bonjour voilà le rapport et apparament plus de virus!!!!!MERCI!!!!!!!!!!!!!
ComboFix 08-03-01.3 - sonia 2008-03-01 13:19:53.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.189 [GMT 1:00]
Endroit: C:\Documents and Settings\sonia\Local Settings\Temporary Internet Files\Content.IE5\APZW9GNE\ComboFix[1].exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\system32\ddcayxu.dll
C:\WINDOWS\system32\jjkmp.ini
C:\WINDOWS\system32\jjkmp.ini2
C:\WINDOWS\system32\pmkjj.dll
C:\WINDOWS\system32\xxyawxx.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\LEGACY_OULTRAF
-------\oUltraf
((((((((((((((((((((((((((((( Fichiers créés 2008-02-01 to 2008-03-01 ))))))))))))))))))))))))))))))))))))
.
2008-03-01 11:22 . 2008-03-01 11:25 1,355 --a------ C:\WINDOWS\imsins.BAK
2008-03-01 11:10 . 2007-12-07 03:08 63,488 -----c--- C:\WINDOWS\system32\dllcache\icardie.dll
2008-02-29 12:38 . 2008-02-29 16:21 <REP> d-------- C:\WINDOWS\BDOSCAN8
2008-02-29 10:20 . 2008-02-29 10:20 <REP> d-------- C:\Documents and Settings\sonia\Application Data\Grisoft
2008-02-29 10:04 . 2008-02-29 10:04 <REP> d----c--- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-29 10:04 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-02-29 09:53 . 2008-02-29 09:53 <REP> d-------- C:\Documents and Settings\sonia\Application Data\AVG7
2008-02-29 09:53 . 2008-02-29 09:53 <REP> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-02-29 09:52 . 2008-02-29 10:00 <REP> d----c--- C:\Documents and Settings\All Users\Application Data\avg7
2008-02-28 17:38 . 2008-02-28 17:38 <REP> d-------- C:\Documents and Settings\sonia\Application Data\EPSON
2008-02-01 11:17 . 2008-02-01 11:17 587,264 --a------ C:\WINDOWS\WLXPGSS.SCR
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-29 14:34 --------- d-----w C:\Program Files\Trust_CR-1200_16-in-1_USB2_CARD_READER
2008-02-29 11:31 --------- dc----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-28 20:00 10 ----a-w C:\Program Files\.autoreg
2008-02-27 21:56 --------- d-----w C:\Program Files\Windows Live
2008-02-11 14:09 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-01-22 17:29 --------- d-----w C:\Program Files\Free PDF to Word Doc Converter
2008-01-21 05:24 --------- d-----w C:\Documents and Settings\sonia\Application Data\OpenOffice.org2
2008-01-13 12:00 --------- d-----w C:\Program Files\Shareaza
2008-01-13 12:00 --------- d-----w C:\Documents and Settings\sonia\Application Data\Shareaza
2008-01-11 19:53 --------- d-----w C:\Program Files\Shareaza Applications
2008-01-11 12:20 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-11 12:09 --------- d-----w C:\Program Files\Eidos Interactive
2008-01-09 14:01 53,248 ----a-w C:\WINDOWS\bdoscandel.exe
2008-01-07 17:45 --------- d-----w C:\Program Files\Jewel Quest
2008-01-07 16:57 --------- d-----w C:\Program Files\SpywareBlaster
2008-01-06 15:51 --------- d-----w C:\Documents and Settings\sonia\Application Data\dvdcss
2008-01-04 18:42 --------- dc----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-01-03 16:01 --------- d-----w C:\Documents and Settings\sonia\Application Data\MSN6
2004-10-01 13:00 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
2006-05-19 16:52 56 -csh--r C:\WINDOWS\system32\8A7D6E4389.sys
2006-05-19 16:52 10,126 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2007-10-09 12:02 208946]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 15:09 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 17:24 1694208]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [2005-06-08 13:44 196608]
"Shareaza"="C:\Program Files\Shareaza\Shareaza.exe" [2008-01-01 17:49 4739072]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2003-12-08 16:35 32768]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 09:50 155648]
"pccguide.exe"="C:\Program Files\Trend Micro\Internet Security\pccguide.exe" [2003-11-14 17:58 942142]
"PCClient.exe"="C:\Program Files\Trend Micro\Internet Security\PCClient.exe" [2004-05-22 20:48 634946]
"TM Outbreak Agent"="C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe" [2003-11-14 17:56 290816]
"SoundMan"="SOUNDMAN.EXE" [2004-05-14 14:47 67072 C:\WINDOWS\SOUNDMAN.EXE]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-04-21 09:03 98304]
"MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" [2006-04-22 18:07 190024]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2005-07-19 16:32 221184]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2005-06-08 14:24 458752]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2005-06-08 14:14 217088]
"Device Detector"="DevDetect.exe" []
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"!AVG Anti-Spyware"="C:\Documents and Settings\sonia\Bureau\anti spyware\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 15:09 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=MsgPlusLoader.dll
[HKLM\~\startupfolder\C:^Documents and Settings^sonia^Menu Démarrer^Programmes^Démarrage^Anti-Pub.lnk]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eMuleAutoStart]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\My Web Search Bar]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrojanScanner]
C:\Program Files\Trojan Remover\Trjscan.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\messenger\\msmsgs.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImLc.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncrediMail_Install.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Ares\\Ares.exe"=
"C:\\Program Files\\Freeplayer\\vlc\\vlc.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
R2 PccPfw;Trend Micro Personal Firewall;C:\Program Files\Trend Micro\Internet Security\PccPfw.exe [2003-11-14 18:01]
S3 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" [2007-11-29 14:28]
S3 fbxusb;Carte réseau virtuelle FreeBox USB;C:\WINDOWS\system32\DRIVERS\fbxusb32.sys [2004-10-20 13:23]
S3 PID_0920;Logitech QuickCam Express(PID_0920);C:\WINDOWS\system32\DRIVERS\LV532AV.SYS [2005-01-31 10:13]
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-01 13:27:09
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\Trend Micro\Internet Security\tmproxy.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-03-01 13:31:18 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-01 12:31:14
.
2008-02-27 21:56:17 --- E O F ---