voila le rapport,
en attendant je vais installer la console de récupération manuellement
at
ComboFix 09-03-01.01 - po 2009-03-02 15:31:24.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.511.292 [GMT 1:00]
Lancé depuis: c:\documents and settings\po\Bureau\ComboFix.exe
AV: avast! antivirus 4.8.1335 [VPS 090301-0] *On-access scanning disabled* (Updated)
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\autorun.inf
c:\windows\IE4 Error Log.txt
D:\Autorun.inf
E:\Autorun.inf
E:\i6g6x.cmd
I:\Autorun.inf
I:\i6g6x.cmd
J:\Autorun.inf
J:\i6g6x.cmd
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-02 au 2009-03-02 ))))))))))))))))))))))))))))))))))))
.
2009-03-01 23:17 . 2009-03-01 23:17 <REP> d-------- c:\program files\Crawler
2009-02-15 01:24 . 2009-02-18 19:46 <REP> d-------- c:\windows\system32\CatRoot_bak
2009-02-12 19:28 . 2009-02-12 19:28 8,192 --ahs---- c:\windows\Thumbs.db
2009-02-12 19:28 . 2009-02-12 19:28 5,120 --ahs---- C:\Thumbs.db
2009-02-11 12:05 . 2009-02-11 12:05 <REP> d-------- c:\program files\KaraFun
2009-02-11 12:05 . 2009-02-11 12:05 <REP> d-------- c:\documents and settings\All Users\Application Data\Recisio
2009-02-11 03:39 . 2009-02-11 03:39 <REP> d-------- c:\program files\MSXML 4.0
2009-02-11 03:09 . 2008-10-16 11:38 1,024,000 -----c--- c:\windows\system32\dllcache\browseui.dll
2009-02-11 03:09 . 2008-10-16 11:38 663,552 -----c--- c:\windows\system32\dllcache\wininet.dll
2009-02-11 03:09 . 2008-10-16 11:38 474,624 -----c--- c:\windows\system32\dllcache\shlwapi.dll
2009-02-11 03:09 . 2008-10-16 11:38 449,024 -----c--- c:\windows\system32\dllcache\mshtmled.dll
2009-02-11 03:09 . 2008-10-16 11:38 357,888 -----c--- c:\windows\system32\dllcache\dxtmsft.dll
2009-02-11 03:09 . 2008-06-14 18:59 272,768 -----c--- c:\windows\system32\dllcache\bthport.sys
2009-02-11 03:09 . 2008-10-16 11:38 205,312 -----c--- c:\windows\system32\dllcache\dxtrans.dll
2009-02-11 03:09 . 2008-10-16 11:38 152,064 -----c--- c:\windows\system32\dllcache\cdfview.dll
2009-02-11 03:09 . 2008-10-16 11:38 146,432 -----c--- c:\windows\system32\dllcache\msrating.dll
2009-02-11 03:08 . 2008-08-14 14:44 2,138,112 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-02-11 03:08 . 2008-09-15 16:39 1,846,144 -----c--- c:\windows\system32\dllcache\win32k.sys
2009-02-11 03:08 . 2008-10-16 11:38 1,495,040 -----c--- c:\windows\system32\dllcache\shdocvw.dll
2009-02-11 03:08 . 2008-10-16 11:38 1,056,768 -----c--- c:\windows\system32\dllcache\danim.dll
2009-02-11 03:08 . 2008-10-16 11:38 617,984 -----c--- c:\windows\system32\dllcache\urlmon.dll
2009-02-11 03:08 . 2008-10-16 11:38 532,480 -----c--- c:\windows\system32\dllcache\mstime.dll
2009-02-11 03:08 . 2008-10-16 11:38 251,392 -----c--- c:\windows\system32\dllcache\iepeers.dll
2009-02-11 03:08 . 2008-10-16 11:38 96,768 -----c--- c:\windows\system32\dllcache\inseng.dll
2009-02-11 03:08 . 2008-10-16 11:38 55,808 -----c--- c:\windows\system32\dllcache\extmgr.dll
2009-02-11 03:08 . 2008-10-16 11:38 39,424 -----c--- c:\windows\system32\dllcache\pngfilt.dll
2009-02-11 03:08 . 2008-10-15 10:45 18,432 -----c--- c:\windows\system32\dllcache\iedw.exe
2009-02-11 03:08 . 2008-10-16 11:38 16,384 -----c--- c:\windows\system32\dllcache\jsproxy.dll
2009-02-11 03:07 . 2008-12-12 18:35 3,081,216 -----c--- c:\windows\system32\dllcache\mshtml.dll
2009-02-11 03:07 . 2008-08-14 14:44 2,182,400 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
2009-02-11 03:07 . 2008-08-14 14:44 2,059,776 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-02-11 03:07 . 2008-08-14 14:44 2,017,792 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
2009-02-11 03:06 . 2008-04-11 19:51 683,520 -----c--- c:\windows\system32\dllcache\inetcomm.dll
2009-02-11 03:06 . 2008-10-24 12:10 453,632 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2009-02-11 03:06 . 2008-12-11 12:57 333,184 -----c--- c:\windows\system32\dllcache\srv.sys
2009-02-11 03:06 . 2008-05-01 15:31 331,776 -----c--- c:\windows\system32\dllcache\msadce.dll
2009-02-11 03:05 . 2008-09-04 17:45 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2009-02-11 03:05 . 2008-10-15 17:59 332,800 -----c--- c:\windows\system32\dllcache\netapi32.dll
2009-02-11 03:05 . 2008-10-03 11:17 247,326 -----c--- c:\windows\system32\dllcache\strmdll.dll
2009-02-11 03:02 . 2009-02-26 02:00 <REP> d--h----- c:\windows\$hf_mig$
2009-02-11 01:45 . 2001-08-23 17:47 8,704 --a------ c:\windows\system32\kbdjpn.dll
2009-02-11 01:45 . 2001-08-23 17:47 8,192 --a------ c:\windows\system32\kbdkor.dll
2009-02-11 01:45 . 2001-08-17 22:55 6,144 --a------ c:\windows\system32\kbd106.dll
2009-02-11 01:45 . 2001-08-17 22:55 6,144 --a------ c:\windows\system32\kbd101c.dll
2009-02-11 01:45 . 2001-08-17 22:55 6,144 --a------ c:\windows\system32\kbd101b.dll
2009-02-11 01:45 . 2001-08-17 22:55 5,632 --a------ c:\windows\system32\kbd103.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-28 14:25 --------- d-----w c:\documents and settings\po\Application Data\dvdcss
2009-02-13 21:06 --------- d-----w c:\program files\Macromedia
2009-02-13 14:34 --------- d-----w c:\program files\OpenOffice.org 2.0
2009-02-13 12:01 --------- d-----w c:\documents and settings\po\Application Data\OpenOffice.org2
2009-01-19 23:51 --------- d-----w c:\program files\Fichiers communs\Adobe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-19 1667584]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"="c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2006-01-12 155648]
"NVRaidService"="c:\windows\system32\nvraidservice.exe" [2004-06-11 83968]
"NVMixerTray"="c:\program files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-06-03 131072]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2004-12-14 483328]
"WinampAgent"="c:\program files\Winamp\winampa.exe" [2003-12-13 33792]
"QuickTime Task"="c:\program files\quicktime\qttask.exe" [2007-01-20 98304]
"Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 159744]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2005-07-15 25214]
Adobe Gamma Loader.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-07-15 110592]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"14495:TCP"= 14495:TCP:NortonAV
"12981:TCP"= 12981:TCP:NortonAV
"17205:TCP"= 17205:TCP:NortonAV
"12520:TCP"= 12520:TCP:NortonAV
"16545:TCP"= 16545:TCP:NortonAV
"13397:TCP"= 13397:TCP:NortonAV
"17475:TCP"= 17475:TCP:NortonAV
"16217:TCP"= 16217:TCP:NortonAV
"15435:TCP"= 15435:TCP:NortonAV
"15418:TCP"= 15418:TCP:NortonAV
"16245:TCP"= 16245:TCP:NortonAV
"18167:TCP"= 18167:TCP:NortonAV
"14468:TCP"= 14468:TCP:NortonAV
"18206:TCP"= 18206:TCP:NortonAV
"16978:TCP"= 16978:TCP:NortonAV
"12502:TCP"= 12502:TCP:NortonAV
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2009-02-10 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-02-10 20560]
S3 w200bus;Sony Ericsson W200 driver (WDM);c:\windows\system32\drivers\w200bus.sys [2008-03-02 61504]
S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;c:\windows\system32\drivers\w200mdfl.sys [2008-03-02 9328]
S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;c:\windows\system32\drivers\w200mdm.sys [2008-03-02 97056]
S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\w200mgmt.sys [2008-03-02 88560]
S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface;c:\windows\system32\drivers\w200obex.sys [2008-03-02 86368]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{acec32dd-f4c8-11d9-8ded-806d6172696f}]
\Shell\AutoRun\command - K:\ASUSACPI.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e5aa89c4-8bda-11dc-85e6-0013d4cad5f0}]
\Shell\AutoRun\command - explorer.exe
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-cdoosoft - c:\windows\system32\olhrwef.exe
HKLM-Run-Cmaudio - cmicnfg.cpl
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.fr/
uInternet Settings,ProxyOverride = *.local
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Crawler Search - tbr:iemenu
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-02 15:33:14
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-602162358-796845957-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
Heure de fin: 2009-03-02 15:35:17
ComboFix-quarantined-files.txt 2009-03-02 14:34:59
Avant-CF: 2,943,078,400 octets libres
Après-CF: 4,687,433,728 octets libres
169 --- E O F --- 2009-02-26 01:30:15
est ce que tu as un lien pour le telechargement?
merci :-)