voila le rapport de combofix
ComboFix 10-03-24.01 - Dominique LECLERC 24/03/2010 20:38:54.1.1 - x86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1023.585 [GMT 1:00]
Lancé depuis: c:\documents and settings\Dominique LECLERC\Bureau\machin.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
.
ADS - WINDOWS: deleted 24 bytes in 1 streams. (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\1
c:\windows\system32\drivers\Changer.sys
c:\windows\system32\drivers\npf.sys
c:\windows\system32\Packet.dll
c:\windows\system32\pthreadVC.dll
c:\windows\system32\wpcap.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_NPF
-------\Service_NPF
((((((((((((((((((((((((((((( Fichiers créés du 2010-02-24 au 2010-03-24 ))))))))))))))))))))))))))))))))))))
.
2010-03-24 14:15 . 2010-03-24 14:15 -------- d-----w- c:\documents and settings\Dominique LECLERC\Application Data\Malwarebytes
2010-03-24 14:15 . 2010-01-07 15:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-24 14:15 . 2010-03-24 14:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-24 14:15 . 2010-03-24 14:15 -------- d-----w- C:\Malwarebytes' Anti-Malware
2010-03-24 14:15 . 2010-01-07 15:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-24 13:57 . 2010-03-24 18:03 -------- d-----w- c:\program files\trend micro
2010-03-24 13:57 . 2010-03-24 13:58 -------- d-----w- C:\rsit
2010-03-24 13:09 . 2010-03-24 13:09 0 ----a-w- C:\SDFix.exe
2010-03-24 12:41 . 2008-04-13 18:41 8576 -c--a-w- c:\windows\system32\dllcache\i2omgmt.sys
2010-03-24 12:41 . 2008-04-13 18:41 8576 ----a-w- c:\windows\system32\drivers\i2omgmt.sys
2010-03-24 12:40 . 2008-04-13 18:40 8192 -c--a-w- c:\windows\system32\dllcache\changer.sys
2010-03-20 19:52 . 2001-08-23 16:47 5632 ----a-w- c:\windows\system32\ptpusb.dll
2010-03-20 19:52 . 2008-04-14 02:33 159232 ----a-w- c:\windows\system32\ptpusd.dll
2010-03-11 12:44 . 2010-03-11 12:44 -------- d-----w- C:\found.004
2010-03-02 12:43 . 2010-03-02 12:43 604488 ----a-w- c:\windows\system32\TUProgSt.exe
2010-03-02 12:43 . 2009-07-15 09:48 29000 ----a-w- c:\windows\system32\uxtuneup.dll
2010-03-02 12:43 . 2010-03-02 12:43 361288 ----a-w- c:\windows\system32\TuneUpDefragService.exe
2010-03-02 12:09 . 2010-03-02 12:09 -------- d-----w- c:\documents and settings\Dominique LECLERC\Application Data\Apowersoft
2010-03-02 12:09 . 2010-03-02 12:09 -------- d-----w- c:\program files\Streaming Video Recorder
2010-02-26 12:47 . 2010-03-18 08:49 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Temp
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-24 12:39 . 2010-03-24 12:39 12 ----a-w- c:\documents and settings\Dominique LECLERC\Application Data\jasltw.dat
2010-03-23 12:58 . 2009-12-15 11:11 -------- d-----w- c:\program files\Steam
2010-03-21 16:48 . 2010-02-07 05:36 -------- d-----w- c:\documents and settings\Dominique LECLERC\Application Data\vlc
2010-03-21 14:46 . 2009-12-12 10:59 1 ----a-w- c:\documents and settings\Dominique LECLERC\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-03-09 10:17 . 2010-01-05 09:19 -------- d-----w- c:\documents and settings\Dominique LECLERC\Application Data\dvdcss
2010-03-02 12:46 . 2010-01-07 12:44 -------- d-----w- c:\program files\CCleaner
2010-03-02 12:43 . 2009-12-15 10:11 -------- d-----w- c:\program files\TuneUp Utilities 2009
2010-02-23 09:01 . 2010-02-10 09:07 -------- d-----w- c:\program files\Radio Fr Solo
2010-02-11 00:34 . 2009-12-25 15:00 -------- d-----w- c:\program files\Google
2010-02-07 05:54 . 2010-02-07 05:12 -------- d-----w- c:\program files\adslTV
2010-01-26 13:12 . 2010-01-26 13:12 -------- d-----w- c:\documents and settings\Dominique LECLERC\Application Data\Capcom
2010-01-26 13:12 . 2010-01-26 13:12 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2010-01-26 12:55 . 2010-01-26 12:55 -------- d-----w- c:\program files\Capcom
2010-01-26 12:55 . 2009-12-11 22:38 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-01-01 20:49 . 2003-04-24 12:00 551974 ----a-w- c:\windows\system32\perfh00C.dat
2010-01-01 20:49 . 2003-04-24 12:00 104688 ----a-w- c:\windows\system32\perfc00C.dat
2009-12-25 21:32 . 2009-12-25 15:50 152168 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-12-25 16:42 . 2009-12-11 22:53 26448 ----a-w- c:\documents and settings\Dominique LECLERC\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-12-25 15:35 . 2009-12-25 15:35 12212040 ----a-w- c:\documents and settings\All Users\Application Data\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X86-ENU.exe
2009-12-25 15:35 . 2009-12-25 15:35 13930312 ----a-w- c:\documents and settings\All Users\Application Data\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\WMFDist11-WindowsXP-X64-ENU.exe
2009-12-25 15:35 . 2009-12-25 15:35 77824 ----a-w- c:\documents and settings\All Users\Application Data\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\Run_XML6_SP1.exe
2009-12-25 15:35 . 2009-12-25 15:35 61440 ----a-w- c:\documents and settings\All Users\Application Data\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\WMF11Runx86.exe
2009-12-25 15:35 . 2009-12-25 15:35 58880 ----a-w- c:\documents and settings\All Users\Application Data\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\WMF11Runx64.exe
2009-12-25 15:35 . 2009-12-25 15:35 50000 ----a-w- c:\documents and settings\All Users\Application Data\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Installer\CommonCustomActions\pcswpc.exe
2009-12-25 15:34 . 2009-12-25 15:34 95992424 ----a-w- c:\documents and settings\All Users\Application Data\OviInstallerCache\{B6164ADA-55DA-4FA9-B78B-A7EB741742A1}\Nokia_Ovi_Suite_11_update.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"$Volumouse$"="c:\program files\Volumouse\volumouse.exe" [2009-08-05 33280]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-06-08 29696]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"NMB"="c:\program files\mxsun\VOLVOXKEYLOG.exe" [2008-01-10 661504]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\KEM.exe [2009-12-12 581632]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\ImApp.exe"=
"c:\\Program Files\\IncrediMail\\Bin\\ImpCnt.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\call of duty modern warfare 2\\iw4sp.exe"=
"c:\\Program Files\\Steam\\SteamApps\\rooster85\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Capcom\\MotoGP 08\\Launcher.exe"=
"c:\\Program Files\\Steam\\SteamApps\\common\\call of duty modern warfare 2\\iw4mp.exe"=
R0 avgntmgr;avgntmgr;c:\windows\system32\drivers\avgntmgr.sys [12/12/2009 10:36 22360]
R0 viadsk;viadsk;c:\windows\system32\drivers\viadsk.sys [19/06/2003 18:00 56576]
R1 avgntdd;avgntdd;c:\windows\system32\drivers\avgntdd.sys [12/12/2009 10:36 45416]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [12/12/2009 10:36 108289]
S0 ikltm;ikltm; [x]
S1 SysTool;SysTool Overclocking Utility;c:\windows\system32\drivers\SysTool.sys [10/11/2006 14:08 24064]
S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [18/01/2010 12:14 135664]
S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [17/12/2009 19:00 243056]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contenu du dossier 'Tâches planifiées'
2010-01-01 c:\windows\Tasks\Driver Robot.job
- c:\program files\Driver Robot\1.2.0.5\DriverRobot.exe [2010-01-01 07:54]
2010-03-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-18 11:14]
2010-03-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-18 11:14]
2010-03-24 c:\windows\Tasks\Maintenance en 1 clic.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-07-16 09:00]
.
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://www.orange.fr/uInternet Connection Wizard,ShellNext = iexplore
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Barre RoboForm -
file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
IE: Enregistrer le formulaire -
file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
IE: Personnaliser le menu -
file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
IE: Remplir le formulaire -
file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
FF - ProfilePath - c:\documents and settings\Dominique LECLERC\Application Data\Mozilla\Firefox\Profiles\pdvh2zdx.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
hxxp://orange.frFF - prefs.js: keyword.URL -
hxxp://mystart.incredimail.com/?loc=ff_ ... ar&search=FF - component: c:\program files\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension\components\FirefoxExtension.dll
FF - component: c:\program files\Siber Systems\AI RoboForm\Firefox\components\rfproxy_31.dll
FF - plugin: c:\documents and settings\Dominique LECLERC\Application Data\Mozilla\Firefox\Profiles\pdvh2zdx.default\extensions\OberonGameHost@OberonGames.com\platform\WINNT_x86-msvc\plugins\npOberonGameHost.dll
FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Picasa3\npPicasa3.dll
---- PARAMETRES FIREFOX ----
FF - user.js: yahoo.homepage.dontask - true
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-03-24 20:44
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(1080)
c:\windows\system32\Ati2evxx.dll
- - - - - - - > 'explorer.exe'(2520)
c:\program files\Logitech\SetPoint\lgscroll.dll
c:\program files\Volumouse\vlmshlp.dll
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\System32\TUProgSt.exe
c:\program files\Logitech\SetPoint\KHALMNPR.EXE
c:\windows\System32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Heure de fin: 2010-03-24 20:47:38 - La machine a redémarré
ComboFix-quarantined-files.txt 2010-03-24 19:47
Avant-CF: 121 956 630 528 octets libres
Après-CF: 121 916 882 944 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /fastdetect /NoExecute=OptIn
- - End Of File - - 3762B33368217089F98B3F6800415F24