SoundMan"="SOUNDMAN.EXE" [2004-09-10 18:29 77824 C:\WINDOWS\SoundMan.exe]
"AlcWzrd"="ALCWZRD.EXE" [2004-09-15 11:20 2557952 C:\WINDOWS\ALCWZRD.EXE]
"nwiz"="nwiz.exe" [2006-08-11 21:43 1519616 C:\WINDOWS\system32\nwiz.exe]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 04:34 110592 C:\WINDOWS\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 04:33 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.yv12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll
[HKLM\~\startupfolder\C:^Documents and Settings^CHILL^Menu Démarrer^Programmes^Démarrage^ubisoft register.lnk]
path=C:\Documents and Settings\CHILL\Menu Démarrer\Programmes\Démarrage\ubisoft register.lnk
backup=C:\WINDOWS\pss\ubisoft register.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\APPS\\Inventime\\my.exe"=
"C:\\program files sam\\eMule\\emule.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\adslTV\\adsltv.exe"=
"C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"C:\\APPS\\skype\\phone\\Skype.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\HomePlayer\\HomePlayer.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 16:35]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 16:37]
R2 IJPLMSVC;PIXMA Extended Survey Program;C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [2007-04-13 09:20]
R3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2005-04-14 09:59]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 20:45]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 20:45]
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
2008-07-26 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-Magentic - C:\PROGRA~1\Magentic\bin\Magentic.exe
HKLM-Run-NWEReboot - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\CHILL\Application Data\Mozilla\Firefox\Profiles\1fy15e9n.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://fr.yahoo.com/
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-08-31 13:24:23
Windows 5.1.2600 Service Pack 3 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
C:\WINDOWS\system32\wbem\Logs\wbemess.log 24576 bytes
C:\WINDOWS\system32\wbem\Logs\wmiprov.log 67 bytes
Scan termin‚ avec succŠs
Les fichiers cach‚s: 2
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MysqlInventime]
"ImagePath"="C:\Apps\INVENT~1\mysql\bin\mysqld-nt --defaults-file=C:\Apps\Inventime\mysql\my.ini MysqlInventime"
.
--------------------- DLLs a charg‚ sous des processus courants ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\WINDOWS\system32\nview.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\program files sam\ad-award\aawservice.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\APPS\ABOARD\AOSD.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-08-31 13:28:20 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-31 11:28:15
Pre-Run: 34,572,435,456 octets libres
Post-Run: 34,503,917,568 octets libres
196 --- E O F --- 2008-08-25 18:01:12