jean-chretien1 a écrit :
Bon, tu dois vraiment avoir une saleté, bien coriace. Essayons cette dernière tentative
Télécharge combofix (sUBs) http://download.bleepingcomputer.com/sUBs/ComboFix.exe] sur ton Bureau
Double clique combofix.exe et suis les instructions.
Installe la console de récupération si proposé et continue.
Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
NOTE : Le rapport se trouve également ici : C:\Combofix.txt
voilComboFix 09-02-28.01 - EEEPC 2009-03-01 14:13:02.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.1015.651 [GMT 1:00]
Lancé depuis: c:\documents and settings\EEEPC\Bureau\ComboFix.exe
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Outdated)
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\EEEPC\Bureau\System Security.lnk
c:\documents and settings\EEEPC\Menu Démarrer\Programmes\System Security
c:\documents and settings\EEEPC\Menu Démarrer\Programmes\System Security\System Security.lnk
.
((((((((((((((((((((((((((((( Fichiers créés du 2009-02-01 au 2009-03-01 ))))))))))))))))))))))))))))))))))))
.
2009-11-25 00:17 . 2002-01-01 01:14 <REP> d----c--- c:\windows\system32\Atheros_L2
2009-02-28 18:00 . 2009-03-01 09:17 <REP> d----c--- c:\program files\Lavasoft
2009-02-28 18:00 . 2009-03-01 09:17 <REP> d----c--- c:\documents and settings\All Users\Application Data\Lavasoft
2009-02-28 16:53 . 2009-02-28 16:57 <REP> d----c--- c:\windows\BDOSCAN8
2009-02-26 15:56 . 2009-02-26 15:56 <REP> d--h-c--- c:\windows\msdownld.tmp
2009-02-26 15:43 . 2007-04-17 10:32 2,455,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dat
2009-02-26 15:43 . 2007-03-08 06:10 1,048,576 -----c--- c:\windows\system32\dllcache\ieframe.dll.mui
2009-02-26 15:43 . 2008-12-20 23:46 459,264 -----c--- c:\windows\system32\dllcache\msfeeds.dll
2009-02-26 15:43 . 2008-12-20 23:46 383,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dll
2009-02-26 15:43 . 2008-12-20 23:46 267,776 -----c--- c:\windows\system32\dllcache\iertutil.dll
2009-02-26 15:43 . 2008-12-20 23:46 52,224 -----c--- c:\windows\system32\dllcache\msfeedsbs.dll
2009-02-26 15:43 . 2008-12-19 10:10 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
2009-02-26 15:42 . 2008-12-20 23:46 6,066,688 -----c--- c:\windows\system32\dllcache\ieframe.dll
2009-02-26 15:42 . 2008-12-20 23:46 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll
2009-02-26 15:42 . 2007-08-13 18:54 33,792 --a--c--- c:\windows\system32\dllcache\custsat.dll
2009-02-26 15:39 . 2009-02-26 15:39 <REP> d----c--- c:\program files\Windows Live Toolbar
2009-02-26 14:32 . 2009-02-26 14:32 <REP> d----c--- c:\program files\Yahoo!
2009-02-26 14:32 . 2009-02-26 14:32 <REP> d----c--- c:\program files\CCleaner
2009-02-26 14:32 . 2009-02-26 14:32 <REP> d----c--- c:\documents and settings\EEEPC\Application Data\Yahoo!
2009-02-26 14:32 . 2009-02-26 14:35 <REP> d----c--- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-02-26 13:26 . 2009-02-26 13:27 <REP> d----c--- C:\GenProc
2009-02-26 08:16 . 2009-02-26 08:16 200,208 --a--c--- c:\windows\system32\vumer.dll
2009-02-25 09:52 . 2009-02-25 09:52 <REP> d----c--- c:\program files\Avira
2009-02-25 09:52 . 2009-02-25 09:52 <REP> d----c--- c:\documents and settings\All Users\Application Data\Avira
2009-02-25 09:09 . 2009-02-28 17:44 <REP> d----c--- c:\documents and settings\EEEPC\.housecall6.6
2009-02-25 09:08 . 2009-02-25 09:08 <REP> d----c--- c:\windows\Sun
2009-02-25 09:07 . 2009-02-28 17:15 410,984 --a--c--- c:\windows\system32\deploytk.dll
2009-02-25 08:35 . 2009-02-25 08:35 <REP> d----c--- c:\documents and settings\All Users\Application Data\1825537224
2009-02-25 08:05 . 2009-03-01 14:20 <REP> d----c--- c:\documents and settings\EEEPC\Tracing
2009-02-25 08:03 . 2009-02-25 08:03 <REP> d----c--- c:\program files\Windows Live SkyDrive
2009-02-24 13:50 . 2009-02-25 07:48 <REP> d----c--- c:\program files\Alice
2009-02-23 18:18 . 2009-02-23 18:18 <REP> d----c--- c:\program files\TechCity Solutions
2009-02-23 14:52 . 2009-02-23 14:52 <REP> d----c--- c:\documents and settings\EEEPC\Application Data\Malwarebytes
2009-02-23 14:52 . 2009-02-23 14:52 <REP> d----c--- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-23 08:32 . 2009-03-01 08:51 <REP> d----c--- c:\program files\Spybot - Search & Destroy
2009-02-23 08:32 . 2009-02-28 17:59 <REP> d----c--- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-02-22 18:37 . 2009-02-22 18:39 4,212 ---h-c--- c:\windows\system32\zllictbl.dat
2009-02-22 18:35 . 2009-02-24 14:47 <REP> d----c--- c:\windows\Internet Logs
2009-02-22 17:08 . 2003-03-18 21:20 1,060,864 --a--c--- c:\windows\system32\MFC71.dll
2009-02-22 17:07 . 2009-02-22 17:07 <REP> d----c--- c:\program files\Alwil Software
2009-02-22 09:40 . 2009-02-22 09:40 <REP> d----c--- c:\program files\Microsoft Sync Framework
2009-02-22 09:39 . 2009-02-22 09:39 <REP> d----c--- c:\program files\Microsoft SQL Server Compact Edition
2009-02-22 09:38 . 2009-02-22 09:39 <REP> d----c--- c:\program files\Windows Live
2009-02-22 09:38 . 2009-02-22 09:38 <REP> d----c--- c:\program files\Microsoft
2009-02-22 09:33 . 2009-02-22 09:33 <REP> d----c--- c:\program files\Fichiers communs\Windows Live
2009-02-20 15:53 . 2009-02-20 15:53 <REP> d----c--- c:\documents and settings\EEEPC\Application Data\AdobeUM
2009-02-06 18:52 . 2009-02-06 18:52 49,504 --a--c--- c:\windows\system32\sirenacm.dll
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-23 17:18 --------- dc-h--w c:\program files\InstallShield Installation Information
2009-01-15 17:22 --------- dc----w c:\documents and settings\EEEPC\Application Data\Azureus
2009-01-14 01:30 --------- dc----w c:\documents and settings\All Users\Application Data\ma-config.com
2009-01-14 01:21 --------- dc----w c:\program files\Intel
2009-01-08 01:31 --------- dc----w c:\documents and settings\All Users\Application Data\NOS
2008-12-20 22:47 826,368 -c--a-w c:\windows\system32\wininet.dll
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2006-03-03 15360]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AsusACPIServer"="c:\program files\Asus\EeePC ACPI\AsAcpiSvr.exe" [2008-03-20 544768]
"AsusTray"="c:\program files\Asus\EeePC ACPI\AsTray.exe" [2008-03-27 102400]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-22 104984]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-22 121368]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-22 100888]
"ACU"="c:\program files\Atheros\ACU.exe" [2007-05-03 376921]
"AliceSAV"="c:\program files\TechCity Solutions\AliceSAV\AliceAgent.exe" [2005-09-14 80384]
"467518897"="c:\documents and settings\All Users\Application Data\1825537224\467518897.exe" [2009-02-25 1197593]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"RTHDCPL"="RTHDCPL.EXE" [2008-03-07 c:\windows\RTHDCPL.EXE]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2006-03-03 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"MemCheckBoxInRunDlg"= 1 (0x1)
"NoSMBalloonTip"= 1 (0x1)
"NoWelcomeScreen"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\adbfbdcaced]
2004-07-07 03:26 280079 c:\windows\system32\adbfbdcaced.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\
0aswBoot.exe /M:34449cba
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RTHDCPL]
--a--c--- 2008-03-07 01:14 16858112 c:\windows\RTHDCPL.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 yqfvxkza;yqfvxkza;c:\windows\system32\drivers\yqfvxkza.sys [2008-03-18 23424]
R2 SeaPort;SeaPort;c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
R3 AsusACPI;ASUS ACPI Driver;c:\windows\system32\drivers\ASUSACPI.SYS [2008-04-05 11264]
R3 USB_RNDIS_51;Broadcom USB Remote NDIS Device Driver;c:\windows\system32\drivers\usb8023.sys [2008-11-30 12672]
R3 WSIMD;wsimd Service;c:\windows\system32\drivers\wsimd.sys [2002-01-01 57024]
S0 04784bb3f94c4e27cf350d599e99171e;04784bb3f94c4e27cf350d599e99171e;c:\windows\system32\
04784bb3f94c4e27cf350d599e99171e.sys --> c:\windows\system32\
04784bb3f94c4e27cf350d599e99171e.sys [?]
S3 AtcL002;NDIS Miniport Driver for Atheros L2 Fast Ethernet Controller;c:\windows\system32\drivers\l251x86.sys [2008-04-15 30720]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe --> c:\program files\NOS\bin\getPlus_HelperSvc.exe [?]
S3 Ktp;Elantech Smart-Pad;c:\windows\system32\drivers\ETD.sys [2008-04-07 25088]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{484ba444-ff4a-11dd-b52d-0015afa2e845}]
\Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\m.exe /s
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{927d5950-fe43-11d5-b518-002215ee08af}]
\Shell\AutoRun\command - F:\wdsync.exe
.
Contenu du dossier 'Tâches planifiées'
2009-02-28 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe []
2009-03-01 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
- - - - ORPHELINS SUPPRIMES - - - -
BHO-{3D578A15-4D8E-4EF9-BC9A-70A74FAA9AB3} - c:\windows\system32\browsew.dll
Notify-dimsntfy - (no file)
MSConfigStartUp-Alcmtr - ALCMTR.EXE
.
------- Examen supplémentaire -------
.
uSearchMigratedDefaultURL =
hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
uInternet Connection Wizard,ShellNext =
hxxp://eeepc.asus.com/global
uSearchURL,(Default) =
hxxp://www.google.fr/keyword/%s
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} -
hxxp://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetecti(...)
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-01 14:19:45
Windows 5.1.2600 Service Pack 2 NTFS
Recherche de processus cachés ...
Recherche d'éléments en démarrage automatique cachés ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
AliceSAV = c:\program files\TechCity Solutions\AliceSAV\AliceAgent.exe????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
Recherche de fichiers cachés ...
Scan terminé avec succès
Fichiers cachés: 0
**************************************************************************
.
--------------------- CLES DE REGISTRE BLOQUEES ---------------------
[HKEY_USERS\S-1-5-21-1634560575-1191945786-1831919508-1006\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs chargées dans les processus actifs ---------------------
- - - - - - - > 'winlogon.exe'(528)
c:\windows\system32\adbfbdcaced.dll
.
------------------------ Autres processus actifs ------------------------
.
c:\windows\system32\acs.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exe
c:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Heure de fin: 2009-03-01 14:24:01 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-03-01 13:23:54
Avant-CF: 117 157 888 octets libres
Après-CF: 193,736,704 octets libres
WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect
188 --- E O F --- 2009-02-28 08:27:35
a merci d avance