Re, voila je pense avoir réussi toutes les étapes, je te poste le rapport combo, si ça te parle lol. Moi ça me dis rien du tout, en tout cas merci de ton aide. A bientot bonne soirée.
ComboFix 08-03-18.1 - Léo_2 2008-03-19 21:51:39.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.199 [GMT 1:00]
Endroit: C:\Documents and Settings\Léo_2\Bureau\ComboFix.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
.
((((((((((((((((((((((((((((( Fichiers créés 2008-02-19 to 2008-03-19 ))))))))))))))))))))))))))))))))))))
.
2008-03-19 20:20 . 2008-03-19 20:20 <REP> d-------- C:\WINDOWS\LastGood
2008-03-16 21:30 . 2008-03-16 21:31 <REP> d-------- C:\Program Files\Windows Live Safety Center
2008-03-01 15:03 . 2008-03-01 15:03 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-03-01 15:03 . 2008-03-01 15:03 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-20 13:35 . 2008-02-20 13:44 <REP> d-------- C:\Program Files\PhotoFiltre
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-19 14:08 --------- d-----w C:\Program Files\eMule
2008-03-16 20:36 --------- d-----w C:\Program Files\TVAnts
2008-02-21 12:44 70,744 ----a-w C:\Documents and Settings\Léo_2\Application Data\GDIPFONTCACHEV1.DAT
2008-02-21 12:44 70,744 ----a-w C:\Documents and Settings\Léo_2\Application Data\GDIPFONTCACHEV1.DAT
2008-02-21 12:44 70,744 ----a-w C:\Documents and Settings\Léo_2\Application Data\GDIPFONTCACHEV1.DAT
2008-02-15 14:54 --------- d-----w C:\Documents and Settings\Léo_2\Application Data\NASA
2008-02-15 14:54 --------- d-----w C:\Documents and Settings\Léo_2\Application Data\NASA
2008-02-15 14:54 --------- d-----w C:\Documents and Settings\Léo_2\Application Data\NASA
2008-02-15 12:42 --------- d-----w C:\Program Files\Google
2008-02-15 11:24 --------- d-----w C:\Program Files\NASA
2008-02-09 19:32 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-09 19:21 --------- d-----w C:\Program Files\SopCast
2008-02-09 14:12 --------- d-----w C:\Documents and Settings\Léo_2\Application Data\SopCast
2008-02-09 14:12 --------- d-----w C:\Documents and Settings\Léo_2\Application Data\SopCast
2008-02-09 14:12 --------- d-----w C:\Documents and Settings\Léo_2\Application Data\SopCast
2008-02-02 19:23 --------- d-----w C:\Program Files\NCH Software
2008-02-02 19:17 --------- d-----w C:\Program Files\NCH Swift Sound
2008-02-02 19:17 --------- d-----w C:\Documents and Settings\Léo_2\Application Data\NCH Swift Sound
2008-02-02 19:17 --------- d-----w C:\Documents and Settings\Léo_2\Application Data\NCH Swift Sound
2008-02-02 19:17 --------- d-----w C:\Documents and Settings\Léo_2\Application Data\NCH Swift Sound
2008-02-02 19:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2007-10-25 11:29 5,632 -csha-w C:\Program Files\Thumbs.db
2007-06-10 19:48 1,163,592 -c--a-w C:\Program Files\install_flash_player.exe
2005-10-23 16:29 0 -c--a-w C:\Documents and Settings\Léo_2\Application Data\wklnhst.dat
2005-10-23 16:29 0 -c--a-w C:\Documents and Settings\Léo_2\Application Data\wklnhst.dat
2005-10-23 16:29 0 -c--a-w C:\Documents and Settings\Léo_2\Application Data\wklnhst.dat
2005-03-05 23:02 160,808,873 ----a-w C:\Program Files\AdobePhotoshopCS_Fr.zip
2005-01-19 22:58 1,256,444 ----a-w C:\Program Files\wrar342fr.exe
2005-01-19 22:56 7,741,336 ----a-w C:\Program Files\DivX521XP2K.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 08:59 204288]
"eMuleAutoStart"="C:\Program Files\eMule\emule.exe" [2007-05-13 15:57 5308416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"farstone"="" []
"RestoreIT!"="C:\Program Files\Phoenix Technologies Ltd\RecoverPro_XP\VBPTASK.exe" [2004-09-21 16:39 114688]
"Raccourci vers la page des propriétés de High Definition Audio"="HDAudPropShortcut.exe" [2004-03-17 16:10 61952 C:\WINDOWS\system32\Hdaudpropshortcut.exe]
"Cmaudio"="cmicnfg.cpl" []
"fenaffiche"="C:\Program Files\FenAffiche\Fenpowernet.exe" [2004-07-23 09:43 49152]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-12-15 12:01 5513216]
"nwiz"="nwiz.exe" [2004-12-15 12:01 1490944 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2004-12-15 12:01 86016]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2005-01-19 23:48 180269]
"AGRSMMSG"="AGRSMMSG.exe" [2004-04-13 12:49 88363 C:\WINDOWS\AGRSMMSG.exe]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-02-28 23:06 155648]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2005-09-16 07:43 274432]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
"AliceSAV"="C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe" [2005-12-16 16:57 81408]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 13:00 15360]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
WiFi Station.lnk - C:\Program Files\Hercules\WiFi Station\WifiStation.exe [2008-01-07 12:21:58 650240]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Eidos\\CM 03-04\\cm0304.exe"=
"C:\\WINDOWS\\system32\\rtcshare.exe"=
"C:\\Program Files\\NetMeeting\\conf.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\SopCast\\SopCast.exe"=
"C:\\Documents and Settings\\Léo_2\\Application Data\\SopCast\\adv\\SopAdver.exe"=
"C:\\Program Files\\TVAnts\\Tvants.exe"=
"C:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
R0 RITCPT;RITCPT;C:\WINDOWS\system32\drivers\RITCPT.sys [2004-09-21 16:39]
R0 VVBackd5;VVBackd5;C:\WINDOWS\system32\drivers\VVBackd5.sys [2004-09-21 16:39]
R2 FBAPI;FBAPI;C:\WINDOWS\system32\drivers\FBAPI.sys [2004-09-21 16:39]
R3 cmudax;C-Media High Definition Audio Interface;C:\WINDOWS\system32\drivers\cmudax.sys [2004-10-01 14:58]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 22:08]
S2 NISDRV;NISDRV;C:\WINDOWS\system32\Drivers\NISDRV.SYS []
S3 adiusbae;USB ADSL LAN Adapter;C:\WINDOWS\system32\DRIVERS\adiusbae.sys []
S3 fbxusb;FreeBox USB Network Adapter;C:\WINDOWS\system32\DRIVERS\fbxusb.sys [2003-12-31 11:35]
S3 PsShutdownSvc;PsShutdown;C:\WINDOWS\System32\PSSDNSVC.EXE [2004-12-20 14:20]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 21:58]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{40b3a35a-9a6e-11db-beeb-0008d30734e4}]
\Shell\AutoRun\command - G:\ta2.cmd
\Shell\explore\Command - G:\ta2.cmd
\Shell\open\Command - G:\ta2.cmd
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{779d738f-c5d8-11dc-81cd-0008d30734e4}]
\Shell\AutoRun\command - G:\22wcb21o.exe
\Shell\explore\Command - G:\22wcb21o.exe
\Shell\open\Command - G:\22wcb21o.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b9c5553b-53fe-11d9-aa3e-806d6172696f}]
\Shell\AutoRun\command - D:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ccba173b-5290-11d9-8ca1-806d6172696f}]
\Shell\AutoRun\command - D:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d171d1bb-5276-11d9-8426-806d6172696f}]
\Shell\AutoRun\command - D:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e43cd43b-527f-11d9-aee6-806d6172696f}]
\Shell\AutoRun\command - D:\setup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f6bc98c8-13fb-11da-bae4-0007cb0000ff}]
\Shell\AutoRun\command - G:\cayfq2.cmd
\Shell\explore\Command - G:\cayfq2.cmd
\Shell\open\Command - G:\cayfq2.cmd
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-03-19 20:50:00 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDetect.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-03-19 21:54:19
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
AliceSAV = C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-03-19 21:54:47
ComboFix-quarantined-files.txt 2008-03-19 20:54:45
.
2008-03-12 11:25:42 --- E O F ---