j'ai fait combofix.exe , voici le rapport
ComboFix 08-06-01.6 - Nico et Steph 2008-06-02 10:54:43.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.878 [GMT 2:00]
Endroit: C:\Documents and Settings\Nico et Steph\Mes documents\Stephanie DERRE\ComboFix.exe
* Création d'un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Nico et Steph\Favoris\Error Cleaner.url
C:\Documents and Settings\Nico et Steph\Favoris\Privacy Protector.url
C:\Documents and Settings\Nico et Steph\Favoris\Spyware&Malware Protection.url
C:\Documents and Settings\Nico et Steph\ResErrors.log
C:\Program Files\iSecurity
C:\Program Files\iSecurity\{0C09EA49-E55C-481a-87F2-49DACBE8E8BD}\install.exe
C:\Program Files\iSecurity\{A39F804A-4A63-4ff2-B201-23B0E2CC8474}\install.exe
C:\Program Files\iSecurity\axpdefender.bmp
C:\Program Files\iSecurity\axpdefender.ico
C:\Program Files\iSecurity\axpdefenderi.bmp
C:\Program Files\iSecurity\axpfixer.bmp
C:\Program Files\iSecurity\axpfixer.ico
C:\Program Files\iSecurity\axpfixeri.bmp
C:\Program Files\iSecurity\iSecurity.dat
C:\Program Files\iSecurity\systemdefender.bmp
C:\Program Files\iSecurity\systemdefender.ico
C:\Program Files\iSecurity\systemdefenderi.bmp
C:\Program Files\iSecurity\Thumbs.db
C:\Program Files\tmp0.exe
C:\Program Files\tmp1.exe
C:\Program Files\tmp2.exe
C:\WINDOWS\atfxqogp.dll
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\setup.inf
C:\WINDOWS\privacy_danger
C:\WINDOWS\system32\818646
C:\WINDOWS\system32\byXqqNFW.dll
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\wupjfgbh.ini
C:\WINDOWS\system32\xwbyefjc.ini
C:\WINDOWS\system32\yGPooUvw.ini
C:\WINDOWS\system32\yGPooUvw.ini2
C:\WINDOWS\system32\ylildfys.ini
C:\WINDOWS\vregfwlx.dll
C:\WINDOWS\xmpstean.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_DHLP
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-05-02 to 2008-06-02 ))))))))))))))))))))))))))))))))))))
.
2018-05-17 02:42 . 2018-05-17 02:42 3,120 --a--c--- C:\WINDOWS\MF_C421.lfa
2018-05-17 02:42 . 2018-05-17 02:42 3,120 --a--c--- C:\WINDOWS\MF_C420.lfa
2008-06-01 23:17 . 2008-06-01 23:17 <REP> d-------- C:\kav
2008-06-01 21:29 . 2008-06-01 21:29 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-06-01 21:11 . 2008-06-01 21:11 <REP> d-------- C:\VundoFix Backups
2008-06-01 21:11 . 2008-06-01 21:11 <REP> d-------- C:\Documents and Settings\LocalService\Mes documents
2008-06-01 18:12 . 2008-06-01 18:12 <REP> d-------- C:\Documents and Settings\Nico et Steph\Application Data\Grisoft
2008-06-01 18:11 . 2008-06-01 18:11 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-06-01 18:11 . 2007-05-30 14:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-05-31 12:49 . 2008-06-01 23:23 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-05-29 11:40 . 2008-05-29 11:42 <REP> d-------- C:\WINDOWS\system32\NtmsData
2008-05-28 23:30 . 2008-05-28 23:30 36,336,033 --a------ C:\WINDOWS\VPTNFILE.305
2008-05-28 23:30 . 2008-05-28 23:30 36,336,033 --a------ C:\WINDOWS\LPT$VPN.305
2008-05-28 23:29 . 2008-05-28 23:30 <REP> d-------- C:\WINDOWS\AU_Temp
2008-05-28 18:13 . 2008-06-01 23:31 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-05-28 18:13 . 2008-06-01 23:31 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-05-28 18:08 . 2008-06-01 23:31 <REP> d-------- C:\Program Files\Yahoo!
2008-05-28 17:32 . 2008-05-28 17:32 <REP> d-------- C:\Program Files\Trend Micro
2008-05-28 15:47 . 2008-05-31 14:33 <REP> d-------- C:\Program Files\IE Extensions
2008-05-28 15:37 . 2008-05-28 15:37 <REP> d-------- C:\Documents and Settings\Nico et Steph\Application Data\AXPDefender
2008-05-28 14:41 . 2008-05-28 14:41 <REP> d-------- C:\Program Files\Alwil Software
2008-05-27 21:52 . 2008-05-27 21:52 <REP> d--hs---- C:\AntivirusFiable
2008-05-27 21:44 . 2008-05-27 21:44 <REP> d-------- C:\Documents and Settings\Nico et Steph\Application Data\AntivirusFiable
2008-05-27 20:37 . 2008-05-27 20:37 <REP> dr------- C:\Documents and Settings\All Users\Application Data\SalesMon
2008-05-27 20:34 . 2004-10-07 14:39 1,060,864 --a------ C:\WINDOWS\system32\mfc71.dll
2008-05-27 20:34 . 2004-10-07 14:39 89,088 --a------ C:\WINDOWS\system32\atl71.dll
2008-05-27 20:30 . 2008-05-27 20:30 <REP> d-------- C:\Documents and Settings\Nico et Steph\Application Data\AXPFixer
2008-05-27 08:57 . 2008-05-27 01:20 94,208 --a------ C:\WINDOWS\ekel.exe
2008-05-20 20:51 . 2008-05-20 20:51 158,456 --------- C:\WINDOWS\system32\pxwma.dll
2008-05-19 17:23 . 2008-05-19 17:23 <REP> d-------- C:\Program Files\Fichiers communs\xing shared
2008-05-19 17:23 . 2008-05-19 17:23 499,712 --a------ C:\WINDOWS\system32\msvcp71.dll
2008-05-19 17:23 . 2008-05-19 17:23 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
2008-05-19 17:22 . 2008-05-19 17:22 <REP> d-------- C:\Program Files\Google
2008-05-14 22:22 . 2008-05-15 00:01 <REP> d-------- C:\Documents and Settings\Nico et Steph\Application Data\Download Manager
2008-05-06 22:00 . 2008-05-06 22:00 <REP> d-------- C:\Program Files\MSBuild
2008-05-06 22:00 . 2008-05-06 22:00 <REP> d-------- C:\Program Files\Microsoft Works
2008-05-06 21:59 . 2008-05-06 21:59 <REP> d-------- C:\Program Files\Microsoft.NET
2008-05-06 21:54 . 2008-05-06 22:00 <REP> d-------- C:\WINDOWS\SHELLNEW
2008-05-06 21:53 . 2008-05-06 21:53 <REP> dr-h----- C:\MSOCache
2008-05-04 23:10 . 2008-05-04 23:10 <REP> d-------- C:\Program Files\MSECache
2008-05-04 23:10 . 2008-05-06 08:42 <REP> d-------- C:\Program Files\EoRezo
2008-05-04 23:10 . 2008-05-06 08:42 <REP> d-------- C:\Documents and Settings\Nico et Steph\Application Data\EoRezo
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-06-02 09:05 --------- d-----w C:\Program Files\Wanadoo
2008-06-02 09:04 --------- d-----w C:\Program Files\eMule
2008-05-28 21:30 91,744 ----a-w C:\WINDOWS\BPMNT.dll
2008-05-28 21:30 71,749 ----a-w C:\WINDOWS\hcextoutput.dll
2008-05-28 21:30 333,576 ----a-w C:\WINDOWS\tsc.exe
2008-05-28 21:30 1,213,784 ----a-w C:\WINDOWS\vsapi32.dll
2008-05-28 08:53 --------- d-----w C:\Program Files\MSN Messenger
2008-05-20 17:39 --------- d-----w C:\Program Files\YesMessenger
2008-05-19 15:23 --------- d-----w C:\Program Files\Fichiers communs\Real
2008-05-18 16:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-18 16:11 --------- d-----w C:\Program Files\Ludiclub
2008-04-21 17:36 --------- d-----w C:\Program Files\FoxTarot4
2008-04-20 14:27 --------- d-----w C:\Program Files\monAlbumPhoto
2008-04-13 18:02 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-04-13 17:24 --------- d-----w C:\Program Files\Microsoft ActiveSync
2008-04-13 17:02 --------- d-----w C:\Program Files\epson
2008-04-13 17:01 --------- d-----w C:\Program Files\Fichiers communs\AVSMedia
2008-04-13 17:01 --------- d-----w C:\Program Files\DivX
2008-04-13 17:01 --------- d-----w C:\Program Files\AVS4YOU
2008-04-02 17:35 --------- d-----w C:\Program Files\Java
2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
2008-03-25 04:51 194,144 ----a-w C:\WINDOWS\system32\msjint40.dll
2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{54192079-8E8A-43D8-BCBC-3874916159AF}]
C:\WINDOWS\system32\818646\818646.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{62D4F8FE-6F77-41C3-BA4C-FD7880DE17F3}]
C:\WINDOWS\system32\wvUooPGy.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{109C6D5D-2E6B-48CA-9584-4691AEEA8FBF}"= "C:\WINDOWS\atfxqogp.dll" [ ]
[HKEY_CLASSES_ROOT\clsid\{109c6d5d-2e6b-48ca-9584-4691aeea8fbf}]
[HKEY_CLASSES_ROOT\atfxqogp.1]
[HKEY_CLASSES_ROOT\TypeLib\{D2F84F86-E8F3-46DC-8D18-4601915C7F56}]
[HKEY_CLASSES_ROOT\atfxqogp]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-20 01:09 15360]
"WOOKIT"="C:\PROGRA~1\Wanadoo\Shell.exe" [2004-08-23 14:50 122880]
"MSMSGS"="C:\Program Files\Messenger\MSMSGS.exe" [2004-10-13 18:24 1694208]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [ ]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-05-19 17:22 171448]
"eMuleAutoStart"="C:\Program Files\eMule\emule.exe" [2007-05-13 16:57 5308416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-05-19 17:23 185896]
"BMN"="C:\Program Files\Fichiers communs\AntivirusFiable\bm.exe" [ ]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-20 01:09 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"BootSrv"= {112781bc-0f36-4797-9ed1-b9680fd017c6} - C:\WINDOWS\Resources\BootSrv.dll [ ]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Weezo\\Apache\\bin\\weezoHttpd.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\kav\\kav7.0\\french\\setup.exe"=
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
R3 SG760_XP;SAGEM 802.11g XG760 1211 Driver;C:\WINDOWS\system32\DRIVERS\WlanUZXP.sys [2005-07-13 16:37]
R3 usbstor;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 08:08]
S0 NVDual;NVDual;C:\WINDOWS\system32\DRIVERS\nvDual.sys []
S3 SetupNTGLM7X;SetupNTGLM7X;F:\NTGLM7X.sys []
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-04 07:58]
S3 ZDCndis5;ZDCndis5 Protocol Driver;C:\WINDOWS\System32\ZDCndis5.SYS []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{39b0e09c-50f5-11dc-90c0-0060b3eba21f}]
\Shell\AutoRun\command - I:\setupSNK.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-02 11:02:09
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cach‚s ...
Balayage cach‚ autostart entries ...
Balayage des fichiers cach‚s ...
Scan termin‚ avec succŠs
Les fichiers cach‚s: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\FTRTSVC.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\SAGEM Wi-Fi USB 802.11g\WLANUTL.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\system32\ALERTM~1\ALERTM~1.EXE
C:\PROGRA~1\Wanadoo\Watch.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-06-02 11:09:30 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-02 09:09:14
Pre-Run: 18,033,225,728 octets libres
Post-Run: 18,128,363,520 octets libres
202 --- E O F --- 2008-05-28 16:30:48
A priori, j'ai récupérer l'ordi comme avant. car dans demarrer j'ai recupérer tous les dossiers!!
merci