Voici le rapport :
ComboFix 08-09-27.05 - guillaume 2008-09-28 21:17:18.1 - [color=red][b]FAT32/b/colorx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.646 [GMT 2:00]
Lancé depuis: C:\Documents and Settings\guillaume\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WA6P
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_FOPN
-------\Service_NPF
((((((((((((((((((((((((((((( Fichiers créés du 2008-08-28 au 2008-09-28 ))))))))))))))))))))))))))))))))))))
.
2008-09-28 20:04 . 2008-09-28 20:04 <REP> d-------- C:\Documents and Settings\guillaume\Application Data\Malwarebytes
2008-09-28 20:04 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-28 20:03 . 2008-09-28 20:03 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-28 20:03 . 2008-09-28 20:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-28 20:03 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-28 19:00 . 2008-09-28 19:00 <REP> d-------- C:\VundoFix Backups
2008-09-28 18:55 . 2008-09-28 18:55 <REP> d-------- C:\Program Files\Trend Micro
2008-09-28 18:34 . 2008-09-28 18:33 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-09-28 18:33 . 2008-09-28 18:33 <REP> d-------- C:\Documents and Settings\guillaume\.housecall6.6
2008-09-28 00:45 . 2008-09-28 00:45 91 --a------ C:\WINDOWS\wininit.ini
2008-09-27 15:14 . 2008-09-27 15:14 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-09-27 15:14 . 2008-09-27 15:14 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-09-27 15:02 . 2008-09-27 15:02 <REP> d-------- C:\Program Files\Spyware Doctor
2008-09-27 15:02 . 2008-09-27 15:02 <REP> d-------- C:\Documents and Settings\guillaume\Application Data\PC Tools
2008-09-27 15:02 . 2008-09-27 15:02 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-27 15:02 . 2008-08-25 11:36 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-09-27 15:02 . 2008-08-25 11:36 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-09-27 15:02 . 2008-08-25 11:36 40,840 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-09-27 15:02 . 2008-06-02 15:19 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-09-26 21:05 . 2008-09-26 21:05 <REP> d-------- C:\WINDOWS\AU_Temp
2008-09-25 22:18 . 2008-09-25 22:18 <REP> d-------- C:\WINDOWS\McAfee.com
2008-09-25 22:12 . 2008-09-25 22:12 <REP> d-------- C:\Program Files\Panda Security
2008-09-25 22:12 . 2008-06-19 17:24 28,544 --a------ C:\WINDOWS\system32\drivers\pavboot.sys
2008-09-25 22:01 . 2007-11-12 13:24 39,376,181 --a------ C:\WINDOWS\LPT$VPN.821
2008-09-19 22:32 . 2008-09-19 22:32 <REP> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-09-11 22:42 . 2008-09-11 22:42 <REP> d-------- C:\Program Files\ffrmooe
2008-09-11 22:42 . 2008-09-11 22:42 <REP> d-------- C:\Documents and Settings\All Users\Application Data\mfelglah
2008-09-11 22:42 . 2008-09-11 22:42 <REP> d-------- C:\Documents and Settings\All Users\Application Data\gpqhqngv
2008-09-11 22:42 . 2008-09-11 22:42 <REP> d-------- C:\Documents and Settings\All Users\Application Data\eluxwpyd
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-22 16:49 94,208 ----a-w C:\WINDOWS\DUMP8963.tmp
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-07 20:31 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:31 253,952 ----a-w C:\WINDOWS\system32\dllcache\es.dll
2008-06-05 20:58 56,320 ----a-w C:\Documents and Settings\bob\Application Data\GDIPFONTCACHEV1.DAT
2007-12-17 16:12 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-10-21 12:55 56,320 ----a-w C:\Documents and Settings\guillaume\Application Data\GDIPFONTCACHEV1.DAT
2007-03-25 19:07 87,608 ----a-w C:\Documents and Settings\guillaume\Application Data\ezpinst.exe
2007-03-25 19:07 47,360 ----a-w C:\Documents and Settings\guillaume\Application Data\pcouffin.sys
2006-03-26 16:16 10,704,584 ----a-w C:\Program Files\setupfre.exe
2005-07-07 08:17 22,606,384 ----a-w C:\Program Files\AdbeRdr70_fra_full.exe
2005-07-07 08:16 7,043,504 ----a-w C:\Program Files\psa2011se_fre.exe
2005-07-07 08:15 494,704 ----a-w C:\Program Files\ytb01_efgsip.exe
2005-06-15 17:25 12,674,592 ----a-w C:\Program Files\RealPlayer10-5GOLD_fr.exe
2005-06-08 09:29 7,561,382 ----a-w C:\Program Files\PDFCreator-0_8_0_GNUGhostscript.exe
2005-06-01 14:08 15,814,200 ----a-w C:\Program Files\jre-1_5_0_01-windows-i586-p.exe
2005-05-14 11:45 2,562,585 ----a-w C:\Documents and Settings\sonia\foxmail.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"AdobeUpdater"="C:\Program Files\Fichiers communs\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 2321600]
"TomTomHOME.exe"="C:\Program Files\TomTom HOME 2\HOMERunner.exe" [2008-02-18 206184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LaunchApp"="Alaunch" [X]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-02-07 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-02-07 126976]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-07 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-07 688218]
"PCMService"="C:\Program Files\Arcade\PCMService.exe" [2005-03-09 49152]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 59392]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-02-08 339968]
"EPM-DM"="c:\acer\epm\epm-dm.exe" [2005-03-28 188416]
"ePowerManagement"="C:\Acer\ePM\ePM.exe" [2005-03-24 2880512]
"LManager"="C:\Program Files\Launch Manager\QtZgAcer.EXE" [2005-03-28 319488]
"eRecoveryService"="C:\Windows\System32\Check.exe" [2005-03-23 245760]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 83608]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2005-06-15 180269]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2004-09-13 49152]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-22 63712]
"LogitechCommunicationsManager"="C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe" [2007-02-08 488984]
"LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" [2007-02-08 774168]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-05 C:\WINDOWS\system32\bthprops.cpl]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 15360]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-28 443968]
C:\Documents and Settings\bob\Menu D‚marrer\Programmes\D‚marrage\
Palm Registration.lnk - C:\Program Files\Palm\register.exe [2005-08-08 2494464]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.GEOX"= C:\WINDOWS\system32\GeoCodec.dll
"vidc.GEOV"= C:\WINDOWS\system32\GeoCodec.dll
"vidc.GMP4"= C:\WINDOWS\system32\GXAMP4.dll
"vidc.GM40"= C:\WINDOWS\system32\GXAMP4.dll
"msacm.geoadpcm"= C:\WINDOWS\system32\GeoADPCM.acm
"vidc.G264"= C:\WINDOWS\system32\GX264.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Spooler"=2 (0x2)
"helpsvc"=2 (0x2)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\MSMSGS.EXE"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"C:\\Program Files\\Real\\RealPlayer\\RealPlay.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Telefonica\\AsistCfg69\\awcbrwsr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\SopCast\\SopCast.exe"=
"C:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
"C:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 pavboot;pavboot;C:\WINDOWS\system32\drivers\pavboot.sys [2008-06-19 28544]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 EpmPsd;Acer EPM Power Scheme Driver;C:\WINDOWS\system32\drivers\epm-psd.sys [2004-07-19 4096]
R2 EpmShd;Acer EPM System Hardware Driver;C:\WINDOWS\system32\drivers\epm-shd.sys [2005-03-24 78208]
R3 int15.sys;int15.sys;C:\Program Files\acer\eRecovery\int15.sys [2005-01-13 69632]
.
Contenu du dossier 'Tâches planifiées'
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-HlpApi - C:\WINDOWS\system32\itezivcd.exe
.
------- Examen supplémentaire -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.fr/
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://global.acer.com/
R1 -: HKCU-SearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
O8 -: &Traduire à partir de l'anglais - c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 -: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 -: Pages liées - c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 -: Pages similaires - c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 -: Recherche &Google - c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 -: Télécharger avec &BitSpirit - C:\Program Files\BitSpirit\bsurl.htm
O8 -: Version de la page actuelle disponible dans le cache Google - c:\program files\google\GoogleToolbar1.dll/cmcache.html
O17 -: HKLM\CCS\Interface\{ADFFEC35-5FD5-434B-A227-62A97EFB64C3}: NameServer = 80.58.61.250,80.58.61.254
O16 -: {ADACAA8F-3595-47FE-9C31-9C7471B9BEC7} - hxxp://91.142.211.173/cab/OCXChecker_8000.cab
C:\WINDOWS\Downloaded Program Files\OCXDownloadChecker.inf
C:\WINDOWS\Downloaded Program Files\OCXDownloadChecker_8000.ocx
O16 -: {DBAFE6AD-DC14-45DF-A3F7-F8832289A1CD} - hxxp://91.142.211.173/cab/DownloadFile_8110.cab
C:\WINDOWS\Downloaded Program Files\Download.inf
C:\WINDOWS\Downloaded Program Files\Download_8110.ocx
O16 -: {F5D98C43-DB16-11CF-8ECA-0000C0FD59C7} - hxxp://gestiona.madrid.org/pipa_pub/ocx/acgm.cab
C:\WINDOWS\Downloaded Program Files\acgm.inf
C:\WINDOWS\system32\msvcrt.dll
C:\WINDOWS\system32\snbdpl1.dll
C:\WINDOWS\system32\snbd10dm.dll
C:\WINDOWS\system32\igsnrn22.dll
C:\WINDOWS\system32\igsnpb22.dll
C:\WINDOWS\system32\igsnol22.dll
C:\WINDOWS\system32\igsncm22.dll
C:\WINDOWS\system32\browser.exa
C:\WINDOWS\system32\Acgm.Dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-28 21:25:34
Windows 5.1.2600 Service Pack 2 FAT NTAPI
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\EVTENG.EXE
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\S24EVMON.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWUPDSV.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
C:\PROGRAM FILES\FICHIERS COMMUNS\LOGISHRD\LVMVFM\LVPRCSRV.EXE
C:\PROGRAM FILES\INTEL\WIRELESS\BIN\REGSRVC.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHMAISV.EXE
C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHWEBSV.EXE
C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
C:\Program Files\acer\eRecovery\Monitor.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\LVComSX.exe
C:\PROGRAM FILES\PALM\HOTSYNC.EXE
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
.
**************************************************************************
.
Heure de fin: 2008-09-28 21:29:25 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-09-28 19:29:22
Avant-CF: 8ÿ712ÿ781ÿ824 octets libres
Après-CF: 9,498,525,696 octets libres
226 --- E O F --- 2008-09-10 21:01:47