re!
voici le log de combofix, il est trop long pour le poster une seule fois don je le divise:
ComboFix 08-10-25.01 - Administrateur 2008-10-27 15:41:05.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.222 [GMT 1:00]
Lancé depuis: C:\Documents and Settings\Administrateur\Bureau\ComboFix.exe
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Autorun.inf
C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\SuggestedSites.dat
C:\WINDOWS\autorun.inf
C:\WINDOWS\IE4 Error Log.txt
.
((((((((((((((((((((((((((((( Fichiers créés du 2008-09-27 au 2008-10-27 ))))))))))))))))))))))))))))))))))))
.
2008-10-24 16:36 . 2008-10-24 16:36 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-24 16:36 . 2008-10-24 16:36 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-24 16:36 . 2008-10-24 16:36 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Malwarebytes
2008-10-24 16:36 . 2008-10-22 15:10 38,496 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-10-24 16:36 . 2008-10-22 15:10 15,504 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-10-23 14:11 . 2008-10-23 14:16 <REP> d-------- C:\quarantine
2008-10-23 14:11 . 2008-10-23 14:11 <REP> d-------- C:\Program Files\Trend Micro
2008-10-23 09:50 . 2006-07-01 01:21 <REP> d--h----- C:\Documents and Settings\Walid\Voisinage réseau
2008-10-23 09:50 . 2006-07-01 01:21 <REP> d--h----- C:\Documents and Settings\Walid\Voisinage d'impression
2008-10-23 09:50 . 2006-07-01 01:21 <REP> d--h----- C:\Documents and Settings\Walid\Modèles
2008-10-23 09:50 . 2008-10-23 09:51 <REP> dr------- C:\Documents and Settings\Walid\Mes documents
2008-10-23 09:50 . 2006-07-01 01:21 <REP> dr------- C:\Documents and Settings\Walid\Menu Démarrer
2008-10-23 09:50 . 2008-10-23 09:51 <REP> dr------- C:\Documents and Settings\Walid\Favoris
2008-10-23 09:50 . 2006-07-01 01:21 <REP> d-------- C:\Documents and Settings\Walid\Bureau
2008-10-23 09:50 . 2006-07-01 01:21 <REP> d-------- C:\Documents and Settings\Walid\Application Data\Symantec
2008-10-23 09:50 . 2006-07-01 01:21 <REP> d-------- C:\Documents and Settings\Walid\Application Data\Sonic
2008-10-23 09:50 . 2008-10-23 09:50 <REP> d-------- C:\Documents and Settings\Walid
2008-10-23 09:50 . 2008-10-23 09:50 <REP> d-------- C:\Documents and Settings\LocalService\Menu Démarrer
2008-10-23 09:22 . 2008-10-27 15:44 <REP> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-23 09:21 . 2008-10-23 09:21 <REP> d-------- C:\Program Files\ThreatFire
2008-10-23 09:21 . 2008-10-23 09:21 <REP> d-------- C:\Documents and Settings\All Users\Application Data\PC Tools
2008-10-23 09:21 . 2008-04-24 15:52 51,520 --a------ C:\WINDOWS\system32\drivers\TfFsMon.sys
2008-10-23 09:21 . 2008-04-24 15:52 38,208 --a------ C:\WINDOWS\system32\drivers\TfSysMon.sys
2008-10-23 09:21 . 2008-04-24 15:52 33,088 --a------ C:\WINDOWS\system32\drivers\TfNetMon.sys
2008-10-23 09:21 . 2008-04-24 15:52 12,608 --a------ C:\WINDOWS\system32\drivers\TfKbMon.sys
2008-10-22 00:45 . 2007-06-18 16:09 63,826 --a------ C:\WINDOWS\system32\pubnet.vbs
2008-10-22 00:45 . 2008-10-22 00:45 30,446 --a------ C:\WINDOWS\system32\nansy.jpg
2008-10-20 03:32 . 2008-10-20 03:32 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2008-10-19 22:02 . 2008-08-11 09:02 90,295 -r-hs---- C:\r2nl.com
2008-10-19 21:31 . 2007-07-30 18:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
2008-10-19 21:31 . 2007-07-30 18:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
2008-10-19 21:31 . 2007-07-30 18:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
2008-10-18 12:51 . 2008-10-18 12:51 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
2008-10-18 12:50 . 2008-10-18 12:50 <REP> d-------- C:\Program Files\Windows Live
2008-10-18 12:50 . 2008-10-18 12:55 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-10-16 00:26 . 2006-08-21 10:14 128,896 --------- C:\WINDOWS\system32\dllcache\fltmgr.sys
2008-10-16 00:26 . 2006-08-21 10:14 23,040 --------- C:\WINDOWS\system32\dllcache\fltmc.exe
2008-10-16 00:26 . 2006-08-21 13:26 16,896 --------- C:\WINDOWS\system32\dllcache\fltlib.dll
2008-10-15 23:26 . 2008-10-15 23:26 <REP> d-------- C:\WINDOWS\Sun
2008-10-15 17:48 . 2008-08-28 11:04 333,056 --------- C:\WINDOWS\system32\dllcache\srv.sys
2008-10-15 17:45 . 2008-08-14 14:44 2,182,400 --------- C:\WINDOWS\system32\dllcache\ntoskrnl.exe
2008-10-15 17:45 . 2008-08-14 14:44 2,138,112 --------- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
2008-10-15 17:45 . 2008-08-14 14:44 2,059,776 --------- C:\WINDOWS\system32\dllcache\ntkrnlpa.exe
2008-10-15 17:45 . 2008-08-14 14:44 2,017,792 --------- C:\WINDOWS\system32\dllcache\ntkrpamp.exe
2008-10-15 02:09 . 2008-10-15 02:09 <REP> d-------- C:\Program Files\MSXML 4.0
2008-10-15 01:58 . 2008-10-22 11:58 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\skypePM
2008-10-15 01:58 . 2008-10-15 01:58 48 --ah----- C:\WINDOWS\system32\ezsidmv.dat
2008-10-15 01:56 . 2008-10-15 01:56 <REP> d-------- C:\Program Files\Google
2008-10-15 01:56 . 2008-10-15 01:56 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Skype
2008-10-14 16:30 . 2008-10-22 21:49 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-10-14 11:09 . 2007-07-09 14:11 584,192 --------- C:\WINDOWS\system32\dllcache\rpcrt4.dll
2008-10-14 11:00 . 2008-05-08 13:28 202,752 --------- C:\WINDOWS\system32\dllcache\rmcast.sys
2008-10-14 10:59 . 2008-05-01 15:31 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll
2008-10-14 10:57 . 2008-04-11 19:51 683,520 --------- C:\WINDOWS\system32\dllcache\inetcomm.dll
2008-10-14 01:04 . 2008-06-14 18:59 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-10-14 01:04 . 2008-06-14 18:59 272,768 --------- C:\WINDOWS\system32\dllcache\bthport.sys
2008-10-13 08:35 . 2008-10-14 13:40 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Winamp
2008-10-12 00:52 . 2008-10-12 00:52 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Yahoo!
2008-10-12 00:41 . 2008-10-22 21:50 <REP> d-------- C:\Program Files\Yahoo!
2008-10-11 23:58 . 2008-10-11 23:58 <REP> d--hs---- C:\Documents and Settings\Administrateur\PrivacIE
2008-10-11 23:50 . 2008-06-12 10:28 26,144 --a------ C:\WINDOWS\system32\spupdsvc.exe
2008-10-11 23:48 . 2008-10-11 23:50 <REP> d-------- C:\WINDOWS\system32\fr-fr
2008-10-11 23:48 . 2008-10-11 23:50 <REP> d--h-c--- C:\WINDOWS\ie8
2008-10-11 00:16 . 2008-10-11 00:16 <REP> d-------- C:\Program Files\Winamp Toolbar
2008-10-11 00:16 . 2008-10-11 00:16 <REP> d-------- C:\Program Files\Winamp Remote
2008-10-11 00:16 . 2008-10-11 00:16 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Winamp Toolbar
2008-10-11 00:16 . 2008-10-11 10:39 <REP> d-------- C:\Documents and Settings\All Users\Application Data\OrbNetworks
2008-10-11 00:03 . 2007-03-08 00:51 129,784 --------- C:\WINDOWS\system32\pxafs.dll
2008-10-11 00:03 . 2007-03-08 00:51 9,464 --------- C:\WINDOWS\system32\drivers\cdralw2k.sys
2008-10-11 00:03 . 2007-03-08 00:51 9,336 --------- C:\WINDOWS\system32\drivers\cdr4_xp.sys
2008-10-10 16:11 . 2008-10-10 16:11 <REP> d--hs---- C:\Documents and Settings\Administrateur\UserData
2008-10-10 14:26 . 2008-10-20 20:04 512 --a------ C:\WINDOWS\randseed.rnd
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-19 20:56 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\AdobeUM
2008-10-13 07:36 --------- d-----w C:\Program Files\Winamp
2008-09-15 15:39 1,846,144 ----a-w C:\WINDOWS\system32\win32k.sys
2008-09-15 15:39 1,846,144 ------w C:\WINDOWS\system32\dllcache\win32k.sys
2008-09-08 22:23 637,984 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
2008-08-28 10:04 333,056 ----a-w C:\WINDOWS\system32\drivers\srv.sys
2008-08-22 01:09 5,699,584 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
2008-08-22 01:08 878,592 ----a-w C:\WINDOWS\system32\wininet.dll
2008-08-22 01:08 878,592 ------w C:\WINDOWS\system32\dllcache\wininet.dll
2008-08-22 01:08 43,008 ----a-w C:\WINDOWS\system32\licmgr10.dll
2008-08-22 01:08 43,008 ------w C:\WINDOWS\system32\dllcache\licmgr10.dll
2008-08-22 01:08 236,544 ------w C:\WINDOWS\system32\dllcache\webcheck.dll
2008-08-22 01:08 1,206,784 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
2008-08-22 01:07 755,200 ------w C:\WINDOWS\system32\dllcache\VGX.dll
2008-08-22 01:07 193,536 ------w C:\WINDOWS\system32\dllcache\msrating.dll
2008-08-22 01:07 18,944 ----a-w C:\WINDOWS\system32\corpol.dll
2008-08-22 01:07 18,944 ------w C:\WINDOWS\system32\dllcache\corpol.dll
2008-08-22 01:07 116,224 ------w C:\WINDOWS\system32\dllcache\occache.dll
2008-08-22 01:07 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll
2008-08-22 01:05 70,656 ------w C:\WINDOWS\system32\dllcache\mshtmled.dll
2008-08-22 01:05 630,272 ------w C:\WINDOWS\system32\dllcache\mstime.dll
2008-08-22 01:05 48,640 ------w C:\WINDOWS\system32\PrivacIE.dll
2008-08-22 01:05 48,128 ----a-w C:\WINDOWS\system32\mshtmler.dll
2008-08-22 01:05 48,128 ------w C:\WINDOWS\system32\dllcache\mshtmler.dll
2008-08-22 01:05 45,056 ------w C:\WINDOWS\system32\dllcache\pngfilt.dll
2008-08-22 01:05 35,840 ----a-w C:\WINDOWS\system32\imgutil.dll
2008-08-22 01:05 35,840 ------w C:\WINDOWS\system32\dllcache\imgutil.dll
2008-08-22 01:05 346,624 ------w C:\WINDOWS\system32\dllcache\dxtmsft.dll
2008-08-22 01:05 217,088 ------w C:\WINDOWS\system32\dllcache\dxtrans.dll
2008-08-22 01:05 186,880 ------w C:\WINDOWS\system32\dllcache\iepeers.dll
2008-08-22 01:04 45,568 ----a-w C:\WINDOWS\system32\mshta.exe
2008-08-22 01:04 45,568 ------w C:\WINDOWS\system32\dllcache\mshta.exe
2008-08-22 01:00 68,608 ------w C:\WINDOWS\system32\dllcache\hmmapi.dll
2008-08-22 00:57 156,160 ----a-w C:\WINDOWS\system32\msls31.dll
2008-08-22 00:57 156,160 ------w C:\WINDOWS\system32\dllcache\msls31.dll
2008-08-14 13:44 2,182,400 ----a-w C:\WINDOWS\system32\ntoskrnl.exe
2008-08-14 13:44 2,059,776 ----a-w C:\WINDOWS\system32\ntkrnlpa.exe
2008-08-14 09:51 138,368 ------w C:\WINDOWS\system32\dllcache\afd.sys
2008-08-05 15:55 265,720 ----a-w C:\WINDOWS\system32\msdbg2.dll
2007-02-02 19:48 401,408 --shatr C:\WINDOWS\system32\ahr.exe
.