Et voila le rapport Combofix :
ComboFix 09-09-18.02 - DO 20/09/2009 23:02.1.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.765.302 [GMT 2:00]
Lancé depuis: c:\documents and settings\DO\Bureau\Combo-Fix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: AntiVir PersonalEdition Classic Virus Protection *On-access scanning enabled* (Updated) {00000000-0000-0000-0000-000000000000}
AV: AntiVir PersonalEdition Classic Virus Protection *On-access scanning enabled* (Updated) {804E58E8-FFA4-00DA-0D24-347CA8A3377C}
AV: AntiVir PersonalEdition Classic Virus Protection *On-access scanning enabled* (Updated) {804E58E8-FFA4-00EB-0D24-347CA8A3377C}
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\S-1-5-21-329068152-1409082233-1417001333-1003
c:\windows\Downloaded Program Files\bdcore.dll
c:\windows\Downloaded Program Files\libfn.dll
c:\windows\Installer\1328b4c.msi
c:\windows\Installer\22711.msi
c:\windows\Installer\2271e.msi
c:\windows\Installer\22726.msi
c:\windows\Installer\22732.msi
c:\windows\Installer\2273a.msi
c:\windows\Installer\2a0e9af.msp
c:\windows\Installer\f7f918.msi
c:\windows\Installer\f7f91e.msi
c:\windows\patch.exe
c:\windows\system32\open.ico
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-08-20 au 2009-09-20 ))))))))))))))))))))))))))))))))))))
.
2009-09-20 17:44 . 2009-09-20 19:28 -------- d-----w- c:\windows\BDOSCAN8
2009-09-20 17:44 . 2009-09-20 17:44 -------- d-----w- c:\windows\LastGood
2009-09-19 21:30 . 2009-09-19 21:30 -------- d-----w- c:\documents and settings\DO\Application Data\ScanSoft
2009-09-19 19:19 . 2009-09-19 19:25 -------- d-----w- c:\documents and settings\DO\Application Data\GlarySoft
2009-09-19 19:15 . 2009-09-19 19:15 -------- d-----w- c:\program files\Glary Utilities
2009-09-18 04:22 . 2009-09-18 04:22 -------- d-----w- c:\program files\Trend Micro
2009-09-16 11:12 . 2009-09-16 11:12 -------- d-----w- c:\program files\ESET
2009-09-15 20:53 . 2009-09-20 18:35 -------- d-----w- C:\$AVG8.VAULT$
2009-09-15 20:43 . 2009-09-15 20:43 -------- d-----w- c:\documents and settings\DO\Local Settings\Application Data\AVG Security Toolbar
2009-09-15 20:19 . 2009-09-15 20:19 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-09-15 20:19 . 2009-09-15 20:19 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-09-15 20:19 . 2009-09-15 20:19 335240 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-09-15 20:19 . 2009-09-15 20:19 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-09-15 20:19 . 2009-09-20 16:34 -------- d-----w- c:\windows\system32\drivers\Avg
2009-09-15 20:19 . 2009-09-16 11:07 -------- d-----w- c:\documents and settings\All Users\Application Data\AVG Security Toolbar
2009-09-15 20:18 . 2009-09-15 20:18 -------- d-----w- c:\program files\AVG
2009-09-15 20:18 . 2009-09-15 20:18 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-09-15 18:49 . 2009-09-15 18:49 -------- d-----w- c:\documents and settings\DO\Application Data\Malwarebytes
2009-09-15 18:49 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-15 18:49 . 2009-09-15 18:49 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-15 18:49 . 2009-09-15 18:49 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-15 18:49 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-15 18:33 . 2009-09-15 19:37 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8ls
2009-09-15 18:29 . 2009-09-15 18:29 -------- d-----w- c:\documents and settings\DO\Application Data\AVG8
2009-09-14 19:29 . 2009-09-19 22:24 -------- d-----w- c:\documents and settings\DO\Application Data\vlc
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-20 21:09 . 2009-05-11 20:03 39126560 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-09-20 21:08 . 2009-05-11 20:03 396320 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-09-20 17:38 . 2009-05-24 21:33 -------- d-----w- c:\program files\Steam
2009-09-20 17:12 . 2009-05-11 20:03 507284 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-09-20 17:12 . 2009-05-11 20:03 37340 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-09-20 17:09 . 2006-06-12 21:18 5632 --sha-w- c:\program files\Thumbs.db
2009-09-20 06:25 . 2005-06-10 18:16 -------- d-----w- c:\program files\Mozilla Thunderbird
2009-09-20 06:24 . 2002-12-29 12:00 -------- d-----w- c:\program files\Microsoft Money
2009-09-19 21:16 . 2006-03-31 20:55 -------- d-----w- c:\program files\Fnacmusic
2009-09-19 21:13 . 2008-10-05 12:15 -------- d-----w- c:\program files\TF1Vision
2009-09-19 19:36 . 2002-08-30 12:00 62654 ----a-w- c:\windows\system32\perfc00C.dat
2009-09-19 19:36 . 2002-08-30 12:00 443048 ----a-w- c:\windows\system32\perfh00C.dat
2009-09-15 05:58 . 2009-02-01 09:10 -------- d-----w- c:\program files\MinitelADSL
2009-09-10 10:29 . 2009-02-21 07:31 -------- d-----w- c:\program files\Microsoft Silverlight
2009-08-28 20:09 . 2005-02-15 21:31 -------- d-----w- c:\program files\Java
2009-08-25 21:37 . 2009-08-09 19:42 -------- d-----w- c:\documents and settings\DO\Application Data\dvdcss
2009-08-22 21:21 . 2002-10-31 12:08 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-18 18:46 . 2009-05-02 20:18 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2009-08-15 20:56 . 2006-11-05 23:40 -------- d-----w- c:\program files\FreeUndelete
2009-08-15 20:55 . 2004-05-02 14:16 -------- d-----w- c:\program files\Canon
2009-08-15 14:16 . 2009-03-15 06:49 -------- d-----w- c:\documents and settings\DO\Application Data\VSO
2009-08-05 19:40 . 2002-12-27 22:16 -------- d-----w- c:\program files\Fichiers communs\Adobe
2009-08-05 09:06 . 2004-08-03 22:54 205312 ----a-w- c:\windows\system32\mswebdvd.dll
2009-07-25 03:23 . 2008-11-25 19:54 411368 ----a-w- c:\windows\system32\deploytk.dll
2009-07-17 18:56 . 2004-08-03 22:54 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-13 21:43 . 2004-08-03 22:54 286208 ----a-w- c:\windows\system32\wmpdxm.dll
2009-06-29 15:57 . 2004-08-03 22:54 827392 ----a-w- c:\windows\system32\wininet.dll
2009-06-29 15:57 . 2004-08-03 22:54 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-06-29 15:57 . 2004-08-03 22:54 17408 ------w- c:\windows\system32\corpol.dll
2009-06-25 18:36 . 2004-08-03 22:54 95744 ----a-w- c:\windows\system32\mqsec.dll
2009-06-25 18:36 . 2004-08-03 22:54 661504 ----a-w- c:\windows\system32\mqqm.dll
2009-06-25 18:36 . 2004-08-03 22:54 527360 ----a-w- c:\windows\system32\mqutil.dll
2009-06-25 18:36 . 2004-08-03 22:54 517120 ----a-w- c:\windows\system32\mqsnap.dll
2009-06-25 18:36 . 2004-08-03 22:54 48640 ----a-w- c:\windows\system32\mqupgrd.dll
2009-06-25 18:36 . 2004-08-03 22:54 186880 ----a-w- c:\windows\system32\mqtrig.dll
2009-06-25 18:36 . 2004-08-03 22:54 177152 ----a-w- c:\windows\system32\mqrt.dll
2009-06-25 18:36 . 2004-08-03 22:54 123392 ----a-w- c:\windows\system32\mqrtdep.dll
2009-06-25 18:36 . 2004-08-03 22:54 47104 ----a-w- c:\windows\system32\mqdscli.dll
2009-06-25 18:36 . 2004-08-03 22:54 225280 ----a-w- c:\windows\system32\mqoa.dll
2009-06-25 18:36 . 2004-08-03 22:54 16896 ----a-w- c:\windows\system32\mqise.dll
2009-06-25 18:36 . 2004-08-03 22:54 138240 ----a-w- c:\windows\system32\mqad.dll
2009-02-24 19:34 . 2009-02-24 19:34 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-02-24 19:34 . 2009-02-24 19:34 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{A3BC75A2-1F87-4686-AA43-5347D756017C}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{a3bc75a2-1f87-4686-aa43-5347d756017c}]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}]
2009-07-24 07:55 1090816 ----a-w- c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"= "c:\program files\AVG\AVG8\Toolbar\IEToolbar.dll" [2009-07-24 1090816]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="\Program\" [X]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
"NoSpam"="c:\program files\StofWare\NoSpam\NoSpam.exe" [2003-08-31 1230336]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\WCESCOMM.EXE" [2004-02-24 401491]
"Steam"="c:\program files\Steam\Steam.exe" [2009-06-14 1217784]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PinnacleDriverCheck"="c:\windows\System32\PSDrvCheck.exe" [2003-08-28 396800]
"pdfc"="c:\program files\Adolix\Adolix PDF Converter\pdfcload.exe" [2004-09-03 77824]
"ToUcamVProperty"="c:\progra~1\PHILIP~1\VProperty.exe" [2003-04-02 131072]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2006-03-28 622592]
"SetDefPrt"="c:\program files\Brother\Brmfl06a\BrStDvPt.exe" [2005-01-26 49152]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2006-04-10 61440]
"fssui"="c:\program files\Windows Live\Family Safety\fsui.exe" [2009-02-06 454000]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-14 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-09-15 2007832]
"Logitech Utility"="Logi_MwX.Exe" - c:\windows\LOGI_MWX.EXE [2003-12-17 19968]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2005-2-13 450560]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-09-15 20:19 11952 ----a-w- c:\windows\system32\avgrsstx.dll
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winboot
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"MoneyStartUp10.0"="c:\program files\Microsoft Money\System\Activation.exe"
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
"SSBkgdUpdate"="c:\program files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
"PaperPort PTD"=c:\program files\ScanSoft\PaperPort\pptd40nt.exe
"IndexSearch"=c:\program files\ScanSoft\PaperPort\IndexSearch.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"4662:TCP"= 4662:TCP:EMULE TCP
"4672:UDP"= 4672:UDP:EMULE UDP
R0 pavboot;pavboot;c:\windows\system32\drivers\pavboot.sys [12/05/2009 18:28 28544]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [15/09/2009 22:19 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [15/09/2009 22:19 108552]
R2 AntiVirSchedulerService;Avira AntiVir Planificateur;c:\program files\Avira\AntiVir Desktop\sched.exe [02/05/2009 22:18 108289]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [15/09/2009 22:18 297752]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [31/01/2009 09:23 55136]
R2 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 19:08 533360]
R3 camvid20;Philips ToUcam Camera; Video;c:\windows\system32\drivers\camdrv21.sys [14/06/2004 19:12 223232]
R3 fbxusb;Carte réseau virtuelle FreeBox USB;c:\windows\system32\drivers\fbxusb32.sys [20/10/2004 15:23 21344]
S3 adiusbae;USB ADSL LAN Adapter;c:\windows\system32\DRIVERS\adiusbae.sys --> c:\windows\system32\DRIVERS\adiusbae.sys [?]
S3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys [09/05/2006 17:50 34944]
S3 Ntmarbcnkvcd;Ntmarbcnkvcd; [x]
.
Contenu du dossier 'Tâches planifiées'
2009-09-20 c:\windows\Tasks\GlaryInitialize.job
- c:\program files\Glary Utilities\initialize.exe [2009-09-19 14:09]
2009-09-20 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-22 20:18]
.
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://portail.free.fr/
uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = localhost
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: DirectAnimation Java Classes -
file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java -
file://c:\windows\Java\classes\xmldso.cab
DPF: {09C21411-B9A2-4DE6-8416-4E3B58577BE0} -
hxxp://minitelweb.minitel.com/imin_data/ocx/MDM.cab
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -
hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} -
hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {D28C3640-A6D7-4668-A53C-07A9CF67D157} -
hxxps://www.fnacmusic.com/telechargementFnacmusic/FnacComposant.cab
DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} -
hxxp://asp06.photoprintit.de/microsite/defaults/activex/ImageUploader3.cab
FF - ProfilePath - c:\documents and settings\DO\Application Data\Mozilla\Firefox\Profiles\07cmlru5.default\
FF - prefs.js: browser.startup.homepage -
hxxp://www.free.fr/
FF - prefs.js: keyword.URL -
hxxp://fr.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type=yahoo_avg_hs2-t(...)
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils2.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils3.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\IGeared_tavgp_xputils35.dll
FF - component: c:\program files\AVG\AVG8\Toolbar\Firefox\avg@igeared\components\xpavgtbapi.dll
FF - plugin: c:\documents and settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npzylomgamesplayer.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-20 23:08
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
ToUcamVProperty = c:\progra~1\PHILIP~1\VProperty.exe??~?1?\?V?P?r?o?p?e?r?t?y?.?e?x?e???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B949B43D-1810-C590-5BA3D3FB47E71A33}\{C4C70B00-DFFA-18F9-0AB85D5A53F53FFC}\{5A6DA99E-454A-644B-5884B00FD9434DA2}*]
"WVZENWCHWFKXMRXM1FQWBAYGMD1"=hex:01,00,01,00,00,00,00,00,fa,de,c6,7c,16,d0,d3,
6d,35,81,92,71,e8,29,5a,84,14,35,16,70,d8,6e,ff,61
.
Heure de fin: 2009-09-20 23:13
ComboFix-quarantined-files.txt 2009-09-20 21:12
Avant-CF: 8 780 001 280 octets libres
Après-CF: 8 873 975 808 octets libres
WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /fastdetect /noexecute=optin
239 --- E O F --- 2009-09-15 23:21