bonjour
Voici le rapport de ce mation de combofix:
ComboFix 08-10-04.07 - admin 2008-10-11 10:46:32.2 - NTFSx86 MINIMAL
Lancé depuis: C:\Documents and Settings\admin\Bureau\ComboFix.exe
[B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B]
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-11 au 2008-10-11 ))))))))))))))))))))))))))))))))))))
.
2008-10-10 11:27 . 2008-10-10 11:27 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-10-10 10:49 . 2008-10-10 10:49 268 --ah----- C:\sqmdata07.sqm
2008-10-10 10:49 . 2008-10-10 10:49 244 --ah----- C:\sqmnoopt07.sqm
2008-10-09 21:25 . 2008-10-09 21:25 <REP> d-------- C:\Program Files\Yahoo!
2008-10-09 21:24 . 2008-10-09 21:26 <REP> d-------- C:\Program Files\CCleaner
2008-10-09 20:43 . 2008-10-09 20:43 <REP> d-------- C:\_OTMoveIt
2008-10-08 20:24 . 2008-04-17 13:12 107,368 --a------ C:\WINDOWS\system32\GEARAspi.dll
2008-10-08 20:24 . 2008-04-17 13:12 15,464 --a------ C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
2008-10-08 20:23 . 2008-10-08 20:24 <REP> d-------- C:\Program Files\iTunes
2008-10-08 20:23 . 2008-10-08 20:23 <REP> d-------- C:\Program Files\iPod
2008-10-08 20:23 . 2008-10-08 20:24 <REP> d-------- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-10-08 20:22 . 2008-10-08 20:22 <REP> d-------- C:\Program Files\Bonjour
2008-10-08 20:17 . 2008-10-08 20:21 <REP> d-------- C:\Program Files\QuickTime
2008-10-08 20:17 . 2008-10-08 20:23 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-10-08 20:15 . 2008-10-08 20:16 <REP> d-------- C:\Program Files\Apple Software Update
2008-10-08 20:15 . 2008-10-01 13:01 32,000 --a------ C:\WINDOWS\system32\drivers\usbaapl.sys
2008-10-08 20:13 . 2008-10-08 20:18 <REP> d-------- C:\Program Files\Fichiers communs\Apple
2008-10-08 20:13 . 2008-10-08 20:13 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-10-07 20:29 . 2008-10-07 20:29 1,674 --a------ C:\WINDOWS\system32\tmp.reg
2008-10-07 20:29 . 2008-10-07 20:29 0 --a------ C:\WINDOWS\system32\tmp.MSNFix
2008-10-07 18:22 . 2008-10-10 19:13 <REP> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-10-06 20:15 . 2008-10-06 20:27 <REP> d-------- C:\Program Files\Navilog1
2008-10-05 12:10 . 2008-10-05 12:10 <REP> d-------- C:\Documents and Settings\admin\Contacts
2008-10-05 10:53 . 2008-10-05 10:53 <REP> d-------- C:\Program Files\Trend Micro
2008-10-05 10:53 . 2008-10-05 10:53 268 --ah----- C:\sqmdata06.sqm
2008-10-05 10:53 . 2008-10-05 10:53 244 --ah----- C:\sqmnoopt06.sqm
2008-10-04 18:36 . 2008-10-05 16:31 <REP> d-------- C:\nettoyage
2008-10-04 16:06 . 2008-10-04 16:06 268 --ah----- C:\sqmdata05.sqm
2008-10-04 16:06 . 2008-10-04 16:06 244 --ah----- C:\sqmnoopt05.sqm
2008-09-28 16:51 . 2008-10-05 14:28 <REP> d--h----- C:\Documents and Settings\admin\Voisinage réseau
2008-09-28 16:51 . 2007-12-28 16:35 <REP> d--h----- C:\Documents and Settings\admin\Voisinage d'impression
2008-09-28 16:51 . 2007-12-28 15:47 <REP> d--h----- C:\Documents and Settings\admin\Modèles
2008-09-28 16:51 . 2008-10-05 12:13 <REP> dr------- C:\Documents and Settings\admin\Mes documents
2008-09-28 16:51 . 2007-12-28 16:35 <REP> dr------- C:\Documents and Settings\admin\Menu Démarrer
2008-09-28 16:51 . 2008-09-28 16:52 <REP> dr------- C:\Documents and Settings\admin\Favoris
2008-09-28 16:51 . 2008-10-09 21:24 <REP> d-------- C:\Documents and Settings\admin\Bureau
2008-09-28 16:51 . 2008-10-09 21:27 <REP> d-------- C:\Documents and Settings\admin
2008-09-27 22:19 . 2008-09-27 22:19 268 --ah----- C:\sqmdata04.sqm
2008-09-27 22:19 . 2008-09-27 22:19 244 --ah----- C:\sqmnoopt04.sqm
2008-09-27 20:14 . 2008-09-27 20:14 268 --ah----- C:\sqmdata03.sqm
2008-09-27 20:14 . 2008-09-27 20:14 244 --ah----- C:\sqmnoopt03.sqm
2008-09-27 20:03 . 2008-09-27 20:03 268 --ah----- C:\sqmdata02.sqm
2008-09-27 20:03 . 2008-09-27 20:03 244 --ah----- C:\sqmnoopt02.sqm
2008-09-27 19:39 . 2008-09-27 19:39 268 --ah----- C:\sqmdata01.sqm
2008-09-27 19:39 . 2008-09-27 19:39 244 --ah----- C:\sqmnoopt01.sqm
2008-09-27 19:10 . 2008-10-10 10:45 <REP> d-------- C:\Documents and Settings\vhurel
2008-09-27 19:06 . 2008-09-27 19:08 <REP> d-------- C:\Documents and Settings\Administrateur\amsn
2008-09-27 14:55 . 2008-09-27 14:55 268 --ah----- C:\sqmdata00.sqm
2008-09-27 14:55 . 2008-09-27 14:55 244 --ah----- C:\sqmnoopt00.sqm
2008-09-27 13:29 . 2008-09-27 13:29 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Malwarebytes
2008-09-27 13:27 . 2007-12-28 16:35 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
2008-09-27 13:27 . 2007-12-28 16:35 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-09-27 13:27 . 2007-12-28 15:47 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
2008-09-27 13:27 . 2008-10-10 10:47 <REP> dr------- C:\Documents and Settings\Administrateur\Mes documents
2008-09-27 13:27 . 2007-12-28 16:35 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
2008-09-27 13:27 . 2008-10-10 10:47 <REP> dr------- C:\Documents and Settings\Administrateur\Favoris
2008-09-27 13:27 . 2008-10-11 10:50 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2008-09-27 13:27 . 2008-09-27 19:06 <REP> d-------- C:\Documents and Settings\Administrateur
2008-09-27 12:09 . 2008-09-27 12:30 16 --a------ C:\WINDOWS\system32\drivers\ksdevice.sys
2008-09-27 12:09 . 2008-09-27 12:30 16 --a------ C:\WINDOWS\system32\drivers\KeenSense.sys
2008-09-18 19:13 . 2008-09-19 12:45 <REP> d-------- C:\WINDOWS\system32\fr
2008-09-18 19:13 . 2008-09-19 12:45 <REP> d-------- C:\WINDOWS\system32\bits
2008-09-18 19:13 . 2008-09-19 12:42 <REP> d-------- C:\WINDOWS\l2schemas
2008-09-18 18:38 . 2004-08-19 16:09 4,290,048 --a------ C:\WINDOWS\system32\dllcache\wmm2res.dll
2008-09-18 18:37 . 2004-08-19 16:11 4,190,352 --a------ C:\WINDOWS\system32\dllcache\luna.mst
2008-09-18 18:36 . 2005-09-10 03:55 2,067,968 --a------ C:\WINDOWS\system32\dllcache\cdosys.dll
2008-09-18 18:35 . 2007-04-18 18:14 2,854,400 --a------ C:\WINDOWS\system32\dllcache\msi.dll
2008-09-18 18:34 . 2007-10-25 18:43 8,516,608 --a------ C:\WINDOWS\system32\dllcache\shell32.dll
2008-09-18 18:33 . 2007-02-28 18:02 2,182,400 --a------ C:\WINDOWS\system32\ntoskrnl.exe
2008-09-13 16:04 . 2008-09-13 16:04 121 --a------ C:\WINDOWS\Winchat.ini
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-11 08:39 839,712 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
2008-10-11 08:39 79,184 --sha-w C:\WINDOWS\system32\drivers\fidbox2.idx
2008-10-11 08:39 199,952 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
2008-10-11 08:39 14,810,912 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2008-10-11 08:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-09-13 09:42 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
2008-09-09 22:04 38,528 ----a-w C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-09 22:03 17,200 ----a-w C:\WINDOWS\system32\drivers\mbam.sys
2008-09-06 20:19 --------- d-----w C:\Program Files\aMSN
2008-09-06 11:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\TEMP
2008-09-06 10:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-09-06 08:58 --------- d-----w C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-29 08:18 87,336 ----a-w C:\WINDOWS\system32\dns-sd.exe
2008-08-29 07:53 61,440 ----a-w C:\WINDOWS\system32\dnssd.dll
2008-08-16 17:34 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-07-20 17:52 10,050 ----a-w C:\WINDOWS\system32\shutdown.zip
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2006-12-09 19:11 71,357 ----a-w C:\Program Files\Love-Test(www.MsnTrucAstuce.fr).plsc
2006-11-17 17:22 284,139 ----a-w C:\Program Files\Ultimate(biensur)www.MsnTrucAstuce.fr).plsc
2006-10-12 15:46 2,201 ----a-w C:\Program Files\Huhu Leet 1.0(www.MsnTrucAstuce.free.fr).plsc
.
(((((((((((((((((((((((((((((
snapshot@2008-10-05_15.59.56.28 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-10-08 18:16:21 27,136 ----a-r C:\WINDOWS\Installer\{6956856F-B6B3-4BE0-BA0B-8F495BE32033}\AppleSoftwareUpdateIco.exe
+ 2008-10-08 18:22:19 86,016 ----a-r C:\WINDOWS\Installer\{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}\PrntWzrdIco.exe
+ 2008-10-08 18:26:06 102,400 ----a-r C:\WINDOWS\Installer\{DDDE0BE3-0CBE-4BF6-B75A-E3F69C947843}\iTunesIco.exe
- 2008-10-03 08:16:30 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
+ 2008-10-10 07:18:37 16,384 ----a-w C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat
- 2008-10-03 08:16:30 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\index.dat
+ 2008-10-10 07:18:37 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\index.dat
- 2008-10-03 08:16:30 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-10-10 07:18:37 32,768 ----a-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-10-10 20:05:59 2,512 ----a-w C:\WINDOWS\system32\d3d9caps.dat
+ 2008-04-17 11:12:54 107,368 -c--a-w C:\WINDOWS\system32\DRVSTORE\GEARAspiWD_D213663B6381F01E45A131159A9DEFE018321CB3\x86\GEARAspi.dll
+ 2008-04-17 11:12:54 15,464 -c--a-w C:\WINDOWS\system32\DRVSTORE\GEARAspiWD_D213663B6381F01E45A131159A9DEFE018321CB3\x86\GEARAspiWDM.sys
+ 2008-10-01 11:01:28 32,000 -c--a-w C:\WINDOWS\system32\DRVSTORE\usbaapl_246F92BBD6449C86FC3F3F28C40D59AC1F69C558\usbaapl.sys
+ 2006-12-01 20:54:32 479,232 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll
+ 2006-12-01 20:54:34 548,864 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
+ 2006-12-01 20:54:32 626,688 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe" [2005-09-08 94208]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb05.exe" [2002-03-18 188416]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-19 15360]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.exe.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2007-12-28 110592]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\rtcshare.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"\\\\C000273\\Diablo\\Diablo.exe"=
"C:\\WINDOWS\\system32\\dplaysvr.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\Kaspersky Lab Setup Files\\Kaspersky Anti-Virus 7.0.1.325\\French\\setup.exe"=
"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"C:\\WINDOWS\\system32\\usmt\\migwiz.exe"=
"C:\\Program Files\\aMSN\\bin\\wish.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
S3 G200;G200;C:\WINDOWS\system32\DRIVERS\G200m.sys [2001-08-23 320512]
S3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-12-13 24592]
.
Contenu du dossier 'Tâches planifiées'
2008-07-16 C:\WINDOWS\Tasks\!cid_605.job
- C:\Documents and Settings\viviane\Mes documents\Mes images\!cid_605.jpg []
.
.
------- Examen supplémentaire -------
.
O16 -: Microsoft XML Parser for Java -
file://C:\WINDOWS\Java\classes\xmldso.cab
C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-11 10:50:23
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-10-11 10:54:19
ComboFix-quarantined-files.txt 2008-10-11 08:53:49
ComboFix2.txt 2008-10-05 14:06:13
Avant-CF: 2 033 836 032 octets libres
Après-CF: 2,024,787,968 octets libres
195 --- E O F --- 2008-10-10 16:51:13
Va suivre le rapport de msnfix.
Je voulais te dire aussi que dans le raport c'est indiqué que la console de récupération n'est pas installée... comment faire pour la manip avec le cd XP ?
Je pense qu'il faudrait un utilitaire encore plus puissant que otmove non ?
Comment faire pour installer la console de récupération ?
A plus grisonnant 28