Salut jlpjlp
voici le rapport de combofix. Auparavant, j'ai une question au sujet d'avast anti-virus. Je l'ai désactivé poue ComboFix, maintenant, il apparaît activé dans le centre de sécurité de W$ mais il n'est plus dans la barre de tâche. Comment être sur que la protection résidente est active. D'autre part aurais-tu un conseil à me donner pour choisir un bon AV.
Le rapport :
ComboFix 08-11-21.04 - client 2008-11-22 8:11:52.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.484 [GMT 1:00]
Lancé depuis: c:\documents and settings\client\Bureau\ComboFix.exe
* Un nouveau point de restauration a été créé
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\uninstall.exe
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TDSSSERV.SYS
((((((((((((((((((((((((((((( Fichiers créés du 2008-10-22 au 2008-11-22 ))))))))))))))))))))))))))))))))))))
.
2729-04-08 00:35 . 2729-04-08 00:35 3,120 --a--c--- c:\windows\MF_C421.lfa
2729-04-08 00:35 . 2729-04-08 00:35 3,120 --a--c--- c:\windows\MF_C420.lfa
2008-11-22 07:28 . 2008-11-22 07:33 <REP> d-------- c:\program files\Exterminate It!
2008-11-21 19:14 . 2008-11-21 19:14 579,584 --a--c--- c:\windows\system32\dllcache\user32.dll
2008-11-21 19:12 . 2008-11-21 19:12 <REP> d-------- c:\windows\ERUNT
2008-11-21 19:10 . 2008-11-21 19:33 <REP> d-------- C:\SDFix
2008-11-17 14:48 . 2008-11-17 14:48 <REP> d-------- c:\documents and settings\Administrateur\Application Data\Logitech
2008-11-17 14:45 . 2004-03-19 11:17 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage réseau
2008-11-17 14:45 . 2004-03-19 11:17 <REP> d--h----- c:\documents and settings\Administrateur\Voisinage d'impression
2008-11-17 14:45 . 2004-03-19 11:21 <REP> d--h----- c:\documents and settings\Administrateur\Modèles
2008-11-17 14:45 . 2004-03-19 11:17 <REP> d-------- c:\documents and settings\Administrateur\Mes documents
2008-11-17 14:45 . 2004-03-19 11:17 <REP> dr------- c:\documents and settings\Administrateur\Menu Démarrer
2008-11-17 14:45 . 2004-03-19 11:17 <REP> d-------- c:\documents and settings\Administrateur\Favoris
2008-11-17 14:45 . 2008-11-21 18:21 <REP> d-------- c:\documents and settings\Administrateur\Bureau
2008-11-17 14:45 . 2008-11-17 14:45 <REP> d-------- c:\documents and settings\Administrateur
2008-11-13 13:12 . 2008-09-04 18:16 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
2008-11-13 13:12 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
2008-11-12 22:10 . 2008-11-12 22:10 <REP> d-------- c:\documents and settings\client\Application Data\Malwarebytes
2008-11-12 19:10 . 2008-11-12 22:10 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-11-12 19:10 . 2008-11-12 19:10 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-11-12 19:10 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-11-12 19:10 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-11-12 18:06 . 2008-11-12 18:06 <REP> d-------- c:\documents and settings\client\Application Data\Talkback
2008-11-12 17:24 . 2008-11-12 17:24 <REP> d-------- c:\program files\Trend Micro
2008-11-12 17:03 . 2008-11-12 17:04 <REP> d-------- c:\documents and settings\client\Application Data\MSN6
2008-11-02 17:26 . 2008-11-02 17:26 <REP> d-------- c:\documents and settings\LocalService\Application Data\agi
2008-11-02 17:25 . 2008-11-02 17:25 2,117,632 --a------ c:\windows\system32\python25.dll
2008-11-02 17:25 . 2008-09-16 17:26 1,332,197 --a------ c:\windows\system32\pythondll.zip
2008-11-02 17:25 . 2008-11-02 17:25 339,968 --a------ c:\windows\system32\pythoncom25.dll
2008-11-02 17:25 . 2008-11-02 17:25 114,688 --a------ c:\windows\system32\pywintypes25.dll
2008-11-02 17:17 . 2008-11-02 19:37 <REP> d-------- c:\program files\Bandoo
2008-10-24 17:43 . 2008-10-15 17:35 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-18 01:28 --------- d-----w c:\documents and settings\client\Application Data\OpenOffice.org2
2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
2008-10-23 18:34 --------- d-----w c:\program files\Shareaza
2008-10-11 14:35 --------- d-----w c:\program files\Java
2008-10-11 14:29 --------- d-----w c:\program files\Microsoft Works
2008-10-11 14:18 --------- d-----w c:\program files\Microsoft AutoRoute
2008-10-11 14:14 --------- d-----w c:\program files\Mobile Action
2008-10-11 14:11 --------- d-----w c:\program files\Yahoo!
2008-10-11 14:10 --------- d-----w c:\program files\KODAK
1999-04-08 12:35 5,168 -c----w c:\program files\cncqx404.exe
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2008-07-06 173368]
[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2008-07-06 11:44 1164600 --a------ c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-07-06 1164600]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-07-06 1164600]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-02-24 67128]
"MsnMsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"IncrediMail"="c:\program files\IncrediMail\bin\IncMail.exe" [2007-01-11 204843]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-10-14 68856]
"Shareaza"="c:\program files\Shareaza\Shareaza.exe" [2008-10-01 5723136]
"updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\ati-cpanel\atiptaxx.exe" [2003-06-05 335872]
"EPSON Stylus CX3200"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE" [2002-07-01 74752]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-01-25 98304]
"InCD"="c:\program files\Ahead\InCD\InCD.exe" [2003-09-05 1200178]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2006-01-12 155648]
"MaBtSh"="c:\program files\Mobile Action\Bluetooth Manager\MaBtSh.exe" [2006-02-08 24576]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" [2005-06-23 57344]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"LVCOMSX"="c:\windows\system32\LVCOMSX.EXE" [2005-12-09 225280]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2008-07-06 111928]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"ATIModeChange"="Ati2mdxx.exe" [2001-09-04 c:\windows\system32\Ati2mdxx.exe]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 c:\windows\KHALMNPR.Exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2008-04-14 15360]
"Symantec NetDriver Warning"="c:\progra~1\SYMNET~1\SNDWarn.exe" [2004-10-29 218232]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.exe.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2004-03-19 98304]
Adobe Gamma Loader.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2004-03-19 98304]
InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2004-03-19 98304]
Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 01:42 72208 c:\program files\Fichiers communs\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.HFYU"= huffyuv.dll
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
"VIDC.ACDV"= ACDV.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"6346:TCP"= 6346:TCP:shareaza
"6346:UDP"= 6346:UDP:shareaza
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-05-04 110160]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-05-04 20560]
R2 DK9ZOZMA;DK9ZOZMA;\??\c:\windows\System32\Drivers\YLMJ7EA8.sys [2007-07-16 28384]
R3 Ma730Pt;MA730 Bluetooth VCOM Driver;c:\windows\system32\DRIVERS\Ma730Pt.sys [2007-07-02 103680]
R3 Ma730VaA;MA730 Bluetooth Advanced Audio;c:\windows\system32\DRIVERS\Ma730VaA.sys [2007-07-02 21851]
R3 Ma730Vad;MA730 Bluetooth Audio;c:\windows\system32\DRIVERS\Ma730Vad.sys [2007-07-02 50522]
R3 SG762_XP;SAGEM 802.11g XG762 1211B Driver;c:\windows\system32\DRIVERS\WlanBZXP.sys [2008-05-01 450560]
S3 jbridgep;jbridgep;\??\c:\docume~1\DELALA~1\LOCALS~1\Temp\jbridgep.sys []
S3 Ma730c;MA730 Bluetooth Core Driver;c:\windows\system32\DRIVERS\MA730C.sys [2007-07-02 156960]
S3 TV_551805_Sp50;TV_551805_Sp50 NDIS Protocol Driver;c:\windows\system32\Drivers\TV_551805_Sp50.sys [2007-11-12 27072]
S3 ZDCndis5;ZDCndis5 Protocol Driver;\??\c:\windows\system32\ZDCndis5.SYS []
.
Contenu du dossier 'Tâches planifiées'
2008-11-22 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-Configuration de la C-BOX - c:\program files\Cegetel\C-BOX\Wizard\QuickAccess.exe
HKLM-Run-Microsoft Works Update Detection - c:\program files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
HKLM-Run-POINTER - point32.exe
HKU-Default-Run-ALUAlert - c:\program files\Symantec\LiveUpdate\ALUNotify.exe
.
------- Examen supplémentaire -------
.
FireFox -: Profile - c:\documents and settings\client\Application Data\Mozilla\Firefox\Profiles\[u]0/ua11kxx7.default\
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-11-22 08:22:02
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Fichiers communs\EPSON\EBAPI\eEBSvc.exe
c:\program files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
c:\program files\Ahead\InCD\incdsrv.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\program files\Logitech\SetPoint\SetPoint.exe
c:\program files\DartyBox Wifi\SAGEM WiFi manager\WLANUTL.EXE
c:\program files\Fichiers communs\Logishrd\KHAL2\KHALMNPR.exe
c:\program files\Windows Live\Messenger\usnsvc.exe
.
**************************************************************************
.
Heure de fin: 2008-11-22 8:27:32 - La machine a redémarré
ComboFix-quarantined-files.txt 2008-11-22 07:27:25
Avant-CF: 28 672 528 384 octets libres
Après-CF: 29,106,262,016 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /fastdetect /NoExecute=OptIn
203 --- E O F --- 2008-11-18 01:27:54
J'attends ta réponse pour mentionner ce fil comme résolu. A+