trop tard je l'ai desinstallé ! voici le rapport de combofix : (par ailleurs, après le redemarage aucune traces du virus.. .)
ComboFix 09-03-01.01 - Internet 2009-03-02 14:14:23.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.511.236 [GMT 1:00]
Lancé depuis: c:\documents and settings\Internet\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\docume~1\Internet\APPLIC~1\MFCDBI~1\Dart style remote.exe
C:\Documents
c:\program files\Temporary
c:\program files\Temporary\kernInst.MSNFix
c:\program files\Yahoo!\Messenger\ypager.exe
c:\windows\system32\404Fix.exe
c:\windows\system32\Agent.OMZ.Fix.exe
c:\windows\system32\dumphive.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\IEDFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\Process.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
c:\windows\system32\VACFix.exe
c:\windows\system32\VCCLSID.exe
c:\windows\system32\WS2Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_BOONTY_GAMES
-------\Service_Boonty Games
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-02 au 2009-03-02 ))))))))))))))))))))))))))))))))))))
.
2009-03-02 11:41 . 2009-03-02 11:46 <REP> d-------- C:\ToolBar SD
2009-03-02 11:21 . 2009-03-02 11:50 0 --a------ c:\windows\system32\tmp.MSNFix
2009-03-02 10:16 . 2009-03-02 10:16 <REP> d-------- c:\program files\CCleaner
2009-03-02 09:59 . 2009-03-02 12:58 <REP> d-------- c:\program files\FindyKill
2009-03-02 09:51 . 2009-03-02 09:52 <REP> d-------- C:\GenProc
2009-03-02 09:00 . 2009-03-02 09:00 <REP> d-------- C:\bureau
2009-03-01 22:46 . 2009-03-01 23:06 <REP> d-------- C:\SDFix
2009-03-01 22:22 . 2009-03-01 22:22 <REP> d-------- c:\documents and settings\Internet\Application Data\3DFA
2009-03-01 22:18 . 2009-03-01 22:27 <REP> d-------- c:\program files\3D Flash Animator 4.9.8.7
2009-03-01 22:03 . 2009-03-01 22:04 <REP> d-------- c:\program files\Anim-FX
2009-02-27 11:20 . 2009-02-27 11:20 <REP> d-------- c:\program files\Karasoft
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-02 13:16 --------- d-----w c:\program files\Wanadoo
2009-03-02 13:15 --------- d-----w c:\documents and settings\Internet\Application Data\Mfcd Bib
2009-03-02 10:50 --------- d-----w c:\program files\Google
2009-03-02 07:58 --------- d-----w c:\program files\Trend Micro
2009-03-01 21:15 --------- d-----w c:\program files\eMule
2009-03-01 15:29 --------- d-----w c:\documents and settings\Internet\Application Data\FileZilla
2009-02-27 10:46 --------- d--h--w c:\program files\InstallShield Installation Information
2009-02-25 20:25 --------- d-----w c:\documents and settings\Internet\Application Data\OpenOffice.org2
2009-02-23 12:39 --------- d-----w c:\program files\Messenger Plus! Live
2009-01-18 11:01 --------- d-----w c:\program files\Alwil Software
2009-01-02 11:29 53,248 ----a-w c:\documents and settings\Internet\lametritonus_en.dll
2009-01-02 11:29 162,304 ----a-w c:\documents and settings\Internet\lame_enc_en.dll
2008-02-08 21:21 357 ----a-w c:\documents and settings\Internet\.cb_layout.bin
2008-01-26 16:06 1,114 ----a-w c:\documents and settings\Internet\Application Data\wklnhst.dat
2007-06-25 14:15 20 ---h--w c:\documents and settings\All Users\Application Data\PKP_DLec.DAT
2004-07-22 08:51 3,432,656 ----a-w c:\program files\ManagedDX.CAB
2004-07-16 12:30 3,858 ----a-w c:\program files\directx redist.txt
2006-03-12 18:24 56 --sh--r c:\windows\system32\3378B53900.sys
2006-03-12 18:24 1,682 --sha-w c:\windows\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"TheTurtle"="c:\program files\TheTurtle\TheTurtle.exe" [2005-09-15 815104]
"DAEMON Tools"="c:\program files\DAEMON Tools\daemon.exe" [2007-04-03 165784]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
"EPSON SX100 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATIEDE.EXE" [2008-02-05 188928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-08-11 7630848]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-05-27 413696]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableNotifications"= 1
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Macromedia\\Dreamweaver 2\\Dreamweaver.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Mythology\\aom.exe"=
"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\FileZilla Client\\filezilla.exe"=
"c:\\wamp\\bin\\apache\\Apache2.2.11\\bin\\httpd.exe"=
"c:\\Documents and Settings\\Internet\\Mes documents\\Olivier\\freezer v1.4 fr\\freezer.exe"=
R2 PoliceService;PoliceService;c:\windows\system32\srksrv.exe [2008-08-20 453120]
S3 s716bus;Sony Ericsson Device 716 driver (WDM);c:\windows\system32\drivers\s716bus.sys [2008-06-18 83208]
S3 s716mdfl;Sony Ericsson Device 716 USB WMC Modem Filter;c:\windows\system32\drivers\s716mdfl.sys [2008-06-18 15112]
S3 s716mdm;Sony Ericsson Device 716 USB WMC Modem Driver;c:\windows\system32\drivers\s716mdm.sys [2008-06-18 108552]
S3 s716mgmt;Sony Ericsson Device 716 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s716mgmt.sys [2008-06-18 100360]
S3 s716nd5;Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (NDIS);c:\windows\system32\drivers\s716nd5.sys [2008-06-18 23176]
S3 s716obex;Sony Ericsson Device 716 USB WMC OBEX Interface;c:\windows\system32\drivers\s716obex.sys [2008-06-18 98568]
S3 s716unic;Sony Ericsson Device 716 USB Ethernet Emulation SEMC716 (WDM);c:\windows\system32\drivers\s716unic.sys [2008-06-18 98952]
S3 sea3bus;Sony Ericsson Device 0A3 driver (WDM);c:\windows\system32\drivers\sea3bus.sys [2007-01-26 61600]
S3 sea3mdfl;Sony Ericsson Device 0A3 USB WMC Modem Filter;c:\windows\system32\drivers\sea3mdfl.sys [2007-01-26 9392]
S3 sea3mdm;Sony Ericsson Device 0A3 USB WMC Modem Driver;c:\windows\system32\drivers\sea3mdm.sys [2007-01-26 97152]
S3 w200bus;Sony Ericsson W200 driver (WDM);c:\windows\system32\drivers\w200bus.sys [2007-04-17 61504]
S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;c:\windows\system32\drivers\w200mdfl.sys [2007-04-17 9328]
S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;c:\windows\system32\drivers\w200mdm.sys [2007-04-17 97056]
S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\w200mgmt.sys [2007-04-17 88560]
S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface;c:\windows\system32\drivers\w200obex.sys [2007-04-17 86368]
.
Contenu du dossier 'Tâches planifiées'
2009-03-02 c:\windows\Tasks\HP Usg Daily.job
- c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\pexpress\hphped05.exe [2004-06-07 05:53]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-fsc-reminder.exe - c:\windows\reminder\fsc-reminder.exe
HKCU-Run-Yahoo! Pager - c:\program files\Yahoo!\Messenger\ypager.exe
HKCU-Run-typedrive - c:\docume~1\Internet\APPLIC~1\MFCDBI~1\Dart style remote.exe
HKCU-Run-OM2_Monitor - c:\program files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
HKLM-Run-1utccag.exe - c:\program files\Windows Security Officer\utccag.exe
.
------- Examen supplémentaire -------
.
mWindow Title =
uInternet Connection Wizard,ShellNext = iexplore
FF - ProfilePath - c:\documents and settings\Internet\Application Data\Mozilla\Firefox\Profiles\
01jtc0on.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.fr/firefox
FF - prefs.js: keyword.URL -
hxxp://search.live.com/results.aspx?mkt=fr-fr&FORM=MIMWA1&q=
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAdbESD.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-02 14:19:52
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(740)
c:\program files\TheTurtle\rkmt.dll
- - - - - - - > 'lsass.exe'(796)
c:\program files\TheTurtle\rkmt.dll
- - - - - - - > 'csrss.exe'(712)
c:\program files\TheTurtle\rkmt.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\HPZipm12.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2009-03-02 14:25:08 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-03-02 13:24:39
Avant-CF: 130 795 212 800 octets libres
Après-CF: 131,638,468,608 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
184 --- E O F --- 2009-02-25 14:12:00