Voici le rapport de combofix
===============================
combofix
===============================
ComboFix 07-11-01.1 - Sebastien 2007-11-02 15:30:50.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.33.1036.18.443 [GMT -4:00]
Running from: C:\Documents and Settings\Sebastien\Bureau\ComboFix.exe
* Created a new restore point
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Sebastien\Application Data\addon.dat
C:\WINDOWS\system32\drivers\symavc32.sys
C:\WINDOWS\system32\drivers\WDFY42.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_NTMLSVC
-------\LEGACY_RUNTIME
-------\LEGACY_RUNTIME2
-------\LEGACY_WDFY42
((((((((((((((((((((((((((((( Fichiers créés 2007-10-02 to 2007-11-02 ))))))))))))))))))))))))))))))))))))
.
2007-11-02 15:28 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-01 22:44 25,992 --a------ C:\WINDOWS\system32\pgdfgsvc.exe
2007-11-01 22:12 <REP> d-------- C:\Program Files\Microsoft BootVis
2007-11-01 20:10 <REP> d-------- C:\Documents and Settings\Sebastien\Application Data\uTorrent
2007-11-01 18:09 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2007-10-31 19:54 <REP> d-------- C:\WINDOWS\pss
2007-10-31 19:36 <REP> d-------- C:\Documents and Settings\Sebastien\SecurityScans
2007-10-31 19:25 <REP> d-------- C:\Program Files\Microsoft Baseline Security Analyzer 2
2007-10-31 18:56 512 --a------ C:\ScanSectorLog.dat
2007-10-31 18:32 <REP> d-------- C:\Documents and Settings\Sebastien\Application Data\MailFrontier
2007-10-31 18:25 <REP> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-10-31 18:20 <REP> d-------- C:\WINDOWS\Internet Logs
2007-10-31 17:47 <REP> d-------- C:\Program Files\Eraser
2007-10-31 17:47 <REP> d--h----- C:\Documents and Settings\All Users\Application Data\{74D61F17-FFC2-41AF-96E5-1DCB0631B6D1}
2007-10-31 17:07 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-30 17:52 <REP> d-------- C:\Documents and Settings\Sebastien\Application Data\Grisoft
2007-10-30 17:52 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-10-30 17:50 <REP> d-------- C:\Program Files\CCleaner
2007-10-29 19:42 1,156 --a------ C:\WINDOWS\mozver.dat
2007-10-29 17:53 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2007-10-29 17:53 94,416 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-10-29 17:53 92,848 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-10-29 17:53 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-10-29 17:53 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-10-29 17:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-10-29 17:52 <REP> d-------- C:\Program Files\Alwil Software
2007-10-29 17:52 801,144 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-10-28 19:49 <REP> d--h----- C:\WINDOWS\PIF
2007-10-28 19:45 <REP> d-------- C:\Documents and Settings\Sebastien\Application Data\Bell
2007-10-28 17:14 <REP> d-------- C:\Program Files\Lavasoft
2007-10-28 17:14 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-10-28 16:44 0 --a------ C:\WINDOWS\nsreg.dat
2007-10-28 14:33 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
2007-10-28 14:33 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2007-10-28 14:33 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
2007-10-28 14:33 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents
2007-10-28 14:33 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
2007-10-28 14:33 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris
2007-10-28 14:33 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2007-10-28 11:18 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-27 19:19 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Autodesk
2007-10-25 20:20 <REP> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-10-25 19:58 <REP> d-------- C:\Program Files\Bonjour
2007-10-25 19:45 <REP> d-------- C:\Program Files\Fichiers communs\Macrovision Shared
2007-10-19 16:58 <REP> d-------- C:\Program Files\Overland
2007-10-18 18:28 <REP> d-------- C:\Documents and Settings\Sebastien\Application Data\dvdcss
2007-10-18 18:25 <REP> d-------- C:\Program Files\Alcohol Toolbar
2007-10-18 18:25 <REP> d-------- C:\Program Files\Alcohol Soft
2007-10-18 18:25 229,057 --a------ C:\WINDOWS\Alcohol_Toolbar_Uninstaller_4890.exe
2007-10-17 17:33 <REP> d-------- C:\Program Files\Project64 1.6
2007-10-14 20:37 <REP> d-------- C:\Program Files\iPod
2007-10-12 20:20 98,304 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2007-10-10 18:10 <REP> d-------- C:\Program Files\TuneUp Utilities 2007
2007-10-10 18:10 <REP> d-------- C:\Documents and Settings\Sebastien\Application Data\TuneUp Software
2007-10-10 18:10 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TuneUp Software
2007-10-10 18:10 29,704 --a------ C:\WINDOWS\system32\uxtuneup.dll
2007-10-09 21:31 <REP> d-------- C:\Program Files\Any DVD Converter for iPod
2007-10-09 21:31 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-09 16:21 <REP> d-------- C:\Program Files\VideoLAN
2007-10-09 16:21 <REP> d-------- C:\Documents and Settings\Sebastien\Application Data\vlc
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-02 19:39 331,808 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2007-11-02 19:37 4,916 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2007-11-02 00:10 --------- d-----w C:\Documents and Settings\Sebastien\Application Data\StumbleUpon
2007-11-01 22:15 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-31 22:24 75,932 ----a-w C:\WINDOWS\system32\drivers\klick.dat
2007-10-31 22:24 74,396 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2007-10-30 01:33 --------- d-----w C:\Documents and Settings\Sebastien\Application Data\OpenOffice.org2
2007-10-29 22:03 --------- d-----w C:\Documents and Settings\Sebastien\Application Data\Poproamball
2007-10-28 23:06 --------- d-----w C:\Program Files\MSN Messenger
2007-10-28 21:13 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2007-10-28 18:47 --------- d-----w C:\Program Files\Fichiers communs\BitDefender
2007-10-28 18:46 81,984 ----a-w C:\WINDOWS\system32\bdod.bin
2007-10-28 18:41 --------- d-----w C:\Program Files\Azureus
2007-10-27 22:32 --------- d-----w C:\Documents and Settings\Sebastien\Application Data\LimeWire
2007-10-25 23:58 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2007-10-18 21:46 --------- d-----w C:\Documents and Settings\Sebastien\Application Data\Lavasoft
2007-10-12 01:09 --------- d-----w C:\Program Files\Java
2007-10-07 17:02 219,648 ----a-w C:\WINDOWS\system32\uxtheme.dll
2007-09-30 22:27 --------- d-----w C:\Documents and Settings\Sebastien\Application Data\ArcSoft
2007-09-30 22:24 --------- d-----w C:\Program Files\ArcSoft
2007-09-30 02:07 --------- d-----w C:\Program Files\Windows Media Components
2007-09-29 14:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Proxy Long Chin Ping
2007-09-28 21:51 --------- d-----w C:\Program Files\Adverts
2007-09-25 15:01 87,824 ----a-w C:\WINDOWS\system32\drivers\bdfndisf.sys
2007-09-25 00:22 --------- d-----w C:\Program Files\StuffPlug3
2007-09-25 00:21 --------- d-----w C:\Program Files\Messenger Plus! Live
2007-09-25 00:13 --------- d-----w C:\Program Files\Windows Live
2007-09-25 00:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-09-23 18:46 --------- d-----w C:\Program Files\StumbleUpon
2007-09-22 00:25 --------- d-----w C:\Documents and Settings\Sebastien\Application Data\Apple Computer
2007-09-18 23:56 82,380 ----a-w C:\WINDOWS\system32\drivers\AFS2K.SYS
2007-09-18 23:56 --------- d-----w C:\Program Files\Hewlett-Packard
2007-09-18 23:55 --------- d-----w C:\Program Files\HP
2007-09-16 22:16 --------- d-----w C:\Documents and Settings\Sebastien\Application Data\Azureus
2007-09-16 20:44 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2007-09-09 22:38 --------- d-----w C:\Documents and Settings\Sebastien\Application Data\Windows Desktop Search
2007-09-09 19:25 --------- d-----w C:\Program Files\QuickTime
2007-09-09 19:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2007-09-09 19:24 --------- d-----w C:\Program Files\Fichiers communs\Apple
2007-09-09 19:24 --------- d-----w C:\Program Files\Apple Software Update
2007-09-09 19:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2007-09-09 18:29 --------- d-----w C:\Program Files\utorrent
2007-09-09 18:21 --------- d-----w C:\Program Files\Windows Desktop Search
2007-09-09 18:21 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
2007-09-06 01:51 --------- d-----w C:\Program Files\MSXML 6.0
2007-09-05 21:01 --------- d-----w C:\Program Files\Google
2007-09-05 01:57 --------- d-----w C:\Documents and Settings\Sebastien\Application Data\Druide
2007-09-05 01:56 --------- d-----w C:\Program Files\Druide
2007-09-05 01:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2007-09-05 01:14 --------- d-----w C:\Program Files\MessengerPlus! 3
2007-09-04 21:17 --------- d-----w C:\Program Files\DAEMON Tools
2007-09-04 21:08 685,816 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
2007-09-04 18:53 --------- d-----w C:\Program Files\Fichiers communs\Ahead
2007-09-04 18:53 --------- d-----w C:\Documents and Settings\Sebastien\Application Data\Ahead
2007-09-04 18:49 --------- d-----w C:\Program Files\Nero
2007-09-04 18:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2007-09-04 18:46 --------- d-----w C:\Program Files\CyberLink
2007-09-04 18:33 --------- d-----w C:\Program Files\OpenOffice.org 2.0
2007-09-04 18:33 --------- d-----w C:\Program Files\Fichiers communs\Java
2007-09-04 18:15 --------- d-----w C:\Program Files\MSBuild
2007-09-04 18:11 --------- d-----w C:\Program Files\Reference Assemblies
2007-09-04 18:09 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-08-21 06:17 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-08-13 22:54 413,696 ----a-w C:\WINDOWS\system32\vbscript.dll
2007-08-13 22:54 156,160 ----a-w C:\WINDOWS\system32\msls31.dll
2007-08-13 22:45 78,336 ----a-w C:\WINDOWS\system32\ieencode.dll
2007-08-13 22:44 40,960 ----a-w C:\WINDOWS\system32\licmgr10.dll
2007-08-13 22:42 17,408 ----a-w C:\WINDOWS\system32\corpol.dll
2007-08-13 22:39 71,680 ----a-w C:\WINDOWS\system32\admparse.dll
2007-08-13 22:39 55,296 ----a-w C:\WINDOWS\system32\iesetup.dll
2007-08-13 22:36 36,352 ----a-w C:\WINDOWS\system32\imgutil.dll
2007-08-13 22:32 45,568 ----a-w C:\WINDOWS\system32\mshta.exe
2007-08-13 22:01 48,128 ----a-w C:\WINDOWS\system32\mshtmler.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{971D5B7B-F7DF-43ee-B771-6B7FA09975C3}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 15:21 C:\WINDOWS\system32\HdAShCut.exe]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2005-05-19 21:11]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2005-07-26 09:54]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-06-29 00:43]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-06-29 00:43]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 06:06]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 05:25]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-06-21 21:54]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 08:00]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2007-02-05 15:39 294400]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\yayawts]
yayawts.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Windows Desktop Search.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Windows Desktop Search.lnk
backup=C:\WINDOWS\pss\Windows Desktop Search.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
"C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeviceDiscovery]
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Eraser]
C:\Program Files\Eraser\eraser.exe -hide
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gestionnaire Antidote.exe]
C:\Program Files\Druide\Antidote\Gestionnaire Antidote.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Gestionnaire de sécurité]
"C:\Program Files\Bell\Gestionnaire de securite\Rps.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Component Manager]
"C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
"C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"D:\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
"C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSA.exe]
"C:\Program Files\Bell\Sympatico Security Advisor\SSA.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"WLSetupSvc"=3 (0x3)
"NMIndexingService"=3 (0x3)
"NBService"=3 (0x3)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"gusvc"=3 (0x3)
"FLEXnet Licensing Service"=3 (0x3)
R2 UxTuneUp;TuneUp Extension de thème;C:\WINDOWS\System32\svchost.exe -k netsvcs
R3 AEAudioService;AEAudio Service;C:\WINDOWS\system32\drivers\AEAudio.sys
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{77213DA1-E3BD-29CD-A872-370A7D83DF99}]
C:\WINDOWS\system32\win32GI\Game.exe s
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2007-11-02 05:00:00 C:\WINDOWS\Tasks\A3C7144D91409395.job"
"2007-09-09 19:24:39 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-10-26 21:16:22 C:\WINDOWS\Tasks\Maintenance en 1 clic.job"
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-02 15:38:38
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-02 15:42:36 - machine was rebooted
.
--- E O F ---