Merci encore de m'aider:)
ComboFix 08-02.05.3 - anik 2008-02-08 10:00:07.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.226 [GMT -5:00]
Endroit: C:\Documents and Settings\anik\Local Settings\Temporary Internet Files\Content.IE5\JCCFZ6H3\ComboFix[1].exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
C:\Documents and Settings\jf\Menu Démarrer\Programmes\moviebox
C:\Documents and Settings\jf\Menu Démarrer\Programmes\moviebox\Uninstall.lnk
C:\WINDOWS\rs.txt
C:\WINDOWS\search_res.txt
----- BITS: Possible sites infect‚s -----
hxxp://softworldnetwork.com
hxxp://onsafepro.com
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\nm
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-01-08 to 2008-02-08 ))))))))))))))))))))))))))))))))))))
.
2008-02-08 08:17 . 2008-02-08 08:17 <REP> d-------- C:\Program Files\Trend Micro
2008-02-07 11:18 . 2008-02-08 07:59 <REP> d-------- C:\Program Files\RogueRemover FREE
2008-02-02 12:19 . 2008-02-02 00:55 83,456 --a------ C:\WINDOWS\system32\VACFix.exe
2008-01-31 10:01 . 2008-02-08 09:46 3,042 --a------ C:\WINDOWS\system32\tmp.reg
2008-01-31 10:00 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-01-31 10:00 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-01-31 10:00 . 2008-01-27 14:37 81,920 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-01-31 10:00 . 2003-06-05 20:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-01-31 10:00 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-01-31 10:00 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-01-24 10:58 . 2008-01-24 10:58 40 --a------ C:\WINDOWS\TSC.INI
2008-01-24 10:56 . 2008-01-24 10:56 <REP> d-------- C:\WINDOWS\AU_Temp
2008-01-24 10:56 . 2008-01-24 10:56 <REP> d-------- C:\WINDOWS\AU_Log
2008-01-24 10:56 . 2008-01-24 10:56 507,904 --a------ C:\WINDOWS\TMUPDATE.DLL
2008-01-24 10:56 . 2008-01-24 10:56 286,720 --a------ C:\WINDOWS\PATCH.EXE
2008-01-24 10:56 . 2008-01-24 10:56 69,689 --a------ C:\WINDOWS\UNZIP.DLL
2008-01-24 10:56 . 2008-01-24 10:56 170 --a------ C:\WINDOWS\GetServer.ini
2008-01-23 10:39 . 2008-01-23 10:39 97 --a------ C:\WINDOWS\wininit.ini
2008-01-22 16:55 . 2008-01-22 12:55 81,920 --a------ C:\WINDOWS\fvqkfsp.exe
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-07 22:01 --------- d-----w C:\Documents and Settings\anik\Application Data\AdobeUM
2008-01-31 22:52 --------- d-----w C:\Documents and Settings\anik\Application Data\LimeWire
2008-01-23 15:03 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2007-12-30 16:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2007-12-28 23:10 --------- d-----w C:\Program Files\iTunes
2007-12-28 23:09 --------- d-----w C:\Program Files\iPod
2007-12-28 23:08 --------- d-----w C:\Program Files\QuickTime
2007-12-28 23:06 --------- d-----w C:\Program Files\Fichiers communs\Apple
2007-12-28 23:06 --------- d-----w C:\Program Files\Apple Software Update
2007-12-28 23:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple
2007-12-28 22:40 --------- d-----w C:\Program Files\Java
2007-12-28 22:36 --------- d-----w C:\Program Files\Fichiers communs\Java
2007-04-09 12:28 18,696 ----a-w C:\Documents and Settings\jf\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 18:09 15360]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:55 5674352]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2005-11-29 19:19 57344]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"VTTimer"="VTTimer.exe" [2005-03-07 14:33 53248 C:\WINDOWS\system32\VTTimer.exe]
"VTTrayp"="VTtrayp.exe" [2005-10-31 15:15 163840 C:\WINDOWS\system32\VTTrayp.exe]
"RaidTool"="C:\Program Files\VIA\RAID\raid_tool.exe" [2005-11-22 21:12 1060864]
"AudioDeck"="C:\Program Files\VIAudioi\SBADeck\ADeck.exe" [2006-03-20 03:26 516096]
"WireLessMouse "="C:\Program Files\Multimedia Combo Set\MouseDrv.exe" [2004-06-27 14:38 503808]
"WireLessKeyboard "="C:\Program Files\Multimedia Combo Set\PS2USBKbdDrv.exe" [2005-08-02 21:55 245760]
"OrderReminder"="C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe" [2006-01-30 11:00 98304]
"OM_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [2005-11-29 19:19 40960]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]
"Lexmark X74-X75"="C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe" [2002-10-14 14:09 57344]
"VX1000"="C:\WINDOWS\vVX1000.exe" [2006-10-13 17:04 707376]
"LifeCam"="C:\Program Files\Microsoft LifeCam\LifeExp.exe" [2006-10-13 17:01 277296]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 18:09 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"aswmklt"= {D6CC70CE-833C-4FBC-A318-44BE26578E17} - C:\WINDOWS\aswmklt.dll [ ]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 nwprovau
R2 MSCamSvc;MSCamSvc;"C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [2006-10-13 17:01]
R3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 23:58]
R3 VX1000;VX-1000;C:\WINDOWS\system32\DRIVERS\VX1000.sys [2006-10-13 17:04]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 01:08]
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-02-01 01:45:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-08 10:04:21
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\Program Files\MSN Messenger\usnsvc.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-02-08 10:05:57 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-08 15:05:53
.
2008-01-11 14:05:52 --- E O F ---