Re bonjour!
voici le rapport combofix:
ComboFix 07-12-31.4 - Annie 2008-01-04 22:14:04.3 - NTFSx86
Running from: C:\Documents and Settings\Annie\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Annie\Bureau\CFscript.txt
* Created a new restore point
FILE
C:\DOCUME~1\Annie\LOCALS~1\Temp\crasos.exe
C:\DOCUME~1\Annie\LOCALS~1\Temp\woso.exe
C:\WINDOWS\eSellerateEngine.dll
C:\WINDOWS\system32\diactfrmv.dll
C:\WINDOWS\system32\drivers\kabymbkc.dat
C:\WINDOWS\system32\else.dll
C:\WINDOWS\system32\fdulgolt.dat
C:\WINDOWS\system32\fyyv433b.exe
C:\WINDOWS\system32\gwxlidbq.dat
C:\WINDOWS\system32\lbxnwkxm.dat
C:\WINDOWS\system32\libeay32.dll
C:\WINDOWS\system32\libssl32.dll
C:\WINDOWS\system32\mralrqwl.dat
C:\WINDOWS\system32\twdrrquu.dat
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\diactfrmv.dll
C:\WINDOWS\system32\drivers\kabymbkc.dat
C:\WINDOWS\system32\else.dll
C:\WINDOWS\system32\fdulgolt.dat
C:\WINDOWS\system32\fyyv433b.exe
C:\WINDOWS\system32\gwxlidbq.dat
C:\WINDOWS\system32\lbxnwkxm.dat
C:\WINDOWS\system32\libeay32.dll
C:\WINDOWS\system32\libssl32.dll
C:\WINDOWS\system32\mralrqwl.dat
C:\WINDOWS\system32\twdrrquu.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_MNQIACEI
-------\mnqiacei
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-12-05 to 2008-01-05 ))))))))))))))))))))))))))))))))))))
.
2007-12-31 15:35 . 2007-12-31 15:35 <REP> d-------- C:\Program Files\Trend Micro
2007-12-31 14:56 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-12-30 15:21 . 2007-12-30 16:42 3,490 --a------ C:\WINDOWS\system32\tmp.reg
2007-12-30 15:20 . 2008-01-04 21:47 <REP> d-------- C:\Program Files\SmitfraudFix
2007-12-30 15:16 . 2007-12-30 15:16 1,129,580 --a------ C:\Program Files\SmitfraudFix.exe
2007-12-30 09:51 . 2007-12-30 09:51 <REP> d-------- C:\Program Files\EsetOnlineScanner
2007-12-29 13:54 . 2007-12-29 13:54 <REP> d-------- C:\Documents and Settings\Annie\Application Data\Grisoft
2007-12-29 13:50 . 2007-12-29 13:50 <REP> d-------- C:\Program Files\CCleaner
2007-12-29 13:47 . 2007-12-29 13:47 2,724,328 --a------ C:\Program Files\ccsetup203.exe
2007-12-29 13:41 . 2007-12-29 13:41 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-29 13:41 . 2007-05-30 07:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-29 13:40 . 2007-12-29 13:40 12,413,440 --a------ C:\Program Files\avgas-setup-7.5.1.43.exe
2007-12-28 14:33 . 2008-01-04 21:50 <REP> d-------- C:\Program Files\a-squared Anti-Malware
2007-12-28 14:26 . 2007-12-28 14:26 25,618,144 --a------ C:\Program Files\a2AntiMalwareSetup.exe
2007-12-28 14:11 . 2007-12-28 14:11 0 --a------ C:\WINDOWS\LAYOUT.INI
2007-12-24 10:09 . 2007-12-26 13:00 <REP> d-------- C:\WINDOWS\system32\AppCert
2007-12-16 11:17 . 2007-12-16 11:17 15,942,656 --a------ C:\Program Files\IE7Setup.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-29 20:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-28 19:02 5,154,304 ----a-w C:\Program Files\WindowsDefender.msi
2007-12-14 01:13 --------- d-----w C:\Documents and Settings\Annie\Application Data\FrostWire
2007-11-20 00:40 --------- d-----w C:\Program Files\FrostWire
2007-04-05 09:01 6,864,896 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_12_15_14_41_53_full.dmp.zip
2007-03-06 17:28 3,060,095 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2006-12-13 19:02 90,986 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_12_12_21_26_27_small.dmp.zip
2006-12-12 23:13 110,791 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_12_07_12_16_16_small.dmp.zip
2006-12-03 03:47 95,058 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_11_29_02_23_31_small.dmp.zip
2006-12-03 03:47 93,373 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_12_02_03_38_19_small.dmp.zip
2006-11-12 13:37 95,648 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_11_12_08_14_48_small.dmp.zip
2006-11-12 13:37 93,451 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_11_11_23_16_55_small.dmp.zip
2006-11-12 04:00 109,608 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_11_11_08_23_44_small.dmp.zip
2006-10-09 20:18 1,479,884 ----a-w C:\Program Files\picmaster.exe
2006-10-09 20:06 465,899 ----a-w C:\Program Files\imagegrab30fr.zip
2006-09-11 00:08 4,135,461 ----a-w C:\Program Files\FrostWireWin_4.10.9_Beta.exe
2005-09-29 15:51 976,020 ----a-w C:\Program Files\BDAXP.cab
2005-09-29 15:51 916,815 ----a-w C:\Program Files\Oct2005_MDX_x86.cab
2005-09-29 15:51 86,784 ----a-w C:\Program Files\Oct2005_xinput_x64.cab
2005-09-29 15:51 74,448 ----a-w C:\Program Files\DSETUP.dll
2005-09-29 15:51 74,430 ----a-w C:\Program Files\dxupdate.cab
2005-09-29 15:51 703,080 ----a-w C:\Program Files\BDA.cab
2005-09-29 15:51 488,656 ----a-w C:\Program Files\DXSETUP.exe
2005-09-29 15:51 46,085 ----a-w C:\Program Files\Oct2005_xinput_x86.cab
2005-09-29 15:51 41,888 ----a-w C:\Program Files\dxdllreg_x86.cab
2005-09-29 15:51 2,245,840 ----a-w C:\Program Files\dsetup32.dll
2005-09-29 15:51 15,493,481 ----a-w C:\Program Files\DirectX.cab
2005-09-29 15:51 13,265,040 ----a-w C:\Program Files\dxnt.cab
2005-09-29 15:51 1,351,430 ----a-w C:\Program Files\Aug2005_d3dx9_27_x64.cab
2005-09-29 15:51 1,156,363 ----a-w C:\Program Files\BDANT.cab
2005-09-29 15:51 1,078,532 ----a-w C:\Program Files\Aug2005_d3dx9_27_x86.cab
.
((((((((((((((((((((((((((((( snapshot@2007-12-31_15.20.21.65 )))))))))))))))))))))))))))))))))))))))))
.
+ 2000-08-31 13:00:00 163,328 ----a-w C:\WINDOWS\erdnt\subs\ERDNT.EXE
- 2007-11-01 20:18:17 40,128 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2007-12-31 20:23:33 40,128 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2007-11-01 20:18:17 48,820 ----a-w C:\WINDOWS\system32\perfc00C.dat
+ 2007-12-31 20:23:33 48,820 ----a-w C:\WINDOWS\system32\perfc00C.dat
- 2007-11-01 20:18:17 311,740 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2007-12-31 20:23:33 311,740 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2007-11-01 20:18:17 367,988 ----a-w C:\WINDOWS\system32\perfh00C.dat
+ 2007-12-31 20:23:33 367,988 ----a-w C:\WINDOWS\system32\perfh00C.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2001-08-28 07:00 13312]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2001-08-02 07:14 1077277]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2005-10-24 14:53 307200]
"fyyv433b"="" []
"0z5imhw697e"="" []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"fyyv433b"="" []
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe" [2006-05-03 01:56 36975]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [2003-09-29 06:10 81990]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2003-09-10 02:11 135251]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 09:36 256576]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 15:57 282624]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-08 23:02 919280]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-09-03 15:34 185632]
"a-squared"="C:\Program Files\a-squared Anti-Malware\a2guard.exe" [2007-12-28 15:33 1816208]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25 6731312]
"wosa"="" []
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2001-08-28 07:00 13312]
"Symantec NetDriver Warning"="C:\PROGRA~1\SYMNET~1\SNDWarn.exe" [2004-10-29 08:52 218232]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [ ]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableRegistryTools"= 0 (0x0)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
swcfygfd
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-01-05 02:33:00 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-04 22:26:58
Windows 5.1.2600 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-01-04 22:39:25 - machine was rebooted
C:\qoobox\ComboFix-quarantined-files.txt 2008-01-05 03:38:53
C:\qoobox\ComboFix2.txt 2008-01-01 17:34:06
C:\qoobox\ComboFix3.txt 2007-12-31 20:23:23
WOW,je sais pas ce que tu viens de me faire exécuter mais je pense bien que ca a fonctionné,j'ouvre IE et je n'ai plus de redirection de pages et AVG ne me signal plus de la présence du trojan a chaque fois que j'ouvre IE!On peut dire que tu est vraiment bolé en informatique,tu viens de me sauver beaucoup de tracas,j'en reviens pas!j'avais perdu espoir!Est-ce que je devrais relancer tous l'artillerie quand même(AVG,adaware,spybot,etc...)et y-a-t-il des des fonction à recocher?Merci encore!!!!!!!!