voici le rapport CombFix :
ComboFix 08-08-08.02 - Mathieu 2008-08-08 19:27:04.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.510 [GMT 2:00]
Endroit: C:\Documents and Settings\Mathieu\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !! .
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Secure Solutions
C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\as2008xp.exe
C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\LOG\20080806194549046.log
C:\Documents and Settings\Mathieu\ravmonlog
C:\WINDOWS\eoam.exe
C:\WINDOWS\pack.epk
C:\WINDOWS\privacy_danger
C:\WINDOWS\privacy_danger\images\capt.gif
C:\WINDOWS\privacy_danger\images\danger.jpg
C:\WINDOWS\privacy_danger\images\down.gif
C:\WINDOWS\privacy_danger\images\spacer.gif
C:\WINDOWS\privacy_danger\index.htm
C:\WINDOWS\system32\qwhycmcskzal.dll
C:\WINDOWS\system32\sswavxt.dat
C:\WINDOWS\system32\sswavxt_nav.dat
C:\WINDOWS\system32\sswavxt_navps.dat
C:\WINDOWS\system32\tdssadw.dll
C:\WINDOWS\system32\tdssinit.dll
C:\WINDOWS\system32\tdssl.dll
C:\WINDOWS\system32\tdsslog.dll
C:\WINDOWS\system32\tdssmain.dll
C:\WINDOWS\system32\tdssservers.dat
C:\WINDOWS\tfnslopk.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TDSSSERV
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-07-08 to 2008-08-08 ))))))))))))))))))))))))))))))))))))
.
2008-08-08 18:03 . 2008-08-08 18:03 <REP> d-------- C:\Documents and Settings\Mathieu\Application Data\Lavasoft
2008-08-08 18:01 . 2008-08-08 18:01 <REP> d-------- C:\Program Files\Webroot
2008-08-08 18:01 . 2008-08-08 18:01 <REP> d-------- C:\Documents and Settings\Mathieu\Application Data\Webroot
2008-08-08 18:01 . 2008-08-08 18:01 <REP> d-------- C:\Documents and Settings\LocalService\Application Data\Webroot
2008-08-08 18:01 . 2008-08-08 18:01 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Webroot
2008-08-08 18:01 . 2007-03-01 19:54 144,960 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
2008-08-08 18:01 . 2007-03-01 19:54 22,080 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
2008-08-08 18:01 . 2007-03-01 19:54 21,056 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2008-08-08 18:01 . 2007-03-01 19:54 20,544 --a------ C:\WINDOWS\system32\drivers\SSFS0509.sys
2008-08-08 17:59 . 2008-08-08 18:02 <REP> d-------- C:\Program Files\SpywareBlaster
2008-08-08 17:59 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2008-08-08 17:57 . 2008-08-08 17:59 <REP> d-------- C:\Temp
2008-08-08 17:57 . 2008-08-08 17:57 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Prevx
2008-08-08 17:28 . 2008-08-08 17:28 <REP> d-------- C:\WINDOWS\system32\GroupPolicy
2008-08-08 17:28 . 2008-08-08 18:31 <REP> d-------- C:\Program Files\Hitman Pro
2008-08-08 02:23 . 2008-08-08 02:23 <REP> d-------- C:\Program Files\Alwil Software
2008-08-07 18:13 . 2008-08-07 18:13 <REP> d-------- C:\WINDOWS\system32\AlertModule
2008-08-07 18:01 . 2008-08-07 18:01 <REP> d-------- C:\Program Files\SAGEM
2008-08-07 15:56 . 2008-08-07 20:00 3,624 --a------ C:\WINDOWS\system32\tmp.reg
2008-08-07 15:54 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-08-07 15:54 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-08-07 15:54 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-08-07 15:54 . 2008-07-02 13:33 82,432 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-08-07 15:54 . 2008-05-23 18:21 81,920 --a------ C:\WINDOWS\system32\404Fix.exe
2008-08-07 15:54 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-08-07 15:54 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-08-07 15:54 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-08-06 19:45 . 2008-08-06 19:54 <REP> d-------- C:\Documents and Settings\All Users\Application Data\services
2008-08-06 19:45 . 2008-08-06 19:45 64,362 --a------ C:\WINDOWS\system32\mjnvqoxsvq.exe
2008-08-06 19:41 . 2008-08-06 18:13 86,016 --a------ C:\WINDOWS\lnvegaow.exe
2008-07-20 19:40 . 2008-08-03 20:20 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-07-20 19:40 . 2008-07-20 19:40 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-08 17:36 --------- d-----w C:\Program Files\Wanadoo
2008-08-08 16:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-08 16:00 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-08 16:00 --------- d-----w C:\Program Files\Lavasoft
2008-08-08 14:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-08-07 17:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg8
2008-08-07 16:01 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-07 12:52 --------- d-----w C:\Program Files\Google
2008-08-06 22:31 --------- d-----w C:\Program Files\eMule
2008-08-06 21:32 --------- d-----w C:\Program Files\Soulseek
2008-08-05 15:35 137,472 ----a-w C:\WINDOWS\system32\drivers\PnkBstrK.sys
2008-08-01 23:45 --------- d-----w C:\Program Files\PokerStars
2008-06-23 10:02 --------- d-----w C:\Program Files\Prélude
2008-06-23 10:01 --------- d-----w C:\Program Files\Prelude 2008
2008-06-23 09:42 --------- d-----w C:\Documents and Settings\Mathieu\Application Data\Prelude
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-15 16:34 --------- d-----w C:\Program Files\Error Repair Professional
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-14 10:59 --------- d-----w C:\Program Files\Anti Trojan Elite
2007-05-15 00:33 14,001,680 ----a-w C:\Program Files\RealPlayer10-5GOLD_fr.exe
2007-05-15 00:10 18,346,191 ----a-w C:\Program Files\WDM_A400.exe
2007-05-06 22:46 9,187,304 ----a-w C:\Program Files\winamp534_full_bundle_emusic-7plus.exe
2006-09-30 20:14 11,280,185 ----a-w C:\Program Files\setupfre.exe
2006-06-15 03:06 937,001 ----a-w C:\Program Files\slsk156c.exe
2004-08-03 23:55 28,672 ----a-w C:\Program Files\setupSNK.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15:00 15360]
"WOOKIT"="C:\Program Files\Wanadoo\Shell.exe" [2004-08-23 14:50 122880]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-04-18 01:10 68856]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2005-05-12 01:15 102400]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-04-28 02:16 5562368]
"ASUS Live Update"="C:\Program Files\ASUS\ASUS Live Update\ALU.exe" [2003-09-19 13:54 172032]
"NB Probe"="C:\Program Files\ASUS\NB Probe\NBProbe.exe" [2005-05-30 18:39 765952]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-12-22 00:23 98394]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-12-22 00:23 688218]
"RemoteControl"="C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe" [2004-11-02 21:24 32768]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]
"Power_Gear"="c:\program files\asus\power4 gear\batterylife.exe" [2004-09-21 17:55 81920]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-04-29 23:37 155648]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-05-15 02:34 185896]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 16:18 241664]
"WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 14:49 20480]
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 16:55 32768]
"nwiz"="nwiz.exe" [2005-04-28 02:16 1495040 C:\WINDOWS\system32\nwiz.exe]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 15:28 577536 C:\WINDOWS\soundman.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 15:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=sockspy.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"spmgr"=2 (0x2)
"CaCCProvSP"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Asus\\ASUS Live Update\\LiveUpdt.exe"=
"C:\\Program Files\\Resolume 2.3\\resolume.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"18864:TCP"= 18864:TCP:NortonAV
"18507:TCP"= 18507:TCP:NortonAV
"17300:TCP"= 17300:TCP:NortonAV
"18454:TCP"= 18454:TCP:NortonAV
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R0 R592;R592;C:\WINDOWS\system32\DRIVERS\R592.sys [2004-10-15 01:29]
R0 risdpntk;risdpntk;C:\WINDOWS\system32\DRIVERS\risdpntk.sys [2004-10-15 01:29]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 16:35]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 16:37]
R3 HSFHWSIS;HSFHWSIS;C:\WINDOWS\system32\DRIVERS\HSFHWSIS.sys [2004-06-17 00:57]
S3 Asushwio;Asushwio;C:\WINDOWS\system32\drivers\Asushwio.sys [2000-03-29 15:17]
S3 ATE_PROCMON;ATE_PROCMON;C:\Program Files\Anti Trojan Elite\ATEPMon.sys []
S3 SE2Ebus;Sony Ericsson Device 046 Driver driver (WDM);C:\WINDOWS\system32\DRIVERS\SE2Ebus.sys [2006-11-10 18:23]
S3 SE2Emdfl;Sony Ericsson Device 046 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\SE2Emdfl.sys [2006-11-10 18:23]
S3 SE2Emdm;Sony Ericsson Device 046 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\SE2Emdm.sys [2006-11-10 18:23]
S3 SE2Emgmt;Sony Ericsson Device 046 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\SE2Emgmt.sys [2006-11-10 18:23]
S3 se2End5;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (NDIS);C:\WINDOWS\system32\DRIVERS\se2End5.sys [2006-11-10 18:23]
S3 SE2Eobex;Sony Ericsson Device 046 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\SE2Eobex.sys [2006-11-10 18:23]
S3 se2Eunic;Sony Ericsson Device 046 USB Ethernet Emulation SEMC46 (WDM);C:\WINDOWS\system32\DRIVERS\se2Eunic.sys [2006-11-10 18:24]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{13cea00e-06df-11db-b135-0012f0d7555c}]
\Shell\AutoRun\command - I:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{647d9baa-edbd-11da-b0c2-0012f0d7555c}]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Recycled\ctfmon.exe
\Shell\Open(&0)\command - Recycled\ctfmon.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c1ac7ffc-8ff2-11dc-b4ba-0012f0d7555c}]
\Shell\AutoRun\command - H:\setupSNK.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c940820c-ffbb-11dc-b5df-0012f0d7555c}]
\Shell\AutoRun\command - H:\LaunchU3.exe -a
.
- - - - ORPHANS REMOVED - - - -
BHO-{DBEF65C0-913F-49C4-82FD-7EB478B30FB5} - C:\WINDOWS\wnlmdakqsrg.dll
Toolbar-{0448CEDF-E4D9-49B6-A3CF-1D7AA90C0177} - C:\WINDOWS\bgrqfetx.dll
HKCU-Run-E06FXLRD_324656 - C:\Program Files\Microsoft Encarta\Collection Microsoft Encarta 2006 DVD\EDICT.EXE
HKCU-Run-BitTorrent - C:\Program Files\BitTorrent\bittorrent.exe
HKLM-Run-Zshutdown - c:\sysprep\patch\sysprep.cmd
HKLM-Run-Anti Trojan Elite - C:\Program Files\Anti Trojan Elite\TJEnder.exe
HKLM-Run-{9488a32e-9046-7fc9-6a72-6295b661b3f3} - C:\WINDOWS\system32\qwhycmcskzal.dll
MSConfigStartUp-cctray - C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
MSConfigStartUp-magsthe - C:\DOCUME~1\Mathieu\APPLIC~1\CAMP01~1\Intrapokelong.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Mathieu\Application Data\Mozilla\Firefox\Profiles\b61abbhl.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://en-us.start.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fr:official
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net Rootkit scan 2008-08-08 19:34:25
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Program Files\Asus\NB Probe\SPM\spmgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Asus\ASUSLI~1\ALU.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\system32\ALERTM~1\ALERTM~1.EXE
C:\WINDOWS\system32\imapi.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-08-08 19:40:15 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-08 17:40:04
Pre-Run: 7,488,495,616 octets libres
Post-Run: 7,396,472,320 octets libres
231 --- E O F --- 2008-07-08 18:13:09