ok je fais sa desuite :) Merci de m'aidé .
Par contre j'ai un autre petit soucis , c'est que a la place du fond d'écran du bureau y'as comme un explorateur . c'est a dire quand je veux déplacé un icones il se met en arriere plan .
Ajout du 21-10-2007 à 01:24:
ComboFix 07-10-20.6 - voillon 2007-10-21 1:10:09.1 - NTFSx86
Microsoft Windows XP dition familiale 5.1.2600.2.1252.1.1036.18.122 [GMT 2:00]
Running from: C:\Documents and Settings\voillon\Local Settings\Temporary Internet Files\Content.IE5\ECGRI087\ComboFix[1].exe
* Created a new restore point
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\All Users\Application Data.\bkrancdc.dll
C:\Documents and Settings\All Users\Application Data.\mjubktqx.dll
C:\WINDOWS\dat.txt
C:\WINDOWS\rs.txt
.
((((((((((((((((((((((((((((( Fichiers créés 2007-09-20 to 2007-10-20 ))))))))))))))))))))))))))))))))))))
.
2007-10-21 01:07 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-10-20 23:26 <REP> d-------- C:\Program Files\Navilog1
2007-10-20 19:51 79,688 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-10-20 19:51 62,280 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-10-20 19:51 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-10-20 19:51 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-10-20 19:50 <REP> d-------- C:\Program Files\Spyware Doctor
2007-10-20 19:50 <REP> d-------- C:\Documents and Settings\voillon\Application Data\PC Tools
2007-10-20 19:50 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll
2007-10-20 19:43 <REP> d-------- C:\SmitfraudFix
2007-10-20 19:39 1,035,316 --a------ C:\SmitfraudFix.exe
2007-10-20 19:23 <REP> d-------- C:\WINDOWS\system32\Kaspersky Lab
2007-10-20 18:40 3,694 --a------ C:\WINDOWS\system32\tmp.reg
2007-10-20 18:39 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2007-10-20 18:39 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2007-10-20 18:39 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-10-20 18:39 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2007-10-20 18:39 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2007-10-20 18:11 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage r‚seau
2007-10-20 18:11 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2007-10-20 18:11 <REP> d--h----- C:\Documents and Settings\Administrateur\ModŠles
2007-10-20 18:11 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents
2007-10-20 18:11 <REP> dr------- C:\Documents and Settings\Administrateur\Menu D‚marrer
2007-10-20 18:11 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris
2007-10-20 18:11 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2007-10-20 03:31 <REP> d-------- C:\Program Files\PokerStars.NET
2007-10-19 17:46 <REP> d-------- C:\Program Files\Micro Application
2007-10-19 17:46 <REP> d-------- C:\Program Files\Fichiers communs\Anti-Hacker
2007-10-19 17:46 <REP> d-------- C:\Documents and Settings\voillon\Application Data\SpamTest
2007-10-19 17:46 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Anti-Virus Personal
2007-10-19 17:29 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2007-10-19 06:57 <REP> d-------- C:\Program Files\Lavasoft
2007-10-19 06:57 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2007-10-19 06:56 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
2007-10-19 06:45 512,688 --a------ C:\WINDOWS\system32\XceedCry.dll
2007-10-19 06:45 423,784 --a------ C:\WINDOWS\system32\XceedBkp.dll
2007-10-19 06:45 101,888 --a------ C:\WINDOWS\system32\VB6STKIT.DLL
2007-10-19 06:45 10,752 --a------ C:\WINDOWS\system32\md5.dll
2007-10-19 02:46 <REP> d-------- C:\Program Files\wcyxcmzf
2007-10-19 02:39 256,512 --a------ C:\WINDOWS\hostctrl.dll
2007-10-19 02:39 109,568 --a------ C:\WINDOWS\nmcuninstall.exe
2007-10-03 16:21 <REP> d-------- C:\Documents and Settings\voillon\Application Data\Leadertech
2007-09-30 06:28 801,144 --a------ C:\WINDOWS\system32\aswBoot.exe
2007-09-30 06:28 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
2007-09-30 06:28 94,416 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
2007-09-30 06:28 92,848 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
2007-09-30 06:28 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
2007-09-30 06:28 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
2007-09-30 06:28 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
2007-09-29 12:32 <REP> d-------- C:\Program Files\Neuf
2007-09-28 20:12 <REP> d-------- C:\Program Files\Cam‚ra Caf‚, Le jeu
2007-09-28 19:23 43,520 --a------ C:\WINDOWS\system32\CmdLineExt03.dll
2007-09-24 02:49 <REP> d-------- C:\WINDOWS\system32\Samsung_USB_Drivers
2007-09-24 02:49 94,000 --a------ C:\WINDOWS\system32\drivers\ss_mdm.sys
2007-09-24 02:49 58,320 --a------ C:\WINDOWS\system32\drivers\ss_bus.sys
2007-09-24 02:49 8,304 --a------ C:\WINDOWS\system32\drivers\ss_mdfl.sys
2007-09-24 02:49 6,144 --a------ C:\WINDOWS\system32\drivers\ss_cmnt.sys
2007-09-24 02:49 6,144 --a------ C:\WINDOWS\system32\drivers\ss_cm.sys
2007-09-24 02:49 5,808 --a------ C:\WINDOWS\system32\drivers\ss_whnt.sys
2007-09-24 02:49 5,808 --a------ C:\WINDOWS\system32\drivers\ss_wh.sys
2007-09-24 02:36 <REP> d-------- C:\WINDOWS\system32\Samsung
2007-09-24 02:34 <REP> d-------- C:\WINDOWS\system32\Samsung PC Studio Codecs
2007-09-24 02:34 <REP> d-------- C:\Program Files\Samsung
2007-09-24 02:34 2,067,140 -ra------ C:\WINDOWS\system32\avcodec.dll
2007-09-24 02:34 712,704 --a------ C:\WINDOWS\system32\fun_mp4_enc.dll
2007-09-24 02:34 61,440 --a------ C:\WINDOWS\system32\mp4_vcodec.dll
2007-09-22 23:42 <REP> d-------- C:\Program Files\Codemasters
2007-09-21 12:57 <REP> d-------- C:\Program Files\Fichiers communs\Adobe Systems Shared
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-20 22:39 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2007-10-20 18:49 --------- d-----w C:\Program Files\eChanblard
2007-10-20 16:13 --------- d-----w C:\Program Files\Bonjour
2007-10-20 04:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2007-10-19 19:20 --------- d-----w C:\Documents and Settings\voillon\Application Data\teamspeak2
2007-10-10 14:11 --------- d-----w C:\Program Files\Teamspeak2_RC2
2007-10-10 01:05 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2007-10-03 14:19 --------- d-----w C:\Program Files\Pirax
2007-09-29 09:49 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-09-29 09:49 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
2007-09-28 18:38 --------- d-----w C:\Program Files\Caméra Café, Le jeu
2007-09-23 18:05 --------- d-----w C:\Documents and Settings\voillon\Application Data\ma-config.com
2007-09-21 11:01 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2007-09-18 13:10 --------- d-----w C:\Program Files\PKR
2007-09-17 23:54 --------- d-----w C:\Program Files\ma-config.com
2007-09-16 23:07 6,853,088 ----a-w C:\WINDOWS\system32\drivers\nv4_mini.sys
2007-09-16 17:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\nView_Profiles
2007-09-13 23:43 --------- d-----w C:\Program Files\Fichiers communs\xing shared
2007-09-13 23:43 --------- d-----w C:\Program Files\Fichiers communs\Real
2007-09-11 21:41 --------- d-----w C:\Program Files\Real
2007-09-09 01:04 --------- d-----w C:\Program Files\Mindscape
2007-09-03 18:01 --------- d-----w C:\Documents and Settings\voillon\Application Data\Skype
2007-09-02 03:28 --------- d-----w C:\Program Files\plugins
2007-09-02 03:10 --------- d-----w C:\Program Files\VirtualDubMOD
2007-08-25 06:03 --------- d-----w C:\Documents and Settings\All Users\Application Data\FLEXnet
2007-08-25 05:34 --------- d-----w C:\Program Files\Fichiers communs\Macrovision Shared
2007-08-25 04:50 --------- d-----w C:\Program Files\Photo Frame Genius
2007-08-24 21:41 --------- d-----w C:\Program Files\SnowXtreM
2007-08-22 02:06 --------- d-----w C:\Program Files\Skype
2007-08-22 02:06 --------- d-----w C:\Program Files\Fichiers communs\Skype
2007-08-22 02:06 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
2007-06-03 13:01 758,272 ----a-w C:\Program Files\VirtualDub.exe
2007-06-03 12:58 210,421 ----a-w C:\Program Files\VirtualDub.chm
2005-07-10 12:47 117,991 ----a-w C:\Program Files\VirtualDub.vdi
2005-07-10 12:45 7,738 ----a-w C:\Program Files\vdub.exe
2005-07-10 12:45 16,384 ----a-w C:\Program Files\auxsetup.exe
2005-07-10 12:44 74,196 ----a-w C:\Program Files\VirtualDub.vdhelp
2005-07-10 12:44 7,168 ----a-w C:\Program Files\vdremote.dll
2005-07-10 12:44 6,656 ----a-w C:\Program Files\vdicmdrv.dll
2005-07-10 12:44 5,120 ----a-w C:\Program Files\vdsvrlnk.dll
2004-09-26 12:00 18,321 ----a-w C:\Program Files\copying
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{409AF909-76FA-9B47-8162-0A30D19978A1}]
2007-10-19 02:47 102400 --a------ C:\Program Files\wcyxcmzf\kmwnzxcy.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"nwiz"="nwiz.exe" [2007-09-17 01:07 C:\WINDOWS\system32\nwiz.exe]
"EnvyHFCPL"="C:\Program Files\Gamesurround Fortissimo 4 mixer\EnMixCPL.exe" [2004-10-14 08:59]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]
"SoundMan"="SOUNDMAN.EXE" [2006-11-17 05:42 C:\WINDOWS\soundman.exe]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" []
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06]
"PKR Pal"="C:\Program Files\PKR\pkrpal.exe" [2007-09-18 15:10]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-09-14 01:42]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-09-17 01:07]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 12:06]
"KAVPersonal50"="C:\Program Files\Micro Application\Sécurité Internet\Anti-Virus Perso & Pro\Anti-Virus\kav.exe" []
"OESpamTest"="C:\PROGRA~1\MICROA~1\SCURIT~1\ANTI-V~1\ANTI-S~1\OESpamTest.ExE" [2006-05-11 19:53]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-09-17 01:07]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-27 18:49]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:55]
"NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2005-07-14 21:35]
"AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" []
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-03-02 14:00]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"hstsys"= {0A480620-197C-44B6-B994-914E5F773307} - C:\WINDOWS\hstsys.dll [ ]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"
R0 Klpf;Klpf;C:\WINDOWS\system32\drivers\Klpf.sys
R0 Klpid;Klpid;C:\WINDOWS\system32\drivers\Klpid.sys
R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);C:\WINDOWS\system32\drivers\sfsync03.sys
R1 Klmc;Klmc;C:\WINDOWS\system32\drivers\klmc.sys
R3 Envy24HFS;Gamesurround Fortissimo 4 Audio Controller WDM;C:\WINDOWS\system32\drivers\Envy24HF.sys
R3 usbstor;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
S3 jgameenp;jgameenp;\??\C:\DOCUME~1\voillon\LOCALS~1\Temp\jgameenp.sys
S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys
S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys
S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cda07128-4d62-11dc-b6d3-0011d8dcaf2a}]
Auto\command - AdobeR.exe e
AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e
.
**************************************************************************
catchme 0.3.1232 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2007-10-21 01:19:09
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
Completion time: 2007-10-21 1:22:14 - machine was rebooted
.
--- E O F ---