Salut,

tout a l'air de fonctionner. Effectivement, cette fois, je n'ai pas eu de proposition de full scan avec GMER.
Voilà d'abord le Mbam
Malwarebytes' Anti-Malware 1.44
Version de la base de données: 3556
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.11
14/01/2010 21:43:31
mbam-log-2010-01-14 (21-43-31).txt
Type de recherche: Examen complet (C:\|)
Eléments examinés: 242286
Temps écoulé: 8 hour(s), 37 minute(s), 29 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 5
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 8
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d5792aa9-d373-4039-8670-2cdab6a71f15} (Trojan.Swizzor) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Malware Defense (Rogue.MalwareDefense) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\H8SRT (Rootkit.TDSS) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\WakeNet (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\h8srtd.sys (Rootkit.TDSS) -> Quarantined and deleted successfully.
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
C:\ComboFix\Combo-Fix.sys (Malware.Trace) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7AFC631D-71A6-4CBE-9F8F-EFDBDC0F94C6}\RP1203\A0352100.sys (Malware.Packer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{7AFC631D-71A6-4CBE-9F8F-EFDBDC0F94C6}\RP1203\A0352160.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\H8SRTffmqxouigs.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\H8SRTjpqirrdwrd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\krl32mainweq.dll (Trojan.DNSChanger) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\h8srtkrl32mainweq.dll (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\H8SRTbakdqvparm.dat (Rootkit.TDSS) -> Quarantined and deleted successfully.
Puis le GMER...
GMER 1.0.15.15281 -
http://www.gmer.netRootkit scan 2010-01-15 00:37:39
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\OWNER~1.LAU\LOCALS~1\Temp\uxldapog.sys
---- System - GMER 1.0.15 ----
SSDT F7BF5B4E ZwCreateKey
SSDT F7BF5B44 ZwCreateThread
SSDT F7BF5B53 ZwDeleteKey
SSDT F7BF5B5D ZwDeleteValueKey
SSDT sptd.sys ZwEnumerateKey [0xF7390C7E]
SSDT sptd.sys ZwEnumerateValueKey [0xF7390FF6]
SSDT F7BF5B62 ZwLoadKey
SSDT sptd.sys ZwOpenKey [0xF7390A18]
SSDT F7BF5B30 ZwOpenProcess
SSDT F7BF5B35 ZwOpenThread
SSDT sptd.sys ZwQueryKey [0xF73910C0]
SSDT sptd.sys ZwQueryValueKey [0xF7390F58]
SSDT F7BF5B6C ZwReplaceKey
SSDT F7BF5B67 ZwRestoreKey
SSDT F7BF5B58 ZwSetValueKey
SSDT F7BF5B3F ZwTerminateProcess
---- Kernel code sections - GMER 1.0.15 ----
? hmcmyups.sys Le fichier spécifié est introuvable. !
? C:\WINDOWS\system32\drivers\sptd.sys Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
? C:\WINDOWS\System32\Drivers\SPTD4829.SYS Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus.
---- Kernel IAT/EAT - GMER 1.0.15 ----
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F738CA32] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F738CB6E] sptd.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F738CAF6] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F738D6CC] sptd.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F738D5A2] sptd.sys
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F73AEC82] sptd.sys
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisCloseAdapter] [F79713FC] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisOpenAdapter] [F7971458] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisDeregisterProtocol] [F79716B2] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\system32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisRegisterProtocol] [F7971684] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [F7971684] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [F7971458] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [F79713FC] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\system32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [F79716B2] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] [F79716B2] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [F7971684] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [F7971458] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\system32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter] [F79713FC] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [F7971684] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [F79716B2] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [F79713FC] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [F7971458] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [F79713FC] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [F7971458] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\system32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [F7971684] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] [F79716B2] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] [F7971684] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] [F7971458] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\system32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] [F79713FC] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\system32\DRIVERS\irda.sys[NDIS.SYS!NdisOpenAdapter] [F7971458] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\system32\DRIVERS\irda.sys[NDIS.SYS!NdisRegisterProtocol] [F7971684] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\system32\DRIVERS\irda.sys[NDIS.SYS!NdisCloseAdapter] [F79713FC] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\system32\DRIVERS\irda.sys[NDIS.SYS!NdisDeregisterProtocol] [F79716B2] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisRegisterProtocol] [F7971684] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisDeregisterProtocol] [F79716B2] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisCloseAdapter] [F79713FC] GDNdisIc.sys (G DATA Software AG)
IAT \SystemRoot\system32\DRIVERS\ndisuio.sys[NDIS.SYS!NdisOpenAdapter] [F7971458] GDNdisIc.sys (G DATA Software AG)
---- Devices - GMER 1.0.15 ----
Device \FileSystem\Ntfs \Ntfs 84F93C78
Device \Driver\Tcpip \Device\Ip GDTdiIcpt.sys
Device \Driver\Tcpip \Device\Tcp GDTdiIcpt.sys
Device \Driver\Ftdisk \Device\HarddiskVolume1 84F96A58
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume1 VolumeFilter.sys
Device \Driver\GDNdisIc \Device\GDNdisIc 84F93A40
Device \Driver\Ftdisk \Device\HarddiskVolume2 84F96A58
AttachedDevice \Driver\Ftdisk \Device\HarddiskVolume2 VolumeFilter.sys
Device \Driver\Cdrom \Device\CdRom0 84D9AEB0
Device \FileSystem\Rdbss \Device\FsWrap 848379A8
Device \Driver\Cdrom \Device\CdRom1 84D9AEB0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T1L0-17 [F7305B40] atapi.sys[unknown section] {MOV EAX, 0x84f93008; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf73a1442; RET }
Device \Driver\atapi \Device\Ide\IdePort0 [F7305B40] atapi.sys[unknown section] {MOV EAX, 0x84f93008; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf73a1442; RET }
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 [F7305B40] atapi.sys[unknown section] {MOV EAX, 0x84f93008; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf73a1442; RET }
Device \Driver\atapi \Device\Ide\IdePort1 [F7305B40] atapi.sys[unknown section] {MOV EAX, 0x84f93008; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf73a1442; RET }
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-f [F7305B40] atapi.sys[unknown section] {MOV EAX, 0x84f93008; XCHG [ESP], EAX; PUSH EAX; PUSH 0xf73a1442; RET }
Device \Driver\NetBT \Device\NetBt_Wins_Export 848548A8
Device \Driver\usbstor \Device\00000077 84C17BB8
Device \Driver\NetBT \Device\NetBT_Tcpip_{C5EA7C3A-DCCE-4EBF-9685-F5A03AFDDD53} 848548A8
Device \Driver\NetBT \Device\NetbiosSmb 848548A8
Device \Driver\usbstor \Device\00000079 84C17BB8
Device \Driver\Tcpip \Device\Udp GDTdiIcpt.sys
Device \Driver\Disk \Device\Harddisk0\DR0 84F93EB0
Device \Driver\Tcpip \Device\RawIp GDTdiIcpt.sys
Device \Driver\Disk \Device\Harddisk1\DR3 84F93EB0
Device \Driver\Disk \Device\Harddisk1\DP(1)0-0+7 84F93EB0
Device \Driver\Disk \Device\Harddisk2\DR4 84F93EB0
Device \Driver\Disk \Device\Harddisk2\DP(1)0-0+8 84F93EB0
Device \Driver\Disk \Device\Harddisk3\DR5 84F93EB0
Device \Driver\Disk \Device\Harddisk3\DP(1)0-0+9 84F93EB0
Device \Driver\usbstor \Device\0000007a 84C17BB8
Device \Driver\Disk \Device\Harddisk4\DP(1)0-0+a 84F93EB0
Device \Driver\Disk \Device\Harddisk4\DR6 84F93EB0
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 84832748
Device \Driver\usbstor \Device\0000007b 84C17BB8
Device \Driver\Tcpip \Device\IPMULTICAST GDTdiIcpt.sys
Device \FileSystem\MRxSmb \Device\LanmanRedirector 84832748
Device \Driver\usbstor \Device\0000007c 84C17BB8
Device \FileSystem\Npfs \Device\NamedPipe 849F7C78
Device \Driver\Ftdisk \Device\FtControl 84F96A58
Device \FileSystem\Msfs \Device\Mailslot 849F7EB0
Device \FileSystem\Cdfs \Cdfs 84B8ED78
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x6E 0x80 0xA7 0x2F ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x6E 0x80 0xA7 0x2F ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s0 -439251334
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s1 -1130272018
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@s2 -52219117
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x6E 0x80 0xA7 0x2F ...
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@h0 0
Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4@khjeh 0x6E 0x80 0xA7 0x2F ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C7DF7C37-8150-5550-D040-3F51A8264909}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C7DF7C37-8150-5550-D040-3F51A8264909}@iambonhlilaccdbion 0x6A 0x61 0x69 0x6B ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{C7DF7C37-8150-5550-D040-3F51A8264909}@hagcinohilplohec 0x6A 0x61 0x70 0x6B ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DC82148C-29CE-5171-826E-DB728319EBC5}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DC82148C-29CE-5171-826E-DB728319EBC5}@iadblnkpfcdllccfjm 0x6A 0x61 0x70 0x6B ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{DC82148C-29CE-5171-826E-DB728319EBC5}@hafcfnafnecbpbco 0x6A 0x61 0x70 0x6B ...
---- EOF - GMER 1.0.15 ----
Merci et bon courage
