Bonjour
et désolé pour le retard
ci-dessous le rapport de combofix
merci encore
---
ComboFix 09-01-21.04 - fol 2009-01-27 10:32:40.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.2815.2441 [GMT 1:00]
Lancé depuis: c:\documents and settings\fol\Bureau\ComboFix.exe
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-27 au 2009-01-27 ))))))))))))))))))))))))))))))))))))
.
2009-01-22 17:10 . 2009-01-22 17:10 <REP> d-------- c:\documents and settings\fol\Application Data\Malwarebytes
2009-01-22 17:10 . 2009-01-22 17:10 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-01-22 15:39 . 2009-01-22 15:41 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2009-01-22 14:41 . 2009-01-27 10:12 <REP> d-a------ c:\documents and settings\All Users\Application Data\TEMP
2009-01-22 13:34 . 2009-01-22 13:34 <REP> d-------- C:\rsit
2009-01-22 13:34 . 2009-01-22 16:25 <REP> d-------- c:\program files\trend micro
2009-01-22 11:28 . 2009-01-27 10:01 <REP> d-------- c:\program files\Spybot - Search & Destroy
2009-01-22 11:28 . 2009-01-27 10:01 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-22 10:28 . 2009-01-22 12:20 95,744 -r-hs---- c:\windows\system32\nmdfgds1.dll
2009-01-20 16:31 . 2009-01-20 16:31 <REP> d-------- c:\windows\Sun
2009-01-05 09:10 . 2009-01-05 09:10 17,672 --a------ c:\windows\system32\GDIPFONTCACHEV1.DAT
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-21 13:45 --------- d-----w c:\program files\Google
2008-12-23 08:24 --------- d-----w c:\documents and settings\fol\Application Data\OpenOffice.org
2008-12-23 08:23 --------- d-----w c:\program files\OpenOffice.org 3
2008-12-23 08:23 --------- d-----w c:\program files\OpenOffice.org 2.4
2008-12-23 08:23 --------- d-----w c:\program files\JRE
2008-12-23 08:20 --------- d-----w c:\documents and settings\fol\Application Data\OpenOffice.org2
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
.
((((((((((((((((((((((((((((( snapshot@2009-01-27_ 9.56.19,35 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-01-27 09:13:20 262,144 ----a-w c:\windows\system32\config\systemprofile\NtUser.dat
- 2009-01-27 08:45:31 71,444 ----a-w c:\windows\system32\perfc009.dat
+ 2009-01-27 09:19:34 71,444 ----a-w c:\windows\system32\perfc009.dat
- 2009-01-27 08:45:31 85,058 ----a-w c:\windows\system32\perfc00C.dat
+ 2009-01-27 09:19:34 85,058 ----a-w c:\windows\system32\perfc00C.dat
- 2009-01-27 08:45:31 441,760 ----a-w c:\windows\system32\perfh009.dat
+ 2009-01-27 09:19:34 441,760 ----a-w c:\windows\system32\perfh009.dat
- 2009-01-27 08:45:31 511,154 ----a-w c:\windows\system32\perfh00C.dat
+ 2009-01-27 09:19:34 511,154 ----a-w c:\windows\system32\perfh00C.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-10-31 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVRaidService"="c:\windows\System32\nvraidservice.exe" [2007-10-31 188448]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2007-10-04 8491008]
"NvMediaCenter"="c:\windows\System32\NvMcTray.dll" [2007-10-04 81920]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"nwiz"="nwiz.exe" [2007-10-04 c:\windows\system32\nwiz.exe]
"RTHDCPL"="RTHDCPL.EXE" [2008-07-31 c:\windows\RTHDCPL.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\fol\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-09-12 384000]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
FTP Utility.lnk - c:\program files\KONICA MINOLTA\FTP Utility\KMFtp.exe [2004-10-27 102400]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\KONICA MINOLTA\\FTP Utility\\KMFtp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R4 NwSapAgent;Agent SAP;c:\windows\System32\svchost.exe -k netsvcs [2003-04-24 14336]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{aade971a-e63b-11dd-b1e4-002185096f1f}]
\Shell\AutoRun\command - D:\gy.exe
\Shell\open\Command - D:\gy.exe
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-27 10:33:26
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2009-01-27 10:34:18
ComboFix-quarantined-files.txt 2009-01-27 09:34:17
ComboFix2.txt 2009-01-27 08:56:57
Avant-CF: 145 894 916 096 octets libres
Après-CF: 145,893,269,504 octets libres
95 --- E O F --- 2009-01-19 08:09:21