Salut verni j'etais tres contante quand j'ai lue ton message. je vient de rentré a la maison car j'ai travaillé aujourd'hui. j'ai fait ce que tu ma demandé . je te remerci
ComboFix 08-08-19.06 - s 2008-08-21 19:49:35.1 - [color=red][b]FAT32/b/colorx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.112 [GMT 2:00]
Endroit: C:\Documents and Settings\s\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\s\Application Data\macromedia\Flash Player\#SharedObjects\94E93H9K\static.youku.com
C:\Documents and Settings\s\Application Data\macromedia\Flash Player\#SharedObjects\94E93H9K\static.youku.com\v1.0.0243\v\swf\qplayer.swf\qplayer.sol
C:\Documents and Settings\s\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.youku.com
C:\Documents and Settings\s\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#static.youku.com\settings.sol
C:\WINDOWS\system32\Cfx32.lic
C:\WINDOWS\system32\cfx32.ocx
.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-07-21 to 2008-08-21 ))))))))))))))))))))))))))))))))))))
.
2008-08-20 21:21 . 2008-08-20 21:21 <REP> d-------- C:\Program Files\Navilog1
2008-08-20 21:07 . 2008-08-20 21:07 <REP> d-------- C:\Program Files\Trend Micro
2008-08-20 19:28 . 2008-08-20 19:28 268 --ah----- C:\sqmdata09.sqm
2008-08-20 19:28 . 2008-08-20 19:28 244 --ah----- C:\sqmnoopt09.sqm
2008-08-20 19:24 . 2008-08-20 19:24 244 --ah----- C:\sqmnoopt07.sqm
2008-08-20 19:24 . 2008-08-20 19:24 232 --ah----- C:\sqmdata07.sqm
2008-08-20 19:24 . 2008-08-20 19:24 208 --ah----- C:\sqmdata08.sqm
2008-08-20 19:24 . 2008-08-20 19:24 172 --ah----- C:\sqmnoopt08.sqm
2008-08-20 14:45 . 2008-08-20 14:45 268 --ah----- C:\sqmdata06.sqm
2008-08-20 14:45 . 2008-08-20 14:45 244 --ah----- C:\sqmnoopt06.sqm
2008-08-19 21:59 . 2008-08-19 21:59 244 --ah----- C:\sqmnoopt05.sqm
2008-08-19 21:59 . 2008-08-19 21:59 232 --ah----- C:\sqmdata05.sqm
2008-08-13 22:26 . 2008-08-13 22:26 <REP> d-------- C:\Program Files\JPEG Camera
2008-08-07 00:19 . 2008-08-07 00:19 <REP> d-------- C:\Program Files\Fichiers communs\xing shared
2008-08-04 23:09 . 2008-08-04 23:09 268 --ah----- C:\sqmdata04.sqm
2008-08-04 23:09 . 2008-08-04 23:09 244 --ah----- C:\sqmnoopt04.sqm
2008-08-04 04:07 . 2008-08-04 04:07 <REP> d-------- C:\Program Files\oovooToolbar
2008-08-04 04:07 . 2008-08-04 04:07 <REP> d-------- C:\Program Files\ooVoo
2008-08-04 04:07 . 2008-08-04 04:07 <REP> d-------- C:\Documents and Settings\s\Application Data\oovooToolbar
2008-08-04 04:07 . 2008-08-04 04:07 <REP> d-------- C:\Documents and Settings\s\Application Data\ooVoo Details
2008-08-01 23:36 . 2008-08-01 23:36 <REP> d-------- C:\Program Files\Shareaza
2008-08-01 23:36 . 2008-08-01 23:36 <REP> d-------- C:\Documents and Settings\s\Application Data\Shareaza
2008-07-26 17:11 . 2008-07-26 17:11 <REP> d--hs---- C:\FOUND.022
2008-07-25 07:38 . 2008-07-25 07:38 <REP> d-------- C:\Program Files\Bandoo
2008-07-25 07:38 . 2008-07-25 07:38 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Bandoo
2008-07-21 21:32 . 2008-07-21 21:32 268 --ah----- C:\sqmdata03.sqm
2008-07-21 21:32 . 2008-07-21 21:32 244 --ah----- C:\sqmnoopt03.sqm
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-06 22:18 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-07-18 18:39 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
2008-07-14 20:36 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-07-14 20:36 --------- d-----w C:\Documents and Settings\s\Application Data\InterTrust
2008-07-09 17:52 --------- d-----w C:\Program Files\Avira
2008-07-09 17:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Avira
2008-07-07 20:31 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-07-07 20:31 253,952 ----a-w C:\WINDOWS\system32\dllcache\es.dll
2008-07-02 18:16 --------- d-----w C:\Documents and Settings\s\Application Data\Windows Live Writer
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\dllcache\mscms.dll
2008-06-23 15:39 152,064 ----a-w C:\WINDOWS\system32\dllcache\cdfview.dll
2008-06-23 15:39 1,024,000 ----a-w C:\WINDOWS\system32\dllcache\browseui.dll
2008-06-23 09:49 18,432 ----a-w C:\WINDOWS\system32\dllcache\iedw.exe
2008-06-20 20:37 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\dllcache\mswsock.dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\dllcache\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\dllcache\bthport.sys
1999-04-30 14:00 98,304 ------w C:\Program Files\internet explorer\plugins\UPjpeg.dll
2003-01-13 08:55 282,624 ------w C:\Program Files\internet explorer\plugins\PanoViewer.dll
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A057A204-BACC-4D26-8087-36EE87E26986}]
2008-07-29 21:56 1987544 --a------ C:\PROGRA~1\OOVOOT~1\OOVOOT~1.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-8087-36EE87E26986}"= "C:\PROGRA~1\OOVOOT~1\OOVOOT~1.DLL" [2008-07-29 21:56 1987544]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-8087-36ee87e26986}]
[HKEY_CLASSES_ROOT\oovooToolbar.OOVOOTOOLBAR]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{A057A204-BACC-4D26-8087-36EE87E26986}"= "C:\PROGRA~1\OOVOOT~1\OOVOOT~1.DLL" [2008-07-29 21:56 1987544]
[HKEY_CLASSES_ROOT\clsid\{a057a204-bacc-4d26-8087-36ee87e26986}]
[HKEY_CLASSES_ROOT\oovooToolbar.OOVOOTOOLBAR]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2006-06-01 13:32 94208]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:54 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-05-19 00:27 68856]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-04-23 17:45 22058792]
"Shareaza"="C:\Program Files\Shareaza\Shareaza.exe" [2008-01-01 17:49 4739072]
"oovoo.exe"="C:\Program Files\ooVoo\oovoo.exe" [2008-07-31 13:54 13494064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HDAudDeck"="C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe" [2007-06-29 10:51 811008]
"NeroFilterCheck"="C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40 155648]
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-08-07 00:18 185896]
"VTTimer"="VTTimer.exe" [2006-09-21 09:36 53248 C:\WINDOWS\system32\VTTimer.exe]
"S3Trayp"="S3trayp.exe" [2007-06-11 04:15 176128 C:\WINDOWS\system32\S3Trayp.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 04:54 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.dvacm"= C:\PROGRA~1\FICHIE~1\ULEADS~1\Vio\Dvacm.acm
"msacm.MPEGacm"= C:\PROGRA~1\FICHIE~1\ULEADS~1\MPEG\MPEGacm.acm
"msacm.ulmp3acm"= C:\PROGRA~1\FICHIE~1\ULEADS~1\MPEG\ulmp3acm.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"=
"C:\\Program Files\\VIA\\VIAudioi\\HDADeck\\HDeck.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Shareaza\\Shareaza.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:TCP port 443 ooVoo
"443:UDP"= 443:UDP:UDP port 443 ooVoo
"37674:TCP"= 37674:TCP:TCP port 37674 ooVoo
"37674:UDP"= 37674:UDP:UDP port 37674 ooVoo
"37675:UDP"= 37675:UDP:UDP port 37675 ooVoo
R0 ViBus;ViBus;C:\WINDOWS\system32\DRIVERS\ViBus.sys [2007-03-26 08:26]
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2007-03-29 04:36]
R0 ViPrt;VIA SATA IDE Device Driver;C:\WINDOWS\system32\DRIVERS\ViPrt.sys [2007-03-26 08:26]
R2 Bandoo Coordinator;Bandoo Coordinator;C:\PROGRA~1\BANDOO\BANDOO.EXE [2008-06-26 18:31]
R3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys [2007-04-17 04:58]
R3 S3GIGP;S3GIGP;C:\WINDOWS\system32\DRIVERS\S3gIGPm.sys [2007-07-11 06:08]
S3 Boonty Games;Boonty Games;C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe [2008-06-10 19:29]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{63afec7e-2325-11dd-a85c-001bb9dd327a}]
\Shell\AutoRun\command - H:\AutoRun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{69cbde64-4ddd-11dd-a8d9-001bb9dd327a}]
\Shell\AutoRun\command - H:\jiwsxh39.exe
\Shell\explore\Command - H:\jiwsxh39.exe
\Shell\open\Command - H:\jiwsxh39.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{69cbde68-4ddd-11dd-a8d9-001bb9dd327a}]
\Shell\AutoRun\command - jiwsxh39.exe
\Shell\explore\Command - jiwsxh39.exe
\Shell\open\Command - jiwsxh39.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6e607c1e-2a88-11dd-a876-001bb9dd327a}]
\Shell\AutoRun\command - H:\jiwsxh39.exe
\Shell\explore\Command - H:\jiwsxh39.exe
\Shell\open\Command - H:\jiwsxh39.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e0385dcc-21d0-11dd-a855-001bb9dd327a}]
\Shell\AutoRun\command - H:\AutoRun.exe
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-NWEReboot - (no file)
HKLM-Explorer_Run-SALIM-72DD69EB2 - .vbe
Notify-WgaLogon - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\s\Application Data\Mozilla\Firefox\Profiles\7caefocb.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-21 19:53:35
Windows 5.1.2600 Service Pack 2 FAT NTAPI
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
--------------------- DLLs a charg‚ sous des processus courants ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> ?:\WINDOWS\System32\CSCDLL.dll
.
------------------------ Other Running Processes ------------------------
.
C:\PROGRAM FILES\AVIRA\ANTIVIR PERSONALEDITION CLASSIC\SCHED.EXE
C:\PROGRAM FILES\AVIRA\ANTIVIR PERSONALEDITION CLASSIC\AVGUARD.EXE
C:\PROGRAM FILES\BANDOO\BANDOO.EXE
C:\PROGRAM FILES\BANDOO\BANDOOUI.EXE
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-08-21 19:55:20 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-21 17:55:16
Pre-Run: 10,204,332,032 octets libres
Post-Run: 10,162,257,920 octets libres
191 --- E O F --- 2008-08-16 23:40:17