du coup je ne peu plus me passer de vous, mais voici un autre rapport combo d'un autre ordi, moi, ça ne me parle pas du tout !!! je ne sais pas quoi en tirer...
ComboFix 08-08-14.03 - savitri de koumac 2008-08-15 20:28:33.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.671 [GMT 2:00]
Endroit: C:\Documents and Settings\savitri de koumac\Bureau\partage_portable\____\ComboFix.exe
Command switches used :: C:\Documents and Settings\savitri de koumac\Bureau\partage_portable\____\CFScript.txt
* Création d'un nouveau point de restauration
[color=red]
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/color]
FILE ::
C:\WINDOWS\system32\Down(4).exe
D:\Down(4).exe
E:\Down(4).exe
F:\Down(4).exe
G:\Down(4).exe
H:\Down(4).exe
J:\Down(4).exe
M:\Down(4).exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\savitri de koumac\Favoris\Online Security Test.url
C:\Program Files\VirusHeat 4.4
C:\Program Files\VirusHeat 4.4\blacklist.txt
C:\Program Files\VirusHeat 4.4\vht.dat
C:\Program Files\VirusHeat 4.4\VirusHeat 4.4.url
E:\autorun.inf
.
((((((((((((((((((((((((((((( Fichiers créés 2008-07-15 to 2008-08-15 ))))))))))))))))))))))))))))))))))))
.
2008-07-25 17:54 . 2008-07-25 17:54 <REP> d-------- C:\WINDOWS\system32\fr-fr
2008-07-25 17:47 . 2008-07-25 17:54 1,374 --a------ C:\WINDOWS\imsins.BAK
2008-07-25 17:44 . 2008-07-25 17:52 <REP> d--h----- C:\WINDOWS\$hf_mig$
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-15 17:57 --------- d-----w C:\Documents and Settings\savitri de koumac\Application Data\Skype
2008-08-15 14:03 --------- d-----w C:\Documents and Settings\savitri de koumac\Application Data\skypePM
2008-08-14 09:08 --------- d-----w C:\Program Files\eMule
2008-08-12 22:32 --------- d-----w C:\Program Files\3Dsmax7
2008-07-28 00:23 --------- d-----w C:\Documents and Settings\savitri de koumac\Application Data\Azureus
2008-07-25 16:05 97,928 ----a-w C:\WINDOWS\system32\drivers\avgldx86.sys
2008-07-14 20:32 --------- d-----w C:\Program Files\Ontrack
2008-07-10 23:31 --------- d-----w C:\Program Files\QuickTime
2008-07-10 23:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-07-10 23:29 --------- d-----w C:\Program Files\Apple Software Update
2008-07-10 23:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2008-07-08 09:57 10,520 ----a-w C:\WINDOWS\system32\avgrsstx.dll
2008-07-03 23:10 --------- d-----w C:\Program Files\Azureus
2008-06-28 11:11 --------- d-----w C:\Documents and Settings\savitri de koumac\Application Data\Canon
2008-06-21 07:06 76,040 ----a-w C:\WINDOWS\system32\drivers\avgtdix.sys
2008-06-21 07:06 12,936 ----a-w C:\WINDOWS\system32\drivers\avgrkx86.sys
2008-06-17 11:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\albumphoto
2008-06-17 10:33 --------- d-----w C:\Program Files\monAlbumPhoto
2008-06-15 10:03 --------- d-----w C:\Program Files\cam
2008-05-19 11:35 3,822 ----a-w C:\Program Files\satsukidecodersettings.ini
2008-03-04 21:17 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
2007-08-19 19:01 428 ----a-w C:\Documents and Settings\savitri de koumac\scriptsOrganizer.dat
2006-12-21 11:14 13,679 ----a-w C:\Program Files\uninstal.log
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"fsc-reminder.exe"="C:\WINDOWS\reminder\fsc-reminder.exe" [2005-01-19 18:10 28672]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [2005-01-18 17:07 196608]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-04-23 17:45 22058792]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-11-24 09:26 7122944]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-03-18 15:35 98393]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-03-18 15:34 688217]
"InstantOn"="C:\Program Files\CyberLink\PowerCinema Linux\ion_install.exe" [2005-05-11 18:28 93640]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"Sunkist2k"="C:\Program Files\Trust_CR-1200_16-in-1_USB2_CARD_READER\shwicon2k.exe" [2005-06-29 20:10 143360]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2005-04-15 17:13 45056]
"DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-03-12 22:43 81920]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2004-10-08 11:52 221184]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-01-18 17:47 458752]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-01-18 17:37 217088]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-03-05 23:48 185896]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-07-25 18:05 1235736]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"Raccourci vers la page des propriétés de High Definition Audio"="HDAShCut.exe" [2005-01-07 18:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
"SoundMan"="SOUNDMAN.EXE" [2005-03-10 09:46 90112 C:\WINDOWS\SOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2005-03-10 09:49 2803712 C:\WINDOWS\ALCWZRD.EXE]
"nwiz"="nwiz.exe" [2005-11-24 09:26 1519616 C:\WINDOWS\system32\nwiz.exe]
"SMSERIAL"="sm56hlpr.exe" [2005-08-01 08:59 544768 C:\WINDOWS\sm56hlpr.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]
C:\Documents and Settings\savitri de koumac\Menu D‚marrer\Programmes\D‚marrage\
Registration-Studio 8.lnk - C:\Program Files\Pinnacle\Studio 8\Register\RegTool.exe [2008-06-01 04:43:04 245760]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 05:44:06 29696]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2000-01-21 10:15:56 65588]
QuickScan (OpticFilm 7200i).lnk - C:\Program Files\Plustek\OpticFilm 7200i\QuickScan.exe [2008-04-12 13:26:47 290816]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.i263"= C:\WINDOWS\system32\i263_32.drv
"vidc.yv12"= yv12vfw.dll
"msacm.dvacm"= C:\PROGRA~1\FICHIE~1\ULEADS~1\Vio\Dvacm.acm
"VIDC.ACDV"= ACDV.dll
"VIDC.VP40"= vp4vfw.dll
"VIDC.HFYU"= huffyuv.dll
"VIDC.PIM1"= pclepim1.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\3Dsmax7\\3dsmax.exe"=
"C:\\Program Files\\backburner 2\\monitor.exe"=
"C:\\Program Files\\backburner 2\\manager.exe"=
"C:\\Program Files\\backburner 2\\server.exe"=
"C:\\Program Files\\Autodesk\\3ds Max 9\\3dsmax.exe"=
"C:\\Program Files\\Autodesk\\Backburner\\monitor.exe"=
"C:\\Program Files\\Autodesk\\Backburner\\manager.exe"=
"C:\\Program Files\\Autodesk\\Backburner\\server.exe"=
"C:\\Program Files\\Autodesk\\3dsMax8\\3dsmax.exe"=
"C:\\Program Files\\Next Limit\\RealFlow4\\realflow.exe"=
"C:\\Program Files\\Crazybump Beta Test\\CrazyBump.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-06-21 09:06]
R0 d346bus;d346bus;C:\WINDOWS\system32\DRIVERS\d346bus.sys [2004-03-12 22:41]
R0 d346prt;d346prt;C:\WINDOWS\system32\Drivers\d346prt.sys [2004-03-12 22:41]
R0 IABFilt;Iomega Snapshot Volume Filter;C:\WINDOWS\system32\DRIVERS\IABFilt.sys [2005-07-01 10:15]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-07-25 18:05]
R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-07-25 18:05]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-07-25 18:05]
R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-06-21 09:06]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 00:08]
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys [2006-05-09 17:50]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
2008-08-15 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-MSMSGS - C:\Program Files\Messenger\Msmsgs.exe
HKCU-Run-MsnMsgr - C:\Program Files\MSN Messenger\MsnMsgr.Exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-15 20:34:29
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-08-15 20:37:10
ComboFix-quarantined-files.txt 2008-08-15 18:36:27
Pre-Run: 16,644,669,440 octets libres
Post-Run: 16,695,537,664 octets libres
164