J'ai supprimé les fichiers infectés trouvés avec malware amis l'un des deux n'a pu etre supprimé qu'après le redémarrage de l'ordi.Voici le rapport de combofix.
ComboFix 08-09-27.06 - Propri‚taire 2008-09-29 12:47:43.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.689 [GMT 2:00]
Lancé depuis: C:\Documents and Settings\Propri‚taire\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Noémie\Cookies\noémie@ad.yieldmanager[1].txt
C:\Documents and Settings\Noémie\Cookies\noémie@serving-sys[1].txt
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-08-28 au 2008-09-29 ))))))))))))))))))))))))))))))))))))
.
2008-09-29 10:49 . 2008-09-29 11:53 <REP> d-------- C:\hijackthis
2008-09-29 10:45 . 2008-09-29 11:47 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-09-29 10:45 . <REP> C:\Documents and Settings\Propriétaire\Application Data\Malwarebytes
2008-09-29 10:45 . 2008-09-29 10:45 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-09-29 10:45 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-09-29 10:45 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-09-26 10:00 . 2008-09-26 10:01 <REP> d-------- C:\rsit
2008-09-26 10:00 . 2008-09-26 10:01 <REP> d-------- C:\Program Files\trend micro
2008-09-23 17:06 . <REP> C:\Documents and Settings\Propriétaire\Application Data\Apple Computer
2008-09-23 17:04 . 2008-09-23 17:04 <REP> d-------- C:\Program Files\QuickTime
2008-09-23 17:04 . 2008-09-23 17:04 <REP> d-------- C:\Program Files\Fichiers communs\Apple
2008-09-23 17:03 . 2008-09-23 17:03 <REP> d-------- C:\Program Files\Apple Software Update
2008-09-23 17:03 . 2008-09-23 17:03 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-09-23 17:03 . 2008-09-23 17:03 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-09-20 14:34 . 2008-09-20 14:34 244 --ah----- C:\sqmnoopt08.sqm
2008-09-20 14:34 . 2008-09-20 14:34 232 --ah----- C:\sqmdata08.sqm
2008-09-18 11:49 . 2008-09-18 11:49 244 --ah----- C:\sqmnoopt07.sqm
2008-09-18 11:49 . 2008-09-18 11:49 232 --ah----- C:\sqmdata07.sqm
2008-09-18 10:26 . 2008-09-18 10:26 244 --ah----- C:\sqmnoopt06.sqm
2008-09-18 10:26 . 2008-09-18 10:26 232 --ah----- C:\sqmdata06.sqm
2008-09-18 10:16 . 2008-09-18 10:16 <REP> d-------- C:\Program Files\Microsoft.NET
2008-09-18 10:15 . 2008-09-18 10:16 <REP> d-------- C:\WINDOWS\SHELLNEW
2008-09-17 13:57 . 2008-09-17 13:57 <REP> d-------- C:\WINDOWS\Sun
2008-09-17 09:58 . 2008-09-17 09:58 244 --ah----- C:\sqmnoopt05.sqm
2008-09-17 09:58 . 2008-09-17 09:58 232 --ah----- C:\sqmdata05.sqm
2008-09-16 14:57 . 2008-09-16 14:57 244 --ah----- C:\sqmnoopt04.sqm
2008-09-16 14:57 . 2008-09-16 14:57 232 --ah----- C:\sqmdata04.sqm
2008-09-16 09:43 . 2008-09-16 09:43 244 --ah----- C:\sqmnoopt03.sqm
2008-09-16 09:43 . 2008-09-16 09:43 232 --ah----- C:\sqmdata03.sqm
2008-09-06 15:09 . 2008-09-06 15:09 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
2008-09-06 15:09 . 2008-09-06 15:09 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
2008-09-01 21:23 . 2008-09-01 21:23 244 --ah----- C:\sqmnoopt02.sqm
2008-09-01 21:23 . 2008-09-01 21:23 232 --ah----- C:\sqmdata02.sqm
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-28 19:09 --------- d-----w C:\Documents and Settings\Noémie\Application Data\OpenOffice.org2
2008-09-27 21:16 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\LimeWire
2008-09-24 18:41 --------- d-----w C:\Documents and Settings\Noémie\Application Data\LimeWire
2008-09-12 10:16 --------- d-s---w C:\Documents and Settings\Noémie\Application Data\Microsoft
2008-09-10 16:08 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\OpenOffice.org2
2008-08-28 16:50 --------- d-s---w C:\Documents and Settings\Propriétaire\Application Data\Microsoft
2008-08-23 06:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-22 08:10 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-08-20 16:27 --------- d-----w C:\Documents and Settings\Noémie\Application Data\Adobe
2008-08-17 15:03 --------- d-----w C:\Documents and Settings\Noémie\Application Data\Sun
2008-08-16 15:02 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\CyberLink
2008-08-16 15:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
2008-08-03 15:43 5,632 ----a-w C:\WINDOWS\system32\drivers\StarOpen.sys
2008-08-03 12:40 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Ahead
2008-07-30 08:49 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Icone
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-15 10:13 81,984 ----a-w C:\WINDOWS\system32\bdod.bin
2008-07-07 20:28 253,952 ----a-w C:\WINDOWS\system32\es.dll
2004-10-01 13:00 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"PowerBar"="C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe" [2004-04-21 86016]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-23 68856]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2006-02-10 2048000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-01 7618560]
"SW20"="C:\WINDOWS\system32\sw20.exe" [2006-09-07 208896]
"SW24"="C:\WINDOWS\system32\sw24.exe" [2006-09-07 69632]
"RemoteControl"="C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
"InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2006-11-02 1397760]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
"nwiz"="nwiz.exe" [2006-06-01 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="NvMCTray.dll" [2006-06-01 C:\WINDOWS\system32\nvmctray.dll]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]
C:\Documents and Settings\No‚mie\Menu D‚marrer\Programmes\D‚marrage\
OpenOffice.org 2.3.lnk - C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe [2007-08-17 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R3 cm102u32;C-Media CM6501 Like Sound Interface;C:\WINDOWS\system32\drivers\c6501.sys [2006-07-11 1419776]
S3 SMCWGU(SMC);SMCWUSB-G 802.11g Wireless USB 2.0 Adapter(SMC);C:\WINDOWS\system32\DRIVERS\SMCWGU.sys [2005-12-16 408064]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{000327fe-7aaa-11dd-bebf-00138fcb80fd}]
\Shell\AutoRun\command - F:\EmDesk.exe
\Shell\EmDesk\command - F:\EmDesk.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2ac4ed3a-6d65-11dd-bea2-00138fcb80fd}]
\Shell\Auto\command - F:\Start.exe
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{77018b42-3872-11dd-8cf9-806d6172696f}]
\Shell\AutoRun\command - E:\Bin\assetup.exe
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Tâches planifiées'
.
- - - - ORPHELINS SUPPRIMES - - - -
HKLM-Run-C6501Sound - c6501.cpl
.
------- Examen supplémentaire -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.fr/
R0 -: HKCU-Main,Default_Search_URL = hxxp://www.google.com/ie
R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
O8 -: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-29 12:49:53
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2008-09-29 12:50:22
ComboFix-quarantined-files.txt 2008-09-29 10:50:20
Avant-CF: 52ÿ623ÿ568ÿ896 octets libres
Après-CF: 53,282,340,864 octets libres
157 --- E O F --- 2008-09-10 09:01:58