Voici le rapport de COMBO
ComboFix 08-10-23.06 - Administrateur 2008-10-24 10:25:46.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.583 [GMT 2:00]
Lancé depuis: C:\Documents and Settings\Administrateur\Bureau\VIRUSDIDIER\ComboFix.exe
* Un nouveau point de restauration a été créé
[COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/B/COLOR
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\fyno.sys
C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\pisi._sy
C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\qeqag.com
C:\WINDOWS\system32\instsrv.exe
C:\WINDOWS\system32\x64
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Legacy_TDSSSERV.SYS)
-------\Service_NPF
-------\Service_TDSSserv.sys)
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-24 au 2008-10-24 ))))))))))))))))))))))))))))))))))))
.
2008-10-24 09:38 . 2008-10-24 09:38 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-24 09:38 . 2008-10-24 09:38 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-24 09:38 . 2008-10-24 09:38 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Malwarebytes
2008-10-24 09:38 . 2008-10-22 16:10 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-24 09:38 . 2008-10-22 16:10 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-24 08:55 . 2008-10-24 08:55 579,584 --a--c--- C:\WINDOWS\system32\dllcache\user32.dll
2008-10-24 08:53 . 2008-10-24 08:53 <REP> d-------- C:\WINDOWS\ERUNT
2008-10-24 08:46 . 2008-10-22 02:19 <REP> d-------- C:\SDFix
2008-10-23 18:58 . 2008-10-23 19:15 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-23 18:10 . 2008-10-23 18:26 3,068 --a------ C:\WINDOWS\system32\tmp.reg
2008-10-23 18:09 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-10-23 18:09 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-10-23 18:09 . 2008-09-08 23:38 88,576 --a------ C:\WINDOWS\system32\AntiXPVSTFix.exe
2008-10-23 18:09 . 2008-10-01 15:51 87,552 --a------ C:\WINDOWS\system32\VACFix.exe
2008-10-23 18:09 . 2008-10-10 08:58 82,944 --a------ C:\WINDOWS\system32\o4Patch.exe
2008-10-23 18:09 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-10-23 18:09 . 2008-10-10 08:58 82,944 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-10-23 18:09 . 2008-08-18 12:19 82,432 --a------ C:\WINDOWS\system32\404Fix.exe
2008-10-23 18:09 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-10-23 18:09 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-10-23 18:09 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-10-23 17:49 . 2008-10-23 17:49 <REP> d-------- C:\Program Files\Enigma Software Group
2008-10-23 16:50 . 2008-10-23 16:50 <REP> d-------- C:\Program Files\Alwil Software
2008-10-23 16:41 . 2008-10-23 16:41 18,792 --a------ C:\Program Files\Fichiers communs\pewojute.exe
2008-10-23 16:41 . 2008-10-23 16:41 18,664 --a------ C:\WINDOWS\xyrewe._dl
2008-10-23 16:41 . 2008-10-23 16:41 18,252 --a------ C:\Program Files\Fichiers communs\hefajob.pif
2008-10-23 16:41 . 2008-10-23 16:41 17,835 --a------ C:\WINDOWS\oluket.bat
2008-10-23 16:41 . 2008-10-23 16:41 17,334 --a------ C:\Documents and Settings\Administrateur\Application Data\tomomiquk.bin
2008-10-23 16:41 . 2008-10-23 16:41 17,286 --a------ C:\WINDOWS\tujypahehu._dl
2008-10-23 16:41 . 2008-10-23 16:41 17,024 --a------ C:\WINDOWS\acylyga.bat
2008-10-23 16:41 . 2008-10-23 16:41 16,763 --a------ C:\Documents and Settings\Administrateur\Application Data\habobu.com
2008-10-23 16:41 . 2008-10-23 16:41 15,267 --a------ C:\WINDOWS\system32\cyryga._sy
2008-10-23 16:41 . 2008-10-23 16:41 15,193 --a------ C:\WINDOWS\system32\rymare.bin
2008-10-23 16:41 . 2008-10-23 16:41 14,735 --a------ C:\Documents and Settings\Administrateur\Application Data\hemapa.scr
2008-10-23 16:41 . 2008-10-23 16:41 14,729 --a------ C:\Documents and Settings\Administrateur\Application Data\ozofaje.dll
2008-10-23 16:41 . 2008-10-23 16:41 13,328 --a------ C:\WINDOWS\cinyd.dl
2008-10-23 16:41 . 2008-10-23 16:41 13,086 --a------ C:\WINDOWS\adok.reg
2008-10-23 16:33 . 2008-10-24 09:00 164 --a------ C:\WINDOWS\system32\TDSSosvd.dat
2008-10-22 10:12 . 2008-09-08 12:41 333,824 -----c--- C:\WINDOWS\system32\dllcache\srv.sys
2008-10-22 10:11 . 2008-08-14 15:23 2,191,232 -----c--- C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-22 10:11 . 2008-08-14 15:23 2,147,328 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-22 10:11 . 2008-08-14 15:23 2,068,096 -----c--- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-22 10:11 . 2008-08-14 15:23 2,025,984 -----c--- C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-22 10:11 . 2008-09-15 17:26 1,846,528 -----c--- C:\WINDOWS\system32\dllcache\win32k.sys
2008-09-26 10:42 . 2008-09-26 10:42 <REP> d-------- C:\WINDOWS\system32\fr
2008-09-26 10:42 . 2008-09-26 10:42 <REP> d-------- C:\WINDOWS\system32\bits
2008-09-26 10:42 . 2008-09-26 10:42 <REP> d-------- C:\WINDOWS\l2schemas
2008-09-26 10:39 . 2008-09-26 10:43 <REP> d-------- C:\WINDOWS\ServicePackFiles
2008-09-26 09:07 . 2008-09-26 09:07 <REP> d-------- C:\Program Files\InfraRecorder
2008-09-26 09:07 . 2008-09-26 10:20 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\InfraRecorder
2008-09-26 09:02 . 2008-09-26 09:02 <REP> d-------- C:\Program Files\WinASPI
2008-09-26 09:02 . 2008-09-26 09:04 <REP> d-------- C:\Program Files\Morgan
2008-09-26 09:01 . 2008-09-26 09:05 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\NeoDivX2008
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-23 14:38 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\uTorrent
2008-09-30 15:04 --------- d-----w C:\Program Files\MSN Messenger
2008-09-15 15:26 1,846,528 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-08 10:41 333,824 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-26 08:11 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-08-14 13:23 2,147,328 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:23 2,025,984 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-04-28 16:57 27,344 ----a-w C:\Documents and Settings\Administrateur\Application Data\GDIPFONTCACHEV1.DAT
2008-03-04 08:39 8 --sh--r C:\WINDOWS\system32\4BAD612816.sys
2008-03-04 08:48 2,516 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"Nokia.PCSync"="C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" [2008-06-17 1249280]
"PC Suite Tray"="C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-06-18 1122816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2008-04-13 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-13 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-13 455168]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2002-12-31 159744]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2002-12-31 138008]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2002-12-31 162584]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2002-12-31 138008]
"SigmatelSysTrayApp"="stsystra.exe" [2002-12-31 C:\WINDOWS\stsystra.exe]
C:\Documents and Settings\Administrateur\Menu D‚marrer\Programmes\D‚marrage\
Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe [2007-11-14 3450608]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
UpdateTimer.lnk - C:\Program Files\Inmarsat\Launchpad\UpdateTimer.exe [2008-01-29 319488]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoDesktopCleanupWizard"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\uTorrent\\uTorrent.exe"=
"C:\\WINDOWS\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 CAPI20;Eumex 504PC USB;C:\WINDOWS\system32\Drivers\CAPI20.SYS [2001-11-14 234732]
R2 DETEWECP;DeTeWe CapiPort;C:\WINDOWS\system32\drivers\detewecp.sys [2001-09-18 38480]
R2 rvsport;RVS Virtual COM Port;C:\WINDOWS\system32\drivers\rvsport.sys [2001-05-23 38400]
R3 cxbp0wdm;CardMan 4040;C:\WINDOWS\system32\DRIVERS\cxbp0wdm.sys [2007-06-05 73728]
S3 cxbu0wdm;CardMan 3x21;C:\WINDOWS\system32\DRIVERS\cxbu0wdm.sys [2007-02-28 91008]
S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\DNINDIS5.SYS [2003-07-24 17149]
S3 SG762_XP;SAGEM 802.11g XG762 1211B Driver;C:\WINDOWS\system32\DRIVERS\WlanBZXP.sys [2006-01-18 402432]
S3 tap0801;TAP-Win32 Adapter V8;C:\WINDOWS\system32\DRIVERS\tap0801.sys [2006-10-01 26624]
S3 ulisa;DeTeWe ISDN-Adapter (USB);C:\WINDOWS\system32\Drivers\ulisa.sys [2001-11-15 31769]
S3 wg51und5;NETGEAR WG511U Wireless Network Adapter Service;C:\WINDOWS\system32\DRIVERS\wg51und5.sys [ ]
S3 ZDCndis5;ZDCndis5 Protocol Driver;C:\WINDOWS\system32\ZDCndis5.SYS [ ]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0f162447-b16a-11dc-95b3-001c239f125f}]
\Shell\AutoRun\command - E:\LaunchU3.exe -a
.
.
------- Examen supplémentaire -------
.
FireFox -: Profile - C:\Documents and Settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\2t9ekniv.default\
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-24 10:28:51
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
PROCESSUS: C:\WINDOWS\explorer.exe
-> C:\Program Files\Stardock\ObjectDock\DockShellHook.dll
.
------------------------ Autres processus actifs ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\scardsvr.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\stacsv.exe
C:\WINDOWS\system32\fxssvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Program Files\Apoint\hidfind.exe
C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Program Files\Fichiers communs\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\Apoint\ApntEx.exe
C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\WINDOWS\system32\verclsid.exe
.
**************************************************************************
.
Heure de fin: 2008-10-24 10:31:38 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-10-24 08:31:34
Avant-CF: 4 801 548 288 octets libres
Après-CF: 4,752,711,680 octets libres
183 --- E O F --- 2008-10-23 12:00:49
Merci