finalement, après 2 tentatives et au moins 4 redémarrage de l'ordi' voici le rapport :
ComboFix 08-06-15.4 - Romain 2008-06-16 22:05:23.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.550 [GMT 2:00]
Endroit: C:\Documents and Settings\Romain\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2006
C:\Documents and Settings\All Users\Documents\_desktop.ini
C:\Documents and Settings\All Users\Documents\Ma musique\_desktop.ini
C:\Documents and Settings\All Users\Documents\Ma musique\chantillons de musique\_desktop.ini
C:\Documents and Settings\All Users\Documents\Ma musique\My Playlists\_desktop.ini
C:\Documents and Settings\All Users\Documents\Ma musique\Sample Playlists\_desktop.ini
C:\Documents and Settings\All Users\Documents\Ma musique\Sample Playlists\000F695F\_desktop.ini
C:\Documents and Settings\All Users\Documents\Ma musique\Sync Playlists\_desktop.ini
C:\Documents and Settings\All Users\Documents\Ma musique\Sync Playlists\0259CDA5\_desktop.ini
C:\Documents and Settings\All Users\Documents\Mes images\_desktop.ini
C:\Documents and Settings\All Users\Documents\Mes images\chantillons d'images\_desktop.ini
C:\Documents and Settings\All Users\Documents\Mes images\chantillons d'images\Mes images\_desktop.ini
C:\Documents and Settings\All Users\Documents\Mes images\chantillons d'images\Mes images\Mes photos Logitech\_desktop.ini
C:\Documents and Settings\All Users\Documents\Mes images\chantillons d'images\Mes images\Mes photos Logitech\Photos et vid‚os\_desktop.ini
C:\Documents and Settings\All Users\Documents\Mes vid‚os\_desktop.ini
C:\Documents and Settings\All Users\Documents\My Pictures\_desktop.ini
C:\Documents and Settings\All Users\Documents\My Pictures\Image Editor\_desktop.ini
C:\Documents and Settings\All Users\Documents\My Pictures\Image Editor\Default Archive\_desktop.ini
C:\Documents and Settings\All Users\Documents\T‚l‚chargements AOL\_desktop.ini
C:\Documents and Settings\Doudou\Application Data\HbTools_Icons
C:\Documents and Settings\Doudou\Application Data\HbTools_Icons\games2.ico
C:\Documents and Settings\Doudou\Application Data\HbTools_Icons\Registryrepair.ico
C:\Documents and Settings\Doudou\Application Data\HbTools_Icons\wallpapere1.ico
C:\Documents and Settings\Doudou\Menu Démarrer\Programmes\Spyware-Secure
C:\Documents and Settings\Doudou\Menu Démarrer\Programmes\Spyware-Secure\Spyware-Secure.lnk
C:\Documents and Settings\Doudou\Menu Démarrer\Programmes\Spyware-Secure\Uninstall.lnk
C:\Documents and Settings\Doudou\Menu Démarrer\Programmes\Spyware-Secure\Website.lnk
C:\Documents and Settings\Philippe\Menu Démarrer\Programmes\Spyware-Secure
C:\Documents and Settings\Philippe\Menu Démarrer\Programmes\Spyware-Secure\Spyware-Secure.lnk
C:\Documents and Settings\Philippe\Menu Démarrer\Programmes\Spyware-Secure\Website.lnk
C:\Documents and Settings\Romain\Application Data\WinAntiVirus Pro 2006
C:\WINDOWS\BM53e30670.xml
C:\WINDOWS\system32\ccLVCcdd.ini
C:\WINDOWS\system32\ccLVCcdd.ini2
C:\WINDOWS\system32\ciamxjkc.ini
C:\WINDOWS\system32\cnlpkwgb.ini
C:\WINDOWS\system32\efxheelhq.dat
c:\WINDOWS\system32\efxheelhq_nav.dat
c:\WINDOWS\system32\efxheelhq_navps.dat
C:\WINDOWS\system32\JkjlSvut.ini
C:\WINDOWS\system32\JkjlSvut.ini2
.
---- Previous Run -------
.
C:\Program Files\Fichiers communs\winantivirus pro 2006
C:\Program Files\Fichiers communs\winantivirus pro 2006\WapCHK.dll
C:\Program Files\winantivirus pro 2006
C:\Program Files\winantivirus pro 2006\history.db
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\WINDOWS\dialerexe.ini
C:\WINDOWS\pack.epk
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\nvs2.inf
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\stera.job
C:\WINDOWS\system32\stera.log
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_FOPF
-------\Legacy_FOPN
-------\Legacy_VSPF
-------\Legacy_VSPF_HK
-------\Service_vspf
-------\Service_vspf_hk
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-05-16 to 2008-06-16 ))))))))))))))))))))))))))))))))))))
.
2008-06-16 21:07 . 2008-06-16 21:07 <REP> d-------- C:\Program Files\Trend Micro
2008-06-16 18:52 . 2008-06-16 18:52 123,392 --a------ C:\WINDOWS\system32\ckjxmaic.dll
2008-06-16 18:49 . 2008-06-16 18:49 131,584 --a------ C:\WINDOWS\system32\ibnxhwkm.dll
2008-06-16 18:49 . 2008-06-16 18:49 127,488 --a------ C:\WINDOWS\system32\iwlauenk.dll
2008-06-15 20:56 . 2008-06-15 20:56 30,760 --a------ C:\WINDOWS\system32\bonrppyk.exe
2008-06-15 17:18 . 2008-06-15 17:18 41,984 --a------ C:\WINDOWS\17PHolmes1000106.exe
2008-06-15 17:17 . 2008-06-15 17:17 <REP> d-------- C:\WINDOWS\system32\vRI
2008-06-15 17:17 . 2008-06-15 17:17 <REP> d-------- C:\WINDOWS\system32\rt
2008-06-15 17:17 . 2008-06-15 17:17 <REP> d-------- C:\WINDOWS\system32\netrax05
2008-06-15 17:17 . 2008-06-15 17:17 <REP> d-------- C:\temp\itmp4
2008-06-15 17:17 . 2008-06-15 17:17 100,784 --a------ C:\temp\reywdl.exe
2008-06-15 13:02 . 2008-06-15 13:02 <REP> d-------- C:\Documents and Settings\Romain\Application Data\Viewpoint
2008-06-11 08:51 . 2008-04-14 17:52 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 08:51 . 2008-04-14 17:52 272,768 --------- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-08 04:16 . 2008-06-08 04:16 32,768 --a------ C:\WINDOWS\system32\netrax05\netrax051080.exe
2008-06-06 11:17 . 2008-06-06 11:17 <REP> d-------- C:\Program Files\Fichiers communs\Adobe AIR
2008-06-06 11:17 . 2008-06-06 11:17 <REP> d-------- C:\Program Files\Canal
2008-05-29 20:49 . 2008-05-29 22:31 <REP> d-------- C:\Program Files\World of Warcraft
2008-05-29 20:49 . 2008-05-29 21:51 <REP> d-------- C:\Program Files\Fichiers communs\Blizzard Entertainment
2008-05-17 20:55 . 2008-05-17 20:55 <REP> d-------- C:\Program Files\SoftChris
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-16 20:04 --------- d-----w C:\Documents and Settings\Romain\Application Data\VMNTOOLBAR
2008-06-16 13:51 --------- d-----w C:\Documents and Settings\Doudou\Application Data\VMNTOOLBAR
2008-06-11 08:23 5,546 ----a-w C:\Documents and Settings\Doudou\Application Data\wklnhst.dat
2008-06-11 05:14 --------- d-----w C:\Program Files\eMule
2008-05-22 18:39 6,596 ----a-w C:\Documents and Settings\Romain\Application Data\wklnhst.dat
2008-05-12 18:56 --------- d-----w C:\Program Files\LimeWire
2008-05-11 21:10 --------- d-----w C:\Documents and Settings\Romain\Application Data\LimeWire
2008-05-10 12:23 --------- d-----w C:\Program Files\vmntoolbar
2008-05-10 12:23 --------- d-----w C:\Program Files\Visicom Media
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-04-26 08:54 --------- d-----w C:\Documents and Settings\Doudou\Application Data\Yahoo!
2008-04-25 22:12 --------- d-----w C:\Documents and Settings\Romain\Application Data\Yahoo!
2008-04-25 14:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-04-25 13:56 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-25 13:56 --------- d-----w C:\Program Files\Yahoo!
2008-04-25 13:53 --------- d-----w C:\Program Files\Veoh Networks
2008-04-20 10:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\close poke frag ooze
2008-04-19 16:40 --------- d-----w C:\Program Files\Zylom Games
2008-04-19 16:39 --------- d-----w C:\Program Files\Poker Indicator
2008-04-19 16:38 --------- d-----w C:\Program Files\Oberon Media
2008-04-19 16:31 --------- d-----w C:\Program Files\Larousse
2008-04-16 14:50 --------- d-----w C:\Program Files\Microsoft Picture It! 9
2007-02-02 06:52 31 ----a-w C:\Documents and Settings\Philippe\getfile.dat
2007-02-01 15:52 31 ----a-w C:\Documents and Settings\Doudou\getfile.dat
2007-01-31 15:22 31 ----a-w C:\Documents and Settings\Romain\getfile.dat
2006-08-12 09:37 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2006-03-05 11:28 4,096 ----a-w C:\Documents and Settings\Romain\log.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e85620ee-130b-420f-9c8f-d43a4fd943a7}]
2008-06-16 18:49 131584 --a------ C:\WINDOWS\system32\ibnxhwkm.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15:00 15360]
"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-02-15 22:04 67128]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [2005-06-08 15:44 196608]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
"Aim6"="" []
"Yahoo! Pager"="C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-04 20:55 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-05 15:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 15:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 15:00 455168]
"Raccourci vers la page des propriétés de High Definition Audio"="HDAudPropShortcut.exe" [2004-03-17 16:10 61952 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
"SoundMan"="SOUNDMAN.EXE" [2004-09-10 19:29 77824 C:\WINDOWS\SoundMan.exe]
"AlcWzrd"="ALCWZRD.EXE" [2004-09-15 12:20 2557952 C:\WINDOWS\ALCWZRD.EXE]
"ATIPTA"="C:\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-08-12 22:10 339968]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"PCMService"="c:\Apps\Powercinema\PCMService.exe" [2005-01-28 12:10 110740]
"ACTIVBOARD"="c:\apps\ABoard\ABoard.exe" [2003-05-02 11:31 24576]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe" [2004-04-06 12:28 172032]
"HPHUPD06"="C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 06:53 49152]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 15:54 241664]
"HPHmon06"="C:\WINDOWS\system32\hphmon06.exe" [2004-06-07 06:43 659456]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-07-19 18:32 221184]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-17 00:11 49152]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-06-08 16:24 458752]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-06-08 16:14 217088]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-08-11 14:06 180269]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-05-01 12:07 843776]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-01-10 16:27 385024]
"iTunesHelper"="C:\WINDOWS\iTunesHelper.exe" [2008-01-15 04:22 267048]
"Canal Widget"="C:\Program Files\Canal\Canal Widget\Launcher.exe" [2008-06-03 15:55 103992]
"BM53e30670"="C:\WINDOWS\system32\iwlauenk.dll" [2008-06-16 18:49 127488]
"50d035ec"="C:\WINDOWS\system32\ckjxmaic.dll" [2008-06-16 18:52 123392]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 15:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.yv12"= C:\PROGRA~1\ACEMEG~1\SystemS\ATI\atiyuv12.DLL
"msacm.enc"= ITIG726.acm
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\APPS\\Inventime\\my.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\WINDOWS\\system32\\rtcshare.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Documents and Settings\\Romain\\Mes documents\\StationRipper\\StationRipperConsole.exe"=
"C:\\Program Files\\ICQLite\\ICQLite.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"C:\\WINDOWS\\iTunes.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
R2 CanalPlus.VOD;CanalPlus.VOD;"C:\Program Files\Canal\Canal Widget\VOD\CanalPlus.VOD.exe" [2008-06-03 13:19]
R3 Cap713x;Cap713x Video Capture;C:\WINDOWS\system32\DRIVERS\Cap713x.sys [2004-10-08 18:58]
R3 PID_0920;Logitech QuickCam Express(PID_0920);C:\WINDOWS\system32\DRIVERS\LV532AV.SYS [2005-01-31 12:13]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5efee4de-af24-11dc-9ad8-001a926f2107}]
\Shell\AutoRun\command - K:\start.exe
\Shell\iledefrance\command - K:\start.exe
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-06-11 05:20:10 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-16 18:32:17 C:\WINDOWS\Tasks\HP Usg Daily FY04.job"
- C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\pexpress\hphped06.exe
"2008-06-16 08:00:29 C:\WINDOWS\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
"2008-06-16 20:31:00 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-16 22:25:27
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MysqlInventime]
"ImagePath"="c:\mysql\bin\mysqld-nt MysqlInventime"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\APPS\HIDSERVICE\HidService.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\MDM.EXE
C:\Program Files\Fichiers communs\Symantec Shared\Security Center\symwsc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\APPS\ABOARD\AOSD.EXE
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\digital imaging\bin\hpqgalry.exe
C:\WINDOWS\system32\notepad.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-06-16 22:32:06 - machine was rebooted [Romain]
ComboFix-quarantined-files.txt 2008-06-16 20:32:01
Pre-Run: 9,756,237,824 octets libres
Post-Run: 11,582,414,848 octets libres
256 --- E O F --- 2008-06-14 09:06:01