J'ai réussi a faire combo fix; voici le rapport.merci
ComboFix 08-01-30.1 - Jean-Michel 2008-01-31 16:11:50.3 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.193 [GMT 1:00]
Endroit: I:\Documents and Settings\Jean-Michel\Bureau\ComboFix.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
((((((((((((((((((((((((((((( Fichiers créés 2007-12-28 to 2008-01-31 ))))))))))))))))))))))))))))))))))))
.
2008-01-31 13:11 . 2008-01-31 13:11 <REP> d-------- I:\Program Files\Avira
2008-01-31 13:02 . 2008-01-31 13:02 244 --ah----- I:\sqmnoopt02.sqm
2008-01-31 13:02 . 2008-01-31 13:02 232 --ah----- I:\sqmdata02.sqm
2008-01-31 03:31 . 2008-01-31 03:31 244 --ah----- I:\sqmnoopt01.sqm
2008-01-31 03:31 . 2008-01-31 03:31 232 --ah----- I:\sqmdata01.sqm
2008-01-31 03:17 . 2008-01-31 03:17 244 --ah----- I:\sqmnoopt00.sqm
2008-01-31 03:17 . 2008-01-31 03:17 232 --ah----- I:\sqmdata00.sqm
2008-01-31 02:12 . 2008-01-31 03:08 250 --a------ I:\WINDOWS\gmer.ini
2008-01-31 01:23 . 2008-01-31 01:23 161 --a------ I:\Delme.bat
2008-01-31 01:15 . 2008-01-31 01:15 <REP> d-------- I:\WINDOWS\DED53B0BB67C4244AE6AD6FD3C28D1EF.TMP
2008-01-30 17:47 . 2008-01-30 17:47 <REP> d-------- I:\Documents and Settings\Jean-Michel\Application Data\Live-Prod
2008-01-30 15:29 . 2008-01-30 15:29 <REP> d-------- I:\Documents and Settings\Jean-Michel\Application Data\Grisoft
2008-01-30 15:29 . 2007-05-30 13:10 10,872 --a------ I:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-01-30 03:39 . 2008-01-30 17:18 <REP> d-------- I:\Documents and Settings\All Users\Application Data\Lavasoft
2008-01-30 03:30 . 2007-09-05 23:22 289,144 --a------ I:\WINDOWS\system32\VCCLSID.exe
2008-01-30 03:30 . 2006-04-27 16:49 288,417 --a------ I:\WINDOWS\system32\SrchSTS.exe
2008-01-30 03:30 . 2008-01-27 14:37 81,920 --a------ I:\WINDOWS\system32\IEDFix.exe
2008-01-30 03:30 . 2004-07-31 17:50 51,200 --a------ I:\WINDOWS\system32\dumphive.exe
2008-01-30 03:30 . 2007-10-03 23:36 25,600 --a------ I:\WINDOWS\system32\WS2Fix.exe
2008-01-30 03:30 . 2008-01-30 03:30 1,834 --a------ I:\WINDOWS\system32\tmp.reg
2008-01-30 02:58 . 2008-01-30 02:58 <REP> d-------- I:\Rustbfix
2008-01-30 02:33 . 2008-01-30 02:33 <REP> d-------- I:\VundoFix Backups
2008-01-30 02:08 . 2008-01-30 13:23 2,374 --a------ I:\WINDOWS\mozver.dat
2008-01-30 02:06 . 2008-01-30 02:06 0 --a------ I:\WINDOWS\nsreg.dat
2008-01-30 01:56 . 2008-01-30 01:56 59,640 --a------ I:\Documents and Settings\Jean-Michel\Application Data\GDIPFONTCACHEV1.DAT
2008-01-30 00:47 . 2008-01-30 00:47 <REP> d-------- I:\Program Files\Tiscali Triway Wi-Fi
2008-01-30 00:44 . 2008-01-30 00:44 <REP> d-------- I:\WINDOWS\Tiscali
2008-01-30 00:44 . 2008-01-30 00:44 <REP> d-------- I:\Program Files\Tiscali_Triway_WiFi
2008-01-29 23:43 . 2008-01-29 23:43 <REP> d-------- I:\Documents and Settings\Jean-Michel\Application Data\GlarySoft
2008-01-29 23:34 . 2008-01-31 13:11 <REP> d-------- I:\Documents and Settings\All Users\Application Data\Avira
2008-01-29 22:14 . 2008-01-29 22:14 <REP> d-------- I:\Documents and Settings\LocalService\Bureau
2008-01-29 21:51 . 2008-01-29 21:51 <REP> d-------- I:\Documents and Settings\Jean-Michel\Application Data\AVG7
2008-01-29 21:50 . 2008-01-29 21:50 <REP> d-------- I:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-29 21:50 . 2008-01-30 15:28 <REP> d-------- I:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-29 21:14 . 2008-01-29 21:14 <REP> d-------- I:\WINDOWS\ERUNT
2008-01-29 20:14 . 1997-03-05 08:53 48,128 --a------ I:\WINDOWS\system32\SMMSCRPT.DLL
2008-01-29 20:05 . 2004-08-19 16:09 21,504 --a------ I:\WINDOWS\system32\hidserv.dll
2008-01-29 20:05 . 2004-08-19 16:09 21,504 --a--c--- I:\WINDOWS\system32\dllcache\hidserv.dll
2008-01-29 20:05 . 2001-08-23 17:04 12,288 --a------ I:\WINDOWS\system32\drivers\mouhid.sys
2008-01-29 20:05 . 2001-08-23 17:04 12,288 --a--c--- I:\WINDOWS\system32\dllcache\mouhid.sys
2008-01-29 20:05 . 2001-08-17 22:02 9,600 --a------ I:\WINDOWS\system32\drivers\hidusb.sys
2008-01-29 20:05 . 2001-08-17 22:02 9,600 --a--c--- I:\WINDOWS\system32\dllcache\hidusb.sys
2008-01-24 20:21 . 2007-06-13 14:22 1,075,713 --a------ I:\WINDOWS\gilcqfo.exe
2008-01-18 11:21 . 2008-01-27 14:19 <REP> d-------- I:\Program Files\IncrediMail
2008-01-13 16:47 . 2008-01-20 14:31 150 --a------ I:\Documents and Settings\MATHIS\Application Data\wklnhst.dat
2007-12-30 17:48 . 2007-12-30 17:48 284 --a------ I:\Documents and Settings\MANON\Application Data\ViewerApp.dat
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-31 15:10 --------- d-----w I:\Documents and Settings\Jean-Michel\Application Data\OpenOffice.org2
2008-01-31 00:37 --------- d-----w I:\Program Files\RegCleaner
2008-01-31 00:25 --------- d-----w I:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-31 00:15 --------- d-----w I:\Program Files\Fichiers communs\Wise Installation Wizard
2008-01-30 23:06 --------- d-----w I:\Program Files\Alwil Software
2008-01-30 01:32 2,666 ----a-w I:\Documents and Settings\Jean-Michel\Application Data\wklnhst.dat
2008-01-29 23:47 --------- d--h--w I:\Program Files\InstallShield Installation Information
2008-01-29 22:42 --------- d-----w I:\Program Files\Wanadoo
2008-01-29 19:54 67,904 ----a-w I:\Documents and Settings\Jean-Michel\Application Data\mdbu.bin
2008-01-23 16:50 --------- d-----w I:\Program Files\Microsoft Picture It! 9
2008-01-09 16:35 --------- d-----w I:\Program Files\eMule
2008-01-02 10:33 560 ----a-w I:\Documents and Settings\Jean-Michel\Application Data\ViewerApp.dat
2007-11-30 22:32 --------- d-----w I:\Program Files\Windows Live Toolbar
2007-11-19 09:57 254 ----a-w I:\Documents and Settings\MANON\Application Data\wklnhst.dat
2007-11-07 09:28 728,576 ----a-w I:\WINDOWS\system32\lsasrv.dll
2007-10-29 22:43 1,293,824 ----a-w I:\WINDOWS\system32\quartz.dll
2007-10-25 09:00 230,912 ----a-w I:\WINDOWS\system32\wmasf.dll
2007-10-10 23:49 824,832 ----a-w I:\WINDOWS\system32\wininet.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="I:\WINDOWS\system32\ctfmon.exe" [2006-03-02 13:00 15360]
"ccleaner"="I:\Program Files\CCleaner\ccleaner.exe" [2007-07-13 10:10 598656]
"msnmsgr"="I:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:55 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="I:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe" [2004-10-14 08:11 1388544]
"MessagerStarter Wanadoo"="I:\PROGRA~1\MESSAG~1\StartMessager.exe" [2003-04-11 16:06 32768]
"Microsoft Works Update Detection"="I:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe" [2003-06-10 17:49 50688]
"!AVG Anti-Spyware"="I:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
"avgnt"="I:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-01-31 13:16 249896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="I:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:55 5674352]
I:\Documents and Settings\Jean-Michel\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 2.2.lnk - I:\Program Files\OpenOffice.org 2.2\program\quickstart.exe [2007-02-02 15:54:56 393216]
I:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Microsoft Office.lnk - I:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 08:01:04 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
"WooCnxMon"=I:\PROGRA~1\Wanadoo\CnxMon.exe
"WOOWATCH"=I:\PROGRA~1\Wanadoo\Watch.exe
"WOOTASKBARICON"=I:\PROGRA~1\Wanadoo\TaskbarIcon.exe
"TkBellExe"="I:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-01-31 15:12:01 I:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
- I:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-31 16:14:01
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-01-31 16:14:34
ComboFix-quarantined-files.txt 2008-01-31 15:14:32
ComboFix2.txt 2008-01-30 01:02:04
ComboFix3.txt 2008-01-30 00:55:33
.
2008-01-09 16:15:47 --- E O F ---