Voici le rapport :
ComboFix 09-03-28.06 - pc 2009-03-29 15:14:11.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.511.140 [GMT 2:00]
Lancé depuis: c:\documents and settings\pc\Bureau\ComboFix.exe
AV: ESET Smart Security 3.0 *On-access scanning disabled* (Updated)
FW: Pare-feu personnel d'ESET *enabled*
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\MabryObj.dll
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_BOONTY_GAMES
-------\Service_Boonty Games
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-28 au 2009-03-29 ))))))))))))))))))))))))))))))))))))
.
2009-03-29 15:12 . 2009-03-29 15:13 <REP> d-------- C:\32788R22FWJFW
2009-03-29 15:00 . 2009-03-29 15:00 <REP> d-------- c:\documents and settings\pc\belgacom
2009-03-29 14:21 . 2009-03-29 14:21 <REP> d-------- c:\program files\7-Zip
2009-03-29 13:45 . 2009-03-29 13:45 <REP> d-------- C:\GenProc
2009-03-29 11:42 . 2009-03-29 11:42 <REP> d-------- c:\program files\Ad-remover
2009-03-29 11:24 . 2009-03-29 11:24 <REP> d-------- c:\program files\Trend Micro
2009-03-28 20:21 . 2009-03-28 20:21 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-28 20:21 . 2009-03-28 20:21 <REP> d-------- c:\documents and settings\pc\Application Data\Malwarebytes
2009-03-28 20:21 . 2009-03-28 20:21 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-28 20:21 . 2009-03-26 17:49 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-28 20:21 . 2009-03-26 17:49 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-17 19:58 . 2009-03-17 19:58 <REP> d-------- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2009-03-12 17:50 . 2009-03-12 17:50 <REP> d-------- c:\documents and settings\pc\Application Data\Apple Computer
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-29 12:26 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-03-29 12:02 --------- d-----w c:\program files\Fichiers communs\Wise Installation Wizard
2009-03-29 11:51 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-03-29 09:57 --------- d-----w c:\program files\CCleaner
2009-03-12 17:01 --------- d-----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-02-16 16:13 --------- d-----w c:\program files\Fichiers communs\Symantec Shared
2009-02-01 19:57 --------- d-----w c:\program files\Travel Adventure
2009-01-30 18:24 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-28 19:29 --------- d-----w c:\program files\Easy Computing
2008-05-11 12:52 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008051120080512\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Belgacom"="c:\program files\Belgacom\bin\sprtcmd.exe" [2006-06-22 192512]
"HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" [2007-03-16 63712]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2008-03-13 1443072]
"SoundMan"="SOUNDMAN.EXE" [2003-08-05 c:\windows\SOUNDMAN.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="c:\documents and settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Magentic\\bin\\MgImp.exe"=
"c:\\Program Files\\Magentic\\bin\\Magentic.exe"=
"c:\\Program Files\\Magentic\\bin\\MgApp.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Sony Ericsson\\Sony Ericsson Media Manager\\MediaManager.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R1 Asapi;Asapi;c:\windows\system32\drivers\asapi.sys [2003-10-31 11264]
R1 vcsmpdrv;vcsmpdrv;c:\windows\system32\drivers\vcsmpdrv.sys [2003-10-31 49024]
R2 ekrn;Eset Service;c:\program files\ESET\ESET Smart Security\ekrn.exe [2008-03-13 472320]
R2 VCSSecS;Virtual CD v4 Security service (SDK - Version);c:\program files\Virtual CD v4 SDK\System\vcssecs.exe [2003-10-31 139264]
S3 cdiskdun;cdiskdun;\??\c:\docume~1\pc\LOCALS~1\Temp\cdiskdun.sys --> c:\docume~1\pc\LOCALS~1\Temp\cdiskdun.sys [?]
S3 se3ebus;Sony Ericsson Device 062 (WDM);c:\windows\system32\drivers\se3ebus.sys [2008-09-21 66656]
S3 se3emdfl;Sony Ericsson Device 062 USB WMC Modem Filter;c:\windows\system32\drivers\se3emdfl.sys [2008-09-21 9392]
S3 se3emdm;Sony Ericsson Device 062 USB WMC Modem Driver;c:\windows\system32\drivers\se3emdm.sys [2008-09-21 100736]
S3 se3emgmt;Sony Ericsson Device 062 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\se3emgmt.sys [2008-09-21 92304]
S3 se3eobex;Sony Ericsson Device 062 USB WMC OBEX Interface;c:\windows\system32\drivers\se3eobex.sys [2008-09-21 90144]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f086dc26-d199-11dc-b54c-000d61222f4d}]
\Shell\AutoRun\command - H:\start.exe
\Shell\FramaKey\command - H:\start.exe
.
Contenu du dossier 'Tâches planifiées'
2009-01-01 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2008-01-22 c:\windows\Tasks\Rappel d'enregistrement 3.job
- c:\windows\System32\OOBE\oobebaln.exe [2008-04-14 04:34]
.
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://www.skynet.be/
uInternet Connection Wizard,ShellNext =
hxxp://www.skynet.be/
uInternet Settings,ProxyOverride = <local>
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Handler: cdefs - {B5F329B4-2BBD-48F5-ADAF-9EAF2AFE37B3} - c:\program files\Easy Computing\3D Modeltreinen 3.0\monki.dll
DPF: DirectAnimation Java Classes -
file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\pc\Application Data\Mozilla\Firefox\Profiles\db78isb5.default\
FF - component: c:\documents and settings\pc\Application Data\Mozilla\Firefox\Profiles\db78isb5.default\extensions\{39757f01-c5ad-4d4b-8387-b6aa8e929ce0}\components\FFAlert.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nppl3260.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprjplug.dll
FF - plugin: c:\program files\Real\RealOne Player\Netscape6\nprpjplug.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-29 15:21:32
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-3816970085-689719414-876072145-1007\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
@SACL=
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(932)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\msv1_0.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\windows\system32\ati2evxx.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
c:\program files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2009-03-29 15:27:17 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-03-29 13:27:13
Avant-CF: 40.410.103.808 octets libres
Après-CF: 40,290,881,536 octets libres
Current=4 Default=4 Failed=1 LastKnownGood=5 Sets=1,2,3,4,5
154 --- E O F --- 2009-03-17 21:13:05