et voici le rapport pour combofix :
* Création d'un nouveau point de restauration
[color=red]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/color]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\dcbeg.ini
C:\WINDOWS\system32\dcbeg.ini2
C:\WINDOWS\system32\khcnayei.ini
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-01-20 to 2008-02-20 ))))))))))))))))))))))))))))))))))))
.
2008-02-19 18:50 . 2008-02-19 18:51 <REP> d-------- C:\WINDOWS\ERUNT
2008-02-19 18:46 . 2008-02-19 19:07 <REP> d-------- C:\SDFix
2008-02-18 19:11 . 2007-12-07 03:08 6,066,176 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll
2008-02-18 19:11 . 2007-07-01 04:31 2,455,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-02-18 19:11 . 2007-07-01 04:36 1,048,576 -----c--- C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-02-18 19:11 . 2007-12-07 03:08 459,264 -----c--- C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-02-18 19:11 . 2007-12-07 03:08 383,488 -----c--- C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-02-18 19:11 . 2007-12-07 03:08 267,776 -----c--- C:\WINDOWS\system32\dllcache\iertutil.dll
2008-02-18 19:11 . 2007-12-07 03:08 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-02-18 19:11 . 2007-12-07 03:08 52,224 -----c--- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-02-18 19:11 . 2007-12-06 12:00 13,824 -----c--- C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-02-18 19:10 . 2008-02-18 19:11 <REP> d-------- C:\WINDOWS\system32\fr-fr
2008-02-18 19:08 . 2007-08-13 18:54 33,792 --a--c--- C:\WINDOWS\system32\dllcache\custsat.dll
2008-02-18 18:58 . 2006-08-21 10:14 128,896 -----c--- C:\WINDOWS\system32\dllcache\fltmgr.sys
2008-02-18 18:58 . 2006-08-21 10:14 23,040 -----c--- C:\WINDOWS\system32\dllcache\fltmc.exe
2008-02-18 18:58 . 2006-08-21 13:26 16,896 -----c--- C:\WINDOWS\system32\dllcache\fltlib.dll
2008-02-18 18:56 . 2007-07-09 14:11 584,192 -----c--- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-02-18 18:47 . 2008-02-18 18:47 <REP> d--h----- C:\WINDOWS\PIF
2008-02-17 23:33 . 2008-02-17 23:33 <REP> d-------- C:\Documents and Settings\LocalService\Menu D‚marrer
2008-02-17 23:07 . 2008-02-17 23:34 316,640 --a------ C:\WINDOWS\WMSysPr9.prx
2008-02-17 23:06 . 2008-02-17 23:06 <REP> d-------- C:\WINDOWS\provisioning
2008-02-17 23:06 . 2008-02-17 23:06 <REP> d-------- C:\WINDOWS\peernet
2008-02-17 23:04 . 2008-02-17 23:04 <REP> d-------- C:\WINDOWS\ServicePackFiles
2008-02-17 22:57 . 2008-02-17 22:57 <REP> d-------- C:\WINDOWS\EHome
2008-02-17 22:38 . 2002-04-15 21:11 67,866 --------- C:\WINDOWS\system32\drivers\netwlan5.img
2008-02-17 22:38 . 2004-08-19 16:10 11,776 --------- C:\WINDOWS\system32\spnpinst.exe
2008-02-17 22:38 . 2004-08-02 14:20 7,208 --------- C:\WINDOWS\system32\secupd.sig
2008-02-17 22:38 . 2004-08-02 14:20 4,569 --------- C:\WINDOWS\system32\secupd.dat
2008-02-17 22:22 . 2004-08-20 00:09 614,912 --a------ C:\WINDOWS\system32\h323msp.dll
2008-02-17 22:22 . 2004-08-20 00:09 332,800 --a------ C:\WINDOWS\system32\ipnathlp.dll
2008-02-17 22:22 . 2004-08-20 00:10 266,752 --a------ C:\WINDOWS\system32\h323.tsp
2008-02-17 22:22 . 2004-03-30 02:49 40,960 -----c--- C:\WINDOWS\system32\dllcache\evtgprov.dll
2008-02-17 22:22 . 2004-01-10 06:11 26,112 --a------ C:\WINDOWS\system32\xpsp1hfm.exe
2008-02-17 22:10 . 2008-02-17 22:10 <REP> d-------- C:\Program Files\Trend Micro
2008-02-17 22:10 . 2008-02-17 22:10 812,344 --a------ C:\Program Files\HJTInstall.exe
2008-02-17 22:04 . 2005-10-20 23:25 1,097,728 --a------ C:\WINDOWS\system32\esent.dll
2008-02-17 21:56 . 2008-02-17 21:56 <REP> d-------- C:\WINDOWS\system32\bits
2008-02-17 21:56 . 2008-02-18 19:18 <REP> d--h----- C:\WINDOWS\$hf_mig$
2008-02-17 21:56 . 2006-09-06 17:43 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-02-17 21:44 . 2008-02-17 21:44 <REP> d-------- C:\WINDOWS\AU_Temp
2008-02-17 21:05 . 2008-02-20 19:14 <REP> d-------- C:\Documents and Settings\JOBIN\Application Data\AVG7
2008-02-17 21:04 . 2008-02-17 21:04 <REP> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-02-17 21:04 . 2008-02-17 21:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-17 21:04 . 2008-02-17 21:13 <REP> d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-02-17 21:04 . 2008-02-17 21:04 32,981,120 --a------ C:\Program Files\avg75free_516a1225.exe
2008-02-17 20:52 . 2008-02-17 20:52 26,112 --a------ C:\WINDOWS\system32\cygwn32.dll
2008-02-17 20:49 . 2008-02-17 20:49 36,864 --a------ C:\WINDOWS\system32\service .exe
2008-02-17 20:34 . 2008-02-17 21:18 13 --ah----- C:\WINDOWS\mmax_hren2.ini
2008-02-17 20:31 . 2008-02-17 20:31 <REP> d--hs---- C:\Documents and Settings\JOBIN\UserData
2008-02-17 20:23 . 2008-02-17 20:52 52,236 --a------ C:\wmfvdfy.exe
2008-02-17 20:23 . 2008-02-17 20:23 26,112 --a------ C:\WINDOWS\system32\marwin32.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-17 20:44 86,094 ----a-w C:\WINDOWS\BPMNT.dll
2008-02-17 20:44 1,163,344 ----a-w C:\WINDOWS\vsapi32.dll
2008-02-17 19:31 71,749 ----a-w C:\WINDOWS\hcextoutput.dll
2008-02-17 19:31 69,689 ----a-w C:\WINDOWS\UNZIP.DLL
2008-02-17 19:31 507,904 ----a-w C:\WINDOWS\TMUPDATE.DLL
2008-02-17 19:31 286,720 ----a-w C:\WINDOWS\PATCH.EXE
2008-02-17 19:31 267,845 ----a-w C:\WINDOWS\tsc.exe
2008-01-15 17:28 --------- d-----w C:\Program Files\Alwil Software
2008-01-15 12:59 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-01-15 12:53 --------- d-----w C:\Program Files\MSI
2008-01-15 12:40 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-15 12:40 --------- d-----w C:\Program Files\France Telecom Cable
2008-01-15 12:33 --------- d-----w C:\Program Files\Realtek Sound Manager
2008-01-15 12:33 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-01-15 12:33 --------- d-----w C:\Program Files\AvRack
2008-01-15 12:24 --------- d-----w C:\Program Files\microsoft frontpage
2008-01-15 12:22 --------- d-----w C:\Program Files\Services en ligne
.
[code]<pre>
----a-w 40,048 2008-01-15 18:00:12 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl .exe
----a-w 1,511,453 2008-02-17 19:47:22 C:\Program Files\Messenger\msmsgs .exe
----a-w 13,312 2008-02-17 19:49:37 C:\WINDOWS\system32\ctfmon .exe
----a-w 36,864 2008-02-17 19:49:34 C:\WINDOWS\system32\service .exe
</pre>[/code]
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E6069507-2C01-4E94-856C-E68B9A8E744E}]
C:\WINDOWS\System32\gebcd.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{e8bb5f78-ba23-440f-8fed-282342be5819}]
C:\WINDOWS\System32\rsadbqgd.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 00:09 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2002-11-19 14:01 46592 C:\WINDOWS\SOUNDMAN.EXE]
"3081cc26"="C:\WINDOWS\System32\ieyanchk.dll" [ ]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-02-17 21:04 579072]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-20 00:09 15360]
"AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-02-17 21:04 219136]
S2 SMSCGISVC;System Managment Controler;"C:\WINDOWS\system\smscg.exe" []
S3 service.sys;service.sys;C:\WINDOWS\System32\service.sys []
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 07:08]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-20 19:14:22
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-02-20 19:16:41 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-20 18:15:59
.
2008-02-17 22:37:19 --- E O F ---