Voici le resultat du log de combo
ComboFix 08-11-10.01 - milie 2008-11-11 17:35:46.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.615 [GMT 1:00]
Lancé depuis: c:\documents and settings\milie\Bureau\ComboFix.exe
Commutateurs utilisés :: c:\documents and settings\milie\Bureau\WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
* Un nouveau point de restauration a été créé
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-11 au 2008-11-11 ))))))))))))))))))))))))))))))))))))
.
2008-11-11 17:07 . 2008-11-11 17:09 <REP> d-------- C:\hijackthis
2008-11-11 16:49 . 2008-11-11 16:49 <REP> d-------- c:\windows\LastGood
2008-11-10 11:57 . 2008-11-10 11:57 <REP> d-------- c:\windows\system32\fr-fr
2008-11-10 11:57 . 2008-11-10 11:57 <REP> d-------- c:\windows\system32\fr
2008-11-10 11:57 . 2008-11-10 11:57 <REP> d-------- c:\windows\system32\bits
2008-11-10 11:57 . 2008-11-10 11:57 <REP> d-------- c:\windows\l2schemas
2008-11-10 11:54 . 2008-11-10 11:57 <REP> d-------- c:\windows\ServicePackFiles
2008-11-07 21:06 . 2008-11-09 19:43 <REP> d-------- c:\documents and settings\milie\Application Data\dvdcss
2008-11-07 19:12 . 2004-08-04 00:38 327,168 --------- c:\windows\system32\drivers\ati2mtaa.sys
2008-11-07 17:22 . 2008-09-08 11:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
2008-11-07 17:22 . 2008-08-14 11:04 138,496 -----c--- c:\windows\system32\dllcache\afd.sys
2008-11-07 17:20 . 2008-08-14 14:23 2,191,232 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2008-11-07 17:20 . 2008-08-14 14:23 2,147,328 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2008-11-07 17:20 . 2008-08-14 14:23 2,068,096 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2008-11-07 17:20 . 2008-08-14 14:23 2,025,984 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2008-11-07 17:20 . 2008-09-15 16:26 1,846,528 -----c--- c:\windows\system32\dllcache\win32k.sys
2008-11-07 17:12 . 2008-05-08 15:02 203,136 -----c--- c:\windows\system32\dllcache\rmcast.sys
2008-11-07 17:11 . 2008-04-11 20:05 691,712 -----c--- c:\windows\system32\dllcache\inetcomm.dll
2008-11-07 17:05 . 2008-11-11 16:49 <REP> d--h----- c:\windows\$hf_mig$
2008-11-07 17:05 . 2007-08-10 08:18 26,488 --a------ c:\windows\system32\spupdsvc.exe
2008-11-07 11:28 . 2008-10-15 17:35 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
2008-11-07 11:28 . 2008-06-14 18:33 272,768 --------- c:\windows\system32\drivers\bthport.sys
2008-11-07 11:28 . 2008-06-14 18:33 272,768 -----c--- c:\windows\system32\dllcache\bthport.sys
2008-11-06 19:04 . 2008-11-06 19:36 <REP> d-------- c:\documents and settings\milie\Application Data\vlc
2008-11-06 19:03 . 2008-11-06 19:03 <REP> d-------- c:\program files\VideoLAN
2008-11-06 17:08 . 2008-11-07 21:42 <REP> d-------- c:\program files\uTorrent
2008-11-06 17:08 . 2008-11-10 21:44 <REP> d-------- c:\documents and settings\milie\Application Data\uTorrent
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-11 15:19 --------- d-----w c:\program files\F-Secure
2008-11-07 19:52 --------- d-----w c:\documents and settings\milie\Application Data\Ahead
2008-10-09 16:33 118,784 ------r c:\windows\bwUnin-6.3.2.110-7681197L.exe
2008-10-09 16:29 --------- d-----w c:\program files\IZArc
2008-10-09 16:06 81,920 ----a-w c:\windows\system32\W32N50.DLL
2008-10-09 16:06 17,134 ----a-w c:\windows\system32\PCANDIS5.SYS
2008-10-09 16:05 --------- d-----w c:\program files\Inventel
2008-10-08 17:40 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-08 17:40 --------- d-----w c:\program files\SAGEM
2008-10-08 17:24 --------- d-----w c:\program files\Services en ligne
2008-10-08 16:59 --------- d-----w c:\program files\Securitoo
2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
2008-08-20 05:10 670,208 ----a-w c:\windows\system32\wininet.dll
2008-08-14 20:42 44,512 ----a-w c:\documents and settings\milie\Application Data\GDIPFONTCACHEV1.DAT
2008-08-14 13:23 2,147,328 ----a-w c:\windows\system32\ntoskrnl.exe
2008-08-14 13:23 2,025,984 ----a-w c:\windows\system32\ntkrnlpa.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Le Petit Robert Hyperappel"="c:\program files\Le Robert\Le Petit Robert\prhyper.exe" [2001-10-11 22560]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\lib\NMBgMonitor.exe" [2006-02-01 98304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Asus USB Switch"="c:\windows\system32\AsusUSBSwitch\AsUsbSw.exe" [2005-10-27 20480]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-12 344064]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-10-25 282624]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2006-10-30 256576]
"F-Secure Manager"="c:\program files\F-Secure\Common\FSM32.EXE" [2004-09-09 118832]
"F-Secure TNB"="c:\program files\F-Secure\TNB\TNBUtil.exe" [2004-05-27 684032]
"SoundMan"="SOUNDMAN.EXE" [2005-07-22 c:\windows\soundman.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users.WINDOWS\Menu D‚marrer\Programmes\D‚marrage\
Acrobat Assistant.lnk - c:\program files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe [2006-05-22 49254]
F-Secure Automatic Update.lnk - c:\program files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe [2008-10-09 32807]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"c:\\Program Files\\F-Secure\\BackWeb\\7681197\\program\\F-Secure Automatic Update.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 FSFW;F-Secure Firewall Driver;c:\windows\system32\drivers\fsdfw.sys [2005-04-07 68944]
R2 BackWeb Plug-in - 7681197;F-Secure Automatic Update;c:\progra~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE [2008-10-09 32807]
R2 F-Secure Filter;F-Secure File System Filter;c:\program files\F-Secure\Anti-Virus\Win2K\FSfilter.sys [2004-09-10 48720]
R2 F-Secure Gatekeeper;F-Secure Gatekeeper;c:\program files\F-Secure\Anti-Virus\Win2K\FSgk.sys [2005-01-13 45168]
R2 F-Secure Recognizer;F-Secure File System Recognizer;c:\program files\F-Secure\Anti-Virus\Win2K\FSrec.sys [2003-02-06 16048]
R2 Machnm32;Machnm32 Driver;c:\windows\system32\Machnm32.sys [2003-08-12 2304]
R3 RTL8187B;TG123g USB Wireless Adapter;c:\windows\system32\DRIVERS\RTL8187B.sys [2007-07-18 264576]
S3 PhnxVcd;PhnxVcd;c:\windows\system32\Drivers\PhnxVcd.sys [2005-03-21 45056]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{01d52ff2-14f6-11dc-bc6a-0015f24f92ff}]
\Shell\Auto\command - McRegWizz.exe e
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL McRegWizz.exe e
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{67e0e796-6f7a-11dd-bd12-0015f24f92ff}]
\Shell\AutoRun\command - E:\setupSNK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bc38651a-831d-11dc-bc90-0015f24f92ff}]
\shell\verb1\command - PeSrvr.exe
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Tâches planifiées'
2008-11-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-10-10 17:13]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-farstone - (no file)
HKLM-Run-NWEReboot - (no file)
.
------- Examen supplémentaire -------
.
FireFox -: Profile - c:\documents and settings\milie\Application Data\Mozilla\Firefox\Profiles\tmqh3rp7.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.orange.fr
FF -: plugin - c:\program files\Adobe\Acrobat 5.0\Acrobat\browser\nppdf32.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-11 17:36:40
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Le Petit Robert Hyperappel = c:\program files\Le Robert\Le Petit Robert\prhyper.exe??????????????????????????????????????????????????????????????????????????????????????????????????????????\??? /??\??????????????????????|? ??\???Q??|x???m??|????????\??????|Z????????????,K????? 4?????
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-11-11 17:37:10
ComboFix-quarantined-files.txt 2008-11-11 16:37:07
Avant-CF: 6 654 197 760 octets libres
Après-CF: 6,681,939,968 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect
144 --- E O F --- 2008-11-10 11:02:31