Voici le rapport combofix :
ComboFix 08-10-04.07 - D 2008-10-05 17:28:26.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.661 [GMT 2:00]
Lancé depuis: C:\Documents and Settings\D\Bureau\ComboFix.exe
Commutateurs utilisés :: C:\Documents and Settings\D\Bureau\WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\D\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-05 au 2008-10-05 ))))))))))))))))))))))))))))))))))))
.
2008-10-05 16:54 . 2008-10-05 17:06 <REP> d-------- C:\WINDOWS\LastGood
2008-10-05 16:10 . 2008-10-05 16:10 <REP> d-------- C:\Program Files\CCleaner
2008-10-05 15:02 . 2008-10-05 15:02 <REP> d-------- C:\_OTMoveIt
2008-10-05 14:43 . 2008-10-05 14:43 <REP> d-------- C:\WINDOWS\LastGood.Tmp
2008-10-05 14:41 . 2008-10-05 14:41 <REP> d-------- C:\WINDOWS\system32\fr
2008-10-05 14:41 . 2008-10-05 14:41 <REP> d-------- C:\WINDOWS\system32\bits
2008-10-05 14:41 . 2008-10-05 14:41 <REP> d-------- C:\WINDOWS\l2schemas
2008-10-05 14:39 . 2008-10-05 14:41 <REP> d-------- C:\WINDOWS\ServicePackFiles
2008-10-05 14:34 . 2008-10-05 14:34 <REP> d-------- C:\WINDOWS\EHome
2008-10-05 13:15 . 2008-10-05 13:15 1,956 --a------ C:\Documents and Settings\Orph.egd
2008-10-05 13:13 . 2008-10-05 13:15 <REP> d-------- C:\ToolBar SD
2008-10-05 10:36 . 2008-06-23 18:28 6,066,176 --------- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-10-05 10:36 . 2007-04-17 11:32 2,455,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-10-05 10:36 . 2007-03-08 07:10 1,048,576 --------- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-10-05 10:36 . 2008-06-23 18:28 459,264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-10-05 10:36 . 2008-06-23 18:28 383,488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-10-05 10:36 . 2008-06-23 18:28 267,776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-10-05 10:36 . 2008-06-23 18:28 63,488 --------- C:\WINDOWS\system32\dllcache\icardie.dll
2008-10-05 10:36 . 2008-06-23 18:28 52,224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-10-05 10:36 . 2008-06-23 11:20 13,824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-10-05 10:35 . 2008-10-05 14:41 <REP> d-------- C:\WINDOWS\system32\fr-fr
2008-10-05 10:05 . 2008-10-05 10:05 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-05 10:05 . 2008-10-05 10:05 <REP> d-------- C:\Documents and Settings\D\Application Data\Malwarebytes
2008-10-05 10:05 . 2008-10-05 10:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-05 10:05 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-05 10:05 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-05 02:48 . 2008-10-05 02:48 <REP> d-------- C:\Program Files\Trend Micro
2008-10-05 01:00 . 2008-10-05 16:54 <REP> d-------- C:\Program Files\Fighters
2008-10-05 01:00 . 2008-10-05 01:00 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Fighters
2008-10-05 00:52 . 2008-10-05 00:53 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-10-04 23:49 . 2008-10-04 23:49 <REP> d-------- C:\Program Files\Alwil Software
2008-10-04 23:47 . 2008-10-04 23:47 <REP> d---s---- C:\Documents and Settings\D\UserData
2008-10-04 23:45 . 2008-10-04 23:45 <REP> d-------- C:\Program Files\Sun
2008-10-04 23:44 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-10-04 23:43 . 2008-10-04 23:43 <REP> d-------- C:\Program Files\MSXML 4.0
2008-10-04 20:37 . 2008-10-04 20:37 <REP> d-------- C:\Program Files\Google
2008-10-04 20:35 . 2004-08-04 00:38 327,168 --------- C:\WINDOWS\system32\drivers\ati2mtaa.sys
2008-10-04 20:31 . 2008-10-05 15:02 <REP> d-------- C:\Program Files\EoRezo
2008-10-04 20:31 . 2008-10-05 16:59 <REP> d-------- C:\Documents and Settings\D\Application Data\EoRezo
2008-10-04 20:23 . 2008-04-11 21:05 691,712 --------- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-10-04 20:23 . 2008-05-01 16:36 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll
2008-10-04 20:23 . 2008-07-07 22:28 253,952 --------- C:\WINDOWS\system32\dllcache\es.dll
2008-10-04 20:23 . 2008-05-08 16:02 203,136 --------- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-10-04 20:22 . 2007-08-10 08:18 26,488 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-10-03 13:05 . 2008-06-14 19:33 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-10-03 13:05 . 2008-06-14 19:33 272,768 --------- C:\WINDOWS\system32\dllcache\bthport.sys
2008-10-03 08:00 . 2008-10-03 08:00 <REP> d-------- C:\Program Files\Neuf
2008-10-02 22:30 . 2008-10-02 17:21 <REP> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\You've Got Pictures Screensaver
2008-10-02 22:30 . 2008-10-02 17:16 <REP> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Symantec
2008-10-02 22:30 . 2008-10-02 17:36 <REP> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\AOL
2008-10-02 22:30 . 2004-08-16 17:55 <REP> d--h----- C:\Documents and Settings\D\Voisinage réseau
2008-10-02 22:30 . 2004-08-16 17:55 <REP> d--h----- C:\Documents and Settings\D\Voisinage d'impression
2008-10-02 22:30 . 2004-08-16 17:55 <REP> d--h----- C:\Documents and Settings\D\Modèles
2008-10-02 22:30 . 2008-10-05 10:41 <REP> dr------- C:\Documents and Settings\D\Mes documents
2008-10-02 22:30 . 2004-08-16 17:55 <REP> dr------- C:\Documents and Settings\D\Menu Démarrer
2008-10-02 22:30 . 2008-10-05 10:41 <REP> dr------- C:\Documents and Settings\D\Favoris
2008-10-02 22:30 . 2008-10-05 16:42 <REP> dr------- C:\Documents and Settings\D\Bureau
2008-10-02 22:30 . 2008-10-02 17:21 <REP> d-------- C:\Documents and Settings\D\Application Data\You've Got Pictures Screensaver
2008-10-02 22:30 . 2008-10-02 17:36 <REP> d-------- C:\Documents and Settings\D\Application Data\AOL
2008-10-02 22:30 . 2008-10-05 16:13 <REP> d-------- C:\Documents and Settings\D
2008-10-02 22:25 . 2008-10-02 22:25 8,192 --a------ C:\WINDOWS\REGLOCS.OLD
2008-10-02 22:23 . 2008-10-02 22:23 333 --a------ C:\WINDOWS\system32\$ncsp$.inf
2008-10-02 22:23 . 2008-10-02 22:23 61 --a------ C:\WINDOWS\smscfg.ini
2008-10-02 22:22 . 2008-10-02 22:22 791,289 --a------ C:\WINDOWS\system\RESTORE.INS
2008-10-02 22:22 . 2008-10-02 22:22 791,289 --a------ C:\WINDOWS\RESTORE.INS
2008-10-02 22:19 . 2008-10-02 22:19 <REP> d-------- C:\Program Files\Fichiers communs\Sonic Shared
2008-10-02 17:58 . 2008-10-02 17:58 1,440,054 --a------ C:\snapshot.bmp
2008-10-02 17:23 . 2008-10-02 17:23 <REP> d-------- C:\Documents and Settings\All Users\Application Data\CyberLink
2008-10-02 17:22 . 2008-10-02 17:22 <REP> d-------- C:\Program Files\Fichiers communs\Adobe
2008-10-02 17:22 . 2008-10-02 17:22 <REP> d-------- C:\Program Files\CyberLink
2008-10-02 17:22 . 2008-10-02 17:22 <REP> d-------- C:\Documents and Settings\All Users\Application Data\OD2
2008-10-02 17:22 . 2005-01-28 11:10 1,645,320 --a------ C:\WINDOWS\system32\gdiplus.dll
2008-10-02 17:22 . 2004-08-06 17:22 307,200 -ra------ C:\WINDOWS\system32\FlatBtn6.ocx
2008-10-02 17:22 . 2004-08-06 17:23 132,880 -ra------ C:\WINDOWS\system32\MSINET.OCX
2008-10-02 17:22 . 2004-08-06 17:22 98,304 -ra------ C:\WINDOWS\system32\unzip32.dll
2008-10-02 17:22 . 2005-01-28 11:10 82,432 --a------ C:\WINDOWS\system32\msxml4r.dll
2008-10-02 17:22 . 2005-01-28 11:10 44,544 --a------ C:\WINDOWS\system32\msxml4a.dll
2008-10-02 17:21 . 2008-10-02 17:21 <REP> d-------- C:\Program Files\Viewpoint
2008-10-02 17:21 . 2008-10-02 17:21 <REP> d-------- C:\Program Files\QuickTime
2008-10-02 17:21 . 2008-10-02 17:21 <REP> d-------- C:\Program Files\Learn2.com
2008-10-02 17:21 . 2008-10-02 17:21 <REP> d-------- C:\Program Files\Fichiers communs\Nullsoft
2008-10-02 17:21 . 2008-10-02 17:21 <REP> d-------- C:\Program Files\Fichiers communs\aolshare
2008-10-02 17:21 . 2008-10-02 17:21 <REP> d-------- C:\Program Files\AOL Compagnon
2008-10-02 17:21 . 2008-10-02 17:21 <REP> d-------- C:\Program Files\AOL 9.0
2008-10-02 17:21 . 2008-10-02 17:21 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-10-02 17:21 . 2008-10-02 17:21 <REP> d-------- C:\Documents and Settings\All Users\Application Data\QuickTime
2008-10-02 17:21 . 2008-10-02 17:21 <REP> d-------- C:\Documents and Settings\All Users\Application Data\AOL
2008-10-02 17:20 . 2008-10-02 17:21 <REP> d-------- C:\Program Files\Fichiers communs\AOL
2008-10-02 17:20 . 1998-10-29 16:45 306,688 --a------ C:\WINDOWS\IsUninst.exe
2008-10-02 17:20 . 2008-10-02 22:29 7,584 --a------ C:\WINDOWS\HDReg.ini
2008-10-02 17:20 . 2008-10-02 17:21 822 --ah----- C:\IPH.PH
2008-10-02 17:20 . 2008-10-02 17:20 335 --a------ C:\WINDOWS\nsreg.dat
2008-10-02 17:15 . 2008-10-02 17:15 <REP> d-------- C:\Program Files\Real
2008-10-02 17:15 . 2008-10-02 17:15 <REP> d-------- C:\Program Files\Fichiers communs\xing shared
2008-10-02 17:15 . 2008-10-02 17:15 <REP> d-------- C:\Program Files\Fichiers communs\Real
2008-10-02 17:15 . 2005-05-03 11:56 410,112 --a------ C:\WINDOWS\system32\SETUPPC.CPL
2008-10-02 17:15 . 2005-05-04 15:39 501 --a------ C:\WINDOWS\system32\SETUPPC.INI
2008-10-02 17:14 . 2008-10-02 22:19 <REP> d-------- C:\Program Files\Sonic
2008-10-02 17:14 . 2008-10-02 17:14 <REP> d-------- C:\Program Files\Fichiers communs\SureThing Shared
2008-10-02 17:13 . 2008-10-02 17:13 <REP> d-------- C:\WINDOWS\system32\Lang
2008-10-02 17:10 . 2008-10-04 23:44 <REP> d-------- C:\Program Files\Java
2008-10-02 17:10 . 2008-10-02 17:10 <REP> d-------- C:\Program Files\Fichiers communs\Java
2008-10-02 17:10 . 2004-08-05 14:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-10-02 17:08 . 2008-10-05 17:06 <REP> d--h----- C:\WINDOWS\$hf_mig$
2008-10-02 17:08 . 2008-10-02 17:08 <REP> d-------- C:\ATI Technologies
2008-10-02 17:05 . 2008-10-02 17:05 <REP> d-------- C:\Program Files\Realtek
2008-10-02 17:05 . 2008-10-02 17:22 <REP> d--h----- C:\Program Files\InstallShield Installation Information
2008-10-02 17:05 . 2008-10-02 17:19 <REP> d-------- C:\Program Files\Fichiers communs\InstallShield
2008-10-02 17:03 . 2008-10-02 17:03 <REP> d-------- C:\WINDOWS\system32\URTTemp
2008-10-02 17:00 . 2008-04-13 20:46 61,696 --a------ C:\WINDOWS\system32\drivers\ohci1394.sys
2008-10-02 17:00 . 2008-04-13 20:46 53,376 --a------ C:\WINDOWS\system32\drivers\1394bus.sys
2008-10-02 17:00 . 2008-04-13 20:45 30,208 --a------ C:\WINDOWS\system32\drivers\usbehci.sys
2008-10-02 17:00 . 2008-04-13 20:45 20,608 --a------ C:\WINDOWS\system32\drivers\usbuhci.sys
2008-10-02 17:00 . 2008-04-14 04:33 7,168 --a------ C:\WINDOWS\system32\hccoin.dll
2008-10-02 17:00 . 2001-08-17 21:46 6,400 --a------ C:\WINDOWS\system32\drivers\enum1394.sys
2008-10-02 16:57 . 2008-10-02 16:57 <REP> d--h----- C:\WINDOWS\I386
2008-10-02 16:56 . 2008-10-02 16:56 0 --a------ C:\UPDFLOP.TAG
2008-10-02 16:53 . 2008-10-02 16:53 <REP> d--h----- C:\PNP
2008-10-02 16:48 . 2008-10-02 22:30 <REP> d--hs---- C:\DRIVERS
2008-10-02 16:48 . 2008-10-02 17:21 <REP> d--h----- C:\DIVTOOLS
2008-10-02 16:48 . 2008-10-02 17:22 <REP> d-------- C:\APPS
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
2008-07-07 20:28 253,952 ----a-w C:\WINDOWS\system32\es.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-10-04 171448]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"ATIPTA"="C:\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-03-22 339968]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"PCMService"="c:\Apps\Powercinema\PCMService.exe" [2005-01-28 110740]
"ACTIVBOARD"="c:\apps\ABoard\ABoard.exe" [2003-05-02 24576]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"Raccourci vers la page des propriétés de High Definition Audio"="HDAudPropShortcut.exe" [2004-03-17 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
"SoundMan"="SOUNDMAN.EXE" [2004-09-10 C:\WINDOWS\SoundMan.exe]
"AlcWzrd"="ALCWZRD.EXE" [2004-09-15 C:\WINDOWS\ALCWZRD.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\APPS\\Inventime\\my.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2005-05-27 799744]
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Tâches planifiées'
2008-10-02 C:\WINDOWS\Tasks\HDReg.job
- c:\Apps\HDReg\HDRegRem.exe [2003-07-15 10:14]
2008-10-02 C:\WINDOWS\Tasks\Rappel d'enregistrement 2.job
- C:\WINDOWS\system32\OOBE\oobebaln.exe [2008-04-14 04:34]
2008-10-02 C:\WINDOWS\Tasks\Rappel d'enregistrement 3.job
- C:\WINDOWS\system32\OOBE\oobebaln.exe [2008-04-14 04:34]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-EoEngine - C:\Program Files\EoRezo\EoEngine.exe
.
------- Examen supplémentaire -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.lo.st
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-05 17:29:33
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MysqlInventime]
"ImagePath"="C:\Apps\INVENT~1\mysql\bin\mysqld-nt --defaults-file=C:\Apps\Inventime\mysql\my.ini MysqlInventime"
.
Heure de fin: 2008-10-05 17:30:06
ComboFix-quarantined-files.txt 2008-10-05 15:30:03
Avant-CF: 190 945 001 472 octets libres
Après-CF: 190,957,924,352 octets libres
226 --- E O F --- 2008-10-05 12:46:31