Et voici la suite, je voulais te préciser que j'ai la pile de l'horloge de mon pc qui est morte (je rerègle l'horloge à chaque fois) je ne sais pas si cela peut changer quelque chose. Sinon je voulais savoir si tu pouvais me conseiller un anti-virus et un anti-spyware gratuit?
Merci beaucoup ;)
Jeremy
ComboFix 08-05-21.3 - jay 2008-05-24 19:38:32.3 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.261 [GMT 2:00]
Endroit: C:\Documents and Settings\jay\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\jay\Bureau\CFScript.txt
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
FILE ::
C:\WINDOWS\system32\drivers\lrjcxkfc.sys
C:\WINDOWS\system32\y567x.exe
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_LRJCXKFC
-------\Service_lrjcxkfc
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-04-24 to 2008-05-24 ))))))))))))))))))))))))))))))))))))
.
2008-05-20 23:16 . 2002-01-01 00:00 <REP> d-------- C:\Program Files\Fichiers communs\Motive
2008-05-16 01:02 . 2002-01-01 00:06 <REP> d--h----- C:\$AVG8.VAULT$
2008-05-13 18:45 . 2008-05-13 18:45 <REP> d-------- C:\Program Files\CCleaner
2008-05-13 17:25 . 2008-05-13 17:25 1,160 --a------ C:\WINDOWS\mozver.dat
2008-05-13 17:17 . 2008-05-13 17:17 0 --a------ C:\WINDOWS\nsreg.dat
2008-05-06 23:25 . 2008-05-20 23:18 <REP> d-------- C:\Program Files\QuickHelp2
2008-05-03 07:17 . 2008-05-13 18:18 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-05-03 07:17 . 2008-05-03 07:17 1,409 --a------ C:\WINDOWS\QTFont.for
2008-05-03 06:32 . 2002-01-01 02:10 <REP> d-------- C:\Program Files\Fichiers communs\Mozilla Shared
2008-05-03 06:32 . 2008-05-03 06:32 1,015,808 --a------ C:\WINDOWS\system32\libeay32.dll
2008-05-03 06:32 . 2008-05-03 06:32 196,608 --a------ C:\WINDOWS\system32\libssl32.dll
2008-05-03 06:28 . 2008-05-03 06:28 <REP> d-------- C:\Program Files\Lavasoft
2008-05-03 06:28 . 2008-05-03 06:30 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-05-03 06:27 . 2008-05-03 06:27 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-24 17:42 65,536 ----a-w C:\WINDOWS\system32\drivers\CnxE2FS.bin
2008-05-20 21:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Motive
2008-05-20 21:18 --------- d-----w C:\Documents and Settings\jay\Application Data\Motive
2008-05-20 21:16 --------- d-----w C:\Program Files\Winamp
2008-05-20 21:16 --------- d-----w C:\Program Files\QuickTime
2008-05-20 21:16 --------- d-----w C:\Program Files\Navilog1
2008-05-20 21:16 --------- d-----w C:\Program Files\DivX
2008-05-20 21:16 --------- d-----w C:\Program Files\Ahead
2008-05-15 23:01 --------- d-----w C:\Documents and Settings\jay\Application Data\AVGTOOLBAR
2008-05-03 04:25 --------- d-----w C:\Program Files\Nokia
2008-05-03 04:23 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-05-03 04:22 --------- d-----w C:\Documents and Settings\jay\Application Data\Lavasoft
2007-12-16 22:42 18,620,376 ----a-w C:\Program Files\Avast français.exe
2007-12-16 22:32 210,416 ----a-w C:\Program Files\zaavSetup_fr.exe
2007-06-09 05:25 6,221,304 ----a-w C:\Program Files\winamp535_full_emusic-7plus.exe
2007-02-21 01:11 17,929,072 ----a-w C:\Program Files\Install_Messenger.exe
2007-01-28 20:23 206,602,104 ----a-w C:\Program Files\Nero-7.7.5.1_fra_trialbis.exe
2007-01-20 17:37 19,666,504 ----a-w C:\Program Files\QuickTimeInstaller.exe
2006-12-05 20:24 1,035,271 ----a-w C:\Program Files\winrar362.exe
2006-10-25 20:47 15,926,792 ----a-w C:\Program Files\DivXPlay.exe
2006-06-11 23:12 9,393,352 ----a-w C:\Program Files\Install_MSN_Messenger.EXE
2006-06-11 23:08 8,282,187 ----a-w C:\Program Files\vlc-0.8.5-win32.exe
.
((((((((((((((((((((((((((((( snapshot@2008-05-23_12.28.15.65 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-23 10:24:46 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-24 17:41:25 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-16 00:24:43 1,152,888 ----a-w C:\WINDOWS\system32\aswBoot.exe
+ 2008-05-16 00:12:36 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
+ 2008-05-16 00:13:26 26,944 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
- 2008-03-29 18:35:49 20,560 ----a-w C:\WINDOWS\system32\drivers\aswFsBlk.sys
+ 2008-05-16 00:16:06 20,560 ----a-w C:\WINDOWS\system32\drivers\aswFsBlk.sys
+ 2008-01-17 17:34:01 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
+ 2008-05-16 00:18:33 94,416 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
+ 2008-05-16 00:15:29 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
- 2008-03-29 18:31:34 75,856 ----a-w C:\WINDOWS\system32\drivers\aswSP.sys
+ 2008-05-16 00:20:32 78,416 ----a-w C:\WINDOWS\system32\drivers\aswSP.sys
+ 2008-05-16 00:14:11 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
- 2008-05-23 10:23:00 40,128 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2002-01-01 04:35:56 40,128 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-05-23 10:23:00 48,856 ----a-w C:\WINDOWS\system32\perfc00C.dat
+ 2002-01-01 04:35:56 48,856 ----a-w C:\WINDOWS\system32\perfc00C.dat
- 2008-05-23 10:23:00 311,740 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2002-01-01 04:35:56 311,740 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2008-05-23 10:23:00 368,076 ----a-w C:\WINDOWS\system32\perfh00C.dat
+ 2002-01-01 04:35:56 368,076 ----a-w C:\WINDOWS\system32\perfh00C.dat
+ 2008-05-24 17:41:48 16,384 ----atw C:\WINDOWS\TEMP\Perflib_Perfdata_524.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 18:09 15360]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 13:55 5674352]
"BlazeServoTool"="C:\Program Files\BlazeVideo\BlazeDVD 5 Standard\MediaDetector.exe" [ ]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [ ]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [ ]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2005-08-09 15:28 1961984]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" [ ]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\Smtray.exe" [2002-06-26 18:36 90112]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 16:57 282624]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-12-20 17:16 37376]
"QuickHelp2_McciTrayApp"="C:\Program Files\QuickHelp2\QuickHelp.exe" [2007-11-02 17:40 1474048]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-19 18:09 15360]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [ ]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 02:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 02:16]
R2 McciCMService;McciCMService;"C:\Program Files\Fichiers communs\Motive\McciCMService.exe" [2007-09-10 10:19]
S3 MREMP50;MREMP50 NDIS Protocol Driver;C:\PROGRA~1\FICHIE~1\Motive\MREMP50.SYS [2007-07-10 18:37]
S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver;C:\PROGRA~1\FICHIE~1\Motive\MREMP50a64.SYS []
S3 MRESP50;MRESP50 NDIS Protocol Driver;C:\PROGRA~1\FICHIE~1\Motive\MRESP50.SYS [2007-07-10 18:37]
S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver;C:\PROGRA~1\FICHIE~1\Motive\MRESP50a64.SYS []
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
wtoqxing
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-04-22 18:25:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-05-24 19:42:12
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\QuickHelp2\QuickHelpBrowser.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-05-24 19:45:03 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-24 17:44:58
ComboFix2.txt 2008-05-23 20:20:11
ComboFix3.txt 2008-05-23 10:28:41
Pre-Run: 223,760,384 octets libres
Post-Run: 222,535,680 octets libres
156 --- E O F --- 2008-05-14 10:17:21
LOG HIJACK THIS
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:48:18, on 24.05.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Fichiers communs\Motive\McciCMService.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\QuickHelp2\QuickHelp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\jay\Bureau\NETTOYAGE VIRUS\HiJackThis.exe
C:\WINDOWS\system32\wuauclt.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.bluewin.ch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\ANTIVIRUS\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [QuickHelp2_McciTrayApp] C:\Program Files\QuickHelp2\QuickHelp.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BlazeServoTool] "C:\Program Files\BlazeVideo\BlazeDVD 5 Standard\MediaDetector.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) -
http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) -
http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) -
http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) -
http://upload.facebook.com/controls/FacebookPhotoUploader4_5.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: hpdj - Unknown owner - C:\DOCUME~1\jay\LOCALS~1\Temp\hpdj.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Fichiers communs\Motive\McciCMService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe