Voici le rapport vundofix
undoFix V6.7.7
Checking Java version...
Scan started at 22:47:50 13/01/2008
Listing files found while scanning....
No infected files were found.
Beginning removal...
Pour le rapport virtumondebegone, je crois que c'est là que l'ordi m'a affiché une fenetre drawone.exe "l'application n'a pu s'initialiser car la station est entrain de s'arrêter"
Merci pour votre aide car je n'y comprends plus rien
Voici le rapport combofix
ComboFix 08-01-14.1 - Magali 2008-01-14 23:11:32.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.581 [GMT 1:00]
Running from: C:\Documents and Settings\Magali\Mes documents\ComboFix.exe
[color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\msacm32.drv
F:\Autorun.inf
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-12-14 to 2008-01-14 ))))))))))))))))))))))))))))))))))))
.
2008-01-13 23:07 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
2008-01-13 22:47 . 2008-01-13 22:47 <REP> d-------- C:\VundoFix Backups
2008-01-13 22:43 . 2008-01-13 22:44 <REP> d-------- C:\HIJACKTHIS
2008-01-12 19:53 . 2008-01-13 22:33 <REP> d-------- C:\Program Files\RogueRemover FREE
2008-01-12 19:18 . 2008-01-13 22:32 <REP> d-------- C:\Program Files\Navilog1
2008-01-10 22:58 . 2006-12-26 13:26 <REP> d--h----- C:\Documents and Settings\Administrateur.GRANCI-5645F929\Voisinage r‚seau
2008-01-10 22:58 . 2006-12-26 13:26 <REP> d--h----- C:\Documents and Settings\Administrateur.GRANCI-5645F929\Voisinage d'impression
2008-01-10 22:58 . 2006-12-26 12:45 <REP> d--h----- C:\Documents and Settings\Administrateur.GRANCI-5645F929\ModŠles
2008-01-10 22:58 . 2006-12-26 13:26 <REP> d-------- C:\Documents and Settings\Administrateur.GRANCI-5645F929\Mes documents
2008-01-10 22:58 . 2006-12-26 13:26 <REP> dr------- C:\Documents and Settings\Administrateur.GRANCI-5645F929\Menu D‚marrer
2008-01-10 22:58 . 2006-12-26 13:26 <REP> d-------- C:\Documents and Settings\Administrateur.GRANCI-5645F929\Favoris
2008-01-10 22:58 . 2006-12-26 13:26 <REP> d-------- C:\Documents and Settings\Administrateur.GRANCI-5645F929\Bureau
2008-01-10 22:52 . 2006-12-26 13:26 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage r‚seau
2008-01-10 22:52 . 2006-12-26 13:26 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-01-10 22:52 . 2006-12-26 12:45 <REP> d--h----- C:\Documents and Settings\Administrateur\ModŠles
2008-01-10 22:52 . 2006-12-26 13:26 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents
2008-01-10 22:52 . 2006-12-26 13:26 <REP> dr------- C:\Documents and Settings\Administrateur\Menu D‚marrer
2008-01-10 22:52 . 2006-12-26 13:26 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris
2008-01-10 22:52 . 2006-12-26 13:26 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2008-01-10 22:42 . 2008-01-11 00:26 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-08 19:30 . 2008-01-08 19:30 <REP> d-------- C:\Program Files\CCleaner
2008-01-07 13:16 . 2008-01-07 13:16 <REP> d-------- C:\Program Files\size kind city
2008-01-05 21:41 . 2008-01-07 13:16 <REP> d-------- C:\Documents and Settings\Magali\Application Data\size kind city
2008-01-03 19:51 . 2008-01-03 19:51 <REP> d-------- C:\Documents and Settings\Magali\Application Data\vlc
2008-01-03 19:50 . 2008-01-03 19:50 <REP> d-------- C:\Program Files\VideoLAN
2007-12-21 18:18 . 2008-01-04 19:37 <REP> d-------- C:\Documents and Settings\Maurice\Application Data\size kind city
2007-12-21 18:07 . 2008-01-07 13:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\flag ace stupid data
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-14 22:15 --------- d-----w C:\Program Files\Wanadoo
2008-01-14 22:15 --------- d-----w C:\Documents and Settings\Magali\Application Data\OpenOffice.org2
2008-01-13 20:18 --------- d-----w C:\Documents and Settings\Maurice\Application Data\OpenOffice.org2
2008-01-08 12:32 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-08 11:24 --------- d-----w C:\Documents and Settings\Magali\Application Data\MSNInstaller
2008-01-07 19:00 --------- d-----w C:\Program Files\eMule
2008-01-05 15:07 --------- d-----w C:\Program Files\Messenger Plus! Live
2008-01-01 18:42 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2007-12-30 19:18 --------- d-----w C:\Program Files\Java
2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-11-07 09:28 728,576 ----a-w C:\WINDOWS\system32\lsasrv.dll
2007-10-29 22:43 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 13:00 15360]
"Programnoun"="C:\DOCUME~1\Magali\APPLIC~1\SIZEKI~1\Drawone.exe" [2008-01-07 13:16 410624]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 14:49 20480]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 13:38 49152]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 15:18 241664]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 16:55 32768]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06 40048]
"Stupid Data Dart Wave"="C:\Documents and Settings\All Users\Application Data\flag ace stupid data\Rect Bind.exe" [2008-01-14 23:16 1816064]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2006-03-02 13:00 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--------- 2004-10-13 17:24 1694208 C:\Program Files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOKIT]
--a------ 2004-08-23 14:50 122880 C:\Program Files\Wanadoo\Shell.exe
S3 MosIrUsb;MosIrUsb.sys;C:\WINDOWS\system32\DRIVERS\MosIrUsb.sys [2004-04-14 14:52]
S3 ZDCndis5;ZDCndis5 Protocol Driver;C:\WINDOWS\system32\ZDCndis5.SYS []
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-01-13 22:00:00 C:\WINDOWS\Tasks\A0C450B290C7CFFA.job"
- c:\docume~1\cdric~1\applic~1\sizeki~1\Date This Mp3.exe
"2008-01-13 22:00:04 C:\WINDOWS\Tasks\A8488DC591B70291.job"
- c:\docume~1\magali\applic~1\sizeki~1\Date This Mp3.exe
"2008-01-13 22:00:01 C:\WINDOWS\Tasks\B16613AD90DD8521.job"
- c:\docume~1\maurice\applic~1\sizeki~1\Date This Mp3.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-01-14 23:15:37
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\Program Files\ArcSoft\PhotoImpression 5\share\pihook.dll
.
Completion time: 2008-01-14 23:19:24 - machine was rebooted [Magali]
ComboFix-quarantined-files.txt 2008-01-14 22:19:20
.
2008-01-09 22:28:55 --- E O F ---
Pour les deux fichiers à analyser, je ne trouve pas leur chemin
Merci de m'aider