Bonjour dédétraqué, merci de ta réponse.
Joyeux Noël à vous tous !!!!!
Voici le scan de combofix :
ComboFix 07-12-24.9 - MALLORY 2007-12-24 16:57:46.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.343 [GMT 1:00]
Running from: C:\Documents and Settings\MALLORY\Bureau\ComboFix.exe
* Created a new restore point
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\WINDOWS\system32\service.exe
C:\WINDOWS\system32\SysPr.prx
D:\Autorun.inf
E:\Autorun.inf
O:\copy.exe
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-11-24 to 2007-12-24 ))))))))))))))))))))))))))))))))))))
.
2007-12-22 00:44 . 2002-03-11 09:32 <REP> d-------- C:\Documents and Settings\Administrateur\WINDOWS
2007-12-22 00:44 . 2002-03-11 08:52 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage r‚seau
2007-12-22 00:44 . 2002-03-11 08:52 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2007-12-22 00:44 . 2002-04-19 10:20 <REP> d--h----- C:\Documents and Settings\Administrateur\ModŠles
2007-12-22 00:44 . 2002-04-18 22:08 <REP> dr------- C:\Documents and Settings\Administrateur\Mes documents
2007-12-22 00:44 . 2002-03-11 08:52 <REP> dr------- C:\Documents and Settings\Administrateur\Menu D‚marrer
2007-12-22 00:44 . 2002-03-11 14:11 <REP> dr------- C:\Documents and Settings\Administrateur\Favoris
2007-12-22 00:44 . 2002-03-11 10:23 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2007-12-22 00:44 . 2002-03-11 09:40 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\InterTrust
2007-12-22 00:44 . 2002-03-11 14:01 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\CyberLink
2007-12-21 13:10 . 2007-12-21 13:10 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-12-21 13:10 . 2007-12-21 13:10 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2007-12-16 21:46 . 2007-12-22 21:38 <REP> d--hs---- C:\Recycled
2007-12-14 18:44 . 2007-12-14 18:44 <REP> d-------- C:\Documents and Settings\MALLORY\Contacts
2007-12-14 18:43 . 2007-12-14 18:43 <REP> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-12-01 13:50 . 2007-12-01 13:49 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2007-12-01 13:49 . 2007-12-01 13:50 <REP> d-------- C:\Documents and Settings\MALLORY\.housecall6.6
2007-12-01 13:39 . 2007-12-01 13:48 <REP> d-------- C:\Program Files\RegCleaner
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-21 23:47 --------- d-----w C:\Program Files\a-squared Free
2007-12-21 21:56 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2007-12-18 14:09 --------- d-----w C:\Program Files\Quake III Arena
2007-12-17 16:11 --------- d-----w C:\Documents and Settings\JAIME\Application Data\Skype
2007-12-16 14:25 --------- d-----w C:\Documents and Settings\MALLORY\Application Data\LimeWire
2007-12-14 17:44 --------- d-----w C:\Program Files\MSN Messenger
2007-12-03 17:06 --------- d-----w C:\Documents and Settings\MALLORY\Application Data\Skype
2007-11-30 12:33 --------- d-----w C:\Program Files\The All-Seeing Eye
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-03 20:35 --------- d-----w C:\Program Files\Common Files
2007-11-02 20:46 --------- d-----w C:\Program Files\Norton AntiVirus
2007-11-02 20:42 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2007-11-02 20:42 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2007-11-02 20:42 10,740 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2007-11-02 20:42 --------- d-----w C:\Program Files\Symantec
2007-11-02 20:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-06-20 15:17 47,152 ----a-w C:\Documents and Settings\JAIME\Application Data\GDIPFONTCACHEV1.DAT
2006-12-05 20:29 47,152 ----a-w C:\Documents and Settings\MALLORY\Application Data\GDIPFONTCACHEV1.DAT
2004-12-16 17:54 46,768 ----a-w C:\Documents and Settings\MAUD\Application Data\GDIPFONTCACHEV1.DAT
1999-03-30 16:06 20,480 ----a-w C:\Documents and Settings\MALLORY\RegSetUp.exe
1999-03-30 15:15 2,968,576 ----a-w C:\Documents and Settings\MALLORY\Coman_mp.exe
1999-03-23 15:30 178,688 ----a-w C:\Documents and Settings\MALLORY\MSS32.DLL
1999-03-22 19:53 2,982,400 ----a-w C:\Documents and Settings\MALLORY\Tutorial.exe
1999-03-22 17:16 79,872 ----a-w C:\Documents and Settings\MALLORY\setup.exe
1999-03-19 00:59 158,208 ----a-w C:\Documents and Settings\MALLORY\Ace.exe
1999-01-26 10:38 107,008 ----a-w C:\Documents and Settings\MALLORY\mpserver.exe
1998-10-30 10:22 113,152 ----a-w C:\Documents and Settings\MALLORY\MSS16.DLL
2006-02-14 22:35 2 --shatr C:\WINDOWS\winstart.bat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SuperCopier2.exe"="C:\Program Files\SuperCopier2\SuperCopier2.exe" [2006-07-07 17:45]
"H/PC Connection Agent"="D:\program files\Navman\WCESCOMM.EXE" [2004-02-24 15:20]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VirtualCloneDrive"="D:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2004-08-20 11:28]
"SoundMan"="SOUNDMAN.EXE" [2003-01-20 10:48 C:\WINDOWS\SOUNDMAN.EXE]
"NvMediaCenter"="RUNDLL32.exe" [2004-08-20 00:10 C:\WINDOWS\system32\rundll32.exe]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-20 00:10 C:\WINDOWS\system32\rundll32.exe]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2005-11-08 23:00]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-04-26 18:25]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-02-23 15:45]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2007-01-22 22:19]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 09:50]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00]
"Symantec PIF AlertEng"="C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2006-07-25 18:03]
"Symantec Network Driver Update Warning"="C:\PROGRA~1\Symantec\LIVEUP~1\SNDWarn.EXE" []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoLogoff"= 0 (0x0)
"NoSharedDocuments"= 00000000
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli scecli
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, zwebauth.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech Desktop Messenger Agent.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech Desktop Messenger Agent.lnk
backup=C:\WINDOWS\pss\Logitech Desktop Messenger Agent.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Anti-Blaxx Manager]
2005-05-18 16:08 208896 --a------ C:\Program Files\Anti-Blaxx\Anti-Blaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BullsEye Network]
C:\Program Files\BullsEye Network\bin\bargains.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Cash software plan real]
C:\Documents and Settings\All Users\Application Data\rect dumb cash software\partmpeg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DownloadWare]
C:\Program Files\DownloadWare\dw.exe /H
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Forbes]
C:\Program Files\Forbes\ForbesAlerts.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\gcasServ]
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
2004-02-24 15:20 401491 --a------ D:\program files\Navman\WCESCOMM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
2005-05-12 22:28 32768 --a------ C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\math remote bib exit]
C:\Documents and Settings\All Users\Application Data\OOZE LIST MATH REMOTE\Kind Meta.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MediaLoads Installer]
C:\Program Files\DownloadWare\dw.exe /H
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MNI.UWFX5V_0001_LP]
C:\Documents and Settings\MALLORY\Mes documents\WinFixer2005ScannerInstallFRA.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PromulGate]
C:\Program Files\DelFin\PromulGate\PgMonitr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Rulelies]
C:\DOCUME~1\MALLORY\APPLIC~1\MOVEAN~1\citypeakgreat.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\salm]
c:\temp\salm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
e:\valve\steam\steam.exe -silent
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebRebates0]
C:\Program Files\Web_Rebates\WebRebates0.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WildTangent CDA]
C:\Program Files\WildTangent\Apps\CDA\GameDrvr.exe /startup C:\Program Files\WildTangent\Apps\CDA\cdaEngine0500.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ewido security suite control"=2 (0x2)
"a2free"=2 (0x2)
R2 nvcap;nVidia WDM Video Capture (universal);C:\WINDOWS\system32\DRIVERS\nvcap.sys [2002-12-17 11:54]
R2 NVXBAR;nVidia WDM A/V Crossbar;C:\WINDOWS\system32\DRIVERS\NVxbar.sys [2002-12-17 11:54]
R3 Intels51;Creatix V.9X DSP Data Fax Modem;C:\WINDOWS\system32\DRIVERS\ctxs51.sys [2002-07-01 15:10]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 07:08]
S0 ElbyVCD;ElbyVCD;C:\WINDOWS\system32\DRIVERS\ElbyVCD.sys []
S3 fbxusb;FreeBox USB Network Adapter;C:\WINDOWS\system32\DRIVERS\fbxusb.sys [2002-12-10 19:27]
S3 sscdbus;SAMSUNG USB Composite Device driver (WDM);C:\WINDOWS\system32\DRIVERS\sscdbus.sys [2005-12-22 12:24]
S3 sscdmdfl;SAMSUNG CDMA Modem Filter;C:\WINDOWS\system32\DRIVERS\sscdmdfl.sys [2005-12-22 12:24]
S3 sscdmdm;SAMSUNG CDMA Modem Drivers;C:\WINDOWS\system32\DRIVERS\sscdmdm.sys [2005-12-22 12:24]
S3 v800bus;Sony Ericsson V800-Vodafone 802SE driver (WDM);C:\WINDOWS\system32\DRIVERS\v800bus.sys [2004-08-09 13:51]
S3 v800mdfl;Sony Ericsson V800-Vodafone 802SE USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\v800mdfl.sys [2004-08-09 13:52]
S3 v800mdm;Sony Ericsson V800-Vodafone 802SE USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\v800mdm.sys [2004-08-09 13:53]
S3 v800mgmt;Sony Ericsson V800-Vodafone 802SE USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\v800mgmt.sys [2004-08-09 13:54]
S3 v800obex;Sony Ericsson V800-Vodafone 802SE USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\v800obex.sys [2004-08-09 13:55]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\C]
\Shell\AutoRun\command - explorer.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - explorer.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
\Shell\AutoRun\command - explorer.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\I]
\Shell\AutoRun\command - I:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{05713004-850b-11db-982c-806d6172696f}]
\Shell\AutoRun\command - G:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2c89e486-c4da-11da-9782-806d6172696f}]
\Shell\AutoRun\command - I:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2c8b492a-8a8f-11db-9672-806d6172696f}]
\Shell\AutoRun\command - G:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{62385285-a07f-11da-a15b-806d6172696f}]
\Shell\AutoRun\command - H:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{70b1f886-a768-11da-ab15-806d6172696f}]
\Shell\AutoRun\command - I:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{78759e8a-29f3-11d9-9841-0007cb0000ff}]
\Shell\AutoRun\command - H:\loader.exe /no hidden
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{7a89d49c-bb69-11db-b7b3-000c760806f2}]
\Shell\AutoRun\command - H:\ReadMe.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{83587096-2b02-11dc-a4f1-000c760806f2}]
\Shell\AutoRun\command - H:\ReadMe.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{864e3486-7bb9-11db-a957-806d6172696f}]
\Shell\AutoRun\command - I:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8cac93d2-8c1b-11db-8e8c-806d6172696f}]
\Shell\AutoRun\command - I:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a6c07783-fc8d-11db-9e15-000c760806f2}]
\Shell\AutoRun\command - H:\ReadMe.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d42b15d2-ae7a-11da-b46e-806d6172696f}]
\Shell\AutoRun\command - I:\Autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e12b978c-3b5d-11dc-9fb8-000c760806f2}]
\Shell\AutoRun\command - N:\ReadMe.exe
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2007-12-24 16:00:00 C:\WINDOWS\Tasks\A005C40C918679D8.job"
- c:\docume~1\mallory\applic~1\movean~1\Globalcakeonline.exe
"2007-12-24 16:00:00 C:\WINDOWS\Tasks\A706BAC691813426.job"
- c:\docume~1\mallory\applic~1\movean~1\Globalcakeonline.exe
"2007-12-24 16:00:00 C:\WINDOWS\Tasks\A8FB480A9188FBD2.job"
- c:\docume~1\jaime\applic~1\movean~1\Globalcakeonline.exe
"2007-12-24 16:00:00 C:\WINDOWS\Tasks\AB2EA3B0918521D8.job"
- c:\docume~1\mallory\applic~1\movean~1\Globalcakeonline.exe
"2007-12-24 16:00:01 C:\WINDOWS\Tasks\AC16A19591855589.job"
- c:\docume~1\jaime\applic~1\movean~1\Globalcakeonline.exe
"2007-12-24 16:00:01 C:\WINDOWS\Tasks\AC909BB591CF0FE9.job"
- c:\progra~1\movean~1\Globalcakeonline.exe
"2007-12-24 16:00:01 C:\WINDOWS\Tasks\AE199EF491B21044.job"
- c:\docume~1\mallory\applic~1\movean~1\Globalcakeonline.exe
"2007-12-24 16:00:01 C:\WINDOWS\Tasks\AF4A26E69185D8E2.job"
- c:\docume~1\mallory\applic~1\movean~1\Globalcakeonline.exe
"2007-12-21 16:15:00 C:\WINDOWS\Tasks\Maintenance en 1 clic.job"
- C:\Program Files\TuneUp Utilities 2004\SystemOptimizer.exe
"2007-12-21 19:19:25 C:\WINDOWS\Tasks\Norton AntiVirus - Run Full System Scan - MALLORY.job"
- C:\PROGRA~1\NORTON~1\Navw32.exe
"2007-12-21 15:00:00 C:\WINDOWS\Tasks\{00F291AD-6A15-4D04-9ED7-A8CF24CEC055}_CASTRO_JAIME.job"
- C:\WINDOWS\system32\mobsync.exe
"2007-12-24 15:00:00 C:\WINDOWS\Tasks\{B78BA949-AC3F-45D1-A086-871885A2BDAF}_CASTRO_JAIME.job"
- C:\WINDOWS\system32\mobsync.exeA /Schedule=
"2007-12-21 08:00:00 C:\WINDOWS\Tasks\{EFAE4BDA-2AC0-46BE-BC2F-9BC78C2AADC2}_CASTRO_JAIME.job"
- C:\WINDOWS\system32\mobsync.exeA /Schedule=
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-12-24 18:08:00
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-12-24 18:11:22 - machine was rebooted
.
2007-12-12 19:04:22 --- E O F ---
A bientôt et merci encore.