oui j ai fait la 3eme partie smitfraudfix j ai meme collé le rapport
voici le rapport combofix
ComboFix 08-03-14.4 - geoffrey 2008-03-16 22:15:03.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.206 [GMT 1:00]
Endroit: C:\Documents and Settings\geoffrey \Bureau\Combo-Fix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS.0\system32\efaddffebfe_g.dll
.
((((((((((((((((((((((((((((( Fichiers créés 2008-02-16 to 2008-03-16 ))))))))))))))))))))))))))))))))))))
.
2008-03-16 21:20 . 2008-03-16 21:20 <REP> d-------- C:\Program Files\Trend Micro
2008-03-16 18:14 . 2008-03-16 18:14 9,061,589 --a------ C:\upload_moi_PERSONNE-BZQUFV.tar.gz
2008-03-15 18:14 . 2008-03-15 18:14 <REP> d-------- C:\Documents and Settings\geoffrey loreto\DoctorWeb
2008-03-14 01:51 . 2007-06-05 10:56 44,928 --a------ C:\WINDOWS.0\system32\drivers\SDTHOOK.SYS
2008-03-13 23:46 . 2008-03-13 23:46 <REP> d-------- C:\Program Files\ClearProg
2008-03-13 22:17 . 2008-03-13 22:17 <REP> d-------- C:\Program Files\Lavasoft
2008-03-13 22:17 . 2008-03-13 22:17 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2008-03-13 22:17 . 2008-03-13 22:18 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-12 23:11 . 2008-03-13 21:04 <REP> d-------- C:\Documents and Settings\Administrateur\Modèles
2008-03-12 23:11 . 2008-03-12 23:11 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Sony Ericsson
2008-03-06 23:00 . 2008-03-14 00:09 <REP> d-------- C:\Program Files\SpywareBlaster
2008-03-06 01:02 . 2008-03-06 01:02 <REP> d-------- C:\fsaua.data
2008-03-05 23:30 . 2008-03-14 19:39 <REP> d-------- C:\WINDOWS.0\system32\ActiveScan
2008-03-05 23:30 . 2008-03-14 01:47 30,590 --a------ C:\WINDOWS.0\system32\pavas.ico
2008-03-05 22:04 . 2008-03-05 22:04 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-05 22:00 . 2006-09-05 17:03 3,968 --a------ C:\WINDOWS.0\system32\drivers\AvgAsCln.sys
2008-03-05 21:56 . 2008-03-05 21:56 <REP> d--hs---- C:\found.002
2008-03-05 01:35 . 2008-03-05 01:35 <REP> d--h----- C:\WINDOWS.0\PIF
2008-03-04 23:24 . 2008-03-14 02:58 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-03-04 21:39 . 2008-03-14 00:27 466,852 --a------ C:\WINDOWS.0\system32\perfh040.dat
2008-03-04 21:39 . 2008-03-14 00:27 73,750 --a------ C:\WINDOWS.0\system32\perfc040.dat
2008-03-04 21:14 . 2008-03-04 21:14 23 --a------ C:\WINDOWS.0\system32\ccbbcaee_g.ocx
2008-02-28 23:22 . 2008-02-28 23:22 <REP> d-------- C:\Documents and Settings\geoffrey \Application Data\vlc
2008-02-28 23:21 . 2008-02-28 23:21 <REP> d-------- C:\Program Files\VideoLAN
2008-02-28 22:50 . 2008-02-28 22:50 <REP> d-------- C:\Program Files\Java
2008-02-28 22:50 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS.0\system32\javacpl.cpl
2008-02-28 22:49 . 2008-02-28 22:49 <REP> d-------- C:\Program Files\Fichiers communs\Java
2008-02-28 22:44 . 2008-02-28 22:44 <REP> d-------- C:\Program Files\CCleaner
2008-02-17 14:01 . 2008-02-17 15:06 820 --a------ C:\WINDOWS.0\eReg.dat
2008-02-17 13:50 . 2008-02-17 13:52 <REP> d-------- C:\Program Files\Maxis
2008-02-17 13:27 . 2008-02-17 13:27 <REP> d-------- C:\Program Files\Microsoft Games
2008-02-16 15:03 . 2006-11-30 15:12 18,704 -ra------ C:\WINDOWS.0\system32\drivers\se57nd5.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-14 02:00 --------- d-----w C:\Program Files\Windows Defender
2008-03-14 01:19 --------- d-----w C:\Program Files\a-squared Free
2008-03-14 00:52 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-05 23:33 --------- d-----w C:\Program Files\Fichiers communs\Teleca Shared
2008-03-05 23:33 --------- d-----w C:\Program Files\Fichiers communs\Sony Ericsson Shared
2008-03-05 22:54 --------- d-----w C:\Program Files\MSN Messenger
2008-03-04 22:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-28 21:42 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-28 20:42 --------- d-----w C:\Program Files\Fichiers communs\Ahead
2008-02-11 16:37 --------- d-----w C:\Documents and Settings\geoffrey loreto\Application Data\AdobeUM
2008-02-09 00:34 --------- d-----w C:\Documents and Settings\geoffrey loreto\Application Data\TeamViewer
2008-02-09 00:32 --------- d-----w C:\Program Files\TeamViewer3
2008-02-05 22:25 --------- d-----w C:\Program Files\Avira
2008-02-05 22:25 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
2008-02-05 22:08 --------- d-----w C:\Program Files\CleanUp!
2008-02-05 22:07 --------- d-----w C:\Program Files\ToniArts
2008-02-03 00:21 --------- d-----w C:\Program Files\Fichiers communs\Blizzard Entertainment
2008-02-02 21:38 --------- d-----w C:\Program Files\Fichiers communs\BitDefender
2008-01-31 22:53 77,824 ----atw C:\WINDOWS.0\system32\DRWEBSP.DLL
2008-01-31 22:52 --------- d-----w C:\Documents and Settings\geoffrey loreto\Application Data\InstallShield
2008-01-31 20:29 --------- d-----w C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-28 21:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-01-28 19:38 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-01-27 22:30 --------- d-----w C:\Program Files\Stardock
2008-01-27 22:21 --------- d-----w C:\Program Files\Skype
2008-01-27 22:19 --------- d-----w C:\Program Files\Logitech
2008-01-27 17:03 --------- d-----w C:\Documents and Settings\geoffrey \Application Data\Teleca
2008-01-27 16:56 --------- d-----w C:\Documents and Settings\geoffrey \Application Data\Sony Ericsson
2008-01-27 16:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Teleca
2008-01-27 16:36 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sony Ericsson
2008-01-27 16:35 --------- d-----w C:\Program Files\Sony Ericsson
2001-11-23 04:08 712,704 -c--a-w C:\WINDOWS.0\inf\OTHER\AUDIO3D.DLL
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS.0\system32\ctfmon.exe" [2004-08-19 16:09 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-05 23:27 249896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS.0\System32\CTFMON.EXE" [2004-08-19 16:09 15360]
"DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2007-03-22 19:29 39264]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"UIHost"="LogonUI.EXE"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Accélérateur de démarrage AutoCAD.lnk]
backup=C:\WINDOWS.0\pss\Accélérateur de démarrage AutoCAD.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
backup=C:\WINDOWS.0\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Pack Sécurité.lnk]
backup=C:\WINDOWS.0\pss\Pack Sécurité.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
--a------ 2008-03-05 22:01 6731312 C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-19 16:09 15360 C:\WINDOWS.0\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\F-Secure Startup Wizard]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\F-Secure TNB]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 17:24 1694208 C:\PROGRA~1\MESSEN~1\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite]
-ra------ 2006-11-24 01:06 487424 C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 01:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2006-11-03 17:20 866584 C:\Program Files\Windows Defender\MSASCui.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\Microsoft Games\\Age of Empires II\\EMPIRES2.ICD"=
S3 MEMSWEEP2;MEMSWEEP2;C:\WINDOWS.0\system32\A8C.tmp []
S3 se57bus;Sony Ericsson Device 087 driver (WDM);C:\WINDOWS.0\system32\DRIVERS\se57bus.sys [2006-11-30 15:12]
S3 se57mdfl;Sony Ericsson Device 087 USB WMC Modem Filter;C:\WINDOWS.0\system32\DRIVERS\se57mdfl.sys [2006-11-30 15:12]
S3 se57mdm;Sony Ericsson Device 087 USB WMC Modem Driver;C:\WINDOWS.0\system32\DRIVERS\se57mdm.sys [2006-11-30 15:12]
S3 se57mgmt;Sony Ericsson Device 087 USB WMC Device Management Drivers (WDM);C:\WINDOWS.0\system32\DRIVERS\se57mgmt.sys [2006-11-30 15:12]
S3 se57nd5;Sony Ericsson Device 087 USB Ethernet Emulation SEMC57 (NDIS);C:\WINDOWS.0\system32\DRIVERS\se57nd5.sys [2006-11-30 15:12]
S3 se57obex;Sony Ericsson Device 087 USB WMC OBEX Interface;C:\WINDOWS.0\system32\DRIVERS\se57obex.sys [2006-11-30 15:12]
S3 se57unic;Sony Ericsson Device 087 USB Ethernet Emulation SEMC57 (WDM);C:\WINDOWS.0\system32\DRIVERS\se57unic.sys [2006-11-30 15:12]
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2007-04-02 16:04:01 C:\WINDOWS.0\Tasks\MP Scheduled Quick Scan.job"
- C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MpCmdRun.exe%Scan -RestrictPrivileges -ScanType 1
"2008-03-16 20:55:11 C:\WINDOWS.0\Tasks\MP Scheduled Scan.job"
- C:\Program Files\Windows Defender\MpCmdRun.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-16 22:17:16
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MEMSWEEP2]
"ImagePath"="\??\C:\WINDOWS.0\system32\A8C.tmp"
.
Temps d'accomplissement: 2008-03-16 22:18:01
ComboFix-quarantined-files.txt 2008-03-16 21:17:51
.
2008-03-16 02:19:43 --- E O F ---
***************************
et voici le rapport AVGAS
--------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 23:32:51 16/03/2008
+ Résultat de l'analyse:
C:\System Volume Information\_restore{FF9ACA80-5664-4D7B-94E7-A6FCE1F71AFC}\RP21\A0005643.EXE -> Heuristic.Win32.AVKiller : Nettoyé et sauvegardé (mise en quarantaine).
C:\Documents and Settings\geoffrey loreto\Cookies\geoffrey_loreto@weborama[2].txt -> TrackingCookie.Weborama : Nettoyé.
Fin du rapport
***********************************
voici le rapport de a-squared free
Version - a-squared Free 3.1
Dernière mise à jour: 16/03/2008 22:37:54
Réglages Scan:
Objets: Mémoire, Traces, Cookies, C:\WINDOWS.0\, C:\Program Files
Scan archives: Marche
Heuristiques: Marche
Scan ADS: Marche
Début du scan: 16/03/2008 22:38:38
Key: HKEY_USERS\S-1-5-21-527237240-1482476501-725345543-1004\software\kazaa Détecter: Trace.Registry.KaZaA
C:\Documents and Settings\geoffrey loreto\Cookies\geoffrey_loreto@commentcamarche[1].txt Détecter: Trace.TrackingCookie
C:\Documents and Settings\geoffrey loreto\Cookies\geoffrey_loreto@weborama[2].txt Détecter: Trace.TrackingCookie
Scanné
Fichiers: 58726
Traces: 384922
Cookies: 22
Processus: 29
Trouver
Fichiers: 0
Traces: 1
Cookies: 2
Processus: 0
Clés de Registre: 0
Fin du Scan: 16/03/2008 23:44:49
Temps du Scan: 1:06:11
C:\Documents and Settings\geoffrey loreto\Cookies\geoffrey_loreto@commentcamarche[1].txt Supprimé Trace.TrackingCookie
C:\Documents and Settings\geoffrey loreto\Cookies\geoffrey_loreto@weborama[2].txt Supprimé Trace.TrackingCookie
Key: HKEY_USERS\S-1-5-21-527237240-1482476501-725345543-1004\software\kazaa Supprimé Trace.Registry.KaZaA
Supprimé
Fichiers: 0
Traces: 1
Cookies: 2