merci
j'ai fixer les deux que tu me demandais
recuperer la console windows (apres le pc a redemarrer et une fenetre noire est appuru avec soit demarrer ....xp ou soit la console "qu'il n'a pas voulu prendre")
A la fin de l'installation, ComboFix signalera que la console de récupération est installée et demandera si tu veux effectuer une analyse.
Cliques sur Non/No car le paramétrage n'est pas encore achevé.
pas eu de message
A la fenêtre Disclaimer, tu tapes sur [1].
pas eu
Patientes, ComboFix nettoie en 41 étapes.
50 pour moi
voici le rapport combofix
ComboFix 09-03-15.01 - frederic 2009-03-16 10:57:56.1 - NTFSx86
Microsoft Windows XP Edition familiale 5.1.2600.3.1252.1.1036.18.1535.1122 [GMT 1:00]
Lancé depuis: c:documents and settingsfredericMes documentsTelechargementsComboFix.exe
AV: Avira AntiVir PersonalEdition Classic *On-access scanning disabled* (Updated)
* Un nouveau point de restauration a été créé
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-16 au 2009-03-16 ))))))))))))))))))))))))))))))))))))
.
2009-03-16 08:39 . 2009-03-16 08:39 <REP> d-------- c:program filesTrend Micro
2009-03-14 21:00 . 2009-03-14 21:00 <REP> d-------- c:documents and settingsfredericApplication DataAuslogics
2009-03-14 11:34 . 2009-03-14 11:34 81,920 --a------ c:windowsALCFDRTM.EXE
2009-03-10 18:43 . 2009-03-10 18:43 <REP> d-------- c:program filesMalwarebytes' Anti-Malware
2009-03-10 18:43 . 2009-03-10 18:43 <REP> d-------- c:documents and settingsfredericApplication DataMalwarebytes
2009-03-10 18:43 . 2009-03-10 18:43 <REP> d-------- c:documents and settingsAll UsersApplication DataMalwarebytes
2009-03-10 18:43 . 2009-02-11 10:19 38,496 --a------ c:windowssystem32driversmbamswissarmy.sys
2009-03-10 18:43 . 2009-02-11 10:19 15,504 --a------ c:windowssystem32driversmbam.sys
2009-03-10 18:34 . 2009-03-10 18:34 <REP> d-------- c:program filesWindows Defender
2009-03-08 19:16 . 2009-03-08 19:16 <REP> d-------- c:program filesFichiers communsEPSON
2009-03-08 19:16 . 2009-03-08 19:16 <REP> d-------- c:program filesEpsonNet
2009-03-08 11:39 . 2009-03-08 11:39 <REP> d-------- c:documents and settingsLocalServiceApplication DataXfire
2009-03-08 11:38 . 2009-03-08 11:44 <REP> d-------- c:program filesXfire
2009-03-08 11:38 . 2009-03-08 12:28 <REP> d-------- c:documents and settingsfredericApplication DataXfire
2009-03-08 10:23 . 2009-03-15 18:31 <REP> d-------- c:documents and settingsAll UsersApplication DataGoogle Updater
2009-03-07 20:10 . 2009-02-18 14:44 453,152 --a------ c:windowssystem32
vudisp.exe
2009-03-07 20:10 . 2009-03-16 10:52 212,973 --a------ c:windowssystem32
vapps.xml
2009-03-07 20:10 . 2009-02-18 14:44 19,021 --a------ c:windowssystem32
vdisp.nvu
2009-03-07 20:09 . 2009-02-16 23:17 453,152 --a------ c:windowssystem32NVUNINST.EXE
2009-03-02 14:57 . 2009-03-02 14:57 <REP> d-------- c:program filesWindows Media Connect 2
2009-03-02 14:54 . 2009-03-02 14:55 <REP> d-------- c:windowssystem32driversUMDF
2009-03-02 14:54 . 2009-03-02 14:55 <REP> d-------- C:f1ad59362e9f7391801c
2009-03-01 19:31 . 2009-03-01 19:31 <REP> dr------- c:documents and settingsLocalServiceFavoris
2009-03-01 12:46 . 2009-03-01 12:46 <REP> d-------- c:documents and settingsfredericApplication DataRoxio
2009-03-01 12:44 . 2009-03-01 12:44 <REP> d-------- c:documents and settingsAll UsersApplication DataSonic
2009-03-01 11:53 . 2009-03-01 11:53 <REP> d-------- c:documents and settingsfredericApplication DataBackup MyPC Deluxe
2009-03-01 11:49 . 2009-03-01 12:43 <REP> d-------- c:program filesRoxio
2009-03-01 11:49 . 2009-03-01 11:49 <REP> d-------- c:documents and settingsAll UsersApplication DataInstallShield
2009-03-01 11:49 . 2009-03-01 11:49 0 --a------ c:windowsEEventManager.INI
2009-03-01 11:48 . 2009-03-01 12:53 <REP> d-------- c:program filesFichiers communsRoxio Shared
2009-03-01 11:44 . 2006-05-18 17:58 309,760 --a------ c:windowssystem32DIFxAPI.dll
2009-03-01 11:44 . 2007-06-18 04:40 200,704 -ra------ c:windowssystem32UMonit.exe
2009-03-01 11:44 . 2007-05-09 07:34 176,128 -ra------ c:windowssystem32ustor.dll
2009-03-01 11:44 . 2007-03-21 12:03 139,264 -ra------ c:windowssystem32GeneIcon.dll
2009-03-01 11:44 . 2007-06-11 03:27 12,416 -ra------ c:windowssystem32driversfixustor.sys
2009-03-01 11:44 . 2007-03-21 12:03 1,372 -ra------ c:windowssystem32IconCfg0.ini
2009-02-28 22:55 . 2009-03-01 21:02 <REP> d-------- c:documents and settingsfredericApplication DataEPSON
2009-02-28 22:35 . 2007-12-07 03:08 86,528 --a------ c:windowssystem32E_FLBEKE.DLL
2009-02-28 22:35 . 2007-12-07 03:01 78,848 --a------ c:windowssystem32E_FD4BEKE.DLL
2009-02-28 22:35 . 2007-04-10 02:06 8,192 --a------ c:windowssystem32E_DCINST.DLL
2009-02-28 22:33 . 2009-02-28 22:33 <REP> d-------- c:documents and settingsAll UsersApplication DataUDL
2009-02-28 22:32 . 2009-02-28 22:33 <REP> d-------- c:program filesEpson Software
2009-02-28 22:31 . 2009-02-28 22:32 <REP> d-------- c:program filesABBYY FineReader 6.0 Sprint
2009-02-28 22:30 . 2009-02-28 22:30 <REP> d-------- c:documents and settingsfredericApplication DataInstallShield
2009-02-28 22:30 . 2009-03-01 17:59 <REP> d-------- c:documents and settingsAll UsersApplication DataEPSON
2009-02-28 22:29 . 2009-03-01 17:56 <REP> d-------- c:program filesepson
2009-02-26 19:47 . 2009-02-26 19:47 42,320 --a------ c:windowssystem32xfcodec.dll
2009-02-19 19:40 . 2009-02-19 19:47 <REP> d-------- c:documents and settingsfredericApplication Dataflightgear.org
2009-02-19 19:39 . 2009-02-20 15:50 <REP> d-------- c:program filesFlightGear
2009-02-18 19:49 . 2009-03-13 18:58 189,496 --a------ c:windowssystem32PnkBstrB.xtr
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-15 12:18 146 ----a-w c:documents and settingsfredericApplication Datawklnhst.dat
2009-03-15 10:06 --------- d-----w c:program fileseMule
2009-03-15 09:59 --------- d-----w c:program filesma-config.com
2009-03-15 09:59 --------- d-----w c:documents and settingsAll UsersApplication Datama-config.com
2009-03-14 07:52 --------- d-----w c:program filesSpybot - Search & Destroy
2009-03-13 17:58 189,496 ----a-w c:windowssystem32PnkBstrB.exe
2009-03-13 17:24 139,984 ----a-w c:windowssystem32driversPnkBstrK.sys
2009-03-08 18:16 --------- d--h--w c:program filesInstallShield Installation Information
2009-03-08 12:29 --------- d-----w c:documents and settingsAll UsersApplication DataTrackMania
2009-03-08 09:30 --------- d-----w c:program filesGoogle
2009-03-04 16:58 5,045,760 ----a-w c:windowssystem32driversRtkHDAud.sys
2009-03-02 15:01 17,530,368 ----a-w c:windowsRTHDCPL.EXE
2009-03-02 10:14 57,344 ----a-w c:windowsALCMTR.EXE
2009-02-28 21:33 --------- d-----w c:program filesFichiers communsInstallShield
2009-02-27 08:56 --------- d-----w c:program filesMicrosoft Silverlight
2009-02-25 17:32 --------- d-----w c:program filesMicrosoft
2009-02-25 08:43 --------- d-----w c:documents and settingsLocalServiceApplication DataSACore
2009-02-21 16:36 --------- d-----w c:program filesFichiers communsWise Installation Wizard
2009-02-21 16:36 --------- d-----w c:program filesAGEIA Technologies
2009-02-21 16:30 73,728 ----a-w c:windowssystem32RtNicProp32.dll
2009-02-21 16:30 118,656 ----a-w c:windowssystem32driversRtnicxp.sys
2009-02-18 18:37 75,064 ----a-w c:windowssystem32PnkBstrA.exe
2009-02-15 10:03 682,280 ----a-w c:windowssystem32pbsvc.exe
2009-02-15 10:03 22,328 ----a-w c:documents and settingsfredericApplication DataPnkBstrK.sys
2009-02-15 09:51 --------- d-----w c:program filesActivision
2009-02-14 17:27 --------- d-----w c:program filesSafari
2009-02-14 12:47 23,600 ----a-w c:windowssystem32driversTVICHW32.SYS
2009-02-13 17:18 --------- d-----w c:program filesPC Wizard 2008
2009-02-10 09:56 --------- d-----w c:documents and settingsAll UsersApplication DataSpybot - Search & Destroy
2009-02-09 14:05 1,846,912 ----a-w c:windowssystem32win32k.sys
2009-02-09 07:57 410,984 ----a-w c:windowssystem32deploytk.dll
2009-02-09 07:57 --------- d-----w c:program filesJava
2009-02-08 19:07 --------- d-----w c:program filesIntel Corporation
2009-02-08 10:17 --------- d-----w c:documents and settingsfredericApplication Datavlc
2009-02-08 10:15 --------- d-----w c:program filesVideoLAN
2009-02-07 17:09 --------- d-----w c:documents and settingsfredericApplication DataApple Computer
2009-02-07 17:00 --------- d-----w c:documents and settingsAll UsersApplication DataApple Computer
2009-02-07 16:58 --------- d-----w c:program filesQuickTime
2009-02-07 15:59 --------- d-----w c:program filesSpeedFan
2009-02-06 17:52 49,504 ----a-w c:windowssystem32sirenacm.dll
2009-01-28 18:13 --------- d-----w c:program filesSystemRequirementsLab
2009-01-28 18:13 --------- d-----w c:documents and settingsfredericApplication DataSystemRequirementsLab
2009-01-27 19:02 --------- d-----w c:program filesFichiers communsFuturemark Shared
2009-01-27 16:39 --------- d---a-w c:documents and settingsAll UsersApplication DataTEMP
2009-01-27 15:46 --------- d-----w c:program filesWanadoo
2009-01-26 19:00 --------- d-----w c:program filesRealtek
2009-01-26 14:35 --------- d-----w c:documents and settingsfredericApplication DataRaptr
2009-01-26 14:35 --------- d-----w c:documents and settingsfredericApplication Datacom.raptr.Raptr.848BBC53270CAC248E8FA0F339176201CDEB525F.1
2009-01-23 20:16 --------- d-----w c:program files7-Zip
2009-01-23 19:41 --------- d-----w c:program filesSymantec
2009-01-23 08:26 --------- d-----w c:program filesAvira
2009-01-23 08:26 --------- d-----w c:documents and settingsAll UsersApplication DataAvira
2009-01-23 08:23 --------- d-----w c:program filesFichiers communsSymantec Shared
2009-01-23 08:19 --------- d-----w c:documents and settingsAll UsersApplication DataSymantec
2009-01-22 09:14 --------- d-----w c:program filesFichiers communsAdobe
2009-01-21 14:54 1,206,816 ----a-w c:windowsRtlUpd.exe
2009-01-19 13:11 --------- d-----w c:documents and settingsAll UsersApplication Data
View_Profiles
2009-01-16 17:24 70,936 ----a-w c:windowssystem32PhysXLoader.dll
2009-01-04 08:54 77,824 ----a-w c:windowssystem32slmdmco.dll
2009-01-04 08:54 61,440 ----a-w c:windowssystem32slmdmsr.exe
2009-01-04 08:54 221,184 ----a-w c:windowssystem32slmdmsp.dll
2009-01-04 08:54 192,512 ----a-w c:windowssystem32slmdmgx.dll
2008-12-20 22:47 826,368 ----a-w c:windowssystem32wininet.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"swg"="c:program filesGoogleGoogleToolbarNotifierGoogleToolbarNotifier.exe" [2009-01-04 68856]
"SpybotSD TeaTimer"="c:program filesSpybot - Search & DestroyTeaTimer.exe" [2009-03-05 2260480]
"EPSON Stylus SX600FW(réseau)"="c:windowsSystem32spoolDRIVERSW32X863E_FATIEKE.EXE" [2008-03-05 188928]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"avgnt"="c:program filesAviraAntiVir PersonalEdition Classicavgnt.exe" [2008-06-12 266497]
"UMonit"="c:windowssystem32UMonit.exe" [2007-06-18 200704]
"NvCplDaemon"="c:windowssystem32NvCpl.dll" [2009-02-18 13680640]
"High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2004-10-27 c:windowssystem32HdAShCut.exe]
"nwiz"="nwiz.exe" [2009-02-18 c:windowssystem32
wiz.exe]
"SoundMan"="SOUNDMAN.EXE" [2008-08-19 c:windowsSOUNDMAN.EXE]
"AlcWzrd"="ALCWZRD.EXE" [2008-06-19 c:windowsALCWZRD.EXE]
[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
"CTFMON.EXE"="c:windowssystem32CTFMON.EXE" [2008-04-14 15360]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversiondrivers32]
"VIDC.XFR1"= xfcodec.dll
[HKLM~startupfolderC:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
path=c:documents and settingsAll UsersMenu DémarrerProgrammesDémarrageMicrosoft Office.lnk
backup=c:windowspssMicrosoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregKernelFaultCheck]
c:windowssystem32dumprep 0 -k [X]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregAdobe Reader Speed Launcher]
--a------ 2008-06-12 02:38 34672 c:program filesAdobeReader 9.0Reader
eader_sl.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregCTFMON.EXE]
--a------ 2008-04-14 03:33 15360 c:windowssystem32ctfmon.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregEEventManager]
--------- 2008-05-07 15:28 591696 c:progra~1EPSONS~1EVENTM~1EEventManager.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregISUSPM Startup]
--a------ 2006-11-16 13:55 226224 c:progra~1FICHIE~1INSTAL~1UPDATE~1ISUSPM.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregISUSScheduler]
--a------ 2006-11-16 13:55 86960 c:program filesFichiers communsInstallShieldUpdateServiceissch.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregNeroFilterCheck]
--a------ 2001-07-09 10:50 155648 c:windowssystem32NeroCheck.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregNvMediaCenter]
--a------ 2009-02-18 14:44 86016 c:windowssystem32
vmctray.dll
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregQuickTime Task]
--a------ 2009-01-05 16:18 413696 c:program filesQuickTimeQTTask.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregSunJavaUpdateSched]
--a------ 2009-02-09 08:57 136600 c:program filesJavajre6injusched.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregPRISMSTA.EXE]
-ra------ 2003-08-04 13:54 215552 c:windowssystem32PRISMSTA.exe
[HKEY_LOCAL_MACHINEsoftwaremicrosoftsecurity center]
"AntiVirusDisableNotify"=dword:00000001
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
"%windir%\Network Diagnostic\xpnetdiag.exe"=
"c:\Program Files\Messenger\msmsgs.exe"=
"c:\Program Files\TmNationsForever\TmForever.exe"=
"c:\Program Files\eMule\emule.exe"=
"c:\WINDOWS\system32\PnkBstrA.exe"=
"c:\WINDOWS\system32\PnkBstrB.exe"=
"c:\WINDOWS\system32\dpnsvr.exe"=
"c:\WINDOWS\system32\dxdiag.exe"=
"c:\WINDOWS\system32\sessmgr.exe"=
"c:\WINDOWS\system32\dpvsetup.exe"=
"c:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe"=
"c:\Program Files\Windows Live\Messenger\msnmsgr.exe"=
"c:\Program Files\Activision\Call of Duty - World at War\CoDWaW.exe"=
"c:\Program Files\Activision\Call of Duty - World at War\CoDWaWmp.exe"=
"c:\Program Files\Xfire\Xfire.exe"=
"c:\WINDOWS\system32\mmc.exe"=
"c:\WINDOWS\twain_32\escndv\escfg.exe"=
"c:\WINDOWS\twain_32\escndv\escndv.exe"=
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileGloballyOpenPortsList]
"6434:TCP"= 6434:TCP:emule
"6585:UDP"= 6585:UDP:emule
"28960:TCP"= 28960:TCP:codwaw
"28960:UDP"= 28960:UDP:codwaw1
"3074:UDP"= 3074:UDP:codwaw2
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:program filesMcAfeeSiteAdvisorMcSACore.exe [2009-01-03 206096]
R2 WinDefend;Windows Defender;c:program filesWindows DefenderMsMpEng.exe [2006-11-03 13592]
R3 FIXUSTOR;FIXUSTOR;c:windowssystem32driversfixustor.sys [2009-03-01 12416]
R3 PRISM_A00;CREATIX 802.11g Driver;c:windowssystem32driversPRISMA00.sys [2009-01-03 362688]
S2 gupdate1c99fcfb93ed35e;Service Google Update (gupdate1c99fcfb93ed35e);c:program filesGoogleUpdateGoogleUpdate.exe [2009-03-08 133104]
S3 cpuz130;cpuz130;??c:docume~1fredericLOCALS~1Tempcpuz130cpuz_x32.sys --> c:docume~1fredericLOCALS~1Tempcpuz130cpuz_x32.sys [?]
S3 maconfservice;Ma-Config Service;c:program filesma-config.commaconfservice.exe [2009-03-15 216232]
S3 WPRO_40_1340;WinPcap Packet Driver (WPRO_40_1340);c:windowssystem32driversWPRO_40_1340.sys --> c:windowssystem32driversWPRO_40_1340.sys [?]
.
Contenu du dossier 'Tâches planifiées'
2009-03-14 c:windowsTasksAppleSoftwareUpdate.job
- c:program filesApple Software UpdateSoftwareUpdate.exe [2008-07-30 12:34]
2009-03-16 c:windowsTasksGoogle Software Updater.job
- c:program filesGoogleCommonGoogle UpdaterGoogleUpdaterService.exe [2009-03-08 10:23]
2009-03-16 c:windowsTasksGoogleUpdateTaskMachine.job
- c:program filesGoogleUpdateGoogleUpdate.exe [2009-03-08 10:24]
2009-03-16 c:windowsTasksMP Scheduled Scan.job
- c:program filesWindows DefenderMpCmdRun.exe [2006-11-03 19:20]
.
- - - - ORPHELINS SUPPRIMES - - - -
HKCU-Run-WOOKIT - c:program filesWanadooShell.exe
.
------- Examen supplémentaire -------
.
uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page =
hxxp://www.crawler.com/?tbid=66028
uSearchURL,(Default) =
hxxp://www.google.com/search?q=%s
IE: Add to AMV Converter... - c:program filesMP3 Player Utilities 4.13AMVConvertergrab.html
IE: E&xporter vers Microsoft Excel - c:progra~1MICROS~4Office10EXCEL.EXE/3000
IE: MediaManager tool grab multimedia file - c:program filesMP3 Player Utilities 4.13MediaManagergrab.html
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -
hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
FF - ProfilePath -
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-16 10:59:46
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
HKLMSoftwareMicrosoftWindowsCurrentVersionRun
UMonit = c:windowssystem32UMonit.exe?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
Heure de fin: 2009-03-16 11:01:16
ComboFix-quarantined-files.txt 2009-03-16 10:01:14
Avant-CF: 207 143 886 848 octets libres
Après-CF: 207,172,501,504 octets libres
250 --- E O F --- 2009-03-14 20:08:19