bonsoir,
Voici le rapport ci:dessous: qu'en penses-tu ?
ComboFix 08-10-04.07 - admin 2008-10-05 15:38:33.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.116 [GMT 2:00]
Lancé depuis: C:\Documents and Settings\admin\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
[B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\k_urlmon.dll
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-05 au 2008-10-05 ))))))))))))))))))))))))))))))))))))
.
2008-10-05 12:10 . 2008-10-05 12:10 <REP> d-------- C:\Documents and Settings\admin\Contacts
2008-10-05 10:53 . 2008-10-05 10:53 <REP> d-------- C:\Program Files\Trend Micro
2008-10-05 10:53 . 2008-10-05 10:53 268 --ah----- C:\sqmdata06.sqm
2008-10-05 10:53 . 2008-10-05 10:53 244 --ah----- C:\sqmnoopt06.sqm
2008-10-04 18:36 . 2008-10-04 18:37 <REP> d-------- C:\nettoyage
2008-10-04 16:06 . 2008-10-04 16:06 268 --ah----- C:\sqmdata05.sqm
2008-10-04 16:06 . 2008-10-04 16:06 244 --ah----- C:\sqmnoopt05.sqm
2008-09-28 16:51 . 2008-10-05 14:28 <REP> d--h----- C:\Documents and Settings\admin\Voisinage réseau
2008-09-28 16:51 . 2007-12-28 16:35 <REP> d--h----- C:\Documents and Settings\admin\Voisinage d'impression
2008-09-28 16:51 . 2007-12-28 15:47 <REP> d--h----- C:\Documents and Settings\admin\Modèles
2008-09-28 16:51 . 2008-10-05 12:13 <REP> dr------- C:\Documents and Settings\admin\Mes documents
2008-09-28 16:51 . 2007-12-28 16:35 <REP> dr------- C:\Documents and Settings\admin\Menu Démarrer
2008-09-28 16:51 . 2008-09-28 16:52 <REP> dr------- C:\Documents and Settings\admin\Favoris
2008-09-28 16:51 . 2008-10-05 15:33 <REP> d-------- C:\Documents and Settings\admin\Bureau
2008-09-28 16:51 . 2008-10-05 12:10 <REP> d-------- C:\Documents and Settings\admin
2008-09-27 22:19 . 2008-09-27 22:19 268 --ah----- C:\sqmdata04.sqm
2008-09-27 22:19 . 2008-09-27 22:19 244 --ah----- C:\sqmnoopt04.sqm
2008-09-27 20:14 . 2008-09-27 20:14 268 --ah----- C:\sqmdata03.sqm
2008-09-27 20:14 . 2008-09-27 20:14 244 --ah----- C:\sqmnoopt03.sqm
2008-09-27 20:03 . 2008-09-27 20:03 268 --ah----- C:\sqmdata02.sqm
2008-09-27 20:03 . 2008-09-27 20:03 244 --ah----- C:\sqmnoopt02.sqm
2008-09-27 19:39 . 2008-09-27 19:39 268 --ah----- C:\sqmdata01.sqm
2008-09-27 19:39 . 2008-09-27 19:39 244 --ah----- C:\sqmnoopt01.sqm
2008-09-27 19:10 . 2008-10-04 19:04 <REP> d-------- C:\Documents and Settings\vhurel
2008-09-27 19:06 . 2008-09-27 19:08 <REP> d-------- C:\Documents and Settings\Administrateur\amsn
2008-09-27 14:55 . 2008-09-27 14:55 268 --ah----- C:\sqmdata00.sqm
2008-09-27 14:55 . 2008-09-27 14:55 244 --ah----- C:\sqmnoopt00.sqm
2008-09-27 13:29 . 2008-09-27 13:29 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Malwarebytes
2008-09-27 13:27 . 2007-12-28 16:35 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
2008-09-27 13:27 . 2007-12-28 16:35 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-09-27 13:27 . 2007-12-28 15:47 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
2008-09-27 13:27 . 2008-09-27 13:29 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents
2008-09-27 13:27 . 2007-12-28 16:35 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
2008-09-27 13:27 . 2007-12-28 16:35 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris
2008-09-27 13:27 . 2007-12-28 16:35 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2008-09-27 13:27 . 2008-09-27 19:06 <REP> d-------- C:\Documents and Settings\Administrateur
2008-09-27 12:09 . 2008-09-27 12:30 16 --a------ C:\WINDOWS\system32\drivers\ksdevice.sys
2008-09-27 12:09 . 2008-09-27 12:30 16 --a------ C:\WINDOWS\system32\drivers\KeenSense.sys
2008-09-18 19:13 . 2008-09-19 12:45 <REP> d-------- C:\WINDOWS\system32\fr
2008-09-18 19:13 . 2008-09-19 12:45 <REP> d-------- C:\WINDOWS\system32\bits
2008-09-18 19:13 . 2008-09-19 12:42 <REP> d-------- C:\WINDOWS\l2schemas
2008-09-18 18:38 . 2004-08-19 16:09 4,290,048 --a------ C:\WINDOWS\system32\dllcache\wmm2res.dll
2008-09-18 18:37 . 2004-08-19 16:11 4,190,352 --a------ C:\WINDOWS\system32\dllcache\luna.mst
2008-09-18 18:36 . 2005-09-10 03:55 2,067,968 --a------ C:\WINDOWS\system32\dllcache\cdosys.dll
2008-09-18 18:35 . 2007-04-18 18:14 2,854,400 --a------ C:\WINDOWS\system32\dllcache\msi.dll
2008-09-18 18:34 . 2007-10-25 18:43 8,516,608 --a------ C:\WINDOWS\system32\dllcache\shell32.dll
2008-09-18 18:33 . 2007-02-28 18:02 2,182,400 --a------ C:\WINDOWS\system32\ntoskrnl.exe
2008-09-13 16:04 . 2008-09-13 16:04 121 --a------ C:\WINDOWS\Winchat.ini
2008-09-06 22:18 . 2008-09-06 22:19 <REP> d-------- C:\Program Files\aMSN
2008-09-06 13:22 . 2008-09-06 13:22 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-06 10:58 . 2008-09-13 11:42 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-06 10:58 . 2008-09-06 10:58 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-06 10:58 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-06 10:58 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-05 13:53 13,796,640 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-05 13:51 644,640 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-10-05 13:49 62,504 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-10-05 13:49 188,936 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-05 13:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-09-06 10:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-16 17:34 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-08-06 18:37 96,976 ----a-w C:\WINDOWS\system32\drivers\klin.dat
2008-07-20 17:52 10,050 ----a-w C:\WINDOWS\system32\shutdown.zip
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:31 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:31 253,952 ----a-w C:\WINDOWS\system32\dllcache\es.dll
2006-12-09 19:11 71,357 ----a-w C:\Program Files\Love-Test(www.MsnTrucAstuce.fr).plsc
2006-11-17 17:22 284,139 ----a-w C:\Program Files\Ultimate(biensur)www.MsnTrucAstuce.fr).plsc
2006-10-12 15:46 2,201 ----a-w C:\Program Files\Huhu Leet 1.0(www.MsnTrucAstuce.free.fr).plsc
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe" [2005-09-08 94208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe" [2002-03-18 188416]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" [2008-02-08 227856]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-19 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\rtcshare.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"\\\\C000273\\Diablo\\Diablo.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\French\\setup.exe"=
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"C:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"C:\\Program Files\\aMSN\\bin\\wish.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
R3 G200;G200;C:\WINDOWS\system32\DRIVERS\G200m.sys [2001-08-23 320512]
R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-12-13 24592]
R3 MBAMSwissArmy;MBAMSwissArmy;C:\WINDOWS\system32\drivers\mbamswissarmy.sys [2008-09-10 38528]
.
Contenu du dossier 'Tâches planifiées'
2008-07-16 C:\WINDOWS\Tasks\!cid_605.job
- C:\Documents and Settings\viviane\Mes documents\Mes images\!cid_605.jpg []
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-ares - C:\Program Files\Ares\Ares.exe
HKLM-Run-NeroFilterCheck - C:\WINDOWS\system32\NeroCheck.exe
HKLM-Run-Motive SmartBridge - C:\PROGRA~1\CLUB-I~1\LECOMP~1\SMARTB~1\MotiveSB.exe
HKLM-Run-BJCFD - C:\Program Files\BroadJump\Client Foundation\CFD.exe
HKLM-Run-StandardInstall - (no file)
HKLM-Run-NWEReboot - (no file)
Notify-dimsntfy - (no file)
.
------- Examen supplémentaire -------
.
O16 -: Microsoft XML Parser for Java -
file://C:\WINDOWS\Java\classes\xmldso.cab
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-05 15:53:17
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
.
**************************************************************************
.
Heure de fin: 2008-10-05 16:05:56 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-10-05 14:05:12
Avant-CF: 3 242 774 528 octets libres
Après-CF: 3,220,918,272 octets libres
173 --- E O F --- 2008-09-19 21:49:34