voici le rapport de combofix :
ComboFix 08-10-15.01 - Propriétaire 2008-10-15 18:59:42.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.2686 [GMT 2:00]
Lancé depuis: C:\Documents and Settings\Propriétaire\Bureau\Combo-Fix.exe
* Un nouveau point de restauration a été créé
[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/B/COLOR
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Program Files\OneStepSearch
C:\WINDOWS\k.txt
C:\WINDOWS\system32\c.ico
C:\WINDOWS\system32\m.ico
C:\WINDOWS\system32\s.ico
----- BITS: Il y a peut-être des sites infectés -----
hxxp://premium.virginmega.fr
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-15 au 2008-10-15 ))))))))))))))))))))))))))))))))))))
.
2008-10-15 17:40 . 2008-10-15 17:40 <REP> d-------- C:\WINDOWS\system32\IOSUBSYS
2008-10-15 17:40 . 2008-10-15 17:40 <REP> d-------- C:\Program Files\Picasa2
2008-10-15 17:40 . 2006-10-05 04:42 2,560 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-10-15 17:40 . 2006-10-05 04:42 2,432 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-10-15 14:54 . 2008-10-15 14:54 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-15 14:54 . 2008-10-15 14:54 <REP> d-------- C:\Documents and Settings\Propriétaire\Application Data\Malwarebytes
2008-10-15 14:54 . 2008-10-15 14:54 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-15 14:54 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-15 14:54 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-15 14:20 . 2008-10-15 14:32 <REP> d-------- C:\Program Files\Hijackthis Version Française
2008-10-15 14:07 . 2008-10-15 14:07 <REP> d-------- C:\Program Files\Trend Micro
2008-10-15 13:09 . 2008-09-08 12:41 333,824 -----c--- C:\WINDOWS\system32\dllcache\srv.sys
2008-10-15 13:08 . 2008-08-14 15:23 2,191,232 -----c--- C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-15 13:08 . 2008-08-14 15:23 2,147,328 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-15 13:08 . 2008-08-14 15:23 2,068,096 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-15 13:08 . 2008-08-14 15:23 2,025,984 -----c--- C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-15 13:08 . 2008-09-15 17:26 1,846,528 -----c--- C:\WINDOWS\system32\dllcache\win32k.sys
2008-10-14 15:41 . 2008-10-14 15:41 <REP> d-------- C:\Documents and Settings\Propriétaire\Application Data\Grisoft
2008-10-14 15:41 . 2008-10-14 15:41 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-10-14 15:41 . 2007-05-30 14:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-10-14 14:46 . 2008-10-14 14:50 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-10-14 14:46 . 2008-10-14 15:09 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-13 23:21 . 2008-10-14 14:26 <REP> d-------- C:\Program Files\TS2009
2008-10-13 18:30 . 2008-10-13 18:30 244 --ah----- C:\sqmnoopt00.sqm
2008-10-13 18:30 . 2008-10-13 18:30 232 --ah----- C:\sqmdata00.sqm
2008-10-10 09:11 . 2008-10-10 09:11 4,096 --ahs---- C:\WINDOWS\system32\Thumbs.db
2008-10-06 16:32 . 2008-10-06 16:32 <REP> d-------- C:\Program Files\LibUSB-Win32-0.1.10.1
2008-10-06 16:32 . 2005-03-09 20:50 46,592 --a------ C:\WINDOWS\system32\libusb0.dll
2008-10-06 16:32 . 2005-03-09 20:50 33,792 --a------ C:\WINDOWS\system32\drivers\libusb0.sys
2008-10-06 16:32 . 2005-03-09 20:50 19,456 --a------ C:\WINDOWS\system32\libusbd-9x.exe
2008-10-06 16:32 . 2005-03-09 20:50 18,944 --a------ C:\WINDOWS\system32\libusbd-nt.exe
2008-10-06 16:31 . 2008-10-06 16:31 <REP> d-------- C:\Program Files\11679_Sixaxis_PS3_Win32_Driver_For_PC
2008-09-28 18:28 . 2008-10-05 10:44 <REP> d-------- C:\Documents and Settings\Propriétaire\.homeplayer
2008-09-28 18:28 . 2008-10-05 10:44 <REP> d-------- C:\Documents and Settings\Propriétaire\.homeplayer
2008-09-28 14:25 . 2008-09-28 14:25 230,424 --a------ C:\img2-001.raw
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-15 15:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-10-15 12:39 196,608 ----a-w C:\WINDOWS\system32\drivers\nStandard.bin
2008-10-15 10:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-10-15 10:06 --------- d-----w C:\Program Files\Windows Live
2008-10-15 10:05 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-10-15 10:05 --------- d-----w C:\Program Files\epson
2008-10-15 10:04 --------- d-----w C:\Program Files\adslTV
2008-10-15 10:04 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\vlc
2008-10-15 10:03 --------- d-----w C:\Program Files\eMule
2008-10-13 07:16 --------- d-----w C:\Program Files\qFreeFax
2008-09-28 10:11 --------- d-----w C:\Program Files\Google
2008-09-15 15:26 1,846,528 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-14 17:48 --------- d-----w C:\Program Files\Java
2008-09-08 11:19 --------- d-----w C:\Program Files\Fichiers communs\Java
2008-09-08 10:41 333,824 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-09-05 22:10 716 ----a-w C:\Documents and Settings\Propriétaire\Application Data\filterclsid.dat
2008-09-05 21:58 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Samsung
2008-09-05 20:58 --------- d-----w C:\Program Files\MSXML 4.0
2008-09-04 10:38 5,632 ----a-w C:\WINDOWS\system32\drivers\StarOpen.sys
2008-09-04 10:07 --------- d-----w C:\Program Files\Samsung
2008-09-02 16:15 --------- d-----w C:\Program Files\Fichiers communs\ArTech
2008-09-02 16:12 --------- d-----w C:\Program Files\Tupsoft
2008-08-30 16:12 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-08-30 16:12 --------- d-----w C:\Program Files\Real
2008-08-30 16:12 --------- d-----w C:\Program Files\Fichiers communs\xing shared
2008-08-30 16:12 --------- d-----w C:\Program Files\Fichiers communs\Real
2008-08-29 07:57 97,928 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-08-26 08:11 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-08-25 13:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\LightScribe
2008-08-25 13:47 --------- d-----w C:\Program Files\LightScribeTemplateLabeler
2008-08-25 13:38 --------- d-----w C:\Program Files\Fichiers communs\LightScribe
2008-08-25 13:29 --------- d-----w C:\Program Files\LightScribe
2008-08-19 15:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Downloaded Installations
2008-08-18 13:15 2,287,104 ----a-w C:\WINDOWS\system32\TUKernel.exe
2008-08-18 08:53 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Nero
2008-08-18 08:40 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Ahead
2008-08-18 08:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ahead
2008-08-18 08:39 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Ahead
2008-08-16 08:24 --------- d-----w C:\Program Files\Fichiers communs\LogiShrd
2008-08-16 08:24 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-08-16 08:23 --------- d-----w C:\Program Files\Fichiers communs\Logitech
2008-08-14 13:23 2,147,328 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:23 2,025,984 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-07-21 10:07 10,520 ----a-w C:\WINDOWS\system32\avgrsstx.dll
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-15 13:10 306,432 ----a-w C:\WINDOWS\system32\TuneUpDefragService.exe
2008-07-15 12:34 315,392 ----a-w C:\WINDOWS\HideWin.exe
2006-06-23 22:48 32,768 ----a-r C:\WINDOWS\inf\UpdateUSB.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2007-01-15 147456]
"EPSON Stylus DX8400 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICEE.EXE" [2007-04-12 182272]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2008-08-21 443968]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-04-19 7700480]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-04-19 86016]
"GamerOSD"="C:\Program Files\ASUS\GamerOSD\GamerOSD.exe" [2007-02-14 380928]
"NeroFilterCheck"="C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-09-30 1234712]
"VX3000"="C:\WINDOWS\vVX3000.exe" [2006-10-13 707376]
"LifeCam"="C:\Program Files\Microsoft LifeCam\LifeExp.exe" [2006-10-13 277296]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
"RTHDCPL"="RTHDCPL.EXE" [2007-03-21 C:\WINDOWS\RTHDCPL.exe]
"nwiz"="nwiz.exe" [2007-04-19 C:\WINDOWS\system32\nwiz.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-04-11 C:\WINDOWS\KHALMNPR.Exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]
C:\Documents and Settings\Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2008-08-16 805392]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="C:\\Documents and Settings\\All Users\\Application Data\\TuneUp Software\\TuneUp Utilities\\WinStyler\\tu_logonui.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 02:42 72208 c:\Program Files\Fichiers communs\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"C:\\Program Files\\Fichiers communs\\Ahead\\Nero Web\\SetupX.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
R1 asusgsb;ASUS Virtual Video Capture Device Driver;C:\WINDOWS\system32\drivers\asusgsb32.sys [2005-10-20 12416]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-08-29 97928]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-08-29 231704]
R2 MSCamSvc;MSCamSvc;C:\Program Files\Microsoft LifeCam\MSCamS32.exe [2006-10-13 207664]
R2 UxTuneUp;TuneUp Extension de thème;C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;C:\WINDOWS\system32\DRIVERS\atl01_xp.sys [2007-03-15 38656]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.10.1;C:\WINDOWS\system32\drivers\libusb0.sys [2005-03-09 33792]
R3 Video3D;ASUS Video3D Service;C:\WINDOWS\system32\Drivers\Video3D32.sys [2006-09-29 10752]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-07-15 306432]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c8bc1f00-77fc-11dd-b1d2-001e8cd62029}]
\Shell\AutoRun\command - M:\wd_windows_tools\WDEULA.exe
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"C:\Program Files\Fichiers communs\LightScribe\LSRunOnce.exe"
.
Contenu du dossier 'Tâches planifiées'
2008-10-03 C:\WINDOWS\Tasks\Maintenance en 1 clic.job
- C:\Program Files\TuneUp Utilities 2008\OneClick.exe [2007-12-21 15:39]
.
.
------- Examen supplémentaire -------
.
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
O16 -: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} - hxxp://www.new2.foto.com/ImageUploader5.cab
C:\WINDOWS\Downloaded Program Files\ImageUploader5.inf
C:\WINDOWS\system32\unicows.dll
C:\WINDOWS\Downloaded Program Files\ImageUploader5.ocx
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-15 19:01:14
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-10-15 19:01:51
ComboFix-quarantined-files.txt 2008-10-15 17:01:48
Avant-CF: 61 031 612 416 octets libres
Après-CF: 61,059,940,352 octets libres
214 --- E O F --- 2008-10-15 15:12:56