Je ne l'ai pas trouvé danc c:\ mais dans c:\combofix\combofix.txt
ComboFix 08-01-09.2 - Lud 2008-01-09 13:31:36.1 - NTFSx86 MINIMAL
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.555 [GMT 1:00]
Running from: C:\Documents and Settings\Lud\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data.\salesmonitor
C:\Documents and Settings\Lud\Application Data\DriveCleaner Free
C:\Documents and Settings\Lud\Application Data\DriveCleaner Free\Logs\update.log
C:\Documents and Settings\Lud\err.log
C:\Documents and Settings\Lud\ResErrors.log
C:\PROGRA~1\Wanadoo\GestMaj.exe
C:\PROGRA~1\Wanadoo\Watch.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Wanadoo\GestMaj .exe
C:\Program Files\Wanadoo\Shell.exe
C:\Program Files\Wanadoo\Watch .exe
C:\Program Files\winantivirus pro 2007
C:\WINDOWS\system32\0_exception.nls
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\ctfmon.exe.tmp
C:\WINDOWS\system32\ddcyy.dll
C:\WINDOWS\system32\ddcyy.exe
C:\WINDOWS\system32\jkkjk.dll
C:\WINDOWS\system32\rtstv.ini
C:\WINDOWS\system32\rtstv.ini2
C:\WINDOWS\system32\ssttu.dll
C:\WINDOWS\system32\vturo.dll
C:\WINDOWS\system32\xbxokqaj.exe
C:\WINDOWS\system32\yycdd.ini
C:\WINDOWS\system32\yycdd.ini2
[code] <pre>
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt .exe ---> avgnt.exe
C:\Program Files\Wanadoo\GestMaj .exe ---> QooBox
C:\Program Files\Wanadoo\Shell .exe ---> Shell.exe
C:\Program Files\Wanadoo\Watch .exe ---> QooBox
C:\WINDOWS\system32\ctfmon .exe ---> ctfmon.exe
</pre> [/code]
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_DOMAINSERVICE
-------\LEGACY_RUNTIME
-------\LEGACY_SMTPDRV
-------\DomainService
-------\nm
-------\runtime
-------\smtpdrv
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-12-09 to 2008-01-09 ))))))))))))))))))))))))))))))))))))
.
2008-01-09 13:29 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-09 13:08 . 2008-01-09 13:08 <REP> d-------- C:\Program Files\Trend Micro
2008-01-09 12:49 . 2008-01-09 12:49 <REP> d-------- C:\Program Files\Avira
2008-01-09 12:46 . 2008-01-09 13:24 24,832 --a------ C:\WINDOWS\system32\drivers\Swb71.sys
2008-01-09 12:17 . 2008-01-09 12:17 1,568,947 --a------ C:\upload_moi_LUDOVIC-KPOLFMO.tar.gz
2008-01-09 12:01 . 2008-01-09 12:11 <REP> d-------- C:\Program Files\Navilog1
2008-01-09 11:47 . 2008-01-09 11:47 <REP> d-------- C:\Program Files\Sophos
2008-01-09 10:37 . 2008-01-09 10:51 <REP> d-------- C:\WINDOWS\system32\ActiveScan
2008-01-09 10:37 . 2008-01-09 10:39 30,590 --a------ C:\WINDOWS\system32\pavas.ico
2008-01-09 10:37 . 2008-01-09 10:39 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-01-09 10:37 . 2008-01-09 10:39 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-01-09 08:56 . 2008-01-09 08:56 <REP> d-------- C:\Program Files\MSXML 6.0
2008-01-08 19:37 . 2008-01-08 19:37 <REP> d-------- C:\Program Files\Reference Assemblies
2008-01-08 19:36 . 2008-01-08 19:36 <REP> d-------- C:\c7e28b6c0af72f076f96a7c47928776b
2008-01-08 19:35 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-01-08 19:02 . 2008-01-08 19:02 <REP> d-------- C:\VundoFix Backups
2008-01-08 17:09 . 2008-01-08 17:09 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-01-06 13:32 . 2004-08-03 23:00 29,056 --a------ C:\WINDOWS\system32\drivers\ip6fw.sys
2008-01-06 13:32 . 2004-08-03 23:00 29,056 --a--c--- C:\WINDOWS\system32\dllcache\ip6fw.sys
2008-01-06 13:03 . 2008-01-06 13:03 <REP> d-------- C:\Program Files\SAGEM WiFi manager
2008-01-06 13:03 . 2008-01-06 13:03 <REP> d-------- C:\Program Files\SAGEM
2008-01-06 13:03 . 2006-01-18 14:09 31,744 --a------ C:\WINDOWS\system32\drivers\ZDPSp50a64.sys
2008-01-06 13:03 . 2006-01-18 14:09 29,184 --a------ C:\WINDOWS\system32\drivers\BRGSp50a64.sys
2008-01-06 13:03 . 2006-01-18 14:09 20,608 --a------ C:\WINDOWS\system32\drivers\BRGSp50.sys
2008-01-06 13:03 . 2006-01-18 14:09 17,664 --a------ C:\WINDOWS\system32\drivers\ZDPSp50.sys
2008-01-06 13:01 . 2005-12-22 14:45 493,440 --a------ C:\WINDOWS\system32\drivers\WlanBZ64.SYS
2008-01-06 13:01 . 2005-12-22 14:45 402,432 --a------ C:\WINDOWS\system32\drivers\WlanBZXP.sys
2008-01-06 12:59 . 2008-01-06 12:59 <REP> d-------- C:\Program Files\Securitoo
2008-01-05 13:16 . 2008-01-08 17:04 21,760 --a------ C:\WINDOWS\Nsv04.sys
2008-01-05 10:14 . 2008-01-08 18:51 2,034 ---hs---- C:\WINDOWS\system32\dqvwcmkf.ini
2008-01-05 10:03 . 2008-01-05 10:03 21,760 --a------ C:\WINDOWS\system32\drivers\Nsv04.sys
2007-12-30 08:15 . 2007-12-30 08:15 268 --ah----- C:\sqmdata07.sqm
2007-12-30 08:15 . 2007-12-30 08:15 244 --ah----- C:\sqmnoopt07.sqm
2007-12-15 23:15 . 2007-12-15 23:15 268 --ah----- C:\sqmdata06.sqm
2007-12-15 23:15 . 2007-12-15 23:15 244 --ah----- C:\sqmnoopt06.sqm
2007-12-15 20:42 . 2007-12-15 20:42 244 --ah----- C:\sqmnoopt04.sqm
2007-12-15 20:42 . 2007-12-15 20:42 232 --ah----- C:\sqmdata03.sqm
2007-12-15 20:42 . 2007-12-15 20:42 172 --ah----- C:\sqmnoopt05.sqm
2007-12-15 20:42 . 2007-12-15 20:42 172 --ah----- C:\sqmdata05.sqm
2007-12-15 20:42 . 2007-12-15 20:42 136 --ah----- C:\sqmdata04.sqm
2007-12-15 20:41 . 2007-12-15 20:41 244 --ah----- C:\sqmnoopt03.sqm
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-09 12:40 --------- d-----w C:\Program Files\Wanadoo
2008-01-06 12:03 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-04 08:20 --------- d-----w C:\Documents and Settings\Lud\Application Data\uTorrent
2007-12-07 18:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-29 12:34 512 ----a-w C:\ScanSectorLog.dat
2007-10-27 18:41 92,064 ----a-w C:\Documents and Settings\Lud\mqdmmdm.sys
2007-10-27 18:41 9,232 ----a-w C:\Documents and Settings\Lud\mqdmmdfl.sys
2007-10-27 18:41 79,328 ----a-w C:\Documents and Settings\Lud\mqdmserd.sys
2007-10-27 18:41 66,656 ----a-w C:\Documents and Settings\Lud\mqdmbus.sys
2007-10-27 18:41 6,208 ----a-w C:\Documents and Settings\Lud\mqdmcmnt.sys
2007-10-27 18:41 5,936 ----a-w C:\Documents and Settings\Lud\mqdmwhnt.sys
2007-10-27 18:41 4,048 ----a-w C:\Documents and Settings\Lud\mqdmcr.sys
2007-10-27 18:41 25,600 ----a-w C:\Documents and Settings\Lud\usbsermptxp.sys
2007-10-27 18:41 22,768 ----a-w C:\Documents and Settings\Lud\usbsermpt.sys
2007-02-16 19:19 278,528 ----a-w C:\Program Files\Fichiers communs\FDEUnInstaller.exe
.
[code]<pre>
----a-w 153,136 2008-01-05 19:34:56 C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck .exe
----a-w 202,024 2008-01-05 19:35:15 C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor .exe
----a-w 1,836,328 2008-01-05 19:35:07 C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan .exe
</pre>[/code]
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4a29c20e-2312-4374-a091-0c0e090a3e16}]
C:\WINDOWS\system32\roirafsf.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WOOKIT"="C:\Program Files\Wanadoo\Shell.exe" [2008-01-09 13:07 122880]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [ ]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-08-30 06:48 69632 C:\WINDOWS\SOUNDMAN.EXE]
"NeroFilterCheck"="C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe" [ ]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [ ]
"WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [ ]
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [ ]
"Cmaudio"="cmicnfg.cpl" []
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-01-09 13:06 249896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [ ]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Nsv04.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Swb71.sys]
@="Driver"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe
"msnmsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
"WOOKIT"=C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe
"WOOTASKBARICON"=C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
"Creative WebCam Tray"=C:\Program Files\Creative\Shared Files\CAMTRAY.EXE
"WOOWATCH"=C:\PROGRA~1\Wanadoo\Watch.exe
"InCD"=C:\Program Files\Ahead\InCD\InCD.exe
"SiSPower"=Rundll32.exe SiSPower.dll,ModeAgent
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
"SiSUSBRG"=C:\WINDOWS\SiSUSBrg.exe
"AGRSMMSG"=AGRSMMSG.exe
"SiS Windows KeyHook"=C:\WINDOWS\System32\keyhook.exe
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
"SynTPLpr"=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
R0 Nsv04;Nsv04;C:\WINDOWS\system32\Drivers\Nsv04.sys [2008-01-05 10:03]
R0 Swb71;Swb71;C:\WINDOWS\system32\Drivers\Swb71.sys [2008-01-09 13:24]
S3 MEMSWEEP2;MEMSWEEP2;C:\WINDOWS\system32\1A.tmp []
S3 P1171VID;Creative WebCam Notebook #2;C:\WINDOWS\system32\DRIVERS\P1171Vid.sys [2004-03-19 02:00]
S3 RescueDrv;Inventel Access Point USB Rescue Driver;C:\WINDOWS\system32\Drivers\resc_dwb.sys [2003-04-24 12:03]
S3 SG762_XP;SAGEM 802.11g XG762 1211B Driver;C:\WINDOWS\system32\DRIVERS\WlanBZXP.sys [2005-12-22 14:45]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
S3 ZDCndis5;ZDCndis5 Protocol Driver;C:\WINDOWS\System32\ZDCndis5.SYS []
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-01-04 16:15:00 C:\WINDOWS\Tasks\Maintenance en 1 clic.job"
- C:\Program Files\TuneUp Utilities 2006\SystemOptimizer.exe
"2008-01-09 12:21:01 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"