J'ai bien coché les cases sur le rapport hijack .
Voici le rapport combo fix :
ComboFix 09-01-17.02 - HP_Propriétaire 2009-01-17 21:50:08.3 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.510.270 [GMT 1:00]
Lancé depuis: c:\documents and settings\HP_Propriétaire\Bureau\genesis.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Outdated)
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-17 au 2009-01-17 ))))))))))))))))))))))))))))))))))))
.
2009-01-16 22:29 . 2009-01-16 22:29 <REP> d-------- c:\windows\system32\CatRoot_bak
2009-01-16 22:25 . 2009-01-16 22:28 <REP> d--hs---- C:\RECYCLER(2)
2009-01-12 18:31 . 2009-01-12 18:37 664 --a------ c:\windows\system32\d3d9caps.dat
2009-01-11 21:33 . 2009-01-11 21:33 0 --a----t- c:\windows\
005473_.tmp
2009-01-04 18:06 . 2009-01-16 22:32 <REP> d-------- c:\program files\SAGEM(2)
2008-12-17 18:03 . 2008-12-17 18:03 <REP> dr-h----- c:\documents and settings\HP_Propriétaire\Application Data\SecuROM
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-17 20:48 --------- d-----w c:\program files\Wanadoo
2009-01-12 11:04 2,568 ----a-w c:\windows\system32\PerfStringBackup.TMP
2008-12-17 17:03 108,144 ----a-w c:\windows\system32\CmdLineExt.dll
2008-11-17 13:33 --------- d-----w c:\program files\Foxit Software
2008-11-17 13:24 --------- d-----w c:\documents and settings\All Users\Application Data\NOS
2008-11-17 13:20 --------- d-----w c:\program files\NOS
2008-10-24 11:10 453,632 ------w c:\windows\system32\dllcache\mrxsmb.sys
2008-08-01 10:22 20 -c-h--w c:\documents and settings\All Users\Application Data\PKP_DLdu.DAT
2007-04-30 16:51 212,849 -c--a-w c:\program files\hijackthis.zip
2006-04-06 17:40 278,528 -c--a-w c:\program files\Fichiers communs\FDEUnInstaller.exe
2007-10-26 06:17 66,408 -c--a-w c:\program files\mozilla firefox\components\jar50.dll
2007-10-26 06:17 54,112 -c--a-w c:\program files\mozilla firefox\components\jsd3250.dll
2007-10-26 06:17 34,688 -c--a-w c:\program files\mozilla firefox\components\myspell.dll
2007-10-26 06:17 46,456 -c--a-w c:\program files\mozilla firefox\components\spellchk.dll
2007-10-26 06:17 171,880 -c--a-w c:\program files\mozilla firefox\components\xpinstal.dll
2005-09-16 02:19 22 -csha-w c:\windows\SMINST\HPCD.sys
.
((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
-c--a-w 253,952 2004-10-14 20:54:32 c:\hp\drivers\hplsbwatcher\bak\lsburnwatcher.exe
----a-w 253,952 2004-10-14 20:54:32 c:\hp\drivers\hplsbwatcher\LSBurnWatcher.exe
-c--a-w 61,440 2005-02-02 22:44:24 c:\hp\KBD\bak\KBD.EXE
----a-w 61,440 2005-02-02 22:44:24 c:\hp\KBD\KBD.exe
-c--a-w 155,648 2006-01-12 14:40:44 c:\program files\Fichiers communs\Ahead\Lib\bak\NeroCheck.exe
----a-w 155,648 2006-01-12 15:40:44 c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe
-c--a-w 94,208 2006-06-01 11:32:12 c:\program files\Fichiers communs\Ahead\Lib\bak\NMBgMonitor.exe
----a-w 94,208 2006-06-01 11:32:12 c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
-c--a-w 496,752 2004-04-08 03:25:04 c:\program files\Fichiers communs\AOL\ACS\bak\AOLDial.exe
-c--a-w 49,152 2004-06-07 18:53:26 c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\bak\hphupd06.exe
-c--a-w 49,152 2004-06-07 18:53:26 c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
-c--a-w 204,843 2007-01-23 07:06:18 c:\program files\IncrediMail\bin\bak\IncMail.exe
-c--a-w 233,472 2005-05-10 09:05:36 c:\program files\InterVideo\Common\Bin\bak\WinRemote.exe
-c--a-w 233,472 2005-05-10 09:05:36 c:\program files\InterVideo\Common\Bin\WinRemote.exe
-c--a-w 36,975 2005-11-10 11:03:52 c:\program files\Java\jre1.5.0_06\bin\bak\jusched.exe
-c--a-w 98,304 2005-01-01 20:43:33 c:\program files\QuickTime\bak\qttask.exe
----a-w 98,304 2005-01-01 20:43:33 c:\program files\QuickTime\qttask.exe
-c--a-w 49,152 2003-05-08 09:00:58 c:\program files\ScanSoft\OmniPageSE2.0\bak\OpwareSE2.exe
-c--a-w 32,768 2004-10-14 15:55:30 c:\program files\Wanadoo\bak\GestMaj.exe
------w 32,768 2004-10-14 14:55:30 c:\program files\Wanadoo\GestMAJ.exe
-c--a-w 20,480 2004-08-23 13:49:56 c:\program files\Wanadoo\bak\Watch.exe
------w 20,480 2004-08-23 12:49:56 c:\program files\Wanadoo\Watch.exe
-c--a-w 233,472 2004-04-14 20:43:46 c:\windows\SMINST\bak\RECGUARD.EXE
----a-w 233,472 2004-04-14 20:43:46 c:\windows\SMINST\Recguard.exe
-c--a-w 52,736 1998-05-07 16:04:38 c:\windows\system\bak\hpsysdrv.exe
-c--a-w 52,736 1998-05-07 16:04:38 c:\windows\system\hpsysdrv.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-14 68856]
"WOOKIT"="c:\progra~1\Wanadoo\Shell.exe" [2004-08-23 122880]
"DriverLoad"="" [N/A]
"DriverCheck"="" [N/A]
"SystemDriverLoad"="" [N/A]
"SystemDriver"="" [N/A]
"FDriver"="" [N/A]
"ADriver"="" [N/A]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-14 233472]
"PS2"="c:\windows\system32\ps2.exe" [2004-10-25 90112]
"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]
"!AVG Anti-Spyware"="c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-11-07 6731312]
"NeroFilterCheck"="c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-29 266497]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-01-01 98304]
"WOOWATCH"="c:\progra~1\Wanadoo\Watch.exe" [2004-08-23 20480]
"WOOTASKBARICON"="c:\progra~1\Wanadoo\GestMaj.exe" [2004-10-14 32768]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-07-30 185896]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-02-24 5537792]
"AlcxMonitor"="ALCXMNTR.EXE" [2004-09-07 c:\windows\ALCXMNTR.EXE]
"NWEReboot"="" [N/A]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DriverCheck"="" [N/A]
"SystemDriverLoad"="" [N/A]
c:\documents and settings\Administrateur\Menu D‚marrer\Programmes\D‚marrage\
AutoTBar.exe [2003-09-30 57344]
c:\documents and settings\HP_Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
Webshots.lnk - c:\program files\Webshots\WebshotsTray.exe [2008-01-01 196608]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-05 258048]
Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
Nikon Monitor.lnk - c:\program files\Fichiers communs\Nikon\Monitor\NkMonitor.exe [2008-04-10 479232]
RaConfig2500.lnk - c:\program files\RALINK\RT2500 USB Wireless LAN Card\Installer\WINXP\RaConfig2500.exe [2007-06-08 528384]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Messenger\\msmsgs.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26779:TCP"= 26779:TCP:BitComet 26779 TCP
"26779:UDP"= 26779:UDP:BitComet 26779 UDP
R3 PhTVTune;ASUS WDM TV Tuner;c:\windows\system32\drivers\PhTVTune.sys [2005-01-01 24544]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-11-17 33752]
.
Contenu du dossier 'Tâches planifiées'
2007-11-02 c:\windows\Tasks\Connexion facile à Internet.job
- c:\program files\Easy Internet signup\HPSdpApp.exe [2005-03-03 18:04]
.
.
------- Examen supplémentaire -------
.
uSearch Page =
hxxp://www.google.com
uSearch Bar =
hxxp://www.google.com/ie
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
IE: { - c:\program files\Messenger\msmsgs.exe
c:\windows\system32\unicows.dll - c:\windows\Downloaded Program Files\CONFLICT.1\ImageUploader5.ocx
O16 -: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3}
hxxp://copainsdavant.linternaute.com/framework/lib/objimageuploader/html_incl(...)
c:\windows\Downloaded Program Files\CONFLICT.1\ImageUploader5.inf
c:\windows\system32\unicows.dll - c:\windows\Downloaded Program Files\ImageUploader5.ocx
O16 -: {BA162249-F2C5-4851-8ADC-FC58CB424243}
hxxp://copainsdavant.linternaute.com/html_include_bibliotheque/objimageupload(...)
c:\windows\Downloaded Program Files\ImageUploader5.inf
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-17 21:52:21
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2009-01-17 21:53:49
ComboFix-quarantined-files.txt 2009-01-17 20:53:47
Avant-CF: 119,553,204,224 octets libres
Après-CF: 119,540,543,488 octets libres
152 --- E O F --- 2008-11-28 18:11:40