مرحبا فارس
شكرا على المساعدة
بالنسبة للتقرير الأول هيدا هو
ComboFix 08-08-08.08 - Computer 2008-08-09 22:14:47.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.1.1252.1.1036.18.12 [GMT 0:00]
Endroit: C:\Documents and Settings\Malika\Bureau\ComboFix.exe
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\system32\AutoRun.inf
C:\WINDOWS\system32\REGOBJ.DLL
.
((((((((((((((((((((((((((((( Fichiers créés 2008-07-09 to 2008-08-09 ))))))))))))))))))))))))))))))))))))
.
2008-08-03 18:20 . 2008-08-09 22:09 <REP> d-------- C:\Program Files\Arovax AntiSpyware
2008-08-02 22:53 . 2008-08-02 22:53 0 --a------ C:\WINDOWS\SMMVSplitter.INI
2008-08-02 22:43 . 2008-08-02 22:43 <REP> d-------- C:\Program Files\Solveig Multimedia
2008-08-02 22:43 . 2008-08-02 22:43 <REP> d-------- C:\Program Files\Fichiers communs\Solveig Multimedia
2008-07-11 23:45 . 2008-07-12 17:44 163,840 --a------ C:\WINDOWS\mmproxy_40.mdb
2008-07-11 23:45 . 2008-07-12 17:19 159,744 --a------ C:\WINDOWS\mmproxy_40_Backup.mdb
2008-07-11 23:42 . 2008-07-11 23:42 <REP> d-------- C:\Program Files\AIST
2008-07-09 18:17 . 2008-07-09 21:53 <REP> d-------- C:\Documents and Settings\Malika\Application Data\MxBoost
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-08 23:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\AntiVir PersonalEdition Classic
2008-08-04 13:31 --------- d-----w C:\Documents and Settings\Malika\Application Data\U3
2008-07-22 22:59 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-07-22 22:55 --------- d-----w C:\Program Files\Moyea
2008-07-22 22:55 --------- d-----w C:\Documents and Settings\Malika\Application Data\Moyea
2008-07-22 21:32 --------- d-----w C:\Program Files\Panicware
2008-07-13 19:30 --------- d-----w C:\Program Files\NCH Swift Sound
2008-07-13 19:30 --------- d-----w C:\Documents and Settings\Malika\Application Data\NCH Swift Sound
2008-07-11 23:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
2008-07-11 19:07 --------- d-----w C:\Program Files\NCH Software
2008-07-06 15:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-07-04 18:17 --------- d-----w C:\Documents and Settings\Malika\Application Data\CdromAcidFour
2008-07-03 18:32 --------- d-----w C:\Program Files\Real
2008-06-27 17:04 --------- d-----w C:\Documents and Settings\Malika\Application Data\AdobeUM
2008-06-21 21:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\TVU Networks
2008-06-21 14:22 --------- d-----w C:\Program Files\CdromAcidFour
2008-05-20 23:48 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-05-20 23:48 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-04-11 00:35 65,112 ------w C:\Documents and Settings\Malika\Application Data\GDIPFONTCACHEV1.DAT
2007-05-16 16:53 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2006-11-09 15:20 2,111,096 ----a-w C:\Program Files\NPSWF32.dll
2006-09-16 16:20 3,808 ----a-w C:\Program Files\SETUP.LST
2005-08-28 23:36 1,528 ----a-w C:\Program Files\Accessibility Wizard.lnk
2004-10-31 15:39 76 --sh--w C:\Program Files\Desktop.ini
1998-06-18 00:00 140,800 ----a-w C:\Program Files\setup.exe
2007-02-15 21:51 5 --sha-w C:\WINDOWS\system32\abade_s.dll
2007-05-29 12:20 320,800 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
2007-05-29 12:20 13,088 --sha-w C:\WINDOWS\system32\drivers\fidbox2.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-19 20:57 266497]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-05-20 23:47 185896]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2002-08-29 09:45 13312]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55 5674352]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
DSLMON.lnk - C:\Program Files\Menara\dslmon.exe [2006-11-18 21:50:32 966756]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Adobe Gamma Loader.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Adobe Gamma Loader.lnk
backup=C:\WINDOWS\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^EyeLoveU.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\EyeLoveU.lnk
backup=C:\WINDOWS\pss\EyeLoveU.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk
backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Orbit.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Orbit.lnk
backup=C:\WINDOWS\pss\Orbit.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^WinZip Quick Pick.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\WinZip Quick Pick.lnk
backup=C:\WINDOWS\pss\WinZip Quick Pick.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Malika^Menu Démarrer^Programmes^Démarrage^Yahoo! Widgets.lnk]
path=C:\Documents and Settings\Malika\Menu Démarrer\Programmes\Démarrage\Yahoo! Widgets.lnk
backup=C:\WINDOWS\pss\Yahoo! Widgets.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2002-08-29 09:45 13312 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
--a------ 2007-03-11 21:34 49152 C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
--a------ 2002-08-28 21:38 208953 C:\WINDOWS\ime\IMJP8_1\imjpmig.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
--------- 2005-01-27 17:17 1381376 C:\Program Files\Ahead\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2007-09-26 14:42 267064 C:\Program Files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
--a------ 2007-01-19 12:55 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhotoShow Deluxe Media Manager]
--a------ 2005-02-26 00:28 212992 C:\PROGRA~1\Nero\data\Xtras\mssysmgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-06-29 06:24 286720 C:\Program Files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\snpstd3]
--a------ 2005-09-05 15:55 339968 C:\WINDOWS\vsnpstd3.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2008-05-20 23:47 185896 C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tsnpstd3]
--a------ 2005-11-04 15:05 90112 C:\WINDOWS\tsnpstd3.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ERSvc"=2 (0x2)
"RDSessMgr"=3 (0x3)
"mnmsrvc"=3 (0x3)
R0 avgntmgr;avgntmgr;C:\WINDOWS\System32\drivers\avgntmgr.sys [2008-04-19 19:16]
R1 avgntdd;avgntdd;C:\WINDOWS\System32\DRIVERS\avgntdd.sys [2008-07-19 20:57]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f7dc25c0-de93-11da-b8b6-806d6172696f}]
\shell\play\Command - "C:\Program Files\Windows Media Player\wmplayer.exe" /prefetch:3 /device:AudioCD "%L"
*Newly Created Service* - CATCHME
*Newly Created Service* - PROCEXP90
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
2008-06-01 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job
- C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
MSConfigStartUp-antinetcut2 - C:\Program Files\Anti Netcut\Anti NetCut.exe
MSConfigStartUp-ares - C:\Documents and Settings\Malika\Bureau\Nouveau dossier\Ares portable\App\Ares.exe
MSConfigStartUp-Babylon Client - C:\Program Files\Babylon\Babylon-Pro\Babylon.exe
MSConfigStartUp-Flapplatform - C:\DOCUME~1\Malika\APPLIC~1\CDROMA~1\tick loud.exe
MSConfigStartUp-Orb - C:\Program Files\Winamp Remote\bin\OrbTray.exe
MSConfigStartUp-STYLEXP - C:\Program Files\TGTSoft\StyleXP\StyleXP.exe
MSConfigStartUp-SunJavaUpdateSched - C:\Program Files\Java\j2re1.4.2_15\bin\jusched.exe
MSConfigStartUp-SweetIM - C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
MSConfigStartUp-WinampAgent - C:\Documents and Settings\Malika\Bureau\Winamp\winampa.exe
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\Malika\Application Data\Mozilla\Firefox\Profiles\e5jczc0o.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2685&invocationType=tb50ffwinampie7&query=
FF -: plugin - C:\Program Files\Adobe\Acrobat 5.0\Reader\Browser\nppdf32.dll
FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
FF -: plugin - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2008-08-09 22:22:25
Windows 5.1.2600 Service Pack 1 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
**************************************************************************
.
Temps d'accomplissement: 2008-08-09 22:33:38
ComboFix-quarantined-files.txt 2008-08-09 22:32:29
Pre-Run: 4,065,247,232 octets libres
Post-Run: 4,328,599,552 octets libres
162 --- E O F --- 2008-07-25 00:23:15