voilà le rapport combofix :
ComboFix 08-09-10.04 - Client 2008-09-12 8:30:27.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1019 [GMT 1:00]
Endroit: E:\documentations\informatique décisionnelle\ComboFix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\dao350.dll
.
((((((((((((((((((((((((((((( Fichiers créés 2008-08-12 to 2008-09-12 ))))))))))))))))))))))))))))))))))))
.
2008-09-12 07:37 . 2008-09-12 07:44 12,288 --a------ C:\Documents and Settings\Client\spydb.dat
2008-09-12 00:01 . 2008-09-12 00:01 <REP> d-------- C:\SpySoapBin
2008-09-11 22:13 . 2008-09-11 22:13 <REP> d-------- C:\Documents and Settings\Client\Application Data\SUPERAntiSpyware.com
2008-09-11 22:13 . 2008-09-11 22:13 <REP> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-09-11 22:12 . 2008-09-11 22:12 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-09-11 05:33 . 2008-09-12 08:25 <REP> d--h----- C:\$AVG8.VAULT$
2008-09-11 05:17 . 2008-09-11 05:23 <REP> d-------- C:\Documents and Settings\Client\.smplayer
2008-09-11 05:09 . 2008-09-11 05:09 <REP> d--hs---- C:\WINDOWS\ftpcache
2008-09-11 02:07 . 2008-09-12 02:44 <REP> d-------- C:\WINDOWS\system32\drivers\Avg
2008-09-11 02:07 . 2008-09-11 05:50 97,928 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-09-11 02:07 . 2008-09-11 05:50 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
2008-09-11 02:07 . 2008-09-11 05:50 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-09-11 00:57 . 2008-09-11 01:54 <REP> d-------- C:\Documents and Settings\Client\Application Data\AVGTOOLBAR
2008-09-11 00:57 . 2008-09-11 02:06 <REP> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-09-10 23:27 . 2008-09-10 23:27 173 --a------ C:\curr_ver.tmp
2008-09-09 00:06 . 2008-09-09 00:06 3,932,214 --a------ C:\WINDOWS\BricoPack Wallpaper.bmp
2008-09-09 00:06 . 2008-09-09 00:06 52,191 --a------ C:\WINDOWS\BricoPackUninst.cmd
2008-09-08 23:51 . 2008-09-09 00:06 4,835 --a------ C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-09-08 23:49 . 2008-09-08 23:49 <REP> d-------- C:\WINDOWS\BricoPacks
2008-09-08 22:49 . 2007-08-22 07:55 2,759,438 --a------ C:\WINDOWS\Sim AQUARIUM 2.scr
2008-09-08 18:48 . 2008-09-12 07:37 <REP> d-------- C:\Documents and Settings\Client\Application Data\IDM
2008-09-08 18:48 . 2008-09-12 08:33 <REP> d-------- C:\Documents and Settings\Client\Application Data\DMCache
2008-09-07 03:38 . 2008-09-07 03:38 <REP> d-------- C:\Documents and Settings\Client\Application Data\3M
2008-09-07 03:18 . 2008-09-07 03:36 <REP> d-------- C:\Documents and Settings\Client\Application Data\GetRightToGo
2008-09-06 04:15 . 2008-09-06 04:15 <REP> d-------- C:\Documents and Settings\Client\Application Data\Apple Computer
2008-09-04 22:53 . 2008-09-04 22:53 <REP> d-------- C:\Documents and Settings\Client\Application Data\Malwarebytes
2008-09-04 22:53 . 2008-09-04 22:53 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-04 22:53 . 2008-09-02 00:16 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-04 22:53 . 2008-09-02 00:16 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-01 13:56 . 2008-07-09 15:34 206,256 --a------ C:\WINDOWS\system32\idmmbc.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-12 07:33 75,362,336 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-09-12 04:51 878,636 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-09-12 01:54 --------- d-----w C:\Documents and Settings\Client\Application Data\Skype
2008-09-12 00:26 --------- d-----w C:\Documents and Settings\Client\Application Data\skypePM
2008-09-11 12:16 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-09-11 05:55 --------- d-----w C:\Documents and Settings\Client\Application Data\Free Download Manager
2008-09-08 23:06 219,648 ----a-w C:\WINDOWS\system32\uxtheme.dll
2008-09-07 19:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-07 04:18 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-09-06 07:00 444,928 ----a-w C:\WINDOWS\Internet Logs\xDB6.tmp
2008-08-28 16:40 198,656 ----a-w C:\WINDOWS\Internet Logs\xDB5.tmp
2008-08-24 14:18 124,416 ----a-w C:\WINDOWS\Internet Logs\xDB4.tmp
2008-08-23 03:07 197,632 ----a-w C:\WINDOWS\Internet Logs\xDB3.tmp
2008-08-18 03:23 828,416 ----a-w C:\WINDOWS\Internet Logs\xDB1.tmp
2008-08-18 03:23 1,422,848 ----a-w C:\WINDOWS\Internet Logs\xDB2.tmp
2008-07-30 01:51 --------- d-----w C:\Program Files\EsetOnlineScanner
2008-07-29 16:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-07-21 17:46 201,728 ----a-w C:\WINDOWS\system32\Les Simpson - Le film.scr
2008-07-16 08:47 --------- d-----w C:\Documents and Settings\Client\Application Data\dvdcss
2008-07-09 08:05 75,248 ----a-w C:\WINDOWS\zllsputility.exe
2008-07-09 08:05 54,672 ----a-w C:\WINDOWS\system32\vsutil_loc040c.dll
2008-07-09 08:05 42,384 ----a-w C:\WINDOWS\zllsputility_loc040c.dll
2008-07-09 08:05 21,904 ----a-w C:\WINDOWS\system32\imsinstall_loc040c.dll
2008-07-09 08:05 17,808 ----a-w C:\WINDOWS\system32\imslsp_install_loc040c.dll
2008-07-09 08:05 1,086,952 ----a-w C:\WINDOWS\system32\zpeng24.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 15360]
"L08FXLRD_2306265"="C:\Program Files\Microsoft Etudes\Microsoft Encarta 2008 - Études DVD\EDICT.EXE" [2007-06-12 351000]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-08-04 1667584]
"SpybotSD TeaTimer"="D:\Mes Programmes\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]
"IDMan"="D:\Mes Programmes\Internet Download Manager\IDMan.exe" [2008-09-01 2610608]
"AdobeUpdater"="C:\Program Files\Fichiers communs\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 2321600]
"SUPERAntiSpyware"="D:\Mes Programmes\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-09-03 1576176]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiSRaid"="C:\Program Files\Silicon Integrated Systems\SiSRaidPackage\SRaid.exe" [2005-05-18 905216]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe" [2002-07-10 188416]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_12\bin\jusched.exe" [2007-05-02 75520]
"FixCamera"="C:\WINDOWS\FixCamera.exe" [2007-07-11 20480]
"tsnpstd3"="C:\WINDOWS\tsnpstd3.exe" [2007-04-21 270336]
"snpstd3"="C:\WINDOWS\vsnpstd3.exe" [2007-05-10 835584]
"ZoneAlarm Client"="D:\Mes Programmes\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 919016]
"AVG8_TRAY"="D:\MESPRO~1\AVG\AVG8\avgtray.exe" [2008-09-11 1235736]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SpySoap_tray"="D:\Mes Programmes\SpySoap\tray.exe" [2008-04-16 425984]
"SpySoap_schedules"="D:\Mes Programmes\SpySoap\schedules.exe" [2008-04-16 64512]
"SiSPower"="SiSPower.dll" [2005-08-25 C:\WINDOWS\system32\SiSPower.dll]
"SoundMan"="SOUNDMAN.EXE" [2005-06-20 C:\WINDOWS\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 15360]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Utility Tray.lnk - C:\WINDOWS\system32\sistray.exe [2008-06-02 262144]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "D:\Mes Programmes\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-07-23 16:28 352256 D:\Mes Programmes\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"vidc.DIV3"= DIVXc32.dll
"vidc.DIV4"= DIVXc32f.dll
"msacm.divxa32"= DivXa32.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"D:\\Mes Programmes\\AVG\\AVG8\\avgupd.exe"=
"D:\\Mes Programmes\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-09-11 97928]
R2 avg8emc;AVG8 E-mail Scanner;D:\MESPRO~1\AVG\AVG8\avgemc.exe [2008-09-11 875288]
R2 avg8wd;AVG8 WatchDog;D:\MESPRO~1\AVG\AVG8\avgwdsvc.exe [2008-09-11 231704]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-09-11 76040]
R2 SpySoapSysGuardService;System Guard(SpySoap);D:\Mes Programmes\SpySoap\SysGuard.exe [2008-04-16 186368]
R3 SpySoapSysGuardDriver;SpySoapSysGuardDriver;D:\Mes Programmes\SpySoap\sysGuard.sys [2008-04-16 13824]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1b725225-3096-11dd-9a99-0019216f0368}]
\Shell\AutoRun\command - wscript.exe .\.vbs
\Shell\open\command - wscript.exe .\.vbs
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
.
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Client\Application Data\Mozilla\Firefox\Profiles\a1acxl8q.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.com/
FF -: plugin - C:\Program Files\Java\jre1.5.0_12\bin\NPJava11.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_12\bin\NPJava12.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_12\bin\NPJava13.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_12\bin\NPJava14.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_12\bin\NPJava32.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_12\bin\NPJPI150_12.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_12\bin\NPOJI610.dll
FF -: plugin - D:\Mes Programmes\Opera\program\plugins\NP_IDM1.dll
FF -: plugin - D:\Mes Programmes\Opera\program\plugins\NP_IDM2.dll
FF -: plugin - D:\Mes Programmes\Opera\program\plugins\NP_IDM3.dll
FF -: plugin - D:\Mes Programmes\Opera\program\plugins\NP_IDM4.dll
FF -: plugin - D:\Mes Programmes\Opera\program\plugins\NP_IDM5.dll
FF -: plugin - D:\Mes Programmes\Opera\program\plugins\NP_IDM6.dll
FF -: plugin - D:\Mes Programmes\Opera\program\plugins\npdsplay.dll
FF -: plugin - D:\Mes Programmes\Opera\program\plugins\npfdm.dll
FF -: plugin - D:\Mes Programmes\Opera\program\plugins\npwmsdrm.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-12 08:33:36
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MySQL]
"ImagePath"="\"D:\Mes Programmes\MySQL\MySQL Server 5.0\bin\mysqld-nt\" --defaults-file=\"D:\Mes Programmes\MySQL\MySQL Server 5.0\my.ini\" MySQL"
.
Temps d'accomplissement: 2008-09-12 8:37:01
ComboFix-quarantined-files.txt 2008-09-12 07:35:54
Pre-Run: 4,247,281,664 octets libres
Post-Run: 4,284,170,240 octets libres
175 --- E O F --- 2008-08-02 09:29:30