Bonjour,
svp jlpjlp aide-moi jé ri1 pu faire!!
jé besoin de votre aide les gars
c le rsultat du scan avec combofix
ComboFix 08-09-05.12 - user 2008-09-10 0:32:36.3 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.1565 [GMT 2:00]
Endroit: C:\Documents and Settings\user\Bureau\ComboFix.exe
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\PCHealthCenter
.
((((((((((((((((((((((((((((( Fichiers créés 2008-08-09 to 2008-09-09 ))))))))))))))))))))))))))))))))))))
.
2008-09-09 23:17 . 2008-09-09 23:17 <REP> d-------- C:\Program Files\Enigma Software Group
2008-09-09 19:23 . 2008-09-08 17:32 3,262 --a------ C:\WINDOWS\system32\2.ico
2008-09-09 19:15 . 2008-09-09 19:15 <REP> d-------- C:\Program Files\MSA
2008-09-09 19:15 . 2008-09-09 19:15 581,120 ---hs---- C:\Documents and Settings\user\css.exe
2008-09-09 19:15 . 2008-09-08 16:50 165,888 --a------ C:\WINDOWS\system32\MSa.cpl
2008-09-09 19:15 . 2008-09-08 17:32 31,232 --a------ C:\x
2008-09-09 19:15 . 2008-09-08 17:32 3,262 --a------ C:\WINDOWS\system32\1.ico
2008-09-09 19:14 . 2008-09-09 19:15 519,168 ---hs---- C:\Documents and Settings\user\intelOP.exe
2008-09-09 19:14 . 2008-09-09 19:14 73,728 ---hs---- C:\Documents and Settings\user\MediaTubeCodec_ver1.1463.0.exe
2008-09-09 19:07 . 2008-09-09 19:33 <REP> d-------- C:\Program Files\CONVERT
2008-09-09 19:07 . 2008-09-09 19:08 294,912 --------- C:\WINDOWS\Setup1.exe
2008-09-09 19:07 . 2008-09-09 19:08 73,216 --a------ C:\WINDOWS\ST6UNST.EXE
2008-09-09 17:31 . 2008-09-09 17:41 <REP> d-------- C:\Documents and Settings\user\Application Data\REAPER
2008-09-08 18:51 . 2008-09-08 18:51 <REP> d-------- C:\Downloads
2008-09-08 18:51 . 2008-09-08 18:57 <REP> d-------- C:\Documents and Settings\user\Application Data\GetRightToGo
2008-09-08 14:13 . 2008-09-08 14:24 <REP> d-------- C:\djp
2008-09-08 14:03 . 2008-09-08 14:03 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-09-08 13:42 . 2008-09-08 13:42 <REP> d-------- C:\Program Files\Messenger Plus! Live
2008-09-08 13:42 . 2008-09-08 13:42 <REP> d-------- C:\Program Files\Circle Developement
2008-09-08 13:02 . 2008-09-08 13:42 <REP> d-------- C:\Program Files\Audacity
2008-09-08 12:36 . 2008-09-08 16:55 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb
2008-09-08 12:36 . 2008-09-08 16:55 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb
2008-09-08 12:27 . 2008-09-08 16:51 <REP> d-------- C:\Program Files\The KMPlayer FR
2008-09-07 17:29 . 2008-09-07 17:29 268 --ah----- C:\sqmdata05.sqm
2008-09-07 17:29 . 2008-09-07 17:29 244 --ah----- C:\sqmnoopt05.sqm
2008-09-05 15:09 . 2008-09-09 17:53 <REP> d-------- C:\Program Files\AskTBar
2008-09-05 13:37 . 2008-09-08 13:32 <REP> d-------- C:\Program Files\Windows Media Connect 2
2008-09-05 13:36 . 2008-09-05 13:36 <REP> d-------- C:\WINDOWS\system32\LogFiles
2008-09-05 13:36 . 2008-09-08 13:32 <REP> d-------- C:\WINDOWS\system32\drivers\UMDF
2008-09-02 16:20 . 2008-09-02 16:20 <REP> d-------- C:\Documents and Settings\user\Application Data\FaxCtr
2008-09-02 14:51 . 2008-09-02 14:51 <REP> d-------- C:\Program Files\Lexmark Fax Solutions
2008-09-02 14:51 . 2008-09-02 14:51 <REP> d-------- C:\Documents and Settings\All Users\Application Data\FaxCtr
2008-09-02 14:51 . 2006-04-28 11:16 339,968 --a------ C:\WINDOWS\system32\IMGMAN32.DLL
2008-09-02 14:51 . 2006-04-28 11:16 98,345 --a------ C:\WINDOWS\system32\IMHOST32.DLL
2008-09-02 14:51 . 2006-04-28 11:16 98,304 --a------ C:\WINDOWS\system32\IM31XPNG.DEL
2008-09-02 14:51 . 2006-04-28 11:16 69,632 --a------ C:\WINDOWS\system32\IM31XTIF.DEL
2008-09-02 14:51 . 2006-04-28 11:16 49,152 --a------ C:\WINDOWS\system32\IM31IMG.DIL
2008-09-02 14:51 . 2006-11-22 15:51 45,056 --a------ C:\WINDOWS\system32\LXPRMON.DLL
2008-09-02 14:51 . 2006-11-22 15:50 32,768 --a------ C:\WINDOWS\system32\LXPMONUI.DLL
2008-09-02 14:51 . 2006-11-22 16:08 12,288 --a------ C:\WINDOWS\system32\LXPMONRC.DLL
2008-09-02 14:50 . 2008-09-09 22:55 <REP> d-------- C:\Program Files\Abbyy FineReader 6.0 Sprint
2008-09-02 14:47 . 2008-09-02 14:51 <REP> d-------- C:\Program Files\Lexmark 1200 Series
2008-09-02 14:46 . 2006-12-21 00:06 1,224,704 --a------ C:\WINDOWS\system32\lxczserv.dll
2008-09-01 19:15 . 2006-11-29 13:06 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
2008-09-01 19:15 . 2006-09-28 16:05 2,414,360 --a------ C:\WINDOWS\system32\d3dx9_31.dll
2008-09-01 19:15 . 2007-01-24 15:27 255,848 --a------ C:\WINDOWS\system32\xactengine2_6.dll
2008-09-01 19:15 . 2006-12-08 12:02 251,672 --a------ C:\WINDOWS\system32\xactengine2_5.dll
2008-09-01 19:15 . 2006-09-28 16:05 237,848 --a------ C:\WINDOWS\system32\xactengine2_4.dll
2008-09-01 19:15 . 2006-09-28 16:04 68,888 --a------ C:\WINDOWS\system32\xinput1_3.dll
2008-09-01 19:15 . 2007-01-08 15:30 15,128 --a------ C:\WINDOWS\system32\x3daudio1_1.dll
2008-09-01 17:32 . 2008-09-01 17:32 307 --a------ C:\WINDOWS\game.ini
2008-09-01 17:06 . 2008-09-01 17:06 <REP> d--hs---- C:\WINDOWS\ftpcache
2008-08-31 21:13 . 2008-08-31 21:14 <REP> d-------- C:\Program Files\Ares
2008-08-27 15:44 . 2008-08-30 21:03 <REP> d-------- C:\WINDOWS\system32\CatRoot_bak
2008-08-24 16:29 . 2008-08-24 16:29 268 --ah----- C:\sqmdata04.sqm
2008-08-24 16:29 . 2008-08-24 16:29 244 --ah----- C:\sqmnoopt04.sqm
2008-08-10 21:45 . 2008-08-10 21:45 <REP> d-------- C:\Program Files\Free Audio Pack
2008-08-10 21:45 . 1998-06-17 01:00 516,173 --a------ C:\WINDOWS\system32\MSVCP60D.DLL
2008-08-10 21:45 . 1998-06-17 01:00 385,100 --a------ C:\WINDOWS\system32\MSVCRTD.DLL
2008-08-10 21:45 . 2003-08-07 17:01 237,568 --a------ C:\WINDOWS\system32\lame_enc.dll
2008-08-09 16:54 . 2008-08-09 16:54 268 --ah----- C:\sqmdata03.sqm
2008-08-09 16:54 . 2008-08-09 16:54 244 --ah----- C:\sqmnoopt03.sqm
2008-08-09 16:12 . 2008-08-09 16:12 268 --ah----- C:\sqmdata02.sqm
2008-08-09 16:12 . 2008-08-09 16:12 244 --ah----- C:\sqmnoopt02.sqm
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-09 16:58 --------- d-----w C:\Program Files\VideoLAN
2008-09-06 18:50 --------- d-----w C:\Documents and Settings\user\Application Data\skypePM
2008-09-06 18:50 --------- d-----w C:\Documents and Settings\user\Application Data\Skype
2008-09-05 13:02 --------- d-----w C:\Program Files\dBpowerAMP
2008-09-01 15:32 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-27 22:00 --------- d-----w C:\Program Files\Dealio
2008-08-10 19:48 --------- d-----w C:\Program Files\Search Settings
2008-08-10 14:01 --------- d-----w C:\Documents and Settings\user\Application Data\gtk-2.0
2008-07-27 19:09 --------- d-----w C:\Program Files\BearShare Applications
2008-07-26 21:33 --------- d-----w C:\Documents and Settings\user\Application Data\BearShare
2008-07-24 00:14 --------- d-----w C:\Documents and Settings\user\Application Data\Media Live Each
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
2008-07-07 20:31 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 15:40 663,552 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:37 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2008-04-11 17:25 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
.
((((((((((((((((((((((((((((( snapshot@2008-09-10_ 0.27.22.04 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-09-09 22:31:50 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_5ec.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9CB65206-89C4-402c-BA80-02D8C59F9B1D}"= "C:\Program Files\AskTBar\SrchAstt\2.bin\A5SRCHAS.DLL" [2008-09-05 57344]
[HKEY_CLASSES_ROOT\clsid\{9cb65206-89c4-402c-ba80-02d8c59f9b1d}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ares"="C:\Program Files\Ares\Ares.exe" [2008-08-21 888832]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe" [2005-08-26 36975]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 155648]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2007-12-19 131072]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-18 8523776]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-18 81920]
"FixCamera"="C:\WINDOWS\FixCamera.exe" [2007-02-10 20480]
"Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2005-10-26 159744]
"tsnpstd3"="C:\WINDOWS\tsnpstd3.exe" [2007-07-10 270336]
"snpstd3"="C:\WINDOWS\vsnpstd3.exe" [2007-05-10 835584]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-05-15 185896]
"SearchSettings"="C:\Program Files\Search Settings\SearchSettings.exe" [2008-06-12 991584]
"lxczbmgr.exe"="C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe" [2007-02-09 74672]
"FaxCenterServer"="C:\Program Files\Lexmark Fax Solutions\fm3032.exe" [2007-02-09 295856]
"ANTIVIRUS"="C:\Program Files\MSA\MSA.exe" [2008-09-08 396800]
"Raccourci vers la page des propriétés de High Definition Audio"="HDAShCut.exe" [2005-01-07 C:\WINDOWS\system32\HdAShCut.exe]
"VTTimer"="VTTimer.exe" [2006-09-21 C:\WINDOWS\system32\VTTimer.exe]
"S3Trayp"="S3trayp.exe" [2006-10-10 C:\WINDOWS\system32\S3Trayp.exe]
"RTHDCPL"="RTHDCPL.EXE" [2006-10-30 C:\WINDOWS\RTHDCPL.EXE]
"SkyTel"="SkyTel.EXE" [2006-05-16 C:\WINDOWS\SkyTel.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\Ares\\Ares.exe"=
"C:\\WINDOWS\\system32\\lxczcoms.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"443:TCP"= 443:TCP:TCP port 443 ooVoo
"443:UDP"= 443:UDP:UDP port 443 ooVoo
"37674:TCP"= 37674:TCP:TCP port 37674 ooVoo
"37674:UDP"= 37674:UDP:UDP port 37674 ooVoo
"37675:UDP"= 37675:UDP:UDP port 37675 ooVoo
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
R2 lxcz_device;lxcz_device;C:\WINDOWS\system32\lxczcoms.exe [2007-02-09 537520]
R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 S3GIGP;S3GIGP;C:\WINDOWS\system32\DRIVERS\S3gIGPm.sys [2006-11-15 634880]
S3 SMCWGU(SMC);SMCWUSB-G 802.11g Wireless USB 2.0 Adapter(SMC);C:\WINDOWS\system32\DRIVERS\SMCWGU.sys [ ]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3c96241e-30be-11dd-b972-001bb9fb5961}]
\Shell\AutoRun\command - ntde1ect.com
\Shell\explore\Command - ntde1ect.com
\Shell\open\Command - ntde1ect.com
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3c96241f-30be-11dd-b972-001bb9fb5961}]
\Shell\AutoRun\command - 1.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8641beff-d0d2-11dc-ba79-001bb9f98ae1}]
\Shell\AutoRun\command - ylr.exe
\Shell\explore\Command - ylr.exe
\Shell\open\Command - ylr.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{95afa69c-32ed-11dd-b983-001bb9fb5961}]
\Shell\AutoRun\command - ntde1ect.com
\Shell\explore\Command - ntde1ect.com
\Shell\open\Command - ntde1ect.com
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
.
- - - - ORPHANS REMOVED - - - -
URLSearchHooks-{E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
.
------- Supplementary Scan -------
.
FireFox -: Profile - C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\3wirqhko.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://fr.search.yahoo.com/search?ei=UTF-8&fr=ytff-msgr&p=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://fr.start2.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:fr:official
FF -: plugin - C:\Program Files\Java\jre1.5.0_05\bin\NPJava11.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_05\bin\NPJava12.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_05\bin\NPJava13.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_05\bin\NPJava14.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_05\bin\NPJava32.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_05\bin\NPJPI150_05.dll
FF -: plugin - C:\Program Files\Java\jre1.5.0_05\bin\NPOJI610.dll
FF -: plugin - C:\Program Files\ma-config.com\nphardwaredetection.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-10 00:34:09
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
.
Temps d'accomplissement: 2008-09-10 0:35:05
ComboFix-quarantined-files.txt 2008-09-09 22:34:54
ComboFix2.txt 2008-09-09 22:27:42
Pre-Run: 346,549,559,296 octets libres
Post-Run: 346,535,546,880 octets libres
219 --- E O F --- 2008-09-08 15:31:17
Afficher la suite