voici le rapport Combofix
il ne m'a pas posé de question
j'ai meme pas du appuyer sur [1]
ComboFix 08-07-18.5 - Gàbor 2008-07-19 18:52:50.1 - NTFSx86
Microsoft Windows XP Edition familiale 5.1.2600.3.1252.33.1036.18.406 [GMT 2:00]
Endroit: C:Documents and SettingsGàborBureauComboFix.exe
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RECUPERATION N'EST PAS INSTALLEE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:WINDOWScookies.ini
C:WINDOWSefoe.exe
C:WINDOWSevgratsm.dll
C:WINDOWSsystem32doheoifg.ini
C:WINDOWSsystem32jxcdisgx.dll
C:WINDOWSsystem32kTuwyyxx.ini
C:WINDOWSsystem32kTuwyyxx.ini2
C:WINDOWSsystem32ljJDuVMG.dll
C:WINDOWSsystem32
rielh.dll
C:WINDOWSsystem32ogfwtimw.ini
C:WINDOWSsystem32pxxcbute.dll
C:WINDOWSsystem32 uvVOGxX.dll
C:WINDOWSsystem32usscfx.dll
C:WINDOWSsystem32vkzygg.dll
C:WINDOWSsystem32wjwgytcl.dll
C:WINDOWSsystem32wmitwfgo.dll
C:WINDOWSsystem32wuforwea.dll
C:WINDOWSsystem32xgsidcxj.ini
C:WINDOWSsystem32xxyywuTk.dll
.
((((((((((((((((((((((((((((( Fichiers cr,,s 2008-06-19 to 2008-07-19 ))))))))))))))))))))))))))))))))))))
.
2008-07-16 22:02 . 2008-07-16 22:02 <REP> d-------- C:Documents and SettingsAll UsersApplication DataSecuriSoft SARL
2008-07-16 22:02 . 2008-07-16 18:32 98,304 --a------ C:WINDOWSagpqlrfm.exe
2008-07-03 15:13 . 2008-07-03 15:13 <REP> d-------- C:Program Filesmp3split
2008-06-27 19:11 . 2008-06-27 19:11 <REP> d-------- C:Program FilesFichiers communsWise Installation Wizard
2008-06-26 01:29 . 2008-06-26 01:29 <REP> d-------- C:Program FilesMSXML 4.0
2008-06-22 10:37 . 2008-06-22 10:37 <REP> d-------- C:Program FilesOverland
2008-06-20 19:47 . 2008-06-20 19:47 247,808 -----c--- C:WINDOWSsystem32dllcachemswsock.dll
2008-06-20 19:47 . 2008-06-20 19:47 147,968 -----c--- C:WINDOWSsystem32dllcachednsapi.dll
2008-06-20 13:51 . 2008-06-20 13:51 361,600 -----c--- C:WINDOWSsystem32dllcache cpip.sys
2008-06-20 13:40 . 2008-06-20 13:40 138,496 -----c--- C:WINDOWSsystem32dllcacheafd.sys
2008-06-20 13:08 . 2008-06-20 13:08 225,856 -----c--- C:WINDOWSsystem32dllcache cpip6.sys
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-19 17:01 --------- d-----w C:Program FileseMule
2008-06-20 11:51 361,600 ----a-w C:WINDOWSsystem32drivers cpip.sys
2008-06-20 11:40 138,496 ----a-w C:WINDOWSsystem32driversafd.sys
2008-06-20 11:08 225,856 ----a-w C:WINDOWSsystem32drivers cpip6.sys
2008-06-17 18:30 --------- d-----w C:Program FilesYahoo!
2008-06-14 17:33 272,768 ------w C:WINDOWSsystem32driversthport.sys
2008-06-11 09:01 --------- d-----w C:Documents and SettingsAll UsersApplication DataYahoo!
2008-06-05 10:46 --------- d-----w C:Program FilesMP3Gain
2008-05-23 07:23 --------- d-----w C:Program FilesHP
2008-05-23 07:23 --------- d-----w C:Program FilesHewlett-Packard
2008-05-20 17:26 --------- d-----w C:Program FilesJava
2008-05-20 17:24 --------- d-----w C:Program FilesFichiers communsJava
2008-05-19 14:32 --------- d--h--w C:Program FilesInstallShield Installation Information
2008-05-19 14:32 --------- d-----w C:Program FilesPhilips ToUcam Camera
2008-05-19 14:32 --------- d-----w C:Program FilesPhilips CSI
2008-05-19 14:31 --------- d-----w C:Program FilesFichiers communsInstallShield
2008-05-15 12:52 65,536 ----a-w C:WINDOWSIFinst27.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ,l,ments vides & les ,l,ments initiaux l,gitimes ne sont pas list,s
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"MsnMsgr"="C:Program FilesWindows LiveMessengerMsnMsgr.Exe" [2007-10-18 11:34 5724184]
"ctfmon.exe"="C:WINDOWSsystem32ctfmon.exe" [2008-04-14 04:33 15360]
"eMuleAutoStart"="C:Program FileseMuleemule.exe" [2007-05-13 16:57 5308416]
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"IMJPMIG8.1"="C:WINDOWSIMEimjp8_1IMJPMIG.EXE" [2004-08-04 07:31 208952]
"PHIME2002ASync"="C:WINDOWSSystem32IMETINTLGNTTINTSETP.EXE" [2004-08-04 07:32 455168]
"PHIME2002A"="C:WINDOWSSystem32IMETINTLGNTTINTSETP.EXE" [2004-08-04 07:32 455168]
"AzMixerSel"="C:Program FilesRealtekInstallShieldAzMixerSel.exe" [2006-01-25 18:45 53248]
"IgfxTray"="C:WINDOWSsystem32igfxtray.exe" [2007-01-13 09:47 131072]
"HotKeysCmds"="C:WINDOWSsystem32hkcmd.exe" [2007-01-13 09:47 163840]
"Persistence"="C:WINDOWSsystem32igfxpers.exe" [2007-01-13 09:46 135168]
"Adobe Reader Speed Launcher"="C:Program FilesAdobeReader 8.0ReaderReader_sl.exe" [2008-01-11 22:16 39792]
"SunJavaUpdateSched"="C:Program FilesJavajre1.6.0_06injusched.exe" [2008-03-25 04:28 144784]
"HP Software Update"="C:Program FilesHewlett-PackardHP Software UpdateHPWuSchd.exe" [2003-06-25 11:24 49152]
"HP Component Manager"="C:Program FilesHPhpcoretechhpcmpmgr.exe" [2004-05-12 15:18 241664]
"HPDJ Taskbar Utility"="C:WINDOWSsystem32spooldriversw32x863hpztsb09.exe" [2003-09-01 13:42 176128]
[HKEY_USERS.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun]
"CTFMON.EXE"="C:WINDOWSSystem32CTFMON.EXE" [2008-04-14 04:33 15360]
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindows ntcurrentversiondrivers32]
"msacm.l3acm"= l3codecp.acm
[HKLM~servicessharedaccessparametersfirewallpolicystandardprofileAuthorizedApplicationsList]
"%windir%\system32\sessmgr.exe"=
"%windir%\Network Diagnostic\xpnetdiag.exe"=
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"=
"C:\Program Files\Windows Live\Messenger\livecall.exe"=
"C:\Program Files\eMule\emule.exe"=
"C:\WINDOWS\system32\mshta.exe"=
R1 aswSP;avast! Self Protection;C:WINDOWSsystem32driversaswSP.sys [2008-05-16 01:20]
R2 aswFsBlk;aswFsBlk;C:WINDOWSsystem32DRIVERSaswFsBlk.sys [2008-05-16 01:16]
R2 NMSAccessU;NMSAccessU;C:Program FilesCDBurnerXPNMSAccessU.exe [2008-03-09 11:20]
R3 SPI;Périphérique de contrôle d'E/S programmable Sony;C:WINDOWSsystem32DRIVERSSonyPI.sys [2001-08-17 21:51]
R3 ti21sony;ti21sony;C:WINDOWSsystem32drivers i21sony.sys [2007-04-23 13:29]
S3 Camdrv30;Philips ToUcam XS;C:WINDOWSsystem32Driverscamdrv30.sys [2001-08-17 22:04]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-07-19 19:01:14
Windows 5.1.2600 Service Pack 3 NTFS
Balayage processus cach,s ...
Balayage cach, autostart entries ...
Balayage des fichiers cach,s ...
Scan termin, avec succSs
Les fichiers cach,s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:Program FilesIntelWirelessBinEvtEng.exe
C:Program FilesIntelWirelessBinS24EvMon.exe
C:Program FilesAlwil SoftwareAvast4aswUpdSv.exe
C:Program FilesAlwil SoftwareAvast4ashServ.exe
C:Program FilesIntelWirelessBinRegSrvc.exe
C:Program FilesAlwil SoftwareAvast4ashMaiSv.exe
C:Program FilesAlwil SoftwareAvast4ashWebSv.exe
C:Program FilesWinZipWZQKPICK.EXE
C:Program FilesToshibaBluetooth Toshiba StackTosBtMng.exe
C:Program FilesToshibaBluetooth Toshiba StackTosA2dp.exe
C:Program FilesToshibaBluetooth Toshiba StackTosBtHid.exe
C:Program FilesToshibaBluetooth Toshiba StackTosBtHSP.exe
C:Program FilesToshibaBluetooth Toshiba StackTosOBEX.exe
C:Program FilesToshibaBluetooth Toshiba StackTosBtProc.exe
C:Program FilesWindows LiveMessengerusnsvc.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-07-19 19:06:09 - machine was rebooted
ComboFix-quarantined-files.txt 2008-07-19 17:05:38
Pre-Run: 11,954,282,496 octets libres
Post-Run: 12,142,841,856 octets libres
137 --- E O F --- 2008-07-09 09:59:44