Bonsoir,
J'ai fais comme tu dis mais c'était bizarre, l'ordi à redémarré et de drôles de questions de ComboFix... j'espère ne pas avoir fais de gaffe!
J'attends la suite... Merci!
A+
Stéphane
Voici le rapport:
ComboFix 09-01-21.04 - Stephane 2009-01-22 19:18:18.1 - NTFSx86
Lancé depuis: c:\documents and settings\Stephane\Bureau\ComboFix.exe
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\dumphive.exe
c:\windows\system32\SrchSTS.exe
c:\windows\system32\tmp.reg
.
((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_poof
((((((((((((((((((((((((((((( Fichiers créés du 2008-12-22 au 2009-01-22 ))))))))))))))))))))))))))))))))))))
.
2009-01-21 09:21 . 2009-01-21 09:21 <REP> d----c--- c:\documents and settings\All Users\Application Data\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}
2009-01-20 16:06 . 2009-01-20 16:06 14,890,811 --a------ C:\upload_moi_NOM-A467A8C8D57.tar.gz
2009-01-19 20:22 . 2009-01-19 20:22 410,984 --a------ c:\windows\system32\deploytk.dll
2009-01-19 10:32 . 2009-01-19 10:33 <REP> d-------- c:\program files\Executive Software
2009-01-18 11:36 . 2009-01-18 11:36 <REP> d-------- c:\program files\CodeStuff
2009-01-16 12:33 . 2009-01-18 11:34 <REP> d-------- c:\program files\Advanced StartUp Manager
2009-01-16 12:24 . 2009-01-16 12:24 <REP> d-------- c:\documents and settings\All Users\Application Data\Avg8
2009-01-15 14:00 . 2009-01-15 14:00 <REP> d-------- c:\program files\Trend Micro
2009-01-13 17:26 . 2009-01-13 17:26 <REP> d-------- c:\documents and settings\Stephane\Application Data\OpenOffice.org
2009-01-13 17:23 . 2009-01-13 17:24 <REP> d-------- c:\program files\OpenOffice.org 3
2009-01-11 14:00 . 2009-01-14 22:06 <REP> d-------- C:\# Telechargements
2009-01-01 12:06 . 2009-01-01 12:21 <REP> d-------- c:\program files\NOS
2009-01-01 12:06 . 2009-01-01 12:21 <REP> d-------- c:\documents and settings\All Users\Application Data\NOS
2008-12-30 10:44 . 2008-12-30 10:44 <REP> d-------- c:\program files\AVG
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2017-07-13 20:04 --------- d-----w c:\documents and settings\All Users\Application Data\Quark
2009-01-22 18:10 --------- d-----w c:\documents and settings\Stephane\Application Data\Skype
2009-01-22 17:39 --------- d-----w c:\documents and settings\Stephane\Application Data\skypePM
2009-01-20 10:57 36,410 ----a-w c:\documents and settings\Stephane\Application Data\wklnhst.dat
2009-01-19 19:22 --------- d-----w c:\program files\Java
2009-01-19 08:56 --------- d-----w c:\program files\Spybot - Search & Destroy
2009-01-19 08:56 --------- d-----w c:\program files\Lavasoft
2009-01-19 08:56 --------- d-----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-19 08:54 --------- d-----w c:\program files\a-squared Free
2009-01-14 20:59 --------- d-----w c:\program files\eMule
2009-01-11 13:40 --------- d-----w c:\program files\Fichiers communs\Adobe
2008-12-30 08:48 --------- d-----w c:\program files\CCleaner
2008-12-16 09:34 --------- d-----w c:\documents and settings\Stephane\Application Data\Canon
2008-12-11 18:48 --------- d-----w c:\program files\LaserSoft
2008-12-11 18:35 --------- d-----w c:\documents and settings\Stephane\Application Data\Lasersoft Imaging
2008-12-11 10:57 333,952 ----a-w c:\windows\system32\drivers\srv.sys
2008-11-27 13:15 --------- d-----w c:\program files\Canon
2008-11-26 16:07 --------- d-----w c:\program files\QuickTime
2008-11-26 15:09 --------- d-----w c:\program files\iTunes
2008-11-26 15:09 --------- d-----w c:\program files\iPod
2008-11-26 15:09 --------- d-----w c:\program files\Fichiers communs\Apple
2008-11-26 15:09 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-04-18 20:31 74,040 ----a-w c:\documents and settings\Stephane\Application Data\GDIPFONTCACHEV1.DAT
2008-04-09 06:35 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
2005-03-17 21:43 8 --sh--r c:\windows\system32\C805D7AFDE.sys
2005-03-17 21:43 4,704 --sha-w c:\windows\system32\KGyGaAvL.sys
2008-08-18 10:03 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008081820080819\index.dat
2008-08-18 10:03 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-08 98394]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-08 688218]
"Realtime Monitor"="c:\progra~1\CA\ETRUST~1\realmon.exe" [2004-06-25 504080]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2004-12-22 5517312]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-01-19 136600]
"AlcWzrd"="ALCWZRD.EXE" [2004-12-10 c:\windows\ALCWZRD.EXE]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\
0autocheck lsdelete
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccleaner]
--a------ 2008-12-19 19:28 1434864 c:\program files\CCleaner\ccleaner.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-11-20 13:20 290088 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 15:09 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2004-11-02 20:24 32768 c:\program files\Home Cinema\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-06-10 03:27 144784 c:\program files\Java\jre1.6.0_07\bin\jusched.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\eMule\\emule.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Fichiers communs\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
"3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
"50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
"50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowOutboundDestinationUnreachable"= 1 (0x1)
"AllowOutboundSourceQuench"= 1 (0x1)
"AllowOutboundTimeExceeded"= 1 (0x1)
"AllowRedirect"= 1 (0x1)
R1 hwinterface;hwinterface;c:\windows\system32\drivers\hwinterface.sys [2005-03-17 3026]
R3 LVHybrid;LVHybrid service;c:\windows\system32\drivers\LVHybrid.sys [2005-03-11 1013248]
R3 Slazldrv;SmartLink AMR_PCI Driver;c:\windows\system32\drivers\SLDRV\slazldrv.sys [2005-03-11 226768]
S3 CBEN5;Pilote de la famille de carte CardBus Ethernet 10/100 Xircom;c:\windows\system32\drivers\cben5.sys [2005-03-18 46108]
S3 uxddrv;Dynamically loaded UxdDrv;\??\c:\documents and settings\All Users\Bureau\WinStress\uxddrv.sys --> c:\documents and settings\All Users\Bureau\WinStress\uxddrv.sys [?]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{16ccad66-6d21-11dd-9b73-0012f013ed40}]
\Shell\AutoRun\command - G:\AutoTransfer.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{8730779c-ff93-11db-ac3e-000325242965}]
\Shell\AutoRun\command - G:\WinStressCopie.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{bd4091a4-a442-11d9-b4b5-000e35e0c54c}]
\Shell\AutoRun\command - G:\OEMBranding.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c8f5874c-d58b-11dd-9cb2-0012f013ed40}]
\Shell\Auto\command - G:\auto.exe
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL auto.exe
\Shell\EmDesk\command - G:\EmDesk.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cb400e49-a45a-11d9-b278-000e35e0c54c}]
\Shell\AutoRun\command - H:\setup.exe
.
Contenu du dossier 'Tâches planifiées'
2008-12-31 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
2009-01-17 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
2007-06-07 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
.
- - - - ORPHELINS SUPPRIMES - - - -
MSConfigStartUp-!AVG Anti-Spyware - c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
MSConfigStartUp-AppleSyncNotifier - c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
MSConfigStartUp-SmartBtn - c:\program files\smartbutton\smartbtn.exe
.
------- Examen supplémentaire -------
.
uStart Page =
hxxp://www.talti.comuSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Envoyer à &Bluetooth - c:\program files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} -
hxxp://www.coupdepoucepc.com/scan8/oscan8.cabFF - ProfilePath - c:\documents and settings\Stephane\Application Data\Mozilla\Firefox\Profiles\jbg2krtt.default\
FF - prefs.js: browser.startup.homepage -
www.google.comFF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-01-22 19:23:32
Windows 5.1.2600 Service Pack 3 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\a-squared Free\a2service.exe
c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
c:\program files\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe
c:\program files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
c:\program files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
c:\program files\Executive Software\DiskeeperLite\DKService.exe
c:\program files\CA\eTrust Antivirus\InoRpc.exe
c:\program files\CA\eTrust Antivirus\InoRT.exe
c:\program files\CA\eTrust Antivirus\InoTask.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
c:\windows\system32\nvsvc32.exe
c:\progra~1\CA\SHARED~1\SCANEN~1\Inodist.exe
c:\windows\system32\slserv.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Home Cinema\PowerCinema\Kernel\TV\CLSched.exe
c:\windows\system32\wbem\wmiapsrv.exe
.
**************************************************************************
.
Heure de fin: 2009-01-22 19:27:45 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-01-22 18:27:29
Avant-CF: 6.933.245.952 octets libres
Après-CF: 6,834,843,648 octets libres
191 --- E O F --- 2009-01-14 08:47:53