Bonjour a tous.
---------------
Voilà, j'ai fais le scan avec combofix. Voici le rapport. Encore merci.
ComboFix 08-01-04.1 - patrick 2008-01-06 21:15:42.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.634 [GMT 1:00]
Running from: C:\Documents and Settings\patrick\Mes documents\ComboFix.exe
* Created a new restore point
.
((((((((((((((((((((((((((((( Fichiers créés 2007-12-06 to 2008-01-06 ))))))))))))))))))))))))))))))))))))
.
2008-01-06 21:13 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-03 17:52 . 2008-01-03 17:52 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-01-03 11:23 . 2008-01-03 11:23 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-01-02 20:05 . 2008-01-02 20:05 <REP> d-------- C:\Documents and Settings\patrick\Application Data\Grisoft
2008-01-02 20:05 . 2008-01-02 20:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-02 20:05 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-01 18:15 . 2008-01-01 18:15 <REP> d-------- C:\Program Files\Yahoo!
2008-01-01 18:09 . 2008-01-01 18:09 <REP> d-------- C:\Program Files\CCleaner
2007-12-29 11:48 . 2007-12-29 11:48 37,473 --a------ C:\WINDOWS\system32\muzika.xm
2007-12-29 11:47 . 2007-12-04 15:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-29 11:47 . 2007-12-04 15:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-29 11:47 . 2007-12-04 15:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-29 11:47 . 2007-12-04 15:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-29 11:47 . 2007-12-04 15:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-29 11:46 . 2007-12-04 14:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-12-29 11:46 . 2004-01-09 11:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2007-12-29 11:46 . 2007-12-04 13:54 95,608 --a------ C:\WINDOWS\system32\AVASTSS.scr
2007-12-19 09:13 . 2007-12-19 09:13 <REP> d-------- C:\Documents and Settings\patrick\Application Data\Luminova
2007-12-19 09:12 . 2007-12-19 09:12 <REP> d-------- C:\Ikea-colours
2007-12-15 20:44 . 2007-12-15 20:46 24 ---hs---- C:\WINDOWS\S52B5157E.tmp
2007-12-11 20:39 . 2007-12-13 19:38 87,638 --a------ C:\WINDOWS\Run32A60.mch
2007-12-11 19:28 . 2007-12-13 18:37 <REP> d-------- C:\WINDOWS\A6W_DATA
2007-12-11 19:28 . 2007-12-11 19:28 <REP> d-------- C:\PC_Play&Learn
2007-12-11 19:28 . 2007-12-13 18:08 35 --a------ C:\WINDOWS\A6W.INI
2007-12-09 22:44 . 2007-12-09 22:44 <REP> d-------- C:\Documents and Settings\patrick\Application Data\MCB
2007-12-09 22:42 . 2007-12-30 20:05 <REP> d-------- C:\Program Files\ExtraFilm PhotoAssistant
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-02 20:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-30 22:24 --------- d-----w C:\Documents and Settings\patrick\Application Data\BitTorrent
2007-12-30 20:23 --------- d-----w C:\Documents and Settings\patrick\Application Data\LimeWire
2007-12-30 20:22 --------- d-----w C:\Program Files\LimeWire
2007-12-30 14:48 --------- d-----w C:\Program Files\BitTorrent
2007-12-29 11:17 181,168 ----a-w C:\WINDOWS\system32\drivers\fwdrv.err
2007-12-27 15:50 111,576 ----a-w C:\Documents and Settings\patrick\Application Data\GDIPFONTCACHEV1.DAT
2007-12-19 22:08 --------- d-----w C:\Program Files\a-squared Free
2007-11-30 15:44 --------- d-----w C:\Program Files\Windows Live Toolbar
2007-11-28 15:37 --------- d-----w C:\Program Files\MSECache
2007-11-26 21:39 --------- d-----w C:\Program Files\Real
2007-11-26 21:39 --------- d-----w C:\Program Files\Fichiers communs\xing shared
2007-11-26 21:39 --------- d-----w C:\Program Files\Fichiers communs\Real
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-29 22:43 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-06-15 14:39 87,608 ----a-w C:\Documents and Settings\patrick\Application Data\ezpinst.exe
2007-06-15 14:39 47,360 ----a-w C:\Documents and Settings\patrick\Application Data\pcouffin.sys
2004-01-31 17:54 331,776 ----a-w C:\WINDOWS\inf\pdfinst2.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 00:09 15360]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 15:45 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [2004-01-29 15:45 2899968]
"nwiz"="nwiz.exe" [2004-01-29 15:45 782336 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [2004-01-29 15:45 46080]
"HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-11-29 19:50 196608]
"SoundMan"="SOUNDMAN.EXE" [2002-06-18 11:44 46592 C:\WINDOWS\SOUNDMAN.EXE]
"AME_CSA"="amecsa.cpl" [2002-10-30 03:26 757760 C:\WINDOWS\system32\AmeCSA.cpl]
"AnyDVD"="C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe" [2007-06-11 10:11 458752]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"NeroFilterCheck"="C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2007-03-01 14:57 153136]
"Easy PDF Creator"="C:\Program Files\Easy PDF Creator\EasyPDFCreator.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-10-10 20:05 286720]
"TomTomHOME.exe"="C:\Program Files\TomTom HOME 2\HOMERunner.exe" [2007-10-31 10:19 378784]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-11-26 22:39 185896]
"ExtraFilmHemmaAgent"="C:\Program Files\ExtraFilm PhotoAssistant\Agent.exe" [2006-10-03 09:40 323584]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-20 00:09 15360]
C:\Documents and Settings\patrick\Menu D‚marrer\Programmes\D‚marrage\
Rainlendar.lnk - C:\Program Files\Rainlendar\Rainlendar.exe [2005-07-22 16:14:46]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.lnk - C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2007-10-09 21:38:58]
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 08:01:04]
Samsung Internet Keyboard.lnk - C:\Program Files\SAMSUNG\Samsung Internet Keyboard\MMKbd.exe [2007-06-10 20:47:30]
ScanPanel.lnk - C:\Program Files\Trust\Easy Webscan\ScnPanel.exe [2007-06-10 20:50:07]
R1 VIAPFD;VIAPFD;C:\WINDOWS\system32\Drivers\VIAPFD.SYS [2001-12-18 13:45]
R3 AmeAtmPc;AmeAtmPc;C:\WINDOWS\system32\DRIVERS\AmeAtmPc.sys [2002-12-17 02:29]
R3 SampleScanner;Trust Easy Webscan 19200 Scanner;C:\WINDOWS\system32\DRIVERS\TR12388.sys [2001-06-07 16:56]
S3 AtmElan;Réseau émulant ATM;C:\WINDOWS\system32\DRIVERS\atmlane.sys [2004-08-04 06:58]
S3 AtmLane;Émulation réseau ATM;C:\WINDOWS\system32\DRIVERS\atmlane.sys [2004-08-04 06:58]
S4 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" [2007-08-23 13:59]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{312d6f7c-9ac9-11dc-8033-000c6e0475aa}]
\Shell\AutoRun\command - K:\InstallTomTomHOME.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{596e103c-311e-11dc-bf02-000c6e0475aa}]
\Shell\AutoRun\command - K:\InstallTomTomHOME.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b748504e-9540-11dc-802b-000c6e0475aa}]
\Shell\AutoRun\command - K:\InstallTomTomHOME.exe
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-01-05 19:42:31 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-06 21:19:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-06 21:21:01
.
2007-12-21 12:05:38 --- E O F ---