Rebonsoir à tous, un petit contre-temps m’a éloigné de cet ordi malade.
J’ai terminé l’analyse combofix. Voici le rapport :
ComboFix 08-08-25.01 - cecile_2 2008-08-26 20:29:34.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.198 [GMT 2:00]
Endroit: C:\Documents and Settings\cecile_2\Bureau\ComboFix.exe
- Création d’un nouveau point de restauration
AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N’EST PAS INSTALLÉE SUR CETTE MACHINE !!
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Administrateur\Application Data\macromedia\Flash Player#SharedObjects\S77QLNAY\bin.clearspring.com
C:\Documents and Settings\Administrateur\Application Data\macromedia\Flash Player#SharedObjects\S77QLNAY\bin.clearspring.com\clearspring.sol
C:\Documents and Settings\Administrateur\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys#bin.clearspring.com
C:\Documents and Settings\Administrateur\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys#bin.clearspring.com\settings.sol
C:\Documents and Settings\cecile\Application Data\macromedia\Flash Player#SharedObjects\MS37DSZQ\bin.clearspring.com
C:\Documents and Settings\cecile\Application Data\macromedia\Flash Player#SharedObjects\MS37DSZQ\bin.clearspring.com\clearspring.sol
C:\Documents and Settings\cecile\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys#bin.clearspring.com
C:\Documents and Settings\cecile\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys#bin.clearspring.com\settings.sol
C:\Documents and Settings\cecile_2\Application Data\macromedia\Flash Player#SharedObjects\PPKW9UDF\bin.clearspring.com
C:\Documents and Settings\cecile_2\Application Data\macromedia\Flash Player#SharedObjects\PPKW9UDF\bin.clearspring.com\clearspring.sol
C:\Documents and Settings\cecile_2\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys#bin.clearspring.com
C:\Documents and Settings\cecile_2\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys#bin.clearspring.com\settings.sol
C:\WINDOWS\system32_000012_.tmp.dll
C:\WINDOWS\system32\ickdelfh.dll
C:\WINDOWS\system32\morCMUvw.ini
C:\WINDOWS\system32\morCMUvw.ini2
C:\WINDOWS\system32\xjbwdsib.ini
D:\Autorun.inf
.
((((((((((((((((((((((((((((( Fichiers créés 2008-07-26 to 2008-08-26 ))))))))))))))))))))))))))))))))))))
.
2008-08-26 19:54 . 2008-08-26 19:54 d-------- C:\VundoFix Backups
2008-08-26 14:16 . 2008-08-26 14:16 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-08-26 14:16 . 2008-08-26 14:16 d-------- C:\WINDOWS\LastGood
2008-08-26 11:58 . 2008-08-26 11:58 d-------- C:\Documents and Settings\NetworkService\Application Data\Webroot
2008-08-26 11:55 . 2008-08-26 11:55 d-------- C:\Program Files\Malwarebytes’ Anti-Malware
2008-08-26 11:55 . 2008-08-26 11:55 d-------- C:\Documents and Settings\cecile_2\Application Data\Malwarebytes
2008-08-26 11:55 . 2008-08-26 11:55 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-26 11:55 . 2008-08-17 15:01 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-26 11:55 . 2008-08-17 15:01 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-08-25 15:37 . 2008-08-25 15:38 d-------- C:\Program Files\Spyware Doctor
2008-08-25 15:37 . 2008-08-26 14:18 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-25 15:37 . 2008-08-25 15:37 d-------- C:\Documents and Settings\Administrateur\Application Data\PC Tools
2008-08-25 15:37 . 2008-06-10 21:22 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-08-25 15:37 . 2008-06-02 15:19 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-08-25 15:37 . 2008-06-02 15:19 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-08-25 15:37 . 2008-06-02 15:19 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-08-25 15:36 . 2008-08-25 15:36 d-------- C:\Program Files\Webroot
2008-08-25 15:36 . 2008-08-25 15:36 d-------- C:\Documents and Settings\LocalService\Application Data\Webroot
2008-08-25 15:36 . 2008-08-25 15:36 d-------- C:\Documents and Settings\All Users\Application Data\Webroot
2008-08-25 15:36 . 2007-03-01 19:54 144,960 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
2008-08-25 15:36 . 2007-03-01 19:54 22,080 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
2008-08-25 15:36 . 2007-03-01 19:54 21,056 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2008-08-25 15:36 . 2007-03-01 19:54 20,544 --a------ C:\WINDOWS\system32\drivers\SSFS0509.sys
2008-08-25 15:33 . 2008-08-25 15:33 d-------- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
2008-08-25 15:33 . 2008-08-25 15:33 d-------- C:\Program Files\Spybot - Search & Destroy
2008-08-25 15:33 . 2008-08-25 17:00 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-08-25 15:33 . 2008-08-25 15:33 d-------- C:\Documents and Settings\Administrateur\Application Data\Webroot
2008-08-25 15:33 . 2008-08-25 15:33 164 --a------ C:\install.dat
2008-08-25 15:32 . 2008-08-25 15:39 d-------- C:\Program Files\SpywareBlaster
2008-08-25 15:30 . 2008-08-25 15:30 d-------- C:\Documents and Settings\All Users\Application Data\Prevx
2008-08-25 15:27 . 2008-08-25 15:27 d-------- C:\WINDOWS\system32\GroupPolicy
2008-08-25 15:26 . 2008-08-25 18:34 d-------- C:\Program Files\Hitman Pro
2008-08-17 20:46 . 2008-05-01 16:31 331,776 -----c— C:\WINDOWS\system32\dllcache\msadce.dll
2008-08-17 20:31 . 2008-08-17 20:31 d-------- C:\Program Files\barb way acid
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-26 17:58 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\barb way acid
2008-08-26 09:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Memo save stupid creative
2008-08-25 17:22 --------- d-----w C:\Documents and Settings\cecile_2\Application Data\barb way acid
2008-08-25 16:19 --------- d-----w C:\Program Files\Circle Developement
2008-08-20 12:57 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\LimeWire
2008-08-18 18:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-07 20:31 253,952 ----a-w C:\WINDOWS\system32\es.dll
2008-06-29 20:00 --------- d-----w C:\Program Files\LimeWire
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
2008-06-23 15:40 663,552 ----a-w C:\WINDOWS\system32\wininet.dll
2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
2004-10-01 13:00 40,960 ----a-w C:\Program Files\Uninstall_CDS.exe
.
------- Sigcheck -------
2004-08-19 16:10 14336 2979b03d5382a602623c0535b16ab9c0 C:\WINDOWS\system32\svchost.exe
2004-08-19 16:09 82944 eed74b969b2ca1acc558ff60fb420e28 C:\WINDOWS\system32\ws2_32.dll
2004-08-19 16:10 506368 123eea158f74d0f67a51dcdf065d1091 C:\WINDOWS\system32\winlogon.exe
2004-08-03 23:14 182912 558635d3af1c7546d26067d5d9b6959e C:\WINDOWS\system32\drivers\ndis.sys
2004-08-03 23:00 29056 4448006b6bc60e6c027932cfc38d6855 C:\WINDOWS\system32\drivers\ip6fw.sys
2004-08-19 16:10 108544 63dcde1a0d86eeb8924d6738ff616ead C:\WINDOWS\system32\services.exe
2004-08-19 16:09 13312 259af82a0932eea4f316f92db94707b6 C:\WINDOWS\system32\lsass.exe
2004-08-19 16:09 15360 64e41e8fee655b03e3f19ded21ba5118 C:\WINDOWS\system32\ctfmon.exe
2004-08-19 16:10 25088 84717891f0734c611721f56c60b5fbc3 C:\WINDOWS\system32\userinit.exe
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Note les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\ctfmon.exe” [2004-08-19 16:09 15360]
“msnmsgr”=“C:\Program Files\MSN Messenger\msnmsgr.exe” [2007-01-19 12:55 5674352]
“swg”=“C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe” [2008-02-08 13:06 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
“ATIPTA”=“C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe” [2005-05-24 21:05 344064]
“RemoteControl”=“C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe” [2004-11-02 20:24 32768]
“NeroFilterCheck”=“C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe” [2006-01-12 16:40 155648]
“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe” [2008-05-16 01:19 79224]
“OFFICEKB”=“C:\Program Files\Labtec\Keyboard\V5.1\kbdap32a.exe” [2007-05-03 20:03 387584]
“SSBkgdUpdate”=“C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe” [2003-09-30 00:14 155648]
“OpwareSE4”=“C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe” [2006-03-21 13:19 69632]
“SunJavaUpdateSched”=“C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe” [2008-02-22 04:25 144784]
“QuickTime Task”=“C:\Program Files\QuickTime\qttask.exe” [2007-06-29 06:24 286720]
“iTunesHelper”=“C:\Program Files\iTunes\iTunesHelper.exe” [2007-09-26 14:42 267064]
“SoundMan”=“SOUNDMAN.EXE” [2006-08-02 23:12 577536 C:\WINDOWS\soundman.exe]
[HKEY_USERS.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
“CTFMON.EXE”=“C:\WINDOWS\system32\CTFMON.EXE” [2004-08-19 16:09 15360]
C:\Documents and Settings\All Users\Menu D?marrer\Programmes\D?marrage
Lancement rapide d’Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 22:05:26 29696]
Logiciel Kodak EasyShare.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2007-09-19 04:33:46 282624]
ZDWLan Utility.lnk - C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe [2007-05-24 18:54:35 413696]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dllschannel.dlldigest.dllmsnsspc.dll
[HKLM~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
“%windir%\system32\sessmgr.exe”=
“C:\Program Files\Messenger\msmsgs.exe”=
“C:\Program Files\Shareaza\Shareaza.exe”=
“C:\Program Files\eMule\emule.exe”=
“C:\Program Files\LimeWire\LimeWire.exe”=
“C:\Program Files\MSN Messenger\msnmsgr.exe”=
“C:\Program Files\MSN Messenger\livecall.exe”=
“C:\Program Files\iTunes\iTunes.exe”=
“C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE”=
“C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe”=
R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2006-02-23 05:38]
R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
S3 ZDBRGSYS;ZDBRGSYS NDIS Protocol Driver;C:\WINDOWS\system32\ZDBRGSYS.SYS [2004-06-30 13:54]
Newly Created Service - CATCHME
Newly Created Service - PROCEXP90
.
Contenu du dossier ‘Scheduled Tasks/Tâches planifiées’
2008-04-23 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 14:57]
.
-
BHO-{1F6AC0B9-6DA1-4BAF-B6B5-2AA37D45CE99} - C:\WINDOWS\system32\wvUMCrom.dll
Notify-WgaLogon - (no file)
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Search Page = www.google.com…
R0 -: HKCU-Main,Search Bar = www.google.com…
R1 -: HKCU-SearchURL,(Default) = www.google.com…
O8 -: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
.
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, www.gmer.net…
Rootkit scan 2008-08-26 20:31:29
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés …
Balayage caché autostart entries …
Balayage des fichiers cachés …
Scan terminé avec succès
Les fichiers cachés: 0
.
Temps d’accomplissement: 2008-08-26 20:32:08
ComboFix-quarantined-files.txt 2008-08-26 18:32:05
Pre-Run: 66,149,302,272 octets libres
Post-Run: 66,291,871,744 octets libres
177 — E O F — 2008-08-18 18:54:18
En espérant que cela puisse vous aidez…