Re
j avaisbien lancé runonce ; mais j ai supprimé les 6 lignes comme demandé
ci dessous le rapport combofix
ComboFix 08-03-09.1 - LOIRS 1 2008-03-09 21:51:55.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.232 [GMT 1:00]
Endroit: C:\Documents and Settings\LOIRS 1\Bureau\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\LOIRS 1\Application Data\ShoppingReport
C:\Documents and Settings\LOIRS 1\Application Data\ShoppingReport\cs\Config.xml
C:\Documents and Settings\LOIRS 1\Application Data\ShoppingReport\cs\db\Aliases.dbs
C:\Documents and Settings\LOIRS 1\Application Data\ShoppingReport\cs\db\Sites.dbs
C:\Documents and Settings\LOIRS 1\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
C:\Documents and Settings\LOIRS 1\Application Data\ShoppingReport\cs\report\aggr_storage.xml
C:\Documents and Settings\LOIRS 1\Application Data\ShoppingReport\cs\report\send_storage.xml
C:\Documents and Settings\LOIRS 1\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
C:\Documents and Settings\LOIRS 1\Local Settings\Application Data\evfvf.dat
C:\Documents and Settings\LOIRS 1\Local Settings\Application Data\evfvf_nav.dat
C:\Documents and Settings\LOIRS 1\Local Settings\Application Data\evfvf_navps.dat
C:\Documents and Settings\LOIRS 1\Local Settings\Application Data\yitsfuwlqs.dat
C:\Documents and Settings\LOIRS 1\Local Settings\Application Data\yitsfuwlqs_nav.dat
C:\Documents and Settings\LOIRS 1\Local Settings\Application Data\yitsfuwlqs_navps.dat
C:\Program Files\ShoppingReport
.
((((((((((((((((((((((((((((( Fichiers créés 2008-02-09 to 2008-03-09 ))))))))))))))))))))))))))))))))))))
.
2008-03-08 00:24 . 2008-03-08 00:24 <REP> d-------- C:\Documents and Settings\LOIRS 1\Application Data\dvdcss
2008-03-08 00:21 . 2008-03-08 00:21 <REP> d-------- C:\Documents and Settings\LOIRS 1\Application Data\vlc
2008-03-08 00:20 . 2008-03-08 00:20 <REP> d-------- C:\Program Files\VideoLAN
2008-03-07 23:40 . 2008-03-07 23:43 <REP> d-------- C:\Documents and Settings\LOIRS 1\Application Data\Media Player Classic
2008-03-07 23:12 . 2008-03-07 23:12 <REP> d-------- C:\DECCHECK
2008-03-07 21:44 . 2008-03-07 22:03 <REP> d-------- C:\WINDOWS\BDOSCAN8
2008-03-06 14:27 . 2008-03-06 14:27 <REP> d-------- C:\VundoFix Backups
2008-03-05 20:43 . 1980-01-04 01:34 <REP> d--h----- C:\Documents and Settings\Invité\Voisinage réseau
2008-03-05 20:43 . 1980-01-04 01:34 <REP> d--h----- C:\Documents and Settings\Invité\Voisinage réseau
2008-03-05 20:43 . 1980-01-04 01:34 <REP> d--h----- C:\Documents and Settings\Invité\Voisinage d'impression
2008-03-05 20:43 . 1980-01-04 01:34 <REP> d--h----- C:\Documents and Settings\Invité\Voisinage d'impression
2008-03-05 20:43 . 1980-01-04 00:42 <REP> d--h----- C:\Documents and Settings\Invité\Modèles
2008-03-05 20:43 . 1980-01-04 00:42 <REP> d--h----- C:\Documents and Settings\Invité\Modèles
2008-03-05 20:43 . 2008-03-05 20:45 <REP> dr------- C:\Documents and Settings\Invité\Mes documents
2008-03-05 20:43 . 2008-03-05 20:45 <REP> dr------- C:\Documents and Settings\Invité\Mes documents
2008-03-05 20:43 . 1980-01-04 01:34 <REP> dr------- C:\Documents and Settings\Invité\Menu Démarrer
2008-03-05 20:43 . 1980-01-04 01:34 <REP> dr------- C:\Documents and Settings\Invité\Menu Démarrer
2008-03-05 20:43 . 2008-03-05 20:44 <REP> dr------- C:\Documents and Settings\Invité\Favoris
2008-03-05 20:43 . 2008-03-05 20:44 <REP> dr------- C:\Documents and Settings\Invité\Favoris
2008-03-05 20:43 . 1980-01-04 01:34 <REP> d-------- C:\Documents and Settings\Invité\Bureau
2008-03-05 20:43 . 1980-01-04 01:34 <REP> d-------- C:\Documents and Settings\Invité\Bureau
2008-03-05 02:53 . 2008-03-05 02:55 <REP> d-------- C:\Program Files\RogueRemover FREE
2008-03-05 01:55 . 2008-03-05 02:00 <REP> d-------- C:\Program Files\Lopxp
2008-03-05 01:12 . 2008-03-05 01:42 <REP> d-------- C:\Program Files\Trojan Remover
2008-03-05 01:12 . 2003-02-02 19:06 153,088 --a------ C:\WINDOWS\system32\UNRAR3.dll
2008-03-05 01:12 . 2002-03-06 00:00 75,264 --a------ C:\WINDOWS\system32\unacev2.dll
2008-03-05 01:05 . 2008-03-05 01:05 <REP> d-------- C:\Documents and Settings\LOIRS 1\DoctorWeb
2008-03-05 00:11 . 2008-03-05 00:48 <REP> d-------- C:\Program Files\a-squared Free
2008-03-04 19:49 . 1996-08-20 20:37 15,840 --a------ C:\WINDOWS\system32\Machnm1.exe
2008-03-04 19:49 . 2005-09-25 16:37 5,632 --a------ C:\WINDOWS\system32\Machnm64.sys
2008-03-04 19:49 . 2008-03-04 19:49 3,120 --a------ C:\WINDOWS\system32\118290.54
2008-03-04 19:49 . 2008-03-04 19:49 3,120 --a------ C:\WINDOWS\118294.78
2008-03-04 19:49 . 2003-08-13 00:27 2,304 --a------ C:\WINDOWS\system32\Machnm32.sys
2008-03-04 19:13 . 2008-03-05 21:01 <REP> d-------- C:\Program Files\SpywareBlaster
2008-03-03 15:34 . 2008-03-04 18:51 <REP> d-------- C:\Program Files\SPYWAREfighter
2008-03-03 14:56 . 2008-03-03 14:56 <REP> d-------- C:\Program Files\Enigma Software Group
2008-03-03 11:55 . 2007-07-30 19:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-03-03 11:55 . 2007-07-30 19:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-03-03 00:56 . 2007-12-04 14:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
2008-03-03 00:56 . 2004-01-09 10:13 380,928 --a------ C:\WINDOWS\system32\actskin4.ocx
2008-03-03 00:56 . 2007-12-04 13:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2008-03-03 00:56 . 2007-12-04 15:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2008-03-03 00:56 . 2007-12-04 15:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2008-03-03 00:56 . 2007-12-04 15:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2008-03-03 00:56 . 2007-12-04 15:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2008-03-03 00:56 . 2007-12-04 15:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2008-03-02 23:11 . 2008-03-03 00:51 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Trend Micro
2008-03-01 10:49 . 2008-03-01 10:49 281 --a------ C:\WINDOWS\wininit.ini
2008-03-01 01:37 . 2008-03-01 10:49 <REP> d-------- C:\Program Files\NetProject
2008-02-29 22:40 . 2008-02-29 22:40 1,158 --a------ C:\WINDOWS\mozver.dat
2008-02-29 21:44 . 2008-02-29 21:51 <REP> d-------- C:\Program Files\Opera
2008-02-27 21:55 . 2008-02-27 21:55 <REP> d-------- C:\Program Files\CCleaner
2008-02-24 22:58 . 2008-02-24 22:58 465,130 --a------ C:\WINDOWS\system32\perfh040.dat
2008-02-24 22:58 . 2008-02-24 22:58 73,458 --a------ C:\WINDOWS\system32\perfc040.dat
2008-02-24 15:57 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-02-24 15:57 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-02-24 15:57 . 2008-02-22 18:44 86,016 --a------ C:\WINDOWS\system32\VACFix.exe
2008-02-24 15:57 . 2008-02-08 10:37 82,432 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-02-24 15:57 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-02-24 14:43 . 2008-03-03 00:52 <REP> d-------- C:\Program Files\Trend Micro
2008-02-23 23:31 . 2008-02-24 16:41 1,040 --a------ C:\WINDOWS\system32\tmp.reg
2008-02-17 18:55 . 2008-02-17 18:55 <REP> d-------- C:\Documents and Settings\LOIRS 1\Application Data\winpcdoctor
2008-02-17 18:50 . 2008-02-17 18:58 <REP> d-------- C:\Program Files\WinPCDoctor
2008-02-17 18:50 . 2008-02-17 21:09 <REP> d-------- C:\Program Files\Fichiers communs\WinPCDoctor
2008-02-17 18:50 . 2008-02-17 18:50 <REP> dr------- C:\Documents and Settings\All Users.WINDOWS\Application Data\winpcdoctor
2008-02-17 18:50 . 2008-02-17 18:50 <REP> dr------- C:\Documents and Settings\All Users.WINDOWS\Application Data\SalesMon
2008-02-17 03:46 . 2006-10-04 15:06 1,197,294 -----c--- C:\WINDOWS\system32\dllcache\sysmain.sdb
2008-02-17 03:44 . 2004-08-19 16:09 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2008-02-17 03:43 . 2008-02-17 03:43 <REP> d-------- C:\Program Files\Windows Media Connect 2
2008-02-17 03:37 . 2008-02-17 03:37 <REP> d-------- C:\WINDOWS\system32\drivers\umdf
2008-02-17 00:51 . 2005-08-25 18:18 118,784 --a------ C:\WINDOWS\system32\MSSTDFMT.DLL
2008-02-17 00:51 . 2005-08-25 18:19 115,920 --a------ C:\WINDOWS\system32\MSINET.OCX
2008-02-16 22:47 . 2004-08-19 16:08 97,280 --a------ C:\WINDOWS\system32\dpcdll.dll.wga
2008-02-16 22:47 . 2004-08-19 16:08 24,064 --a------ C:\WINDOWS\system32\pidgen.dll.wga
2008-02-16 22:47 . 2008-02-16 22:47 13,588 --a------ C:\WINDOWS\system32\wpa.bak
2008-02-14 23:31 . 2008-02-24 21:44 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-02-14 23:31 . 2008-02-24 22:42 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-02-14 23:10 . 2008-03-02 22:58 <REP> d-------- C:\Program Files\Yahoo!
2008-02-10 14:32 . 2008-02-10 14:32 168 --a------ C:\WINDOWS\adidsl.ini
2008-02-10 14:32 . 2008-02-10 14:32 21 --a------ C:\WINDOWS\Fast800.ini
2008-02-10 14:31 . 2008-02-10 14:31 <REP> d-------- C:\Program Files\SAGEM
2008-02-10 14:30 . 2008-02-10 14:30 <REP> d-------- C:\WINDOWS\system32\AlertModule
2008-02-10 14:30 . 2004-08-23 14:49 40,960 --a------ C:\WINDOWS\system32\FTRTSVC.exe
2008-02-09 14:08 . 2008-02-09 14:08 <REP> d-------- C:\Program Files\Panicware
2008-02-09 09:11 . 2008-02-17 00:57 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
2008-02-09 01:35 . 2008-02-09 08:51 <REP> d----c--- C:\WINDOWS\system32\DRVSTORE
2008-02-09 01:34 . 2008-02-09 01:34 <REP> d-------- C:\WINDOWS\system32\bits
2008-02-09 01:34 . 2007-03-29 13:58 7,168 -----c--- C:\WINDOWS\system32\dllcache\bitsprx4.dll
2008-02-09 01:34 . 2007-03-29 13:58 7,168 --------- C:\WINDOWS\system32\bitsprx4.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-09 20:46 --------- d---a-w C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-03-09 20:38 --------- d-----w C:\Program Files\Wanadoo
2008-03-04 19:13 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-03-04 19:13 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2008-02-17 03:46 --------- d-----w C:\Program Files\Hot-TV
2008-02-13 20:18 --------- d-----w C:\Program Files\OpenOffice.org 2.3
2008-02-10 13:32 31 ----a-w C:\WINDOWS\system32\drivers\adidsl.cfg
2008-02-02 23:08 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-02-02 22:58 --------- d-----w C:\Documents and Settings\LOIRS 1\Application Data\AdobeUM
2008-01-24 22:19 --------- d-----w C:\Program Files\JeffProd
2008-01-21 23:56 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Arovax
2008-01-21 23:20 --------- d-----w C:\Program Files\Spyware Doctor
2008-01-19 01:52 --------- d-----w C:\Program Files\CyberDefender
2008-01-16 23:44 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft
2008-01-13 01:01 --------- d-----w C:\Documents and Settings\LOIRS 1\Application Data\OpenOffice.org2
2008-01-13 00:52 --------- d-----w C:\Program Files\Java
2008-01-13 00:51 --------- d-----w C:\Program Files\Fichiers communs\Java
2008-01-13 00:38 --------- d-----w C:\Program Files\olibul
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WOOKIT"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 16:55 32768]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 16:09 15360]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
"ccleaner"="C:\Program Files\CCleaner\CCleaner.exe" [2008-02-20 15:15 816368]
"PopUpStopperFreeEdition"="C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe" [2005-03-17 11:10 536576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-06-07 21:05 344064]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
"WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 14:49 20480]
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 16:55 32768]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"nlsf"="cmd.exe" [2004-08-19 16:09 400896 C:\WINDOWS\system32\cmd.exe]
"tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-19 15:52 44544]
C:\Documents and Settings\All Users.WINDOWS\Menu D‚marrer\Programmes\D‚marrage\
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoDesktopCleanupWizard"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"NoStrCmpLogical"= 0 (0x0)
"NoInstrumentation"= 0 (0x0)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoDesktopCleanupWizard"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"DisablePagingExecutive"=dword:00000001
"SecondLevelDataCache"=dword:00000200
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R3 e4usbaw;USB ADSL2 WAN Adapter;C:\WINDOWS\system32\DRIVERS\e4usbaw.sys [2006-05-04 18:50]
S2 IKANLOADER2;General Purpose USB Driver (e4ldr.sys);C:\WINDOWS\system32\Drivers\e4ldr.sys [2006-03-02 19:25]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-09 21:53:24
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-03-09 21:54:29
ComboFix-quarantined-files.txt 2008-03-09 20:53:58
.
2008-02-20 22:43:01 --- E O F ---
voila a plus