Voila c'est fait par contre Combofix ne ma pas demandé de choisir Type 1 ou 2. Il a démarrer de suite? j'espère que ça à marché?
ComboFix 08-05-27.4 - sisiyeya 2008-05-28 15:10:40.3 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.444 [GMT 2:00]
Endroit: C:\Documents and Settings\sisiyeya\Mes documents\ComboFix.exe
Command switches used :: C:\Documents and Settings\sisiyeya\Bureau\CFScript.txt
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
FILE ::
C:\WINDOWS\awtUkKAr.dll
C:\WINDOWS\system32\awtUkKAr.dll
C:\WINDOWS\system32\sdryctep.dll
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\emovihev.dll
C:\WINDOWS\system32\FNnnmnpo.ini
C:\WINDOWS\system32\FNnnmnpo.ini2
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\opnmnnNF.dll
C:\WINDOWS\system32\petcyrds.ini
C:\WINDOWS\system32\tckfsnai.dll
C:\WINDOWS\system32\tkkixacd.ini
C:\WINDOWS\system32\tqsykkeg.dll
C:\WINDOWS\system32\UpMedia
C:\WINDOWS\system32\vehivome.ini
C:\WINDOWS\system32\xwlvoahr.dll
.
((((((((((((((((((((((((((((( Fichiers créés 2008-04-28 to 2008-05-28 ))))))))))))))))))))))))))))))))))))
.
2008-05-28 15:01 . 2008-05-28 15:01 <REP> d-------- C:\WINDOWS\LastGood
2008-05-28 13:07 . 2008-05-28 13:07 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-28 13:07 . 2008-05-28 13:07 <REP> d-------- C:\Documents and Settings\sisiyeya\Application Data\Malwarebytes
2008-05-28 13:07 . 2008-05-28 13:07 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-28 13:07 . 2008-05-05 20:46 27,048 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
2008-05-28 13:07 . 2008-05-05 20:46 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-05-28 01:40 . 2008-05-28 10:27 <REP> d-------- C:\Program Files\Navilog1
2008-05-28 01:37 . 2008-05-28 01:37 0 --a------ C:\WINDOWS\BM1be168b4.xml
2008-05-28 01:36 . 2008-05-28 14:48 530 --a------ C:\hpfr3420.xml
2008-05-27 13:40 . 2008-05-27 13:40 <REP> d-------- C:\Program Files\Lavasoft
2008-05-27 13:40 . 2008-05-27 13:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-16 11:58 . 2008-05-16 11:58 12,632 --a------ C:\WINDOWS\system32\lsdelete.exe
2008-04-29 11:40 . 2008-04-29 11:40 268 --ah----- C:\sqmdata17.sqm
2008-04-29 11:40 . 2008-04-29 11:40 244 --ah----- C:\sqmnoopt17.sqm
2008-04-29 11:20 . 2008-04-29 11:20 15,648 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys
2008-04-29 11:19 . 2008-04-29 11:19 15,648 --a------ C:\WINDOWS\system32\drivers\Awrtrd.sys
2008-04-29 11:19 . 2008-04-29 11:19 12,960 --a------ C:\WINDOWS\system32\drivers\Awrtpd.sys
2008-04-29 09:52 . 2008-04-29 09:52 244 --ah----- C:\sqmnoopt16.sqm
2008-04-29 09:52 . 2008-04-29 09:52 232 --ah----- C:\sqmdata16.sqm
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-27 22:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-27 20:41 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-05-27 20:41 --------- d-----w C:\Program Files\Google
2008-05-27 11:40 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-05-27 10:28 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-05-25 13:05 --------- d-----w C:\Program Files\TomTom HOME 2
2008-05-23 07:56 --------- d-----w C:\Documents and Settings\sisiyeya\Application Data\LimeWire
2008-05-17 20:29 --------- d-----w C:\Program Files\Picasa2
2008-05-09 06:48 --------- d-----w C:\Program Files\LimeWire
2008-04-11 19:59 --------- d-----w C:\Documents and Settings\sisiyeya\Application Data\CDBurnerXP_Soft
2008-04-11 19:58 --------- d-----w C:\Program Files\CDBurnerXP
2008-04-11 19:56 --------- d-----w C:\Program Files\Reference Assemblies
2008-04-11 19:56 --------- d-----w C:\Program Files\MSBuild
2008-04-11 19:51 --------- d-----w C:\Program Files\MSXML 6.0
2008-04-11 19:32 --------- d-----w C:\Program Files\Sonic
2008-04-11 18:55 --------- d-----w C:\Documents and Settings\sisiyeya\Application Data\ArcSoft
2008-04-11 18:41 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-29 22:08 --------- d-----w C:\Program Files\Realtek AC97
2008-03-29 21:23 315,392 ----a-w C:\WINDOWS\HideWin.exe
2008-03-29 21:23 --------- d-----w C:\Program Files\Realtek
2008-03-29 21:22 9,715,200 ----a-w C:\WINDOWS\RTLCPL.exe
2008-03-29 21:22 69,632 ----a-w C:\WINDOWS\Alcmtr.exe
2008-03-29 21:22 520,192 ----a-w C:\WINDOWS\RtlExUpd.dll
2008-03-29 21:22 4,687,872 ----a-w C:\WINDOWS\system32\drivers\RtkHDAud.sys
2008-03-29 21:22 2,808,832 ----a-w C:\WINDOWS\alcwzrd.exe
2008-03-29 21:22 2,165,760 ----a-w C:\WINDOWS\MicCal.exe
2008-03-29 21:22 16,858,112 ----a-w C:\WINDOWS\RTHDCPL.exe
2008-03-29 21:22 1,826,816 ----a-w C:\WINDOWS\SkyTel.exe
2008-03-29 21:22 1,191,936 ----a-w C:\WINDOWS\RtlUpd.exe
2008-03-29 20:10 --------- d-----w C:\Program Files\ATI Technologies
2008-03-29 19:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\SymplisIT
2008-03-29 19:21 --------- d-----w C:\Program Files\Windows Media Connect 2
2008-03-29 13:04 --------- d-----w C:\Program Files\Fichiers communs\Teleca Shared
2008-03-29 09:09 --------- d-----w C:\Program Files\Norton AntiVirus
2008-03-29 09:05 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-03-29 09:05 60,800 ----a-w C:\WINDOWS\system32\S32EVNT1.DLL
2008-03-29 09:05 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-03-29 09:05 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-03-29 09:05 --------- d-----w C:\Program Files\Symantec
2008-03-28 19:33 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-03-28 18:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-28 18:18 --------- d-----w C:\Program Files\Windows Sidebar
2008-03-28 17:50 --------- d-----w C:\Program Files\Java
2008-03-28 17:40 --------- d-----w C:\Documents and Settings\sisiyeya\Application Data\Symantec
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 621,344 ------w C:\WINDOWS\system32\dllcache\mswstr10.dll
2008-03-25 04:51 194,144 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-25 04:51 194,144 ------w C:\WINDOWS\system32\dllcache\msjint40.dll
2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-20 08:09 1,845,376 ------w C:\WINDOWS\system32\dllcache\win32k.sys
2008-03-01 16:28 3,591,680 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-02-29 08:57 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-02-29 08:56 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
.
(((((((((((((((((((((((((((((
snapshot@2008-05-28_11.43.05.54 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-28 08:24:14 262,144 ---ha-w C:\WINDOWS\system32\VSS\Documents and Settings\LocalService\NTUSER.DAT
+ 2008-05-28 11:45:41 262,144 ---ha-w C:\WINDOWS\system32\VSS\Documents and Settings\LocalService\NTUSER.DAT
- 2008-05-28 08:24:14 262,144 ---ha-w C:\WINDOWS\system32\VSS\Documents and Settings\NetworkService\NTUSER.DAT
+ 2008-05-28 11:45:41 262,144 ---ha-w C:\WINDOWS\system32\VSS\Documents and Settings\NetworkService\NTUSER.DAT
- 2008-05-28 08:24:14 3,145,728 ---ha-w C:\WINDOWS\system32\VSS\Documents and Settings\sisiyeya\NTUSER.DAT
+ 2008-05-28 11:45:16 3,145,728 ---ha-w C:\WINDOWS\system32\VSS\Documents and Settings\sisiyeya\NTUSER.DAT
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
2008-03-28 20:56 116088 --a------ C:\PROGRA~1\FICHIE~1\SYMANT~1\IDS\IPSBHO.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 01:09 15360]
"TomTomHOME.exe"="C:\Program Files\TomTom HOME 2\HOMERunner.exe" [2008-05-06 10:42 202088]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2003-06-05 13:35 335872]
"Protect"="SHVRTF.EXE" [2003-09-15 20:00 1011712 C:\WINDOWS\system32\SHVRTF.EXE]
"BJCFD"="C:\Program Files\BroadJump\Client Foundation\CFD.exe" [2003-01-27 17:16 376912]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 20:51 39792]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2008-02-14 12:01 51048]
"osCheck"="C:\Program Files\Norton AntiVirus\osCheck.exe" [2007-08-24 22:53 714608]
"SoundMan"="SOUNDMAN.EXE" [2007-04-16 16:28 577536 C:\WINDOWS\soundman.exe]
"18d25b28"="C:\WINDOWS\system32\sdryctep.dll" [ ]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-20 01:09 15360]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2008-02-26 03:23 443968]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSACM.CEGSM"= mobilev.acm
"VIDC.YV12"= yv12vfw.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"=
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 LiveUpdate Notice;LiveUpdate Notice;"C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon []
R2 NMSAccessU;NMSAccessU;C:\Program Files\CDBurnerXP\NMSAccessU.exe [2008-03-09 11:20]
R3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-04 07:58]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 08:08]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-03-06 22:32]
S3 P1130VID;Creative WebCam NX Pro;C:\WINDOWS\system32\DRIVERS\P1130Vid.sys [2003-05-08 03:00]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\Shell\AutoRun\command - Info.exe folder.htt 480 480
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-04-14 19:54:08 C:\WINDOWS\Tasks\Norton AntiVirus - Effectuer une analyse complète du système - sisiyeya.job"
- C:\Program Files\Norton AntiVirus\Navw32.exeh/TASK:
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-28 15:11:30
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
C:\WINDOWS\explorer.exe [2868] 0x81AA4728
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-05-28 15:12:39
ComboFix-quarantined-files.txt 2008-05-28 13:12:08
Pre-Run: 36,504,715,264 octets libres
Post-Run: 36,495,208,448 octets libres
189 --- E O F --- 2008-05-16 18:53:14