bonsoir
l'insolvable je crois que je dois formater, terrible...
je colle le comboFix :
ComboFix 07-09-08 - "alexandre" 2007-09-08 18:54:57.1 - NTFSx86 MINIMAL
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.604 [GMT 2:00]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\DOCUME~1\ALEXAN~1\err.log
C:\WINDOWS\pack.epk
C:\WINDOWS\system32\vsxohl.dat
C:\WINDOWS\system32\vsxohl_nav.dat
C:\WINDOWS\system32\vsxohl_navps.dat
((((((((((((((((((((((((((((( Fichiers créés 2007-08-08 to 2007-09-08 ))))))))))))))))))))))))))))))))))))
.
2007-09-08 18:53 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-09-07 21:20 <REP> d-------- C:\WINDOWS\SxsCaPendDel
2007-08-31 20:02 <REP> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Lavasoft
2007-08-31 02:09 105,856 --a------ C:\WINDOWS\system32\drivers\msfwhlpr.sys
2007-08-31 02:07 67,784 --a------ C:\WINDOWS\system32\drivers\MpFilter.sys
2007-08-31 01:49 <REP> d-------- C:\Program Files\Microsoft Windows OneCare Live
2007-08-31 01:23 <REP> d-------- C:\Program Files\Windows Live Safety Center
2007-08-31 00:02 <REP> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\AntiVir PersonalEdition Classic
2007-08-28 23:04 <REP> d-------- C:\WINDOWS\BDOSCAN8
2007-08-27 18:37 <REP> d-------- C:\WINDOWS\report
2007-08-27 18:35 86,094 --a------ C:\WINDOWS\BPMNT.dll
2007-08-27 18:35 71,749 --a------ C:\WINDOWS\hcextoutput.dll
2007-08-27 18:35 267,845 --a------ C:\WINDOWS\tsc.exe
2007-08-27 18:35 1,163,344 --a------ C:\WINDOWS\vsapi32.dll
2007-08-27 18:35 <REP> d-------- C:\WINDOWS\AU_Backup
2007-08-27 18:31 <REP> d-------- C:\WINDOWS\AU_Temp
2007-08-27 18:31 <REP> d-------- C:\WINDOWS\AU_Log
2007-08-27 18:20 3,968 --a------ C:\WINDOWS\system32\drivers\AvgArCln.sys
2007-08-27 00:58 69,689 --a------ C:\WINDOWS\UNZIP.DLL
2007-08-27 00:58 507,904 --a------ C:\WINDOWS\TMUPDATE.DLL
2007-08-27 00:58 286,720 --a------ C:\WINDOWS\PATCH.EXE
2007-08-27 00:17 <REP> d-------- C:\kav
2007-08-24 21:20 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-08-24 20:16 <REP> d-------- C:\WINDOWS\system32\1036
2007-08-24 20:16 <REP> d-------- C:\WINDOWS\system32\1033
2007-08-24 13:41 <REP> d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Spyware Terminator
2007-08-24 13:21 <REP> d-------- C:\WINDOWS\pss
2007-08-23 18:35 51,072 --a------ C:\WINDOWS\system32\drivers\ikhlayer.sys
2007-08-23 18:35 30,592 --a------ C:\WINDOWS\system32\drivers\ikhfile.sys
2007-08-23 18:34 <REP> d-------- C:\Program Files\Spyware Doctor
2007-08-21 11:53 138,624 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2007-08-21 11:48 <REP> d-------- C:\Program Files\Crawler
2007-08-21 11:48 <REP> d-------- C:\DOCUME~1\ALEXAN~1\APPLIC~1\Spyware Terminator
2007-08-21 11:44 <REP> d-------- C:\Program Files\Spyware Terminator
2007-08-16 23:56 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2007-08-10 20:54 <REP> d-------- C:\Program Files\Fichiers communs\Apple
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-09-08 18:18 39455 --a------ C:\WINDOWS\system32\drivers\fwdrv.err
2007-09-07 21:27 --------- d-------- C:\Program Files\iTunes
2007-09-07 21:26 --------- d-------- C:\Program Files\iPod
2007-09-07 16:32 --------- d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Spybot - Search & Destroy
2007-09-06 12:09 801144 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-09-06 12:05 94416 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-09-06 12:05 92848 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-09-06 12:03 23152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-09-06 12:02 42912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-09-06 12:00 95608 --a------ C:\WINDOWS\system32\AVASTSS.scr
2007-09-06 12:00 26624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-08-31 20:02 --------- d-------- C:\Program Files\Lavasoft
2007-08-31 20:01 --------- d-------- C:\DOCUME~1\ALEXAN~1\APPLIC~1\Lavasoft
2007-08-31 19:55 --------- d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2007-08-24 13:40 --------- d-------- C:\DOCUME~1\ALEXAN~1\APPLIC~1\foobar2000
2007-08-24 13:37 --------- d-------- C:\Program Files\Fritivi
2007-08-23 19:41 --------- d-------- C:\Program Files\Hitman Pro
2007-08-23 18:52 --------- d-a------ C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\TEMP
2007-08-02 17:44 --------- d-------- C:\Program Files\Mozilla Thunderbird
2007-08-01 14:06 --------- d-------- C:\Program Files\Freeplayer
2007-08-01 13:06 --------- d-------- C:\DOCUME~1\ALEXAN~1\APPLIC~1\.clamwin
2007-07-30 19:19 92504 --a------ C:\WINDOWS\system32\cdm.dll
2007-07-30 19:19 549720 --a------ C:\WINDOWS\system32\wuapi.dll
2007-07-30 19:19 53080 --a------ C:\WINDOWS\system32\wuauclt.exe
2007-07-30 19:19 43352 --a------ C:\WINDOWS\system32\wups2.dll
2007-07-30 19:19 325976 --a------ C:\WINDOWS\system32\wucltui.dll
2007-07-30 19:19 271224 --a------ C:\WINDOWS\system32\mucltui.dll
2007-07-30 19:19 207736 --a------ C:\WINDOWS\system32\muweb.dll
2007-07-30 19:19 203096 --a------ C:\WINDOWS\system32\wuweb.dll
2007-07-30 19:19 1712984 --a------ C:\WINDOWS\system32\wuaueng.dll
2007-07-30 19:18 33624 --a------ C:\WINDOWS\system32\wups.dll
2007-07-21 19:28 --------- d-------- C:\Program Files\eMule
2007-07-19 04:50 15544 --a------ C:\WINDOWS\system32\drivers\sbhr.sys
2007-07-18 14:20 --------- d-------- C:\DOCUME~1\ALEXAN~1\APPLIC~1\Sunbelt Software
2007-07-18 13:06 --------- d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Sunbelt Software
2007-07-18 13:05 --------- d-------- C:\Program Files\Sunbelt Software
2007-07-15 00:55 --------- d-------- C:\Program Files\Almanach
2007-07-15 00:53 74752 --a------ C:\WINDOWS\ST6UNST.EXE
2007-07-15 00:53 253952 --------- C:\WINDOWS\Setup1.exe
2007-07-13 22:07 --------- d-------- C:\Program Files\prog muse
2007-07-13 22:02 --------- d-------- C:\Program Files\Apple Software Update
2007-07-13 22:02 --------- d-------- C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\Apple
2007-06-26 08:09 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
2007-06-19 15:32 282112 --a------ C:\WINDOWS\system32\gdi32.dll
2007-06-15 14:37 27376 --a------ C:\WINDOWS\system32\SBBD.exe
2007-06-13 15:22 1037312 --a------ C:\WINDOWS\explorer.exe
2004-08-11 21:49 192512 --a------ C:\WINDOWS\inf\unregmp2(2).exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SBDrvDet"="C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe" [2002-12-03 19:06]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 12:06]
"WinampAgent"="C:\Program Files\winamp\winampa.exe" [2007-05-15 00:22]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-07-07 01:37]
"SBCSTray"="C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe" [2007-06-15 15:17]
"ClamWin"="D:\program files\av\ClamWin\bin\ClamTray.exe" [2007-08-21 23:05]
"SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2007-08-21 11:52]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2007-08-27 16:48]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25]
"avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2007-04-02 10:35]
"OneCareUI"="C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe" [2007-08-02 10:47]
"QuickTime Task"="C:\Program Files\prog muse\QTTask.exe" [2007-06-29 06:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-05 18:03]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-06-01 08:21]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Spyware Doctor"=
C:\DOCUME~1\ALLUSE~1.WIN\MENUDM~1\PROGRA~1\DMARRA~1\
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 01:01:50]
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 02:48:20]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\OneCareMP]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"
R0 SBHR;SBHR;C:\WINDOWS\system32\drivers\sbhr.sys
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys
R2 OneCareMP;OneCare AntiSpyware and AntiVirus;"C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe"
S1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys
S1 MSFWHLPR;MSFWHLPR;C:\WINDOWS\system32\DRIVERS\msfwhlpr.sys
S1 sp_rsdrv2;Spyware Terminator Driver 2;\??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
S2 SPF4;Sunbelt Personal Firewall 4;"C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe"
S3 AN983;Carte Fast Ethernet 10/100 Mbps ADMtek AN983/AN985/ADM951X;C:\WINDOWS\system32\DRIVERS\AN983.sys
S3 MpFilter;Microsoft Malware Protection Driver;C:\WINDOWS\system32\DRIVERS\MpFilter.sys
S3 NPF;NetGroup Packet Filter Driver;C:\WINDOWS\system32\drivers\npf.sys
S3 PhilCam8116_XP;Logitech QuickCam Pro 3000(PID_08B1);C:\WINDOWS\system32\DRIVERS\CamDrL20.sys
S3 SBAPIFS;SBAPIFS;\??\C:\WINDOWS\system32\drivers\sbapifs.sys
S4 freenet-darknet-8888;Freenet 0.7 darknet-8888;"C:\Program Files\Freenet\bin\wrapper-windows-x86-32.exe" -s "C:\Program Files\Freenet\wrapper.conf"
*Newly Created Service* - CATCHME
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2007-09-07 18:52:14 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
.
**************************************************************************
catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-09-08 18:58:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-09-08 19:00:16
C:\ComboFix-quarantined-files.txt ... 2007-09-08 18:59
.
--- E O F ---
merci if someone could help me