voici le rapport de ComboFix :
ComboFix 07-12-09.3 - Utilisateur 2007-12-09 10:26:36.2 - NTFSx86 MINIMAL
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.1767 [GMT 1:00]
Running from: C:\Documents and Settings\Utilisateur\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Utilisateur\Application Data\inst.exe
C:\WINDOWS\system32\nsp7.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_NPF
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-11-09 to 2007-12-09 ))))))))))))))))))))))))))))))))))))
.
2007-12-08 20:56 . 2007-12-08 20:56 <REP> d-------- C:\VundoFix Backups
2007-12-08 19:02 . 2007-12-08 19:03 <REP> d-------- C:\Program Files\Lavasoft
2007-12-08 19:02 . 2007-12-08 19:02 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2007-12-08 19:02 . 2007-12-08 19:02 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-12-08 07:58 . 2007-12-09 10:21 <REP> d-------- C:\Program Files\scanner.exe
2007-12-07 20:50 . 2007-12-07 20:50 138,752 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2007-12-07 20:04 . 2007-12-08 17:32 <REP> d-------- C:\Program Files\Spyware Terminator
2007-12-07 20:04 . 2007-12-08 17:11 <REP> d-------- C:\Documents and Settings\Utilisateur\Application Data\Spyware Terminator
2007-12-07 20:04 . 2007-12-08 17:32 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spyware Terminator
2007-12-07 19:31 . 2007-12-07 19:31 <REP> d-------- C:\Program Files\Sophos
2007-12-05 22:06 . 2007-12-07 07:27 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2007-12-05 21:29 . 2007-12-05 21:29 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-03 20:01 . 2007-12-03 20:01 <REP> d-------- C:\Program Files\MSBuild
2007-12-03 20:01 . 2007-12-03 20:01 <REP> d-------- C:\Program Files\Microsoft Works
2007-12-03 19:48 . 2007-12-03 19:48 <REP> d-------- C:\Program Files\MSECache
2007-12-03 18:10 . 2007-12-03 20:08 <REP> d-------- C:\Program Files\laughnetwork
2007-12-03 13:34 . 2007-12-03 13:34 282,624 --a------ C:\WINDOWS\system32\Adssite_sidebar.dll
2007-11-30 19:31 . 2007-11-30 19:31 <REP> d-------- C:\Documents and Settings\Utilisateur\Application Data\PCF-VLC
2007-11-24 17:48 . 2007-12-07 19:07 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-11-24 17:48 . 2007-12-07 19:07 1,409 --a------ C:\WINDOWS\QTFont.for
2007-11-24 17:37 . 2007-11-30 18:14 79,868 --a------ C:\WINDOWS\system32\adssite-remove.exe
2007-11-24 17:37 . 2007-11-28 17:55 40,737 --a------ C:\WINDOWS\system32\rightonadz-uninst.exe
2007-11-18 17:27 . 2007-11-18 18:15 <REP> d-------- C:\Documents and Settings\Utilisateur\Application Data\Dev-Cpp
2007-11-18 17:26 . 2007-11-18 17:27 <REP> d-------- C:\Dev-Cpp
2007-11-18 17:06 . 2007-11-18 17:16 351 --a------ C:\Documents and Settings\Utilisateur\.cb_layout.bin
2007-11-18 16:50 . 2007-11-18 16:50 <REP> d-------- C:\Documents and Settings\Utilisateur\.CodeBlocks
2007-11-18 16:49 . 2007-11-18 16:49 <REP> d-------- C:\Program Files\CodeBlocks
2007-11-18 10:43 . 2007-11-18 10:46 <REP> d-------- C:\Documents and Settings\Utilisateur\Application Data\U3
2007-11-16 16:15 . 2007-11-16 16:15 <REP> d-------- C:\Documents and Settings\Utilisateur\Application Data\Participatory Culture Foundation
2007-11-14 23:17 . 2007-11-14 23:17 379 --a------ C:\WINDOWS\ODBC.INI
2007-11-11 11:17 . 2007-11-11 11:26 <REP> d-------- C:\Documents and Settings\All Users\Application Data\EPSON
2007-11-11 10:54 . 2007-11-11 11:33 <REP> d-------- C:\Program Files\EPSON
2007-11-11 10:52 . 2006-03-20 00:00 63,488 --a------ C:\WINDOWS\system32\escwiad.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-06 19:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-12-04 17:29 --------- d-----w C:\Documents and Settings\Utilisateur\Application Data\LimeWire
2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-11-18 16:16 351 ----a-w C:\Documents and Settings\Utilisateur\.cb_layout.bin
2007-11-14 21:34 --------- d-----w C:\Program Files\microsoft frontpage
2007-11-14 21:28 --------- d-----w C:\Program Files\Astonsoft
2007-11-11 10:38 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-11-11 10:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\UDL
2007-11-10 18:49 --------- d-----w C:\Program Files\TrackMania Nations ESWC
2007-11-10 15:48 --------- d-----w C:\Program Files\Java
2007-11-07 18:34 --------- d-----w C:\Documents and Settings\Utilisateur\Application Data\DeepBurner
2007-11-05 18:07 --------- d-----w C:\Program Files\HyCam2
2007-11-04 20:04 --------- d-----w C:\Program Files\jv16 PowerTools
2007-11-04 14:23 --------- d-----w C:\Program Files\SourceTec
2007-11-04 14:17 --------- d-----w C:\Documents and Settings\Utilisateur\Application Data\DVD Flick
2007-11-04 12:36 --------- d-----w C:\Program Files\Electronic Arts
2007-11-04 12:35 --------- d-----w C:\Program Files\nfs pro street
2007-10-23 17:19 --------- d-----w C:\Program Files\Ontrack
2007-10-21 17:56 --------- d-----w C:\Documents and Settings\Utilisateur\Application Data\EPSON
2007-10-21 17:16 --------- d-----w C:\Program Files\ABBYY FineReader 6.0 Sprint
2007-10-20 10:50 --------- d-----w C:\Program Files\LimeWire
2007-10-19 13:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Motive
2007-10-19 13:33 --------- d-----w C:\Program Files\Fichiers communs\Motive
2007-10-19 13:33 --------- d-----w C:\Program Files\Common Files
2007-10-16 17:46 --------- d-----w C:\Program Files\Google
2007-10-16 16:07 --------- d-----w C:\Program Files\RALINK
2007-08-15 19:18 47,360 ----a-w C:\Documents and Settings\Utilisateur\Application Data\pcouffin.sys
2007-03-11 18:39 1,127,307 ------w C:\Program Files\wrar362fr.exe
2006-05-03 09:06 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
2007-02-21 10:47 31,232 --sh--r C:\WINDOWS\system32\msfDX.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9BEB16F0-4C03-4726-801B-4ABEE481060B}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:55]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00]
"Videos"="C:\Program Files\laughnetwork\update.exe" [2007-11-24 16:10]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [2006-05-27 03:47 C:\WINDOWS\RTHDCPL.exe]
"SW20"="C:\WINDOWS\system32\sw20.exe" [2006-05-17 04:35]
"SW24"="C:\WINDOWS\system32\sw24.exe" [2006-05-17 04:35]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 15:57]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-07-19 17:32]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-05 13:00 C:\WINDOWS\system32\rundll32.exe]
"nwiz"="nwiz.exe" [2007-10-04 17:14 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-05 13:00 C:\WINDOWS\system32\rundll32.exe]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2007-12-07 20:49]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-05 13:00]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 13:00]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ddcya]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\efccbbb]
efccbbb.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Odebit Multimedia V2]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SkyTel]
SkyTel.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\YeppStudioAgent]
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2007-12-07 10:51:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\DOCUME~1\UTILIS~1\LOCALS~1\Temp\ktrhldye-0C02FB.dll
.
**************************************************************************
catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-09 10:30:17
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-09 10:31:08 - machine was rebooted
.
--- E O F ---
et celui de hijackthis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:36:48, on 09/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\RALINK\Common\RaUI.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\MSN Messenger\livecall.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\scanner.exe\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://1-digital-media.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {9BEB16F0-4C03-4726-801B-4ABEE481060B} - (no file)
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SW20] C:\WINDOWS\system32\sw20.exe
O4 - HKLM\..\Run: [SW24] C:\WINDOWS\system32\sw24.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Videos] "C:\Program Files\laughnetwork\update.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xporter vers Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) -
http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) -
http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} -
http://www.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection_2_(...)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) -
http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O20 - Winlogon Notify: ddcya - C:\WINDOWS\
O20 - Winlogon Notify: efccbbb - efccbbb.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
--
End of file - 6813 bytes