voici le rapport combofix: pour info la page de pub contiue de s'ouvrir.....
merci à vous:
ComboFix 08-11-17.06 - nabil 2008-11-18 18:20:35.1 - NTFSx86 MINIMAL
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.177 [GMT 1:00]
Lancé depuis: c:\documents and settings\nabil\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
c:\program files\INSTALL.LOG
c:\program files\internet optimizer
c:\windows.2\Downloaded Program Files\setup.inf
c:\windows.2\system32\command.pif
c:\windows.2\system32\msupdte.exe
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_BOONTY_GAMES
-------\Service_Boonty Games
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-18 au 2008-11-18 ))))))))))))))))))))))))))))))))))))
.
2008-11-18 18:15 . 2008-11-18 18:15 <REP> d-------- c:\program files\Antipub
2008-11-12 16:23 . 2008-10-24 12:21 455,296 -----c--- c:\windows.2\system32\dllcache\mrxsmb.sys
2008-11-12 16:22 . 2008-09-04 18:16 1,106,944 -----c--- c:\windows.2\system32\dllcache\msxml3.dll
2008-11-06 14:07 . 2008-11-18 18:14 <REP> d-------- c:\program files\Navilog1
2008-11-06 00:01 . 2008-11-02 17:50 5,714 --a--c--- C:\bootini.exe
2008-11-02 17:12 . 2008-04-13 20:40 34,688 --a------ c:\windows.2\system32\drivers\lbrtfdc.sys
2008-11-02 17:12 . 2008-04-13 20:40 34,688 --a--c--- c:\windows.2\system32\dllcache\lbrtfdc.sys
2008-11-02 17:12 . 2008-04-13 20:41 8,576 --a------ c:\windows.2\system32\drivers\i2omgmt.sys
2008-11-02 17:12 . 2008-04-13 20:41 8,576 --a--c--- c:\windows.2\system32\dllcache\i2omgmt.sys
2008-11-02 17:12 . 2008-04-13 20:40 8,192 --a------ c:\windows.2\system32\drivers\changer.sys
2008-11-02 17:12 . 2008-04-13 20:40 8,192 --a--c--- c:\windows.2\system32\dllcache\changer.sys
2008-10-24 10:40 . 2008-10-15 17:35 337,408 -----c--- c:\windows.2\system32\dllcache\netapi32.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-18 12:48 --------- d-----w c:\documents and settings\All Users.WINDOWS.2\Application Data\AntiVir PersonalEdition Classic
2008-11-11 12:04 --------- d-----w c:\program files\eMule
2008-11-05 22:26 --------- d-----w c:\program files\orange
2008-11-05 18:52 --------- d-----w c:\program files\Fichiers communs\Oberon Media
2008-11-02 17:52 --------- d-----w c:\documents and settings\nabil\Application Data\Skype
2008-11-02 17:48 --------- d-----w c:\documents and settings\nabil\Application Data\skypePM
2008-11-02 15:00 --------- d---a-w c:\documents and settings\All Users.WINDOWS.2\Application Data\TEMP
2008-11-01 10:54 --------- d-----w c:\documents and settings\All Users.WINDOWS.2\Application Data\SpinTop Games
2008-10-24 11:21 455,296 ----a-w c:\windows.2\system32\drivers\mrxsmb.sys
2008-10-16 13:13 202,776 ----a-w c:\windows.2\system32\wuweb.dll
2008-10-16 13:13 1,809,944 ----a-w c:\windows.2\system32\wuaueng.dll
2008-10-16 13:12 561,688 ----a-w c:\windows.2\system32\wuapi.dll
2008-10-16 13:12 323,608 ----a-w c:\windows.2\system32\wucltui.dll
2008-10-16 13:09 92,696 ----a-w c:\windows.2\system32\cdm.dll
2008-10-16 13:09 51,224 ----a-w c:\windows.2\system32\wuauclt.exe
2008-10-16 13:09 43,544 ----a-w c:\windows.2\system32\wups2.dll
2008-10-16 13:08 34,328 ----a-w c:\windows.2\system32\wups.dll
2008-10-16 13:06 268,648 ----a-w c:\windows.2\system32\mucltui.dll
2008-10-16 13:06 208,744 ----a-w c:\windows.2\system32\muweb.dll
2008-10-15 09:16 --------- d-----w c:\documents and settings\All Users.WINDOWS.2\Application Data\FarmFrenzy2
2008-10-13 16:06 --------- d-----w c:\documents and settings\nabil\Application Data\TransRender
2008-10-13 16:06 --------- d-----w c:\documents and settings\nabil\Application Data\Temporary
2008-10-13 06:51 --------- d--h--w c:\program files\InstallShield Installation Information
2008-10-11 18:31 --------- d-----w c:\program files\SweetIM
2008-10-11 18:30 --------- d-----w c:\documents and settings\All Users.WINDOWS.2\Application Data\SweetIM
2008-09-30 15:43 1,286,152 ----a-w c:\windows.2\system32\msxml4.dll
2008-09-30 12:01 --------- d-----w c:\program files\LGE GSM PC Sync
2008-09-30 12:00 --------- d-----w c:\documents and settings\nabil\Application Data\InstallShield
2008-09-30 11:57 --------- d-----w c:\documents and settings\nabil\Application Data\LG Electronics
2008-09-30 11:27 --------- d-----w c:\documents and settings\nabil\Application Data\LGSync
2008-09-18 11:45 --------- d-----w c:\program files\HomePlayer
2008-09-15 15:26 1,846,528 ----a-w c:\windows.2\system32\win32k.sys
2008-09-10 01:15 1,307,648 ----a-w c:\windows.2\system32\msxml6.dll
2008-09-04 17:16 1,106,944 ----a-w c:\windows.2\system32\msxml3.dll
2008-08-26 08:11 826,368 ----a-w c:\windows.2\system32\wininet.dll
2008-05-21 20:34 0 ----a-w c:\program files\temp01
2008-05-14 20:43 32 ----a-w c:\documents and settings\All Users.WINDOWS.2\Application Data\ezsid.dat
2007-11-18 00:44 95,752 ----a-w c:\documents and settings\nabil\Application Data\GDIPFONTCACHEV1.DAT
2006-04-11 19:57 774,144 ----a-w c:\program files\RngInterstitial.dll
2003-10-25 23:01 1,060 ----a-w c:\documents and settings\mestoura\settings.bin
2001-11-27 00:40 319,488 ----a-w c:\documents and settings\mestoura\setup.exe
2000-11-03 00:23 2,257,447 ----a-w c:\program files\instalNo.exe
2008-08-06 06:12 32,768 --sha-w c:\windows.2\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008080620080807\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-02-27 67128]
"ctfmon.exe"="c:\windows.2\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2005-11-09 155648]
"NvCplDaemon"="c:\windows.2\system32\NvCpl.dll" [2005-12-10 7311360]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-04-22 185896]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2008-09-28 111928]
"MSBoot Init"="c:\bootini.exe" [2008-11-02 5714]
"avgnt"="c:\program files\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-18 266497]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows.2\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\nabil\Menu D‚marrer\Programmes\D‚marrage\
Anti-Pub.lnk - c:\program files\Antipub\antipub.exe [2003-03-23 674304]
c:\documents and settings\All Users.WINDOWS.2\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.exe.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2002-09-19 113664]
Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-02-27 67128]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 83360]
NkbMonitor.exe.lnk - c:\program files\Nikon\PictureProject\NkbMonitor.exe [2007-06-08 118784]
Ralink Wireless Utility.lnk - c:\program files\RALINK\RT2500 Wireless LAN Card\Installer\WINXP\RaConfig2500.exe [2007-04-28 540672]
Rappels du Calendrier Microsoft Works.lnk - c:\program files\Fichiers communs\Microsoft Shared\Works Shared\wkcalrem.exe [2001-10-05 24633]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.l3acm"= l3codecp.acm
"vidc.dvsd"= dvc.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\regedit.exe]
"Debugger"=0
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\taskmgr.exe]
"Debugger"=0
[HKLM\~\startupfolder\C:^Documents and Settings^All Users.WINDOWS.2^Menu Démarrer^Programmes^Démarrage^E-Compagnon.lnk]
path=c:\documents and settings\All Users.WINDOWS.2\Menu Démarrer\Programmes\Démarrage\E-Compagnon.lnk
backup=c:\windows.2\pss\E-Compagnon.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechImageStudioTray]
--a------ 2002-06-20 12:25 45056 c:\program files\Logitech\ImageStudio\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2005-11-09 22:25 155648 c:\program files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Free.fr\\connect.exe"=
"c:\\Valve\\Steam\\steamapps\\mestourakarim\\condition zero\\hl.exe"=
"c:\\Documents and Settings\\nabil\\Mes documents\\Mes fichiers reçus\\Skype.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\RALINK\\RT2500 Wireless LAN Card\\Installer\\WINXP\\RaConfig2500.exe"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Valve\\Steam\\Steam.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Valve\\Steam\\steamapps\\mestourakarim\\counter-strike\\hl.exe"=
"c:\\Program Files\\HomePlayer\\HomePlayer.exe"=
"c:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
.
- - - - ORPHELINS SUPPRIMES - - - -
WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
HKCU-Run-WINSOS VERIFY - c:\program files\Winsos\WINSOS.EXE
HKCU-Run-Sofres Ad Test - c:\windows.2\system32\TNSClient.exe
HKCU-Run-Microsoft Works Update Detection - c:\program files\Microsoft Works\WkDetect.exe
HKCU-Run-WebCamRT.exe - (no file)
HKCU-Run-Steam - (no file)
HKLM-Run-Microsoft WinUpdate - c:\windows.2\system32\msupdte.exe
MSConfigStartUp-LDM - c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
MSConfigStartUp-Lexmark X74-X75 - c:\program files\Lexmark X74-X75\lxbbbmgr.exe
MSConfigStartUp-WOOKIT - c:\program files\Wanadoo\GestMaj.exe
.
------- Examen supplémentaire -------
.
FireFox -: Profile - c:\documents and settings\nabil\Application Data\Mozilla\Firefox\Profiles\vaolj1ph.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE -
hxxp://www.ircdown.com/fr/index.php?rvs=hompag&d=79919193
.
.
------- Associations de fichier -------
.
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-11-18 18:34:50
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\AntiVir PersonalEdition Classic\avguard.exe
c:\program files\AntiVir PersonalEdition Classic\sched.exe
c:\windows.2\system32\drivers\CDAC11BA.EXE
c:\windows.2\system32\drivers\CDANTSRV.EXE
c:\windows.2\system32\nvsvc32.exe
c:\windows.2\system32\slserv.exe
c:\program files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
c:\program files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
c:\program files\Internet Explorer\iexplore.exe
.
**************************************************************************
.
Heure de fin: 2008-11-18 19:00:23 - La machine a redémarré [nabil]
ComboFix-quarantined-files.txt 2008-11-18 17:59:58
Avant-CF: 4,084,080,640 octets libres
Après-CF: 4,245,110,784 octets libres
198 --- E O F --- 2008-11-12 16:21:48