voilà le rapport combofix. Je refais un scan avec hijackthis.
ComboFix 07-10-14.1 - Utilisateur 2007-10-13 23:47:56.1 - NTFSx86 MINIMAL
Microsoft Windows XP dition familiale 5.1.2600.2.1252.1.1036.18.645 [GMT 2:00]
Running from: C:\Documents and Settings\Utilisateur\Bureau\ComboFix.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2007-09-14 to 2007-10-14 ))))))))))))))))))))))))))))))))))))
.
2007-10-13 23:46 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-13 22:25 <REP> d-------- C:\Program Files\CCleaner
2007-10-13 22:13 <REP> d-------- C:\Program Files\Avira
2007-10-13 20:55 <REP> d-------- C:\Program Files\Navilog1
2007-10-13 20:24 <REP> d-------- C:\WINDOWS\ERUNT
2007-10-13 19:18 <REP> d-------- C:\Program Files\Trend Micro
2007-10-13 19:16 812,344 --a------ C:\scanner.exe.exe
2007-10-13 03:18 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-10-13 01:39 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2007-10-11 16:17 <REP> d-------- C:\Program Files\UnFREEz
2007-10-07 23:40 <REP> d-------- C:\Program Files\PhotoFiltre Studio
2007-10-07 23:40 45 ---h----- C:\WINDOWS\dsez2612.dat
2007-10-01 13:40 <REP> d-------- C:\WINDOWS\Sun
2007-09-29 03:06 <REP> d-------- C:\Program Files\MSXML 6.0
2007-09-27 18:26 <REP> d-------- C:\Documents and Settings\Utilisateur\Application Data\OpenOffice.org2
2007-09-27 18:24 <REP> d-------- C:\Program Files\OpenOffice.org 2.3
2007-09-27 18:23 <REP> d-------- C:\Program Files\Java
2007-09-27 18:23 <REP> d-------- C:\Program Files\Fichiers communs\Java
2007-09-27 17:04 <REP> d-------- C:\Program Files\ECBarre
2007-09-27 16:38 <REP> d-------- C:\Program Files\MSBuild
2007-09-27 16:35 <REP> d-------- C:\Program Files\la Bunny Barre ( Bbarre )
2007-09-27 16:33 <REP> d-------- C:\WINDOWS\system32\XPSViewer
2007-09-27 16:32 <REP> d-------- C:\Program Files\Reference Assemblies
2007-09-27 16:31 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2007-09-27 16:17 <REP> d-------- C:\Program Files\KiddiesBarre
2007-09-27 16:04 <REP> d-------- C:\Program Files\Lavasoft
2007-09-27 16:04 <REP> d-------- C:\Documents and Settings\Utilisateur\Application Data\Lavasoft
2007-09-27 15:59 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-09-19 00:16 <REP> d-------- C:\Documents and Settings\murgen\Contacts
2007-09-19 00:11 <REP> d-------- C:\Documents and Settings\murgen\Application Data\Dossier de t‚l‚chargement Share-to-Web
2007-09-19 00:10 <REP> d--h----- C:\Documents and Settings\murgen\Voisinage r‚seau
2007-09-19 00:10 <REP> d--h----- C:\Documents and Settings\murgen\Voisinage d'impression
2007-09-19 00:10 <REP> d--h----- C:\Documents and Settings\murgen\ModŠles
2007-09-19 00:10 <REP> dr------- C:\Documents and Settings\murgen\Mes documents
2007-09-19 00:10 <REP> dr------- C:\Documents and Settings\murgen\Menu D‚marrer
2007-09-19 00:10 <REP> dr------- C:\Documents and Settings\murgen\Favoris
2007-09-19 00:10 <REP> d-------- C:\Documents and Settings\murgen\Bureau
2007-09-18 23:52 <REP> d--h----- C:\WINDOWS\$hf_mig$
2007-09-18 23:52 23,856 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-09-18 23:45 <REP> d---s---- C:\Documents and Settings\Utilisateur\UserData
2007-09-18 21:02 82,380 --a------ C:\WINDOWS\system32\drivers\AFS2K.SYS
2007-09-18 20:11 <REP> d-------- C:\Program Files\HP
2007-09-18 20:06 327,168 --a------ C:\WINDOWS\IsUn040c.exe
2007-09-18 20:03 <REP> d-------- C:\Documents and Settings\Utilisateur\Application Data\Dossier de t‚l‚chargement Share-to-Web
2007-09-18 20:03 <REP> d-------- C:\Documents and Settings\Utilisateur\Application Data\Dossier de t‚l‚chargement Share-to-Web
2007-09-18 20:02 <REP> d-------- C:\Program Files\Hewlett-Packard
2007-09-18 20:02 <REP> d-------- C:\Program Files\Fichiers communs\Hewlett-Packard
2007-09-18 20:01 385,024 -ra------ C:\WINDOWS\system32\rts8891u.dll
2007-09-18 20:01 253,952 -ra------ C:\WINDOWS\system32\hpgtulbz.dll
2007-09-18 20:01 249,856 -ra------ C:\WINDOWS\system32\hpgud32.dll
2007-09-18 20:01 225,280 -ra------ C:\WINDOWS\system32\hpgtpusd.dll
2007-09-18 20:01 118,784 -ra------ C:\WINDOWS\system32\hpsjvset.dll
2007-09-18 20:01 106,496 -ra------ C:\WINDOWS\system32\hpguapi.dll
2007-09-18 20:01 40,960 -ra------ C:\WINDOWS\system32\hpg4400.dll
2007-09-18 20:01 15,104 --a------ C:\WINDOWS\system32\drivers\usbscan.sys
2007-09-18 20:01 15,104 --a--c--- C:\WINDOWS\system32\dllcache\usbscan.sys
2007-09-18 19:55 25,856 --a------ C:\WINDOWS\system32\drivers\usbprint.sys
2007-09-18 19:55 25,856 --a--c--- C:\WINDOWS\system32\dllcache\usbprint.sys
2007-09-18 17:11 <REP> d-------- C:\Documents and Settings\Utilisateur\Contacts
2007-09-18 17:09 <REP> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-09-18 17:09 <REP> d-------- C:\Program Files\MSN Messenger
2007-09-18 16:44 <REP> d-------- C:\Program Files\WDM_3663
2007-09-18 16:44 <REP> d--h----- C:\Program Files\InstallShield Installation Information
2007-09-18 16:44 <REP> d-------- C:\Program Files\Fichiers communs\InstallShield
2007-09-18 16:44 <REP> d-------- C:\Program Files\Analog Devices
2007-09-18 16:34 1,207,026 --a------ C:\Program Files\wrar370.exe
2007-09-18 16:10 19,373,650 --a------ C:\Program Files\WDM_3663.zip
2007-09-18 15:38 <REP> d-------- C:\Program Files\Alwil Software
2007-09-18 15:38 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2007-09-18 15:38 499,712 --a------ C:\WINDOWS\system32\MSVCP71.dll
2007-09-18 15:38 348,160 --a------ C:\WINDOWS\system32\MSVCR71.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-09 22:02 --------- d-----w C:\Documents and Settings\Utilisateur\Application Data\Dossier de téléchargement Share-to-Web
2007-09-18 22:11 --------- d-----w C:\Documents and Settings\murgen\Application Data\Dossier de téléchargement Share-to-Web
2007-09-18 18:03 --------- d-----w C:\Documents and Settings\Utilisateur\Application Data\Dossier de téléchargement Share-to-Web
2007-09-18 11:50 --------- d-----w C:\Program Files\Fichiers communs\SpeechEngines
2007-09-18 11:50 --------- d-----w C:\Program Files\Fichiers communs\ODBC
2007-09-18 10:04 --------- d-----w C:\Program Files\microsoft frontpage
2007-09-18 10:03 --------- d-----w C:\Program Files\Services en ligne
2007-09-18 10:02 --------- d-----w C:\Program Files\Fichiers communs\MSSoap
2007-08-21 06:17 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-07-30 17:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-07-30 17:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-07-30 17:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-07-30 17:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll
2007-07-30 17:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-07-30 17:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-07-30 17:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-07-30 17:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll
2007-07-30 17:18 207,736 ----a-w C:\WINDOWS\system32\muweb.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2003-05-05 08:57]
"Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 09:11]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2003-06-25 11:24]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-07-28 16:43]
"DeviceDiscovery"="C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe" [2003-05-21 18:37]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-06-14 18:32]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2007-10-13 22:15]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:55]
*Newly Created Service* - CATCHME
.
**************************************************************************
catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-10-14 23:49:19
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-14 23:50:04
.
--- E O F ---