voila le rapport
ComboFix 09-02-28.01 - Aziz 2009-03-01 20:29:25.4 - NTFSx86 NETWORK
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.1535.1252 [GMT 1:00]
Lancé depuis: c:\documents and settings\Aziz\Bureau\ComboFix.exe
AV: avast! antivirus 4.8.1229 [VPS 090227-0] *On-access scanning enabled* (Updated)
AV: Norton Internet Security *On-access scanning enabled* (Updated)
FW: Kerio Personal Firewall *enabled*
FW: Norton Internet Security *enabled*
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\INSTALL.LOG
c:\windows\system32\tmp.reg
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-01 au 2009-03-01 ))))))))))))))))))))))))))))))))))))
.
2009-03-01 19:47 . 2009-03-01 19:49 <REP> d-------- C:\rsit
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-01 18:56 --------- d-----w c:\program files\WinamaxPoker
2009-03-01 18:49 --------- d-----w c:\program files\Trend Micro
2009-02-28 18:38 825 ----a-w c:\windows\system32\drivers\fwdrv.err
2009-02-27 19:12 --------- d-----w c:\documents and settings\Aziz\Application Data\utorrent
2009-02-19 08:16 --------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-02-11 09:19 38,496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-11 09:19 15,504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-01-16 20:15 3,594,752 ----a-w c:\windows\system32\dllcache\mshtml.dll
2008-12-20 22:47 826,368 ----a-w c:\windows\system32\wininet.dll
2008-12-20 22:47 826,368 ----a-w c:\windows\system32\dllcache\wininet.dll
2008-12-20 22:47 671,232 ----a-w c:\windows\system32\dllcache\mstime.dll
2008-12-20 22:47 477,696 ----a-w c:\windows\system32\dllcache\mshtmled.dll
2008-12-20 22:47 44,544 ----a-w c:\windows\system32\dllcache\pngfilt.dll
2008-12-20 22:47 233,472 ------w c:\windows\system32\dllcache\webcheck.dll
2008-12-20 22:47 193,024 ----a-w c:\windows\system32\dllcache\msrating.dll
2008-12-20 22:47 105,984 ------w c:\windows\system32\dllcache\url.dll
2008-12-20 22:47 102,912 ------w c:\windows\system32\dllcache\occache.dll
2008-12-20 22:47 1,160,192 ----a-w c:\windows\system32\dllcache\urlmon.dll
2008-12-19 09:11 70,656 ------w c:\windows\system32\dllcache\ie4uinit.exe
2008-12-19 09:10 13,824 ------w c:\windows\system32\dllcache\ieudinit.exe
2008-12-19 05:25 634,024 ------w c:\windows\system32\dllcache\iexplore.exe
2008-12-19 05:23 161,792 ------w c:\windows\system32\dllcache\ieakui.dll
2008-12-14 09:32 410,984 ----a-w c:\windows\system32\deploytk.dll
2008-12-11 10:57 333,952 ------w c:\windows\system32\dllcache\srv.sys
2008-10-25 23:15 22,328 ----a-w c:\documents and settings\Aziz\Application Data\PnkBstrK.sys
2007-07-26 16:11 134 ----a-w c:\documents and settings\Corinne\Application Data\wklnhst.dat
2007-03-13 12:14 1 -c--a-w c:\documents and settings\Aziz\SI.bin
2006-10-07 08:49 1,828 -c--a-w c:\documents and settings\Aziz\Application Data\wklnhst.dat
2008-10-05 05:21 67,696 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2008-10-05 05:21 54,376 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2008-10-05 05:21 34,952 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2008-10-05 05:21 46,720 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2008-10-05 05:21 172,144 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
2008-10-10 17:00 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008101020081011\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2007-09-06 136136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-01-29 180269]
"MMTray"="c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2006-01-17 135168]
"mmtask"="c:\program files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [2006-01-17 53248]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2006-03-18 184320]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-08-22 98304]
"PCMService"="c:\apps\Powercinema\PCMService.exe" [2005-01-28 110740]
"Motive SmartBridge"="c:\progra~1\NUMERI~1\MONASS~1\SMARTB~1\MotiveSB.exe" [2004-10-22 393216]
"ACTIVBOARD"="c:\apps\ABoard\ABoard.exe" [2003-05-02 24576]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-14 136600]
"CameraFixer"="c:\windows\CameraFixer.exe" [2006-10-09 20480]
"tsnpstd3"="c:\windows\tsnp325.exe" [2006-10-10 270336]
"snp325"="c:\windows\vsnp325.exe" [2006-10-10 827392]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-09-17 86016]
"SoundMan"="SOUNDMAN.EXE" [2004-09-10 c:\windows\SoundMan.exe]
"Raccourci vers la page des propriétés de High Definition Audio"="HDAudPropShortcut.exe" [2004-03-17 c:\windows\system32\Hdaudpropshortcut.exe]
"AlcWzrd"="ALCWZRD.EXE" [2004-09-15 c:\windows\ALCWZRD.EXE]
"nwiz"="nwiz.exe" [2008-09-17 c:\windows\system32\nwiz.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]
c:\docume~1\ALLUSE~1\MENUD~1\PROGRA~1\DMARR~1\
Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\APPS\\Inventime\\my.exe"=
"c:\\Program Files\\AOL 9.0\\waol.exe"=
"c:\\Program Files\\Windows Media Player\\wmplayer.exe"=
"c:\\Program Files\\THQ\\Dawn of War - Dark Crusade\\DarkCrusade.exe"=
"c:\\Program Files\\THQ\\Dawn of War\\W40k.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\APPS\\skype\\phone\\Skype.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Sunbelt Software\\Personal Firewall 4\\kpf4gui.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\FlashFXP\\FlashFXP.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"15555:TCP"= 15555:TCP:emule
"40662:TCP"= 40662:TCP:*:Disabled:Azureus
"18904:TCP"= 18904:TCP:BitComet 18904 TCP
"18904:UDP"= 18904:UDP:BitComet 18904 UDP
"25376:TCP"= 25376:TCP:BitComet 25376 TCP
"25376:UDP"= 25376:UDP:BitComet 25376 UDP
"24807:TCP"= 24807:TCP:BitComet 24807 TCP
"24807:UDP"= 24807:UDP:BitComet 24807 UDP
"27498:TCP"= 27498:TCP:BitComet 27498 TCP
"27498:UDP"= 27498:UDP:BitComet 27498 UDP
"23079:TCP"= 23079:TCP:BitComet 23079 TCP
"23079:UDP"= 23079:UDP:BitComet 23079 UDP
"56213:TCP"= 56213:TCP:Pando P2P TCP Listening Port
"56213:UDP"= 56213:UDP:Pando P2P UDP Listening Port
"13324:TCP"= 13324:TCP:BitComet 13324 TCP
"13324:UDP"= 13324:UDP:BitComet 13324 UDP
R1 fwdrv;Firewall Driver;c:\windows\system32\drivers\fwdrv.sys [2005-12-15 274432]
S1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-04-05 78416]
S1 khips;Kerio HIPS Driver;c:\windows\system32\drivers\khips.sys [2005-12-15 81920]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2008-04-05 20560]
S2 NwSapAgent;Agent SAP;c:\windows\system32\svchost.exe -k netsvcs [2004-08-16 14336]
S3 SNP325;USB PC Camera (SNPSTD325);c:\windows\system32\drivers\snp325.sys [2007-12-16 10218624]
.
Contenu du dossier 'Tâches planifiées'
2005-10-15 c:\windows\Tasks\Rappel d'enregistrement 3.job
- c:\windows\system32\OOBE\oobebaln.exe [2008-04-13 18:34]
.
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://www.google.fr/
uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = 127.0.0.1
IE: &MSN Search - c:\program files\MSN Toolbar Suite\TB\
02.05.0000.1105\fr-fr\msntb.dll/search.htm
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
DPF: {68C1822F-F5C7-4404-A73F-03C10E0E94DA} -
hxxp://www2.photoweb.fr/telechargement/Photoweb_uploader.cab
FF - ProfilePath - c:\documents and settings\Aziz\Application Data\Mozilla\Firefox\Profiles\lteq08gp.default\
FF - prefs.js: browser.startup.homepage -
www.google.fr
FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-01 20:31:14
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\MysqlInventime]
"ImagePath"="c:\apps\INVENT~1\mysql\bin\mysqld-nt --defaults-file=c:\apps\Inventime\mysql\my.ini MysqlInventime"
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-911548928-4235050573-1618012677-1006\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:3b,de,bd,94,3a,64,d8,7b,d1,40,46,98,ef,e6,52,1e,bb,89,1e,74,d4,36,be,
cb,2e,ad,04,c6,55,08,fb,32,9b,b7,23,87,4c,c4,72,c3,2b,38,58,2e,48,89,63,1a,\
"??"=hex:14,02,d2,88,28,70,d4,e2,34,3b,df,b3,28,68,7e,aa
[HKEY_USERS\S-1-5-21-911548928-4235050573-1618012677-1006\Software\SecuROM\License information*]
"datasecu"=hex:c5,86,a6,25,a6,a9,23,7a,4b,af,a9,4e,ca,b7,97,fb,52,c6,9a,bf,64,
68,56,78,d9,bb,0c,ca,7b,f5,10,10,6e,bc,a8,d7,36,04,ce,b7,72,d7,1c,6a,8b,ae,\
"rkeysecu"=hex:5a,05,32,8a,97,26,87,ab,15,46,98,61,7a,c3,62,84
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"C040211900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
.
Heure de fin: 2009-03-01 20:32:36
ComboFix-quarantined-files.txt 2009-03-01 19:32:23
Avant-CF: 42 600 714 240 octets libres
Après-CF: 42,741,182,464 octets libres
Current=5 Default=5 Failed=3 LastKnownGood=6 Sets=1,2,3,4,5,6
190 --- E O F --- 2009-02-24 23:29:53