salut bzhatao
merci de ta réponse voilà le rapport combofix :
ComboFix 09-01-13.04 - Lucas 2009-01-14 11:42:04.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.510.216 [GMT 1:00]
LancÚ depuis: c:\documents and settings\Lucas\Bureau\ComboFix.exe
AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Outdated)
* Un nouveau point de restauration a ÚtÚ crÚÚ
[B]AVERTISSEMENT - LA CONSOLE DE R+CUP+RATION N'EST PAS INSTALL+E SUR CETTE MACHINE !![/B]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Lucas\Local Settings\Application Data\lvlefacmxp_navfx.dat
c:\documents and settings\Lucas\Local Settings\Application Data\qqace_navfx.dat
c:\documents and settings\Lucas\Local Settings\Application Data\smgykwm.dat
c:\documents and settings\Lucas\Local Settings\Application Data\smgykwm.exe
c:\documents and settings\Lucas\Local Settings\Application Data\smgykwm_nav.dat
c:\documents and settings\Lucas\Local Settings\Application Data\smgykwm_navps.dat
c:\windows\cdmxtras
.
((((((((((((((((((((((((((((( Fichiers crÚÚs du 2008-12-14 au 2009-01-14 ))))))))))))))))))))))))))))))))))))
.
2009-01-13 19:07 . 2009-01-13 19:07 <REP> d-------- c:\documents and settings\Lucas\Application Data\DivX
2009-01-13 16:01 . 2008-11-06 17:37 129,784 --------- c:\windows\SYSTEM32\pxafs.dll
2009-01-13 16:01 . 2008-11-06 17:37 9,464 --------- c:\windows\SYSTEM32\DRIVERS\cdralw2k.sys
2009-01-13 16:01 . 2008-11-06 17:37 9,336 --------- c:\windows\SYSTEM32\DRIVERS\cdr4_xp.sys
2009-01-13 16:00 . 2009-01-13 16:01 <REP> d-------- c:\program files\DivX
2009-01-10 16:37 . 2009-01-10 16:37 54,156 --ah----- c:\windows\QTFont.qfn
2009-01-10 16:37 . 2009-01-10 16:37 1,409 --a------ c:\windows\QTFont.for
2009-01-06 03:00 . 2009-01-06 03:12 1,355 --a------ c:\windows\imsins.BAK
2009-01-06 00:58 . 2009-01-06 00:58 <REP> d-------- c:\program files\Bayo
2009-01-06 00:52 . 2009-01-06 00:52 410,984 --a------ c:\windows\SYSTEM32\deploytk.dll
2009-01-06 00:52 . 2009-01-06 00:52 73,728 --a------ c:\windows\SYSTEM32\javacpl.cpl
2009-01-05 23:44 . 2009-01-05 23:44 <REP> d-------- c:\program files\Ad-remover
2009-01-05 19:30 . 2009-01-05 19:30 <REP> d-------- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-01-05 13:41 . 2008-09-08 11:41 333,824 --------- c:\windows\SYSTEM32\DLLCACHE\srv.sys
2009-01-05 13:37 . 2008-09-15 16:26 1,846,528 --------- c:\windows\SYSTEM32\DLLCACHE\win32k.sys
2009-01-05 13:36 . 2008-08-14 14:23 2,191,232 --------- c:\windows\SYSTEM32\DLLCACHE\ntoskrnl.exe
2009-01-05 13:36 . 2008-08-14 14:23 2,147,328 --------- c:\windows\SYSTEM32\DLLCACHE\ntkrnlmp.exe
2009-01-05 13:36 . 2008-08-14 14:23 2,068,096 --------- c:\windows\SYSTEM32\DLLCACHE\ntkrnlpa.exe
2009-01-05 13:36 . 2008-08-14 14:23 2,025,984 --------- c:\windows\SYSTEM32\DLLCACHE\ntkrpamp.exe
2009-01-05 13:35 . 2008-10-24 12:21 455,296 --------- c:\windows\SYSTEM32\DLLCACHE\mrxsmb.sys
2009-01-05 13:32 . 2008-09-04 18:16 1,106,944 --------- c:\windows\SYSTEM32\DLLCACHE\msxml3.dll
2009-01-05 13:32 . 2008-10-15 17:35 337,408 --------- c:\windows\SYSTEM32\DLLCACHE\netapi32.dll
2009-01-05 13:09 . 2009-01-05 13:09 <REP> d-------- c:\program files\Trend Micro
2009-01-05 12:35 . 2009-01-05 12:35 <REP> d-------- c:\windows\SYSTEM32\fr
2009-01-05 12:35 . 2009-01-05 12:35 <REP> d-------- c:\windows\l2schemas
2009-01-05 11:50 . 2009-01-05 11:50 <REP> d-------- c:\program files\Fichiers communs\Adobe AIR
2009-01-05 11:21 . 2009-01-05 11:55 <REP> d-------- c:\program files\NOS
2009-01-05 11:21 . 2009-01-05 11:55 <REP> d-------- c:\documents and settings\All Users\Application Data\NOS
2009-01-05 00:28 . 2009-01-05 00:28 <REP> d-------- c:\documents and settings\Lucas\Application Data\Malwarebytes
2009-01-05 00:27 . 2009-01-05 09:09 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-01-05 00:27 . 2009-01-05 00:27 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-05 00:27 . 2009-01-04 18:38 38,496 --a------ c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys
2009-01-05 00:27 . 2009-01-04 18:38 15,504 --a------ c:\windows\SYSTEM32\DRIVERS\mbam.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-06 10:57 --------- d--h--w c:\program files\InstallShield Installation Information
2009-01-06 10:49 --------- d-----w c:\program files\Sony
2009-01-05 23:57 --------- d-----w c:\program files\CCleaner
2009-01-05 23:52 --------- d-----w c:\program files\Java
2009-01-05 10:49 --------- d-----w c:\program files\Fichiers communs\Adobe
2009-01-05 10:17 --------- d-----w c:\program files\Active WebCam
2008-12-13 06:37 3,593,216 ------w c:\windows\SYSTEM32\DLLCACHE\mshtml.dll
2008-12-12 11:14 --------- d-----w c:\program files\eMule
2008-12-11 00:33 86,016 ----a-w c:\windows\SYSTEM32\dpl100.dll
2008-12-11 00:33 200,704 ----a-w c:\windows\SYSTEM32\dtu100.dll
2008-12-09 02:28 593,920 ----a-w c:\windows\SYSTEM32\dpuGUI11.dll
2008-12-09 02:28 57,344 ----a-w c:\windows\SYSTEM32\dpv11.dll
2008-12-09 02:28 344,064 ----a-w c:\windows\SYSTEM32\dpus11.dll
2008-12-09 02:28 294,912 ----a-w c:\windows\SYSTEM32\dpu11.dll
2008-11-28 17:15 --------- d-----w c:\program files\Microsoft Silverlight
2008-11-06 16:37 524,288 ----a-w c:\windows\SYSTEM32\DivXsm.exe
2008-11-06 16:37 3,596,288 ----a-w c:\windows\SYSTEM32\qt-dx331.dll
2008-11-06 16:37 120,056 ------w c:\windows\SYSTEM32\pxcpyi64.exe
2008-11-06 16:37 118,520 ------w c:\windows\SYSTEM32\pxinsi64.exe
2008-11-06 16:35 200,704 ----a-w c:\windows\SYSTEM32\ssldivx.dll
2008-11-06 16:35 1,044,480 ----a-w c:\windows\SYSTEM32\libdivx.dll
2008-11-06 16:33 823,296 ----a-w c:\windows\SYSTEM32\divx_xx0c.dll
2008-11-06 16:33 823,296 ----a-w c:\windows\SYSTEM32\divx_xx07.dll
2008-11-06 16:33 815,104 ----a-w c:\windows\SYSTEM32\divx_xx0a.dll
2008-11-06 16:33 802,816 ----a-w c:\windows\SYSTEM32\divx_xx11.dll
2008-11-06 16:33 684,032 ----a-w c:\windows\SYSTEM32\DivX.dll
2008-11-06 16:33 12,288 ----a-w c:\windows\SYSTEM32\DivXWMPExtType.dll
2008-10-23 12:36 286,720 ----a-w c:\windows\SYSTEM32\gdi32.dll
2008-10-23 12:36 286,720 ------w c:\windows\SYSTEM32\DLLCACHE\gdi32.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\SYSTEM32\wuweb.dll
2008-10-16 13:13 202,776 ----a-w c:\windows\SYSTEM32\DLLCACHE\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\SYSTEM32\wuaueng.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows\SYSTEM32\DLLCACHE\wuaueng.dll
2008-10-16 13:12 70,656 ------w c:\windows\SYSTEM32\DLLCACHE\ie4uinit.exe
2008-10-16 13:12 561,688 ----a-w c:\windows\SYSTEM32\wuapi.dll
2008-10-16 13:12 561,688 ----a-w c:\windows\SYSTEM32\DLLCACHE\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\SYSTEM32\wucltui.dll
2008-10-16 13:12 323,608 ----a-w c:\windows\SYSTEM32\DLLCACHE\wucltui.dll
2008-10-16 13:11 13,824 ------w c:\windows\SYSTEM32\DLLCACHE\ieudinit.exe
2008-10-16 13:09 92,696 ----a-w c:\windows\SYSTEM32\DLLCACHE\cdm.dll
2008-10-16 13:09 92,696 ----a-w c:\windows\SYSTEM32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows\SYSTEM32\wuauclt.exe
2008-10-16 13:09 51,224 ----a-w c:\windows\SYSTEM32\DLLCACHE\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows\SYSTEM32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\SYSTEM32\wups.dll
2008-10-16 13:08 34,328 ----a-w c:\windows\SYSTEM32\DLLCACHE\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows\SYSTEM32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows\SYSTEM32\muweb.dll
2008-10-15 07:06 633,632 ------w c:\windows\SYSTEM32\DLLCACHE\iexplore.exe
2008-10-15 07:04 161,792 ------w c:\windows\SYSTEM32\DLLCACHE\ieakui.dll
2008-02-01 16:44 33,024 ----a-w c:\documents and settings\Lucas\Application Data\GDIPFONTCACHEV1.DAT
2005-04-24 20:30 25,677 --sh--w c:\windows\Registration\drahcbdo.bak1
2005-05-04 04:50 374,450 --sh--w c:\windows\Registration\drahcbdo.bak2
2005-05-08 10:01 374,519 --sh--w c:\windows\Registration\drahcbdo.ini2
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ÚlÚments vides & les ÚlÚments initiaux lÚgitimes ne sont pas listÚs
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint\Apoint.exe" [2004-02-02 155648]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2003-10-27 118784]
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-06 136600]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring]
2004-01-12 06:55 110592 c:\windows\SYSTEM32\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"VIDC.VP40"= vp4vfw.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\WINDOWS\\PCHealth\\HelpCtr\\Binaries\\helpctr.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\PPLive\\PPLive.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Media Player Classic\\mplayerc.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"13466:TCP"= 13466:TCP:BitComet 13466 TCP
"13466:UDP"= 13466:UDP:BitComet 13466 UDP
R3 {E2B953A7-195A-44F9-9BA3-3D5F4E32BB55};AIM 3.0 Part 01 Codec Driver CH-7009-B;c:\windows\SYSTEM32\DRIVERS\wA301b.sys [1980-01-01 33847]
S3 camvid20;Philips ToUcam Camera; Video;c:\windows\SYSTEM32\DRIVERS\camdrv21.sys [2005-11-10 223232]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;c:\windows\SYSTEM32\DRIVERS\fbxusb32.sys [2004-10-20 21344]
S3 SAFAUSB;Voice Tracer Comm. driver;c:\windows\SYSTEM32\DRIVERS\VocTrace.sys [2004-12-28 16035]
.
Contenu du dossier 'TÔches planifiÚes'
2008-10-08 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 13:57]
2005-10-20 c:\windows\Tasks\Pinball.job
- c:\progra~1\WINDOW~1\Pinball\PINBALL.EXE [2008-04-14 03:34]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-smgykwm - c:\documents and settings\lucas\local settings\application data\smgykwm.exe
HKLM-Run-ISUSPM Startup - c:\program files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe
.
------- Examen supplÚmentaire -------
.
uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mSearch Bar =
uInternet Connection Wizard,ShellNext =
hxxp://www.euro.dell.com/countries/fr/fra/gen/default.htm
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Lucas\Application Data\Mozilla\Firefox\Profiles\hw4zrh1a.Utilisateur par défaut\
FF - prefs.js: browser.search.defaulturl -
hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.fr
FF - prefs.js: keyword.URL -
hxxp://search.yahoo.com/search?ei=UTF-8&fr=vmn&type=vendio&p=
FF - plugin: c:\program files\Mozilla Firefox\plugins\npgcplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-01-14 11:45:56
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachÚs ...
Recherche d'ÚlÚments en dÚmarrage automatique cachÚs ...
Recherche de fichiers cachÚs ...
Scan terminÚ avec succÞs
Fichiers cachÚs: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-2649534831-3281732765-1439617664-1005\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:1e,fc,79,5f,8c,41,98,d0,4e,12,82,db,0c,d1,fc,c0,e3,e0,1f,40,0b,
4a,65,d5,2b,1e,f8,fd,2d,32,61,68,14,8f,4c,5a,3b,33,94,79,9c,9b,67,a6,b5,3d,\
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
"C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:1e,fc,79,5f,8c,41,98,d0,4e,12,82,db,0c,d1,fc,c0,e3,e0,1f,40,0b,
4a,65,d5,2b,1e,f8,fd,2d,32,61,68,14,8f,4c,5a,3b,33,94,79,9c,9b,67,a6,b5,3d,\
.
--------------------- DLLs chargÚes dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(760)
c:\windows\System32\LgNotify.dll
c:\windows\system32\igfxsrvc.dll
c:\windows\system32\hccutils.DLL
.
Heure de fin: 2009-01-14 11:48:52
ComboFix-quarantined-files.txt 2009-01-14 10:48:18
Avant-CF: 7 717 122 048 octets libres
AprÞs-CF: 7,811,502,080 octets libres
214 --- E O F --- 2009-01-06 02:12:58