Voila j'avais mal du le faire car la le rapport c'est afficher directement
ComboFix 08-08-10.02 - Dhondt 2008-08-12 1:27:46.2 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.643 [GMT 2:00]
Endroit: C:\Documents and Settings\Dhondt\Bureau\ComboFix.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Dhondt\Bureau\Vista Antivirus 2008.lnk
.
---- Previous Run -------
.
C:\Documents and Settings\Dhondt\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus-2008pro.lnk
C:\Documents and Settings\Dhondt\Application Data\ShoppingReport
C:\Documents and Settings\Dhondt\Application Data\ShoppingReport\cs\Config.xml
C:\Documents and Settings\Dhondt\Application Data\ShoppingReport\cs\db\Aliases.dbs
C:\Documents and Settings\Dhondt\Application Data\ShoppingReport\cs\db\Sites.dbs
C:\Documents and Settings\Dhondt\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
C:\Documents and Settings\Dhondt\Application Data\ShoppingReport\cs\report\aggr_storage.xml
C:\Documents and Settings\Dhondt\Application Data\ShoppingReport\cs\report\send_storage.xml
C:\Documents and Settings\Dhondt\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
C:\Documents and Settings\Dhondt\Menu Démarrer\Programmes\Antivirus 2008 PRO
C:\Documents and Settings\Dhondt\Menu Démarrer\Programmes\Antivirus 2008 PRO\antivirus-2008pro.lnk
C:\Program Files\Fichiers communs\drivecleaner free
C:\Program Files\PCHealthCenter
C:\Program Files\PCHealthCenter\[u]0/u.exe
C:\Program Files\PCHealthCenter\[u]0/u.gif
C:\Program Files\PCHealthCenter\1.exe
C:\Program Files\PCHealthCenter\1.gif
C:\Program Files\PCHealthCenter\2.exe
C:\Program Files\PCHealthCenter\2.gif
C:\Program Files\PCHealthCenter\3.exe
C:\Program Files\PCHealthCenter\3.gif
C:\Program Files\PCHealthCenter\4.exe
C:\Program Files\PCHealthCenter\5.exe
C:\Program Files\PCHealthCenter\7.exe
C:\Program Files\PCHealthCenter\sex1.ico
C:\Program Files\PCHealthCenter\sex2.ico
C:\Program Files\ShoppingReport
C:\Program Files\ShoppingReport\Uninst.exe
C:\WINDOWS\bgrqfetx.dll
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\emgo.exe
C:\WINDOWS\lnvegaow.exe
C:\WINDOWS\system32\sex2.ico
C:\WINDOWS\system32\tdssl.dll
C:\WINDOWS\system32\UpMedia
C:\WINDOWS\system32\vav.cpl
C:\WINDOWS\tfnslopk.dll
.
((((((((((((((((((((((((((((( Fichiers créés 2008-07-11 to 2008-08-11 ))))))))))))))))))))))))))))))))))))
.
2008-08-11 11:35 . 2008-08-11 11:36 <REP> d-------- C:\hijackthis
2008-08-11 11:13 . 2008-08-11 11:13 <REP> d-------- C:\Documents and Settings\Dhondt\SmitfraudFix
2008-08-11 11:02 . 2008-08-11 11:02 3,394 --a------ C:\WINDOWS\system32\tmp.reg
2008-08-11 11:01 . 2008-08-11 11:01 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-08-11 11:01 . 2008-08-11 11:01 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-08-11 11:01 . 2008-08-11 11:01 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-08-11 11:01 . 2008-08-11 11:01 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-08-11 11:01 . 2008-08-11 11:01 82,432 --a------ C:\WINDOWS\system32\IEDFix.C.exe
2008-08-11 11:01 . 2008-08-11 11:01 82,432 --a------ C:\WINDOWS\system32\404Fix.exe
2008-08-11 11:01 . 2008-08-11 11:01 53,248 --a------ C:\WINDOWS\system32\Process.exe
2008-08-11 11:01 . 2008-08-11 11:01 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-08-11 11:01 . 2008-08-11 11:01 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-08-11 01:54 . 2005-09-01 08:08 <REP> d--h----- C:\Documents and Settings\dhondt2\Voisinage réseau
2008-08-11 01:54 . 2005-09-01 08:08 <REP> d--h----- C:\Documents and Settings\dhondt2\Voisinage d'impression
2008-08-11 01:54 . 2005-09-01 08:08 <REP> d--h----- C:\Documents and Settings\dhondt2\Modèles
2008-08-11 01:54 . 2008-08-11 01:56 <REP> dr------- C:\Documents and Settings\dhondt2\Mes documents
2008-08-11 01:54 . 2005-09-01 08:08 <REP> dr------- C:\Documents and Settings\dhondt2\Menu Démarrer
2008-08-11 01:54 . 2008-08-11 01:54 <REP> dr------- C:\Documents and Settings\dhondt2\Favoris
2008-08-11 01:54 . 2008-08-11 01:54 <REP> d-------- C:\Documents and Settings\dhondt2\Bureau
2008-08-11 01:54 . 2006-02-15 13:49 <REP> d-------- C:\Documents and Settings\dhondt2\Application Data\You've Got Pictures Screensaver
2008-08-11 01:54 . 2008-08-11 01:54 <REP> d-------- C:\Documents and Settings\dhondt2\Application Data\Teleca
2008-08-11 01:54 . 2006-02-15 13:50 <REP> d-------- C:\Documents and Settings\dhondt2\Application Data\Corel
2008-08-11 01:53 . 2008-08-11 01:54 <REP> d-------- C:\Documents and Settings\dhondt2
2008-08-09 13:09 . 2008-08-09 13:09 <REP> d-------- C:\Program Files\Alwil Software
2008-07-18 20:39 . 2008-07-18 20:39 587,264 --a------ C:\WINDOWS\WLXPGSS.SCR
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-10 23:50 --------- d-----w C:\Program Files\Conduit
2008-08-10 23:49 --------- d-----w C:\Program Files\AVS4YOU
2008-08-10 23:46 --------- d-----w C:\Program Files\Fichiers communs\AVSMedia
2008-08-10 23:46 --------- d-----w C:\Program Files\AviSynth 2.5
2008-08-10 23:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-08-09 17:50 --------- d-----w C:\Program Files\Google
2008-08-09 16:49 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-08-09 16:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-08-09 16:31 --------- d-----w C:\Program Files\Symantec
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 247,808 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 10:44 138,368 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\dllcache\bthport.sys
2006-08-24 11:52 284 -c--a-w C:\Documents and Settings\Dhondt\Application Data\ViewerApp.dat
2006-04-25 20:05 251 -c--a-w C:\Program Files\wt3d.ini
2006-04-18 10:15 56 --sh--r C:\WINDOWS\system32\3FEB05FC58.sys
2006-04-18 19:24 56 -csh--r C:\WINDOWS\system32\739F51B0BA.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 14:00 15360]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 20:23 102400]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-03 20:48 68856]
"BitComet"="C:\Program Files\BitComet\BitComet.exe" [2008-03-25 08:38 2196280]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-03-20 18:46 217544]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-04-01 11:39 486856]
"SetDefaultMIDI"="MIDIDef.exe" [2004-12-22 19:40 24576 C:\WINDOWS\MIDIDEF.EXE]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" [2005-06-23 20:33 57344]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 16:17 159744]
"ISUSPM Startup"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" [2005-06-10 12:44 249856]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 00:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 14:00 15360]
"Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2008-02-26 03:23 443968]
C:\Documents and Settings\Dhondt\Menu D‚marrer\Programmes\D‚marrage\
Eurobarre.lnk - C:\Program Files\Eurobarre\eb.exe [2006-12-08 15:54:30 104960]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=MsgPlusLoader.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"MSVIDEO"= pctvcap.dll
"vidc.vixl"= miroxl32.dll
"VIDC.PIXL"= PCLEpixl.dll
"VIDC.PIM1"= PCLEPIM1.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Pinnacle\\Studio PCTV\\TeleText\\WebServer.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\BitComet\\BitComet.exe"=
"C:\\Power 3d Emulation\\Nesticle95FR\\NESTCL95.EXE"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"8750:TCP"= 8750:TCP:BitComet 8750 TCP
"8750:UDP"= 8750:UDP:BitComet 8750 UDP
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 16:35]
R1 pctvNT;Studio PCTV;C:\WINDOWS\system32\DRIVERS\pctvW2k.sys [2001-01-23 12:03]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 16:37]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 01:08]
S3 SaiH040C;SaiH040C;C:\WINDOWS\system32\DRIVERS\SaiH040C.sys [2005-07-07 14:10]
S3 SaiU040C;SaiU040C;C:\WINDOWS\system32\DRIVERS\SaiU040C.sys [2005-07-07 14:10]
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
2008-08-09 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 15:57]
2006-04-01 C:\WINDOWS\Tasks\Rappel d'abonnement 1 auprès de l'ISP.job
- C:\WINDOWS\system32\OOBE\oobebaln.exe [2004-08-10 14:00]
.
- - - - ORPHANS REMOVED - - - -
Toolbar-{8343A9DA-D2C6-46DC-AA55-CE9734B70905} - C:\WINDOWS\bgrqfetx.dll
HKCU-Run-IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
HKCU-Run-\Win54.exe - C:\Windows\system32\Win54.exe
HKCU-Run-\Win55.exe - C:\Windows\system32\Win55.exe
HKCU-Run-\Win56.exe - C:\Windows\system32\Win56.exe
HKCU-Run-\Win57.exe - C:\Windows\system32\Win57.exe
HKCU-Run-\Win58.exe - C:\Windows\system32\Win58.exe
HKLM-Run-NBKeyScan - C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
HKLM-Run-\Win54.exe - C:\Windows\system32\Win54.exe
HKLM-Run-\Win55.exe - C:\Windows\system32\Win55.exe
HKLM-Run-\Win56.exe - C:\Windows\system32\Win56.exe
HKLM-Run-\Win57.exe - C:\Windows\system32\Win57.exe
HKLM-Run-\Win58.exe - C:\Windows\system32\Win58.exe
HKLM-Run-Antivirus - C:\Program Files\VAV\vav.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Dhondt\Application Data\Mozilla\Firefox\Profiles\zgbtwau2.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://google.atcomet.com/b/
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://fr.msn.com/
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-12 01:30:14
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"\\Win54.exe"="C:\\Windows\\system32\\Win54.exe"
"\\Win55.exe"="C:\\Windows\\system32\\Win55.exe"
"\\Win56.exe"="C:\\Windows\\system32\\Win56.exe"
"\\Win57.exe"="C:\\Windows\\system32\\Win57.exe"
"\\Win58.exe"="C:\\Windows\\system32\\Win58.exe"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"\\Win54.exe"="C:\\Windows\\system32\\Win54.exe"
"\\Win55.exe"="C:\\Windows\\system32\\Win55.exe"
"\\Win56.exe"="C:\\Windows\\system32\\Win56.exe"
"\\Win57.exe"="C:\\Windows\\system32\\Win57.exe"
"\\Win58.exe"="C:\\Windows\\system32\\Win58.exe"
.
Temps d'accomplissement: 2008-08-12 1:31:31
ComboFix-quarantined-files.txt 2008-08-11 23:30:50
Pre-Run: 119,232,909,312 octets libres
Post-Run: 119,238,610,944 octets libres
221 --- E O F --- 2008-08-07 02:12:35