voila le rapport, le programme c'est lancé tout de suite donc je sais pas si c'est grave que je n'ai pas su mettre mode sans echec
ComboFix 07-10-29.1 - john 2007-10-29 19:56:02.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.641 [GMT 1:00]
Running from: C:\Documents and Settings\john\Local Settings\Temporary Internet Files\Content.IE5\TI7L38ZX\ComboFix[1].exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\nvrssk.dll
C:\WINDOWS\system32\nvrssl.dll
C:\WINDOWS\system32\winsys.exe
.
((((((((((((((((((((((((((((( Fichiers créés 2007-09-28 to 2007-10-29 ))))))))))))))))))))))))))))))))))))
.
2007-10-29 19:54 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-29 19:10 1,534 --a------ C:\WINDOWS\system32\tmp.reg
2007-10-29 19:09 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2007-10-29 19:09 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-10-29 19:09 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-10-29 19:09 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-10-29 19:09 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2007-10-29 09:13 1,156 --a------ C:\WINDOWS\mozver.dat
2007-10-29 09:07 <REP> d-------- C:\Program Files\Common Files
2007-10-28 18:38 <REP> d-------- C:\Program Files\Trend Micro
2007-10-28 17:35 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2007-10-28 16:56 <REP> d-------- C:\Program Files\Yahoo!
2007-10-28 16:56 <REP> d-------- C:\Program Files\CCleaner
2007-10-28 16:54 <REP> d-------- C:\Documents and Settings\john\Application Data\Lavasoft
2007-10-28 16:53 <REP> d-------- C:\Program Files\Lavasoft
2007-10-28 16:37 0 --a------ C:\WINDOWS\nsreg.dat
2007-10-28 15:52 119,568 --a------ C:\WINDOWS\system32\VB6FR.DLL
2007-10-28 15:41 <REP> d-------- C:\Program Files\RegCleaner
2007-10-27 20:29 <REP> d-------- C:\Program Files\Winsos
2007-10-27 19:43 119,798 -ra------ C:\WINDOWS\system32\drivers\SPCA561.SYS
2007-10-27 19:32 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-10-18 15:24 <REP> d-------- C:\Game
2007-10-16 16:57 <REP> d-------- C:\Program Files\TrackMania Nations ESWC
2007-10-13 14:03 <REP> d-------- C:\WINDOWS\system32\Samsung_USB_Drivers
2007-10-13 14:02 2,729,472 --a------ C:\WINDOWS\system32\fun_avcodec.dll
2007-10-13 14:02 684,032 --a------ C:\WINDOWS\system32\fun_mp4_enc.dll
2007-10-13 14:02 77,824 --a------ C:\WINDOWS\system32\fun_mp4_dec.dll
2007-10-09 16:58 <REP> d-------- C:\Documents and Settings\john\Application Data\DivX
2007-10-08 08:36 120,056 --------- C:\WINDOWS\system32\pxcpyi64.exe
2007-10-08 08:36 118,520 --------- C:\WINDOWS\system32\pxinsi64.exe
2007-10-08 08:36 9,464 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2007-10-08 08:36 9,336 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2007-10-08 08:35 <REP> d-------- C:\Program Files\DivX
2007-10-08 08:35 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2007-10-02 21:45 <REP> d-------- C:\Documents and Settings\All Users\Application Data\NFS Underground
2007-10-02 21:44 <REP> d-------- C:\Program Files\Fichiers communs\DirectX
2007-10-02 20:53 <REP> d-------- C:\Program Files\Pando Networks
2007-10-01 18:42 <REP> d-------- C:\WINDOWS\Sun
2007-09-29 12:17 <REP> d-------- C:\Program Files\The Creative Assembly
2007-09-29 09:31 <REP> d-------- C:\Program Files\MSN Reaper
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-10 18:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-10-02 19:19 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-10-02 19:19 --------- d-----w C:\Program Files\Microsoft Games
2007-09-29 11:27 163,644 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-09-17 19:01 --------- d-----w C:\Documents and Settings\john\Application Data\AVSMedia
2007-09-17 19:00 --------- d-----w C:\Program Files\AVSMedia
2007-09-17 18:57 --------- d-----w C:\Program Files\Fichiers communs\AVSMedia
2007-09-17 18:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\AVS4YOU
2007-09-17 14:51 --------- d-----w C:\Program Files\Samsung
2007-09-15 13:04 --------- d-----w C:\Program Files\Shareaza
2007-09-15 13:04 --------- d-----w C:\Documents and Settings\john\Application Data\Shareaza
2007-09-15 12:51 --------- d-----w C:\Program Files\AlienGUIse
2007-09-15 11:37 --------- d-----w C:\Program Files\Fichiers communs\Stardock
2007-09-15 11:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\NVIDIA
2007-09-14 15:15 --------- d-----w C:\Program Files\Valve
2007-09-13 17:29 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2007-09-13 15:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2007-09-13 14:38 --------- d-----w C:\Program Files\Windows Live
2007-09-13 14:38 --------- d-----w C:\Program Files\MSN Messenger
2007-09-13 14:38 --------- d-----w C:\Program Files\Messenger Plus! Live
2007-09-13 14:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\DVD Shrink
2007-09-12 16:50 --------- d-----w C:\Program Files\MSXML 4.0
2007-09-12 16:17 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-09-12 16:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee.com
2007-09-12 15:35 --------- d-----w C:\Program Files\Siemens
2007-09-12 15:25 --------- d-----w C:\Program Files\HP
2007-09-12 15:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
2007-09-12 15:23 --------- d-----w C:\Program Files\Fichiers communs\Sonic Shared
2007-09-12 15:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sonic
2007-09-12 15:22 --------- d-----w C:\Program Files\Fichiers communs\HP
2007-09-12 15:18 --------- d-----w C:\Program Files\Hewlett-Packard
2007-09-12 15:13 --------- d-----w C:\Program Files\Fichiers communs\Hewlett-Packard
2007-09-12 15:07 --------- d-----w C:\Documents and Settings\john\Application Data\HP
2007-09-12 13:38 --------- d-----w C:\Program Files\DVD Shrink
2007-09-12 13:11 --------- d-----w C:\Documents and Settings\john\Application Data\Publish Providers
2007-09-12 12:27 --------- d-----w C:\Documents and Settings\john\Application Data\Sony
2007-09-12 12:26 --------- d-----w C:\Program Files\Microsoft SQL Server
2007-09-12 12:25 --------- d-----w C:\Program Files\Vstplugins
2007-09-12 12:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sony
2007-09-12 12:24 --------- d-----w C:\Program Files\Sony
2007-09-12 12:07 --------- d-----w C:\Program Files\MSBuild
2007-09-12 12:07 --------- d-----w C:\Program Files\Microsoft Works
2007-09-11 21:59 --------- d-----w C:\Program Files\Fichiers communs\SpeechEngines
2007-09-11 21:59 --------- d-----w C:\Program Files\Fichiers communs\ODBC
2007-09-11 21:40 --------- d-----w C:\Documents and Settings\john\Application Data\Sonic
2007-09-11 21:37 --------- d-----w C:\Program Files\Fichiers communs\TiVo Shared
2007-09-11 21:36 --------- d-----w C:\Program Files\Fichiers communs\SureThing Shared
2007-09-11 21:35 --------- d-----w C:\Program Files\Sonic
2007-09-11 21:24 --------- d-----w C:\Program Files\Java
2007-09-11 21:24 --------- d-----w C:\Program Files\Google
2007-09-11 21:24 --------- d-----w C:\Program Files\Fichiers communs\Java
2007-09-11 21:20 --------- d-----w C:\Documents and Settings\john\Application Data\Leadertech
2007-09-11 21:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
2007-09-11 21:13 --------- d-----w C:\Program Files\Roxio
2007-09-11 21:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2007-09-11 20:57 --------- d-----w C:\Program Files\McAfee.com
2007-09-11 20:46 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-09-11 20:20 --------- d-----w C:\Program Files\ASUS
2007-09-11 20:15 --------- d-----w C:\Program Files\WSTARTUP
2007-09-11 20:15 --------- d-----w C:\Program Files\UTILS
2007-09-11 20:15 --------- d-----w C:\Program Files\JEUX
2007-09-11 20:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\gtopala
2007-09-11 20:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\aignes
2007-09-11 20:09 --------- d-----w C:\Program Files\microsoft frontpage
2007-09-11 20:07 --------- d-----w C:\Program Files\Services en ligne
2007-09-11 20:06 --------- d-----w C:\Program Files\Fichiers communs\MSSoap
2006-12-14 19:26 16,239,227 ----a-r C:\Program Files\metamorphose.ccp
2005-05-11 21:36 12,288 ----a-w C:\WINDOWS\Fonts\RandFont.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SW20"="C:\WINDOWS\system32\sw20.exe" [2006-05-18 02:15]
"SW24"="C:\WINDOWS\system32\sw24.exe" [2006-05-17 03:37]
"SystemTray"="SysTray.Exe" [2002-09-06 21:59 C:\WINDOWS\system32\systray.exe]
"VSOCheckTask"="C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" [2005-07-08 17:18]
"VirusScan Online"="C:\Program Files\McAfee.com\VSO\mcvsshld.exe" [2005-08-10 11:49]
"OASClnt"="C:\Program Files\McAfee.com\VSO\oasclnt.exe" [2005-08-11 21:02]
"MCAgentExe"="c:\PROGRA~1\mcafee.com\agent\mcagent.exe" [2005-09-22 17:29]
"MCUpdateExe"="C:\PROGRA~1\mcafee.com\agent\mcupdate.exe" [2006-01-11 11:05]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-01 10:22]
"NvMediaCenter"="NvMCTray.dll" [2006-06-01 10:22 C:\WINDOWS\system32\nvmctray.dll]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 18:09]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-16 18:05]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:55]
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\
Sonic CinePlayer Quick Launch.lnk - C:\Program Files\Fichiers communs\Sonic Shared\CineTray.exe [2005-10-15 01:01:00]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
C:\Program Files\AlienGUIse\fastload.dll 2001-12-20 22:34 24576 C:\Program Files\AlienGUIse\fastload.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wbsys.dll
R3 gameport;FM801 PCI Joystick;C:\WINDOWS\system32\DRIVERS\fmjoy.sys
R3 wanusb;Siemens USB ADSL WAN Modem;C:\WINDOWS\system32\DRIVERS\gwausb.sys
R3 wdm_fm801;FM801 PCI Audio (WDM);C:\WINDOWS\system32\drivers\fm801.sys
S3 ASNDIS5;ASNDIS5 Protocol Driver;\??\C:\WINDOWS\system32\ASNDIS5.SYS
S3 SetupNTGLM7X;SetupNTGLM7X;\??\H:\NTGLM7X.sys
S3 W8100PCI;ASUS 802.11b/g Driver for Windows XP;C:\WINDOWS\system32\DRIVERS\mrv8k51.sys
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2007-10-29 15:00:04 C:\WINDOWS\Tasks\HPpromotions journeysoftware.job"
.
**************************************************************************
catchme 0.3.1239 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-10-29 20:04:30
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-10-29 20:05:30 - machine was rebooted
.
--- E O F ---