slt,
après recherche des infections (j'ai posté le rapport sur le forum), j'ai procédé à l'option 2 comme indiqué dans la procédure et j'ai eu le rapport suivant:
--------------------\\ Lop S&D 4.2.4-7 XP/Vista
Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) Dual CPU T2390 @ 1.86GHz )
BIOS : Ver 1.00PARTTBL)
USER : soumaya ( Administrator )
BOOT : Normal boot
Antivirus : Avira AntiVir PersonalEdition 8.0.1.26 (Activated)
C:\ (Local Disk) - NTFS - Total : 45 Go Free : 4 Go
D:\ (CD or DVD)
E:\ (Local Disk) - NTFS - Total : 97 Go Free : 5 Go
"C:\Lop SD" ( MAJ : 23-10-2008|23:15 )
Option : [2] ( 26/10/2008|11:55 )
[ UAC => 1 ]
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION
Supprime! - C:\Program Files\Circle Developement
-
[ Fichier Hosts ] .. Restaure!
\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
--------------------\\ Listing des dossiers dans Local
[06/08/2008|13:45] C:\Users\soumaya\AppData\Local\Adobe
[07/07/2008|14:49] C:\Users\soumaya\AppData\Local\Ahead
[07/07/2008|00:02] C:\Users\soumaya\AppData\Local\Application Data
[02/10/2008|19:31] C:\Users\soumaya\AppData\Local\Ares
[02/10/2008|16:58] C:\Users\soumaya\AppData\Local\bcidpkez.bat
[02/11/2006|13:04] C:\Users\soumaya\AppData\Local\d3d9caps.dat
[22/10/2008|17:20] C:\Users\soumaya\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[11/08/2008|17:36] C:\Users\soumaya\AppData\Local\GDIPFONTCACHEV1.DAT
[04/09/2008|10:32] C:\Users\soumaya\AppData\Local\Google
[07/07/2008|00:02] C:\Users\soumaya\AppData\Local\Historique
[26/10/2008|11:13] C:\Users\soumaya\AppData\Local\IconCache.db
[16/07/2008|12:27] C:\Users\soumaya\AppData\Local\javasharedresources
[19/08/2008|21:27] C:\Users\soumaya\AppData\Local\Microsoft
[19/08/2008|17:55] C:\Users\soumaya\AppData\Local\Microsoft Games
[20/09/2008|21:54] C:\Users\soumaya\AppData\Local\Microsoft Help
[07/07/2008|10:49] C:\Users\soumaya\AppData\Local\Mozilla
[26/10/2008|11:55] C:\Users\soumaya\AppData\Local\Temp
[07/07/2008|00:02] C:\Users\soumaya\AppData\Local\Temporary Internet Files
[16/07/2008|12:31] C:\Users\soumaya\AppData\Local\VirtualStore
[26/10/2008|11:54] C:\Users\soumaya\AppData\Local\ywyek.dat
[25/10/2008|20:22] C:\Users\soumaya\AppData\Local\ywyek.exe
[07/10/2008|09:21] C:\Users\soumaya\AppData\Local\ywyek_nav.dat
[26/10/2008|11:54] C:\Users\soumaya\AppData\Local\ywyek_navps.dat
--------------------\\ Tâches planifiées dans C:\Windows\tasks
[26/10/2008 11:14][--ah-----] C:\Windows\tasks\SA.DAT
[26/10/2008 11:13][--a------] C:\Windows\tasks\SCHEDLGU.TXT
--------------------\\ Listing des dossiers dans C:\ProgramData
[06/08/2008|13:45] C:\ProgramData\Adobe
[07/07/2008|14:39] C:\ProgramData\Ahead
[02/11/2006|13:02] C:\ProgramData\Application Data
[06/07/2008|21:26] C:\ProgramData\AuthenTec Biometric Suite
[07/07/2008|09:42] C:\ProgramData\Avira
[06/07/2008|23:55] C:\ProgramData\Bureau
[03/10/2008|11:23] C:\ProgramData\CyberLink
[02/11/2006|13:02] C:\ProgramData\Desktop
[02/11/2006|13:02] C:\ProgramData\Documents
[16/09/2008|09:44] C:\ProgramData\eMule
[06/07/2008|23:55] C:\ProgramData\Favoris
[02/11/2006|13:02] C:\ProgramData\Favorites
[10/07/2008|17:43] C:\ProgramData\FreeDownloadManager.ORG
[17/07/2008|09:36] C:\ProgramData\IBM
[09/07/2008|10:29] C:\ProgramData\Lenovo
[06/07/2008|23:55] C:\ProgramData\Menu D‚marrer
[07/08/2008|11:14] C:\ProgramData\Messenger Plus!
[07/07/2008|11:30] C:\ProgramData\Microsoft
[21/10/2008|09:45] C:\ProgramData\Microsoft Help
[06/07/2008|23:55] C:\ProgramData\ModŠles
[21/10/2008|09:53] C:\ProgramData\Nero
[02/11/2006|13:02] C:\ProgramData\Start Menu
[07/07/2008|10:17] C:\ProgramData\Symantec
[02/11/2006|13:02] C:\ProgramData\Templates
[26/10/2008|11:15] C:\ProgramData\VMware
[08/10/2008|15:00] C:\ProgramData\WindowsSearch
[06/08/2008|14:07] C:\ProgramData\WLInstaller
[28/08/2008|18:21] C:\ProgramData\Yahoo! Companion
--------------------\\ Listing des dossiers dans C:\Program Files
[06/08/2008|13:44] C:\Program Files\Adobe
[07/07/2008|11:12] C:\Program Files\Adobe(154)
[13/10/2008|19:40] C:\Program Files\Alwil Software
[09/07/2008|10:29] C:\Program Files\AskTBar
[07/07/2008|09:42] C:\Program Files\Avira
[06/07/2008|21:05] C:\Program Files\Broadcom
[03/10/2008|20:26] C:\Program Files\Common Files
[01/09/2008|10:51] C:\Program Files\CyberLink
[06/07/2008|21:14] C:\Program Files\Diskeeper Corporation
[24/09/2008|10:13] C:\Program Files\DivX
[24/09/2008|10:19] C:\Program Files\ffdshow
[06/07/2008|23:55] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
[06/07/2008|21:34] C:\Program Files\Google
[23/07/2008|16:34] C:\Program Files\IBM
[01/09/2008|10:53] C:\Program Files\InstallShield Installation Information
[06/07/2008|21:04] C:\Program Files\Intel
[11/09/2008|16:01] C:\Program Files\Internet Explorer
[28/08/2008|11:55] C:\Program Files\Java
[11/08/2008|15:20] C:\Program Files\Lenovo
[06/07/2008|21:12] C:\Program Files\Lenovo Fingerprint Software
[06/07/2008|21:18] C:\Program Files\Lenovo Multimedia Center
[06/07/2008|21:14] C:\Program Files\Lenovo Registration
[04/09/2008|10:34] C:\Program Files\Messenger Plus! Live
[26/09/2008|09:42] C:\Program Files\MessengerSkinner
[23/07/2008|09:38] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[02/11/2006|12:37] C:\Program Files\Microsoft Games
[07/07/2008|11:31] C:\Program Files\Microsoft Office
[22/10/2008|19:02] C:\Program Files\Microsoft Silverlight
[09/07/2008|10:29] C:\Program Files\Microsoft Visual Studio
[09/07/2008|10:29] C:\Program Files\Microsoft Works
[09/07/2008|10:07] C:\Program Files\Microsoft.NET
[28/07/2008|10:35] C:\Program Files\Movie Maker
[26/10/2008|11:28] C:\Program Files\Mozilla Firefox 3 Beta 5
[02/11/2006|12:37] C:\Program Files\MSBuild
[07/07/2008|18:36] C:\Program Files\MSXML 4.0
[20/10/2008|18:12] C:\Program Files\Nero
[07/08/2008|15:07] C:\Program Files\NetCruiser
[31/08/2008|18:23] C:\Program Files\Real
[06/07/2008|21:04] C:\Program Files\Realtek
[02/11/2006|12:37] C:\Program Files\Reference Assemblies
[14/08/2008|17:05] C:\Program Files\SAGEM
[15/10/2008|18:47] C:\Program Files\Spyware-Secure
[23/07/2008|10:39] C:\Program Files\Sun
[06/07/2008|21:02] C:\Program Files\Synaptics
[06/07/2008|21:34] C:\Program Files\ThinkPad
[06/07/2008|21:22] C:\Program Files\ThinkVantage
[02/11/2006|13:01] C:\Program Files\Uninstall Information
[04/09/2008|12:21] C:\Program Files\VMware
[28/07/2008|10:35] C:\Program Files\Windows Calendar
[28/07/2008|10:35] C:\Program Files\Windows Collaboration
[28/07/2008|10:34] C:\Program Files\Windows Defender
[28/07/2008|10:35] C:\Program Files\Windows Journal
[06/08/2008|13:55] C:\Program Files\Windows Live
[10/10/2008|09:24] C:\Program Files\Windows Live Toolbar
[21/10/2008|10:02] C:\Program Files\Windows Mail
[28/07/2008|10:35] C:\Program Files\Windows Media Player
[06/07/2008|23:55] C:\Program Files\Windows NT
[28/07/2008|10:35] C:\Program Files\Windows Photo Gallery
[28/07/2008|10:35] C:\Program Files\Windows Sidebar
[09/07/2008|10:29] C:\Program Files\WinRAR
[28/08/2008|18:01] C:\Program Files\Yahoo!
[16/07/2008|12:26] C:\Program Files\Zero G Registry
--------------------\\ Listing des dossiers dans C:\Program Files\Common Files
[06/08/2008|13:44] C:\Program Files\Common Files\Adobe
[07/07/2008|11:12] C:\Program Files\Common Files\Adobe(155)
[21/10/2008|09:56] C:\Program Files\Common Files\Ahead
[01/09/2008|10:53] C:\Program Files\Common Files\CyberLink
[09/07/2008|10:29] C:\Program Files\Common Files\DESIGNER
[06/07/2008|21:02] C:\Program Files\Common Files\InstallShield
[06/07/2008|21:21] C:\Program Files\Common Files\Java
[11/08/2008|15:20] C:\Program Files\Common Files\Lenovo
[01/09/2008|10:50] C:\Program Files\Common Files\microsoft shared
[20/10/2008|18:38] C:\Program Files\Common Files\Nero
[24/09/2008|10:13] C:\Program Files\Common Files\PX Storage Engine
[05/09/2008|10:30] C:\Program Files\Common Files\Real
[02/11/2006|11:18] C:\Program Files\Common Files\Services
[06/07/2008|20:59] C:\Program Files\Common Files\snp2uvc
[02/11/2006|11:18] C:\Program Files\Common Files\SpeechEngines
[07/07/2008|10:17] C:\Program Files\Common Files\Symantec Shared
[28/07/2008|10:34] C:\Program Files\Common Files\System
[08/09/2008|10:38] C:\Program Files\Common Files\VMware
[06/08/2008|13:53] C:\Program Files\Common Files\WindowsLiveInstaller
--------------------\\ Process
( 100 Processes )
... OK !
--------------------\\ Recherche avec S_Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Recherche de Fichiers / Dossiers Lop
Aucun fichier / dossier Lop trouvé !
--------------------\\ Verification du Registre
..... OK !
--------------------\\ Verification du fichier Hosts
Fichier Hosts PROPRE
--------------------\\ Recherche de fichiers avec Catchme
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-26 11:55:30
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden files ...
C:\Users\soumaya\AppData\Local\ywyek.dat 5326 bytes
C:\Users\soumaya\AppData\Local\ywyek.exe 343552 bytes executable
C:\Users\soumaya\AppData\Local\ywyek_nav.dat 26879 bytes
C:\Users\soumaya\AppData\Local\ywyek_navps.dat 844 bytes
scan completed successfully
hidden processes: 0
hidden files: 4
--------------------\\ Recherche d'autres infections
C:\Program Files\MessengerSkinner
C:\Program Files\MessengerSkinner\download
C:\Program Files\MessengerSkinner\MessengerSkinner.exe
C:\Program Files\MessengerSkinner\MessengerSkinnerDll.dll
C:\Program Files\MessengerSkinner\resources
C:\Program Files\MessengerSkinner\uninst.exe
C:\Users\soumaya\AppData\Roaming\MessengerSkinner
C:\Users\soumaya\AppData\Roaming\MessengerSkinner\Userdata
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\MessengerSkinner
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\MessengerSkinner\Conditions g‚n‚rales.url
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\MessengerSkinner\Confidentialit‚.url
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\MessengerSkinner\D‚sinstaller.lnk
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\MessengerSkinner\MessengerSkinner.lnk
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\MessengerSkinner\Website.url
C:\Users\soumaya\AppData\Local\ywyek.dat
C:\Users\soumaya\AppData\Local\ywyek.exe
C:\Users\soumaya\AppData\Local\ywyek_nav.dat
C:\Users\soumaya\AppData\Local\ywyek_navps.dat
==> EGDACCESS <==
--------------------\\ ROGUES ..
C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Spyware-Secure
C:\Users\soumaya\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Spyware-Secure
C:\PROGRA~1\Spyware-Secure
C:\Users\soumaya\AppData\Roaming\VirusRemover2008
--------------------\\ Cracks & Keygens ..
C:\Users\soumaya\AppData\Roaming\Microsoft\Windows\Recent\Nero.7.Premium.v7.9.6.0.FR.Incl-Keygen.lnk
[F:2265][D:50]-> C:\Users\soumaya\AppData\Local\Temp
[F:32][D:1]-> C:\Users\soumaya\AppData\Roaming\MICROS~1\Windows\Cookies
[F:1284][D:4]-> C:\Users\soumaya\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
[F:4][D:4]-> C:\$Recycle.Bin
1 - "C:\Lop SD\LopR_1.txt" - 26/10/2008|11:22 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 26/10/2008|11:57 - Option : [2]
--------------------\\ Fin du rapport a 11:57:12
[ UAC => 1 ]