merci j'ai fait tous se que tu ma dit,maintenant j'ai plus que 26 processus j'ai que kerio et le volume principale qui se lance je verait dans msconfig et je suis tous seul sur ma machine pourquoi?
voila le rapport combofix:
ComboFix 08-06-20.4 - jyabol 2008-06-24 23:56:30.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.321 [GMT 2:00]
Endroit: E:Documents and SettingsjyabolBureauComboFix.exe
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RECUPERATION N'EST PAS INSTALLEE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
E:Documents and SettingsjyabolLocal SettingsApplication Datavxxybbcl.dat
E:Documents and SettingsjyabolLocal SettingsApplication Datavxxybbcl_nav.dat
E:Documents and SettingsjyabolLocal SettingsApplication Datavxxybbcl_navps.dat
E:WINDOWSsystem32
vs2.inf
E:WINDOWSsystem32
qRHXOgG.dll
.
((((((((((((((((((((((((((((( Fichiers cr,,s 2008-05-24 to 2008-06-24 ))))))))))))))))))))))))))))))))))))
.
2008-06-24 23:45 . 2008-06-24 23:45 <REP> d-------- E:Program FilesSophos
2008-06-24 23:00 . 2008-06-24 23:00 <REP> d-------- E:Program FilesTrend Micro
2008-06-24 17:15 . 2008-06-24 17:15 <REP> d--h----- E:WINDOWSsystem32GroupPolicy
2008-06-24 16:38 . 2008-03-09 07:25 236 --ah----- E:Program FilesFichiers communsdx.reg
2008-06-24 14:43 . 2008-06-24 14:43 <REP> d-------- E:Documents and SettingsjyabolMy Games
2008-06-24 14:43 . 2008-06-24 14:43 <REP> d-------- E:Documents and SettingsAll UsersMicrosoft
2008-06-24 12:57 . 2008-06-24 12:57 <REP> d-------- E:Documents and SettingsjyabolApplication Datavlc
2008-06-24 12:55 . 2008-06-24 12:55 <REP> d-------- E:Program FilesVideoLAN
2008-06-23 21:20 . 2008-06-24 14:12 <REP> d-------- E:Documents and SettingsjyabolApplication DataLimeWire
2008-06-23 21:11 . 2008-03-25 02:37 69,632 --a------ E:WINDOWSsystem32javacpl.cpl
2008-06-23 21:10 . 2008-06-23 21:11 <REP> d-------- E:Program FilesJava
2008-06-23 21:08 . 2008-06-23 21:08 <REP> d-------- E:Program FilesFichiers communsJava
2008-06-23 21:06 . 2008-06-23 21:07 <REP> d-------- E:Program FilesLimeWire
2008-06-21 17:22 . 2008-06-24 17:34 <REP> d-------- E:Documents and SettingsjyabolApplication DataOpenOffice.org2
2008-06-21 16:48 . 2008-06-21 16:49 <REP> d-------- E:Program FilesOpenOffice.org 2.4
2008-06-19 07:32 . 2004-08-03 23:54 159,232 --a------ E:WINDOWSsystem32ptpusd.dll
2008-06-19 07:32 . 2004-08-03 21:58 15,104 --a------ E:WINDOWSsystem32driversusbscan.sys
2008-06-19 07:32 . 2001-08-23 16:47 5,632 --a------ E:WINDOWSsystem32ptpusb.dll
2008-06-18 18:20 . 2008-06-21 00:24 <REP> d-------- E:Program FilesLphant
2008-06-18 16:50 . 2008-06-20 14:27 <REP> d-------- E:Program FileseMule
2008-06-18 16:39 . 2008-06-18 16:39 <REP> d-------- E:Program FilesAvira
2008-06-18 16:39 . 2008-06-18 16:46 <REP> d-------- E:Documents and SettingsAll UsersApplication DataAvira
2008-06-17 02:34 . 2008-06-17 02:34 98,304 --a------ E:WINDOWSsystem32CmdLineExt.dll
2008-06-16 17:24 . 2008-06-16 17:24 <REP> d-------- E:Program FilesQuickPar
2008-06-16 00:18 . 2008-06-23 23:19 <REP> d-------- E:Documents and SettingsjyabolApplication DataFileZilla
2008-06-16 00:17 . 2008-06-16 00:17 <REP> d-------- E:Program FilesFileZilla FTP Client
2008-06-15 21:03 . 2008-06-16 01:38 <REP> d-------- E:Program FilesMumble
2008-06-15 20:53 . 2008-06-15 20:55 <REP> d-------- E:Program FilesVentSrv
2008-06-15 20:29 . 2008-06-15 20:29 <REP> d-------- E:Program FilesCCleaner
2008-06-15 16:39 . 2008-06-15 16:39 <REP> d-------- E:Documents and SettingsjyabolApplication DataMicrosoft Games
2008-06-15 16:39 . 2008-06-15 16:39 <REP> d-------- E:Documents and SettingsAll UsersApplication DataMicrosoft Games
2008-06-15 16:36 . 2008-06-15 16:36 <REP> d-------- E:Program FilesMicrosoft Games
2008-06-15 16:33 . 2008-06-15 16:34 <REP> d-------- E:Program FilesPowerISO
2008-06-15 00:48 . 2008-06-15 20:05 <REP> d-------- E:Program FilesmnProjects
2008-06-13 20:16 . 2008-06-14 16:44 <REP> d-a------ E:Documents and SettingsAll UsersApplication DataTEMP
2008-06-13 20:06 . 2008-06-13 20:32 <REP> d-------- E:Documents and SettingsjyabolApplication Dataflightgear.org
2008-06-13 14:56 . 2008-06-13 14:56 <REP> d-------- E:Program FilesVentrilo
2008-06-13 14:56 . 2008-06-15 20:52 <REP> d-------- E:Program FilesFichiers communsWise Installation Wizard
2008-06-13 14:56 . 2008-06-18 23:20 <REP> d-------- E:Documents and SettingsjyabolApplication DataVentrilo
2008-06-13 12:48 . 2008-06-22 23:18 <REP> d-------- E:Program FilesUltraVNC
2008-06-13 12:48 . 2005-06-10 22:02 12,800 --a------ E:WINDOWSsystem32vncdrv.dll
2008-06-13 12:48 . 2004-06-26 13:22 6,016 --a------ E:WINDOWSsystem32driversvnccom.SYS
2008-06-13 12:48 . 2004-06-26 13:21 5,760 --a------ E:WINDOWSsystem32vnchelp.dll
2008-06-13 12:48 . 2004-06-26 13:22 4,736 --a------ E:WINDOWSsystem32driversvncdrv.sys
2008-06-13 12:48 . 2008-06-13 12:48 17 --a------ E:WINDOWSsystem32'
2008-06-12 17:42 . 2008-06-12 17:42 8 --a------ E:WINDOWSsystem32
vModes.dat
2008-06-12 17:41 . 2008-06-12 17:41 <REP> d-------- E:Documents and SettingsAll UsersApplication Data
View_Profiles
2008-06-12 00:59 . 2008-06-12 00:59 <REP> d-------- E:WINDOWSsystem32Adobe
2008-06-11 23:54 . 2008-06-15 20:04 <REP> d-------- E:Program FilesAnyplace Control
2008-06-11 22:34 . 2008-06-14 19:59 272,768 --------- E:WINDOWSsystem32driversthport.sys
2008-06-11 22:34 . 2008-06-14 19:59 272,768 -----c--- E:WINDOWSsystem32dllcachethport.sys
2008-06-11 17:26 . 2008-06-15 13:51 <REP> d-------- E:Program FilesSpybot - Search & Destroy
2008-06-11 17:26 . 2008-06-14 16:44 <REP> d-------- E:Documents and SettingsAll UsersApplication DataSpybot - Search & Destroy
2008-06-10 19:22 . 2008-06-10 19:22 <REP> d-------- E:Documents and SettingsjyabolApplication DataLavasoft
2008-06-10 18:32 . 2007-08-13 18:54 33,792 --a--c--- E:WINDOWSsystem32dllcachecustsat.dll
2008-06-09 14:57 . 2008-06-09 14:57 <REP> d-------- E:Program Filessl.GameLauncher
2008-06-08 18:17 . 2007-07-30 19:19 271,224 --a------ E:WINDOWSsystem32mucltui.dll
2008-06-08 18:17 . 2007-07-30 19:18 30,072 --a------ E:WINDOWSsystem32mucltui.dll.mui
2008-06-08 17:04 . 2008-06-08 17:11 0 --a------ E:WINDOWSgalaxy.ini
2008-06-08 16:59 . 2008-06-08 16:59 <REP> d-------- E:Program FilesSoftware Informer
2008-06-08 16:59 . 2008-06-08 17:00 <REP> d-------- E:Program FilesFree Download Manager
2008-06-08 16:59 . 2008-06-24 23:57 <REP> d-------- E:Documents and SettingsjyabolApplication DataFree Download Manager
2008-06-08 16:59 . 2008-06-08 16:59 <REP> d-------- E:Documents and SettingsAll UsersApplication DataFreeDownloadManager.ORG
2008-06-08 00:48 . 2008-06-08 00:48 <REP> d-------- E:Program FilesuTorrent
2008-06-08 00:48 . 2008-06-23 23:18 <REP> d-------- E:Documents and SettingsjyabolApplication DatauTorrent
2008-06-07 21:56 . 2008-06-23 00:55 <REP> d-------- E:Documents and SettingsjyabolApplication Data eamspeak2
2008-06-07 21:46 . 2008-06-24 22:20 23,352 --a------ E:WINDOWSsystem32driversPnkBstrK.sys
2008-06-07 21:35 . 2008-06-24 22:19 107,832 --a------ E:WINDOWSsystem32PnkBstrB.exe
2008-06-07 21:34 . 2008-06-07 21:34 <REP> d-------- E:WINDOWSsystem32LogFiles
2008-06-07 21:34 . 2008-06-07 21:34 66,872 --a------ E:WINDOWSsystem32PnkBstrA.exe
2008-06-07 21:28 . 2008-06-21 12:30 <REP> d-------- E:Program FilesTeamspeak2_RC2
2008-06-07 21:28 . 2008-06-07 21:28 34,064 --a------ E:WINDOWSsystem32lhacm.acm
2008-06-07 21:27 . 2008-06-20 09:15 <REP> d-------- E:Program FilesXfire
2008-06-07 21:27 . 2008-06-07 21:27 <REP> d-------- E:Documents and SettingsLocalServiceApplication DataXfire
2008-06-07 21:27 . 2008-06-16 22:41 <REP> d-------- E:Documents and SettingsjyabolApplication DataXfire
2008-06-07 21:25 . 2008-06-23 13:27 <REP> d-------- E:Program FilesWolfenstein - Enemy Territory
2008-06-07 21:04 . 2008-06-09 18:08 <REP> d-------- E:Documents and SettingsjyabolContacts
2008-06-07 21:00 . 2008-06-07 21:00 <REP> d-------- E:WINDOWSsystem32Lang
2008-06-07 21:00 . 2008-06-07 21:00 940,794 --a------ E:WINDOWSsystem32LoopyMusic.wav
2008-06-07 21:00 . 2008-06-07 21:00 146,650 --a------ E:WINDOWSsystem32BuzzingBee.wav
2008-06-03 02:56 . 2008-06-03 02:56 41,296 --a------ E:WINDOWSsystem32xfcodec.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-22 11:19 --------- d--h--w E:Program FilesInstallShield Installation Information
2008-06-15 18:08 --------- d-----w E:Program FilesEset
2008-06-10 17:22 --------- d-----w E:Program FilesAd-Aware
2008-06-07 18:57 --------- d-----w E:Program FilesWindows Live
2008-06-07 18:56 --------- dcsh--w E:Program FilesFichiers communsWindowsLiveInstaller
2008-06-07 18:56 --------- d-----w E:Documents and SettingsAll UsersApplication DataWLInstaller
2008-06-07 18:35 --------- d-----w E:Program FilesKerio
2008-06-07 18:35 --------- d-----w E:Program FilesFichiers communsInstallShield
2008-06-07 16:42 --------- d-----w E:Program FilesJDoe Tools
2008-06-07 16:35 --------- d-----w E:Program Filesmicrosoft frontpage
2008-06-07 16:34 --------- d-----w E:Program FilesReal Alternative
2008-06-07 16:34 --------- d-----w E:Program FilesFichiers communsAhead
2008-06-07 16:34 --------- d-----w E:Documents and SettingsAll UsersApplication DataApple Computer
2008-06-07 16:33 --------- d-----w E:Program FilesQuickTime Alternative
2008-06-07 16:33 --------- d-----w E:Program FilesMedia Player Classic
2008-06-07 16:31 --------- d-----w E:Program FilesWindows Media Connect 2
2008-06-07 16:29 --------- d-----w E:Program FilesServices en ligne
2008-05-19 14:35 9,709,568 ----a-w E:WINDOWSRTLCPL.EXE
2008-05-19 14:35 86,016 ----a-w E:WINDOWSSOUNDMAN.EXE
2008-05-19 14:35 69,632 ----a-w E:WINDOWSALCMTR.EXE
2008-05-19 14:35 4,356,608 ----a-w E:WINDOWSsystem32driversRtkHDAud.sys
2008-05-19 14:35 364,544 ----a-w E:WINDOWSRtlUpd.exe
2008-05-19 14:35 2,879,488 ----a-w E:WINDOWSSkyTel.exe
2008-05-19 14:35 2,808,832 ----a-w E:WINDOWSALCWZRD.EXE
2008-05-19 14:35 2,158,592 ----a-w E:WINDOWSMicCal.exe
2008-05-19 14:35 16,049,664 ----a-w E:WINDOWSRTHDCPL.EXE
2008-05-19 14:28 138,752 ----a-w E:WINDOWSsystem32drivershdaudbus.sys
2008-05-08 12:28 202,752 ----a-w E:WINDOWSsystem32drivers
mcast.sys
2008-05-03 03:46 6,554,496 ----a-w E:WINDOWSsystem32drivers
v4_mini.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ,l,ments vides & les ,l,ments initiaux l,gitimes ne sont pas list,s
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"NvCplDaemon"="E:WINDOWSsystem32NvCpl.dll" [2008-05-03 05:46 13529088]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversiondrivers32]
"VIDC.XFR1"= xfcodec.dll
[HKLM~startupfolderE:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^etmin.exe]
path=E:Documents and SettingsAll UsersMenu DémarrerProgrammesDémarrageetmin.exe
backup=E:WINDOWSpssetmin.exeCommon Startup
[HKLM~startupfolderE:^Documents and Settings^jyabol^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 2.4.lnk]
path=E:Documents and SettingsjyabolMenu DémarrerProgrammesDémarrageOpenOffice.org 2.4.lnk
backup=E:WINDOWSpssOpenOffice.org 2.4.lnkStartup
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregAlcmtr]
--a------ 2008-05-19 16:35 69632 E:WINDOWSALCMTR.EXE
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregavgnt]
--a------ 2008-02-12 10:06 262401 E:Program FilesAviraAntiVir PersonalEdition Classicavgnt.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregctfmon.exe]
--a------ 2004-08-04 01:54 15360 E:WINDOWSsystem32ctfmon.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregFree Download Manager]
--a------ 2008-05-20 17:27 2474031 E:Program FilesFree Download Managerfdm.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregfsm]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregMicrosoft WinUpdate]
E:WINDOWSsystem32msupdatgms.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregMSMSGS]
--------- 2004-10-13 17:24 1694208 E:Program FilesMessengermsmsgs.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregMsnMsgr]
--a------ 2007-10-18 11:34 5724184 E:Program FilesWindows LiveMessengermsnmsgr.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregNvCplDaemon]
--a------ 2008-05-03 05:46 13529088 E:WINDOWSsystem32NvCpl.dll
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregNvMediaCenter]
--a------ 2008-05-03 05:46 86016 E:WINDOWSsystem32NvMcTray.dll
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupreg
wiz]
--a------ 2008-05-03 05:46 1630208 E:WINDOWSsystem32
wiz.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregpjlfh]
e:documents and settingsjyabollocal settingsapplication datapjlfh.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregPowerStrip]
e:program filespowerstrippstrip.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregPWRISOVM.EXE]
--a------ 2008-03-15 01:50 233472 E:Program FilesPowerISOPWRISOVM.EXE
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregRTHDCPL]
--a------ 2008-05-19 16:35 16049664 E:WINDOWSRTHDCPL.EXE
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSkyTel]
--a------ 2008-05-19 16:35 2879488 E:WINDOWSSkyTel.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSoftware Informer]
E:Program FilesFree Download Managersoftinfo.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSunJavaUpdateSched]
--a------ 2008-03-25 04:28 144784 E:Program FilesJavajre1.6.0_06injusched.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregWinVNC]
--a------ 2006-06-18 14:56 712704 E:Program FilesUltraVNCwinvnc.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
"%windir%\system32\sessmgr.exe"=
"E:\Program Files\Windows Live\Messenger\msnmsgr.exe"=
"E:\Program Files\Windows Live\Messenger\livecall.exe"=
"E:\Program Files\uTorrent\uTorrent.exe"=
"%windir%\Network Diagnostic\xpnetdiag.exe"=
"E:\Program Files\Microsoft Games\Zoo Tycoon 2\zt.exe"=
"E:\Program Files\Lphant\eLePhantClient.exe"=
R1 fwdrv;Kerio Personal Firewall Driver;E:WINDOWSsystem32Driversfwdrv.sys [2002-04-15 12:28]
R2 vnccom;vnccom;E:WINDOWSsystem32Driversvnccom.SYS [2004-06-26 13:22]
S3 MEMSWEEP2;MEMSWEEP2;E:WINDOWSsystem3225.tmp []
S3 usbscan;Pilote de scanneur USB;E:WINDOWSsystem32DRIVERSusbscan.sys [2004-08-03 21:58]
[HKEY_CURRENT_USERsoftwaremicrosoftwindowscurrentversionexplorermountpoints2D]
ShellAutoRuncommand - D:setup.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-06-24 23:59:17
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach,s ...
Balayage cach, autostart entries ...
Balayage des fichiers cach,s ...
Scan termin, avec succSs
Les fichiers cach,s: 0
**************************************************************************
[HKEY_LOCAL_MACHINESystemControlSet001ServicesMEMSWEEP2]
"ImagePath"="??E:WINDOWSsystem3225.tmp"
.
------------------------ Other Running Processes ------------------------
.
E:Program FilesAviraAntiVir PersonalEdition Classicsched.exe
E:Program FilesAviraAntiVir PersonalEdition Classicavguard.exe
E:WINDOWSsystem32
vsvc32.exe
E:Program FilesKerioPersonal FirewallPERSFW.exe
E:WINDOWSsystem32PnkBstrA.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-06-25 0:01:09 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-24 22:01:03
Pre-Run: 4,254,232,576 octets libres
Post-Run: 4,262,285,312 octets libres
229 --- E O F --- 2008-06-20 10:27:24